I have a process using svchost. Is this a virus?

shedyk

New Member
Thread author
Apr 15, 2018
2
I have a process that runs high on cpu but has no name.
On checking further details the process is run by svchost.exe and ending the process shuts down my pc.
It started about 3 days ago, it does not run always but I have noticed it runs only when power is connected. It doesn't seem to run when I start my pc on battery only.

The tmp folder it shows on the screenshot is empty.

I have tried a couple of antivirus - anti malware deep scan but all come up clean.
 

Attachments

  • unamed svchost process.png
    unamed svchost process.png
    69.7 KB · Views: 74

tim one

Level 21
Verified
Honorary Member
Top Poster
Malware Hunter
Jul 31, 2014
1,086
It seems a normal instance of svchost.exe. Service Host hosts services that work in the background even when there are no logged users. But sometimes the problem is to understand which services are running within a given instance.

However if you suspect a malware infection, please follow @harlan4096 suggestion.
 

mekelek

Level 28
Verified
Well-known
Feb 24, 2017
1,661
It seems a normal instance of svchost.exe. Service Host hosts services that work in the background even when there are no logged users. But sometimes the problem is to understand which services are running within a given instance.

However if you suspect a malware infection, please follow @harlan4096 suggestion.
svchost that has a temp folder file in the command line? that doesn't seem legit at all.
the 2nd one seems clean but the first isnt.
 

DavidLMO

Level 4
Verified
Dec 25, 2017
158
Agree that the first looks suspect. Also agree that you need to run Process Explorer (or other app) to find out what is acyually running behind that instance of svchost.
 
  • Like
Reactions: Gandalf_The_Grey

tim one

Level 21
Verified
Honorary Member
Top Poster
Malware Hunter
Jul 31, 2014
1,086
svchost that has a temp folder file in the command line? that doesn't seem legit at all.
the 2nd one seems clean but the first isnt.
Ops... you are right! I don't know why I focused only on the second svchost file.
But at this point yes there is something suspicious about the path of the first one.
 

Mahesh Sudula

Level 17
Verified
Top Poster
Well-known
Sep 3, 2017
825
First one is suspected...believe me most of the av fail in process injections!!
Have a scan with rogue killer..most probably he should fix it
For instance the point is a hidden virus from that temp path executed itself in name of svchost to prevent detection.
Zemana is also very good in these instances.
 
  • Like
Reactions: amico81

shedyk

New Member
Thread author
Apr 15, 2018
2
First one is suspected...believe me most of the av fail in process injections!!
Have a scan with rogue killer..most probably he should fix it
For instance the point is a hidden virus from that temp path executed itself in name of svchost to prevent detection.
Zemana is also very good in these instances.
I think the issue might be related to SlimCleaner Plus. I have just seen your reply now and scanned PC with Rogue Killer and it marked lots of files and registry keys related to it as dangerous.

I had already stopped my PC from running the unnamed svchost processes by booting in safemode and emptying the Temp folder and uninstalling all programs I had install in the week before I noticed this issue.(Coincidentally one of them was SlimCleaner). Emptying Temp and uninstalling it seemed to have stopped the processes from loading but infections were still there. Rogue Killer hopefully delivered the final nail on it.
 
Last edited:

Hector1

Level 4
Verified
Well-known
Aug 4, 2015
152
In this case a restore from backup or a clean install of windows is the best solution for peace of mind.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top