Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1505) 33.59%
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459) 32.71%
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459) 1.11%
7.6.7600.243 (winmain_wtr_wsus3sp2(oobla).110811-1411) 0.55%
7.4.7600.226 (winmain_wtr_wsus3sp2(wmbla).090806-1850) 0.33%
7.4.7600.226 (winmain_wtr_wsus3sp2(wmbla).090806-1834) 1.11%
7.1.6001.65 (Longhorn(wmbla).080123-1638) 0.11%
7.0.6000.374 (winmain(wmbla).070416-2057) 0.11%
5.8.0.2694 built by: dnsrv(wmbla) 0.11%
5.8.0.2469 built by: lab01_n(wmbla) 0.11%
5.4.3790.5512 (xpsp.080413-0852) 20.84%
5.4.3790.5512 (xpsp.080413-0852) 0.44%
5.4.3790.5512 (xpsp.080413-0852) 1.22%
5.4.3790.5512 (xpsp.080413-0852) 0.22%
5.4.3790.5512 (xpsp.080413-0852) 1.11%
5.4.3790.5512 (xpsp.080413-0852) 0.11%
5.4.3790.5512 (xpsp.080413-0852) 0.11%
5.4.3790.5512 (xpsp.080413-0852) 0.89%
5.4.3790.5512 (xpsp.080413-0852) 0.22%
5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) 4.77%
5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) 0.22%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
SetServiceStatus
crypt32.dll
CertOpenStore, CertFreeCertificateChain, CertVerifyCertificateChainPolicy, CertGetCertificateChain, CryptHashPublicKeyInfo, CertGetCertificateContextProperty, CryptUnprotectData, CryptProtectData, CertGetPublicKeyLength, CertFreeCertificateContext, CertControlStore, CertFindCertificateInStore, CertCloseStore
esent.dll
JetUpdate, JetGotoBookmark, JetRetrieveColumns, JetCreateTable, JetDeleteTable, JetBeginSession, JetEndSession, JetSetSystemParameter, JetIntersectIndexes, JetIndexRecordCount, JetSetCurrentIndex, JetSeek, JetSetIndexRange, JetMakeKey, JetGetBookmark, JetPrepareUpdate, JetSetColumns, JetMove, JetDelete, JetGetColumnInfo, JetAddColumn, JetCloseTable, JetCreateIndex2, JetTerm2, JetInit, JetDetachDatabase, JetCreateDatabase, JetOpenDatabase, JetAttachDatabase, JetBeginTransaction, JetCommitTransaction, JetRollback, JetOpenTable, JetEscrowUpdate, JetCloseDatabase, JetRenameTable, JetDeleteIndex, JetDeleteColumn, JetGetTableColumnInfo
iphlpapi.dll
GetAdaptersInfo
kernel32.dll
DllMain, DeleteCriticalSection, DisableThreadLibraryCalls, LeaveCriticalSection, EnterCriticalSection, FreeLibrary, GetProcAddress, Sleep, InterlockedCompareExchange, RtlUnwind, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetSystemDirectoryW, lstrlenW, LoadLibraryExW, SetLastError, GetLastError, InitializeCriticalSectionAndSpinCount, InterlockedExchange, CloseHandle
mspatcha.dll
ApplyPatchToFileByHandles
msvcrt.dll
DllMain
ntdll.dll
RtlUnwind, VerSetConditionMask, NtQuerySystemInformation
rpcrt4.dll
RpcBindingFromStringBindingW, UuidToStringW, RpcStringFreeW, UuidFromStringW, UuidCreate, RpcBindingSetAuthInfoExW, RpcBindingFree, NdrClientCall2, I_RpcBindingInqTransportType, RpcStringFreeA, UuidToStringA
shell32.dll
SHGetFolderPathW
shlwapi.dll
PathFindExtensionW, PathStripToRootW, PathIsUNCW, PathIsRelativeW, SHDeleteKeyW, StrRChrW, PathStripPathW, StrToIntW, StrChrW, StrToIntExW, PathIsRootW
user32.dll
ExitWindowsEx, GetUserObjectInformationW, OpenWindowStationW, GetActiveWindow, GetSystemMetrics, LoadStringW, DispatchMessageW, TranslateMessage, GetMessageW, PostThreadMessageW, CharNextW, CloseWindowStation
userenv.dll
UnregisterGPNotification, CreateEnvironmentBlock, DestroyEnvironmentBlock, RegisterGPNotification
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
winhttp.dll
WinHttpGetDefaultProxyConfiguration, WinHttpGetProxyForUrl, WinHttpGetIEProxyConfigForCurrentUser, WinHttpQueryHeaders, WinHttpQueryAuthSchemes, WinHttpSetOption, WinHttpConnect, WinHttpSetTimeouts, WinHttpQueryOption, WinHttpOpenRequest, WinHttpReceiveResponse, WinHttpSetCredentials, WinHttpCrackUrl, WinHttpOpen, WinHttpSendRequest, WinHttpAddRequestHeaders, WinHttpCloseHandle, WinHttpReadData
winspool.drv
ClosePrinter, GetPrinterDataW, OpenPrinterW, EnumPrinterDriversW
winsta.dll
WinStationQueryInformationW
wintrust.dll
WTHelperProvDataFromStateData, WinVerifyTrust, WTHelperGetProvCertFromChain, WTHelperGetProvSignerFromChain
ws2_32.dll
WSAIoctl, WSASocketW
wtsapi32.dll
WTSFreeMemory, WTSQuerySessionInformationW, WTSEnumerateSessionsW
Export table
DllInstall
DllMain
DllRegisterServer
DllUnregisterServer
GeneralizeForImaging
GetAUOptionsEx
GetEngineStatusInfo
RegisterServiceVersion
ServiceHandler
ServiceMain
WUAutoUpdateAtShutdown
WUCheckForUpdatesAtShutdown
WUServiceMain

wuaueng.dll

Windows Update Agent by Microsoft Corporation (Signed)

Remove wuaueng.dll
Version:   5.4.3790.5512 (xpsp.080413-0852)
MD5:   c9f4a98d40483a3e1ab25d4bbfbb5372
SHA1:   6ce86c2d3c2d7f925f9961b0570e504ba6180fe1
SHA256:   ec4ec34aeb4c895c1caf91056e3cc76332f2a5ef169ea5f1d31bfcf1954ff133
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is wuaueng.dll?

If Windows Update or Automatic Updates is turned on, the latest version of the Windows Update Agent will be automatically downloaded and installed on your computer. If you go to Windows Update before it gets installed automatically, you will see a message to install the Windows Update Agent.

About wuaueng.dll (from Microsoft Corporation)

When you turn on automatic updating, most updates will download and install without you having to lift a finger. But sometimes Windows Update will need your input during an installation. In this case,

DetailsDetails

File name:wuaueng.dll
Publisher:Microsoft Corporation
Product name:Windows Update Agent
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\wuaueng.dll
Original name:wuaueng.dll.mui
File version:5.4.3790.5512 (xpsp.080413-0852)
Product version:5.4.3790.5512
Size:6.5 KB (6,656 bytes)
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Expiration date:Monday, April 26, 2010
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'
  • Shared name is 'wuauserv'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 48.50%
Windows 7 Ultimate 20.00%
Windows 7 Professional 10.50%
Windows Vista Home Premium 9.00%
Microsoft Windows XP 6.00%
Windows Vista Home Basic 2.00%
Windows 7 Home Basic 1.00%
Windows 7 Starter 1.00%
Windows Vista Business 1.00%
Windows 7 Enterprise 0.50%
Windows Vista Ultimate 0.50%

Distribution by countryDistribution by country

United States installs about 46.70% of Windows Update Agent.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 24.15%
Hewlett-Packard 16.23%
ASUS 12.83%
Toshiba 9.81%
Acer 8.30%
Sony 6.79%
GIGABYTE 3.77%
Intel 3.77%
Lenovo 3.77%
MSI 2.26%
American Megatrends 2.26%
Samsung 1.89%
Alienware 1.51%
Compaq 0.75%
Medion 0.75%
NEC 0.75%
Packard Bell 0.38%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE