Demystifying the “SVCHOST.EXE” Process and Its Command Line Options

<p>The Service Host process or&nbsp;<em>&ldquo;svchost.exe&rdquo;</em>&nbsp;is one the most&nbsp;notorious&nbsp;processes out there. It got a bad reputation for being &ldquo;malicious&rdquo; due to mostly two factors, one is malware impersonating it and the other is good old &ldquo;Task Manager&rdquo;.</p> <p>Because of the way task manager was designed in the old days (and to some extent today), it never gave much details into processes on the system and especially &ldquo;special&rdquo; processes like&nbsp;<em>&ldquo;svchost.exe&rdquo;</em>. So by using the task manager to see what processes are opened, you&rsquo;ll get a bunch of&nbsp;<em>&ldquo;svchost.exe&rdquo;</em>&nbsp;processes with the description &ldquo;Host Process for Windows Services&rdquo;. Without any information about the services that are hosted in it. So it only took malware two additional steps to make itself look legitimate.</p> <p>First, name the malware&nbsp;<em>&ldquo;svchost.exe&rdquo;</em>&nbsp;and second, give it the description&nbsp;<em>&ldquo;Host Process for Windows Services&rdquo;</em>&nbsp;and you&rsquo;ll be indistinguishable from the legitimate&nbsp;<em>&ldquo;svchost.exe&rdquo;</em>&nbsp;process as far as the old task manager is concerned.</p> <p><a href="https://nasbench.medium.com/demystifying-the-svchost-exe-process-and-its-command-line-options-508e9114e747"><strong>Visit Now</strong></a></p>
Tags: SVCHOST EXE