Jump to content

svchost running under user account


Recommended Posts

Hello,

I have encountered a problem today which leads me to be uncertain about whether or not I have a virus on my PC.

Today I got a notification that svchost tried to access a protected folder (\Device\HarddiskVolume3).

While researching svchost, I found out that svchost should not be running under the user account and that if it does, it at least indicated a virus infection in the past. There are multiple svchost processes running under my account name. 

I ran both a full Windows Defender check (after making sure it is up to date) as well as a regular Malwarebytes scan. None of them managed to find anything.  VirusTotal also did not pick up anything for the svchost.exe, it is the one in the System32 folder, and the signer is verified.

Using Process Explorer, I managed to find out that their services are: CDPUserSvc_8305cab, webthreatdefusersvc_8305cab, WpnUserService_8305cab, cdbhsvc_8305cab, UdkUserSvc_8305cab, NPSMSvc_8305 and finally the following all for one process OneSyncSvc_8305cab, PimIndexMaintenanceSvc_8305cab, UnistoreSvc_8305cab and UserDataSvc_8305cab.

image.thumb.png.116eca69f927ad0e9197b404f543618c.png

I am using Windows 11. 

Could somebody please tell me what next steps I should take? Is there any way to make sure that there is or isn't malware present?

Thank you in advance!

Link to post
Share on other sites

@Phil97

Please download Farbar Recovery Scan Tool and save it to your desktop.

Please rename FRST.EXE or FRST64.EXE to FRSTEnglish.exe image.png.08b987105a3f991c3bd3c5b02d550ebc.png

Note: You need to run the version compatible with your system.
You can check here if you're not sure if your computer is 32-bit or 64-bit

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press the Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
  • The first time the tool is run, it also makes another log (Addition.txt). Please attach it to your reply as well.

Thank you

  • Like 1
Link to post
Share on other sites

Thank you, I had posed a similar question at the Microsoft forum and have been informed that this is completely normal behavior in Windows 11. The svchost services I listed are per-user-services, which are run under the logged-in user account: https://learn.microsoft.com/en-us/windows/application-management/per-user-services-in-windows

Sorry for any inconvenience I caused

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.