Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

14.0.7106.5000 15.82%
14.0.6117.5000 3.06%
14.0.6114.5003 78.06%
14.0.6009.1000 0.51%
14.0.4750.1000 2.55%

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
CopySid, RegOpenKeyExA, ConvertSidToStringSidA, IsValidSid, CheckTokenMembership, GetSecurityDescriptorDacl, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, InitializeAcl, AddAccessDeniedAce, AddAccessAllowedAce, GetLengthSid, TraceEvent, RegQueryValueExA, RegEnumKeyW, RegQueryInfoKeyA, RegEnumValueA, RegDeleteValueA, IsTextUnicode, OpenThreadToken, EqualSid, GetTokenInformation, CreateWellKnownSid, ConvertStringSecurityDescriptorToSecurityDescriptorW, AllocateAndInitializeSid, FreeSid, OpenProcessToken, DeregisterEventSource, RegisterEventSourceW, ReportEventW, RegEnumValueW, RegOpenKeyExW, RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, RegDeleteValueW, RegQueryInfoKeyW, RegCloseKey
comctl32.dll
ImageList_GetIconSize
cvhshared.dll
SendCmdLineToPrimaryInstance, RunCVHLauncher
dbghelp.dll
SymCleanup
gdi32.dll
DllMain
gdiplus.dll
GdiplusShutdown, GdipBitmapUnlockBits, GdipBitmapLockBits, GdipCreateBitmapFromHBITMAP, GdipCreateBitmapFromScan0, GdipCreateBitmapFromStreamICM, GdipCreateBitmapFromStream, GdipCreateBitmapFromFileICM, GdipDeletePen, GdipDrawImageRectRect, GdipGetImageGraphicsContext, GdipAlloc, GdipFree, GdipDisposeImage, GdipGetImageWidth, GdipGetImageHeight, GdipImageRotateFlip, GdipBitmapGetPixel, GdipCloneBitmapAreaI, GdipCloneImage, GdipCreateImageAttributes, GdipDisposeImageAttributes, GdipDeleteGraphics, GdipSetImageAttributesColorKeys, GdipCreateFromHDC, GdipDrawImageRectRectI, GdipGetImagePixelFormat, GdipCreateBitmapFromFile
imm32.dll
ImmAssociateContext
kernel32.dll
LoadLibraryExW, SetErrorMode, SystemTimeToTzSpecificLocalTime, GetSystemTime, GetTimeZoneInformation, GetCurrentDirectoryW, ExpandEnvironmentStringsW, GlobalFree, RaiseException, HeapFree, HeapAlloc, HeapReAlloc, LoadResource, SizeofResource, LockResource, LoadLibraryA, MulDiv, DeleteCriticalSection, EnterCriticalSection, InitializeCriticalSectionAndSpinCount, LeaveCriticalSection, IsValidLocale, LocalFree, GetDiskFreeSpaceExW, GetVersionExW, GetSystemDirectoryW, CloseHandle, OpenProcess, GetTempPathW, FindClose, FindFirstFileW, CompareFileTime, SetFilePointer, CreateFileW, WriteFile, lstrlenA, ReadFile, SetFilePointerEx, SetFileAttributesW, DeleteFileW, CopyFileW, GetCurrentThread, TlsFree, TlsAlloc, TlsSetValue, TlsGetValue, WaitForMultipleObjects, WaitForSingleObject, FindAtomW, GetStringTypeExW, GetAtomNameW, SetProcessWorkingSetSize, GlobalDeleteAtom, GlobalAddAtomW, InitializeCriticalSection, AddAtomW, DeleteAtom, GetFileSize, HeapCreate, HeapDestroy, GlobalLock, GlobalAlloc, FreeLibrary, InterlockedFlushSList, InterlockedPopEntrySList, InterlockedPushEntrySList, SetEvent, QueryDepthSList, CreateEventW, GetTimeFormatW, GetDateFormatW, FileTimeToSystemTime, SystemTimeToFileTime, IsWow64Process, VirtualAlloc, GlobalUnlock, GetUserDefaultLCID, GetCurrencyFormatW, GetNumberFormatW, GetVersionExA, GetLocaleInfoW, IsProcessorFeaturePresent, GetSystemDefaultLCID, GetSystemDefaultLangID, GetACP, VirtualFree, FindResourceA, GetProcessTimes, CreateEventA, CreateMutexA, OpenMutexA, CreateFileMappingA, GetShortPathNameA, GetModuleFileNameA, GetUserDefaultLangID, ReleaseMutex, UnmapViewOfFile, CreateProcessA, MapViewOfFile, DuplicateHandle, GetModuleHandleExW, RtlCaptureStackBackTrace, GetLocalTime, LocalAlloc, TryEnterCriticalSection, GetSystemInfo, IsDBCSLeadByte, IsValidCodePage, CreateDirectoryW, GetFileType, GlobalMemoryStatus, EnumUILanguagesW, EnumSystemLocalesW, GetCalendarInfoW, GetUserDefaultUILanguage, GetModuleFileNameW, SetLastError, LoadLibraryW, GetFileAttributesW, GetModuleHandleA, MultiByteToWideChar, CompareStringA, CompareStringW, GetLastError, WideCharToMultiByte, GetVersion, lstrlenW, FindResourceW, InitializeSListHead, WriteProcessMemory, lstrcmpiA, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetStartupInfoW, InterlockedCompareExchange, Sleep, InterlockedExchange, GetModuleHandleW, GetProcAddress, GetProcessHeap, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, VirtualProtect, OutputDebugStringA
msvcp90.dll
DllMain
msvcr90.dll
DllMain
ole32.dll
RevokeDragDrop, RegisterDragDrop, OleInitialize, OleUninitialize, OleDraw, CoLockObjectExternal, CLSIDFromString, CoDisconnectObject, CreateStreamOnHGlobal, CreateFileMoniker, CoInitialize, CoCreateInstance, CoInitializeEx, CoUninitialize
oleacc.dll
AccessibleObjectFromWindow, LresultFromObject
rpcrt4.dll
UuidCreate
secur32.dll
GetUserNameExW
shell32.dll
SHCreateDirectoryExW, SHGetSpecialFolderPathW
user32.dll
DllMain
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
Export table
_GetAllocCounters@0
_GetStdColorI@4

CVH.exe

Microsoft Office 2010 by Microsoft Corporation (Signed)

Remove CVH.exe
Version:   14.0.7106.5000
MD5:   1fdbbd2f2cf2d11e6247734797dec3c9
SHA1:   82fcc5f71e11b87bd494fc37ba9403fb75bd88c2
SHA256:   b254a8a0cfcd4de71fbe6d1d2b8963d9cd0dc9a048df146a2bbbd4bc6028986f

What is CVH.exe?

The Microsoft Office Client Virtualization Handler is part of the virtual click to run installation for Microsoft Office 2010.

Overview

CVH.EXE executes as a process with the local user's privileges typically within the context of its parent iexplore.exe (by Microsoft). During installation, it (or a shortcut) is added to the user's startup folder which is designed to automatically launch when the user logs into Windows. It is installed with a couple of know programs including Microsoft Office Click-to-Run 2010 published by Microsoft Corporation, Microsoft Office Klick-und-Los 2010 from Microsoft Corporation and Microsoft Office Klick-und-Los 2010 by Microsoft Corporation.

DetailsDetails

File name:CVH.EXE
Publisher:Microsoft Corporation
Product name:Microsoft Office 2010
Description:Microsoft Office Client Virtualization Handler
Typical file path:C:\Program Files\common files\microsoft shared\virtualization handler\cvh.exe
File version:14.0.7106.5000
Size:3.06 MB (3,207,912 bytes)
Build date:7/23/2013 8:11 PM
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Effective date:Monday, December 7, 2009
Expiration date:Monday, March 7, 2011
Digital DNA
PE subsystem:Windows GUI
Entropy:6.639826
File packed:No
Code language:Microsoft Visual C++ 9.0
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
4:20 Communications, Inc.
18% remove
Alien Skin
10% remove
Xenofex 2 delivers 14 more phenomenal effects for Adobe Photoshop,Jasc Paint Shop Pro, Macromedia Fireworks and other image editors. The new collection of 14 effects simulates natural phenomena like storms, stains, cracks and burnt edges. What's more, Xenofex 2 also includes distortions like Television and Crumple, and 3D effects like Flag, Shatter and Rip Open. You can also use Xenofex 2 to transform images into jigsaw puzzles, constel...
Atari, Inc.
24% remove
RollerCoaster Tycoon 2 is a construction and management simulation PC game that simulates amusement park management. The objective of the game is to complete scenarios by successfully building and maintaining amusement parks. Players can choose between various attractions, including transport rides, gentle rides, thrill rides, roller coasters, water rides, and shops or stalls. The player can further modify the amusement park by changing...
Atomix Productions
8% remove
VirtualDJ is the hottest AUDIO and VIDEO mixing software, targeting DJs from the bedroom, mobile, and professional superstars like Carl Cox. With VirtualDJ's breakthrough BeatLock engine, songs will always stay in beat, and the DJ works their mixes incredibly faster than they ever could. The automatic seamless loop engine and synchronized sampler lets the DJ perform astounding remixes live, with no preparation at all. The visual represe...
ClickMeIn Limited
  86% remove
Astromenda/Astromendario may change your default search engine to add Astromenda's (or any of Astromenda's affiliates) search engine; Astromenda's search engine is provided free of charge, and provides you with great search results. is an adware (advertising support) web browser application that is designed to display banner ads as well as contextual link ads (such as hyperlinks the user will see underlined). The ads are injected by the...
ClickMeIn Limited
  86% remove
ClickMeIn Limited
  81% remove
Taplika is an ad-supported browser extension that has been known to cause serious damage the Chrome, Firefox and Internet Explorer. This adware will deliver advertisements in the form of coupons, affiliate links, price-comparisons, display media and other links through a number of functions including those based on the the content of any web page the user is visiting, plug-ins, add-ons, or the web browser itself. Advertisements may be i...
Client Connect LTD
  79% remove
Search Protect from Client Connect (formally Conduit, now a venture of Perion) is a homepage and search provider modifier that when installed will change the default web browser's home page and search pages to a partner portal such as Trovi.
Conduit Ltd.
  65% remove
This toolbar is typiclaly bundled with the installation of some uTorrent versions. The toolbar (French languange version) is a Conduit toolbar (OurToolbar Community) for Intenet Explorer and Firefox. The toolbar collects and stores information about your web browsing habits and sends this information to Conduit so they can suggest services or provide advertising via the toolbar. uTorrentBar Toolbar will attempt to change your home page ...
Cooliris Inc.
25% remove
Cooliris transforms your browser into a visually stunning experience for searching, viewing, and sharing online photos and videos. Our 3D Wall lets you effortlessly search and zoom your way around thousands of images, videos, news feeds, sports feeds, and more. To share stuff with friends, just drag and drop.
Dell Inc.
3% remove
Dell Edoc Viewer is pre-installed with various Dell PCs and is part of the Dell support system. Dell eDoc Viewer or Dell Document Viewer is a display tool that collects and displays all documents hardware and software installed on your Dell computer. This display shows documents in HTML and PDF formats and also supports many other document formats.
GameHouse, Inc.
12% remove
SCRABBLE PLUS is a casual video game distributed through the GameHouse/RealNetworks platform.
Hewlett-Packard
44% remove
This program contains the HP Quick Launch Software, which enables special function keys on supported notebook models to be programmed. For example, the HP Quick Launch Software enables users to press the Fn+ESC keys to view system information. This software works with the supported operating systems.
Microsoft Corporation
12% remove
Office Click-to-Run is a new way for broadband customers to obtain Microsoft Office and to update Office 2010. Office Click-to-Run uses the virtualization and streaming technologies of Microsoft.
Microsoft Corporation
4% remove
Klick-und-Los ist eine neue Technologie für die Bereitstellung und Aktualisierung von Microsoft Office für Kunden mit Breitbandverbindungen, der auf die Streaming- und Virtualisierungstechnologie von Microsoft aufsetzt. Im Folgenden finden Sie Informationen zu den Vorteilen von Klick-und-Los sowie Wissenswertes über eine Kompatibilitätslücke zwischen Klick-und-Los und einigen Lösungen zum Schutz vor Schadsoftware.
Microsoft Corporation
8% remove
Hacer clic y ejecutar es una nueva forma de entregar y actualizar Microsoft Office para los clientes de banda ancha. Hacer clic y ejecutar utiliza la virtualización de Microsoft y tecnologías de transmisión por secuencias. Para Microsoft Office 2010, Microsoft ofrece una nueva manera de descargar e instalar sus productos de Office 2010. Esta tecnología se denomina Hacer clic y ejecutar y en este artículo se describe dicha tecnología y c...
Microsoft Corporation
5% remove
Microsoft Office a portata di clic è un nuovo sistema di distribuzione del software ottimizzato per gli utenti privati che dispongono di connessioni a banda larga (almeno 1 Mbps). Office a portata di clic non è un nuovo prodotto Microsoft Office, ma un nuovo sistema per distribuire e aggiornare i programmi già noti. È disponibile per le edizioni Microsoft Office Home and Student 2010 e Microsoft Office Home and Business 2010, è supporta...
Microsoft Corporation
12% remove
Office « Démarrer en un clic » fait appel à la technologie d’émission en continu et de virtualisation de Microsoft. Celle-ci permet de réduire sensiblement la durée de téléchargement. Vous pourrez ainsi découvrir les nouvelles fonctionnalités de Microsoft Office 2010 plus rapidement. Pour le moment, vous ne pouvez utiliser que Microsoft Office Famille et Étudiant 2010, Microsoft Office Famille et Petite Entreprise 2010 et Microsoft Offi...
Microsoft Corporation
4% remove
Microsoft Office Click-to-Run uses Microsoft streaming and virtualization technology to significantly reduce the time that is required for you to download and begin experiencing the new features of Microsoft Office 2010. At this time, only Microsoft Office Home and Student 2010, Microsoft Office Home and Business 2010, and Microsoft Office Starter 2010 are available by using Office Click-to-Run, which include the following Office 2010 p...
Microsoft Corporation
7% remove

BehaviorsBehaviors

Shell open commands
  • wordhtmlfile
Scheduled tasks
  • The job '{A12696DC-8232-4A4B-A69F-8C090735FAD2}' runs on registration in the path '\{A12696DC-8232-4A4B-A69F-8C090735FAD2}'
  • The job '{8514D44A-B131-432A-8E77-9173EAF0680E}' runs on registration in the path '\{8514D44A-B131-432A-8E77-9173EAF0680E}'
User start menu folder
Shortcut pointer placed in '%appdata%\Microsoft\Windows\Start Menu'
  • Shortcut to 'cvh.exe'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00016797%
0.028634%
Kernel CPU:0.00011813%
0.013761%
User CPU:0.00004984%
0.014873%
Kernel CPU time:367 ms/min
100,923,805ms/min
CPU cycles:19,903/sec
17,470,203/sec
Memory
Private memory:5.86 MB
21.59 MB
Private (maximum):10.89 MB
Private (minimum):7.62 MB
Non-paged memory:5.86 MB
21.59 MB
Virtual memory:109.4 MB
140.96 MB
Virtual memory (peak):129.75 MB
169.69 MB
Working set:8 MB
18.61 MB
Working set (peak):15.66 MB
37.95 MB
Page faults:11,004/min
2,039/min
I/O
I/O read transfer:84 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:2 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:66 Bytes/sec
448.09 KB/min
I/O other operations:5/sec
1,671/min
Resource allocations
Threads:6
12
Handles:219
600
GUI GDI count:58
103
GUI GDI peak:65
142
GUI USER count:18
49
GUI USER peak:22
71

BehaviorsProcess properties

Integrety level:Medium
Platform:64-bit
Command lines:
  • "C:\Program Files\common files\microsoft shared\virtualization handler\cvh.exe" /quietlaunch "onenotem 9014006104090000" /tsr
  • "C:\Program Files\common files\microsoft shared\virtualization handler\cvh.exe" "microsoft word starter 2010 9014006604090000" /n /f "C:\users\user\appdata\local\microsoft\windows\temporary internet files\content.ie5\hzftlv5h\doc_evidence.wiz"
Owner:User
Parent processes:

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 84.38%
Windows 7 Home Basic 15.63%

Distribution by countryDistribution by country

United States installs about 56.67% of Microsoft Office 2010.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Toshiba 36.73%
Sony 16.33%
Hewlett-Packard 14.29%
Dell 12.24%
ASUS 8.16%
Acer 6.12%
Lenovo 4.08%
Samsung 2.04%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE