File details
File name: softwareupdate.exe
Name: Apple Software Update
Description: Apple Software Update
Version: 2.1.3
Size: 548.81 KB
Original file name: SoftwareUpdate.exe
Digital certificate
Certificate authority:
VeriSign
Effective date: 6/26/2007
Expiration date: 6/26/2009
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0638457130%
Privileged CPU:
0.0061684574%

User CPU:
0.05767725557921%

Privileged CPU time: 817.24 ms
Privileged CPU time /min: 4 ms
CPU cycle count:
265,727,738
CPU cycle count /min: 139,438,032
Context switches /sec:
40
 | Memory utilization averages |
Committed memory:
175.32 MB
Peak committed memory: 181.93 MB
Paged memory:
13.21 MB
Peak paged memory: 13.44 MB
Paged system memory:
291.93 KB
Non-paged system memory: 20.79 KB
Working set memory:
6.78 MB
Peak working set memory: 25.37 MB
Min working set memory: 4.49 MB
Private memory:
13.21 MB
Page faults:
23,982
Page faults /min: 90
 | Process I/O averages |
Total read operations:
993
Read operations /min: 6
Total read transfer: 1.2 MB
Read transfer /min: 6.74 KB
Total write operations:
242
Write operations /min: 2
Total write transfer: 606.13 KB
Write transfer /min: 3.3 KB
Total other operations:
6,698
Other operations /min: 39
Total other transfer: 99.89 KB
Other Transfer /min: 560 Bytes
 | GUI Object Averages |
GDI objects:
118
Peak GDI objects: 104
USER objects:
69
Peak USER objects: 76
Resources
Handle count average: 761
Thread count average: 9
Thread resource averages
Total CPU: 0.001971422429%
Privileged CPU: 0.001378362085%
User CPU: 0.000593060343%
CPU Cycle count /sec: 991,067
Context switches /sec: 7
Module memory size: 568 KB
wow64.dll

Total CPU: 0.000462850324%
Privileged CPU: 0.000427214583%
User CPU: 0.000035635741%
CPU Cycle count /sec: 88,338
Module memory size: 252 KB
wininet.dll

Total CPU: 0.000132793130%
Privileged CPU: 0.000132793130%
User CPU: 0.000000000000%
CPU Cycle count /sec: 16,354
Module memory size: 1.11 MB
ntdll.dll

Total CPU: 0.000071043158%
Privileged CPU: 0.000071043158%
User CPU: 0.000000000000%
CPU Cycle count /sec: 2,724
Module memory size: 1.67 MB
wininet.dll

Total CPU: 0.000043671480%
Privileged CPU: 0.000021835740%
User CPU: 0.000021835740%
CPU Cycle count /sec: 41,379
Context switches /sec: 2
Module memory size: 1.11 MB
ntdll.dll

Total CPU: 0.000032753613%
Privileged CPU: 0.000032753613%
User CPU: 0.000000000000%
CPU Cycle count /sec: 744
Module memory size: 1.16 MB
Total CPU: 0.000010918606%
Privileged CPU: 0.000000000000%
User CPU: 0.000010918606%
CPU Cycle count /sec: 48,267
Context switches /sec: 1
Module memory size: 680 KB
gdiplus.dll

Total CPU: 0.000010917761%
Privileged CPU: 0.000010917761%
User CPU: 0.000000000000%
CPU Cycle count /sec: 91
Module memory size: 1.67 MB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 32-bit
Parent Processes
Process Commands
"C:\Program Files\Apple Software Update\SoftwareUpdate.exe" -background
"C:\Program Files\Apple Software Update\SoftwareUpdate.exe" -background
"C:\Program Files\Apple Software Update\SoftwareUpdate.exe" -task
"C:\Program Files\Apple Software Update\SoftwareUpdate.exe" -task
Scheduled task details
CLSID: {025997B9-D40F-4339-917F-3C36E28A6852}
Command: \{025997B9-D40F-4339-917F-3C36E28A6852}
Network connectivity
UDP: LISTENING on port 61306
UDP: LISTENING on port 54602
UDP: LISTENING on port 4314
UDP: LISTENING on port 50587
UDP: LISTENING on port 57746
Image hashes
MD5: 34ebd4ff6a24d86bb4716d6afcc1a89b
SHA-1: 9b5c1dd5c2f7c30a6a303c036406acf4d6be48e0
SHA-256: 70de40de41b9de3b0263b063bbf54e8e5af9860a1379b5d05e9b0a36ee604f62
PE image details
File entropy: 6.34789
File packed: No
Import Table
advapi32.dll

LookupPrivilegeValueW
SetKernelObjectSecurity
RegCloseKey
RegOpenKeyExW
RegQueryValueExW
RegQueryValueW
RegOpenKeyW
RegEnumKeyW
AllocateAndInitializeSid
CheckTokenMembership
FreeSid
CreateProcessAsUserW
RegEnumKeyExW
RegQueryInfoKeyW
RegSetValueExW
RegCreateKeyExW
RegDeleteValueW
RegDeleteKeyW
LookupAccountNameW
EqualSid
OpenThreadToken
GetTokenInformation
GetKernelObjectSecurity
AdjustTokenPrivileges
MakeAbsoluteSD
SetEntriesInAclW
SetSecurityDescriptorDacl
OpenProcessToken
comdlg32.dll

gdi32.dll

SetMapMode
LineTo
MoveToEx
SetBkMode
GetViewportExtEx
GetWindowExtEx
GetPixel
PtVisible
RectVisible
TextOutW
ExtTextOutW
RestoreDC
SaveDC
Ellipse
SetROP2
CreateEllipticRgn
CreateRectRgnIndirect
CreateBitmap
SetBkColor
SetTextColor
GetClipBox
GetDeviceCaps
CreateCompatibleBitmap
GetStockObject
CreatePen
SetRectRgn
CombineRgn
CreateFontIndirectW
CreateDIBSection
CreateSolidBrush
CreateRectRgn
FillRgn
CreateCompatibleDC
DeleteDC
SelectObject
SetDIBColorTable
GetDIBColorTable
GetObjectW
BitBlt
LPtoDP
DeleteObject
GetTextColor
GetBkColor
GetRgnBox
GetMapMode
GetTextExtentPoint32W
CreatePatternBrush
ExtSelectClipRgn
ScaleWindowExtEx
SetWindowExtEx
ScaleViewportExtEx
SetViewportExtEx
OffsetViewportOrgEx
SetViewportOrgEx
Escape
StretchBlt
kernel32.dll

WritePrivateProfileStringW
GetTickCount
FileTimeToLocalFileTime
FindClose
FindFirstFileW
CreateFileW
GetFileAttributesW
GetFileSizeEx
GetFileTime
TlsGetValue
GlobalReAlloc
GlobalHandle
TlsSetValue
LocalReAlloc
TlsFree
GlobalGetAtomNameW
GlobalFlags
GetFullPathNameW
ReadFile
WriteFile
SetFilePointer
FlushFileBuffers
LockFile
UnlockFile
SetEndOfFile
GetFileSize
DuplicateHandle
GetVolumeInformationW
SetErrorMode
GetStartupInfoW
RtlUnwind
HeapAlloc
VirtualProtect
VirtualAlloc
VirtualQuery
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetSystemTimeAsFileTime
HeapReAlloc
ExitProcess
HeapSize
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
HeapCreate
VirtualFree
QueryPerformanceCounter
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
LCMapStringW
InitializeCriticalSectionAndSpinCount
GetTimeZoneInformation
GetLocaleInfoA
LCMapStringA
GetStringTypeA
GetStringTypeW
GetConsoleCP
GetConsoleMode
CreateFileA
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
SetEnvironmentVariableA
ConvertDefaultLocale
EnumResourceLanguagesW
lstrcmpA
GetLocaleInfoW
CompareStringA
GetCurrentProcessId
GetModuleHandleA
FileTimeToSystemTime
GetThreadLocale
GetCurrentThreadId
GlobalAddAtomW
GlobalFindAtomW
GlobalDeleteAtom
CompareStringW
LoadLibraryA
lstrcmpW
GetVersionExA
FreeResource
GlobalFree
GlobalAlloc
GlobalLock
GlobalUnlock
FormatMessageW
MulDiv
GetProcessHeap
HeapFree
WideCharToMultiByte
lstrlenA
SetSystemPowerState
CreateDirectoryW
GetSystemInfo
GetVersionExW
Sleep
CreateProcessW
LoadLibraryExW
FreeLibrary
InterlockedIncrement
lstrcmpiW
OpenProcess
GetCurrentThread
LocalAlloc
LocalFree
CreateMutexW
ReleaseMutex
GetVersion
GetCurrentProcess
CloseHandle
DeleteCriticalSection
InitializeCriticalSection
RaiseException
SetLastError
GetProcAddress
GetModuleHandleW
LoadLibraryW
MultiByteToWideChar
GetLastError
SetEvent
ResetEvent
EnterCriticalSection
LeaveCriticalSection
InterlockedExchange
GetModuleFileNameW
lstrlenW
InterlockedDecrement
FindResourceW
LoadResource
LockResource
SizeofResource
TlsAlloc
msimg32.dll

ole32.dll

CoSetProxyBlanket
CoGetObject
StringFromGUID2
CoTaskMemFree
CoRegisterClassObject
CoTaskMemRealloc
CoTaskMemAlloc
CLSIDFromProgID
OleUninitialize
CoFreeUnusedLibraries
OleInitialize
CoDisconnectObject
CoGetClassObject
CoRevokeClassObject
StgOpenStorageOnILockBytes
CoRegisterMessageFilter
CLSIDFromString
OleFlushClipboard
OleIsCurrentClipboard
CreateILockBytesOnHGlobal
CoCreateInstance
StgCreateDocfileOnILockBytes
oledlg.dll

psapi.dll

EnumProcesses
EnumProcessModules
GetModuleBaseNameW
shell32.dll

SHGetFolderPathW
DragFinish
DragQueryFileW
ShellExecuteW
shlwapi.dll

PathFindFileNameW
PathStripToRootW
PathIsUNCW
PathFindExtensionW
user32.dll
version.dll

GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
wininet.dll

winspool.drv

OpenPrinterW
DocumentPropertiesW
ClosePrinter
wtsapi32.dll

WTSFreeMemory
WTSQuerySessionInformationW
WTSEnumerateSessionsW
WTSEnumerateProcessesW