File details
File name: mcsvhost.exe
Name: McAfee Shared Service Host
Description: McAfee Service Host
Version: 2,6,259,0
Product version: 2,6,0,0
Size: 196.59 KB
Original file name: McSvHost.exe
Digital certificate
Certificate authority:
VeriSign
Expiration date: 12/31/2013
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0033768109%
Privileged CPU:
0.0015614021%

User CPU:
0.00181540883849%

Privileged CPU time: 73846252.63 ms
Privileged CPU time /min: 32,336 ms
CPU cycle count:
160,734,111
CPU cycle count /min: 326,965,898
Context switches /sec:
63
 | Memory utilization averages |
Committed memory:
291.14 MB
Peak committed memory: 342.37 MB
Paged memory:
47.16 MB
Peak paged memory: 56.43 MB
Paged system memory:
380.59 KB
Non-paged system memory: 106.56 KB
Working set memory:
17.02 MB
Peak working set memory: 40.87 MB
Min working set memory: 3.31 MB
Private memory:
47.16 MB
Page faults:
2,839,844
Page faults /min: 1,645
 | Process I/O averages |
Total read operations:
179,046
Read operations /min: 95
Total read transfer: 413.09 MB
Read transfer /min: 326.08 KB
Total write operations:
61,698
Write operations /min: 23
Total write transfer: 83.5 MB
Write transfer /min: 38.99 KB
Total other operations:
4,195,292
Other operations /min: 1,395
Total other transfer: 155.88 MB
Other Transfer /min: 51.98 KB
Resources
Handle count average: 1,142
Thread count average: 70
Thread resource averages
ntdll.dll

Total CPU: 0.046293611529%
Privileged CPU: 0.025249930812%
User CPU: 0.021043680716%
CPU Cycle count /sec: 911,704
Module memory size: 1.74 MB
ntdll.dll

Total CPU: 0.039140404984%
Privileged CPU: 0.025493453998%
User CPU: 0.013646950986%
CPU Cycle count /sec: 591,786
Context switches /sec: 1
Module memory size: 1.75 MB
ole32.dll

Total CPU: 0.037605563370%
Privileged CPU: 0.024482288971%
User CPU: 0.013123274399%
CPU Cycle count /sec: 822,827
Module memory size: 2.01 MB
combase.dll

Total CPU: 0.036130129992%
Privileged CPU: 0.022361079772%
User CPU: 0.013769050220%
CPU Cycle count /sec: 638,256
Module memory size: 1.69 MB
ntdll.dll

Total CPU: 0.032281207112%
Privileged CPU: 0.021526454197%
User CPU: 0.010754752915%
CPU Cycle count /sec: 328,050
Context switches /sec: 26
Module memory size: 1.66 MB
ntdll.dll

Total CPU: 0.029309324032%
Privileged CPU: 0.023716174324%
User CPU: 0.005593149708%
CPU Cycle count /sec: 807,527
Context switches /sec: 1
Module memory size: 1.66 MB
ole32.dll

Total CPU: 0.010336962684%
Privileged CPU: 0.006384099170%
User CPU: 0.003952863514%
CPU Cycle count /sec: 219,953
Module memory size: 2.01 MB
msvcr100.dll

Total CPU: 0.010143950123%
Privileged CPU: 0.006131568102%
User CPU: 0.004012382021%
CPU Cycle count /sec: 243,183
Module memory size: 840 KB
Total CPU: 0.007750466136%
Privileged CPU: 0.002631775344%
User CPU: 0.005118690792%
CPU Cycle count /sec: 310,954
Context switches /sec: 6
Module memory size: 216 KB
Total CPU: 0.007046687502%
Privileged CPU: 0.002932001959%
User CPU: 0.004114685543%
CPU Cycle count /sec: 232,948
Context switches /sec: 5
Module memory size: 216 KB
msvcr100.dll

Total CPU: 0.006620164256%
Privileged CPU: 0.003268929179%
User CPU: 0.003351235077%
CPU Cycle count /sec: 160,238
Module memory size: 840 KB
mfefwctl.dll

Total CPU: 0.005409652555%
Privileged CPU: 0.002612774046%
User CPU: 0.002796878509%
CPU Cycle count /sec: 207,703
Context switches /sec: 3
Module memory size: 216 KB
Total CPU: 0.003859426887%
Privileged CPU: 0.002245105194%
User CPU: 0.001614321693%
CPU Cycle count /sec: 82,303
Module memory size: 868 KB
Total CPU: 0.003748484731%
Privileged CPU: 0.002290200193%
User CPU: 0.001458284538%
CPU Cycle count /sec: 51,417
Module memory size: 940 KB
msksrvr.dll

Total CPU: 0.003527984509%
Privileged CPU: 0.000162798351%
User CPU: 0.003365186158%
CPU Cycle count /sec: 80,655
Module memory size: 64 KB
Total CPU: 0.003215482911%
Privileged CPU: 0.001324683798%
User CPU: 0.001890799114%
CPU Cycle count /sec: 120,706
Context switches /sec: 1
Module memory size: 216 KB
Total CPU: 0.001840842517%
Privileged CPU: 0.001194252255%
User CPU: 0.000646590262%
CPU Cycle count /sec: 40,969
Module memory size: 640 KB
mswsock.dll

Total CPU: 0.001738296354%
Privileged CPU: 0.001332131208%
User CPU: 0.000406165146%
CPU Cycle count /sec: 7,882
Module memory size: 368 KB
Total CPU: 0.001655286079%
Privileged CPU: 0.001069112550%
User CPU: 0.000586173529%
CPU Cycle count /sec: 42,846
Module memory size: 2.35 MB
mswsock.dll

Total CPU: 0.001541374502%
Privileged CPU: 0.001443571240%
User CPU: 0.000097803263%
CPU Cycle count /sec: 6,400
Module memory size: 340 KB
Process details
Runs as (owner): User
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Processes
Child Processes
Process Commands
"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc
"C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc
Service details
Name: HomeNetSvc
Network connectivity
UDP: LISTENING on port 6646
TCP: localhost on port 6646
UDP: LISTENING on port 6646
TCP: 161.69.92.7 on port 61138
UDP: LISTENING on port 6646
UDP: LISTENING on port 6646
TCP: 8.18.25.7 on port 64925
UDP: LISTENING on port 6646
TCP: 161.69.92.7 on port 60773
UDP: LISTENING on port 6646
TCP: 8.21.161.7 on port 52488
UDP: LISTENING on port 6646
Windows Firewall allowed program: Yes
Image hashes
MD5: f928e5e72bba15dd0ce9a26e0413d236
SHA-1: 0b5940cd3313354fb08e3263d2b3d79d749a4b9b
SHA-256: d63efa1408084f524464729c2f3be16550e07ace2bf8a00699a8438079ad381b
PE image details
Subsystem: Windows Console
Langauge*: Microsoft Visual C++ 10.0
File packed: No
Import Table
advapi32.dll

RegQueryValueExA
CopySid
GetLengthSid
IsValidSid
TraceEvent
GetTraceLoggerHandle
GetTraceEnableLevel
GetTraceEnableFlags
RegisterTraceGuidsW
UnregisterTraceGuids
RegSetValueExA
RegQueryInfoKeyW
RegSetValueExW
RegQueryValueExW
RegCreateKeyExW
RegOpenKeyExW
LookupPrivilegeValueW
AdjustTokenPrivileges
RegisterServiceCtrlHandlerW
SetServiceStatus
RegEnumValueW
RegDeleteValueW
RegCloseKey
OpenThreadToken
OpenProcessToken
SetSecurityDescriptorDacl
InitializeAcl
AddAccessAllowedAce
GetAclInformation
AddAce
GetAce
LookupAccountNameW
GetTokenInformation
SetSecurityDescriptorGroup
SetSecurityDescriptorOwner
InitializeSecurityDescriptor
StartServiceCtrlDispatcherW
RegCreateKeyA
StartServiceW
OpenSCManagerW
OpenServiceW
ControlService
QueryServiceStatus
CloseServiceHandle
kernel32.dll

FindClose
InterlockedExchange
SwitchToThread
InterlockedCompareExchange
ReleaseMutex
OutputDebugStringW
GetFileAttributesW
InterlockedIncrement
InterlockedDecrement
GetLocalTime
GetCurrentThreadId
WriteFile
SetFilePointer
CreateFileW
CreateMutexW
GetModuleFileNameW
FindFirstFileW
GetProcessTimes
GetSystemTimeAsFileTime
SetLastError
VirtualQuery
CreateDirectoryW
GetCurrentDirectoryW
WritePrivateProfileStringW
WritePrivateProfileStructW
TerminateProcess
DecodePointer
EncodePointer
lstrlenA
WideCharToMultiByte
MultiByteToWideChar
GetVersionExA
SetProcessWorkingSetSize
ResetEvent
InitializeCriticalSection
CreateTimerQueueTimer
RegisterWaitForSingleObject
CreateTimerQueue
WaitForSingleObject
UnregisterWaitEx
DeleteTimerQueueTimer
DeleteTimerQueueEx
Sleep
SetEvent
CreateEventW
OpenEventW
GetCurrentProcessId
LeaveCriticalSection
EnterCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
LoadLibraryW
GetProcAddress
GetTickCount
FreeLibrary
GetCommandLineW
GetCurrentThread
GetCurrentProcess
CloseHandle
FindResourceExW
FindResourceW
LoadResource
LockResource
SizeofResource
QueryPerformanceCounter
QueryPerformanceFrequency
GetLastError
RaiseException
HeapSetInformation
GetProcessHeap
HeapSize
HeapReAlloc
HeapFree
HeapAlloc
HeapDestroy
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetSystemInfo
GetACP
GetLocaleInfoA
GetModuleHandleW
LoadLibraryA
CreateFileA
SetEndOfFile
WriteConsoleW
GetConsoleOutputCP
WriteConsoleA
ReadFile
FlushFileBuffers
SetStdHandle
GetConsoleMode
GetConsoleCP
RtlUnwind
VirtualAlloc
HeapCreate
VirtualFree
ExitProcess
GetStdHandle
GetModuleFileNameA
GetCPInfo
GetOEMCP
IsValidCodePage
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
LCMapStringW
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
GetModuleHandleA
LCMapStringA
GetStringTypeA
GetStringTypeW
Module32First
CreateToolhelp32Snapshot
OpenProcess
FindFirstFileA
IsBadWritePtr
Module32Next
GetShortPathNameA
lstrlenW
GetSystemDirectoryA
SystemTimeToFileTime
IsBadReadPtr
SetThreadPriority
msvcr100.dll
ole32.dll

CoUninitialize
CLSIDFromString
CoGetClassObject
CoInitializeSecurity
CoInitializeEx
CoRevokeClassObject
CoRegisterClassObject
CoInitialize
CoCreateInstance
psapi.dll

shell32.dll

shlwapi.dll

version.dll

GetFileVersionInfoW
VerQueryValueW
GetFileVersionInfoSizeW
wintrust.dll
