Windows 11 svchost.exe Trojan Alert

Anonymous
2022-09-11T07:53:57+00:00

Hello to whoever this may concern; 
I've recently been getting a window pop-up (from svchost.exe) that temporarily freezes everything that is focused on the desktop, even while gaming, and basically alt tabs whatever I'm focused on for about a millisecond and then re-focuses back on whatever I was on. It's super frustrating mid-game because it stops everything for a split second then tabs back in. 
I did extensive searching throughout my PC, didn't do any suspicious installs recently, I just bought this PC last week and only installed my games and necessary trusted software. 
Went on Task Manager and looked at the file path for svchost and all that I saw was filepaths in System32 (so no signs of malware). 
I ran multiple malware software and not one has fixed the issue yet. I get a notification ~ 5minutes telling me about the Trojan from svchost from Kaspersky. 

I'm currently on Microsoft Windows Version 21H2 (OS Build 22000.918)

I'll also attach a log of the report I get (using Kasperkey) regarding the trojan.

I'd like to know a fix to this problem, as I don't want to get a notification every 5 minutes about it (I have notif's disabled, but still annoying seeing svchost.exe pop up as malware every 5 minutes)

Windows for home | Windows 11 | Files, folders, and storage

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. Anonymous
    2022-09-11T08:30:14+00:00

    Hi EminM1,

    I am Dave, I will help you with this.

    svchost.exe is just a Windows process that other processes on your PC run on top of there is no indication in that what may be causing this trojan indication.

    Please do upload the log from Kaspersky to the Cloud and provide a share link there.

    Also please provide a screenshot of the popup notification you are seeing about Svchost.

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-09-11T12:29:28+00:00

    Sounds to me like Kaspersky is reporting it as a false positive, especially as you have said all the svchost things are in the system32 folder as they should be...I'd try disabling/uninstalling Kaspersky and running a scan with Windows Defender and see if it comes back with anything and then try playing your game or whatever with Kaspersky disabled/uninstalled and see what happens. AV scanners can sometimes flag legitimate svchost files.

    Personally, I'd uninstall Kaspersky completely....3rd party programs can be more problematic than Windows Defender as WD was built into Windows...plus it's free

    0 comments No comments
  3. Anonymous
    2022-09-11T20:09:53+00:00
    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2022-09-11T20:36:22+00:00

    Hi EminM1,

    Thank you for that printout, I do not see anything wrong on your system I believe Kaspersky is producing a false positive on svchost.

    The only way to be sure is to contact Kaspersky support and provide them with the log, seeing as it is their software, they should be able to find out what is causing this.

    0 comments No comments
  5. Anonymous
    2022-10-11T03:04:55+00:00

    Hi EminM1,

    Thank you for that printout, I do not see anything wrong on your system I believe Kaspersky is producing a false positive on svchost.

    The only way to be sure is to contact Kaspersky support and provide them with the log, seeing as it is their software, they should be able to find out what is causing this.

    Hi Dave, my apologies for such a late reply, I've been so busy in life and haven't really had the chance to divulge into this problem as of today.

    I will have two videos shown of what svchost.exe is doing (this svchost is not a virus, I've ran just about everything I read on google in regard to svchost.exe virus impersonating and there was no flagged problem, even with the standard Windows Defender & Kaspersky scans, etc.)
    Fullscreen svchost
    Windowed svchost

    To break it down: This is me disabling Kaspersky and using the default Windows Defender mode built into Windows 11, like Nursemorph said the free version, and during the 'Fullscreen svchost' video, you'll see I get alt-tabbed out of my game using full-screen options, very, very frustrating during clutch moments.

    For the 'Windowed svchost' video, you'll actually see the svchost.exe popup on the screen during me windowing the gameplay to capture what it is Windows is doing behind the scenes. I have no idea why it's prioritizing itself like that onto the desktop and taking full control of any application running and windowing it for no reason. This is exactly why I'm running Kaspersky Defender as it doesn't allow the pop-up to, well, pop-up.

    Ultimately, you can see Kaspersky is just doing what it's supposed to and while it being turned off, why is svchost doing what it's doing and is there any way I can terminate that specific process or maybe do something in regards with Computer Management to stop the window minimizing?

    (Everything posted above (screenshots) is still the same as of today)

    0 comments No comments