Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

7.9.9600.17093 (winblue_gdr.140410-1503) 0.85%
7.9.9600.17093 (winblue_gdr.140410-1503) 0.14%
7.9.9600.16384 (winblue_rtm.130821-1623) 0.14%
7.9.9600.16384 (winblue_rtm.130821-1623) 0.28%
7.9.9431.0 (winmain_bluemp.130615-1214) 0.14%
7.9.9431.0 (winmain_bluemp.130615-1214) 0.14%
7.8.9200.16465 (win8_gdr.121126-1503) 0.99%
7.8.9200.16465 (win8_gdr.121126-1503) 0.28%
7.8.9200.16465 (win8_gdr.121126-1503) 0.85%
7.8.9200.16465 (win8_gdr.121126-1503) 0.57%
7.8.9200.16465 (win8_gdr.121126-1503) 0.14%
7.8.9200.16465 (win8_gdr.121126-1503) 0.28%
7.8.9200.16451 (win8_gdr.121105-1502) 0.28%
7.8.9200.16449 (win8_gdr.121101-1706) 0.14%
7.8.9200.16420 (win8_gdr.120919-1813) 0.14%
7.8.9200.16420 (win8_gdr.120919-1813) 0.14%
7.8.9200.16384 (win8_rtm.120725-1247) 0.28%
7.8.9200.16384 (win8_rtm.120725-1247) 0.14%
7.8.8400.0 (winmain_win8rc.120518-1423) 0.14%
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1505) 43.04%
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459) 41.90%
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459) 1.42%
7.6.7600.243 (winmain_wtr_wsus3sp2(oobla).110811-1411) 0.71%
7.5.7601.17514 (win7sp1_rtm.101119-1850) 1.28%
7.5.7601.17514 (win7sp1_rtm.101119-1850) 0.43%
View more

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
SetServiceStatus
crypt32.dll
CertOpenStore, CertFreeCertificateChain, CertVerifyCertificateChainPolicy, CertGetCertificateChain, CryptHashPublicKeyInfo, CertGetCertificateContextProperty, CryptUnprotectData, CryptProtectData, CertGetPublicKeyLength, CertFreeCertificateContext, CertControlStore, CertFindCertificateInStore, CertCloseStore
esent.dll
JetUpdate, JetGotoBookmark, JetRetrieveColumns, JetCreateTable, JetDeleteTable, JetBeginSession, JetEndSession, JetSetSystemParameter, JetIntersectIndexes, JetIndexRecordCount, JetSetCurrentIndex, JetSeek, JetSetIndexRange, JetMakeKey, JetGetBookmark, JetPrepareUpdate, JetSetColumns, JetMove, JetDelete, JetGetColumnInfo, JetAddColumn, JetCloseTable, JetCreateIndex2, JetTerm2, JetInit, JetDetachDatabase, JetCreateDatabase, JetOpenDatabase, JetAttachDatabase, JetBeginTransaction, JetCommitTransaction, JetRollback, JetOpenTable, JetEscrowUpdate, JetCloseDatabase, JetRenameTable, JetDeleteIndex, JetDeleteColumn, JetGetTableColumnInfo
iphlpapi.dll
GetAdaptersInfo
kernel32.dll
DllMain, DeleteCriticalSection, DisableThreadLibraryCalls, LeaveCriticalSection, EnterCriticalSection, FreeLibrary, GetProcAddress, Sleep, InterlockedCompareExchange, RtlUnwind, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetSystemDirectoryW, lstrlenW, LoadLibraryExW, SetLastError, GetLastError, InitializeCriticalSectionAndSpinCount, InterlockedExchange, CloseHandle
mspatcha.dll
ApplyPatchToFileByHandles
msvcrt.dll
DllMain
ntdll.dll
RtlUnwind, VerSetConditionMask, NtQuerySystemInformation
rpcrt4.dll
RpcBindingFromStringBindingW, UuidToStringW, RpcStringFreeW, UuidFromStringW, UuidCreate, RpcBindingSetAuthInfoExW, RpcBindingFree, NdrClientCall2, I_RpcBindingInqTransportType, RpcStringFreeA, UuidToStringA
shell32.dll
SHGetFolderPathW
shlwapi.dll
PathFindExtensionW, PathStripToRootW, PathIsUNCW, PathIsRelativeW, SHDeleteKeyW, StrRChrW, PathStripPathW, StrToIntW, StrChrW, StrToIntExW, PathIsRootW
user32.dll
ExitWindowsEx, GetUserObjectInformationW, OpenWindowStationW, GetActiveWindow, GetSystemMetrics, LoadStringW, DispatchMessageW, TranslateMessage, GetMessageW, PostThreadMessageW, CharNextW, CloseWindowStation
userenv.dll
UnregisterGPNotification, CreateEnvironmentBlock, DestroyEnvironmentBlock, RegisterGPNotification
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
winhttp.dll
WinHttpGetDefaultProxyConfiguration, WinHttpGetProxyForUrl, WinHttpGetIEProxyConfigForCurrentUser, WinHttpQueryHeaders, WinHttpQueryAuthSchemes, WinHttpSetOption, WinHttpConnect, WinHttpSetTimeouts, WinHttpQueryOption, WinHttpOpenRequest, WinHttpReceiveResponse, WinHttpSetCredentials, WinHttpCrackUrl, WinHttpOpen, WinHttpSendRequest, WinHttpAddRequestHeaders, WinHttpCloseHandle, WinHttpReadData
winspool.drv
ClosePrinter, GetPrinterDataW, OpenPrinterW, EnumPrinterDriversW
winsta.dll
WinStationQueryInformationW
wintrust.dll
WTHelperProvDataFromStateData, WinVerifyTrust, WTHelperGetProvCertFromChain, WTHelperGetProvSignerFromChain
ws2_32.dll
WSAIoctl, WSASocketW
wtsapi32.dll
WTSFreeMemory, WTSQuerySessionInformationW, WTSEnumerateSessionsW
Export table
DllInstall
DllMain
DllRegisterServer
DllUnregisterServer
GeneralizeForImaging
GetAUOptionsEx
GetEngineStatusInfo
RegisterServiceVersion
ServiceHandler
ServiceMain
WUAutoUpdateAtShutdown
WUCheckForUpdatesAtShutdown
WUServiceMain

wuaueng.dll

Windows Update Agent by Microsoft Corporation (Signed)

Remove wuaueng.dll
Version:   7.9.9600.16384 (winblue_rtm.130821-1623)
MD5:   4442c95d1ebdf238ba045191823a367d
SHA1:   0b4d0d4834a9450f7810dd8c2be22842b6b34cf7
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is wuaueng.dll?

If Windows Update or Automatic Updates is turned on, the latest version of the Windows Update Agent will be automatically downloaded and installed on your computer. If you go to Windows Update before it gets installed automatically, you will see a message to install the Windows Update Agent.

About wuaueng.dll (from Microsoft Corporation)

When you turn on automatic updating, most updates will download and install without you having to lift a finger. But sometimes Windows Update will need your input during an installation. In this case,

DetailsDetails

File name:wuaueng.dll
Publisher:Microsoft Corporation
Product name:Windows Update Agent
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\wuaueng.dll
Original name:wuaueng.dll.mui
File version:7.9.9600.16384 (winblue_rtm.130821-1623)
Product version:7.9.9600.16384
Size:2.7 MB (2,832,896 bytes)
Build date:9/13/2013 12:12 PM
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Expiration date:Monday, April 26, 2010
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 48.50%
Windows 7 Ultimate 20.00%
Windows 7 Professional 10.50%
Windows Vista Home Premium 9.00%
Microsoft Windows XP 6.00%
Windows Vista Home Basic 2.00%
Windows 7 Home Basic 1.00%
Windows 7 Starter 1.00%
Windows Vista Business 1.00%
Windows 7 Enterprise 0.50%
Windows Vista Ultimate 0.50%

Distribution by countryDistribution by country

United States installs about 46.70% of Windows Update Agent.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 24.15%
Hewlett-Packard 16.23%
ASUS 12.83%
Toshiba 9.81%
Acer 8.30%
Sony 6.79%
GIGABYTE 3.77%
Intel 3.77%
Lenovo 3.77%
MSI 2.26%
American Megatrends 2.26%
Samsung 1.89%
Alienware 1.51%
Compaq 0.75%
Medion 0.75%
NEC 0.75%
Packard Bell 0.38%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE