Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.2.9200.16384 (win8_rtm.120725-1247) 10.00%
6.2.9200.16384 (win8_rtm.120725-1247) 15.00%
6.1.7601.17562 (win7sp1_gdr.110217-1504) 40.00%
6.1.7601.17562 (win7sp1_gdr.110217-1504) 30.00%
6.1.7600.16385 (win7_rtm.090713-1255) 5.00%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
kernel32.dll
SetEvent, WaitForSingleObject, GetProcAddress, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetSystemTimeAsFileTime, CreateEventW, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, GetStartupInfoA, InterlockedCompareExchange, Sleep, InterlockedExchange, InterlockedDecrement, InterlockedIncrement, GetLastError, GetCurrentProcessId, HeapSetInformation, GetModuleHandleW
msvcrt.dll
DllMain
ntdll.dll
RtlUnwind
ole32.dll
CoRegisterSurrogate, CLSIDFromString, CoUninitialize, CoRegisterClassObject, CoInitializeSecurity, CoCreateInstance, CoRevokeClassObject, CoMarshalInterThreadInterfaceInStream, CoGetInterfaceAndReleaseStream, CoInitializeEx, CoFreeUnusedLibraries
user32.dll
TranslateMessage, MsgWaitForMultipleObjects, DispatchMessageW, PeekMessageW

PREVHOST.exe

Preview Handler Surrogate Host by Microsoft

Remove PREVHOST.exe
Version:   6.1.7601.17562 (win7sp1_gdr.110217-1504)
MD5:   5fac5f264d61d99ee8961480818b9def
SHA1:   7350394ea21974a0689800f2c7deec86c01d30b2
SHA256:   e9717c3c3cb0a8e48764edcf90c7c9287b659489661dc5e6f845e1124d9378b9
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

prevhost.exe executes as a process with the local user's privileges typically within the context of its parent svchost.exe (Host Process for Windows Services by Microsoft Corporation). This version is designed to run on Windows 7 and is compiled as a 64 bit program.

DetailsDetails

File name:prevhost.exe
Publisher:Microsoft Corporation
Product name:Preview Handler Surrogate Host
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\prevhost.exe
File version:6.1.7601.17562 (win7sp1_gdr.110217-1504)
Product version:6.1.7601.17562
Size:30.5 KB (31,232 bytes)
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details
Network connections
  • [UDP] listens on port 65523

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00038243%
    0.028634%
    Kernel CPU:0.00028903%
    0.013761%
    User CPU:0.00009340%
    0.014873%
    Kernel CPU time:26,297 ms/min
    100,923,805ms/min
    CPU cycles:5,914/sec
    17,470,203/sec
    Memory
    Private memory:5.53 MB
    21.59 MB
    Private (maximum):14.97 MB
    Private (minimum):8.94 MB
    Non-paged memory:5.53 MB
    21.59 MB
    Virtual memory:84.33 MB
    140.96 MB
    Virtual memory (peak):93.51 MB
    169.69 MB
    Working set:12.28 MB
    18.61 MB
    Working set (peak):15.84 MB
    37.95 MB
    Page faults:9,872/min
    2,039/min
    I/O
    I/O read transfer:240 Bytes/sec
    1.02 MB/min
    I/O read operations:1/sec
    343/min
    I/O other transfer:7 Bytes/sec
    448.09 KB/min
    I/O other operations:2/sec
    1,671/min
    Resource allocations
    Threads:4
    12
    Handles:112
    600
    GUI GDI count:13
    103
    GUI GDI peak:17
    142
    GUI USER count:10
    49
    GUI USER peak:14
    71

    BehaviorsProcess properties

    Integrety level:Low
    Platform:64-bit
    Command line:C:\Windows\System32\prevhost.exe {914feed8-267a-4baa-b8aa-21e233792679} -embedding
    Owner:User
    Parent process:svchost.exe (Host Process for Windows Services by Microsoft Corporation)

    ResourcesThreads

    Averages
     
    SHLWAPI.dll
    Total CPU:0.03665130%
    0.272967%
    Kernel CPU:0.00834541%
    0.107585%
    User CPU:0.02830589%
    0.165382%
    CPU cycles:818,588/sec
    5,741,424/sec
    Memory:452 KB
    1.16 MB
    prevhost.exe (main module)
    Total CPU:0.00041489%
    Kernel CPU:0.00029418%
    User CPU:0.00012071%
    CPU cycles:10,219/sec
    Memory:48 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 40.00%
    Windows 8 Pro 20.00%
    Windows 7 Professional 20.00%
    Windows 7 Ultimate 15.00%
    Windows 8 5.00%

    Distribution by countryDistribution by country

    United States installs about 55.00% of Preview Handler Surrogate Host.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 33.33%
    GIGABYTE 22.22%
    Hewlett-Packard 22.22%
    Intel 11.11%
    Acer 5.56%
    Alienware 5.56%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE