VersionsVersions

6.3.9600.16384 (winblue_rtm.130821-1623) 5.51%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.06%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.25%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.00%
6.2.9200.16384 (win8_rtm.120725-1247) 0.95%
6.2.9200.16384 (win8_rtm.120725-1247) 0.95%
6.2.9200.16384 (win8_rtm.120725-1247) 1.98%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.06%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.06%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.00%
6.2.8102.0 (winmain_win8m3.110823-1455) 0.06%
6.1.7600.16385 (win7_rtm.090713-1255) 26.23%
6.1.7600.16385 (win7_rtm.090713-1255) 44.56%
6.1.7600.16385 (win7_rtm.090713-1255) 0.00%
6.1.7600.16385 (win7_rtm.090713-1255) 1.89%
6.1.7600.16385 (win7_rtm.090713-1255) 0.00%
6.1.7600.16385 (win7_rtm.090713-1255) 0.00%
6.0.6000.16386 (vista_rtm.061101-2205) 6.47%
6.0.6000.16386 (vista_rtm.061101-2205) 1.41%
6.0.6000.16386 (vista_rtm.061101-2205) 0.38%
5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.00%
5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.03%
5.1.2600.5689 (xpsp_sp3_qfe.081003-1407) 0.10%
5.1.2600.5512 (xpsp.080413-2111) 6.20%
5.1.2600.5512 (xpsp.080413-2111) 0.41%
5.1.2600.5512 (xpsp.080413-2111) 0.28%
5.1.2600.5512 (xpsp.080413-2111) 0.03%
5.1.2600.5512 (xpsp.080413-2111) 0.26%
5.1.2600.5512 (xpsp.080413-2111) 0.00%
5.1.2600.5512 (xpsp.080413-2111) 0.00%
5.1.2600.5512 (xpsp.080413-2111) 0.18%
5.1.2600.5512 (xpsp.080413-2111) 0.03%
5.1.2600.5512 (xpsp.080413-2111) 0.00%
5.1.2600.5512 (xpsp.080413-2111) 0.08%
5.1.2600.5512 (xpsp.080413-2111) 0.13%
5.1.2600.5512 (xpsp.080413-2111) 0.02%
5.1.2600.5512 (xpsp.080413-2111) 0.13%
5.1.2600.5512 (xpsp.080413-2111) 0.03%
5.1.2600.5512 (xpsp.080413-2111) 0.00%
5.1.2600.5512 (xpsp.080413-2111) 0.00%
5.1.2600.5512 (xpsp.080413-2111) 0.00%
5.1.2600.3311 (xpsp.080212-0005) 0.03%
5.1.2600.3300 (xpsp.080125-2028) 0.00%
5.1.2600.3244 (xpsp.071030-1537) 0.00%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 1.24%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.02%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.00%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.00%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.00%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.00%
View more

Relationships

svchost.exe

Host Process for Windows Services by Microsoft Corporation (Signed)

Remove svchost.exe
This is a Windows system installed file with Windows File Protection (WFP) enabled.
Warning 16 antivirus scanners has detected malware in various versions of svchost.exe.

Overview

svchost.exe has 53 known versions, the most recent one is 6.3.9600.16384 (winblue_rtm.130821-1623). It is started as a Windows Service called 'obrvj' with the name 'DcomLaunch' and described as “Bietet Startfunktionalität für DCOM-Dienste.”. . It is run under the context of the LOCAL SERVICE account. This is executed as a shared service (which simply means that this service can share a process with other Win32 services). During installation the program adds a job to the Task Scheduler that will runs weekly. The average file size is about 18.92 KB. It is an authenticode code-signed executable issued to Microsoft Corporation by the certification authority Microsoft Corporation. During the process's lifecycle, the typical CPU resource utilization is about 0.0006% including both foreground and background operations, the average private memory consumption is about 21.62 MB with the maximum memory reaching around 42.23 MB. Addionally, typically read and write I/O disk operations is about 48.42 KB per minute for reads and 14.92 KB per minute for writes.

What is svchost.exe?

Host Process for Windows Tasks is a generic process which acts as a host for processes that run from DLLs rather than EXEs. At startup TASKHOST checks the Services portion of the Registry to construct a list of DLL-based services that it needs to load, and then loads them.

DetailsDetails

File name:svchost.exe
Publisher:Microsoft Corporation
Product name:Host Process for Windows Services
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\svchost.exe
Original name:svchost.exe.mui
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Expiration date:Friday, June 13, 2014

ResourcesPrograms installed in

(Note, the programs listed below are for all versions of Host Process for Windows Services.)
Easy Computing
8% remove
Micro Application
42% remove
LauncherMA is installed with various Micro App distributed applications and is designed to manage the startup of the installed apps that were downloaded or purchased through the microapp.com distribut...
Micro Application
9% remove

BehaviorsBehaviors

(Note, the behaviors below are for all versions of svchost.exe, select a unique version for details.)
Services
This is the shared Service Host controller that runs some of the following shared services:
  • Service name 'obrvj'
  • Service name 'Запуск серверных процессов DCOM'
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\WINDOWS\system32\svchost.exe'
Drivers
  • 1394hub
Scheduled tasks
  • The job 'At1' runs weekly in the path 'C:\WINDOWS\Tasks\At1.job'

MalwareMalware detections

Based on 40+ industry antivirus scanners, 16 of them detected the following malware.
Antivirus engineEngine versionDetectionFile version
Avira AntiVir 7.11.24.6 TR/Patched.CX.75 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
BitDefender 7.2 Trojan.Generic.3553222 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Emsisoft Anti-Malware 5.1.0.11 Trojan.Patched!IK 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
eSafe 7.0.17.0 Win32.TrojanHorse 6.1.7600.16385 (win7_rtm.090713-1255)
eSafe 7.0.17.0 Win32.Banker 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)
eSafe 7.0.17.0 Win32.Conficker.worm 5.1.2600.5512 (xpsp.080413-2111)
eSafe 7.0.17.0 Win32.TrojanHorse 5.1.2600.5512 (xpsp.080413-2111)
eSafe 7.0.17.0 Win32.TrojanHorse 5.1.2600.5512 (xpsp.080413-2111)
F-Secure 9.0.16440.0 Trojan.Generic.3553222 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
G Data 13.5.22 Trojan.Generic.3553222 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Ikarus T3.1.1.118.0 Trojan.Patched 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
K7 AntiVirus 9.130.6244 Trojan 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
McAfee 5.400.1158 Artemis!4E06F50F9535 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
McAfee Gateway Anti-Malware v2010.1E-dat Artemis!4E06F50F9535 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
nProtect 2012-02-24.02 Trojan.Generic.3553222 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
The Hacker 6.7.0.1.409 Trojan/Patched.cx 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)

VersionsAll file variations of svchost.exe

MD5SHA-1File size
e4ca434f251681590d0538bc21c32d2f 4eea9bdfe0eb41759d96ec9bd224c4519314a8fa 36.88 KB
425e22d9f5c01616afc92987791b19e9 b73dfc550dc27562683284fb51661200f31419f9 30.81 KB
f7191317f1cd10f35dc74e24c1b71e06 01c21ae89c35c33eda304f5a65037dd0d23a4b06 36.88 KB
d9f8fa4911fbf85919ba17ffe5b34430 c25a904cb1fbea3d6e4c00ac429e3ba519139462 30.81 KB
0a175af8b65797bd22c11903a8bfeb2d 075d04db237e1fcb7d45d780268371fa80c512a2 22.5 KB
57350bede3834915b6145b67c71c7bda 76111d4f5d751dcc31fbe5066c46378d57ab70ff 29.5 KB
a46dc432f81473f526e3994aa483e366 952b68cbf2654a6208ef277d4300656a18592889 22.5 KB
92b919655ba013e8687e2ae873ba56ed 0422cc8d59c1cde639cf5a3e2212a7c72ee08d54 30.5 KB
d5b55f18a7cd2a6f4019b17baeedc2f3 3046ad49975c7d0c08aae0622b78f42e54ab5181 23.5 KB
e4bc66e3b5638103a02a2837f922c6f4 28f1ccabce4100765eaa0c2fb002dde4b4ccbff0 23.5 KB
038bb82a5f49c7aa196c847850b68e19 48898e2cc8ec0f1ef4414164c14d4e63e3fa4ed5 21 KB
54a47f6b5e09a77e61649109c6a08866 4af001b3c3816b860660cf2de2c0fd3c1dfb4878 20.5 KB
c78655bc80301d76ed4fef1c1ea40a7d 619652b42afe5fb0e3719d7aeda7a5494ab193e8 26.5 KB
dfdf1e4aee12e9021bd72f29b6877a8d 0c329761f2044396a3646e984eb874354561a49c 27 KB
6f68f63794097e54f36474ed4384b759 5e185df5c89365a5e6728e08557c5b1d13dbbe07 27 KB
ffb38d8afd6f4fca1d46d64f1ede0b9f ef5352a3bd4e90ee46e5dee76403e0d191d9046a 21 KB
dfde777faf31dc25e3624e8071073146 73a63279a2e065babb9460777678897877d29945 26.5 KB
3794b461c45882e06856f282eef025af bf15549a7ec01ac505ccac036aba5b9bae688135 21 KB
cda9f1373805af88f6fa4f2064bba24d 8306f3e86107fe1ba1fc8ff6133b357570206d06 27 KB
10da15933d582d2fedcf705efe394b09 00beb64af60255d5eb76b2edbd30b46de681da32 21.5 KB
c09ccfe81dec9b162533d7184d705682 086fc8c82ba9e1f3f764e15ffbe402a6529ef323 14.5 KB
46300880a5062a41c16df5e3e836a6c9 57a6116206e3fe79f15177a891d60c1ef6a01b18 25 KB
67e38b4a549833e02d4d1617b5dbc318 86822a42cebee91fb95009f787d783a63e7905f3 14.5 KB
27c6d03bcdb8cfeb96b716f3d8be3e18 49083ae3725a0488e0a8fbbe1335c745f70c4667 14 KB
e948a9079d0e6350be92d4d3e0077f81 82379592eca1117386e97f7a0500b3f34204d92e 14 KB
e4bdf223cd75478bf44567b4d5c2634d 3d70560753b0ab43252311fa85e12f36a51a5f55 14 KB
6ccef19d7301d9861f90e299c798ad3f b0bce2e7ca629199c5fc504ef9137fb8e2948402 14 KB
4f2340f0bd5b6365c38e74dd391919a8 1aae36311da414c8fd5b32956aaed1d82237ab08 14 KB
be4a520e29b6391f49e79ccc52044d93 f87c6ea4a068ed7f515b20e5f5f22c0329403fad 14 KB
6b1139ca38db1678487678c44874b80f f643afafa067cca765970ef4b412212025b6b3eb 14 KB
4fbc75b74479c7a6f829e0ca19df3366 97c7c354c12b89c797740b35ed81879be58f3deb 14 KB
4c0f692661947b432d184ebfa2fe1912 021a6a1411aa8c62ce66b92e38b0995ff5628ba7 14 KB
e410ec73e2be2a41d923b006f51c8427 c9aef0e56bff968edf21c416d5403e9470951da3 14 KB
ed2d69cd4b0ebe37efe11d4dc4abc68f 1fe9a7ebc983b134f2a7f4500be9a9bc02aaf545 14 KB
b703aee8722ced0f0fd804ea844d8de6 42e60199ac366c782c935325df5de777af4c9206 14 KB
7514a44aee0cdf8a8ed501a9b984627e 03dca6b7424678e4a6e7d8ab1256c411009a46ae 14 KB
05194d8a92cf7e559c1a38fc134c966a 89bdb4dcca2c045c4cda6078dd17e981e106a2c5 14 KB
555f8f4cb284fe94059dcacf6074f9ec d1409e93a89985dfc459c10fb9c8c781cce22777 14 KB
3aececc06b3c127f625a73bb6e01668c 8cc608f5bb954bd7f9b9ac8f90d1cb1426a51c0c 14 KB
87ba1595374fc6a8348f9b8a30b9ee22 03c9b4f15d1db499cb04ae6f65d8192d0de1dda4 14 KB
8607d35d92528e2df386f19a960d23ce f9fdce5b23352e556c5d7dfad53aa0d78fe5c880 14 KB
0c54d685cfa1d5054f59f08adaf71248 f163fd97da33ebff726e36227a950cdab4aa6e38 14 KB
a9e050d11d430cde3c217a230835142e 8c88186a7e09933fa3edb9e744a981d60248ec28 14 KB
9ae650ad5d3df02fbd28ce26746cca5b 49c77ad4aacc3cf925f0a3ae101939a7f764712e 14 KB
8f078ae4ed187aaabc0a305146de6716 da0ff4006859a7580aba81f486f692dead2014fe 14 KB
fa03e1fc17f38fbdba81470d08b3e416 a82a1815a25ee15c9509914c478f601dab3cf321 14 KB
4e06f50f95357b8cfbc81f5699e754b7 8a60cc904a23a2ae70d63aa1cc86fca35c679dc7 16.5 KB
d0488d4c9c04ca3ffda71d8a0d7959fa 81a4334512e8c4d90aa1752f3992172b7f5e9307 14 KB
2979b03d5382a602623c0535b16ab9c0 7317f72ce609b7555a3784ec77157d3ebcf18fb7 14 KB
5de3e7b6f7624552f2f06664f110820d 596ffb54ff52039e6e4a6db1a271a7769e2a0416 14 KB
1bd6c2f707a275cb7c16fd99fe0f31ca 57e04ab52d63d3e6e4e79b3b905ac15e3249f171 14 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 8.1 Pro 77.75%
Windows 7 Home Premium 22.25%

Distribution by countryDistribution by country

Austria installs about 39.50% of Host Process for Windows Services.
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE