{"id":4473,"date":"2017-12-07T23:44:54","date_gmt":"2017-12-07T23:44:54","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=4473"},"modified":"2017-12-07T23:56:21","modified_gmt":"2017-12-07T23:56:21","slug":"svchost-exe-explorer-exe-on-win10","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2017\/12\/07\/svchost-exe-explorer-exe-on-win10\/","title":{"rendered":"svchost.exe -> explorer.exe on win10"},"content":{"rendered":"<p>When Windows Explorer is killed on Win 10, and then manually relaunched with an elevated account, it is actually re-launched by svchost.exe 5 seconds later via a temporary task C:\\Windows\\Tasks\\CreateExplorerShellUnelevatedTask.job &#8211; see below; so, if you see explorer.exe under svchost.exe it doesn&#8217;t necessary mean malware.<\/p>\n<p>There is additional information in <a href=\"https:\/\/www.tenforums.com\/general-support\/79917-whats-createexplorershellunelevatedtask.html\">this thread<\/a> that mentions this is a mechanism to prevent spawning an elevated Explorer process.<\/p>\n<pre>&lt;?xml version=\"1.0\" encoding=\"UTF-16\"?&gt;\r\n&lt;Task version=\"1.3\" xmlns=\"http:\/\/schemas.microsoft.com\/windows\/2004\/02\/mit\/task\"&gt;\r\n\u00a0 &lt;RegistrationInfo&gt;\r\n\u00a0\u00a0\u00a0 &lt;Author&gt;ExplorerShellUnelevated&lt;\/Author&gt;\r\n\u00a0\u00a0\u00a0 &lt;URI&gt;\\CreateExplorerShellUnelevatedTask&lt;\/URI&gt;\r\n\u00a0 &lt;\/RegistrationInfo&gt;\r\n\u00a0 &lt;Triggers&gt;\r\n\u00a0\u00a0\u00a0 &lt;RegistrationTrigger id=\"CreateExplorerShell_Trigger\"&gt;\r\n\u00a0\u00a0\u00a0\u00a0\u00a0 &lt;Enabled&gt;true&lt;\/Enabled&gt;\r\n\u00a0\u00a0\u00a0\u00a0\u00a0 &lt;Delay&gt;PT0S&lt;\/Delay&gt;\r\n\u00a0\u00a0\u00a0 &lt;\/RegistrationTrigger&gt;\r\n\u00a0 &lt;\/Triggers&gt;\r\n\u00a0 &lt;Settings&gt;\r\n\u00a0\u00a0\u00a0 &lt;MultipleInstancesPolicy&gt;IgnoreNew&lt;\/MultipleInstancesPolicy&gt;\r\n\u00a0\u00a0\u00a0 &lt;DisallowStartIfOnBatteries&gt;false&lt;\/DisallowStartIfOnBatteries&gt;\r\n\u00a0\u00a0\u00a0 &lt;StopIfGoingOnBatteries&gt;false&lt;\/StopIfGoingOnBatteries&gt;\r\n\u00a0\u00a0\u00a0 &lt;AllowHardTerminate&gt;true&lt;\/AllowHardTerminate&gt;\r\n\u00a0\u00a0\u00a0 &lt;StartWhenAvailable&gt;true&lt;\/StartWhenAvailable&gt;\r\n\u00a0\u00a0\u00a0 &lt;RunOnlyIfNetworkAvailable&gt;false&lt;\/RunOnlyIfNetworkAvailable&gt;\r\n\u00a0\u00a0\u00a0 &lt;IdleSettings&gt;\r\n\u00a0\u00a0\u00a0\u00a0\u00a0 &lt;Duration&gt;PT10M&lt;\/Duration&gt;\r\n\u00a0\u00a0\u00a0\u00a0\u00a0 &lt;WaitTimeout&gt;PT1H&lt;\/WaitTimeout&gt;\r\n\u00a0\u00a0\u00a0\u00a0\u00a0 &lt;StopOnIdleEnd&gt;true&lt;\/StopOnIdleEnd&gt;\r\n\u00a0\u00a0\u00a0\u00a0\u00a0 &lt;RestartOnIdle&gt;false&lt;\/RestartOnIdle&gt;\r\n\u00a0\u00a0\u00a0 &lt;\/IdleSettings&gt;\r\n\u00a0\u00a0\u00a0 &lt;AllowStartOnDemand&gt;true&lt;\/AllowStartOnDemand&gt;\r\n\u00a0\u00a0\u00a0 &lt;Enabled&gt;true&lt;\/Enabled&gt;\r\n\u00a0\u00a0\u00a0 &lt;Hidden&gt;false&lt;\/Hidden&gt;\r\n\u00a0\u00a0\u00a0 &lt;RunOnlyIfIdle&gt;false&lt;\/RunOnlyIfIdle&gt;\r\n\u00a0\u00a0\u00a0 &lt;DisallowStartOnRemoteAppSession&gt;false&lt;\/DisallowStartOnRemoteAppSession&gt;\r\n\u00a0\u00a0\u00a0 &lt;UseUnifiedSchedulingEngine&gt;true&lt;\/UseUnifiedSchedulingEngine&gt;\r\n\u00a0\u00a0\u00a0 &lt;WakeToRun&gt;false&lt;\/WakeToRun&gt;\r\n\u00a0\u00a0\u00a0 &lt;ExecutionTimeLimit&gt;PT72H&lt;\/ExecutionTimeLimit&gt;\r\n\u00a0\u00a0\u00a0 &lt;Priority&gt;6&lt;\/Priority&gt;\r\n\u00a0 &lt;\/Settings&gt;\r\n\u00a0 &lt;Actions Context=\"Author\"&gt;\r\n\u00a0\u00a0\u00a0 &lt;Exec&gt;\r\n\u00a0\u00a0\u00a0\u00a0\u00a0 &lt;Command&gt;C:\\Windows\\explorer.exe&lt;\/Command&gt;\r\n\u00a0\u00a0\u00a0\u00a0\u00a0 &lt;Arguments&gt;\/NOUACCHECK&lt;\/Arguments&gt;\r\n\u00a0\u00a0\u00a0 &lt;\/Exec&gt;\r\n\u00a0 &lt;\/Actions&gt;\r\n\u00a0 &lt;Principals&gt;\r\n\u00a0\u00a0\u00a0 &lt;Principal id=\"Author\"&gt;\r\n\u00a0\u00a0\u00a0\u00a0\u00a0 &lt;UserId&gt;xxxxxxxxxx\\user&lt;\/UserId&gt;\r\n\u00a0\u00a0\u00a0\u00a0\u00a0 &lt;LogonType&gt;InteractiveToken&lt;\/LogonType&gt;\r\n\u00a0\u00a0\u00a0\u00a0\u00a0 &lt;RunLevel&gt;LeastPrivilege&lt;\/RunLevel&gt;\r\n\u00a0\u00a0\u00a0 &lt;\/Principal&gt;\r\n\u00a0 &lt;\/Principals&gt;\r\n&lt;\/Task&gt;<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>When Windows Explorer is killed on Win 10, and then manually relaunched with an elevated account, it is actually re-launched by svchost.exe 5 seconds later via a temporary task C:\\Windows\\Tasks\\CreateExplorerShellUnelevatedTask.job &#8211; see below; so, if you see explorer.exe under svchost.exe &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2017\/12\/07\/svchost-exe-explorer-exe-on-win10\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[19,46,9],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/4473"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=4473"}],"version-history":[{"count":4,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/4473\/revisions"}],"predecessor-version":[{"id":4478,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/4473\/revisions\/4478"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=4473"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=4473"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=4473"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}