Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

7.9.9600.17093 (winblue_gdr.140410-1503) 0.58%
7.9.9600.17093 (winblue_gdr.140410-1503) 0.10%
7.9.9600.16384 (winblue_rtm.130821-1623) 0.10%
7.9.9600.16384 (winblue_rtm.130821-1623) 0.19%
7.9.9431.0 (winmain_bluemp.130615-1214) 0.10%
7.9.9431.0 (winmain_bluemp.130615-1214) 0.10%
7.8.9200.16465 (win8_gdr.121126-1503) 0.68%
7.8.9200.16465 (win8_gdr.121126-1503) 0.19%
7.8.9200.16465 (win8_gdr.121126-1503) 0.58%
7.8.9200.16465 (win8_gdr.121126-1503) 0.39%
7.8.9200.16465 (win8_gdr.121126-1503) 0.10%
7.8.9200.16465 (win8_gdr.121126-1503) 0.19%
7.8.9200.16451 (win8_gdr.121105-1502) 0.19%
7.8.9200.16449 (win8_gdr.121101-1706) 0.10%
7.8.9200.16420 (win8_gdr.120919-1813) 0.10%
7.8.9200.16420 (win8_gdr.120919-1813) 0.10%
7.8.9200.16384 (win8_rtm.120725-1247) 0.19%
7.8.9200.16384 (win8_rtm.120725-1247) 0.10%
7.8.8400.0 (winmain_win8rc.120518-1423) 0.10%
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1505) 29.47%
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459) 28.70%
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459) 0.97%
7.6.7600.243 (winmain_wtr_wsus3sp2(oobla).110811-1411) 0.49%
7.5.7601.17514 (win7sp1_rtm.101119-1850) 0.88%
7.5.7601.17514 (win7sp1_rtm.101119-1850) 0.29%
View more

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
SetServiceStatus
crypt32.dll
CertOpenStore, CertFreeCertificateChain, CertVerifyCertificateChainPolicy, CertGetCertificateChain, CryptHashPublicKeyInfo, CertGetCertificateContextProperty, CryptUnprotectData, CryptProtectData, CertGetPublicKeyLength, CertFreeCertificateContext, CertControlStore, CertFindCertificateInStore, CertCloseStore
esent.dll
JetUpdate, JetGotoBookmark, JetRetrieveColumns, JetCreateTable, JetDeleteTable, JetBeginSession, JetEndSession, JetSetSystemParameter, JetIntersectIndexes, JetIndexRecordCount, JetSetCurrentIndex, JetSeek, JetSetIndexRange, JetMakeKey, JetGetBookmark, JetPrepareUpdate, JetSetColumns, JetMove, JetDelete, JetGetColumnInfo, JetAddColumn, JetCloseTable, JetCreateIndex2, JetTerm2, JetInit, JetDetachDatabase, JetCreateDatabase, JetOpenDatabase, JetAttachDatabase, JetBeginTransaction, JetCommitTransaction, JetRollback, JetOpenTable, JetEscrowUpdate, JetCloseDatabase, JetRenameTable, JetDeleteIndex, JetDeleteColumn, JetGetTableColumnInfo
iphlpapi.dll
GetAdaptersInfo
kernel32.dll
DllMain, DeleteCriticalSection, DisableThreadLibraryCalls, LeaveCriticalSection, EnterCriticalSection, FreeLibrary, GetProcAddress, Sleep, InterlockedCompareExchange, RtlUnwind, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetSystemDirectoryW, lstrlenW, LoadLibraryExW, SetLastError, GetLastError, InitializeCriticalSectionAndSpinCount, InterlockedExchange, CloseHandle
mspatcha.dll
ApplyPatchToFileByHandles
msvcrt.dll
DllMain
ntdll.dll
RtlUnwind, VerSetConditionMask, NtQuerySystemInformation
rpcrt4.dll
RpcBindingFromStringBindingW, UuidToStringW, RpcStringFreeW, UuidFromStringW, UuidCreate, RpcBindingSetAuthInfoExW, RpcBindingFree, NdrClientCall2, I_RpcBindingInqTransportType, RpcStringFreeA, UuidToStringA
shell32.dll
SHGetFolderPathW
shlwapi.dll
PathFindExtensionW, PathStripToRootW, PathIsUNCW, PathIsRelativeW, SHDeleteKeyW, StrRChrW, PathStripPathW, StrToIntW, StrChrW, StrToIntExW, PathIsRootW
user32.dll
ExitWindowsEx, GetUserObjectInformationW, OpenWindowStationW, GetActiveWindow, GetSystemMetrics, LoadStringW, DispatchMessageW, TranslateMessage, GetMessageW, PostThreadMessageW, CharNextW, CloseWindowStation
userenv.dll
UnregisterGPNotification, CreateEnvironmentBlock, DestroyEnvironmentBlock, RegisterGPNotification
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
winhttp.dll
WinHttpGetDefaultProxyConfiguration, WinHttpGetProxyForUrl, WinHttpGetIEProxyConfigForCurrentUser, WinHttpQueryHeaders, WinHttpQueryAuthSchemes, WinHttpSetOption, WinHttpConnect, WinHttpSetTimeouts, WinHttpQueryOption, WinHttpOpenRequest, WinHttpReceiveResponse, WinHttpSetCredentials, WinHttpCrackUrl, WinHttpOpen, WinHttpSendRequest, WinHttpAddRequestHeaders, WinHttpCloseHandle, WinHttpReadData
winspool.drv
ClosePrinter, GetPrinterDataW, OpenPrinterW, EnumPrinterDriversW
winsta.dll
WinStationQueryInformationW
wintrust.dll
WTHelperProvDataFromStateData, WinVerifyTrust, WTHelperGetProvCertFromChain, WTHelperGetProvSignerFromChain
ws2_32.dll
WSAIoctl, WSASocketW
wtsapi32.dll
WTSFreeMemory, WTSQuerySessionInformationW, WTSEnumerateSessionsW
Export table
DllInstall
DllMain
DllRegisterServer
DllUnregisterServer
GeneralizeForImaging
GetAUOptionsEx
GetEngineStatusInfo
RegisterServiceVersion
ServiceHandler
ServiceMain
WUAutoUpdateAtShutdown
WUCheckForUpdatesAtShutdown
WUServiceMain

wuaueng.dll

Windows Update Agent by Microsoft Corporation (Signed)

Remove wuaueng.dll
Version:   5.8.0.2469 built by: lab01_n(wmbla)
MD5:   0732c538e9891714041638f777f368fc
SHA1:   78fc0497dcbde7cfbf7710b3395b271a5391f7dc
SHA256:   153f6789cab145d178c89f1b5b6ce22b6c24d8424f7bbb06851c71d76e16be9d
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is wuaueng.dll?

If Windows Update or Automatic Updates is turned on, the latest version of the Windows Update Agent will be automatically downloaded and installed on your computer. If you go to Windows Update before it gets installed automatically, you will see a message to install the Windows Update Agent.

About wuaueng.dll (from Microsoft Corporation)

When you turn on automatic updating, most updates will download and install without you having to lift a finger. But sometimes Windows Update will need your input during an installation. In this case,

DetailsDetails

File name:wuaueng.dll
Publisher:Microsoft Corporation
Product name:Windows Update Agent
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\wuaueng.dll
Original name:wuaueng.dll.mui
File version:5.8.0.2469 built by: lab01_n(wmbla)
Product version:5.8.0.2469
Size:18.27 KB (18,712 bytes)
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Expiration date:Monday, April 26, 2010
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 48.50%
Windows 7 Ultimate 20.00%
Windows 7 Professional 10.50%
Windows Vista Home Premium 9.00%
Microsoft Windows XP 6.00%
Windows Vista Home Basic 2.00%
Windows 7 Home Basic 1.00%
Windows 7 Starter 1.00%
Windows Vista Business 1.00%
Windows 7 Enterprise 0.50%
Windows Vista Ultimate 0.50%

Distribution by countryDistribution by country

United States installs about 46.70% of Windows Update Agent.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 24.15%
Hewlett-Packard 16.23%
ASUS 12.83%
Toshiba 9.81%
Acer 8.30%
Sony 6.79%
GIGABYTE 3.77%
Intel 3.77%
Lenovo 3.77%
MSI 2.26%
American Megatrends 2.26%
Samsung 1.89%
Alienware 1.51%
Compaq 0.75%
Medion 0.75%
NEC 0.75%
Packard Bell 0.38%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE