Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

11.0.0045 0.38%
11.0.0042 7.60%
11.0.0031 33.08%
11.0.0028 19.01%
11.0.0027 1.14%
11.0.0022 2.66%
11.0.0015 1.14%
1.0.0031 5.70%
1.0.0026 0.38%
1.0.0018 17.87%
1.0.0017 8.75%
1.0.0012 2.28%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
ControlService, OpenServiceW, CloseServiceHandle, CreateServiceW, OpenSCManagerW, RegisterServiceCtrlHandlerW, StartServiceCtrlDispatcherW, RegQueryValueExW, SetServiceStatus, DeregisterEventSource, ReportEventW, RegisterEventSourceW, OpenProcessToken, RevertToSelf, CreateProcessAsUserW, ImpersonateLoggedOnUser, AdjustTokenPrivileges, LookupPrivilegeValueW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegEnumKeyExW, RegQueryInfoKeyW, RegDeleteKeyW, RegCloseKey, DeleteService
kernel32.dll
SetEvent, WaitForSingleObject, TerminateThread, DeleteFileW, GetSystemTimeAsFileTime, WaitForMultipleObjects, GlobalFree, LockResource, FindResourceExW, WideCharToMultiByte, GetCommandLineW, GetCurrentThreadId, CreateThread, LoadLibraryW, CreateFileW, ReadFile, GetTempPathW, SystemTimeToFileTime, WriteFile, SetLastError, SetFileTime, ResumeThread, SetFileAttributesW, FindFirstFileW, FindClose, VirtualFree, VirtualAlloc, GetSystemInfo, ExpandEnvironmentStringsW, GetModuleHandleExW, TryEnterCriticalSection, CompareStringA, CreateFileA, SetEnvironmentVariableW, SetEnvironmentVariableA, CompareStringW, FlushFileBuffers, WriteConsoleW, ResetEvent, CreateDirectoryW, GetCurrentProcess, VerifyVersionInfoW, VerSetConditionMask, CloseHandle, Sleep, CreateEventW, GetModuleFileNameW, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, MultiByteToWideChar, GetLastError, RaiseException, lstrcmpiW, GetModuleHandleW, lstrlenW, InterlockedDecrement, InterlockedIncrement, LeaveCriticalSection, EnterCriticalSection, FreeLibrary, GetProcAddress, DeleteCriticalSection, InitializeCriticalSection, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, GetConsoleMode, GetConsoleCP, SetFilePointer, GetLocaleInfoA, LoadLibraryA, InitializeCriticalSectionAndSpinCount, GetFileAttributesW, GetTimeZoneInformation, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, GetStartupInfoA, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetModuleHandleA, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, GetModuleFileNameA, GetStdHandle, ExitProcess, HeapCreate, RtlUnwind, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetStartupInfoW, VirtualQuery, VirtualProtect, ExitThread, GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, OpenProcess, GetExitCodeProcess, GetFileSize, IsValidLocale, EnumSystemLocalesA, GetUserDefaultLCID, OutputDebugStringW, LocalFree, GetLocaleInfoW, IsProcessorFeaturePresent, GetDateFormatW, GetTimeFormatW, HeapSetInformation, DecodePointer, EncodePointer, InterlockedExchange, InterlockedCompareExchange, FormatMessageW, CreateFileMappingW, GetVersionExW, UnmapViewOfFile, GetSystemDefaultUILanguage, GetUserDefaultUILanguage, SearchPathW, SetEndOfFile, MapViewOfFile
ole32.dll
IIDFromString, StringFromIID, CoSuspendClassObjects, StringFromGUID2, CoRegisterClassObject, CoRevokeClassObject, CoResumeClassObjects, CoCreateInstance, CoInitializeSecurity, CoUninitialize, CoInitializeEx, CoDisconnectObject, CoTaskMemAlloc, CoTaskMemRealloc, CoTaskMemFree, CoCreateGuid, CoRevertToSelf, CoImpersonateClient, CoReleaseServerProcess, CoAddRefServerProcess, CoGetCurrentLogicalThreadId
shell32.dll
ShellExecuteExW, SHFileOperationW, SHGetFolderPathW
shlwapi.dll
PathMakePrettyW, PathRemoveArgsW, PathParseIconLocationW, SHCreateStreamOnFileW, PathIsUNCServerW, PathFindFileNameW, PathAddExtensionW, PathIsDirectoryW, PathCombineW, PathAddBackslashW, PathFindExtensionW, PathStripPathW, PathRemoveExtensionW, SHCreateStreamOnFileEx, PathRemoveFileSpecW, PathFileExistsW, PathCanonicalizeW, PathIsRootW, PathAppendW
user32.dll
TranslateMessage, wvsprintfA, CharUpperW, DispatchMessageW, MessageBoxW, GetMessageW, PostThreadMessageW, CharNextW, LoadStringW
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
winhttp.dll
WinHttpCloseHandle, WinHttpCrackUrl, WinHttpReceiveResponse, WinHttpSendRequest, WinHttpConnect, WinHttpSetOption, WinHttpGetIEProxyConfigForCurrentUser, WinHttpOpen, WinHttpReadData, WinHttpOpenRequest, WinHttpGetProxyForUrl, WinHttpQueryDataAvailable, WinHttpSetTimeouts, WinHttpQueryAuthSchemes, WinHttpQueryHeaders
wtsapi32.dll
WTSQueryUserToken, WTSFreeMemory, WTSEnumerateSessionsW
xmllite.dll
CreateXmlReaderInputWithEncodingName, CreateXmlWriterOutputWithEncodingName, CreateXmlWriter, CreateXmlReader

NASvc.exe

NeroUpdate by Nero AG (Signed)

Remove NASvc.exe
Version:   1.0.0026
MD5:   2a66dd37f5a44cd4548fa89e4088fd01
SHA1:   1ab9e140ae78e081667ca57e808f807a25a01eb0
SHA256:   8cdca460162fe92e173fc6683514921b3ee4c9c929345ac002df672bcb3f83f9

What is NASvc.exe?

NeroUpdate (NASvc.exe) is the software updater program which runs in the background of Windows and automatically starts up when your PC boots. It checks for software udpates and automatically downloads and installs them if found.

Overview

NASvc.exe runs as a service under the name Nero Güncelleme (NAUpdate) with extensive SYSTEM privileges (full administrator access). The file is digitally signed by Nero AG which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:NASvc.exe
Publisher:Nero AG
Product name:NeroUpdate
Typical file path:C:\Program Files\nero\update\nasvc.exe
Original name:NASvc.exe.mui
File version:1.0.0026
Size:559.79 KB (573,224 bytes)
Certificate
Issued to:Nero AG
Authority (CA):VeriSign
Effective date:Sunday, May 10, 2009
Expiration date:Thursday, June 21, 2012
Digital DNA
Entropy:6.398711
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'NAUpdate' (Nero Güncelleme)
  • NAUpdate
  • 'NAUpdate' (Nero Update)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00000187%
0.028634%
Kernel CPU:0.00000075%
0.013761%
User CPU:0.00000112%
0.014873%
Kernel CPU time:31 ms/min
100,923,805ms/min
CPU cycles:421/sec
17,470,203/sec
Memory
Private memory:2.79 MB
21.59 MB
Private (maximum):7.11 MB
Private (minimum):1.99 MB
Non-paged memory:2.79 MB
21.59 MB
Virtual memory:55.83 MB
140.96 MB
Virtual memory (peak):59.58 MB
169.69 MB
Working set:2 MB
18.61 MB
Working set (peak):7.17 MB
37.95 MB
Page faults:2,035/min
2,039/min
I/O
I/O read transfer:13 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O other transfer:0 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:7
12
Handles:137
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:"C:\Program Files\nero\update\nasvc.exe"
Owner:SYSTEM
Windows Service
Service name:NAUpdate
Display name:Nero Güncelleme
Description:“Voit siirtyä Nero-sovelluksen päivityksiin ja hallita Nero-sovelluksia.”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
NASvc.exe (main module)
Total CPU:0.00000608%
0.272967%
Kernel CPU:0.00000304%
0.107585%
User CPU:0.00000304%
0.165382%
CPU cycles:84/sec
5,741,424/sec
Memory:576 KB
1.16 MB
wow64cpu.dll
Total CPU:0.00000304%
Kernel CPU:0.00000000%
User CPU:0.00000304%
CPU cycles:61/sec
Memory:32 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 35.00%
Windows 7 Ultimate 17.50%
Windows 8 13.50%
Windows 8 Pro 10.50%
Windows 8.1 5.50%
Windows 8.1 Single Language 4.50%
Windows 7 Professional 3.50%
Windows Vista Home Premium 3.50%
Windows 8 Single Language 2.00%
Microsoft Windows XP 2.00%
Windows 7 Home Basic 1.50%
Windows 8 Pro with Media Center 1.00%

Distribution by countryDistribution by country

United States installs about 31.12% of NeroUpdate.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 34.10%
Toshiba 26.73%
Dell 13.82%
Hewlett-Packard 8.76%
ASUS 4.61%
Intel 3.69%
GIGABYTE 2.30%
American Megatrends 1.84%
Compaq 1.84%
Medion 0.92%
Packard Bell 0.92%
Alienware 0.46%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE