Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

7.9.9600.17093 (winblue_gdr.140410-1503) 0.27%
7.9.9600.17092 (winblue_gdr.140408-1543) 0.27%
7.9.9431.198 (winmain_bluemp_gdr.130815-1919) 0.27%
7.8.9200.16731 (win8_gdr.131004-1506) 0.53%
7.8.9200.16693 (win8_gdr.130815-1505) 0.53%
7.8.9200.16604 (win8_gdr.130503-1646) 0.27%
7.8.9200.16465 (win8_gdr.121126-1503) 0.53%
7.8.9200.16449 (win8_gdr.121101-1706) 0.27%
7.8.9200.16384 (win8_rtm.120725-1247) 0.53%
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1505) 43.88%
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459) 48.67%
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459) 0.27%
7.5.7601.17514 (win7sp1_rtm.101119-1850) 0.80%
7.5.7601.17514 (win7sp1_rtm.101119-1850) 0.53%
7.3.7600.16385 (win7_rtm.090713-1255) 2.13%
7.3.7600.16384 (win7_rtm.090710-1945) 0.27%

Relationships

Parent process
Child processes
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
AllocateAndInitializeSid, FreeSid, GetTokenInformation, DuplicateTokenEx, CheckTokenMembership, IsValidSid, CopySid, RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, RegEnumValueW, RegDeleteValueW, GetUserNameW, GetLengthSid, InitializeAcl, AddAccessAllowedAce, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegOpenKeyExW, RegCloseKey
api-ms-win-core-com-l1-1-0.dll
CoTaskMemFree, CoInitializeEx, IIDFromString, CoUninitialize, CoCreateInstance
api-ms-win-core-com-l1-1-1.dll
CoTaskMemFree, CoInitializeEx, IIDFromString, CoCreateInstance, CoUninitialize
api-ms-win-core-debug-l1-1-1.dll
OutputDebugStringW
api-ms-win-core-errorhandling-l1-1-1.dll
GetLastError, SetLastError, UnhandledExceptionFilter, SetUnhandledExceptionFilter
api-ms-win-core-file-l1-2-0.dll
GetDriveTypeW, GetVolumePathNameW, GetFileType, SetFilePointer, FlushFileBuffers, GetFileSize, WriteFile, GetFileAttributesW, CreateFileW, CreateDirectoryW, ReadFile, SetEndOfFile
api-ms-win-core-file-l1-2-1.dll
GetFileType, GetDriveTypeW, GetVolumePathNameW, FlushFileBuffers, WriteFile, SetFilePointer, GetFileSize, CreateDirectoryW, CreateFileW, ReadFile, GetFileAttributesW, SetEndOfFile
api-ms-win-core-handle-l1-1-0.dll
CloseHandle
api-ms-win-core-heap-l1-2-0.dll
HeapAlloc, HeapSetInformation, HeapFree, GetProcessHeap
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedExchange, InterlockedIncrement, InterlockedDecrement, InterlockedCompareExchange
api-ms-win-core-libraryloader-l1-1-1.dll
GetModuleFileNameW, GetProcAddress, GetModuleHandleW, FreeLibrary, GetModuleHandleA, LoadLibraryExW
api-ms-win-core-processenvironment-l1-2-0.dll
ExpandEnvironmentStringsW, GetCommandLineW
api-ms-win-core-processthreads-l1-1-1.dll
GetCurrentProcess, GetCurrentThreadId, GetCurrentProcessId, GetStartupInfoW, TerminateProcess
api-ms-win-core-processthreads-l1-1-2.dll
GetCurrentProcess, GetCurrentThreadId, GetCurrentProcessId, TerminateProcess, GetStartupInfoW
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegCloseKey, RegQueryValueExW, RegOpenKeyExW, RegEnumValueW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW
api-ms-win-core-string-l1-1-0.dll
CompareStringW, WideCharToMultiByte
api-ms-win-core-synch-l1-2-0.dll
Sleep, CreateMutexW, ReleaseMutex, WaitForSingleObject
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemTimeAsFileTime, GetSystemTime, GetTickCount
api-ms-win-core-sysinfo-l1-2-1.dll
GetSystemTime, GetSystemTimeAsFileTime, GetTickCount
api-ms-win-core-timezone-l1-1-0.dll
GetTimeZoneInformation, SystemTimeToTzSpecificLocalTime
api-ms-win-security-base-l1-2-0.dll
CheckTokenMembership, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, AllocateAndInitializeSid, AddAccessAllowedAce, InitializeAcl, GetLengthSid, IsValidSid, FreeSid, CopySid
kernel32.dll
CreateFileW, CreateDirectoryW, GetFileAttributesW, ExpandEnvironmentStringsW, lstrlenW, CreateProcessW, VerSetConditionMask, VerifyVersionInfoW, OutputDebugStringW, WideCharToMultiByte, WriteFile, FlushFileBuffers, GetModuleFileNameW, InterlockedIncrement, InterlockedDecrement, GetSystemTime, GetLastError, SetLastError, GetFileSize, CreateFileMappingW, MapViewOfFile, UnmapViewOfFile, SetFilePointer, SetEndOfFile, ReleaseMutex, WaitForSingleObject, CreateMutexW, CloseHandle, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, GetStartupInfoW, Sleep, InterlockedExchange, GetTimeZoneInformation, SystemTimeToTzSpecificLocalTime, GetSystemDirectoryW, LoadLibraryExW, GetDriveTypeW, GetVolumePathNameW, GetFileType, GetSystemInfo, GetModuleHandleW, CompareStringW, GetProcessHeap, HeapFree, HeapAlloc, GetCommandLineW, FreeLibrary, LoadLibraryW, InterlockedCompareExchange, OpenEventW, GetProcAddress
msvcrt.dll
DllMain
ntdll.dll
RtlUnwind, WinSqmIncrementDWORD
ole32.dll
CoTaskMemFree, CoUninitialize, CoCreateInstance, CoInitialize, CoInitializeEx
shlwapi.dll
StrRChrW, StrChrW, PathIsRelativeW, PathIsUNCW, PathStripToRootW, PathIsRootW
sspicli.dll
GetUserNameExW
user32.dll
IsWindow, PostMessageW

wuauclt.exe

Windows Update by Microsoft Corporation (Signed)

Remove wuauclt.exe
Version:   7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459)
MD5:   2e0b0a051ffaa86e358465bb0880d453
SHA1:   5f57258ab4137f58d499aa98645c7bace28fd573
SHA256:   493cf6150de95b269727631d50fe21405a41e449c4ff43e94f93d27559ea5624
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is wuauclt.exe?

Windows Update is a service provided by Microsoft that provides updates for the Microsoft Windows operating system and its installed components, including Internet Explorer. Windows Update can be configured to install critical updates automatically so long as the computer is connected to the Internet, without the user needing to install them manually, or even be aware that an update is required.

About wuauclt.exe (from Microsoft Corporation)

When you turn on automatic updating, most updates will download and install without you having to lift a finger. But sometimes Windows Update will need your input during an installation. In this case,

DetailsDetails

File name:wuauclt.exe
Publisher:Microsoft Corporation
Product name:Windows Update
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\wuauclt.exe
File version:7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459)
Product version:7.6.7600.256
Size:52.52 KB (53,784 bytes)
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Expiration date:Tuesday, July 9, 2013
Digital DNA
Entropy:5.852595
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.02005454%
0.028634%
Kernel CPU:0.01052193%
0.013761%
User CPU:0.00953261%
0.014873%
Kernel CPU time:353,870 ms/min
100,923,805ms/min
CPU cycles:36,577/sec
17,470,203/sec
Context switches:63/sec
284/sec
Memory
Private memory:2.83 MB
21.59 MB
Private (maximum):7.82 MB
Private (minimum):3.87 MB
Non-paged memory:2.83 MB
21.59 MB
Virtual memory:57.47 MB
140.96 MB
Virtual memory (peak):65.86 MB
169.69 MB
Working set:5.94 MB
18.61 MB
Working set (peak):11.51 MB
37.95 MB
Page faults:12,027/min
2,039/min
I/O
I/O read transfer:130.39 KB/sec
1.02 MB/min
I/O read operations:15/sec
343/min
I/O write transfer:14.14 KB/sec
274.99 KB/min
I/O write operations:5/sec
227/min
I/O other transfer:1.68 KB/sec
448.09 KB/min
I/O other operations:37/sec
1,671/min
Resource allocations
Threads:3
12
Handles:126
600
GUI GDI count:12
103
GUI GDI peak:17
142
GUI USER count:7
49
GUI USER peak:9
71

BehaviorsProcess properties

Integrety level:Medium
Platform:32-bit
Command lines:
  • "C:\Windows\System32\wuauclt.exe"
  • "C:\Windows\System32\wuauclt.exe" /runhandlercomserver
  • "C:\Windows\System32\wuauclt.exe" /runstoreascomserver local\[440]susds32a701d1b6e3de4c85758814f9310362
  • "C:\Windows\System32\wuauclt.exe" /runstoreascomserver local\[594]susdsaf70d583b7376a4d923def99bf8f3eb0
  • "C:\Windows\System32\wuauclt.exe" /runstoreascomserver local\[37c]susdsd5cf091afb911e47ac24b9bfacd308e6
  • "C:\Windows\System32\wuauclt.exe" /runstoreascomserver local\[434]susds00098593a493214780179f0d908e7c5a
  • "C:\Windows\System32\wuauclt.exe" /runstoreascomserver local\[434]susds3cc8d9cdf44ce64ba80a42285e6a7e03
  • (18 more)
Owner:User
Parent processes:

ResourcesThreads

Averages
 
ESENT.dll
Total CPU:0.64553893%
0.272967%
Kernel CPU:0.61357178%
0.107585%
User CPU:0.03196716%
0.165382%
Context switches:31/sec
79/sec
Memory:1.05 MB
1.16 MB
wucltux.dll
Total CPU:0.07645989%
Kernel CPU:0.06441315%
User CPU:0.01204674%
CPU cycles:16,911,158/sec
Context switches:14/sec
Memory:2.33 MB
wuauclt.exe (main module)
Total CPU:0.07207057%
Kernel CPU:0.01609291%
User CPU:0.05597767%
CPU cycles:116,587/sec
Context switches:3/sec
Memory:56 KB
ntdll.dll
Total CPU:0.01562744%
Kernel CPU:0.00000000%
User CPU:0.01562744%
CPU cycles:72,335/sec
Context switches:2/sec
Memory:1.23 MB
wucltui.dll
Total CPU:0.00009662%
Kernel CPU:0.00000000%
User CPU:0.00009662%
Memory:328 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 47.83%
Windows 8 17.39%
Windows 8 Pro 8.70%
Windows 7 Home Premium 8.70%
Windows 8.1 Pro with Media Center 4.35%
Windows 8 Single Language 4.35%
Windows 8.1 4.35%
Windows 8.1 Pro Preview 4.35%

Distribution by countryDistribution by country

United States installs about 53.85% of Windows Update.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
ASUS 26.67%
Lenovo 26.67%
Hewlett-Packard 20.00%
Toshiba 13.33%
Acer 13.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE