Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

12.1.2015.2015 5.26%
12.1.2015.2015 5.26%
12.1.1000.157 21.05%
12.1.671.4971 5.26%
12.0.122.161 5.26%
11.0.6200.530 5.26%
11.0.6200.530 5.26%
11.0.6100.480 5.26%
11.0.6005.440 5.26%
11.0.6005.440 10.53%
11.0.6000.436 5.26%
11.0.5002.301 5.26%
11.0.4014.23 5.26%
11.0.4000.2261 5.26%
11.0.780.980 5.26%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
IsValidSecurityDescriptor, RegDeleteKeyA, RegDeleteValueA, RegEnumKeyA, FreeSid, IsValidSid, RegQueryValueExA, RegOpenKeyExA, LookupAccountSidA, GetTokenInformation, CreateProcessAsUserA, SetTokenInformation, DuplicateTokenEx, OpenProcessToken, RegCloseKey, RegSetValueExA, RegCreateKeyExA, GetSecurityInfo, AllocateAndInitializeSid, GetLengthSid, InitializeAcl, AddAccessDeniedAce, AddAccessAllowedAce, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegEnumValueA, RegQueryInfoKeyA, LookupPrivilegeValueA, AdjustTokenPrivileges, CheckTokenMembership, RegQueryValueExW, SetNamedSecurityInfoA, EqualSid, GetSidIdentifierAuthority, GetSidSubAuthorityCount, GetSidSubAuthority
kernel32.dll
InterlockedCompareExchange, RaiseException, GetSystemInfo, HeapAlloc, GetProcessHeap, HeapFree, InterlockedExchange, DebugBreak, LocalAlloc, UnhandledExceptionFilter, SetUnhandledExceptionFilter, QueryPerformanceCounter, HeapDestroy, HeapReAlloc, HeapSize, IsDebuggerPresent, GetCurrentThread, GetFileAttributesExA, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, GetFileAttributesW, LoadLibraryExW, GetWindowsDirectoryA, CompareFileTime, GetPrivateProfileStringA, OutputDebugStringA, FormatMessageA, LocalFree, GetUserDefaultLangID, FindNextFileA, GetModuleFileNameA, GetLocaleInfoA, GetSystemDirectoryA, InterlockedDecrement, InterlockedIncrement, FileTimeToSystemTime, FileTimeToLocalFileTime, FindClose, FindFirstFileA, FindResourceExA, FindFirstChangeNotificationA, FindNextChangeNotification, DuplicateHandle, GetCurrentProcess, LoadLibraryA, GetExitCodeProcess, Sleep, TerminateProcess, WriteFile, GetModuleHandleA, GetTempFileNameA, GetTempPathA, OpenProcess, Process32Next, ProcessIdToSessionId, Process32First, CreateToolhelp32Snapshot, CreateProcessA, GetVersionExA, SetCurrentDirectoryA, CreateFileA, FindResourceA, LoadResource, LockResource, SizeofResource, WideCharToMultiByte, GetTickCount, GetSystemTimeAsFileTime, TerminateThread, WaitForSingleObject, OpenEventA, GetSystemTime, WaitForMultipleObjectsEx, GetCurrentThreadId, CreateEventA, FindCloseChangeNotification, CloseHandle, DeleteFileA, GetLastError, GetSystemDefaultLangID, ResetEvent, SetEvent, GetProcAddress, FreeLibrary, GetCurrentProcessId, GetACP, CopyFileA, SetFileAttributesA, RemoveDirectoryA, GetStartupInfoA, GetFileAttributesA, CreateDirectoryA, lstrcpynA, GetShortPathNameW, GetStringTypeExW, GetStringTypeExA, GetEnvironmentVariableW, GetEnvironmentVariableA, lstrcmpiW, lstrcmpiA, CompareStringW, CompareStringA, lstrlenW, GetVersion, MultiByteToWideChar, SetLastError, GetThreadLocale, SleepEx, GetExitCodeThread, GlobalFree, GlobalAlloc, lstrcpyA, lstrlenA, LoadLibraryExA, CreateFileW, EncodePointer, DecodePointer, InitializeCriticalSectionAndSpinCount, FindResourceExW, FindResourceW, ResumeThread
msvcp100.dll
DllMain
msvcp80.dll
DllMain
msvcp90.dll
DllMain
msvcr100.dll
DllMain
msvcr80.dll
DllMain
msvcr90.dll
DllMain
setupapi.dll
SetupIterateCabinetA
shell32.dll
SHGetSpecialFolderPathA, ShellExecuteA, ShellExecuteExA
shlwapi.dll
PathAddBackslashW, PathAddBackslashA, PathRemoveBackslashA
user32.dll
GetWindow, GetTopWindow, FindWindowExA, GetWindowTextA, MessageBoxA, CharNextA, WaitForInputIdle, LoadStringA, wsprintfA, EnumWindows, GetClassNameA, FindWindowA, ExitWindowsEx, CharUpperW, CharUpperA, CharLowerW, CharLowerA, GetUserObjectInformationA, GetProcessWindowStation
version.dll
GetFileVersionInfoSizeA, VerQueryValueA, GetFileVersionInfoA
Export table
GetFactory
GetObjectCount

SgHI.dll

Symantec CMC Host Integrity by Symantec Corporation (Signed)

Remove SgHI.dll
Version:   11.0.6200.530
MD5:   05d27987378e6d98dcc26abe399cc013
SHA1:   f3b1478e574583e7e7cd5775203d7051846b2391
SHA256:   3d8fcb8b385d4e55e5ba13059e85b6472ea8d1278b6aa01ae5e9e387f47b9739

Overview

sghi.dll is loaded as dynamic link library that runs in the context of a process. The file is digitally signed by Symantec Corporation which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:sghi.dll
Publisher:Symantec Corporation
Product name:Symantec CMC Host Integrity
Description:Symantec CMC HI SgHI
Typical file path:C:\Program Files\symantec\symantec endpoint protection\12.1.1000.157.105\bin\sghi.dll
File version:11.0.6200.530
Size:685.86 KB (702,320 bytes)
Build date:11/12/2010 10:10 AM
Certificate
Issued to:Symantec Corporation
Authority (CA):VeriSign
Effective date:Wednesday, September 8, 2010
Expiration date:Sunday, November 24, 2013
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 9.0
.NET CLR:No
More details

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 47.37%
Windows 7 Home Premium 26.32%
Windows 7 Ultimate 5.26%
Windows 7 Enterprise 5.26%
Windows 7 Starter 5.26%
Windows Vista Ultimate 5.26%
Windows 7 Professional 5.26%

Distribution by countryDistribution by country

United States installs about 55.56% of Symantec CMC Host Integrity.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 40.00%
Hewlett-Packard 15.00%
Lenovo 10.00%
Toshiba 10.00%
Intel 10.00%
ASUS 10.00%
Acer 5.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE