How to remove the svch0st virus

Most antivirus programs identify svch0st.exe as malware—e.g. TrendMicro identifies it as BKDR_HUPIGON.WGO or BKDR_BAVN.AL, and Symantec identifies it as Backdoor.Graybird or Backdoor.Trojan.

The free file information forum can help you find out how to remove it. If you have additional information about this file, please leave a comment or a suggestion for other users.

Click to Run a Free Virus Scan for the svch0st.exe malware

Svch0st.exe file information

The process known as Microsoft appears to belong to software Windows Update or Socks5 or weiyun or COMSystem by Microsoft ( or Tencent (

Description: Svch0st.exe is not essential for Windows and will often cause problems. Svch0st.exe is located in the C:\Windows\System32 folder. Known file sizes on Windows 10/8/7/XP are 8,797 bytes (33% of all occurrences), 503,859 bytes or 287,226 bytes. 
It is not a Windows system file. There is no description of the program. The program is not visible. It is an unknown file in the Windows folder. The program is loaded during the Windows boot process (see Registry key: Winlogon\Shell, Userinit, User Shell Folders, Run, DEFAULT\Run). The software uses ports to connect to or from a LAN or the Internet. Svch0st.exe is able to monitor applications, record keyboard and mouse inputs and manipulate other programs. Therefore the technical security rating is 86% dangerous.

Recommended: Identify svch0st.exe related errors

External information from Paul Collins:
There are different files with the same name:

Important: You should check the svch0st.exe process on your PC to see if it is a threat. We recommend Security Task Manager for verifying your computer's security. This was one of the Top Download Picks of The Washington Post and PC World.


User Comments

There are no user opinions yet. Why not be the first to write a short comment?

Do you have additional information? Help other users!
What do you know about svch0st.exe:
How would you rate it:
Link for more info:
Your Name:

Best practices for resolving svch0st issues

The following programs have also been shown useful for a deeper analysis: ASecurity Task Manager examines the active svch0st process on your computer and clearly tells you what it is doing. Malwarebytes' well-known Banti-malware tool tells you if the svch0st.exe on your computer displays annoying ads, slowing it down. This type of unwanted adware program is not considered by some antivirus software to be a virus and is therefore not marked for cleanup.

A clean and tidy computer is the key requirement for avoiding PC trouble. This means running a scan for malware, cleaning your hard drive using 1cleanmgr and 2sfc /scannow, 3uninstalling programs that you no longer need, checking for Autostart programs (using 4msconfig) and enabling Windows' 5Automatic Update. Always remember to perform periodic backups, or at least to set restore points.

Should you experience an actual problem, try to recall the last thing you did, or the last thing you installed before the problem appeared for the first time. Use the 6resmon command to identify the processes that are causing your problem. Even for serious problems, rather than reinstalling Windows, you are better off repairing of your installation or, for Windows 8 and later versions, executing the 7DISM.exe /Online /Cleanup-image /Restorehealth command. This allows you to repair the operating system without losing data.

Other processes

svch0st.exe [all]