How to Remove “svchost.exe”

What is Svchost.exe?

The svchost.exe is an executable file of Microsoft Windows and is tagged as a Generic Host Process for Win32 Services. This is an important Windows file and it is used to load the required DLL files that are used with Microsoft Windows and Windows programs that run on your computer. Some Malware often uses a process by the name “svchost.exe” to mimic the windows process.

The orginal file is located only in c:\windows\system32 or c:\winnt\system32 depending on versions of Windows OS. If the file that is located in any other location, then we can conclude that the system is infected with malware.

svchost.exe provides a service which is used by Windows Defender. There are multiple instances provided by svchost.exe which are used for many operations. One instance may provide single operation and other instance provide several service to windows.To know the service which are currently running. Go to Task Manager and click Processes tab. Click Show all process and Right-click an instance of svchost.exe, and then click Go to Service(s). The services associated with the process are highlighted on the Services tab.

Affected OS/Platform: Windows

How to find System is affected by Svchost.exe malware

Step 1: Open the Task Manager with a CTRL+ALT+DEL key combination

Step 2: Right click on the svchost.exe and Select Open File Location The Open File Location will be showing you the path where the file is actually located c:\windows\system32 or c:\winnt\system32.

If it gets open in some other folder or file location, then it is sure that the system is infected with svchost.exe malware.

How to remove the svchost.exe file from system using Comodo Antivirus

Step 1: Download the Award-Winning Comodo Free Antivirus

Step 2: Installation configuration frames will be displayed. Select the configuration you would like to apply

Step 3: Select Customize Configuration option and arrange installers, configuration, and file location.

Step 4: Once the Installation is Finished, restart your PC.

Step 5: Comodo Internet Security starts antivirus bases update. It takes sometime to get updated.

Step 6: After the update, a Quick scan is executed.

Step 7: If threats are found upon completion of scanning, you will be prompted with an alert screen.

Step 8: It will clean all malware including svchost.exe.

33

Malware Entries

First Seen: 30 October 2009 at 1:19 pm
No. Company File Type SHA1 MD5 Malware
Name
Digitally
Signed
File
Version
Product
Version
Submitted
From
Malware Behavior
1 N/A Executable de9fdda8062118fd
daf8b2562627350e
3eb0d109
ce0dbbade0ae2e50
04abcf36ebbd3395
TrojWare.Win
32.VB.QOTY
No 1.00 1.00 Venezuela N/A
2 Microsoft Corporation Executable e02a45b674c4e8dd
2a033b7f06968b89
db0b4e03
98721c8cfb4f6266
7126ccd86c7d0037
Virus.Win32.
Virut.CE
No 5.1.2600.5
512
(xpsp.0804
13-2111)
5.1.2600.5
512
156.211.202.122/32 N/A
3 N/A Executable 89c02bc9fe3a8dde
e11c1dfa06e0fa59
7c593e86
d00f8f9618c33ab7
a8162b23e8b9570a
ApplicUnwnt Yes 1.336 1.336 Ukraine N/A
4 N/A Executable 3d289d9b7e3521f3
3b6cba1c1add5524
33fd7ce1
94cf4243082480da
a79451bf855a8587
Unclassified
Malware
No 1.0.0.0 1.0.0.0 United States N/A
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
15

Safe Entries

First Seen: 04 June 2008 at 6:11 pm
No. Company File Type SHA1 MD5 Digitally
Signed
File
Version
Product
Version
Submitted
From
1 Microsoft Corporation Executable bf15549a7ec01ac5
05ccac036aba5b9b
ae688135
3794b461c45882e0
6856f282eef025af
No 6.0.6001.1
8000
(longhorn_
rtm.080118
-1840)
6.0.6001.1
8000
Slovakia
2 N/A Executable c610179d1bf2e56c
58510f8e9aa452dc
5531eb9d
6e90ebf86ab0373f
7b76f1377f8ed2f3
No N/A N/A United States
3 Microsoft Corporation Executable 0dac68816ae7c09e
fc24d11c27c3274d
fd147dee
36f670d890407090
13f6a460176767ec
Yes 10.0.14393
.0
(rs1_relea
se.160715-
1616)
10.0.14393
.0
United States
4 Microsoft Corporation Executable db9489d0f95f1adf
f8061de8b42c4f80
ee0a3ea8
6a1212077c055902
9cdfb9c39580c835
Yes 10.0.10586
.0
(th2_relea
se.151029-
1700)
10.0.10586
.0
United States
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
 

Comodo Internet Security Pro

Free Antivirus protection from hackers! Get the ultimate Antivirus solution to keep your PC clean and to remove viruses from a slow or infected PC. Improve the PC performance at home or use it on-the-go!

Get Comodo Internet Security Comodo Internet Security

Slow or Infected PC?

Your search for a way to clean your PC of viruses once and for all has Ended. Our Security experts will fix your PC problems. Let's get started right now!

Get GeekBuddy GeekBuddy