Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 4.74%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.05%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.22%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.00%
6.2.9200.16384 (win8_rtm.120725-1247) 0.81%
6.2.9200.16384 (win8_rtm.120725-1247) 0.82%
6.2.9200.16384 (win8_rtm.120725-1247) 1.70%
6.2.9200.16384 (win8_rtm.120725-1247) 13.81%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.05%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.05%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.00%
6.2.8102.0 (winmain_win8m3.110823-1455) 0.05%
6.1.7600.16385 (win7_rtm.090713-1255) 22.55%
6.1.7600.16385 (win7_rtm.090713-1255) 38.30%
6.1.7600.16385 (win7_rtm.090713-1255) 0.00%
6.1.7600.16385 (win7_rtm.090713-1255) 1.62%
6.1.7600.16385 (win7_rtm.090713-1255) 0.00%
6.1.7600.16385 (win7_rtm.090713-1255) 0.00%
6.1.7600.16385 (win7_rtm.090713-1255) 0.23%
6.0.6000.16386 (vista_rtm.061101-2205) 5.56%
6.0.6000.16386 (vista_rtm.061101-2205) 1.21%
6.0.6000.16386 (vista_rtm.061101-2205) 0.32%
5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.00%
5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.02%
5.1.2600.5689 (xpsp_sp3_qfe.081003-1407) 0.09%
View more

Relationships

Parent process
Child processes
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
GetTokenInformation, InitializeSecurityDescriptor, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetEntriesInAclW, SetSecurityDescriptorDacl, StartServiceCtrlDispatcherW, RegDisablePredefinedCacheEx, EventRegister, EventEnabled, EventWrite, RegQueryValueExW, RegOpenKeyExW, RegCloseKey, RegisterServiceCtrlHandlerW, SetServiceStatus, OpenProcessToken
api-ms-win-core-crt-l1-1-0.dll
memcmp, memcpy, _except_handler4_common
api-ms-win-core-crt-l2-1-0.dll
exit, _initterm, _initterm_e, __wgetmainargs
api-ms-win-core-delayload-l1-1-1.dll
ResolveDelayLoadedAPI, DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-0.dll
SetErrorMode, GetLastError, SetUnhandledExceptionFilter, UnhandledExceptionFilter
api-ms-win-core-errorhandling-l1-1-1.dll
GetLastError, SetErrorMode, UnhandledExceptionFilter, SetUnhandledExceptionFilter
api-ms-win-core-handle-l1-1-0.dll
CloseHandle
api-ms-win-core-heap-l1-1-0.dll
HeapAlloc, GetProcessHeap, HeapSetInformation, HeapFree
api-ms-win-core-heap-l1-2-0.dll
GetProcessHeap, HeapAlloc, HeapSetInformation, HeapFree
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalFree, LocalAlloc
api-ms-win-core-libraryloader-l1-1-1.dll
LoadLibraryExW, GetProcAddress, FreeLibrary
api-ms-win-core-libraryloader-l1-2-0.dll
FreeLibrary, GetProcAddress, LoadLibraryExW
api-ms-win-core-localization-l1-1-1.dll
LCMapStringW
api-ms-win-core-localization-l1-2-0.dll
LCMapStringW
api-ms-win-core-localization-l1-2-1.dll
LCMapStringW
api-ms-win-core-processenvironment-l1-1-0.dll
ExpandEnvironmentStringsW, GetCommandLineW
api-ms-win-core-processenvironment-l1-1-1.dll
ExpandEnvironmentStringsW, GetCommandLineW
api-ms-win-core-processenvironment-l1-2-0.dll
ExpandEnvironmentStringsW, GetCommandLineW
api-ms-win-core-processthreads-l1-1-0.dll
TerminateProcess, GetCurrentProcess, OpenProcessToken, GetCurrentProcessId, GetCurrentThreadId
api-ms-win-core-processthreads-l1-1-1.dll
ExitProcess, SetProcessAffinityUpdateMode, OpenProcessToken, TerminateProcess, GetCurrentThreadId, GetCurrentProcess, GetCurrentProcessId, IsProcessorFeaturePresent
api-ms-win-core-processthreads-l1-1-2.dll
SetProcessAffinityUpdateMode, OpenProcessToken, GetCurrentThreadId, ExitProcess, GetCurrentProcess, TerminateProcess, GetCurrentProcessId
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegOpenKeyExW, RegQueryValueExW, RegDisablePredefinedCacheEx, RegCloseKey, RegGetValueW
api-ms-win-core-sidebyside-l1-1-0.dll
DeactivateActCtx, ReleaseActCtx, ActivateActCtx, CreateActCtxW
api-ms-win-core-string-l1-1-0.dll
CompareStringW, WideCharToMultiByte
api-ms-win-core-string-obsolete-l1-1-0.dll
lstrcmpiW, lstrlenW, lstrcmpW
api-ms-win-core-synch-l1-1-1.dll
InitializeSRWLock, AcquireSRWLockShared, EnterCriticalSection, LeaveCriticalSection, ReleaseSRWLockShared, AcquireSRWLockExclusive, ReleaseSRWLockExclusive, InitializeCriticalSection
api-ms-win-core-synch-l1-2-0.dll
AcquireSRWLockShared, InitializeSRWLock, AcquireSRWLockExclusive, EnterCriticalSection, LeaveCriticalSection, ReleaseSRWLockExclusive, ReleaseSRWLockShared
api-ms-win-core-sysinfo-l1-1-1.dll
GetSystemTimeAsFileTime, GetTickCount
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemTimeAsFileTime, GetTickCount
api-ms-win-core-sysinfo-l1-2-1.dll
GetSystemTimeAsFileTime, GetTickCount
api-ms-win-core-threadpool-l1-1-1.dll
RegisterWaitForSingleObjectEx
api-ms-win-core-threadpool-private-l1-1-0.dll
RegisterWaitForSingleObjectEx
api-ms-win-obsolete-kernelbase-l1-1-0.dll
lstrcmpW, lstrlenW, LocalAlloc, lstrcmpiW, LocalFree
api-ms-win-security-base-l1-1-0.dll
SetSecurityDescriptorDacl, AddAccessAllowedAce, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetTokenInformation, InitializeSecurityDescriptor, GetLengthSid, InitializeAcl
api-ms-win-security-base-l1-2-0.dll
GetLengthSid, InitializeAcl, InitializeSecurityDescriptor, GetTokenInformation, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, AddAccessAllowedAce, SetSecurityDescriptorDacl
api-ms-win-service-core-l1-1-0.dll
StartServiceCtrlDispatcherW, SetServiceStatus
api-ms-win-service-core-l1-1-1.dll
SetServiceStatus, StartServiceCtrlDispatcherW
api-ms-win-service-winsvc-l1-1-0.dll
RegisterServiceCtrlHandlerW
api-ms-win-service-winsvc-l1-2-0.dll
RegisterServiceCtrlHandlerW
kernel32.dll
LocalAlloc, CloseHandle, DelayLoadFailureHook, GetProcAddress, GetLastError, FreeLibrary, InterlockedCompareExchange, LoadLibraryExA, InterlockedExchange, Sleep, SetUnhandledExceptionFilter, GetModuleHandleA, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, UnhandledExceptionFilter, DeactivateActCtx, LoadLibraryExW, ActivateActCtx, LeaveCriticalSection, lstrcmpW, EnterCriticalSection, RegCloseKey, RegOpenKeyExW, HeapSetInformation, lstrcmpiW, lstrlenW, LCMapStringW, RegQueryValueExW, ReleaseActCtx, CreateActCtxW, ExpandEnvironmentStringsW, GetCommandLineW, ExitProcess, SetProcessAffinityUpdateMode, RegDisablePredefinedCacheEx, InitializeCriticalSection, GetProcessHeap, SetErrorMode, RegisterWaitForSingleObjectEx, LocalFree, HeapFree, WideCharToMultiByte, HeapAlloc, GetCurrentThreadId, GetCurrentProcessId, TerminateProcess, GetCurrentProcess, RegisterWaitForSingleObject, LoadLibraryA, ReleaseSRWLockShared, AcquireSRWLockShared, InitializeSRWLock, ReleaseSRWLockExclusive, AcquireSRWLockExclusive
msvcrt.dll
DllMain
ntdll.dll
RtlAllocateHeap, RtlLengthRequiredSid, RtlSubAuthoritySid, RtlInitializeSid, RtlCopySid, RtlSubAuthorityCountSid, RtlInitializeCriticalSection, RtlSetProcessIsCritical, RtlImageNtHeader, RtlUnhandledExceptionFilter, EtwEventWrite, EtwEventEnabled, EtwEventRegister, RtlFreeHeap, NtSetInformationProcess
rpcrt4.dll
RpcMgmtSetServerStackSize, I_RpcMapWin32Status, RpcServerUnregisterIf, RpcMgmtWaitServerListen, RpcMgmtStopServerListening, RpcServerUnregisterIfEx, RpcServerRegisterIf, RpcServerUseProtseqEpW, RpcServerListen, I_RpcServerDisableExceptionFilter

svchost.exe

Host Process for Windows Services by Microsoft Corporation (Signed)

Remove svchost.exe
Version:   6.1.7600.16385 (win7_rtm.090713-1255)
MD5:   dfde777faf31dc25e3624e8071073146
SHA1:   73a63279a2e065babb9460777678897877d29945
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is svchost.exe?

Host Process for Windows Tasks is a generic process which acts as a host for processes that run from DLLs rather than EXEs. At startup TASKHOST checks the Services portion of the Registry to construct a list of DLL-based services that it needs to load, and then loads them.

Overview

svchost.exe has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. The file is digitally signed by Microsoft Corporation. This version is designed to run on Windows 7 and is compiled as a 64 bit program.

DetailsDetails

File name:svchost.exe
Publisher:Microsoft Corporation
Product name:Host Process for Windows Services
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\svchost.exe
Original name:svchost.exe.mui
File version:6.1.7600.16385 (win7_rtm.090713-1255)
Product version:6.1.7600.16385
Size:26.5 KB (27,136 bytes)
Build date:10/18/2012 7:02 PM
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Expiration date:Friday, June 13, 2014
Digital DNA
Entropy:5.878473
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Services
This is the shared Service Host controller that runs some of the following shared services:
  • Service name 'QQPCFixSvc'
  • Service name 'Журнал событий Windows'
Drivers
  • SDGame
  • WinDefend
  • 1394hub
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\Windows\system32\svchost.exe'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00006793%
0.028634%
Kernel CPU:0.00004056%
0.013761%
User CPU:0.00002737%
0.014873%
Kernel CPU time:473,592 ms/min
100,923,805ms/min
CPU cycles:25,889/sec
17,470,203/sec
Memory
Private memory:12.93 MB
21.59 MB
Private (maximum):14.97 MB
Private (minimum):540 KB
Non-paged memory:12.93 MB
21.59 MB
Virtual memory:106.85 MB
140.96 MB
Virtual memory (peak):164.45 MB
169.69 MB
Working set:11.38 MB
18.61 MB
Working set (peak):28.35 MB
37.95 MB
Page faults:1,074,694/min
2,039/min
I/O
I/O read transfer:104.04 KB/sec
1.02 MB/min
I/O read operations:40/sec
343/min
I/O write transfer:7.59 KB/sec
274.99 KB/min
I/O write operations:4/sec
227/min
I/O other transfer:37.69 KB/sec
448.09 KB/min
I/O other operations:1,378/sec
1,671/min
Resource allocations
Threads:12
12
Handles:342
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command lines:
  • C:\Windows\System32\svchost.exe -k localservicenetworkrestricted
  • C:\Windows\System32\svchost.exe -k localservice
  • C:\Windows\System32\svchost.exe -k rpcss
  • C:\Windows\System32\svchost.exe -k networkservice
  • C:\Windows\System32\svchost.exe -k dcomlaunch
  • C:\Windows\System32\svchost.exe -k localsystemnetworkrestricted
  • C:\Windows\System32\svchost.exe -k localservicenonetwork
  • (8 more)
Owner:LOCAL SERVICE
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
ntdll.dll
Total CPU:0.19570394%
0.272967%
Kernel CPU:0.16020105%
0.107585%
User CPU:0.03550289%
0.165382%
CPU cycles:7,290,500/sec
5,741,424/sec
Context switches:15/sec
79/sec
Memory:1.66 MB
1.16 MB
audiosrv.dll (Windows Audio Service by Microsoft)
Total CPU:0.00601218%
Kernel CPU:0.00546973%
User CPU:0.00054245%
CPU cycles:196,357/sec
Memory:688 KB
mpssvc.dll (Microsoft Protection Service by Microsoft)
Total CPU:0.00351848%
Kernel CPU:0.00070822%
User CPU:0.00281026%
CPU cycles:138,645/sec
Memory:824 KB
umpnpmgr.dll (User-mode Plug-and-Play Service by Microsoft)
Total CPU:0.00016575%
Kernel CPU:0.00016575%
User CPU:0.00000000%
CPU cycles:6,901/sec
Memory:412 KB
sechost.dll (Host for SCM/SDDL/LSA Lookup APIs by Microsoft)
Total CPU:0.00012243%
Kernel CPU:0.00007534%
User CPU:0.00004709%
CPU cycles:5,263/sec
Memory:124 KB
wevtsvc.dll
Total CPU:0.00011547%
Kernel CPU:0.00009414%
User CPU:0.00002133%
CPU cycles:5,356/sec
Memory:1.59 MB
mmcss.dll (Multimedia Class Scheduler Service by Microsoft)
Total CPU:0.00006027%
Kernel CPU:0.00004521%
User CPU:0.00001507%
CPU cycles:1,890/sec
Memory:116 KB
MMDevAPI.DLL
Total CPU:0.00003767%
Kernel CPU:0.00002260%
User CPU:0.00001507%
CPU cycles:1,512/sec
Memory:300 KB
schedsvc.dll
Total CPU:0.00003014%
Kernel CPU:0.00003014%
User CPU:0.00000000%
CPU cycles:1,070/sec
Memory:1.07 MB
wudfsvc.dll (Windows Driver Foundation - User-mode Driver Framework Service by Microsoft)
Total CPU:0.00002260%
Kernel CPU:0.00000753%
User CPU:0.00001507%
CPU cycles:731/sec
Memory:100 KB
svchost.exe (main module)
Total CPU:0.00001883%
Kernel CPU:0.00001883%
User CPU:0.00000000%
CPU cycles:623/sec
Memory:44 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 8.1 Pro 100.00%

Distribution by countryDistribution by country

Austria installs about 79.00% of Host Process for Windows Services.
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE