svchost.exe (netsvcs): What It Is and How to Fix High CPU, Memory or Network Use

Performance graphs on a screen, like the CPU and memory charts used to check svchost.exe (netsvcs) usage

Quick answer: svchost.exe (netsvcs) is a genuine Windows process. It’s a Service Host that runs a group of system services called netsvcs, including Windows Update, Background Intelligent Transfer Service (BITS), Task Scheduler and Windows Management Instrumentation. Short bursts of high CPU, memory or network use are normal, especially while updates download. If the usage stays high, find which service is busy in Task Manager, then let Windows Update finish or reset it, restart that service, scan for malware and repair system files.

Applies to: Windows 11 and Windows 10, when Task Manager shows svchost.exe -k netsvcs or a Service Host process using a lot of CPU, memory, disk or network.

Performance graphs on a screen, like the CPU and memory charts used to check svchost.exe (netsvcs) usage

What svchost.exe (netsvcs) is

Many Windows services aren’t separate programs. They’re DLL files that need a host process to run, and svchost.exe (Service Host) is that host. Windows sorts these services into groups, and the -k part of the command line names the group. You’ll see something like this:

C:\Windows\system32\svchost.exe -k netsvcs -p

netsvcs is one of the largest groups. Despite the name, it isn’t only about networking. Depending on your Windows version, it can include:

ServiceWhat it does
Windows Update (wuauserv)Checks for, downloads and installs updates
Background Intelligent Transfer Service (BITS)Downloads files in the background for Windows Update and other apps
Task Scheduler (Schedule)Runs scheduled tasks such as maintenance and app updaters
Windows Management Instrumentation (Winmgmt)Lets apps and scripts query system information
Group Policy Client (gpsvc)Applies policy settings, mostly on work PCs
ThemesManages the desktop theme

On PCs with more than 3.5 GB of RAM, Windows 10 version 1703 and later run most of these services in their own svchost process, so Task Manager shows one Service Host entry per service and the command line ends with -s and the service name. On PCs with less memory, several services still share one process, which makes it harder to tell which one is busy.

Is it safe, or a virus?

The real svchost.exe lives in C:\Windows\System32 (64-bit Windows also has a copy in C:\Windows\SysWOW64). Malware sometimes uses the same name to hide. To check:

  1. Open Task Manager with Ctrl + Shift + Esc and go to the Details tab.
  2. Right-click the svchost.exe process and select Open file location.
  3. If the folder is anything other than System32 or SysWOW64, or the name is slightly different (for example svhost.exe or scvhost.exe), treat it as suspicious and scan the PC for malware.

A genuine svchost.exe also runs under the SYSTEM, LOCAL SERVICE or NETWORK SERVICE account, not your own user name. The netsvcs group runs as SYSTEM.

Find the service that’s using resources

Screen full of process data, representing the tasklist and Task Manager views that show which service runs in svchost.exe

Fixing high usage starts with knowing which service is responsible. Use any of these:

  • Task Manager, Processes tab: sort by CPU, Memory or Network. Expand the busy Service Host entry; the services inside it are listed underneath, for example Service Host: Windows Update.
  • Task Manager, Details tab: right-click the busy svchost.exe and select Go to service(s). The services in that process are highlighted on the Services tab. To see the group, right-click a column header, choose Select columns and add Command line.
  • Command Prompt: the command below lists every svchost process with its PID and the services it hosts. Match the PID to the one in Task Manager.
  • Resource Monitor: press Win + R, type resmon and check the CPU and Network tabs. They show live usage per process, and the Services list on the CPU tab shows which services are running inside each svchost PID.
tasklist /svc /fi "imagename eq svchost.exe"

Watch for a few minutes before acting. Windows often runs updates, indexing and maintenance in a burst right after start-up or after the PC has been idle, and the usage then drops on its own.

Fix 1: Let Windows Update finish, or reset it

Computer cooling fan close-up, a sign of high CPU use from a Service Host netsvcs process

Windows Update and BITS are the most common reasons netsvcs gets busy. They scan, download and unpack updates in the background, which can take a long time on a slow connection or an older PC.

  1. Go to Settings > Windows Update and see whether something is downloading or installing. If it is, leave the PC on and plugged in until it finishes, then restart.
  2. If the usage gets in the way right now, select Pause updates for a week. Resume it later, because updates include security fixes.
  3. If Windows Update is stuck at the same percentage or keeps failing, reset its cache: stop the wuauserv and bits services, rename C:\Windows\SoftwareDistribution, then start the services again. The step-by-step commands are in our Windows Update connection guide.

If the network use comes from Service Host: Delivery Optimization instead, Windows may be sharing update downloads with other PCs. On Windows 11, under Settings > Windows Update > Advanced options > Delivery Optimization you can turn off Allow downloads from other PCs, or limit the bandwidth it uses. On Windows 10, the same setting is under Settings > Update & Security > Delivery Optimization.

Fix 2: Restart the busy service

A service can get stuck in a loop and use CPU until it’s restarted. Restarting one service is safer than ending a whole svchost process:

  1. Press Win + R, type services.msc and press Enter.
  2. Find the service you identified, right-click it and select Restart.
  3. If the usage returns straight away, restart the PC, which restarts every service cleanly.

If the busy service is Windows Management Instrumentation, another program is usually querying it constantly. Check whether high usage starts when a particular app (often monitoring, RGB or vendor utility software) is open, and update or remove that app.

Fix 3: Scan for malware

Malware can run inside a genuine Service Host by installing itself as a service, or pretend to be svchost.exe. If the usage is high when the PC is idle, network traffic keeps flowing when nothing should be downloading, or you saw a suspicious file location above, run a full scan and a Microsoft Defender Offline scan. See how to scan for malware on Windows for the steps.

Fix 4: Repair Windows files

Damaged system files can make a service fail and retry over and over. Open Command Prompt as administrator and run:

DISM /Online /Cleanup-Image /RestoreHealth
sfc /scannow

Restart when both finish. If SFC reports that it couldn’t perform the operation, see Windows Resource Protection could not perform the requested operation.

Fix 5: Find a conflicting app with a clean boot

If the cause still isn’t clear, start Windows with only Microsoft services and no startup apps:

  1. Press Win + R, type msconfig and press Enter.
  2. On the Services tab, tick Hide all Microsoft services, then select Disable all.
  3. On the Startup tab, select Open Task Manager and disable each startup item.
  4. Restart and watch the Service Host usage. If it stays normal, turn the third-party services back on a few at a time to find the one that triggers it.

When you’re done, go back to msconfig, select Normal startup and restart.

What not to do

  • Don’t end a netsvcs svchost process in Task Manager. On PCs where several services share it, Windows can become unstable or restart. Restart the single service instead.
  • Don’t disable Windows Update, BITS or Task Scheduler permanently with registry tweaks or “debloat” tools. You’ll stop security updates, and Windows may turn some of them back on anyway.
  • Don’t download a “svchost fixer”. Windows already includes everything needed, and such tools are a common way malware spreads.

Official sources: for more detail, see Microsoft’s own documentation:

Frequently asked questions

What does -k netsvcs mean?

-k tells svchost.exe which service group to load, and netsvcs is the name of that group. The list of services in each group is stored in the registry under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost. The -p flag seen on newer versions applies extra security protections to the process.

Why are there so many svchost.exe processes?

On PCs with more than 3.5 GB of RAM, Windows runs most services in their own Service Host so that one failing service doesn’t take others down and it’s easier to see what uses resources. Dozens of svchost processes is normal.

How much memory should svchost.exe (netsvcs) use?

There’s no fixed figure. Most services use a few to a few tens of megabytes when idle, and Windows Update can briefly use several hundred while it scans for or installs updates. Hundreds of megabytes that keep growing over hours, even when updates aren’t running, point to a stuck service or an app that keeps querying it.

Can I delete svchost.exe?

No. The genuine file is part of Windows and is protected; Windows can’t start its services without it. Only remove a file with that name if it’s outside System32 or SysWOW64 and your antivirus flags it.

How we write our guides: read our editorial policy.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *