Is a Windows process genuine? How to check any file in Task Manager

•Files•Ugnius Kiguolis

To check whether a process is genuine, open Task Manager, go to Details, right-click the process and choose Open file location: genuine Windows files live in C:\Windows or C:\Windows\System32 and are signed by Microsoft, while a copy with a Windows name in AppData, Temp or a random folder is an impostor. The signature, the hash and a Microsoft Defender scan settle the cases that the folder alone does not.

Why the name alone tells you nothing

Task Manager on a normal Windows 11 PC lists well over a hundred processes, many with names that mean nothing to most people: svchost.exe, RuntimeBroker.exe, dllhost.exe, conhost.exe. Almost all of them are legitimate parts of Windows or of programs you installed.

Malware knows this. One of the oldest ways to hide is to use the name of a Windows file, or one that differs by a single letter (scvhost.exe, svch0st.exe, lsasss.exe), so that it blends into the list. Another is to run code inside a genuine process, so that the busy process really is Windows but the work it does is not.

So the question is never "is svchost.exe a virus?" but "is this copy of svchost.exe the one Windows put there?" The checks below answer that in a few minutes, with tools built into Windows 11 and Windows 10.

Our pages about individual file names are grouped under the Files section; the ones linked to known malware also link to the full removal guide.

Step 1: find the file behind the process in Task Manager

  1. Press Ctrl + Shift + Esc to open Task Manager. If it opens in the small view, click More details.
  2. On Windows 11, choose Details in the left-hand menu. On Windows 10, click the Details tab at the top.
  3. Find the process by name. Click the Name column to sort alphabetically.
  4. Right-click it and choose Open file location. File Explorer opens the folder with the file selected.

The folder you land in is the most useful single fact. Write it down, along with the exact file name.

Two extra columns that help

In Details, right-click any column header, choose Select columns and tick Image path name and Command line. You can now see the full path and the command each process was started with, without opening each one. A powershell.exe with a long, unreadable command line containing -enc or -EncodedCommand, or an mshta.exe pointing at a web address, deserves a scan.

On the Processes page you can add a Publisher column the same way. A blank publisher is not proof of malware, but it narrows down what to check.

Processes that have no file location

Some entries are not ordinary programs and Open file location is greyed out or does nothing: System, System Idle Process, Registry, Memory Compression, Secure System and System interrupts. These are parts of the Windows kernel and memory management. That is normal and not a sign of hiding.

For a few protected processes, such as Microsoft Defender's MsMpEng.exe, Task Manager may show Access denied when you try to look further. That is also normal: Windows protects them from tampering.

Step 2: compare the folder with where the genuine file lives

Windows keeps its own programs in a small number of places. The table of common cases:

  • svchost.exe, lsass.exe, csrss.exe, smss.exe, services.exe, wininit.exe, winlogon.exe, dwm.exe, taskhostw.exe, RuntimeBroker.exe, conhost.exe, dllhost.exe, rundll32.exe, SearchIndexer.exe, spoolsv.exe: C:\Windows\System32.
  • explorer.exe: C:\Windows.
  • powershell.exe: C:\Windows\System32\WindowsPowerShell\v1.0.
  • On 64-bit Windows, 32-bit versions of some tools (rundll32.exe, dllhost.exe, conhost.exe, powershell.exe) also exist in C:\Windows\SysWOW64. A copy there is normal.
  • Microsoft Defender's MsMpEng.exe and NisSrv.exe: C:\ProgramData\Microsoft\Windows Defender\Platform\ followed by a version-number folder, or C:\Program Files\Windows Defender on some PCs.
  • Store and built-in apps: C:\Program Files\WindowsApps (you cannot open this folder by default).
  • Edge: C:\Program Files (x86)\Microsoft\Edge\Application. Chrome: C:\Program Files\Google\Chrome\Application. Firefox: C:\Program Files\Mozilla Firefox.

Where impostors hide

A file with a Windows name in any of these folders is not part of Windows:

  • %AppData% (C:\Users\<you>\AppData\Roaming) and %LocalAppData% (...\AppData\Local);
  • %Temp% (...\AppData\Local\Temp) and C:\Windows\Temp;
  • C:\Users\Public, C:\ProgramData with a random folder name, the Downloads folder or the desktop;
  • C:\Windows itself for files that belong in System32 (for example C:\Windows\svchost.exe), or a folder whose name imitates a real one, such as C:\Windows\System32\drivers\svchost.exe or C:\Windows\Sys32.

Do not treat AppData as suspicious in general. Many legitimate programs install there for the current user, including OneDrive, Teams, Zoom, Discord and per-user installs of Chrome. The warning sign is a mismatch: a Windows name in a user folder, or a program you do not recognise with a random name in one.

How many copies are normal

Several copies of svchost.exe, RuntimeBroker.exe, dllhost.exe, conhost.exe and browser processes are normal; Windows and browsers split work into many processes. csrss.exe and winlogon.exe appear once per signed-in session. There should be only one lsass.exe, one services.exe and one wininit.exe. A second copy of any of those three, wherever it is, needs a scan.

Step 3: check the digital signature and file details

A digital signature proves who published a file and that it has not been changed since. In File Explorer, right-click the file, choose Properties and look at two tabs.

  • Digital Signatures: the signer should be the company you expect, such as Microsoft Windows or Microsoft Corporation for Windows files, or the program's publisher. Select the signature and click Details; the window should say This digital signature is OK.
  • Details: File description, Product name and Copyright should match the program. A file called svchost.exe whose product name is empty or names an unknown company is not the Windows file.

When there is no Digital Signatures tab

Many genuine Windows files do not show a Digital Signatures tab at all. They are signed through a catalog, a separate signed list of Windows files, rather than inside the file itself. A missing tab on a file in C:\Windows\System32 therefore does not mean it is fake.

To check catalog signatures, Microsoft's free Sysinternals tool Sigcheck reports whether a file is signed, by whom and whether the signature is valid, including catalog-signed Windows files. Microsoft's own advice for Sigcheck is to investigate any file in a system folder that is not signed. Process Explorer, another Sysinternals tool, can show the verified signer of every running process at once.

A valid signature from an unknown company is not a clean bill of health either. Some unwanted programs and even malware are signed with real certificates. The signature tells you who made the file; you still decide whether you want it.

Step 4: check the hash and scan the file

A hash is a fingerprint of the file's content. Two files with the same SHA-256 hash are identical, whatever they are called.

To get it, open Terminal (right-click the Start button > Terminal) and type Get-FileHash followed by the full path in quotes, for example Get-FileHash "C:\Users\you\AppData\Roaming\svchost.exe". PowerShell shows the SHA-256 hash by default. These are commands you type yourself from Microsoft's documentation; never run commands a website or a stranger tells you to paste.

Then search for the hash on a multi-engine scanner such as VirusTotal. Searching a hash does not upload anything. If the file is known, you see what dozens of antivirus engines call it. If it is unknown, that alone is suspicious for a file with a Windows name. Do not upload files that may contain personal data; uploaded files can be shared with security researchers.

Comparing a hash with the same file on another PC only works if both PCs run exactly the same Windows version and updates, because Microsoft changes system files with updates.

Finally, right-click the file and choose Scan with Microsoft Defender (on Windows 11, it may be under Show more options). If the file is in use, a full scan or an offline scan checks it more thoroughly: Run a Microsoft Defender Offline scan.

If a genuine Windows file seems damaged: SFC and DISM

Sometimes the file is in the right place, but errors, crashes or an antivirus warning suggest it was changed or damaged. Windows has two built-in tools that check every protected system file against a clean copy and replace anything that does not match.

  1. Right-click the Start button and choose Terminal (Admin), then Yes. (On Windows 10, choose Windows PowerShell (Admin).)
  2. Type DISM.exe /Online /Cleanup-Image /RestoreHealth and press Enter. This repairs the store of clean copies that the next step uses, downloading what it needs through Windows Update. It can take a while.
  3. Type sfc /scannow and press Enter. Do not close the window until the check reaches 100%.

If SFC reports Windows Resource Protection did not find any integrity violations, the protected Windows files are original. If it found and repaired corrupt files, restart the PC. If it could not repair some files, Microsoft suggests running it again from Safe Mode: Start Windows or a Mac in Safe Mode On uGetFix.

SFC only checks Windows' own protected files. It does not look for malware, does not remove impostors in other folders and does not check programs from other companies. Run it after a malware clean-up, not instead of one.

What to do with what you found

  • Right folder, valid Microsoft signature, no detections: it is the genuine file. Do not delete it. If it uses a lot of CPU or memory, the cause is the work it is doing, usually for a Windows service or another program; for svchost.exe, right-click it in Details and choose Go to service(s) to see which service.
  • A program you installed, signed by its publisher: keep it, or uninstall the whole program in Settings > Apps > Installed apps if you do not want it: Uninstall a program or app in Windows On uGetFix. Deleting one file breaks a program without removing it.
  • A Windows name in the wrong folder, unsigned or detected by antivirus: do not just delete the file. Search our site for the file name to find the threat it belongs to, end the process, run a full and an offline scan, and remove its startup entries: Stop apps from opening at startup On uGetFix. Then follow the removal guide for that threat.
  • A leftover from a program you already removed: end the process, delete the folder, and remove the matching scheduled task or startup entry. See potentially unwanted programs.
  • Not sure: leave it, run a full scan with Windows Security, and check again after the scan. A few days of waiting does no harm; deleting the wrong system file can.

If an impostor was a stealer or remote access trojan, cleaning the PC is only half the job. Change your passwords from a clean device: securing your accounts after malware.

When the antivirus flags a genuine file

False positives happen, usually right after a definition update or with less common programs. A detection on a file that sits in the right folder, carries a valid signature from the expected publisher and has a hash that most engines consider clean is a candidate.

Update the antivirus definitions and scan again; vendors fix false positives quickly. You can also submit the file to Microsoft through the Microsoft Security Intelligence submission portal so that an analyst reviews it.

Do not restore a quarantined file until you are sure. If the file is in AppData, Temp or another user folder, carries no signature, or is flagged by many engines with malware names, trust the detection. Why one file gets so many different names: why antivirus programs give one threat different names.

Common myths about Windows processes

  • "Many svchost.exe processes means a virus." Windows runs many services, each group in its own svchost.exe. Dozens are normal.
  • "A process I do not recognise should be ended." Ending Windows processes such as csrss.exe or wininit.exe can crash the PC at once. Check before ending anything.
  • "No Digital Signatures tab means it is fake." Many Windows files are catalog-signed and show no tab. Use Sigcheck, or rely on the folder and a scan.
  • "Files in AppData are malware." Many legitimate apps install there. A Windows file name in AppData is the warning sign, not AppData itself.
  • "High CPU means the process is fake." Genuine processes use a lot of CPU when they work for something else. Find out what, before deciding.
  • "Deleting the file fixes it." Malware usually has a startup entry or task that brings it back, and Windows protects its own files. Use the removal steps instead.

Frequently asked questions

How do I know if a process in Task Manager is a virus?

Open Task Manager with Ctrl + Shift + Esc, go to Details, right-click the process and choose Open file location. If a Windows file name such as svchost.exe opens in C:\Windows\System32 and Properties shows a valid Microsoft signature (or no signature tab, which is normal for many Windows files), it is genuine. If it opens in AppData, Temp, ProgramData with a random folder, the Downloads folder or another odd place, or has no publisher, it is suspicious. Scan the file with Microsoft Defender and search its hash on a multi-engine scanner. A name misspelt by one letter is almost always malware.

Where should svchost.exe be located?

The genuine svchost.exe is in C:\Windows\System32 and is part of Windows. It hosts Windows services, so dozens of copies in Task Manager are normal, and all of them should open to that folder. A file named svchost.exe anywhere else, such as AppData, Temp, C:\Windows directly or a folder named like System32, is not Windows. Names with a swapped or extra letter, such as scvhost.exe or svch0st.exe, are impostors too. To see which services a genuine copy runs, right-click it in Details and choose Go to service(s); a busy copy usually points to Windows Update, search indexing or another service.

Can malware use the same name as a Windows process?

Yes, and it often does, because a familiar name is easy to overlook in Task Manager. It may copy the name exactly and sit in another folder, change one letter, or run its code inside a genuine Windows process so that the busy process really is Windows. The first two are easy to catch with Open file location and the file's signature. The third needs a scan: run a full scan and a Microsoft Defender offline scan, which checks memory and startup locations before Windows loads. Unusual command lines in Task Manager's Command line column are another clue.

Why is there no Digital Signatures tab on a Windows file?

Because many Windows system files are signed through a catalog instead of inside the file. A catalog is a separate, signed list of the files that belong to Windows, and Windows checks each file against it. The Properties window only shows signatures embedded in the file, so catalog-signed files show no Digital Signatures tab even though they are genuine. Microsoft's free Sysinternals tool Sigcheck verifies catalog signatures and reports the signer. For a file in C:\Windows\System32 with a correct description in the Details tab, a missing tab is not a reason for concern on its own.

Can I delete a suspicious process file?

Only after you have checked it, and usually not by hand. If the file is genuine Windows, deleting it can break features; Windows protects such files and restores them anyway. If it belongs to a program, uninstall the program instead. If it is an impostor, end the process and run a full and an offline scan, which remove the file together with its startup entries and scheduled tasks; deleting only the file often lets a task bring it back. Then follow the removal guide for the threat it belongs to, and change passwords if it was a stealer.

What does sfc /scannow do, and does it remove viruses?

System File Checker compares every protected Windows file with a clean copy kept by Windows and replaces files that are missing, damaged or changed. Microsoft recommends running DISM with /RestoreHealth first, so the clean copies are themselves correct, then sfc /scannow from an administrator Terminal. It is useful after a malware infection that damaged Windows files. It does not scan for malware, does not remove impostors in other folders and does not touch programs from other companies, so use it together with a Microsoft Defender full and offline scan, not instead of them.

My antivirus flagged a Windows file. Is it a false positive?

It may be, if the file is in its normal Windows folder, has a valid Microsoft signature or is catalog-signed, and its hash is known as clean on multi-engine scanners. Update the antivirus definitions and scan again; vendors correct false positives quickly. You can submit the file to Microsoft through the Microsoft Security Intelligence submission portal for review. If the flagged file is in AppData, Temp or another user folder, has no signature, or is detected by many engines with malware names, trust the detection and follow the removal steps. Do not restore a quarantined file until you are sure.

About the author

Ugnius Kiguolis, Owner and editor of 2-spyware.com. Ugnius Kiguolis owns and edits 2-spyware.com and is responsible for its Windows security guides. Every page he signs is checked against current vendor, law-enforcement and Microsoft sources before it is published and again when the facts change.

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year