VersionsVersions

faccc 3.23%
de70e 3.23%
9b165 3.23%
8b7f5 3.23%
58f9d 16.13%
ebffe 3.23%
b1ec8 3.23%
5e01b 3.23%
ce2c4 3.23%
49792 3.23%
6d7c4 3.23%
ed068 12.90%
1ba41 6.45%
4f887 19.35%
d7539 3.23%
2e615 3.23%
d0c38 6.45%
(Note, Bit Cocktail Ltd. publishes each variation of this file with the same version, but the hashes are unique.)

Relationships

extensionupdaterservice.exe

By Bit Cocktail Ltd. (Signed)

Remove extensionupdaterservice.exe
Warning 28 antivirus scanners has detected malware in various versions of extensionupdaterservice.exe.

Overview

There are 17 versions of extensionupdaterservice.exe in the wild, the latest version being . It is started as a Windows Service called 'Web Assistant' with the name 'Updater By SweetPacks'. In addition, it is run under the context of the SYSTEM account with extensive privileges (the administrator accounts have the same privileges). The average file size is about 182.21 KB. The file is a digitally signed and issued to Bit Cocktail Ltd. by Thawte. The programs Updater By SweetPacks 2.0.0.566, Updater By SweetPacks 2.0.0.583 and Web Assistant 2.0.0.457 have been observed as installing specific variations of extensionupdaterservice.exe. During the process's lifecycle, the typical CPU resource utilization is less than 0.01%, the average private memory consumption is about 9.27 MB and write I/O transfers are about 0 Bytes per minute.

What is extensionupdaterservice.exe?

Plazy Updater is the software updater program which runs in the background of Windows and automatically starts up when your PC boots. It checks for software udpates and automatically downloads and installs them if found.

DetailsDetails

File name:extensionupdaterservice.exe
Typical file path:C:\Program Files\plazy\extensionupdaterservice.exe
Certificate
Issued to:Bit Cocktail Ltd.
Authority (CA):Thawte
Expiration date:Thursday, January 16, 2014
Windows Service
Service name:Updater By SweetPacks
Display name:Web Assistant
Type:Win32OwnProcess

ResourcesPrograms installed in

(Note, the programs listed below are for all versions of extensionupdaterservice.exe.)
Bitshakers LTD
  66% remove
FBFlicker displays advertising in the user's Internet browser by running as an extension and/or add-on. Ads are delivered in the form of search-related ads, banner and video ads, and text-links (roll-...
Perion Network Ltd.
  80% remove
Web Assistant installs into the IE and Firefox web browsers and provides advertisier supported searchs that changes and redircts default search results as well as DNS errors. Web Assistant becomes the...
SweetIM Technologies Ltd.
  67% remove
Updater By SweetPacks (from Perion) is designed to monitor and keep the SweetPacks programs automatically up to date. It checks for software updates and automatically downloads and installs them if fo...

BehaviorsBehaviors

(Note, the behaviors below are for all versions of extensionupdaterservice.exe, select a unique version for details.)
Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • Web Assistant
  • 'Updater By SweetPacks'
  • 'Web Assistant Updater'

MalwareMalware detections

Based on 40+ industry antivirus scanners, 28 of them detected the following malware.
Antivirus engineEngine versionDetectionFile version
Antiy Labs AVL 2.0.3.7 Trojan/Win32.Agent.gen ebffe98048709c7cc7a6f6c36c7de61b
Antiy Labs AVL 2.0.3.7 Trojan/Win32.Agent.gen b1ec8c9300c58ce5e90990f71eea644c
Antiy Labs AVL 2.0.3.7 Trojan/Win32.Agent.gen 6d7c46ef873388df62dc2c21892de317
Antiy Labs AVL 2.0.3.7 Trojan/Win32.Agent d75398987c968dcbabc411e08029e387
Antiy Labs AVL 2.0.3.7 Trojan/Win32.Agent 2e61503cbfec0d6c81dfaf1337930d22
ESET NOD32 7.9341 a variant of Win32/Toolbar.BitCocktail.B ed068a3787b67008b96b994f78302264
ESET NOD32 7.8789 a variant of Win32/Toolbar.BitCocktail.B 4f887d2c0362e1b4183139a5eb926a50
ESET NOD32 7.8752 a variant of Win32/Toolbar.BitCocktail.B d75398987c968dcbabc411e08029e387
ESET NOD32 7.8500 a variant of Win32/Toolbar.Perion.C d0c38e6ae015810ba03cca580793a88b
Kingsoft 2013.4.9.267 Win32.Troj.Generic.a.(kcloud) ed068a3787b67008b96b994f78302264
Kingsoft 2013.4.9.267 Win32.Troj.Generic.a.(kcloud) 4f887d2c0362e1b4183139a5eb926a50
Malwarebytes 1.75.0.1 PUP.Optional.SweetPacks.A ed068a3787b67008b96b994f78302264
Malwarebytes 1.75.0.1 PUP.Optional.SweetPacks.A 4f887d2c0362e1b4183139a5eb926a50
Malwarebytes 1.75.0.1 PUP.Optional.SweetPacks.A d75398987c968dcbabc411e08029e387
Sophos 4.91.0 BitCocktail 4f887d2c0362e1b4183139a5eb926a50
Sophos 4.91.0 BitCocktail d75398987c968dcbabc411e08029e387
Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.F47V0401 1ba417f51bf6715f2a98014e4c093eb4
Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.F47V0315 d75398987c968dcbabc411e08029e387
ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.188760 58f9dbec704ff8af7804e5c416b9fc73
ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.188760 ebffe98048709c7cc7a6f6c36c7de61b
ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.188760 b1ec8c9300c58ce5e90990f71eea644c
ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.188760 6d7c46ef873388df62dc2c21892de317
ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.188760 ed068a3787b67008b96b994f78302264
ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.188760 1ba417f51bf6715f2a98014e4c093eb4
ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.188760 4f887d2c0362e1b4183139a5eb926a50
ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.188760 d75398987c968dcbabc411e08029e387
ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.188760 2e61503cbfec0d6c81dfaf1337930d22
ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.188760 d0c38e6ae015810ba03cca580793a88b

VersionsAll file variations of extensionupdaterservice.exe

MD5SHA-1File size
faccc3394352cd652e33fb04aae8a97f 707b5b1e117595671e838d2c1ba267036c5ee5a7 181.5 KB
de70e5b2aa61cc3392b2a789de2ef472 bf965db25ce1d2b3ec677d1933d6934ec5d4af86 181.5 KB
9b1657512d4487ea648252441f1699c5 a155469be3a59fc0753cca428192d8e97ced9986 179 KB
8b7f5db2c382f479d0d4a2416b66391d 106afd011d4b52597948e7da1e1dd0c0a5f66e7d 181.5 KB
58f9dbec704ff8af7804e5c416b9fc73 1c243f5c1369c8208d1c778e63e70b8f4ea22612 181.5 KB
ebffe98048709c7cc7a6f6c36c7de61b 332971b8d05b53f82119fd3471c232fe75d001f7 181.5 KB
b1ec8c9300c58ce5e90990f71eea644c c91af5caa0124db8e8aba4ff9d26b809de2388d7 181.5 KB
5e01b29dd702e6227f4fc9256d8f4065 26bdeb7554ef3ae0254a35a56e7109bc9de65145 179 KB
ce2c4578a8d8265a6c3fd131959ba2fa 05d4c12e5d212d50d628fc395ae6f425cc62d00d 181.5 KB
497926aee58932c91c34388f4d03d2b4 405e294b3d7113c266cee175947d8c8ea3e06d9b 181.5 KB
6d7c46ef873388df62dc2c21892de317 6fdb7f1fc5ae3a18c2b57c9e167e28404d64145b 181.5 KB
ed068a3787b67008b96b994f78302264 4fca7346b0bfcc61d35c55ad6ed372ef71038470 184.34 KB
1ba417f51bf6715f2a98014e4c093eb4 c5443b4e4c85da02834e4be1d18f97c30c660c49 184.34 KB
4f887d2c0362e1b4183139a5eb926a50 7a3f3cf7ad7bd8a6f74db88ba612694d2626bc7f 184.34 KB
d75398987c968dcbabc411e08029e387 a02bc363b2550ba9d336a7587b6b83c8f7906193 184.34 KB
2e61503cbfec0d6c81dfaf1337930d22 a90489ff5ec732bc9997904204bcc412549cb268 184.34 KB
d0c38e6ae015810ba03cca580793a88b 3cc1ef071fe5f37b6ced1e29ddd7306d667f17d2 184.34 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 26.67%
Windows Vista Home Premium 23.33%
Windows 8 16.67%
Windows 7 Ultimate N 13.33%
Microsoft Windows XP 6.67%
Windows 8 Pro 3.33%
Windows 7 Ultimate 3.33%
Windows 7 Starter 3.33%
Windows 7 Professional 3.33%

Distribution by countryDistribution by country

United States installs about 73.33% of extensionupdaterservice.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Toshiba 51.85%
Hewlett-Packard 25.93%
Gateway 7.41%
Sony 7.41%
ASUS 7.41%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE