Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

8.8.0.975 28.57%
8.8.0.777 28.57%
8.7.0.810 42.86%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
EqualSid, CloseServiceHandle, OpenSCManagerW, OpenServiceW, SetEntriesInAclW, RegisterEventSourceW, ReportEventW, CloseEventLog, RegCloseKey, RegQueryValueExW, InitializeAcl, AddAccessDeniedAce, AddAccessAllowedAce, IsValidSid, GetLengthSid, AllocateAndInitializeSid, RegConnectRegistryW, GetSidIdentifierAuthority, GetSidSubAuthorityCount, GetSidSubAuthority, ImpersonateSelf, OpenThreadToken, GetTokenInformation, RegNotifyChangeKeyValue, RevertToSelf, StartServiceW, QueryServiceLockStatusW, ControlService, QueryServiceStatus, RegOpenKeyExW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, RegSetValueExW, RegCreateKeyExW, CreateProcessAsUserW, OpenProcessToken, GetUserNameW, FreeSid
comctl32.dll
ImageList_Create, ImageList_ReplaceIcon, CreateStatusWindowW
ftcfg.dll
VirusNameListCreate, VirusNameExclusionCreate
gdi32.dll
GetTextMetricsW, CreateDCW, SelectObject, DeleteDC, DeleteObject, GetDeviceCaps, GetObjectW, GetTextExtentPoint32W, CreateFontIndirectW
kernel32.dll
GetLocalTime, LocalFree, LocalUnlock, LocalLock, LocalAlloc, VirtualFreeEx, CreateRemoteThread, VirtualProtectEx, WriteProcessMemory, VirtualAllocEx, GetModuleFileNameW, ExitThread, GetVersion, HeapFree, GetProcessHeap, HeapAlloc, CreateFileW, DeviceIoControl, SetProcessWorkingSetSize, CreateEventW, GetComputerNameW, GlobalGetAtomNameW, GlobalAddAtomW, GetCurrentProcessId, ExitProcess, GlobalDeleteAtom, TerminateProcess, CreateMutexW, SetCurrentDirectoryW, GetWindowsDirectoryW, GetCommandLineW, ExpandEnvironmentStringsW, LoadLibraryExW, GetCurrentThread, FindClose, FindFirstFileW, MulDiv, GetOEMCP, FindNextFileW, FindFirstFileExW, GetSystemDefaultLCID, GetUserDefaultLCID, GetThreadLocale, InterlockedIncrement, InterlockedDecrement, InterlockedExchange, InitializeCriticalSection, DeleteCriticalSection, GetCurrentThreadId, EnterCriticalSection, LeaveCriticalSection, WriteFile, DebugBreak, GetVersionExW, ReadFile, SetNamedPipeHandleState, WaitNamedPipeW, WaitForSingleObject, GetSystemTimeAsFileTime, ResetEvent, FormatMessageW, WaitForMultipleObjects, OpenFileMappingW, MapViewOfFile, UnmapViewOfFile, OpenProcess, GetLastError, OpenEventW, Sleep, SetEvent, FileTimeToLocalFileTime, FileTimeToSystemTime, GetTimeFormatW, GetDateFormatW, CreateProcessW, IsBadReadPtr, GetModuleHandleW, LoadLibraryW, GetProcAddress, FreeLibrary, CreateThread, CloseHandle, GetStartupInfoA, QueryPerformanceCounter, GetTickCount, UnhandledExceptionFilter, GetCurrentProcess, SetUnhandledExceptionFilter
lockdown.dll
LockDownProtectProcessById
lz32.dll
LZRead, LZSeek, LZOpenFileW, LZClose
msvcrt.dll
DllMain
psapi.dll
EnumProcesses, GetModuleFileNameExW
rpcrt4.dll
RpcStringBindingComposeW, NdrClientCall2, RpcBindingFromStringBindingW
shell32.dll
ShellExecuteW, CommandLineToArgvW, Shell_NotifyIconW
shutil.dll
AboutDialogBox2, VseGetLocalMachineAboutInfo, IsWOW64, OMP_FileExists, REG_OpenEx, REG_ConnectComputer, UIP, DisplayCMASchedDialog, OMP_NotifyUser, BetaDialog, REG_QueryValueEx, REG_CloseKey, IsIA64, IsAMD64, GetComponentPath, IsWebBrowserInstalled, Sh_HtmlHelp, LaunchWebHelp, GetGraphicsModuleHandle, REG_SetValueEx, REG_OpenKeyEx, REG_GetOpt, Shutil_SplashScreen
user32.dll
RedrawWindow, GetSystemMenu, SetWindowLongW, GetClassNameW, GetWindowTextW, IsWindow, KillTimer, DialogBoxIndirectParamW, GetDialogBaseUnits, DrawTextW, GetSystemMetrics, SystemParametersInfoW, MessageBoxW, GetLastActivePopup, GetActiveWindow, GetForegroundWindow, GetShellWindow, GetDesktopWindow, FindWindowW, PostMessageW, GetWindowThreadProcessId, EnumWindows, UpdateWindow, DestroyWindow, DefWindowProcW, PostQuitMessage, RegisterClassW, LoadCursorW, RegisterWindowMessageW, GetMenuState, GetMenuDefaultItem, SetMenuDefaultItem, IsChild, EnumChildWindows, SetMenuItemInfoW, GetMenuItemInfoW, GetSubMenu, GetMenuItemID, GetMenuItemCount, EndDialog, IsWindowVisible, IsIconic, LoadStringW, wsprintfW, RemoveMenu, SetWindowTextW, SetActiveWindow, GetDC, ReleaseDC, LoadIconW, LoadAcceleratorsW, CreateDialogParamW, GetMessageW, TranslateAcceleratorW, IsDialogMessageW, TranslateMessage, DispatchMessageW, CreatePopupMenu, TrackPopupMenuEx, DestroyMenu, GetWindowLongW, GetMenuStringW, AppendMenuW, GetMenu, CheckMenuItem, EnableMenuItem, ShowWindow, SetFocus, EnableWindow, SetDlgItemTextW, GetParent, LoadImageW, SendDlgItemMessageW, GetCursorPos, IsWindowEnabled, PtInRect, InvalidateRect, GetClientRect, CreateWindowExW, GetDlgItem, SetWindowPos, GetWindowRect, ScreenToClient, SendMessageW, SetRect, MoveWindow, SetTimer, SetForegroundWindow

shstat.exe

VirusScan Enterprise by McAfee (Signed)

Remove shstat.exe
Version:   8.8.0.777
MD5:   99cbcf9ca57ecaef6f8e078e5287ef14
SHA1:   e8dbee4a22763413a0e6a2133f264ae58200cfcf
SHA256:   2fa7332f6adbf48a342a988dfc474fc4794c8f0bbcb15119d906c0bddd99daeb

What is shstat.exe?

VirusScan tray icon is part of McAfee's enterprise-level product, VirusScan Enterprise, designed this for use on larger networks. It contains features intended to make management of antivirus software on multiple computers easier. Unlike the home-user edition, it consists of a client application - loaded on all networked computers - and a server application, through which the system installs signature and application updates and configures settings for all client programs.

About shstat.exe (from McAfee)

McAfee VirusScan Enterprise combines anti-virus, anti-spyware, firewall, and intrusion prevention technologies to stop and remove malicious software. It also extends coverage to new security risks and

DetailsDetails

File name:shstat.exe
Publisher:McAfee, Inc.
Product name:VirusScan Enterprise
Description:VirusScan tray icon
Typical file path:C:\Program Files\mcafee\virusscan enterprise\shstat.exe
File version:8.8.0.777
Product version:8.8.0
Size:210.31 KB (215,360 bytes)
Certificate
Issued to:McAfee
Authority (CA):VeriSign
Expiration date:Monday, October 10, 2011
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
McAfee, Inc.
7% remove
McAfee produces an enterprise-level product named VirusScan Enterprise: McAfee has designed this for use on larger networks. It contains features intended to make management of antivirus software on multiple computers easier. Unlike the home-user edition, it consists of a client application - loaded on all networked computers - and a server application, through which the system installs signature and application updates and configures s...
McAfee, Inc.
6% remove
The McAfee AntiSpyware Enterprise Module is an add-on to the VirusScan Enterprise product that extends its ability to detect and take action on potentially unwanted spyware and cookies. The module uses the VirusScan Enterprise on-access scanner, on-demand scan task, and unwanted programs policy with the scanning engine and detection definition (DAT) file to protect you from potentially unwanted spyware-related files, registry entries, a...

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'ShStatEXE' → "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00006277%
0.028634%
Kernel CPU:0.00004366%
0.013761%
User CPU:0.00001911%
0.014873%
Kernel CPU time:2,496,016 ms/min
100,923,805ms/min
Memory
Private memory:3.82 MB
21.59 MB
Private (maximum):2.53 MB
Private (minimum):340 KB
Non-paged memory:3.82 MB
21.59 MB
Virtual memory:110.67 MB
140.96 MB
Virtual memory (peak):117.16 MB
169.69 MB
Working set:1.18 MB
18.61 MB
Working set (peak):10.7 MB
37.95 MB
Resource allocations
Threads:10
12
Handles:230
600
GUI GDI count:87
103
GUI GDI peak:90
142
GUI USER count:96
49
GUI USER peak:98
71

BehaviorsProcess properties

Tray notification:Yes
Integrety level:High
Platform:64-bit
Command line:"C:\Program Files\mcafee\virusscan enterprise\shstat.exe" /standalone /nosplash
Owner:User
Parent process:mctray.exe (McAfee System Tray by McAfee)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 42.86%
Windows 7 Professional 42.86%
Windows 8 Enterprise 14.29%

Distribution by countryDistribution by country

United States installs about 42.86% of VirusScan Enterprise.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 60.00%
Toshiba 40.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE