Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 4.76%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.11%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.30%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.03%
6.2.9200.16384 (win8_rtm.120725-1247) 2.67%
6.2.9200.16384 (win8_rtm.120725-1247) 12.52%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.05%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.05%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.03%
6.2.8102.0 (winmain_win8m3.110823-1455) 0.05%
6.1.7600.16385 (win7_rtm.090713-1255) 18.39%
6.1.7600.16385 (win7_rtm.090713-1255) 32.98%
6.1.7600.16385 (win7_rtm.090713-1255) 0.03%
6.1.7600.16384 (win7_rtm.090710-1945) 0.03%
6.0.6000.16386 (vista_rtm.061101-2205) 5.71%
6.0.6000.16386 (vista_rtm.061101-2205) 0.84%
5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.03%
5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.05%
5.1.2600.5512 (xpsp.080413-2108) 14.12%
5.1.2600.5512 (xpsp.080413-2108) 0.95%
5.1.2600.5512 (xpsp.080413-2108) 0.68%
5.1.2600.5512 (xpsp.080413-2108) 0.08%
5.1.2600.5512 (xpsp.080413-2108) 0.65%
5.1.2600.5512 (xpsp.080413-2108) 0.03%
5.1.2600.5512 (xpsp.080413-2108) 0.03%
View more

Relationships


PE structurePE file structure

Show functions
Import table
api-ms-win-core-com-l1-1-0.dll
IIDFromString, CoInitializeEx, CoUninitialize
api-ms-win-core-com-l1-1-1.dll
IIDFromString, CoInitializeEx, CoUninitialize
api-ms-win-core-com-private-l1-1-0.dll
CoRegisterSurrogateEx
api-ms-win-core-errorhandling-l1-1-1.dll
UnhandledExceptionFilter, SetUnhandledExceptionFilter
api-ms-win-core-heap-l1-2-0.dll
HeapSetInformation
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedExchange, InterlockedCompareExchange
api-ms-win-core-libraryloader-l1-1-1.dll
GetModuleHandleA
api-ms-win-core-processthreads-l1-1-1.dll
GetStartupInfoW, TerminateProcess, GetCurrentThreadId, GetCurrentProcessId, GetCurrentProcess
api-ms-win-core-processthreads-l1-1-2.dll
TerminateProcess, GetCurrentProcess, GetStartupInfoW, GetCurrentProcessId, GetCurrentThreadId
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-synch-l1-2-0.dll
Sleep
api-ms-win-core-sysinfo-l1-2-0.dll
GetTickCount, GetSystemTimeAsFileTime
api-ms-win-core-sysinfo-l1-2-1.dll
GetTickCount, GetSystemTimeAsFileTime
kernel32.dll
TerminateProcess, GetCurrentProcess, HeapSetInformation, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, GetStartupInfoW, InterlockedCompareExchange, Sleep, InterlockedExchange, UnhandledExceptionFilter, lstrlenA, GetVersionExW, SetEnvironmentVariableW, MultiByteToWideChar, GetStartupInfoA, lstrcmpiA
msvcrt.dll
DllMain
ntdll.dll
NtSetInformationProcess
ole32.dll
CoInitializeEx, CoRegisterSurrogateEx, CoUninitialize, CLSIDFromString

dllhost.exe

COM Surrogate by Microsoft Corporation (Signed)

Remove dllhost.exe
Version:   6.2.8102.0 (winmain_win8m3.110823-1455)
MD5:   23d06a3aaa6dbcf2f161369b4024977c
SHA1:   87091a6d7be480effdcf09009ecd21d341ee9c73
SHA256:   4f2da287f6fbfe8ccef4b73ffae424e5ebfc1858489d3224b05605c14c12a4c4
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is dllhost.exe?

The COM Surrogate is a fancy name for Sacrificial process for a COM object that is run outside of the process that requested it. Explorer uses the COM Surrogate when extracting thumbnails, for example. If you go to a folder with thumbnails enabled, Explorer will fire off a COM Surrogate and use it to compute the thumbnails for the documents in the folder. It does this because Explorer has learned not to trust thumbnail extractors; they have a poor track record for stability.

Overview

dllhost.exe runs as a service under the name Aplikacja systemowa modelu COM+ (COMSysApp) within the local user context. The file is digitally signed by Microsoft Corporation. This version is installed on Windows 8.

DetailsDetails

File name:dllhost.exe
Publisher:Microsoft Corporation
Product name:COM Surrogate
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\dllhost.exe
File version:6.2.8102.0 (winmain_win8m3.110823-1455)
Product version:6.2.8102.0
Size:8 KB (8,192 bytes)
Build date:8/24/2011 5:43 AM
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Expiration date:Tuesday, July 9, 2013
Digital DNA
PE subsystem:Windows GUI
Entropy:4.980855
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'COMSysApp' (Aplikacja systemowa modelu COM+)
  • 'PrlVssProvider'
  • Symantec SymSnap VSS Provider
  • 'COMSysApp'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 34.00%
Windows 8.1 19.00%
Windows 8.1 Pro 10.00%
Windows 7 Ultimate 9.50%
Windows 8.1 Single Language 7.00%
Windows 7 Professional 5.00%
Windows 8 Single Language 3.50%
Windows 8 3.00%
Windows 8 Pro 3.00%
Windows 8.1 Pro with Media Center 2.00%
Windows Seven Black Edition 1.00%
Windows Vista Home Premium 1.00%
Windows 8.1 N 0.50%
Windows 8 Enterprise N 0.50%
Windows 7 Home Basic 0.50%
Windows 8.1 Enterprise Evaluation 0.50%

Distribution by countryDistribution by country

United States installs about 50.51% of COM Surrogate.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 23.17%
Hewlett-Packard 17.37%
ASUS 13.90%
Acer 11.20%
Toshiba 10.04%
Lenovo 10.04%
Sony 7.72%
Alienware 2.70%
Intel 1.54%
Samsung 1.16%
GIGABYTE 1.16%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE