File details
File name: facebookupdate.exe
Name: Facebook Update
Description: Facebook Installer
Version: 1.2.205.0
Size: 134.86 KB
Original file name: FacebookUpdate.exe
Digital certificate
Certificate authority:
VeriSign
Expiration date: 6/20/2015
Resource utilization
 | CPU utilization averages |
Total CPU: 1.7868060053%
Privileged CPU:
0.1465712523%

User CPU:
1.64023475309073%

Privileged CPU time: 18211.6 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
420,428,145
CPU cycle count /min: 484,296
 | Memory utilization averages |
Committed memory:
63.3 MB
Peak committed memory: 65.25 MB
Paged memory:
3.07 MB
Peak paged memory: 3.1 MB
Paged system memory:
104.33 KB
Non-paged system memory: 9.73 KB
Working set memory:
1.27 MB
Peak working set memory: 6.71 MB
Min working set memory: 1.27 MB
Private memory:
3.07 MB
Page faults:
3,063
Page faults /min: 5
 | Process I/O averages |
Total read operations:
24
Read operations /min: 1
Total read transfer: 85.12 KB
Read transfer /min: 13 Bytes
Total write operations:
3
Write operations /min: 1
Total write transfer: 289 Bytes
Write transfer /min: 0 Bytes
Total other operations:
1,475
Other operations /min: 2
Total other transfer: 59.38 KB
Other Transfer /min: 16 Bytes
 | GUI Object Averages |
GDI objects:
10
Peak GDI objects: 11
USER objects:
5
Peak USER objects: 5
Resources
Handle count average: 177
Thread count average: 6
Thread resource averages
Total CPU: 0.017620951719%
Privileged CPU: 0.010761396171%
User CPU: 0.006859555548%
CPU Cycle count /sec: 440,415
Module memory size: 144 KB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 64-bit
Parent Processes
Process Commands
C:\users\user\appdata\Local\Facebook\Update\FacebookUpdate.exe /ua /installsource scheduler
"C:\Documents and Settings\user\Application Data\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
"C:\Documents and Settings\Ruben Baptista\Configuración local\Datos de programa\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
C:\users\user\appdata\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
C:\users\user\appdata\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
Startup files (user) run details
Name: Facebook Update
Command: "C:\users\user\appdata\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
Scheduled task details
Name: FacebookUpdateTaskUserS-1-5-21-402932088-1460617023-881564081-1000UA
Command: \FacebookUpdateTaskUserS-1-5-21-402932088-1460617023-881564081-1000UA
Image hashes
MD5: 2a3fb4c98f139038e23330d2439db8a4
SHA-1: d33c799d1d26e00cc2d843ac4a94be78fdfcf9da
SHA-256: de9253ad362b03fa5d3d4912662398e5c4ac76f7274b83e51c251a6921a5b838
PE image details
File packed: No
Import Table
advapi32.dll

GetTokenInformation
RegOpenKeyExW
OpenProcessToken
kernel32.dll

GetCommandLineW
FindResourceExW
FindResourceW
FreeLibrary
LoadResource
LoadLibraryExW
VerSetConditionMask
GetCurrentProcess
GetModuleHandleW
SizeofResource
GetModuleFileNameW
lstrlenW
RaiseException
VerifyVersionInfoW
GetLastError
GetProcAddress
LockResource
GetFileAttributesExW
CloseHandle
SetLastError
LocalAlloc
SetStdHandle
SetFilePointer
InterlockedExchange
LoadLibraryA
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSection
DeleteCriticalSection
GetVersionExA
HeapDestroy
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
GetProcessHeap
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetStartupInfoW
WideCharToMultiByte
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
Sleep
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
VirtualAlloc
RtlUnwind
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
InitializeCriticalSectionAndSpinCount
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
GetConsoleCP
GetConsoleMode
FlushFileBuffers
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CreateFileA
ole32.dll
