Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

fe546 17.65%
500d9 8.82%
b4ad3 8.82%
5941b 8.82%
f4a94 2.94%
8b672 35.29%
4f841 2.94%
93480 11.76%
27e40 2.94%
(Note, Bit Cocktail Ltd. publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetSidSubAuthority, GetSidSubAuthorityCount, GetSidIdentifierAuthority, IsValidSid, GetTokenInformation, OpenProcessToken, ControlService, StartServiceW, DeleteService, OpenServiceW, CloseServiceHandle, CreateServiceW, OpenSCManagerW, SetServiceStatus, RegisterServiceCtrlHandlerW, StartServiceCtrlDispatcherW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegEnumKeyExW, RegQueryInfoKeyW, RegCloseKey, RegDeleteKeyW, RegQueryValueExW
kernel32.dll
LocalFree, LocalAlloc, GetVersionExW, GetCurrentProcess, HeapAlloc, GetProcessHeap, CloseHandle, GetTempPathW, HeapFree, GetSystemTime, SystemTimeToFileTime, FindResourceExW, GetFileAttributesW, FindFirstFileW, FindNextFileW, DeleteFileW, FindClose, CreateFileW, RemoveDirectoryW, LCMapStringA, GetStringTypeW, LockResource, GetCurrentDirectoryW, CreateThread, Sleep, InterlockedIncrement, InterlockedDecrement, DeleteCriticalSection, InitializeCriticalSection, GetModuleFileNameW, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, MultiByteToWideChar, GetLastError, EnterCriticalSection, RaiseException, LeaveCriticalSection, lstrcmpiW, GetModuleHandleW, GetProcAddress, lstrlenW, FreeLibrary, LCMapStringW, FileTimeToSystemTime, GetModuleHandleA, WriteConsoleA, lstrlenA, CreateFileA, GetStringTypeA, WriteConsoleW, GetConsoleOutputCP, HeapDestroy, HeapReAlloc, HeapSize, GetSystemTimeAsFileTime, CreateDirectoryW, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetStartupInfoW, RtlUnwind, VirtualFree, VirtualAlloc, HeapCreate, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, SetFilePointer, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, InitializeCriticalSectionAndSpinCount, LoadLibraryA, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, WideCharToMultiByte, GetConsoleCP, GetConsoleMode, SetStdHandle, FlushFileBuffers, GetLocaleInfoA
ole32.dll
CoTaskMemFree, CoCreateInstance, CoInitialize, CoTaskMemRealloc, CoTaskMemAlloc, CoUninitialize
shell32.dll
ShellExecuteExW
urlmon.dll
URLDownloadToFileW
user32.dll
CharNextW

extensionupdaterservice.exe

By Bit Cocktail Ltd. (Signed)

Remove extensionupdaterservice.exe
MD5:   93480110be459273e4333dd23835ddac
SHA1:   3901f0e70944817f3c54aeca6481e994444ad7c2
SHA256:   be4d3c7df4750570cd010ee8be0fd59e81e301eb991dd2022096d45542f4f8fb
Warning 5 antivirus scanners has detected malware.

What is extensionupdaterservice.exe?

Bit Cocktail Web Assistant Updater is the software updater program which runs in the background of Windows and automatically starts up when your PC boots. It checks for software udpates and automatically downloads and installs them if found.

About extensionupdaterservice.exe (from Bit Cocktail Ltd.)

Bitcocktail is home to a variety of products that provide an engaging and productive experience online. Bitcocktail features a variety of social and entertainment destinations like Vidzy, Playzy, Expr

DetailsDetails

File name:extensionupdaterservice.exe
Typical file path:C:\Program Files\web assistant\extensionupdaterservice.exe
Size:184.34 KB (188,760 bytes)
Certificate
Issued to:Bit Cocktail Ltd.
Authority (CA):Thawte
Expiration date:Wednesday, January 16, 2013
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Perion Network Ltd.
  84% remove
The IB (IncrediBar) Updater Service is designed to keep the Perion IncrediBar web browser toolbar (and other related products) up to date. The IB Updater Service runs in the background and periodically connects to the IncrediBar servers. If an update is found it will automatically download and install updates for all Perion programs. The program runs a background Windows service with full administrator privileges under one of the fol...

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • IB Updater Updater

MalwareMalware detections

Based on 40+ industry antivirus scanners, 5 of them detected the following malware.
Antivirus engineEngine versionDetection
Antiy Labs AVL 2.0.3.7 Trojan/Win32.Agent
Kingsoft 2013.1.8.219 Win32.Troj.Agent.k.(kcloud)
nProtect 2013-03-19.01 Trojan/W32.Agent.188760
Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.F47V1217
ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.188760

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00007305%
0.028634%
Kernel CPU:0.00002249%
0.013761%
User CPU:0.00005056%
0.014873%
Kernel CPU time:22,141 ms/min
100,923,805ms/min
Context switches:9/sec
284/sec
Memory
Private memory:9.73 MB
21.59 MB
Private (maximum):584 KB
Private (minimum):444 KB
Non-paged memory:9.73 MB
21.59 MB
Virtual memory:51.72 MB
140.96 MB
Virtual memory (peak):54.72 MB
169.69 MB
Working set:472 KB
18.61 MB
Working set (peak):4.97 MB
37.95 MB
Resource allocations
Threads:5
12
Handles:194
600
GUI GDI count:4
103
GUI USER count:4
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command line:"C:\Program Files\ib updater\extensionupdaterservice.exe"
Owner:SYSTEM
Windows Service
Display name:IB Updater Updater
Parent process:services.exe (Microsoft Windows Operating System by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 26.47%
Microsoft Windows XP 20.59%
Windows 7 Ultimate N 17.65%
Windows 7 Ultimate 11.76%
Windows 7 Professional 8.82%
Windows Vista Ultimate 5.88%
Windows 8 Release Preview 5.88%
Windows Vista Home Premium 2.94%

Distribution by countryDistribution by country

United States installs about 41.38% of extensionupdaterservice.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 50.00%
GIGABYTE 50.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE