Windows Server 2012异常svchost.exe后台进程排查与禁用咨询
Alright, let's break down how to tackle this tricky issue step by step. That "svchost.exe" in c:\windows\fonts you can't see via File Explorer—plus no linked services—screams either obfuscated malware or a misconfigured rogue process. Here's what to do:
Step 1: Reveal the Hidden svchost.exe File
File Explorer's default settings are probably blocked from showing it; malware often tweaks these to hide itself. Try these methods:
- Command Line: Open an elevated Command Prompt (right-click → Run as administrator) and run:
Thedir /a c:\windows\fonts\svchost.exe/aflag shows all files, including those with hidden/system attributes. If it exists, you'll see its details here. - PowerShell (Force Mode): Use elevated PowerShell to bypass hidden file restrictions:
TheGet-ChildItem -Path C:\Windows\Fonts -Force | Where-Object {$_.Name -eq "svchost.exe"}-Forceparameter reveals normally hidden items. - Fix File Explorer Visibility: If even that fails, malware might have modified your registry to disable hidden file viewing. Run this in elevated Command Prompt to reset it:
Then restart File Explorer (reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v Hidden /t REG_DWORD /d 1 /f reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v ShowSuperHidden /t REG_DWORD /d 1 /ftaskkill /f /im explorer.exe && start explorer.exe) and check again.
Step 2: Find Associated .dll Files for the PID
To see which .dlls the process is loading, you'll need a more powerful tool than Task Manager:
- Process Explorer: Grab this from Microsoft's Sysinternals suite (free and official). Once launched:
- Find the target PID in the process list (use the "Find" menu → "Find Process by PID" to speed this up).
- Right-click the process → Properties → navigate to the Modules tab.
- This tab lists every .dll and executable loaded by the process, along with their full file paths.
- Command Line Alternative: If you prefer CLI, run this in elevated Command Prompt:
Replacetasklist /m /fi "PID eq [YOUR_TARGET_PID]"[YOUR_TARGET_PID]with the actual PID of the process. This outputs loaded modules, though it's less detailed than Process Explorer.
Step 3: Block the Process from Starting Up
Once you've identified the files, here's how to stop it from running again:
- Terminate the Process: First, kill the rogue svchost.exe (and any child processes) using Process Explorer: right-click the process → Kill Process Tree. This is safer than Task Manager because it ensures all related processes are stopped.
- Delete the Hidden Executable: Use elevated Command Prompt to delete the file, since File Explorer might fail:
Thedel /f /a c:\windows\fonts\svchost.exe/fforces deletion,/atargets all attribute types. - Remove Startup Triggers: Check all possible launch points to prevent it from returning:
- Registry Startup Keys: Open
regeditand check these paths for entries referencing the fonts folder svchost.exe:HKLM\Software\Microsoft\Windows\CurrentVersion\RunHKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run(for 32-bit processes on 64-bit systems)HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Delete any suspicious entries you find.
- Task Scheduler: Open Task Scheduler and search for tasks that run the svchost.exe from
c:\windows\fonts. Delete any matching tasks. - Autoruns (Sysinternals): This tool is even better for finding hidden startup entries. Launch it, search for "fonts" or "svchost.exe", and disable/delete any suspicious entries it finds.
- Registry Startup Keys: Open
Step 4: Verify and Clean Up
- Run a full scan with Windows Defender (or your enterprise antivirus) to catch any remaining malicious components.
- Check the Modules list from Step 2 for any suspicious .dlls, and delete those as well using the same command line method if needed.
内容的提问来源于stack exchange,提问作者Bryan Raynolds
相关产品推荐
相关产品推荐

