You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows Server 2012异常svchost.exe后台进程排查与禁用咨询

Troubleshooting the Hidden, Unassociated svchost.exe in Windows Server 2012

Alright, let's break down how to tackle this tricky issue step by step. That "svchost.exe" in c:\windows\fonts you can't see via File Explorer—plus no linked services—screams either obfuscated malware or a misconfigured rogue process. Here's what to do:

Step 1: Reveal the Hidden svchost.exe File

File Explorer's default settings are probably blocked from showing it; malware often tweaks these to hide itself. Try these methods:

  • Command Line: Open an elevated Command Prompt (right-click → Run as administrator) and run:
    dir /a c:\windows\fonts\svchost.exe
    
    The /a flag shows all files, including those with hidden/system attributes. If it exists, you'll see its details here.
  • PowerShell (Force Mode): Use elevated PowerShell to bypass hidden file restrictions:
    Get-ChildItem -Path C:\Windows\Fonts -Force | Where-Object {$_.Name -eq "svchost.exe"}
    
    The -Force parameter reveals normally hidden items.
  • Fix File Explorer Visibility: If even that fails, malware might have modified your registry to disable hidden file viewing. Run this in elevated Command Prompt to reset it:
    reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v Hidden /t REG_DWORD /d 1 /f
    reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v ShowSuperHidden /t REG_DWORD /d 1 /f
    
    Then restart File Explorer (taskkill /f /im explorer.exe && start explorer.exe) and check again.

Step 2: Find Associated .dll Files for the PID

To see which .dlls the process is loading, you'll need a more powerful tool than Task Manager:

  • Process Explorer: Grab this from Microsoft's Sysinternals suite (free and official). Once launched:
    1. Find the target PID in the process list (use the "Find" menu → "Find Process by PID" to speed this up).
    2. Right-click the process → Properties → navigate to the Modules tab.
    3. This tab lists every .dll and executable loaded by the process, along with their full file paths.
  • Command Line Alternative: If you prefer CLI, run this in elevated Command Prompt:
    tasklist /m /fi "PID eq [YOUR_TARGET_PID]"
    
    Replace [YOUR_TARGET_PID] with the actual PID of the process. This outputs loaded modules, though it's less detailed than Process Explorer.

Step 3: Block the Process from Starting Up

Once you've identified the files, here's how to stop it from running again:

  1. Terminate the Process: First, kill the rogue svchost.exe (and any child processes) using Process Explorer: right-click the process → Kill Process Tree. This is safer than Task Manager because it ensures all related processes are stopped.
  2. Delete the Hidden Executable: Use elevated Command Prompt to delete the file, since File Explorer might fail:
    del /f /a c:\windows\fonts\svchost.exe
    
    The /f forces deletion, /a targets all attribute types.
  3. Remove Startup Triggers: Check all possible launch points to prevent it from returning:
    • Registry Startup Keys: Open regedit and check these paths for entries referencing the fonts folder svchost.exe:
      • HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      • HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run (for 32-bit processes on 64-bit systems)
      • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
        Delete any suspicious entries you find.
    • Task Scheduler: Open Task Scheduler and search for tasks that run the svchost.exe from c:\windows\fonts. Delete any matching tasks.
    • Autoruns (Sysinternals): This tool is even better for finding hidden startup entries. Launch it, search for "fonts" or "svchost.exe", and disable/delete any suspicious entries it finds.

Step 4: Verify and Clean Up

  • Run a full scan with Windows Defender (or your enterprise antivirus) to catch any remaining malicious components.
  • Check the Modules list from Step 2 for any suspicious .dlls, and delete those as well using the same command line method if needed.

内容的提问来源于stack exchange,提问作者Bryan Raynolds

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:32:49