Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

14,0,0,136 0.03%
14,0,0,126 0.03%
14,0,0,125 2.47%
14,0,0,122 0.03%
13,0,0,214 3.96%
13,0,0,206 0.03%
13,0,0,182 0.03%
13,0,0,133 0.03%
13,0,0,130 0.03%
12,0,0,70 1.04%
12,0,0,39 0.08%
11,9,900,170 1.57%
11,9,900,152 0.20%
11,9,900,117 12.38%
11,9,900,85 0.03%
11,8,800,175 1.85%
11,8,800,174 0.14%
11,8,800,168 1.04%
11,8,800,95 0.08%
11,8,800,94 3.73%
11,8,800,88 0.08%
11,8,800,81 0.03%
11,8,800,50 0.08%
11,7,700,224 10.56%
11,7,700,202 2.05%
View more

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
SetServiceStatus, StartServiceCtrlDispatcherW, ControlService, ChangeServiceConfigW, ChangeServiceConfig2W, StartServiceA, OpenServiceW, OpenSCManagerW, DeleteService, CloseServiceHandle, CreateServiceW, RegSetValueExW, RegCloseKey, RegOpenKeyExW, RegDeleteValueW, RegQueryValueExW, RegCreateKeyExW, RegisterServiceCtrlHandlerW, CreateProcessAsUserW, GetTokenInformation, DuplicateTokenEx, QueryServiceConfigW, UnlockServiceDatabase, LockServiceDatabase, QueryServiceStatusEx, StartServiceW
kernel32.dll
CloseHandle, DeleteFileW, GetSystemTimeAsFileTime, GetModuleHandleW, CreateProcessW, FindFirstFileW, SystemTimeToFileTime, WideCharToMultiByte, GetFileAttributesW, MultiByteToWideChar, GetFileSizeEx, FindClose, FindNextFileW, GetSystemTime, GetVersionExA, GetFullPathNameW, SetEvent, RemoveDirectoryW, InterlockedDecrement, FreeLibrary, GetCurrentProcess, LoadLibraryW, GetProcAddress, SetStdHandle, WriteConsoleW, GetTempPathW, CreateFileW, ReadFile, WriteFile, CreateDirectoryW, GetFileSize, GetTempFileNameW, GetLastError, CreateFileA, SetEndOfFile, GetTickCount, GetCurrentProcessId, GetStringTypeA, CreateEventW, WriteConsoleA, GetConsoleOutputCP, GetLocaleInfoW, InitializeCriticalSectionAndSpinCount, GetModuleHandleA, IsValidLocale, EnumSystemLocalesA, GetLocaleInfoA, GetUserDefaultLCID, QueryPerformanceCounter, GetCommandLineW, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetModuleFileNameW, InterlockedIncrement, InterlockedCompareExchange, InterlockedExchange, Sleep, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, HeapFree, GetProcessHeap, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, LoadLibraryA, RaiseException, RtlUnwind, GetCPInfo, LCMapStringA, LCMapStringW, GetStringTypeW, HeapAlloc, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, HeapSize, ExitProcess, GetACP, GetOEMCP, IsValidCodePage, GetStdHandle, GetModuleFileNameA, SetHandleCount, GetFileType, GetStartupInfoA, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, GetConsoleCP, GetConsoleMode, FlushFileBuffers, SetFilePointer, ResetEvent, TerminateThread, GlobalFree, WTSGetActiveConsoleSessionId, lstrlenA, LocalAlloc, LocalFree, WaitForSingleObject, CopyFileW, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, IsProcessorFeaturePresent, GetVolumeInformationW, HeapDestroy, EncodePointer, DecodePointer, ExitThread, CreateThread, HeapSetInformation, GetStartupInfoW
ole32.dll
CoCreateGuid, CoCreateInstance, CoUninitialize, CoInitializeSecurity, CoInitialize, CoInitializeEx, StringFromGUID2
shell32.dll
SHFileOperationW, SHGetFolderPathW, SHGetSpecialFolderPathW, CommandLineToArgvW
shlwapi.dll
PathFileExistsW, PathAppendW
user32.dll
LoadStringW
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
winhttp.dll
WinHttpQueryDataAvailable, WinHttpReadData, WinHttpCloseHandle, WinHttpConnect, WinHttpSendRequest, WinHttpReceiveResponse, WinHttpOpenRequest, WinHttpOpen, WinHttpSetOption, WinHttpAddRequestHeaders, WinHttpSetStatusCallback, WinHttpGetIEProxyConfigForCurrentUser, WinHttpGetProxyForUrl, WinHttpQueryHeaders
wtsapi32.dll
WTSQueryUserToken

flashplayerupdateservice.exe

Adobe Flash Player Update Service by Adobe Systems Incorporated (Signed)

Remove flashplayerupdateservice.exe
Version:   11,6,602,180
MD5:   249a44dcfa2500eb1c020e33a3e9f25b
SHA1:   942860bedf408cc4c6a1831ef3744a3f9e68b375
SHA256:   b2cad8322db85f67db6ea074d00c2ed56ce1fa92952d07b70baac249fa18236d
Warning 32 antivirus scanners has detected malware.

What is flashplayerupdateservice.exe?

Adobe Flash Player installer and uninstaller process that runs in the background. The Adobe Flash Player is software for viewing multimedia, Rich Internet Applications, and streaming video and audio, on a computer web browser or on supported mobile devices. Flash Player runs SWF files that can be created by the Adobe Flash authoring tool, by Adobe Flex or by a number of other Macromedia and third party tools.

About flashplayerupdateservice.exe (from Adobe Systems Incorporated)

Adobe Flash Player is the standard for delivering high-impact, rich Web content. Designs, animation, and application user interfaces are deployed immediately across all browsers and platforms, attract

DetailsDetails

File name:flashplayerupdateservice.exe
Publisher:Adobe Systems Incorporated
Product name:Adobe® Flash® Player Update Service
Description:Adobe® Flash® Player Update Service 11.2 r202
Typical file path:C:\Windows\System32\macromed\flash\flashplayerupdateservice.exe
File version:11,6,602,180
Size:159.5 KB (163,328 bytes)
Build date:5/28/2013 10:05 PM
Certificate
Issued to:Adobe Systems Incorporated
Authority (CA):VeriSign
Expiration date:Thursday, October 1, 2015
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Adobe Systems Incorporated
4% remove
The Adobe Flash Player is freeware software for viewing multimedia, executing Rich Internet Applications, and streaming video and audio, content created on the Adobe Flash platform. Flash Player can run from a web browser (as a browser plug-in) or on supported mobile devices. Adobe Flash Player 11 is available in three flavors: "ActiveX", "Plug-in" and "Projector". The "ActiveX" version is an ActiveX control for use in Internet Explorer...
Adobe Systems Incorporated
5% remove
The Adobe Flash Player is freeware software for viewing multimedia, executing Rich Internet Applications, and streaming video and audio, content created on the Adobe Flash platform. Adobe Flash Player 11 is available in three flavors: "ActiveX", "Plug-in" and "Projector". The "ActiveX" version is an ActiveX control for use in Internet Explorer and any other Windows applications that supports ActiveX technology. The "plug-in" version is ...
Adobe Systems Incorporated
5% remove
Adobe Flash Player 10 ActiveX is software for viewing multimedia, Rich Internet Applications, and streaming video and audio, on a computer web browser. Flash Player runs SWF files that can be created by the Adobe Flash authoring tool, by Adobe Flex or by a number of other Macromedia and third party tools. Flash Player is freely available as a plugin for recent versions of web browsers (such as Internet Explorer, Mozilla Firefox, Opera, ...
Adobe Systems Incorporated
4% remove
Adobe Flash Player 10 Plugin is software for viewing multimedia, Rich Internet Applications, and streaming video and audio, on a computer web browser. Flash Player runs SWF files that can be created by the Adobe Flash authoring tool, by Adobe Flex or by a number of other Macromedia and third party tools. Flash Player is freely available as a plugin for recent versions of web browsers (such as Internet Explorer, Mozilla Firefox, Opera, a...
Adobe Systems Incorporated
6% remove
Adobe Flash Player 9 ActiveX is software for viewing multimedia, Rich Internet Applications, and streaming video and audio, on a computer web browser. Flash Player runs SWF files that can be created by the Adobe Flash authoring tool, by Adobe Flex or by a number of other Macromedia and third party tools. Flash Player is freely available as a plugin for recent versions of web browsers (such as Internet Explorer, Mozilla Firefox, Opera, a...
Adobe Systems Incorporated
9% remove
The Adobe Flash Player ActiveX is software for viewing multimedia, Rich Internet Applications, and streaming video and audio, on a computer web browser. Flash Player runs SWF files that can be created by the Adobe Flash authoring tool, by Adobe Flex or by a number of other Macromedia and third party tools. Flash Player is freely available as a plugin for recent versions of web browsers (such as Internet Explorer, Mozilla Firefox, Opera,...
Adobe Systems Incorporated
7% remove
Adobe Flash is a multimedia platform used to add animation, video, and interactivity to web pages. Flash is frequently used for advertisements, games and flash animations for broadcast. The Adobe Flash Player is software for viewing multimedia, Rich Internet Applications, and streaming video and audio, on a computer web browser or on supported mobile devices. Flash Player is freely available as a plugin for recent versions of web brows...
Adobe Systems Incorporated
3% remove
The Adobe Flash Player is software for viewing multimedia, Rich Internet Applications, and streaming video and audio, on a computer web browser. Flash Player runs SWF files that can be created by the Adobe Flash authoring tool, by Adobe Flex or by a number of other Macromedia and third party tools. Flash Player is freely available as a plugin for recent versions of web browsers (such as Internet Explorer, Mozilla Firefox, Opera, and Saf...
Adobe Systems Incorporated
9% remove
Adobe Flash Player 11 ActiveX is software for viewing multimedia, Rich Internet Applications, and streaming video and audio, on a computer web browser. Flash Player runs SWF files that can be created by the Adobe Flash authoring tool, by Adobe Flex or by a number of other Macromedia and third party tools. Flash Player is freely available as a plugin for recent versions of web browsers (such as Internet Explorer, Mozilla Firefox, Opera, ...
Adobe Systems Incorporated
11% remove
Adobe® Flash® Player 12 drives innovation for rich, engaging digital experiences with new features for cross-platform browser-based viewing of expressive rich internet applications, content, and videos across devices. This beta release provides access to the Flash Player 12 runtime for Mac OS and Windows desktop environments. We are moving to a rapid beta release cycle using "Background Update". We encourage you to subscribe so you can ...
Adobe Systems Incorporated
12% remove
Cross-platform plugin plays animations, videos and sound files in .SWF format. Adobe® Flash® Player is a lightweight browser plug-in and rich Internet application runtime that delivers consistent and engaging user experiences.
Adobe Systems Incorporated
3% remove
Adobe® Flash® Player 13 drives innovation for rich, engaging digital experiences with new features for cross-platform browser-based viewing of expressive rich internet applications, content, and videos across devices. This beta release provides access to the Flash Player 13 runtime for Mac OS and Windows desktop environments.
Adobe Systems Incorporated
4% remove
Cross-platform plugin plays animations, videos and sound files in .SWF format.
Adobe Systems Incorporated
3% remove
Cross-platform plugin plays animations, videos and sound files in .SWF format.
Adobe Systems Incorporated
8% remove
Cross-platform plugin plays animations, videos and sound files in .SWF format.
Adobe Systems Incorporated
4% remove
Cross-platform plugin plays animations, videos and sound files in .SWF format.
Adobe Systems Incorporated
11% remove
Adobe Flash Player is the standard for delivering high-impact, rich Web content. Designs, animation, and application user interfaces are deployed immediately across all browsers and platforms, attracting and engaging users with a rich Web experience.
Adobe Systems Incorporated
8% remove
Adobe Systems Incorporated
6% remove
Adobe Systems Incorporated
8% remove

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'AdobeFlashPlayerUpdateSvc' (Adobe Flash Player Update Service)
  • AdobeFlashPlayerUpdateSvc
Scheduled tasks
  • The job 'AdobeFlashPlayerUpdate 2' runs on boot in the path '\AdobeFlashPlayerUpdate 2'
  • The task 'AdobeFlashPlayerUpdate' in the path '\AdobeFlashPlayerUpdate'
  • The job 'Adobe Flash Player Updater' runs daily in the path '\Adobe Flash Player Updater'
  • Entry path 'C:\WIN12515\Tasks\Adobe Flash Player Updater.job'
  • Entry path 'C:\WINDOWS.0\Tasks\Adobe Flash Player Updater.job'
  • Entry path 'K:\WINXPSP2\Tasks\Adobe Flash Player Updater.job'
  • Entry path 'C:\WINDOWS1.1\Tasks\Adobe Flash Player Updater.job'
  • Entry path 'C:\WINXP\Tasks\Adobe Flash Player Updater.job'
  • Entry path 'D:\WINDOWS\Tasks\Adobe Flash Player Updater.job'
  • Entry path 'E:\WINDOWS\Tasks\Adobe Flash Player Updater.job'
  • Entry path 'C:\WINDOWS\Tasks\Adobe Flash Player Updater.job'
  • Entry path '\Adobe Flash Player Updater'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
  • Login entry path '\AdobeFlashPlayerUpdate 2'
  • Login entry path 'C:\WINDOWS\Tasks\Adobe Flash Player Updater.job'

MalwareMalware detections

Based on 40+ industry antivirus scanners, 32 of them detected the following malware.
Antivirus engineEngine versionDetection
Agnitum 5.5.1.3 Trojan.DL.MultiDL!X2R8ab5Q6EU
AhnLab V3 Internet Security 2013.09.30 ASD.Prevention
Avira AntiVir 7.11.105.38 TR/Downloader.Gen
Antiy Labs AVL 2.0.3.7 Trojan/Win32.MultiDL
avast! 8.0.1489.320 Win32:Agent-ARRQ [Trj]
AVG 13.0.0.3169 Generic34.COAU
BitDefender 7.2 Trojan.Downloader.JQAC
CAT Quick Heal 9.13.12.00 Trojan.Agent.gen
Commtouch 5.4.1.7 W32/Trojan.JVTT-7664
Dr.Web 8.13.9.30 Trojan.DownLoad3.26006
Emsisoft Anti-Malware 3.0.0.589 Trojan.Downloader.JQAC (B)
ESET NOD32 7.8856 Win32/Downloader.Agent.L
Fortinet 5.1.147.0 W32/MultiDL.C!tr.dldr
F-Prot v6.4.7.1.166 W32/Trojan3.GBS
F-Secure 11.0.19100.45 Trojan-Downloader:W32/Mevade.A
G Data 13.9.22 Trojan.Downloader.JQAC
K7 AntiVirus 9.172.9720 Trojan-Downloader
K7GW 12.7.0.14 Trojan-Downloader
Kaspersky 9.0.0.837 Trojan-Downloader.Win32.MultiDL.c
Malwarebytes 1.75.0.1 Trojan.Sefnit
McAfee 5.600.1067 Generic Downloader.z
McAfee Gateway Anti-Malware v2013-dat Generic Downloader.z
Microsoft Security Essentials 1.9901.0 Trojan:Win32/Sefnit.AS
eScan by MicroWorld 12.0.250.0 Trojan.Downloader.JQAC
nProtect 2013-09-27.03 Trojan-Downloader/W32.Agent.163328.AE
PC Tools 9.0.0.2 Trojan.Gen
Sophos 4.93.0 Troj/DwnLdr-LAZ
Symantec 20131.1.5.61 Downloader
Trend Micro 9.740.0.1012 TROJ_DLOADE.FBV
Trend Micro HouseCall 9.700.0.1001 TROJ_DLOADE.FBV
Vba32 AntiVirus 3.12.24.3 TrojanDownloader.MultiDL
VIPRE Antivirus 21938 Trojan.Win32.Generic!BT

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00058830%
0.028634%
Kernel CPU:0.00036372%
0.013761%
User CPU:0.00022459%
0.014873%
Kernel CPU time:234,042 ms/min
100,923,805ms/min
CPU cycles:10,842/sec
17,470,203/sec
Memory
Private memory:2.14 MB
21.59 MB
Private (maximum):4.42 MB
Private (minimum):3.3 MB
Non-paged memory:2.14 MB
21.59 MB
Virtual memory:74.07 MB
140.96 MB
Virtual memory (peak):88.53 MB
169.69 MB
Working set:3.49 MB
18.61 MB
Working set (peak):5.1 MB
37.95 MB
Page faults:4,366/min
2,039/min
I/O
I/O read transfer:95 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:152 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:444 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:4
12
Handles:122
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command lines:
  • C:\Windows\System32\macromed\flash\flashplayerupdateservice.exe
  • C:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe
Owner:User
Windows Service
Service name:AdobeFlashPlayerUpdateSvc
Display name:Adobe Flash Player Update Service
Description:“This service keeps your Adobe Flash Player installation up to date with the latest enhancements and security fixes.”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
FlashPlayerUpdateService.exe (main module)
Total CPU:0.00073907%
0.272967%
Kernel CPU:0.00046915%
0.107585%
User CPU:0.00026991%
0.165382%
CPU cycles:14,265/sec
5,741,424/sec
Memory:180 KB
1.16 MB
sechost.dll
Total CPU:0.00036070%
Kernel CPU:0.00000000%
User CPU:0.00036070%
CPU cycles:3,213/sec
Memory:100 KB
wow64.dll
Total CPU:0.00018628%
Kernel CPU:0.00000000%
User CPU:0.00018628%
CPU cycles:23,089/sec
Memory:276 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 44.00%
Windows 7 Ultimate 14.50%
Windows 8.1 11.50%
Windows 7 Professional 6.00%
Windows 8.1 Pro 4.50%
Windows 8.1 Pro with Media Center 3.00%
Windows 8 Single Language 3.00%
Windows 8.1 Single Language 3.00%
Windows 7 Home Basic 3.00%
Windows 8 Pro 3.00%
Windows 8 2.00%
Windows 8 Enterprise N 1.00%
Windows Seven Black Edition 1.00%
Windows Vista Home Premium 0.50%

Distribution by countryDistribution by country

United States installs about 52.02% of Adobe® Flash® Player Update Service.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 18.70%
Hewlett-Packard 18.29%
Acer 14.23%
ASUS 11.38%
Lenovo 11.38%
Toshiba 9.76%
Sony 8.13%
Samsung 2.44%
GIGABYTE 2.44%
Alienware 1.63%
Intel 1.63%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE