svchost.exe
Host Process for Windows Services by Microsoft Corporation (Signed)
| Version: | 5.2.3790.3959 (srv03_sp2_rtm.070216-1710) |
| MD5: | 46300880a5062a41c16df5e3e836a6c9 |
| SHA1: | 57a6116206e3fe79f15177a891d60c1ef6a01b18 |
| SHA256: | 7ba7e44427b4fdf1d90bb2d5966ed62bb455b5d97102311ebf0ebfe85a766dfd |
This is a Windows system installed file with Windows File Protection (WFP) enabled.
What is svchost.exe?
Host Process for Windows Tasks is a generic process which acts as a host for processes that run from DLLs rather than EXEs. At startup TASKHOST checks the Services portion of the Registry to construct a list of DLL-based services that it needs to load, and then loads them.
Overview
svchost.exe has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. The file is digitally signed by Microsoft Corporation. and is compiled as a 64 bit program.
Details
| File name: | svchost.exe |
| Publisher: | Microsoft Corporation |
| Product name: | Host Process for Windows Services |
| Description: | Microsoft® Windows® Operating System |
| Typical file path: | C:\Windows\System32\svchost.exe |
| Original name: | svchost.exe.mui |
| File version: | 5.2.3790.3959 (srv03_sp2_rtm.070216-1710) |
| Product version: | 5.2.3790.3959 |
| Size: | 25 KB (25,600 bytes) |
| Certificate |
| Issued to: | Microsoft Corporation |
| Authority (CA): | Microsoft Corporation |
| Expiration date: | Friday, June 13, 2014 |
| Digital DNA |
| Entropy: | 5.878473 |
| File packed: | No |
| Code language: | Microsoft Visual C++ |
| .NET CLR: | No |
More details
Behaviors
Services
This is the shared Service Host controller that runs some of the following shared services:
- Service name 'QQPCFixSvc'
- Service name 'Журнал событий Windows'
Drivers
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
- Firewall exception for 'C:\Windows\system32\svchost.exe'
Network connections
Access through an approved Windows firewall exception
[UDP] listens on port 1900
[UDP] listens on port 1286
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
| CPU |
| Total CPU: | 0.00023836% | |
| Kernel CPU: | 0.00014107% | |
| User CPU: | 0.00009729% | |
| Kernel CPU time: | 8,945 ms/min | |
| Context switches: | 17/sec | |
| Memory |
| Private memory: | 6.13 MB | |
| Private (maximum): | 9.84 MB | |
| Private (minimum): | 4.9 MB | |
| Non-paged memory: | 6.13 MB | |
| Virtual memory: | 81.9 MB | |
| Virtual memory (peak): | 119.06 MB | |
| Working set: | 6.59 MB | |
| Working set (peak): | 10.36 MB | |
| Page faults: | 119,522/min | |
| I/O |
| I/O read transfer: | 9.9 KB/sec | |
| I/O read operations: | 5/sec | |
| I/O write transfer: | 23.74 KB/sec | |
| I/O write operations: | 8/sec | |
| I/O other transfer: | 2.27 KB/sec | |
| I/O other operations: | 88/sec | |
| Resource allocations |
| Threads: | 19 | |
| Handles: | 364 | |
| GUI GDI count: | 5 | |
| GUI USER count: | 7 | |
Process properties
| Integrety level: | Undefined |
| Platform: | 64-bit |
| Command lines: |
- C:\Windows\System32\svchost.exe -k localservice
- C:\Windows\System32\svchost.exe -k dcomlaunch
- C:\Windows\System32\svchost.exe -k rpcss
- C:\Windows\System32\svchost.exe -k networkservice
- C:\Windows\System32\svchost.exe -k netsvcs
- C:\Windows\System32\svchost.exe -k imgsvc
- C:\Windows\System32\svchost.exe -k wudfservicegroup
- (8 more)
|
| Owner: | SYSTEM |
| Parent process: | services.exe (by Microsoft) |
Threads
Averages
| ndptsp.tsp |
| Total CPU: | 0.00097868% | |
| Kernel CPU: | 0.00000000% | |
| User CPU: | 0.00097868% | |
| Memory: | 88 KB | |
| msvcp60.dll |
| Total CPU: | 0.00034134% | |
| Kernel CPU: | 0.00034134% | |
| User CPU: | 0.00000000% | |
| Memory: | 936 KB | |
| Normaliz.dll |
| Total CPU: | 0.00000968% | |
| Kernel CPU: | 0.00000726% | |
| User CPU: | 0.00000242% | |
| Memory: | 40 KB | |
| svchost.exe (main module) |
| Total CPU: | 0.00000484% | |
| Kernel CPU: | 0.00000484% | |
| User CPU: | 0.00000000% | |
| Memory: | 36 KB | |
Common loaded modules
These are modules that are typiclaly loaded within the context of this process.
Distribution by Windows OS
| OS version | distribution |
| Windows 8.1 Pro |
100.00% |
|
Distribution by country
Austria installs about 79.00% of Host Process for Windows Services.