Should I block it?

No, this file is 100% safe to run.

Relationships

Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegDeleteKeyA, AdjustTokenPrivileges, FreeSid, AllocateAndInitializeSid, LookupPrivilegeValueW, EqualSid, GetTokenInformation, OpenProcessToken, StartServiceW, OpenServiceW, OpenSCManagerW, CloseServiceHandle, RegCreateKeyExA, RegEnumKeyExA, RegSetValueExA, RegCloseKey, RegOpenKeyExA, RegQueryValueExA
gdi32.dll
GetStockObject, GetDeviceCaps
kernel32.dll
TlsSetValue, GetCurrentThreadId, TlsAlloc, TlsFree, lstrlenA, lstrcatA, GetModuleFileNameA, GetModuleHandleA, lstrcpyA, GetCurrentProcess, GlobalAlloc, GlobalFree, FindClose, InterlockedExchange, CompareStringA, GetWindowsDirectoryA, GetSystemDirectoryA, LoadLibraryA, SetLastError, FlushFileBuffers, TlsGetValue, IsBadCodePtr, QueryPerformanceCounter, IsBadReadPtr, SetFilePointer, GetStringTypeA, LCMapStringA, GetOEMCP, SetUnhandledExceptionFilter, GetFileType, SetHandleCount, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStdHandle, WriteFile, HeapSize, UnhandledExceptionFilter, TerminateProcess, CreateThread, SetStdHandle, GetCurrentProcessId, ReleaseMutex, InterlockedDecrement, InterlockedIncrement, Sleep, LocalFree, DeleteCriticalSection, LocalAlloc, EnterCriticalSection, MulDiv, LeaveCriticalSection, GetLocaleInfoA, InitializeCriticalSection, FreeLibrary, CloseHandle, GetThreadLocale, GetLastError, GetACP, WaitForSingleObject, GetTickCount, ExitProcess, IsBadWritePtr, VirtualFree, HeapCreate, HeapDestroy, RaiseException, RtlUnwind, GetVersionExA, GetCommandLineA, GetStartupInfoA, GetSystemTimeAsFileTime, HeapReAlloc, VirtualQuery, GetSystemInfo, VirtualAlloc, VirtualProtect, ExitThread, HeapAlloc, HeapFree
ole32.dll
GetRunningObjectTable, CoUninitialize, CoInitialize, CoGetClassObject, CreateClassMoniker, CoTaskMemFree, CoCreateInstance, CoTaskMemAlloc, CoInitializeSecurity, CoDisconnectObject, CoRevokeClassObject, CoRegisterClassObject, StringFromCLSID
user32.dll
PostQuitMessage, GetWindow, CopyRect, GetDlgCtrlID, SetWindowPos, GetDesktopWindow, EndDialog, GetDlgItem, ReleaseDC, OffsetRect, GetDC, SetFocus, GetParent, SetForegroundWindow, CharNextA, CallNextHookEx, UnhookWindowsHookEx, GetSystemMetrics, SetTimer, ExitWindowsEx, KillTimer, DestroyWindow, TranslateMessage, MsgWaitForMultipleObjects, GetWindowRect

McVsShld.exe

McAfee VirusScan by McAfee

Remove McVsShld.exe
Version:   10, 0, 0, 22
MD5:   b154ac6dbd82f96476003e58e1625bd8
SHA1:   a3679a57b3133aa22fe1b78739e7102596361751

Overview

mcvsshld.exe executes as a process with the local user's privileges. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). This particular version is usually found on Microsoft Windows XP (5.1.2600.131072).

DetailsDetails

File name:mcvsshld.exe
Publisher:McAfee, Inc.
Product name:McAfee VirusScan
Description:McAfee VirusScan ActiveShield Resource
Typical file path:C:\Program Files\mcafee.com\vso\mcvsshld.exe
File version:10, 0, 0, 22
Product version:10, 0, 0, 0
Size:160 KB (163,840 bytes)
Build date:8/10/2005 3:49 PM
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'VirusScan Online' → C:\Program Files1\mcafee.com\vso\mcvsshld.exe

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00141322%
0.028634%
Kernel CPU:0.00065225%
0.013761%
User CPU:0.00076096%
0.014873%
Kernel CPU time:60 ms/min
100,923,805ms/min
Memory
Private memory:2.82 MB
21.59 MB
Private (maximum):5.95 MB
Private (minimum):80 KB
Non-paged memory:2.82 MB
21.59 MB
Virtual memory:41.83 MB
140.96 MB
Virtual memory (peak):45.83 MB
169.69 MB
Working set:1.61 MB
18.61 MB
Working set (peak):5.95 MB
37.95 MB
Page faults:2,759/min
2,039/min
I/O
I/O read transfer:774 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:30 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:317 Bytes/sec
448.09 KB/min
I/O other operations:12/sec
1,671/min
Resource allocations
Threads:2
12
Handles:131
600
GUI GDI count:11
103
GUI USER count:4
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command line:"C:\Program Files\mcafee.com\vso\mcvsshld.exe" -embedding
Owner:User
Parent process:svchost.exe (Generic Host Process for Win32 Services by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE