Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.0.0.390 20.00%
6.0.0.381 20.00%
6.0.0.339 20.00%
5.4.0.148 20.00%
5.2.2.121 20.00%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
ImpersonateSelf, GetUserNameA, RegNotifyChangeKeyValue, DuplicateToken, ConvertSidToStringSidW, CheckTokenMembership, RevertToSelf, RegEnumValueW, ImpersonateNamedPipeClient, OpenThreadToken, StartServiceCtrlDispatcherW, OpenSCManagerW, DeregisterEventSource, ReportEventW, RegisterEventSourceW, DeleteService, ControlService, ChangeServiceConfig2W, CloseServiceHandle, RegEnumKeyW, ChangeServiceConfigW, GetSecurityDescriptorLength, OpenServiceW, RegOpenKeyW, MakeSelfRelativeSD, CreateServiceW, StartServiceW, QueryServiceStatus, SetServiceStatus, RegisterServiceCtrlHandlerW, RegQueryValueExW, RegFlushKey, RegDeleteKeyW, RegSetValueExW, RegDeleteValueW, RegCreateKeyExW, RegOpenKeyExW, RegEnumKeyExW, RegQueryInfoKeyW, RegCloseKey, GetSecurityDescriptorSacl, SetSecurityDescriptorDacl, GetSecurityDescriptorDacl, SetSecurityDescriptorGroup, GetSecurityDescriptorGroup, GetTokenInformation, SetSecurityDescriptorOwner, GetSecurityDescriptorOwner, IsValidSid, GetLengthSid, GetAce, GetAclInformation, AddAce, OpenProcessToken, InitializeAcl, InitializeSecurityDescriptor, SetSecurityInfo, MakeAbsoluteSD, CopySid, GetSecurityInfo, GetSidSubAuthority, GetSecurityDescriptorControl, InitializeSid, GetSidLengthRequired
kernel32.dll
GetPrivateProfileSectionNamesW, GetPrivateProfileSectionW, GetSystemDefaultLCID, GetUserDefaultUILanguage, GetSystemDefaultUILanguage, EnumUILanguagesW, GetUserDefaultLCID, IsValidLocale, GetLocaleInfoW, GetUserDefaultLangID, ConvertDefaultLocale, WriteFile, SetFilePointer, OutputDebugStringA, FileTimeToDosDateTime, FileTimeToLocalFileTime, GetFileAttributesExA, MoveFileW, GetFileSizeEx, FormatMessageA, GetComputerNameA, GetSystemTimeAsFileTime, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetStartupInfoW, GetThreadLocale, GetLocaleInfoA, GetACP, InterlockedExchange, VirtualAlloc, VirtualFree, IsProcessorFeaturePresent, LoadLibraryA, InterlockedCompareExchange, GetVersionExA, GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, CreateFileW, DeleteFileW, FindFirstFileW, FindClose, FindNextFileW, GetModuleFileNameA, GetCurrentThread, GetTickCount, WideCharToMultiByte, SetProcessWorkingSetSize, SetEnvironmentVariableW, GetProcAddress, LoadLibraryW, Sleep, lstrlenA, OutputDebugStringW, DebugBreak, SetErrorMode, GetCommandLineW, SetConsoleCtrlHandler, GetEnvironmentVariableW, lstrcpynW, GetFileAttributesW, GetWindowsDirectoryW, WaitForSingleObject, CreateEventW, FindResourceExW, LockResource, WaitForMultipleObjects, LoadLibraryExW, FreeLibrary, FindResourceW, LoadResource, GetModuleFileNameW, SizeofResource, GetModuleHandleW, InterlockedDecrement, InitializeCriticalSection, InterlockedIncrement, lstrlenW, MultiByteToWideChar, DeleteCriticalSection, lstrcmpiW, LeaveCriticalSection, EnterCriticalSection, FlushInstructionCache, SetEvent, OpenEventW, RaiseException, CloseHandle, GetCurrentProcessId, GetLocalTime, GetLastError, LocalFree, SetLastError, GetVersionExW, GetCurrentThreadId, GetCurrentProcess
msvcp80.dll
DllMain
msvcr80.dll
DllMain
ole32.dll
CoInitializeSecurity, CLSIDFromProgID, CoTaskMemAlloc, CoTaskMemFree, CoTaskMemRealloc, CoFreeUnusedLibraries, CoMarshalInterThreadInterfaceInStream, CoCreateInstance, CoInitializeEx, CoUninitialize, StringFromGUID2, CoRevokeClassObject, CoRegisterClassObject, CoInitialize, CoCreateGuid, StringFromCLSID, CoImpersonateClient, CoRevertToSelf, CoDisconnectObject, CoGetInterfaceAndReleaseStream
shell32.dll
SHCreateDirectoryExW
shfolder.dll
SHGetFolderPathW
shlwapi.dll
PathFileExistsW, SHSetValueW, PathStripPathW, PathRenameExtensionW, PathFindFileNameW, PathAppendW, PathFindFileNameA, PathFindExtensionA
user32.dll
UnregisterClassA, GetProcessWindowStation, CreateWindowExW, RegisterClassExW, GetClassInfoExW, CallWindowProcW, LoadCursorW, SetWindowLongW, GetWindowLongW, DefWindowProcW, DestroyWindow, CharNextW, wsprintfW, PostThreadMessageW, MessageBoxW, wvsprintfW, LoadStringW, GetMessageW, TranslateMessage, DispatchMessageW, MsgWaitForMultipleObjects, PeekMessageW, GetUserObjectInformationA
userenv.dll
UnloadUserProfile

myAgtSvc.exe

McAfee Security-as-a-Service by McAfee (Signed)

Remove myAgtSvc.exe
Version:   6.0.0.381
MD5:   6c2af095280d9bf05d20c363868f5582
SHA1:   130038f55d32ad184e755faedc14ffca50dbf650

Overview

myagtsvc.exe runs as a service under the name McAfee Virus and Spyware Protection Service (myAgtSvc) with extensive SYSTEM privileges (full administrator access). The file is digitally signed by McAfee which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:myagtsvc.exe
Publisher:McAfee, Inc.
Product name:McAfee® Security-as-a-Service
Description:Managed Services Agent
Typical file path:C:\Program Files\mcafee\managed virusscan\agent\myagtsvc.exe
File version:6.0.0.381
Product version:6.0.0
Size:284.96 KB (291,800 bytes)
Build date:1/30/2013 12:30 AM
Certificate
Issued to:McAfee
Authority (CA):VeriSign
Effective date:Wednesday, October 5, 2011
Expiration date:Tuesday, December 31, 2013
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'myAgtSvc' (McAfee Virus and Spyware Protection Service)
Network connections
  • [UDP] listens on port 6516
  • [UDP] listens on port 6514

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00000876%
    0.028634%
    Kernel CPU:0.00000530%
    0.013761%
    User CPU:0.00000346%
    0.014873%
    Kernel CPU time:17,703,125 ms/min
    100,923,805ms/min
    Memory
    Private memory:6.07 MB
    21.59 MB
    Private (maximum):7.39 MB
    Private (minimum):6.34 MB
    Non-paged memory:6.07 MB
    21.59 MB
    Virtual memory:78.38 MB
    140.96 MB
    Virtual memory (peak):87.3 MB
    169.69 MB
    Working set:7.24 MB
    18.61 MB
    Working set (peak):14.85 MB
    37.95 MB
    Resource allocations
    Threads:11
    12
    Handles:1442
    600

    BehaviorsProcess properties

    Integrety level:System
    Platform:64-bit
    Command lines:
    • "C:\Program Files\mcafee\managed virusscan\agent\myagtsvc.exe" /servicestart
    • "C:\Program Files\mcafee\managed virusscan\agent\myagtsvc.exe" /rundll=rumorserver.dll;servicehost
    Owner:SYSTEM
    Windows Service
    Service name:myAgtSvc
    Display name:McAfee Virus and Spyware Protection Service
    Description:“Contrôle les activités d'analyse et de mise à jour du poste de travail pour le service de protection antivirus et antispyware.”
    Type:Win32OwnProcess, InteractiveProcess
    Parent process:services.exe (by Microsoft)

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Professional 40.00%
    Windows 8 20.00%
    Windows Vista Ultimate 20.00%
    Windows 7 Home Premium 20.00%

    Distribution by countryDistribution by country

    United States installs about 40.00% of McAfee® Security-as-a-Service.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    ASUS 33.33%
    Intel 33.33%
    Lenovo 33.33%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE