Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

12.1.2015.2015 5.26%
12.1.2015.2015 5.26%
12.1.1000.157 21.05%
12.1.671.4971 5.26%
12.0.122.161 5.26%
11.0.6200.530 5.26%
11.0.6200.530 5.26%
11.0.6100.480 5.26%
11.0.6005.440 5.26%
11.0.6005.440 10.53%
11.0.6000.436 5.26%
11.0.5002.301 5.26%
11.0.4014.23 5.26%
11.0.4000.2261 5.26%
11.0.780.980 5.26%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
IsValidSecurityDescriptor, RegDeleteKeyA, RegDeleteValueA, RegEnumKeyA, FreeSid, IsValidSid, RegQueryValueExA, RegOpenKeyExA, LookupAccountSidA, GetTokenInformation, CreateProcessAsUserA, SetTokenInformation, DuplicateTokenEx, OpenProcessToken, RegCloseKey, RegSetValueExA, RegCreateKeyExA, GetSecurityInfo, AllocateAndInitializeSid, GetLengthSid, InitializeAcl, AddAccessDeniedAce, AddAccessAllowedAce, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegEnumValueA, RegQueryInfoKeyA, LookupPrivilegeValueA, AdjustTokenPrivileges, CheckTokenMembership, RegQueryValueExW, SetNamedSecurityInfoA, EqualSid, GetSidIdentifierAuthority, GetSidSubAuthorityCount, GetSidSubAuthority
kernel32.dll
InterlockedCompareExchange, RaiseException, GetSystemInfo, HeapAlloc, GetProcessHeap, HeapFree, InterlockedExchange, DebugBreak, LocalAlloc, UnhandledExceptionFilter, SetUnhandledExceptionFilter, QueryPerformanceCounter, HeapDestroy, HeapReAlloc, HeapSize, IsDebuggerPresent, GetCurrentThread, GetFileAttributesExA, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, GetFileAttributesW, LoadLibraryExW, GetWindowsDirectoryA, CompareFileTime, GetPrivateProfileStringA, OutputDebugStringA, FormatMessageA, LocalFree, GetUserDefaultLangID, FindNextFileA, GetModuleFileNameA, GetLocaleInfoA, GetSystemDirectoryA, InterlockedDecrement, InterlockedIncrement, FileTimeToSystemTime, FileTimeToLocalFileTime, FindClose, FindFirstFileA, FindResourceExA, FindFirstChangeNotificationA, FindNextChangeNotification, DuplicateHandle, GetCurrentProcess, LoadLibraryA, GetExitCodeProcess, Sleep, TerminateProcess, WriteFile, GetModuleHandleA, GetTempFileNameA, GetTempPathA, OpenProcess, Process32Next, ProcessIdToSessionId, Process32First, CreateToolhelp32Snapshot, CreateProcessA, GetVersionExA, SetCurrentDirectoryA, CreateFileA, FindResourceA, LoadResource, LockResource, SizeofResource, WideCharToMultiByte, GetTickCount, GetSystemTimeAsFileTime, TerminateThread, WaitForSingleObject, OpenEventA, GetSystemTime, WaitForMultipleObjectsEx, GetCurrentThreadId, CreateEventA, FindCloseChangeNotification, CloseHandle, DeleteFileA, GetLastError, GetSystemDefaultLangID, ResetEvent, SetEvent, GetProcAddress, FreeLibrary, GetCurrentProcessId, GetACP, CopyFileA, SetFileAttributesA, RemoveDirectoryA, GetStartupInfoA, GetFileAttributesA, CreateDirectoryA, lstrcpynA, GetShortPathNameW, GetStringTypeExW, GetStringTypeExA, GetEnvironmentVariableW, GetEnvironmentVariableA, lstrcmpiW, lstrcmpiA, CompareStringW, CompareStringA, lstrlenW, GetVersion, MultiByteToWideChar, SetLastError, GetThreadLocale, SleepEx, GetExitCodeThread, GlobalFree, GlobalAlloc, lstrcpyA, lstrlenA, LoadLibraryExA, CreateFileW, EncodePointer, DecodePointer, InitializeCriticalSectionAndSpinCount, FindResourceExW, FindResourceW, ResumeThread
msvcp100.dll
DllMain
msvcp80.dll
DllMain
msvcp90.dll
DllMain
msvcr100.dll
DllMain
msvcr80.dll
DllMain
msvcr90.dll
DllMain
setupapi.dll
SetupIterateCabinetA
shell32.dll
SHGetSpecialFolderPathA, ShellExecuteA, ShellExecuteExA
shlwapi.dll
PathAddBackslashW, PathAddBackslashA, PathRemoveBackslashA
user32.dll
GetWindow, GetTopWindow, FindWindowExA, GetWindowTextA, MessageBoxA, CharNextA, WaitForInputIdle, LoadStringA, wsprintfA, EnumWindows, GetClassNameA, FindWindowA, ExitWindowsEx, CharUpperW, CharUpperA, CharLowerW, CharLowerA, GetUserObjectInformationA, GetProcessWindowStation
version.dll
GetFileVersionInfoSizeA, VerQueryValueA, GetFileVersionInfoA
Export table
GetFactory
GetObjectCount

SgHI.dll

Symantec CMC Host Integrity by Symantec Corporation (Signed)

Remove SgHI.dll
Version:   12.1.1000.157
MD5:   ab10db5296ec0df0b95cd6d52d71424a
SHA1:   646ec4b8b2affc5f72e974321ea8043f64dbef29
SHA256:   3a5a84cb4d1c558a51ee91271992d2d6a69de96aff486710f257eded8bb09b36

Overview

sghi.dll is loaded as dynamic link library that runs in the context of a process. The file is digitally signed by Symantec Corporation which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:sghi.dll
Publisher:Symantec Corporation
Product name:Symantec CMC Host Integrity
Description:Symantec CMC HI SgHI
Typical file path:C:\Program Files\symantec\symantec endpoint protection\12.1.1000.157.105\bin\sghi.dll
File version:12.1.1000.157
Size:433.92 KB (444,336 bytes)
Certificate
Issued to:Symantec Corporation
Authority (CA):VeriSign
Effective date:Wednesday, September 8, 2010
Expiration date:Sunday, November 24, 2013
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 9.0
.NET CLR:No
More details

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 47.37%
Windows 7 Home Premium 26.32%
Windows 7 Ultimate 5.26%
Windows 7 Enterprise 5.26%
Windows 7 Starter 5.26%
Windows Vista Ultimate 5.26%
Windows 7 Professional 5.26%

Distribution by countryDistribution by country

United States installs about 55.56% of Symantec CMC Host Integrity.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 40.00%
Hewlett-Packard 15.00%
Lenovo 10.00%
Toshiba 10.00%
Intel 10.00%
ASUS 10.00%
Acer 5.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE