Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.17031 (winblue_gdr.140221-1952) 14.44%
6.3.9600.16384 (winblue_rtm.130821-1623) 9.17%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.28%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.83%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.28%
6.2.9200.16384 (win8_rtm.120725-1247) 66.67%
6.2.9200.16384 (win8_rtm.120725-1247) 7.78%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.28%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.28%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
ConvertStringSecurityDescriptorToSecurityDescriptorW, TraceMessage, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, RegisterTraceGuidsW, UnregisterTraceGuids, RegGetValueW, RegOpenKeyExW, DuplicateToken, EventWrite, SetThreadToken, ConvertSecurityDescriptorToStringSecurityDescriptorW, RegCloseKey
api-ms-win-core-errorhandling-l1-1-1.dll
GetLastError, SetUnhandledExceptionFilter, UnhandledExceptionFilter
api-ms-win-core-handle-l1-1-0.dll
DuplicateHandle, CloseHandle
api-ms-win-core-heap-l1-2-0.dll
HeapFree, HeapAlloc, GetProcessHeap
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalFree
api-ms-win-core-libraryloader-l1-1-1.dll
GetModuleHandleA, FreeLibrary, LoadLibraryExW, GetProcAddress
api-ms-win-core-libraryloader-l1-2-0.dll
GetModuleHandleA, FreeLibrary, LoadLibraryExW, GetProcAddress
api-ms-win-core-processthreads-l1-1-2.dll
OpenProcess, GetCurrentProcess, TerminateProcess, GetCurrentProcessId, GetCurrentThreadId, SetThreadToken
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegGetValueW, RegCloseKey, RegOpenKeyExW
api-ms-win-core-string-l1-1-0.dll
CompareStringOrdinal
api-ms-win-core-synch-l1-2-0.dll
ResetEvent, AcquireSRWLockExclusive, EnterCriticalSection, InitializeSRWLock, LeaveCriticalSection, ReleaseSRWLockExclusive, DeleteCriticalSection, CreateEventW, AcquireSRWLockShared, ReleaseSRWLockShared, SetEvent, Sleep, WaitForSingleObject, InitializeCriticalSection
api-ms-win-core-sysinfo-l1-2-1.dll
GetSystemTimeAsFileTime, GetTickCount
api-ms-win-core-threadpool-l1-2-0.dll
SubmitThreadpoolWork, WaitForThreadpoolWaitCallbacks, WaitForThreadpoolWorkCallbacks, CloseThreadpoolWork, CreateThreadpoolWork, CloseThreadpoolWait, SetThreadpoolWait, CreateThreadpoolWait
api-ms-win-devices-query-l1-1-1.dll
DevGetObjectPropertiesEx, DevFreeObjectProperties
api-ms-win-eventing-classicprovider-l1-1-0.dll
GetTraceLoggerHandle, UnregisterTraceGuids, TraceMessage, RegisterTraceGuidsW, GetTraceEnableLevel, GetTraceEnableFlags
api-ms-win-eventing-provider-l1-1-0.dll
EventWrite
api-ms-win-security-base-l1-2-0.dll
DuplicateToken
api-ms-win-security-sddl-l1-1-0.dll
ConvertStringSecurityDescriptorToSecurityDescriptorW, ConvertSecurityDescriptorToStringSecurityDescriptorW
kernel32.dll
WaitForSingleObject, CloseHandle, CloseThreadpoolWait, CreateThreadpoolWait, SetThreadpoolWait, InitializeSRWLock, AcquireSRWLockExclusive, ReleaseSRWLockExclusive, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, ResetEvent, LeaveCriticalSection, CreateThreadpoolWork, SubmitThreadpoolWork, WaitForThreadpoolWorkCallbacks, CloseThreadpoolWork, OpenProcess, DuplicateHandle, GetCurrentProcess, InterlockedIncrement, InterlockedDecrement, AcquireSRWLockShared, ReleaseSRWLockShared, HeapAlloc, WaitForThreadpoolWaitCallbacks, LocalFree, LoadLibraryExW, FreeLibrary, CompareStringOrdinal, TerminateProcess, UnhandledExceptionFilter, GetTickCount, GetSystemTimeAsFileTime, GetCurrentThreadId, GetCurrentProcessId, QueryPerformanceCounter, GetModuleHandleA, GetProcessHeap, SetUnhandledExceptionFilter, InterlockedCompareExchange, InterlockedExchange, Sleep, HeapFree, SetEvent, CreateEventW, GetLastError, GetProcAddress
msvcrt.dll
DllMain
rpcrt4.dll
NdrMesTypeEncode2, NdrAsyncServerCall, NdrServerCall2, RpcServerUseProtseqEpW, I_RpcMapWin32Status, RpcServerRegisterIf3, RpcServerUnregisterIfEx, RpcAsyncCompleteCall, MesEncodeIncrementalHandleCreate, MesIncrementalHandleReset, RpcExceptionFilter, MesHandleFree, I_RpcBindingInqLocalClientPID, RpcImpersonateClient, RpcRevertToSelf, I_RpcExceptionFilter, UuidFromStringW, NdrMesTypeAlignSize2, RpcSsDestroyClientContext, RpcStringFreeW, RpcStringBindingComposeW, RpcBindingFromStringBindingW, RpcBindingSetOption, RpcBindingFree, NdrClientCall2

dasHost.exe

Device Association Framework Provider Host by Microsoft

Remove dasHost.exe
Version:   6.3.9431.0 (winmain_bluemp.130615-1214)
MD5:   cf56f49e34e4ec1cd2c72a19bd85ced1
SHA1:   337901cc4fade19636a3626a53ac0eb5b97e7aa0
SHA256:   983922d792f7628ddf4d56978ebfa49dbd6de0189848fb3c23a0906e14a7ef61
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is dasHost.exe?

Device Association Framework Provider Host enables pairing between the system and wired or wireless devices. This service is new for Windows 8.

Overview

dashost.exe executes as a process with LOCAL SERVICE privileges typically within the context of its parent svchost.exe (Host Process for Windows Services by Microsoft Corporation). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). and is compiled as a 64 bit program.

DetailsDetails

File name:dashost.exe
Publisher:Microsoft Corporation
Product name:Device Association Framework Provider Host
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\dashost.exe
File version:6.3.9431.0 (winmain_bluemp.130615-1214)
Product version:6.3.9431.0
Size:90 KB (92,160 bytes)
Build date:6/15/2013 3:44 PM
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details
Network connections
  • [UDP] listens on port 63151
  • [UDP] listens on port 58347

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00002600%
    0.028634%
    Kernel CPU:0.00000871%
    0.013761%
    User CPU:0.00001730%
    0.014873%
    Kernel CPU time:708 ms/min
    100,923,805ms/min
    CPU cycles:11,125/sec
    17,470,203/sec
    Memory
    Private memory:3.18 MB
    21.59 MB
    Private (maximum):7.44 MB
    Private (minimum):6.82 MB
    Non-paged memory:3.18 MB
    21.59 MB
    Virtual memory:48.5 MB
    140.96 MB
    Virtual memory (peak):56.99 MB
    169.69 MB
    Working set:7.17 MB
    18.61 MB
    Working set (peak):8.81 MB
    37.95 MB
    Page faults:2,624/min
    2,039/min
    I/O
    I/O write transfer:3 Bytes/sec
    274.99 KB/min
    I/O write operations:1/sec
    227/min
    I/O other transfer:348 Bytes/sec
    448.09 KB/min
    I/O other operations:5/sec
    1,671/min
    Resource allocations
    Threads:3
    12
    Handles:257
    600

    BehaviorsProcess properties

    Integrety level:System
    Platform:64-bit
    Command lines:
    • dashost.exe {c2b6e115-f356-454c-b3b3355a0308524a}
    • dashost.exe {f8987a7b-7552-4347-acf6eb43c6c1e635}
    • dashost.exe {c403aedd-8585-445c-85564b18002d24fc}
    Owner:LOCAL SERVICE
    Parent process:svchost.exe (Host Process for Windows Services by Microsoft Corporation)

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 8 26.50%
    Windows 8.1 23.50%
    Windows 8 Pro 15.50%
    Windows 8.1 Pro 9.50%
    Windows 8 Single Language 5.50%
    Windows 8.1 Single Language 4.50%
    Windows 8 Pro with Media Center 3.50%
    Windows 8.1 Pro with Media Center 3.00%
    Windows 8 Enterprise 2.50%
    Windows 8.1 Enterprise 1.00%
    Windows 8.1 Pro Preview 1.00%
    Windows 8 Pro N 1.00%
    Windows 8.1 N 0.50%
    Windows 8.1 Enterprise Evaluation 0.50%
    Windows 8 Enterprise N 0.50%
    Windows 8 Enterprise Evaluation 0.50%
    Windows 8.1 Single Language Preview 0.50%
    Windows 8.1 Pro Preview with Media Center 0.50%

    Distribution by countryDistribution by country

    United States installs about 40.20% of Device Association Framework Provider Host.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Hewlett-Packard 16.41%
    ASUS 16.03%
    Lenovo 14.50%
    Acer 12.98%
    Dell 12.98%
    Toshiba 12.98%
    Sony 6.11%
    GIGABYTE 2.67%
    Intel 2.29%
    Samsung 1.91%
    Alienware 0.76%
    American Megatrends 0.38%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE