dllhost.exe
COM Surrogate by Microsoft Corporation (Signed)
| Version: | 6.3.9431.0 (winmain_bluemp.130615-1214) |
| MD5: | cf48adb5e601310a577f0d1badd28acb |
| SHA1: | d7370ccfcfe2c28421ad4cce7972e99a3b9d0a74 |
| SHA256: | 2b2ffdb1b6e30a13a924072a12d36c265be5eff567e134741ba892d54a9c9964 |
This is a Windows system installed file with Windows File Protection (WFP) enabled.
What is dllhost.exe?
The COM Surrogate is a fancy name for Sacrificial process for a COM object that is run outside of the process that requested it. Explorer uses the COM Surrogate when extracting thumbnails, for example. If you go to a folder with thumbnails enabled, Explorer will fire off a COM Surrogate and use it to compute the thumbnails for the documents in the folder. It does this because Explorer has learned not to trust thumbnail extractors; they have a poor track record for stability.
Overview
dllhost.exe runs as a service under the name Aplikacja systemowa modelu COM+ (COMSysApp) with extensive SYSTEM privileges (full administrator access) within the context of the Service Host (SvcHost). The file is digitally signed by Microsoft Corporation. and is compiled as a 32 bit program.
Details
| File name: | dllhost.exe |
| Publisher: | Microsoft Corporation |
| Product name: | COM Surrogate |
| Description: | Microsoft® Windows® Operating System |
| Typical file path: | C:\Windows\System32\dllhost.exe |
| File version: | 6.3.9431.0 (winmain_bluemp.130615-1214) |
| Product version: | 6.3.9431.0 |
| Size: | 17.26 KB (17,672 bytes) |
| Build date: | 6/15/2013 3:07 PM |
| Certificate |
| Issued to: | Microsoft Corporation |
| Authority (CA): | Microsoft Corporation |
| Expiration date: | Tuesday, July 9, 2013 |
| Digital DNA |
| PE subsystem: | Windows GUI |
| Entropy: | 4.980855 |
| File packed: | No |
| Code language: | Microsoft Visual C++ |
| .NET CLR: | No |
More details
Behaviors
Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
- 'COMSysApp' (Aplikacja systemowa modelu COM+)
- 'PrlVssProvider'
- Symantec SymSnap VSS Provider
- 'COMSysApp'
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
| CPU |
| Total CPU: | 0.00000285% | |
| Kernel CPU: | 0.00000046% | |
| User CPU: | 0.00000239% | |
| Kernel CPU time: | 16 ms/min | |
| CPU cycles: | 1,022/sec | |
| Memory |
| Private memory: | 1.11 MB | |
| Private (maximum): | 2.41 MB | |
| Private (minimum): | 2.36 MB | |
| Non-paged memory: | 1.11 MB | |
| Virtual memory: | 40.47 MB | |
| Virtual memory (peak): | 41.69 MB | |
| Working set: | 2.39 MB | |
| Working set (peak): | 4.98 MB | |
| Page faults: | 2,515/min | |
| I/O |
| I/O other transfer: | 0 Bytes/sec | |
| I/O other operations: | 1/sec | |
| Resource allocations |
| Threads: | 3 | |
| Handles: | 118 | |
Process properties
| Integrety level: | System |
| Platform: | 32-bit |
| Command line: | C:\Windows\System32\dllhost.exe /processiC:{30d49246-d217-465f-b00b-ac9ddd652eb7} |
| Owner: | SYSTEM |
| Windows Service |
| Service name: | COMSysApp |
| Display name: | Aplikacja systemowa modelu COM+ |
| Description: | “Administra la configuración y el seguimiento de los componentes del Modelo de objetos componentes (COM+). Si se detiene el servicio, la mayoría de los componentes COM+ no funcionarán correctamente. Si se deshabilita este servicio, no se podrá iniciar ningún servicio que dependa específicamente de él.” |
| Type: | Win32OwnProcess |
| Parent process: | svchost.exe (Host Process for Windows Services by Microsoft Corporation) |
Distribution by Windows OS
| OS version | distribution |
| Windows 7 Home Premium |
34.00% |
|
| Windows 8.1 |
19.00% |
|
| Windows 8.1 Pro |
10.00% |
|
| Windows 7 Ultimate |
9.50% |
|
| Windows 8.1 Single Language |
7.00% |
|
| Windows 7 Professional |
5.00% |
|
| Windows 8 Single Language |
3.50% |
|
| Windows 8 |
3.00% |
|
| Windows 8 Pro |
3.00% |
|
| Windows 8.1 Pro with Media Center |
2.00% |
|
| Windows Seven Black Edition |
1.00% |
|
| Windows Vista Home Premium |
1.00% |
|
| Windows 8.1 N |
0.50% |
|
| Windows 8 Enterprise N |
0.50% |
|
| Windows 7 Home Basic |
0.50% |
|
| Windows 8.1 Enterprise Evaluation |
0.50% |
|
Distribution by country
United States installs about 50.51% of COM Surrogate.
Distribution by PC manufacturer
| PC Manufacturer | distribution |
| Dell |
23.17% |
|
| Hewlett-Packard |
17.37% |
|
| ASUS |
13.90% |
|
| Acer |
11.20% |
|
| Toshiba |
10.04% |
|
| Lenovo |
10.04% |
|
| Sony |
7.72% |
|
| Alienware |
2.70% |
|
| Intel |
1.54% |
|
| Samsung |
1.16% |
|
| GIGABYTE |
1.16% |
|