scvhost.eve - process or virus

joecrashed

New member
Local time
6:41 AM
Messages
3
I have run different online scanners as well as my Norton AV, Malwarebytes, and Defender, and am fairly confident I am virus free. However, when going through the Norton Log, I came across numerous instances of where it blocked scvhost from accessing different processes. I downloaded UniBlues Process QuickLinks, to help decypher what process is what, and saw that for svchost.exe it can either be a legitimate process, or about 3 or 4 different Trojans. How on earth do you tell the legit processes apart from the virus? I understand that svchost process is needed to launch .dll files, and is legit, but can't find any info on how to tell a legit instance of it from a virus; other than understanding that enabling heuristic detection on Norton analyzes how something is running (which I always keep cranked up to High, or agressive)

Thanks for helping me understand this! ;-)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo
OS
Windows 7 Home Premium 64 bit
CPU
Intel core 3 quad processors
Motherboard
OEM
Memory
6GB RAM
Graphics Card(s)
OEM
Hard Drives
1 TB, Seagate
Antivirus
Norton Security Suite, Malwarebytes
Browser
Google Chrome - v. 25
Instances of svchost.exe located in the windows\system32 folder will be legitimate. Elsewhere probably malware. You can determine this by adding the "command line" column in Task Manager, details tab. Don't confuse svchost.exe with scvhost.exe which would usually be malware. The name similarity is deliberately intended to cause confusion.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Pro 64 bit
CPU
Xeon W3520
Memory
8 GB
Graphics Card(s)
Nvidia Geforce 210
The svchost.exe itself is no virus. If anything, Norton may tag a .dll running under the svchost.exe. I have, however, never seen a .dll that was found to be a virus.

You may get more insight if you run Process Explorer and find out which .dlls are running (right click on the svchost.exe in question and go to Properties > Services tag).
 

My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
You might like this little program calles svchost Viewer. It will shwo you the PID of each running instance, and what processes are running under it

svchost viewer - Home

Clicking on each child process will give you a description. A Guy
 

My Computer

Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
Back
Top