Suspicious "Secure System" Process in Task Manager

Anonymous
2021-07-05T14:09:12+00:00

I was looking through my task manager processes the other day and noticed a process I'd never seen before called "Secure System".

The name is so innocuous it actually stuck out to me as a bit suspicious.

While looking it up online, I found some mentions that it's a process that might run on Windows Server installs. The thing is, I'm using Windows 10 Home.

Along with this "Secure System" process, there were also a few others that are apparently only supposed to show up on Server, such as "Credential Guard and Key Guard"(Lsalso.exe). I've also seen a Hyper-V Service running once, yet I cannot find Hyper-V on the Windows Features menu.

(I also have some weirdly named svchost processes, such as cbdhsvc_338d7. Thought I might as well mention these while we're at it)

The Secure System process currently sits at the bottom of CPU and RAM usage, but it has used quite a bit of resources at one point in the past.

Maybe I'm just being ignorant and paranoid, but is this normal by any chance? I was suspecting a virus or rootkit of some sort, but I've since run multiple AV and AR utilities (Win Defender, MBAM, Adwcleaner, MBAR, TDSSKiller, and RogueKiller) and none of them have found anything. Should I be worried? Would it be better to reinstall W10 just to be safe?

Thanks in advance.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. DaveM121 814.5K Reputation points Independent Advisor
    2021-07-05T14:44:51+00:00

    Hi Leif76

    I am Dave, an Independent Advisor, I will help you with this.

    Open the Settings App, then go to Update and Security - Activation, what version of Windows 10 do you have installed on your PC, is that Home, Pro or Enterprise?

    All the processes you list are genuine Windows processes, though they usually are only running in the Enterprise version, though Microsoft are constantly making IWndows10 more secure, but you can rest assured, those are legitimate processes

    14 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2021-07-05T15:10:14+00:00

    Hi Dave,

    The settings say I'm running Windows 10 Home (winver specifies build 19043.1052, if it matters).

    I was just worried that, since these are typically Enterprise processes (not Server, oops), they could have been fake or hijacked processes (don't know if that's even possible), but seems like that isn't the case then huh?

    If you say they're all genuine, then that's that.

    But just out of curiosity, what could be a possible reason for these processes to be running on Home Edition, and is there any way to disable them? Would there be any benefit in doing so?

    In any case, thanks for the reply.

    11 people found this answer helpful.
    0 comments No comments
  3. DaveM121 814.5K Reputation points Independent Advisor
    2021-07-05T15:13:12+00:00

    Hi Leif76,

    Rest assured they are genuine and many people have reported those processes running on the home version, usually that is caused by a VM or Emulator that was running at some time on the PC and that initiated those services in the Home version, either way, you have nothing to worry about.

    15 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2021-07-05T16:05:18+00:00

    If that's the case, then I guess all is well.

    Thanks a lot for the help, Dave!

    5 people found this answer helpful.
    0 comments No comments
  5. DaveM121 814.5K Reputation points Independent Advisor
    2021-07-05T16:05:40+00:00

    Hi Leif76, glad to help!

    9 people found this answer helpful.
    0 comments No comments