Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9431.0 (winmain_bluemp.130615-1214) 2.00%
6.2.9200.16384 (win8_rtm.120725-1247) 94.00%
6.2.9200.16384 (win8_rtm.120725-1247) 4.00%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
api-ms-win-core-com-l1-1-0.dll
CoRegisterClassObject, CoRevokeClassObject, CoInitializeEx, CoUninitialize, CoInitializeSecurity, CoGetClassObject, CoFreeUnusedLibraries
api-ms-win-core-errorhandling-l1-1-1.dll
SetUnhandledExceptionFilter, UnhandledExceptionFilter, SetLastError, GetLastError
api-ms-win-core-file-l1-2-0.dll
WriteFile, UnlockFileEx, GetFileAttributesExW, DeleteFileW, SetFilePointer, CreateFileW, LockFileEx
api-ms-win-core-heap-l1-2-0.dll
HeapSetInformation
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedDecrement, InterlockedIncrement, InterlockedCompareExchange, InterlockedExchange
api-ms-win-core-libraryloader-l1-1-1.dll
GetModuleHandleA
api-ms-win-core-processenvironment-l1-2-0.dll
ExpandEnvironmentStringsW
api-ms-win-core-processthreads-l1-1-1.dll
GetCurrentProcessId, GetCurrentThreadId, GetStartupInfoW, TerminateProcess, ExitProcess, GetCurrentProcess
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegGetValueW
api-ms-win-core-synch-l1-2-0.dll
LeaveCriticalSection, DeleteCriticalSection, Sleep, EnterCriticalSection, InitializeCriticalSection
api-ms-win-core-sysinfo-l1-2-0.dll
GetLocalTime, GetTickCount, GetSystemTimeAsFileTime
api-ms-win-shcore-thread-l1-1-0.dll
GetProcessReference, SetProcessReference
kernel32.dll
LocalFree, LocalAlloc
msvcrt.dll
DllMain
user32.dll
CreateWindowExW, TranslateMessage, PostQuitMessage, RegisterClassW, SetTimer, DestroyWindow, DefWindowProcW, GetMessageW, DispatchMessageW

WSHost.exe

COM Surrogate by Microsoft Corporation (Signed)

Remove WSHost.exe
Version:   6.2.9200.16384 (win8_rtm.120725-1247)
MD5:   4585afd2b8b15e73c42fe5976a8d4a02
SHA1:   ff49d58f7e21b4c2f05176f7f777c56d720a190d
SHA256:   6670366bd22cfa40efb41ca67bfe899994a0237a2fcd5287fd73c68f6e44c813
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is WSHost.exe?

The wshost.exe process goes by the name COM Surrogate and the only time you're likely even to notice its existence is when it crashes and you get the message COM Surrogate has stopped working. The COM Surrogate is a sacrificial process for a COM object that is run outside of the process that requested it. It does this in case the process it is trying to run crashes and instead of crashing the calling process the COM Surrogate crashes instead and the calling program is uneffected.

Overview

wshost.exe executes as a process with the local user's privileges typically within the context of its parent svchost.exe (Host Process for Windows Services by Microsoft Corporation). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). The file is digitally signed by Microsoft Corporation. This version is installed on Windows 8 and is compiled as a 64 bit program.

DetailsDetails

File name:wshost.exe
Publisher:Microsoft Corporation
Product name:COM Surrogate
Description:Microsoft® Windows® Operating System
Typical file path:C:\windows\winstore\wshost.exe
File version:6.2.9200.16384 (win8_rtm.120725-1247)
Product version:6.2.9200.16384
Size:26.15 KB (26,776 bytes)
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Effective date:Monday, April 9, 2012
Expiration date:Tuesday, July 9, 2013
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00270168%
0.028634%
Kernel CPU:0.00136670%
0.013761%
User CPU:0.00133498%
0.014873%
Kernel CPU time:322,904 ms/min
100,923,805ms/min
CPU cycles:547,199/sec
17,470,203/sec
Context switches:4/sec
284/sec
Memory
Private memory:4.55 MB
21.59 MB
Private (maximum):14.57 MB
Private (minimum):8.94 MB
Non-paged memory:4.55 MB
21.59 MB
Virtual memory:105.72 MB
140.96 MB
Virtual memory (peak):124.66 MB
169.69 MB
Working set:10.92 MB
18.61 MB
Working set (peak):16.19 MB
37.95 MB
Page faults:40,430/min
2,039/min
I/O
I/O read transfer:3.77 KB/sec
1.02 MB/min
I/O read operations:101/sec
343/min
I/O write transfer:2.91 KB/sec
274.99 KB/min
I/O write operations:7/sec
227/min
I/O other transfer:1.29 KB/sec
448.09 KB/min
I/O other operations:16/sec
1,671/min
Resource allocations
Threads:7
12
Handles:337
600
GUI GDI count:10
103
GUI GDI peak:14
142
GUI USER count:10
49
GUI USER peak:27
71

BehaviorsProcess properties

Integrety level:Medium
Platform:64-bit
Command line:C:\windows\winstore\wshost.exe -embedding
Owner:User
Parent process:svchost.exe (by Microsoft)

ResourcesThreads

Averages
 
ntdll.dll
Total CPU:0.00940973%
0.272967%
Kernel CPU:0.00681781%
0.107585%
User CPU:0.00259191%
0.165382%
CPU cycles:184,511/sec
5,741,424/sec
Memory:1.75 MB
1.16 MB
WinStoreUI.dll
Total CPU:0.00076052%
Kernel CPU:0.00000000%
User CPU:0.00076052%
CPU cycles:3,925/sec
Memory:844 KB
combase.dll
Total CPU:0.00057916%
Kernel CPU:0.00020156%
User CPU:0.00037759%
CPU cycles:8,431/sec
Memory:1.69 MB
WSHost.exe (main module)
Total CPU:0.00056492%
Kernel CPU:0.00026243%
User CPU:0.00030249%
CPU cycles:17,873/sec
Memory:40 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 8 44.00%
Windows 8 Pro 34.00%
Windows 8 Pro with Media Center 14.00%
Windows 8 Enterprise 4.00%
Windows 8 Single Language 2.00%
Windows 8.1 Pro Preview 2.00%

Distribution by countryDistribution by country

United States installs about 65.31% of COM Surrogate.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Toshiba 26.09%
Hewlett-Packard 21.74%
Dell 17.39%
Acer 10.87%
Sony 8.70%
ASUS 8.70%
Intel 4.35%
American Megatrends 2.17%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE