Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

4.6.0.2935 42.86%
4.6.0.1694 14.29%
4.5.0.1810 14.29%
4.5.0.1499 14.29%
4.0.0.1496 14.29%

Relationships

Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegOpenKeyExA, CloseServiceHandle, OpenSCManagerW, QueryServiceStatus, OpenServiceW, RegCloseKey, RegQueryValueExA
comctl32.dll
ImageList_Create, ImageList_ReplaceIcon, PropertySheetW
gdi32.dll
GetViewportOrgEx, SetViewportOrgEx, DPtoLP, GetStockObject, DeleteDC, CreateCompatibleBitmap, SetTextAlign, BitBlt, Rectangle, SetBkMode, SelectObject, CreateCompatibleDC, CreateSolidBrush, GetDeviceCaps, CreateBrushIndirect, SetTextColor, SetBkColor, DeleteObject
kernel32.dll
GetMailslotInfo, GetLocalTime, Sleep, WaitForMultipleObjects, ResetEvent, GetCurrentProcessId, DeleteCriticalSection, SetLastError, InterlockedExchange, InitializeCriticalSection, GetLastError, InterlockedIncrement, SizeofResource, LoadResource, SetProcessWorkingSetSize, CompareStringA, GetModuleHandleA, GetModuleFileNameA, GetWindowsDirectoryA, GetSystemDirectoryA, LoadLibraryA, GetProcAddress, GetACP, GetThreadLocale, GetVersionExA, FlushInstructionCache, GetCurrentProcess, InterlockedDecrement, lstrlenA, GetTimeFormatA, GetDateFormatA, SystemTimeToTzSpecificLocalTime, GetTimeZoneInformation, GetLocaleInfoA, IsValidLocale, GetUserDefaultLangID, RaiseException, CloseHandle, EnterCriticalSection, LeaveCriticalSection, WaitForSingleObject, SetEvent, FreeLibrary, WriteFile, GetCurrentThreadId, MulDiv, ReadFile, InterlockedCompareExchange, HeapFree, GetProcessHeap, HeapAlloc, IsProcessorFeaturePresent, VirtualFree, VirtualAlloc, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetUserDefaultLCID, GetSystemTimeAsFileTime, GetTickCount, QueryPerformanceCounter, IsDebuggerPresent, LocalFree, ExitProcess
msvcp71.dll
DllMain
msvcp80.dll
DllMain
msvcr71.dll
DllMain
msvcr80.dll
DllMain
nacmnlib3_71.dll
LoadResourceDLLW, GetResString
nailog3.dll
_naimcomn_SetSystem@4, _naimcomn_InitTracer@0, _naimcomn_SetLogToStdout@4, _naimcomn_StartFileLogging@4, naimcomn_LogInfoW, _naimcomn_EndFileLogging@0
ole32.dll
CreateStreamOnHGlobal, CoMarshalInterface, CoInitializeEx, CoInitializeSecurity, CoResumeClassObjects, CoTaskMemFree, CoRegisterClassObject, CoRevokeClassObject, CoTaskMemRealloc, CoTaskMemAlloc, StringFromGUID2, CoCreateInstance, CoUninitialize, CoInitialize
shell32.dll
SHGetFolderPathW
shlwapi.dll
PathFindExtensionW
user32.dll
ShowWindow, IsWindowVisible, IsWindow, SetCursor, InvalidateRect, RedrawWindow, KillTimer, SetTimer, TrackPopupMenu, SetActiveWindow, DestroyWindow, GetDesktopWindow, SetFocus, IsDlgButtonChecked, GetDlgItemInt, ScreenToClient, TranslateMessage, GetWindow, GetWindowRect, BeginPaint, FillRect, GetSysColor, OffsetRect, UpdateWindow, GetMessagePos, CheckDlgButton, GetDC, ReleaseDC, CreatePopupMenu, UnregisterClassA, GetClientRect, EndDialog, MapWindowPoints, SetWindowPos, GetDlgItem, GetParent, GetDlgCtrlID, IsIconic, GetForegroundWindow, PostQuitMessage, SetForegroundWindow, EndPaint, SetDlgItemInt, CheckRadioButton, CreateCursor, DestroyCursor, DestroyIcon, GetCursorPos, GetAsyncKeyState, DestroyMenu, GetSubMenu, GetActiveWindow, MsgWaitForMultipleObjects

udaterui.exe

McAfee Agent by McAfee (Signed)

Remove udaterui.exe
Version:   4.0.0.1496
MD5:   0a74b5376b81e29bf5d4cdb9facc5e46
SHA1:   6660e0f762eaad053fed8a7edd36e8c32769729b
SHA256:   cc08da1ecbf5c211a89f022c69447972d68d76c2c17b22c9eb582eefd3d2bf6e

What is udaterui.exe?

Common User Interface is part of McAfee Agent. The McAfee Agent is a process that runs in the taskbar when the McAfee Security Suite or McAfee Internet Security has been installed on a PC. The McAfee Agent offers access to specific functions instead of opening the full protection center program. Once the McAfee Agent has been installed, it will show up in the notifications area of the taskbar and will load on each reboot.

Overview

udaterui.exe executes as a process with the local user's privileges. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). The file is digitally signed by McAfee which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:udaterui.exe
Publisher:McAfee, Inc.
Product name:McAfee Agent
Description:Common User Interface
Typical file path:C:\Program Files\mcafee\common framework\udaterui.exe
Original name:UpdUI.exe
File version:4.0.0.1496
Size:133.31 KB (136,512 bytes)
Build date:8/14/2009 6:09 PM
Certificate
Issued to:McAfee
Authority (CA):VeriSign
Expiration date:Monday, October 10, 2011
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'McAfeeUpdaterUI' → "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00012084%
0.028634%
Kernel CPU:0.00007465%
0.013761%
User CPU:0.00004620%
0.014873%
Kernel CPU time:656 ms/min
100,923,805ms/min
Context switches:73/sec
284/sec
Memory
Private memory:4.09 MB
21.59 MB
Private (maximum):1.3 MB
Private (minimum):636 KB
Non-paged memory:4.09 MB
21.59 MB
Virtual memory:43.91 MB
140.96 MB
Virtual memory (peak):47.23 MB
169.69 MB
Working set:1.3 MB
18.61 MB
Working set (peak):5.99 MB
37.95 MB
Page faults:2,677/min
2,039/min
I/O
I/O read transfer:455 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:0 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:22.5 KB/sec
448.09 KB/min
I/O other operations:960/sec
1,671/min
Resource allocations
Threads:5
12
Handles:111
600
GUI GDI count:54
103
GUI USER count:43
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command line:"C:\Program Files\mcafee\common framework\udaterui.exe" /startedfromrunkey
Owner:User
Parent process:Explorer.EXE (Windows Explorer by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 42.86%
Windows 7 Professional 42.86%
Windows 8 Enterprise 14.29%

Distribution by countryDistribution by country

Indonesia installs about 28.57% of McAfee Agent.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Toshiba 66.67%
Hewlett-Packard 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE