Windows 11 · Processes

SearchHost.exe in Windows 11: What It Is, and Is It a Virus?

By , Editor · · Windows 11 · Processes
The short answer

SearchHost.exe is the Windows 11 search process — the thing that draws the box when you press the Start button and type. Microsoft names it directly in its own Windows Search troubleshooting article, as the Windows 11 replacement for Windows 10’s SearchUI.exe. If Task Manager shows it as Suspended, that is the correct resting state and not a fault. And be careful with the malware test everyone recommends: checking the Digital Signatures tab does not work on this file, and a missing tab does not mean you are infected.

What SearchHost.exe actually is

SearchHost.exe is the user interface for Windows 11 search. When you press the Start button and start typing, or click the search box on the taskbar, this is the process that draws the panel, runs the query and shows you the results.

You do not have to take our word for that. Microsoft names it explicitly in its Fix problems in Windows Search article, in the instructions for restarting search:

“Follow these steps to end the SearchUI.exe (Windows 10) or SearchHost.exe (Windows 11) process. Stopping this process stops Windows Search. The next time that you search, Windows Search automatically starts.”

So SearchHost.exe on Windows 11 is the direct successor to SearchUI.exe on Windows 10. The genuine copy lives here:

C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchHost.exe
Read that folder name carefully

It is MicrosoftWindows.Client.CBS — no dot between Microsoft and Windows, but dots before Client and CBS. A lot of pages get this wrong and write Microsoft.Windows.Client.CBS, which does not exist. The _cw5n1h2txyewy suffix is a publisher hash shared by Microsoft’s built-in system apps, so seeing it is reassuring rather than suspicious.

Microsoft documents that folder in the same article, as the install location of the Windows 11 search package, and gives a command that re-registers the package from the Appxmanifest.xml inside it. That detail matters more than it looks, and it explains almost everything else on this page: because the package is registered from a manifest, SearchHost.exe is a packaged app — the app model Microsoft used to call UWP — and not a classic Windows program or a service.

One thing we could not establish: what CBS stands for in that package name. It is not Component-Based Servicing, which is a different part of Windows entirely (the one that writes CBS.log). Rather than guess, we are leaving it unexplained.

Why it shows as “Suspended” — and why that is correct

This is the single most common reason people go looking for SearchHost.exe, and the answer is reassuring: suspended is the state it is supposed to be in most of the time.

Because it is a packaged app, it follows the app lifecycle Microsoft documents for that model:

“By default, apps that are not in the foreground are suspended. This results in power savings and more resources available for the app currently in the foreground.”

And from the same app lifecycle documentation, on what suspension actually does: the app’s threads are stopped and the app is left in memory unless the operating system needs to reclaim resources, so that switching back to it restores it quickly. Suspended does not mean crashed, stuck, or idling wastefully. It means parked.

Why it is suspended even though you never opened search

Windows does not wait for you. Microsoft documents that where a device has resources to spare, the operating system will prelaunch frequently used apps that have opted into the behaviour, starting them in the background and then quickly suspending them so they resume faster when you do reach for them.

That is the documented mechanism behind a suspended SearchHost.exe appearing moments after you sign in. We should be precise about the limits of that, though: Microsoft documents prelaunch in general, but does not publish a list naming SearchHost.exe as one of the apps it applies to. The mechanism is documented; the specific attribution is our inference.

On Microsoft’s Q&A forum, a community answerer put the practical version plainly — the process runs whenever you open the search box, and should remain suspended once the search window is closed. That is a community observation rather than documentation, but it matches both the lifecycle docs and what you can watch happen in Task Manager.

About that green leaf

The leaf icon beside the process in Task Manager marks it as suspended. Be careful with advice that treats it as the same thing as Efficiency mode, which is a separate Windows 11 feature with its own double-leaf indicator. Community write-ups conflate the two constantly. They are not the same and they do not mean the same thing.

Is it a virus? The standard test gives a false positive here

Malware does sometimes name itself after a real Windows process, so the question is fair. The useful check is location: the genuine file runs from the SystemApps folder shown above. Something calling itself SearchHost.exe and running from your Downloads folder, a temp directory or a user profile folder is worth investigating.

Now the part most articles get wrong, and get wrong in a way that frightens people unnecessarily.

Do not use the Digital Signatures tab to judge this file

The usual advice — right-click the file, open Properties, look for a Digital Signatures tab, and treat a missing tab as proof of malware — does not work on SearchHost.exe. On Microsoft’s Q&A forum a Microsoft Community Support Specialist gave that advice, checked it, and then retracted it: “SearchHost.exe does not contain digital signature information, which is why verifying the program’s digital signature wouldn’t apply in this case.” The same reply also withdrew an earlier suggestion that the file lives in System32 — it does not. Follow the Properties-tab test and you can conclude that a perfectly healthy Windows installation is infected.

The evidence here is genuinely mixed, and we would rather show you that than pretend otherwise: a third-party file-metadata database reports the opposite result for its sample, listing the signature as verified and issued to Microsoft Windows. The likely reconciliation is catalog signing — Windows can sign a file through a separate catalog file holding cryptographic hashes, instead of embedding a signature blob in the executable. A catalog-signed file shows no Digital Signatures tab yet is entirely genuine. We could not find a Microsoft page stating that SearchHost.exe specifically is signed that way, so treat that as the probable explanation rather than a confirmed one.

What to check instead

PowerShell reads catalog signatures as well as embedded ones, so it gives a straight answer where the Properties dialog does not:

Get-AuthenticodeSignature "C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchHost.exe"

Sysinternals Sigcheck, which Microsoft publishes, is the other good option, and prints a Catalog: line when the signature is external:

sigcheck.exe -v "C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchHost.exe"

If you are still unsure after that, run a full scan with Windows Security rather than trying to judge the file by eye. Two things that are not useful signals: the file’s size, which is build-dependent and will generate false alarms if you compare it against a number from a process database, and the number of copies on disk.

Several copies is normal

People find three copies, or seven, and reasonably assume something is wrong. It is not. Alongside the live copy, Windows keeps additional copies under C:\Windows\WinSxS, the side-by-side store that holds multiple versions of system files so updates can be rolled back and damaged components repaired. A Microsoft support specialist confirmed that finding extra copies there is unremarkable. Those folder names carry build numbers, so they differ on every machine — there is no “correct” list to compare yours against.

When SearchHost.exe is missing from Task Manager

The honest answer is that Microsoft does not document what absence means, so anyone stating confidently that it proves an infection is guessing. Two explanations are realistic:

  1. Search simply is not running. By far the most likely, and not a fault — the process starts when you search. Press Start, type something, and look again.
  2. The package has been removed. Debloat scripts and “privacy” tools sometimes strip the Windows 11 client package, and the process cannot run if the package is gone.

If search itself is broken as well as the process being absent, skip the file hunt and go to the repair ladder below. Re-registering the package is the fix; looking for a deleted executable is not.

High CPU, high memory, or search running hot

The first thing to establish is which process is actually busy, because the one people blame is usually not the one doing the work. SearchHost.exe draws the interface. The heavy lifting — walking your disk and building the index — belongs to SearchIndexer.exe, and that is normally what you see consuming CPU and disk after a large file copy, a fresh install, or an index rebuild. In that situation the correct response is usually to leave it alone until it finishes.

If SearchHost.exe itself is persistently busy rather than suspended, work through the repair ladder in order — and if the machine is sluggish generally rather than only during search, our guide to speeding up Windows 11 is the better starting point. If the indexer is the busy one, our guide to fixing Windows 11 search when it stops working covers narrowing the indexed locations, which is the setting that actually reduces the workload.

Restarting and repairing search, in the order to try it

1. End the process

Microsoft documents this as a supported repair step, and it is completely safe — Windows starts search again automatically the next time you use it. Microsoft’s steps: press Ctrl+Alt+Delete and open Task Manager, go to Details, right-click SearchHost.exe, choose End task, and confirm with End process.

2. Run the built-in troubleshooter

Windows ships a Search and Indexing troubleshooter, and running it costs nothing. Microsoft lists it ahead of the heavier repairs for good reason. If File Explorer is misbehaving alongside search, the shell as a whole may be the problem — see resetting File Explorer.

3. Repair the system files behind it

Run these from a terminal opened as administrator, in this order. DISM repairs the component store that sfc draws its known-good copies from, so running sfc first against a damaged store achieves less:

DISM.exe /Online /Cleanup-Image /RestoreHealth
sfc /scannow

4. Re-register the search package

This is Microsoft’s documented command for Windows 11, run from an elevated PowerShell window. Note the capitalisation of Appxmanifest.xml — it is Microsoft’s own:

Add-AppxPackage -Path "C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Appxmanifest.xml" -DisableDevelopmentMode -Register
Do not use the Windows 10 package name here

Plenty of pages tell Windows 11 users to re-register Microsoft.Windows.Search_cw5n1h2txyewy. That is the Windows 10 package. On Windows 11 the path does not exist, and following that advice means registering a package that is not there and deleting an AppData folder that never existed. Microsoft documents the two branches separately, and the Windows 11 one is the MicrosoftWindows.Client.CBS path above.

We are also deliberately not printing the piped one-liner that circulates for this job. As usually written it is not valid — -Register needs a -Path pointing at a manifest — and we could not verify a working form of it in Microsoft’s documentation. Use the explicit -Path command above.

SearchHost, SearchIndexer, SearchProtocolHost, SearchApp

Four similarly named processes doing genuinely different jobs. Knowing which is which saves you troubleshooting the wrong one.

ProcessWhat it does
SearchHost.exeThe Windows 11 search interface — the panel you type into. Microsoft names it as the successor to Windows 10’s SearchUI.exe. Normally suspended.
SearchIndexer.exeThe indexing engine, running under the Windows Search service. This is what reads your files and builds the index, and what legitimately uses CPU and disk while it catches up.
SearchProtocolHost.exeA helper the indexer starts to reach particular content types and locations. Appears and disappears while indexing is under way.
SearchApp.exeThe name used by the search interface on earlier Windows 11 builds and in some update states. If you see this instead of SearchHost.exe, you are looking at the same job under an older name.

If your problem is that search returns nothing rather than that a process looks odd, the indexer is where to start — see how to fix Windows 11 search when it stops working.

Frequently asked

Why is SearchHost.exe suspended in Task Manager?

Because that is what is supposed to happen. SearchHost.exe is a packaged app rather than a traditional Windows program, and Microsoft documents that apps which are not in the foreground get suspended: their threads are stopped, but the app stays in memory so it can resume instantly. Windows also prelaunches frequently used apps in the background and immediately suspends them, which is why you can see SearchHost.exe sitting suspended straight after you sign in, even if you have not opened search yet. The green leaf beside it in Task Manager is the suspended indicator.

Is SearchHost.exe a virus?

On its own, the name is not evidence either way. The genuine file lives in C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy and a copy running from anywhere else deserves a hard look. What you should not rely on is the Digital Signatures tab in file Properties. A Microsoft support specialist checked this and confirmed that SearchHost.exe does not carry embedded signature information, so the tab can be missing on a completely healthy machine. Use Get-AuthenticodeSignature in PowerShell instead, which also reads catalog signatures.

Can I disable or delete SearchHost.exe?

You should not. It is part of a Windows system app package, it cannot be uninstalled the way an ordinary app can, and removing it takes Start menu search with it. Ending the process is safe and sometimes useful, because Microsoft documents that as a repair step and Windows restarts it automatically the next time you search, but that is different from deleting it. If a debloat script has already removed the package, the repair is to re-register it rather than to hunt for the file.

Why do I have several copies of SearchHost.exe on my PC?

That is normal. Alongside the live copy in SystemApps, Windows keeps additional copies under the WinSxS folder, which stores multiple versions of system files so that updates can be rolled back and components repaired. A Microsoft support specialist confirmed that finding extra copies under WinSxS is expected. The number and the exact folder names differ from machine to machine because they carry build numbers, so there is no correct count to compare against.

SearchHost.exe is missing from Task Manager. What does that mean?

Most often it simply means search is not running at that moment, which is normal, because the process starts when you search. Microsoft does not document what absence signifies, so anyone telling you it definitely means infection is guessing. The two realistic explanations are that search has not been invoked yet, or that a debloat script or cleanup tool has removed the package. Try searching first. If nothing appears and search itself is broken, re-register the package using the documented command.

Where this came from

Written 25 August 2026. Every path, command and package name on this page was verified against Microsoft’s own documentation, then re-checked by a second pass whose job was to reject anything only one source supported. Two widely repeated claims did not survive that and are deliberately absent: that a missing Digital Signatures tab proves the file is malicious, and that SearchHost.exe lives in System32. A Microsoft support specialist publicly retracted both. Where we rely on a community answer rather than documentation, the page says so on the line where it matters.