Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

3,6,6,129 1.54%
3,6,4,128 1.54%
3,6,4,127 1.54%
3,6,3,330 7.69%
3,6,3,330 7.69%
3,6,2,124 7.69%
3,6,0,137 13.85%
3,6,0,137 23.08%
3,6,0,134 1.54%
3,6,0,134 1.54%
3,5,0,159 13.85%
3,5,0,159 10.77%
3,4,1,118 1.54%
3,4,1,118 1.54%
3,3,1,102 1.54%
2,9,0,242 1.54%
2,8,0,306 1.54%

Relationships

Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
StartServiceW, GetAce, AddAce, GetAclInformation, InitializeAcl, AddAccessAllowedAce, GetTokenInformation, OpenThreadToken, OpenProcessToken, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup, IsValidSid, GetLengthSid, CopySid, SetSecurityDescriptorOwner, InitializeSecurityDescriptor, StartServiceCtrlDispatcherW, OpenSCManagerW, QueryServiceConfigW, OpenServiceW, ChangeServiceConfig2W, CreateServiceW, DeleteService, LockServiceDatabase, ControlService, QueryServiceStatus, ChangeServiceConfigW, CloseServiceHandle, UnlockServiceDatabase, RegDeleteValueW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegQueryValueExW, RegSetValueExW, CreateProcessAsUserW, DuplicateTokenEx, RegEnumValueW, ConvertSidToStringSidW, RegisterServiceCtrlHandlerExW, RegEnumKeyExW, RegQueryInfoKeyW, RegDeleteKeyW, RegOpenKeyW, RegCreateKeyW, GetSecurityDescriptorLength, RegSetValueExA, ConvertStringSecurityDescriptorToSecurityDescriptorW, SetServiceStatus, RegisterEventSourceW, ReportEventW, DeregisterEventSource, LookupAccountNameW
crypt32.dll
CryptMsgClose, CertFreeCertificateChain, CertGetSubjectCertificateFromStore, CryptMsgGetParam, CryptQueryObject, CertGetNameStringW, CertVerifyCertificateChainPolicy, CertGetCertificateChain, CertGetCertificateContextProperty, CryptDecodeObject, CertCloseStore, CertFreeCertificateContext
kernel32.dll
GetCurrentThread, GetCurrentProcess, FreeLibrary, LoadLibraryW, GetProcAddress, CloseHandle, GetTickCount, CreateDirectoryW, lstrlenW, Sleep, GetFileAttributesExW, GetLastError, GetModuleFileNameW, CreateFileA, ReadFile, GetProcessHeap, SetEndOfFile, GetStringTypeW, GetStringTypeA, LCMapStringW, HeapAlloc, HeapFree, GetStartupInfoW, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, VirtualFree, VirtualAlloc, HeapReAlloc, HeapCreate, GetModuleHandleW, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, RtlUnwind, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, GetCurrentThreadId, InterlockedDecrement, HeapSize, RaiseException, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, SetHandleCount, GetFileType, GetStartupInfoA, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, InitializeCriticalSectionAndSpinCount, LoadLibraryA, SetStdHandle, WideCharToMultiByte, GetConsoleCP, GetConsoleMode, FlushFileBuffers, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, MultiByteToWideChar, CreateFileW, GetLocaleInfoA, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetFilePointer, LCMapStringA, IsBadCodePtr, IsBadReadPtr, WaitForMultipleObjects, CreateProcessW, OpenProcess, lstrcmpW, GetUserDefaultLangID, GetUserDefaultLCID, GetSystemDefaultLangID, GetCommandLineA, GetEnvironmentStrings, FreeEnvironmentStringsA, lstrlenA, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, SetEvent, CreateEventW, CreateThread, InitializeCriticalSection, WaitForSingleObject, GetModuleHandleA, GetThreadLocale, InterlockedExchange, HeapDestroy, SetCurrentDirectoryW, LocalFree, LoadLibraryExW, OutputDebugStringW, lstrcmpiW, GetVersionExW, GetVersionExA, GetSystemDefaultLCID, OpenEventW, GetExitCodeProcess, ReadConsoleW, SetFilePointerEx, EncodePointer, DecodePointer, GetModuleHandleExW, IsProcessorFeaturePresent
ole32.dll
CoInitializeEx, CoInitializeSecurity, CoUninitialize, CoCreateInstance, CoResumeClassObjects, CoRegisterClassObject, CoSuspendClassObjects, CoTaskMemAlloc, CoTaskMemRealloc, CoTaskMemFree, StringFromGUID2, CoImpersonateClient, CoRevertToSelf, CoRevokeClassObject
shell32.dll
SHGetSpecialFolderPathW
shlwapi.dll
StrCatW, StrStrIW, StrRChrW, StrSpnW, StrCmpW
urlmon.dll
CoInternetParseUrl
user32.dll
CharUpperW, CharNextW, UnregisterClassA, MessageBoxW, CharLowerBuffW, LoadStringW, PostThreadMessageW, GetMessageW, DispatchMessageW, TranslateMessage, MsgWaitForMultipleObjects, PeekMessageW
userenv.dll
CreateEnvironmentBlock
wintrust.dll
WinVerifyTrust
wtsapi32.dll
WTSEnumerateProcessesW, WTSFreeMemory

mcsacore.exe

McAfee SiteAdvisor by McAfee (Signed)

Remove mcsacore.exe
Version:   3,6,6,129
MD5:   f55dc86cc087421f7105966c1a5c0372
SHA1:   b21a57b98573369abb93ad54362669c0206850a3

What is mcsacore.exe?

SiteAdvisor is a service that reports on the safety of web sites by crawling the web and testing the sites it finds for malware and spam. The functionality of SiteAdvisor can be accessed either through a Browser Plugin or by submitting a URL to the website. SiteAdvisor only rates sites based on the risk of malware or spam.

About mcsacore.exe (from McAfee)

McAfee SiteAdvisor software is a free browser plug-in that provides simple Web site safety ratings and a Secure Search box so you can surf, search and shop more safely. With SiteAdvisor software insta

DetailsDetails

File name:McSACore.exe
Publisher:McAfee, Inc.
Product name:McAfee SiteAdvisor
Description:SiteAdvisor
Typical file path:C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
File version:3,6,6,129
Product version:3,6,6,0
Size:137.13 KB (140,424 bytes)
Build date:4/23/2014 6:55 PM
Certificate
Issued to:McAfee
Authority (CA):VeriSign
Expiration date:Tuesday, December 31, 2013
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
McAfee, Inc.
10% remove
SiteAdvisor is a service that reports on the safety of web sites by crawling the web and testing the sites it finds for malware and spam. A paid version of McAfee SiteAdvisor, McAfee SiteAdvisor Plus, has extra features. The functionality of SiteAdvisor can be accessed either through a Browser Plugin or by submitting a URL to the website. In addition to selling to the end consumers, McAfee also sells to the web site owners with their Mc...
McAfee, Inc.
40% remove

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'McAfee SiteAdvisor Service'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00034600%
0.028634%
Kernel CPU:0.00019222%
0.013761%
User CPU:0.00015378%
0.014873%
Kernel CPU time:390,625 ms/min
100,923,805ms/min
Memory
Private memory:15.75 MB
21.59 MB
Private (maximum):5.2 MB
Private (minimum):4.11 MB
Non-paged memory:15.75 MB
21.59 MB
Virtual memory:144.02 MB
140.96 MB
Virtual memory (peak):148.05 MB
169.69 MB
Working set:4.36 MB
18.61 MB
Working set (peak):15.59 MB
37.95 MB
Resource allocations
Threads:26
12
Handles:769
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:"C:\Program Files\mcafee\siteadvisor\mcsacore.exe"
Owner:User
Windows Service
Service name:McAfee SiteAdvisor Service
Description:“McAfee SiteAdvisor Service”
Type:Win32OwnProcess

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 30.77%
Microsoft Windows XP 16.92%
Windows Vista Home Premium 15.38%
Windows 7 Professional 7.69%
Windows 8 6.15%
Windows 7 Home Basic 4.62%
Windows 7 Ultimate 4.62%
Windows 8.1 3.08%
Windows 8 Pro 3.08%
Windows 8.1 Single Language 1.54%
Windows Vista Home Basic 1.54%
Windows 7 Starter 1.54%
Windows 7 Ultimate N 1.54%
Windows 8 Release Preview 1.54%

Distribution by countryDistribution by country

United States installs about 51.56% of McAfee SiteAdvisor.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 38.96%
Hewlett-Packard 18.18%
Sony 15.58%
Lenovo 10.39%
ASUS 5.19%
Acer 3.90%
GIGABYTE 2.60%
American Megatrends 2.60%
NEC 2.60%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE