File details
File name: facebookupdate.exe
Name: Facebook Update
Description: Facebook Installer
Version: 1.2.205.0
Size: 134.86 KB
Original file name: FacebookUpdate.exe
Digital certificate
Certificate authority:
VeriSign
Expiration date: 6/20/2015
Resource utilization
 | CPU utilization averages |
Total CPU: 0.7856129012%
Privileged CPU:
0.7849096347%

User CPU:
0.00070326654298%

Privileged CPU time: 26 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
168,612,669
CPU cycle count /min: 277,493
 | Memory utilization averages |
Committed memory:
48.55 MB
Peak committed memory: 53.77 MB
Paged memory:
2.93 MB
Peak paged memory: 2.98 MB
Paged system memory:
84.05 KB
Non-paged system memory: 3.88 KB
Working set memory:
2.12 MB
Peak working set memory: 5.46 MB
Min working set memory: 2.12 MB
Private memory:
2.93 MB
Page faults:
2,627
Page faults /min: 4
 | Process I/O averages |
Total read operations:
14
Read operations /min: 1
Total read transfer: 56.85 KB
Read transfer /min: 96 Bytes
Total write operations:
4
Write operations /min: 1
Total write transfer: 464 Bytes
Write transfer /min: 0 Bytes
Total other operations:
802
Other operations /min: 1
Total other transfer: 13.76 KB
Other Transfer /min: 23 Bytes
 | GUI Object Averages |
GDI objects:
9
USER objects:
4
Resources
Handle count average: 109
Thread count average: 4
Thread resource averages
Total CPU: 0.000412499974%
Privileged CPU: 0.000274999982%
User CPU: 0.000137499991%
CPU Cycle count /sec: 9,389
Module memory size: 144 KB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 64-bit
Parent Processes
Process Commands
C:\users\user\appdata\Local\Facebook\Update\FacebookUpdate.exe /ua /installsource scheduler
C:\users\user\appdata\Local\Facebook\Update\FacebookUpdate.exe /ua /installsource scheduler
C:\users\user\appdata\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
Startup files (user) run details
Name: Facebook Update
Command: "C:\users\user\appdata\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
Scheduled task details
Name: FacebookUpdateTaskUserS-1-5-21-514042993-1789252401-1726877076-1000UA
Command: \FacebookUpdateTaskUserS-1-5-21-514042993-1789252401-1726877076-1000UA
Image hashes
MD5: 9eb925edc8cf1c3d06e50e9348b54a0a
SHA-1: 43c3dcfca002b416c67a96bedbaa007584f98404
SHA-256: 99c1f8d40a65e1f4975b0d1180b3056712832e0e8fbe829785fdd505b6222aea
PE image details
File packed: No
Import Table
advapi32.dll

GetTokenInformation
RegOpenKeyExW
OpenProcessToken
kernel32.dll

GetCommandLineW
FindResourceExW
FindResourceW
FreeLibrary
LoadResource
LoadLibraryExW
VerSetConditionMask
GetCurrentProcess
GetModuleHandleW
SizeofResource
GetModuleFileNameW
lstrlenW
RaiseException
VerifyVersionInfoW
GetLastError
GetProcAddress
LockResource
GetFileAttributesExW
CloseHandle
SetLastError
LocalAlloc
SetStdHandle
SetFilePointer
InterlockedExchange
LoadLibraryA
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSection
DeleteCriticalSection
GetVersionExA
HeapDestroy
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
GetProcessHeap
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetStartupInfoW
WideCharToMultiByte
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
Sleep
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
VirtualAlloc
RtlUnwind
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
InitializeCriticalSectionAndSpinCount
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
GetConsoleCP
GetConsoleMode
FlushFileBuffers
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CreateFileA
ole32.dll
