How to remove the virus svchost exe. Download the Trojan Svchost removal utility from the Russian company Security Stronghold. svсhost files - good and evil, or who is who


How to remove the svchost.exe virus? Virus infection of the SVCHOST.EXE process is a very common occurrence. This is due to the fact that Windows uses svchost.exe processes simultaneously in for different purposes. Therefore, it is beneficial for the virus to get lost among them and act like a resident. Symptoms are usually severe or fully loaded computer. The network and internet stop working. If there are many suspicious svchost.exe processes in the task manager, this does not mean that you have a virus.


Windows uses this process for many things, such as updating the OS. A sign suspicious for the presence of a virus is active process svchost.exe running as user. If you see this process launched not from NETWORK SERVICE, LOCAL SERVICE or SYSTEM, but from your account, then there is probably a Trojan on the computer.



Unfortunately, the actions of such viruses sometimes lead to severe damage systems. This problem can be solved in two ways. Either full or by restoring the registry. Let's describe simple recommendations, which will answer the question “How to remove Trojan virus in svchost.exe? Please note that before scanning with an antivirus, you must disconnect from the Internet and local network, that is, pull out the cable from network card. To plug USB drives that you use.

    1. So, the first thing we can advise is to put good antivirus. Not all virus removal programs are suitable for scanning. But there are several software solutions, which should help in the fight against the virus embedded in SVCHOST.EXE.
    2. Disable the System Restore service (relevant for Windows XP). It's done like this. Right-click on My Computer -> Properties -> System Restore tab -> check the box Disable system restore on all drives. This is done so that the svchost.exe virus does not return after treatment.
    3. Check startup. Click Start -> Run (for Win 7 command line available immediately) -> enter “msconfig”. It should not contain svchost.exe files.

  1. Download CureIT - http://www.freedrweb.com/cureit and check everything logical drives and flash drives in safe mode Windows.

In principle, you don’t have to download CureIT, but use it high-quality antivirus with updated signatures, but it’s better to play it safe and check everything with two different ways. It may be necessary to restore the keys after verification. Windows registry. If something doesn’t work out, you can always call and order a virus removal service. And for those who find these recommendations insufficient, we advise you to read the article about that - it shows detailed method removing viruses manually.

System svchost file quite often becomes a target for hacker attacks. Moreover, virus writers disguise their malware under its software “appearance.” One of the most prominent representatives viruses of the “false-svchost” category - Win32.HLLP.Neshta (Dr.Web classification).

This “impostor” copies itself into a Windows directory, infects files with the “exe” extension and takes system resources(RAM, Internet traffic). However, he is capable of other nasty things. There are known cases of infection when the virus svchost loads the computer's RAM by 98-100%, disconnects the Internet channel, and disrupts the functioning of the local network.

svсhost files - good and evil, or who is who

The whole difficulty of neutralizing viruses of this type is that there is a risk of damaging/deleting a trusted Windows file with the same name. And without it, the OS will not work; you will have to reinstall it. Therefore, before we begin the cleaning procedure, let’s get acquainted with the special signs of a trusted file and a “stranger”.

True Process

Manages system functions, which are launched from dynamic libraries(.DLL): checks and loads them. Listens network ports, transmits data through them. In fact it is official Windows application. Located in the C directory: → Windows → System 32. In OS versions XP/7/8, in 76% of cases it has a size of 20,992 bytes. But there are other options. You can find out more about them on the recognition resource filecheck.ru/process/svchost.exe.html (link - “29 more options”).

Has the following digital signatures(in the task manager, the “Users” column):

  • SYSTEM;
  • LOCAL SERVICE;
  • NETWORK SERVICE.

hacker fake

May be located in the following directories:

  • C:\Windows
  • C:\My Documents
  • C:\Program Files
  • C:\Windows\System32\drivers
  • C:\Program Files\Common Files
  • C:\Program Files
  • C:\My Documents

In addition to alternative directories, hackers use almost identical ones, similar to system process, names.

For example:

  • svch0st (digit “zero” instead of letter “o”);
  • svrhost (instead of “c” the letter “r”);
  • svhost (no "s").

There are countless versions of the “free interpretation” of the name. Therefore, it is necessary to pay special attention when analyzing existing processes.

Attention! The virus may have a different extension (other than exe). For example, “com” (Neshta virus).

So, knowing the enemy (the virus!) by sight, you can safely begin to destroy it.

Method number 1: cleaning with Comodo Cleaning Essentials utility

Cleaning Essentials - antivirus scanner. Used as an alternative software tool for cleaning the system. It comes with two utilities for detecting and monitoring Windows objects (files and registry keys).

Where to download and how to install?

1. Open comodo.com (the official website of the manufacturer) in your browser.

Advice! It is better to download the utility distribution kit on a “healthy” computer (if possible), and then run it from a USB flash drive or CD.

2. On home page hover over the “Small & Medium Business” section. In the submenu that opens, select Comodo program Cleaning Essentials.

3. In the download block, in the drop-down menu, select the bitness of your OS (32 or 64 bit).

Advice! The bit depth can be found through system menu: open “Start” → enter “System Information” in the line → click on the utility with the same name in the “Programs” list → look at the “Type” line.

4. Click the “Free Download” button. Wait until the download completes.

5. Unpack the downloaded archive: click right click by file → “Extract all...”.

6. Open the unpacked folder and double-click on the “CCE” file with the left button.

How to configure and clean the OS?

1. Select “Custom scan” mode.

2. Wait a little while the utility updates its signature databases.

3. In the scan settings window, check the box next to drive C. And also enable scanning of all additional elements(“Memory”, “Critical Areas..”, etc.).

4. Click "Scan".

5. Upon completion of the scan, allow the antivirus to remove the detected impostor virus and other dangerous objects.

Note. In addition to Comodo Cleaning Essentials, you can use other similar products to treat your PC. antivirus utilities. For example, Dr. Web CureIt!.

Helper utilities

The Cleaning Essentials treatment package includes two auxiliary tools, designed for real-time system monitoring and manual malware detection. They can be used if the virus cannot be neutralized during the automatic scanning process.

Application for quick and convenient work with registry keys, files, services and services. Autorun Analyzer determines the location of the selected object and, if necessary, can delete or copy it.

For automatic search svchost.exe files in the “File” section, select “Find” and specify the file name. Analyze the found processes, guided by the properties described above (see “Hacker fake”). If necessary, remove suspicious objects through the utility's context menu.

Monitors running processes, network connections, physical memory and CPU load. To catch a fake svchost using KillSwitch, follow these steps:

  1. On the System tab, open the Processes section.
  2. Analyze all activated svchost processes:
    • right click on the file;
    • select "Properties";
    • look at its current directory. If it is different from C:\Windows\system32\, it is most likely that the object being examined is a virus.

If malware is detected:

  1. Additionally, look at the “Rating” column (safe) and the signature in its field.
  2. If these properties also do not match the characteristics of the trusted system file, activate the context menu again (right-click). And then run the “Suspend” and “Delete” functions in sequence.
  3. Continue checking, the virus may have created and launched copies of itself. From them too mandatory need to get rid of it!

Method No. 2: using system functions

Checking startup

  1. Click "Start".
  2. Dial in search bar msconfig and press Enter.
  3. In the System Configuration window, go to the Startup tab.
  4. View the commands (Command column) that run elements when Windows startup, and their location (directories, registry keys in the “Location” column):
    • Disable all directives containing svchost (click the checkbox next to the entry). This is 100% a virus. The system process of the same name is never registered in startup.
    • Open the malware directory (listed in “Location”) and delete it. To neutralize a key in the registry, use a standard one regedit editor: “Win ​​+ R” → regedit → Enter.

Analysis of active processes

  1. Press "Ctrl + Alt + Del".
  2. Click on the “Processes” tab.
  3. Check the properties of all active svchosts (name, extension, size, location). When analyzing, rely on the data from the filecheck.ru service and the characteristics given in this article.

Right-click on the image name. From the menu, select Properties.

If a virus is detected:

  • in the properties of the object, find out its location (copy or remember);
  • click “End process”;
  • go to the malware directory and remove it using standard function(right click → Delete).

If it is difficult to determine: trusted or virus?

Sometimes it is difficult to say for sure whether svchost is real or fake. In such a situation, it is recommended to carry out additional detection using the free online scanner Virustotal. This service uses 50-55 antiviruses to scan an object for viruses.

  1. Open virustotal.com in your browser.
  2. Click Select File.
  3. IN Windows Explorer open the directory of the process that you want to check, select it by clicking, and then click “Open”.
  4. To start scanning, click “Check!” The file will be uploaded from the PC to the service and scanning will begin automatically.
  5. Review the test results. If most antivirus programs detect an object as a virus, it must be removed.

The svchost system file quite often becomes a target for hacker attacks. Moreover, virus writers disguise their malware under its software “appearance.” One of the most prominent representatives of the “false svchost” viruses is Win32.HLLP.Neshta (Dr.Web classification).

This “impostor” copies itself to a Windows directory, infects files with the “exe” extension and takes away system resources (RAM, Internet traffic). However, he is capable of other nasty things. There are known cases of infection when the virus svchost loads the computer's RAM by 98-100%, disconnects the Internet channel, and disrupts the functioning of the local network.

svсhost files - good and evil, or who is who

The whole difficulty of neutralizing viruses of this type is that there is a risk of damaging/deleting a trusted Windows file with the same name. And without it, the OS will not work; you will have to reinstall it. Therefore, before we begin the cleaning procedure, let’s get acquainted with the special signs of a trusted file and a “stranger”.

True Process

Manages system functions that are launched from dynamic libraries (.DLLs): checks and loads them. Listens to network ports and transmits data through them. In fact, it is a Windows utility application. Located in the C directory: → Windows → System 32. In OS versions XP/7/8, in 76% of cases it has a size of 20,992 bytes. But there are other options. You can find out more about them on the recognition resource filecheck.ru/process/svchost.exe.html (link - “29 more options”).

Has the following digital signatures (in the task manager, the “Users” column):

  • SYSTEM;
  • LOCAL SERVICE;
  • NETWORK SERVICE.

hacker fake

May be located in the following directories:

  • C:\Windows
  • C:\My Documents
  • C:\Program Files
  • C:\Windows\System32\drivers
  • C:\Program Files\Common Files
  • C:\Program Files
  • C:\My Documents

In addition to alternative directories, hackers use almost identical names, similar to the system process, to disguise the virus.

For example:

  • svch0st (digit “zero” instead of letter “o”);
  • svrhost (instead of “c” the letter “r”);
  • svhost (no "s").

There are countless versions of the “free interpretation” of the name. Therefore, it is necessary to pay special attention when analyzing existing processes.

Attention! The virus may have a different extension (other than exe). For example, “com” (Neshta virus).

So, knowing the enemy (the virus!) by sight, you can safely begin to destroy it.

Method number 1: cleaning with Comodo Cleaning Essentials utility

Cleaning Essentials is an antivirus scanner. Used as an alternative system cleaning software. It comes with two utilities for detecting and monitoring Windows objects (files and registry keys).

Where to download and how to install?

1. Open comodo.com (the official website of the manufacturer) in your browser.

Advice! It is better to download the utility distribution kit on a “healthy” computer (if possible), and then run it from a USB flash drive or CD.

2. On the main page, hover over the “Small & Medium Business” section. In the submenu that opens, select the Comodo Cleaning Essentials program.

3. In the download block, in the drop-down menu, select the bitness of your OS (32 or 64 bit).

Advice! The bit depth can be found through the system menu: open “Start” → enter “System Information” in the line → click on the utility with the same name in the “Programs” list → look at the “Type” line.

4. Click the “Free Download” button. Wait until the download completes.

5. Unpack the downloaded archive: right-click on the file → “Extract all...”.

6. Open the unpacked folder and double-click on the “CCE” file with the left button.

How to configure and clean the OS?

1. Select “Custom scan” mode.

2. Wait a little while the utility updates its signature databases.

3. In the scanning settings window, check the box next to drive C. And also enable checking of all additional elements (“Memory”, “Critical Areas..”, etc.).

4. Click "Scan".

5. Upon completion of the scan, allow the antivirus to remove the detected impostor virus and other dangerous objects.

Note. In addition to Comodo Cleaning Essentials, you can use other similar antivirus utilities to clean your PC. For example, Dr. Web CureIt!.

Helper utilities

The Cleaning Essentials treatment package includes two auxiliary tools designed for real-time system monitoring and manual malware detection. They can be used if the virus cannot be neutralized during the automatic scanning process.

An application for quick and convenient work with registry keys, files, services. Autorun Analyzer determines the location of the selected object and, if necessary, can delete or copy it.

To automatically search for svchost.exe files, in the “File” section, select “Find” and specify the file name. Analyze the found processes, guided by the properties described above (see “Hacker fake”). If necessary, remove suspicious objects through the utility's context menu.

Monitors running processes, network connections, physical memory and CPU load. To catch a fake svchost using KillSwitch, follow these steps:

  1. On the System tab, open the Processes section.
  2. Analyze all activated svchost processes:
    • right click on the file;
    • select "Properties";
    • look at its current directory. If it is different from C:\Windows\system32\, it is most likely that the object being examined is a virus.

If malware is detected:

  1. Additionally, look at the “Rating” column (safe) and the signature in its field.
  2. If these properties also do not correspond to the characteristics of the trusted system file, activate the context menu again (right-click). And then run the “Suspend” and “Delete” functions in sequence.
  3. Continue checking, the virus may have created and launched copies of itself. It is also imperative to get rid of them!

Method No. 2: using system functions

Checking startup

  1. Click "Start".
  2. Type msconfig in the search bar and press Enter.
  3. In the System Configuration window, go to the Startup tab.
  4. View the commands (the “Command” column) that launch elements when Windows starts, and their location (directories, registry keys in the “Location” column):
    • Disable all directives containing svchost (click the checkbox next to the entry). This is 100% a virus. The system process of the same name is never registered in startup.
    • Open the malware directory (listed in “Location”) and delete it. To neutralize a key in the registry, use staff editor regedit: “Win ​​+ R” → regedit → Enter.

Analysis of active processes

  1. Press "Ctrl + Alt + Del".
  2. Click on the “Processes” tab.
  3. Check the properties of all active svchosts (name, extension, size, location). When analyzing, rely on the data from the filecheck.ru service and the characteristics given in this article.

Right-click on the image name. From the menu, select Properties.

If a virus is detected:

  • in the properties of the object, find out its location (copy or remember);
  • click “End process”;
  • go to the malware directory and remove it using the standard function (right-click → Delete).

If it is difficult to determine: trusted or virus?

Sometimes it is difficult to say for sure whether svchost is real or fake. In such a situation, it is recommended to carry out additional detection using the free online scanner Virustotal. This service uses 50-55 antiviruses to scan an object for viruses.

  1. Open virustotal.com in your browser.
  2. Click Select File.
  3. In Windows Explorer, open the directory of the process you want to check, select it by clicking, and then click “Open”.
  4. To start scanning, click “Check!” The file will be uploaded from the PC to the service and scanning will begin automatically.
  5. Review the test results. If most antivirus programs detect an object as a virus, it must be removed.

In Windows 7, the most important process in the OS is Svchost.exe. Very often, PC users with Windows 7 encounter a problem when this process heavily loads the processor. The load on processor cores can reach from 50 to 100 percent. Svchost.exe is host process responsible for launching group services from DDL dynamic libraries. That is, the system, using this host process, starts a group of services without creating unnecessary processes. This approach reduces the load on the processor and RAM. If the system slows down and Svchost.exe heavily loads the processor, this means that the OS is not working properly. This behavior of the system can be caused by malware, as well as problems in the OS itself. To deal with this problem, in this article we will look at all the ways to solve the problem with high CPU load caused by the Svchost.exe process.

First steps to solve the problem with the Svchost.exe process

If you have a situation where the host process Svchost.exe is heavily loading the processor, then you should not immediately think that it is a virus. In addition to the virus, the culprit of this problem may be the OS itself. Below we will look list of problems, and methods to correct them:

Restoring normal processor operation using an antivirus

If the above methods didn't help, then most likely yours is Windows 7 infected with a virus. Typically, infection with a virus occurs from the outside. That is, via the Internet or via external storage data. If you have a good antivirus, then most likely the virus will not pass through. But there are cases when antiviruses do not see new versions of viruses and skip them. If your computer is infected, then the host process Svchost.exe will load the processor up to 100 percent, and in the user name you will see not the system names “LOCAL” and “NETWORK SERVICE”, but a completely different name.

To get rid of a virus in the system, you need run full scan computer in Windows 7 to search for malware. Below we will look at an example of running a full scan of your computer using an antivirus Comodo Internet Security. Also, before running any antivirus to check the OS, update it antivirus database. Let's move on and launch the antivirus Comodo Internet Security .

In the main antivirus window, go to the bottom tab “ Scanning", which will open a menu from which you can select scanning options.

In our case, you need to select the item “ Full scan " This option will scan the entire hard drive and identify malware and neutralize it. Below is the Comodo Internet Security scan window.

In other antivirus programs, the principle of launching a full PC scan is as similar as possible to what was discussed. Therefore, if you have a problem with the Svchost.exe host process, then feel free to run a full PC scan.

For this example, we chose for a reason Comodo antivirus Internet Security. This antivirus has a built-in module called KillSwitch(this module is currently included in free set utilities COMODO Cleaning Essentials, which you can download).

This module is a task manager that has advanced functionality. For example, KillSwitch can stop the process tree and revert the changes made after that.

Also a feature of KillSwitch is checking running processes for trust. That is, if the process is untrusted, KillSwitch will find it and indicate this in the third column " Grade" This feature of the KillSwitch module will help you quickly identify problems related to Svchost.exe and CPU load.

It is also worth mentioning when a virus infects the antivirus itself or reliably disguises itself from it, as a result of which it is not seen installed antivirus. In this situation, the user will come to the aid boot disk. This disk is a portable Linux-based operating system that boots from it. After booting from this disk, the user will be able to run a PC scan directly from the loaded operating system.

Such a scan should find and neutralize viruses that cause Svchost.exe to load processor cores. Most known viruses The ones that load the CPU with Svchost.exe are:

  • « Virus.Win32.Hidrag.d" - is a virus written in C++. Once in the system, he replaces Svchost.exe. After that, it looks for files with the extension “*exe” and infects them. The virus is harmless; it does not harm the system and does not steal information. But constant infection of files with the “*exe” extension greatly loads the processor.
  • « Net-Worm.Win32.Welchia.a" - this virus is Internet worm that loads the processor through Internet attacks.
  • « Trojan-Clicker.Win32.Delf.cn» - a primitive Trojan that registers in the system new process Svchost.exe to open specific page in the browser, thereby loading the system.
  • « Trojan.Carberp» - a dangerous Trojan that also disguises itself as Svchost.exe. The main purpose of this virus is search and theft of information from large retail chains.

High CPU usage due to Windows Update

On computers running Windows 7, there is often a situation where the Svchost.exe process loads the processor and memory because of the update center. To check what exactly the update center is loading up the memory and processor, you need to go to “ Task Manager"and using Svchost.exe go to the services that are in this moment he controls. An example of such a transition is shown in the image below.

After such a transition, a window with services should open, where the service “ wuauserv».

It is this service responsible for downloading and installing updates by seven. Fixing this problem is quite simple.

In the Task Manager Services window, you can completely stop “wuauserv” or disable checking for updates in the Control Panel.

But disabling the “wuauserv” service is an ugly way out of this situation.

When this service is disabled, the security of the OS as a whole is compromised, since installation of updates through the update center will be disabled.

You can solve this problem by installing updates manually. In order not to download dozens of updates from the website www.microsoft.com and then take a long time to install them, it is best to use a set of updates UpdatePack7R2. The developer of this set is " simplex", who is also known by this nickname and is a moderator on the www.oszone.net forum. You can download this set from the website http://update7.simplix.info. Currently posted on the website latest version numbered 12/17/15. After downloading the set, you can begin installing updates. To do this, let's run the installer.

In the window that appears, click the Install button. After this, the update installation process will begin.

This process can take quite a long time and depends on the amount already installed updates. Update this way offline the Windows way 7 is possible constantly, since the author of the project is constantly releasing new sets. You can also restart the update center after the update installation is complete. The memory and CPU usage issue should go away this time as these updates contain a fix.

Other ways to solve the problem with CPU load due to Svchost.exe

In this section we will describe methods that in some cases help solve the problem with Svchost.exe, and also increase overall performance and system stability. Below is list with detailed description each of the ways:

  • Very often it helps to solve the problem of the Svchost.exe process, even when it is infected with a virus, the usual OS rollback using a restore point. But this method can only be used if system protection is enabled.
  • At long-term use various installed programs operating system Windows 7 accumulates a lot of garbage on the hard drive. By garbage we mean temporary files, created when using various utilities. For example, browser history files. In this case, they will come to the rescue special utilities to clean the OS. The most popular among them is the program CCleaner.
  • We also recommend defragmentation, which can improve overall system performance. Defragmentation, although it will not solve the problem with the Svchost.exe process, will significantly speed it up, thereby reducing the load on the processor. One of best defragmenters is a utility Defraggler, which, in addition to its main function, can also defragment system files.
  • Cleaning the registry also helps solve our problem. To clean the registry, as in the method above, use the utility CCleaner which is fast will delete old registry keys, preventing Svchost.exe from working correctly.
  • Also, for all running processes, including Svchost.exe, an important factor is the working RAM. At faulty memory The system and running processes may behave unstable. The way out of this situation would be replacing RAM with working memory. You can check your memory for serviceability using the built-in diagnostic tool in Windows 7.

Conclusion

In this article, we covered quite extensively the problem associated with high CPU usage due to the Svchost.exe process. Based on this, our readers will certainly be able to solve this problem and ensure normal work computer.

Video on the topic

For none of Windows users It’s no secret that when your computer freezes or slows down, you first need to look at the “Task Manager” in order to end the processes that are weighing down the system. The task, let’s say, is for first-graders: it seems like we were swimming and we know what’s there and how. However, looking once again into the notorious dispatcher, many users, to their surprise, notice almost for the first time that overload central processor runs a process like svchost.exe, which, please note, is displayed not in one, but in 4 or even more lines at once:

Well, think for yourself, what other reaction could there be at this moment, other than panic at the thought that a virus has settled on your favorite PC? In my memory, there has never been a time when system processes were duplicated in the “Task Manager”! However, before looking in horror for a solution on how to quickly remove svchost.exe from your computer, you need to figure out whether it is actually a virus or not.

Step No. 1: Detecting viruses

Perhaps it’s worth noting right away that the svchost.exe process itself does not pose any threat to Windows, no matter how strange it may seem. In fact, it is designed to run services built into the system, services and various programs that use special DLL libraries in their work. However, based on the fact that such system services There are often quite a few on a computer; executing them in one process can be very difficult. This is why svchost.exe is often launched several times, serving individual services Windows.

It is clear that deleting such processes does not make any sense, since to disable them it will be enough to simply restart the computer. In the same time complete removal The svchost.exe system file may cause problems with Windows work, the appearance of all sorts of errors and other problems with Windows. That’s why, having found a whole fan of svchost.exe in the “Task Manager”, there is no need to rush to say goodbye to it right away: everything can be much simpler.

However, you shouldn’t relax in this case either. The fact is that viruses often disguise themselves as svchost.exe, bringing with them very unpleasant gifts in the form of:

  • random exit of the computer from sleep mode;
  • appearance system error when launching applications, opening the drive or reading a disc;
  • automatic reboot Windows;
  • turning off the computer for no reason;
  • PC slowdown due to CPU load of more than 90%;
  • spontaneous opening of applications, etc.

The question arises, how can you determine in this case where the virus is and where the normal system process svchost.exe is? The answer is simple - take a closer look at it.

So, the first sign that svchost.exe is a virus will be the execution of this process on behalf of the user (normally it is launched on behalf of LOCAL SERVICE, SYSTEM (system) or NETWORK SERVICE). To determine this, just press Ctrl+Shift+Esc on your keyboard at the same time, thereby calling up the “Task Manager”, then select the “Processes” tab in the window that opens and, finally, look at the data indicated in the “User” column for the process svchost.exe:

I note that for the same purpose, if desired, you can use a special program Process Explorer, which displays full information about all processes running on the computer, including svchost.exe:

At the same time, the location of such a file can help determine whether there is a threat from svchost.exe. Remember: normally it is stored only in one of 4 folders located on the hard drive, namely in the directory:

  • WINDOWS\Prefetch
  • WINDOWS\ServicePackFiles\i386
  • WINDOWS\system32
  • WINDOWS\winsxs

Accordingly, if svchost.exe is located in some other place, for example, separately in the WINDOWS folder, rest assured: this is a real virus. At the same time, the “Task Manager” can again help you check whether this is actually the case. In this case, after starting it, you will need to right-click on the line with the process name svchost.exe, select the “Properties” item in the menu that opens, and then pay attention to the “Location” field:

In addition, the name of the process itself can be a clue. Thus, any deviations from the spelling svchost.exe in the image name can be safely regarded as a hidden virus threat. Therefore, if you see in the “Task Manager” processes such as svhost.exe, svehost.exe, svxhost.exe, svchos1.exe, svchest.exe, svch0st.exe and other misspelled values, you can safely delete them: these are viruses.

Step No. 2: Remove viruses from svchost.exe

It must be said that due to the numerous varieties of svchost.exe viruses of some kind universal method There is simply no way to remove them from your computer at the moment. In particular, in the decision similar problem may I help full check Windows installed on PC antivirus program. The main thing in this case is not to forget before starting it:

  • disconnect from the local network and the Internet;
  • end suspicious svchost.exe processes in the Task Manager;
  • clear startup of svchost.exe files. In this case, we first need to press ÿ+R on the keyboard, then enter the msconfig task into the “Run” utility that appears, click OK, and then after selecting the “Startup” tab in the window that opens, check for the presence of svchost.exe in it:

At the same time, so that the effect of treating your computer does not turn out to be temporary, you must take care of installing and updating the Windows powerful antivirus and firewall. This is the only way to be sure that the problem with the malicious Trojan file svchost.exe will not return to the system.