Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

4.6.0.2935 42.86%
4.6.0.1694 14.29%
4.5.0.1810 14.29%
4.5.0.1499 14.29%
4.0.0.1496 14.29%

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegOpenKeyExA, CloseServiceHandle, OpenSCManagerW, QueryServiceStatus, OpenServiceW, RegCloseKey, RegQueryValueExA
comctl32.dll
ImageList_Create, ImageList_ReplaceIcon, PropertySheetW
gdi32.dll
GetViewportOrgEx, SetViewportOrgEx, DPtoLP, GetStockObject, DeleteDC, CreateCompatibleBitmap, SetTextAlign, BitBlt, Rectangle, SetBkMode, SelectObject, CreateCompatibleDC, CreateSolidBrush, GetDeviceCaps, CreateBrushIndirect, SetTextColor, SetBkColor, DeleteObject
kernel32.dll
GetMailslotInfo, GetLocalTime, Sleep, WaitForMultipleObjects, ResetEvent, GetCurrentProcessId, DeleteCriticalSection, SetLastError, InterlockedExchange, InitializeCriticalSection, GetLastError, InterlockedIncrement, SizeofResource, LoadResource, SetProcessWorkingSetSize, CompareStringA, GetModuleHandleA, GetModuleFileNameA, GetWindowsDirectoryA, GetSystemDirectoryA, LoadLibraryA, GetProcAddress, GetACP, GetThreadLocale, GetVersionExA, FlushInstructionCache, GetCurrentProcess, InterlockedDecrement, lstrlenA, GetTimeFormatA, GetDateFormatA, SystemTimeToTzSpecificLocalTime, GetTimeZoneInformation, GetLocaleInfoA, IsValidLocale, GetUserDefaultLangID, RaiseException, CloseHandle, EnterCriticalSection, LeaveCriticalSection, WaitForSingleObject, SetEvent, FreeLibrary, WriteFile, GetCurrentThreadId, MulDiv, ReadFile, InterlockedCompareExchange, HeapFree, GetProcessHeap, HeapAlloc, IsProcessorFeaturePresent, VirtualFree, VirtualAlloc, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetUserDefaultLCID, GetSystemTimeAsFileTime, GetTickCount, QueryPerformanceCounter, IsDebuggerPresent, LocalFree, ExitProcess
msvcp71.dll
DllMain
msvcp80.dll
DllMain
msvcr71.dll
DllMain
msvcr80.dll
DllMain
nacmnlib3_71.dll
LoadResourceDLLW, GetResString
nailog3.dll
_naimcomn_SetSystem@4, _naimcomn_InitTracer@0, _naimcomn_SetLogToStdout@4, _naimcomn_StartFileLogging@4, naimcomn_LogInfoW, _naimcomn_EndFileLogging@0
ole32.dll
CreateStreamOnHGlobal, CoMarshalInterface, CoInitializeEx, CoInitializeSecurity, CoResumeClassObjects, CoTaskMemFree, CoRegisterClassObject, CoRevokeClassObject, CoTaskMemRealloc, CoTaskMemAlloc, StringFromGUID2, CoCreateInstance, CoUninitialize, CoInitialize
shell32.dll
SHGetFolderPathW
shlwapi.dll
PathFindExtensionW
user32.dll
ShowWindow, IsWindowVisible, IsWindow, SetCursor, InvalidateRect, RedrawWindow, KillTimer, SetTimer, TrackPopupMenu, SetActiveWindow, DestroyWindow, GetDesktopWindow, SetFocus, IsDlgButtonChecked, GetDlgItemInt, ScreenToClient, TranslateMessage, GetWindow, GetWindowRect, BeginPaint, FillRect, GetSysColor, OffsetRect, UpdateWindow, GetMessagePos, CheckDlgButton, GetDC, ReleaseDC, CreatePopupMenu, UnregisterClassA, GetClientRect, EndDialog, MapWindowPoints, SetWindowPos, GetDlgItem, GetParent, GetDlgCtrlID, IsIconic, GetForegroundWindow, PostQuitMessage, SetForegroundWindow, EndPaint, SetDlgItemInt, CheckRadioButton, CreateCursor, DestroyCursor, DestroyIcon, GetCursorPos, GetAsyncKeyState, DestroyMenu, GetSubMenu, GetActiveWindow, MsgWaitForMultipleObjects

udaterui.exe

McAfee Agent by McAfee (Signed)

Remove udaterui.exe
Version:   4.6.0.1694
MD5:   d2480287c344b05e0813287e0b40e84c
SHA1:   2061989f8d8183859424f6165e699df210c32611
SHA256:   fbbf20dc8075ac753309b5d3c1b432815542a0a5d43b0226229f74139e0251ea

What is udaterui.exe?

Common User Interface is part of McAfee Agent. The McAfee Agent is a process that runs in the taskbar when the McAfee Security Suite or McAfee Internet Security has been installed on a PC. The McAfee Agent offers access to specific functions instead of opening the full protection center program. Once the McAfee Agent has been installed, it will show up in the notifications area of the taskbar and will load on each reboot.

Overview

udaterui.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). This is typically installed with the program McAfee Agent published by McAfee, Inc.. The file is digitally signed by McAfee which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:udaterui.exe
Publisher:McAfee, Inc.
Product name:McAfee Agent
Description:Common User Interface
Typical file path:C:\Program Files\mcafee\common framework\udaterui.exe
Original name:UpdUI.exe
File version:4.6.0.1694
Product version:4.6.0
Size:325.31 KB (333,120 bytes)
Certificate
Issued to:McAfee
Authority (CA):VeriSign
Expiration date:Monday, October 10, 2011
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
McAfee, Inc.
11% remove
The McAfee Agent is placed on the taskbar when the McAfee Security Suite or McAfee Internet Security has been installed on a computer. The McAfee Agent offers quick access to specific functions instead of opening the full protection center program. Once the McAfee Agent has been installed, it will show up in the taskbar with the letter M.

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'McAfeeUpdaterUI' → "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00027436%
0.028634%
Kernel CPU:0.00018021%
0.013761%
User CPU:0.00009415%
0.014873%
Kernel CPU time:546 ms/min
100,923,805ms/min
CPU cycles:154,921/sec
17,470,203/sec
Memory
Private memory:2.98 MB
21.59 MB
Private (maximum):5.71 MB
Private (minimum):2.04 MB
Non-paged memory:2.98 MB
21.59 MB
Virtual memory:79.69 MB
140.96 MB
Virtual memory (peak):82.88 MB
169.69 MB
Working set:3.04 MB
18.61 MB
Working set (peak):8.14 MB
37.95 MB
Page faults:4,658/min
2,039/min
I/O
I/O read transfer:124 Bytes/sec
1.02 MB/min
I/O read operations:2/sec
343/min
I/O write transfer:0 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:57 Bytes/sec
448.09 KB/min
I/O other operations:3/sec
1,671/min
Resource allocations
Threads:7
12
Handles:136
600
GUI GDI count:46
103
GUI GDI peak:48
142
GUI USER count:43
49
GUI USER peak:45
71

BehaviorsProcess properties

Integrety level:Medium
Platform:32-bit
Command line:"C:\Program Files\mcafee\common framework\udaterui.exe" /startedfromrunkey
Owner:User
Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

ResourcesThreads

Averages
 
UdaterUI.exe (main module)
Total CPU:0.00404138%
0.272967%
Kernel CPU:0.00058477%
0.107585%
User CPU:0.00345661%
0.165382%
CPU cycles:211,804/sec
5,741,424/sec
Memory:328 KB
1.16 MB
MSVCR80.dll
Total CPU:0.00009203%
Kernel CPU:0.00006327%
User CPU:0.00002876%
CPU cycles:11,237/sec
Memory:620 KB
msiltcfg.dll
Total CPU:0.00002109%
Kernel CPU:0.00000000%
User CPU:0.00002109%
CPU cycles:8/sec
Memory:28 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 42.86%
Windows 7 Professional 42.86%
Windows 8 Enterprise 14.29%

Distribution by countryDistribution by country

Indonesia installs about 28.57% of McAfee Agent.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Toshiba 66.67%
Hewlett-Packard 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE