Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

fe546 17.65%
500d9 8.82%
b4ad3 8.82%
5941b 8.82%
f4a94 2.94%
8b672 35.29%
4f841 2.94%
93480 11.76%
27e40 2.94%
(Note, Bit Cocktail Ltd. publishes each variation of this file with the same version, but the hashes are unique.)

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
GetSidSubAuthority, GetSidSubAuthorityCount, GetSidIdentifierAuthority, IsValidSid, GetTokenInformation, OpenProcessToken, ControlService, StartServiceW, DeleteService, OpenServiceW, CloseServiceHandle, CreateServiceW, OpenSCManagerW, SetServiceStatus, RegisterServiceCtrlHandlerW, StartServiceCtrlDispatcherW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegEnumKeyExW, RegQueryInfoKeyW, RegCloseKey, RegDeleteKeyW, RegQueryValueExW
kernel32.dll
LocalFree, LocalAlloc, GetVersionExW, GetCurrentProcess, HeapAlloc, GetProcessHeap, CloseHandle, GetTempPathW, HeapFree, GetSystemTime, SystemTimeToFileTime, FindResourceExW, GetFileAttributesW, FindFirstFileW, FindNextFileW, DeleteFileW, FindClose, CreateFileW, RemoveDirectoryW, LCMapStringA, GetStringTypeW, LockResource, GetCurrentDirectoryW, CreateThread, Sleep, InterlockedIncrement, InterlockedDecrement, DeleteCriticalSection, InitializeCriticalSection, GetModuleFileNameW, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, MultiByteToWideChar, GetLastError, EnterCriticalSection, RaiseException, LeaveCriticalSection, lstrcmpiW, GetModuleHandleW, GetProcAddress, lstrlenW, FreeLibrary, LCMapStringW, FileTimeToSystemTime, GetModuleHandleA, WriteConsoleA, lstrlenA, CreateFileA, GetStringTypeA, WriteConsoleW, GetConsoleOutputCP, HeapDestroy, HeapReAlloc, HeapSize, GetSystemTimeAsFileTime, CreateDirectoryW, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetStartupInfoW, RtlUnwind, VirtualFree, VirtualAlloc, HeapCreate, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, SetFilePointer, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, InitializeCriticalSectionAndSpinCount, LoadLibraryA, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, WideCharToMultiByte, GetConsoleCP, GetConsoleMode, SetStdHandle, FlushFileBuffers, GetLocaleInfoA
ole32.dll
CoTaskMemFree, CoCreateInstance, CoInitialize, CoTaskMemRealloc, CoTaskMemAlloc, CoUninitialize
shell32.dll
ShellExecuteExW
urlmon.dll
URLDownloadToFileW
user32.dll
CharNextW

extensionupdaterservice.exe

By Bit Cocktail Ltd. (Signed)

Remove extensionupdaterservice.exe
MD5:   fe546adf53e0ab4c27dc7a49da0e3eca
SHA1:   c3240642816a80a006b0dd416b4a084a0e55500a
SHA256:   bf40b8843a8617dc8f8d37aad761776e2c070d518e1c1b10a534e739956d0380
Warning 3 antivirus scanners has detected malware.

What is extensionupdaterservice.exe?

Bit Cocktail Web Assistant Updater is the software updater program which runs in the background of Windows and automatically starts up when your PC boots. It checks for software udpates and automatically downloads and installs them if found.

About extensionupdaterservice.exe (from Bit Cocktail Ltd.)

Bitcocktail is home to a variety of products that provide an engaging and productive experience online. Bitcocktail features a variety of social and entertainment destinations like Vidzy, Playzy, Expr

DetailsDetails

File name:extensionupdaterservice.exe
Typical file path:C:\Program Files\web assistant\extensionupdaterservice.exe
Size:184.34 KB (188,760 bytes)
Certificate
Issued to:Bit Cocktail Ltd.
Authority (CA):Thawte
Expiration date:Wednesday, January 16, 2013
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Perion Network Ltd.
  81% remove
Web Assistant installs into the IE and Firefox web browsers and provides advertisier supported searchs that changes and redircts default search results as well as DNS errors. Web Assistant becomes the browser's default search provider which changes all search requests as well as tracks your Internet surfing behavior in order display targeted advertising.

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • IB Updater Updater
Network connections
  • [UDP] listens on port 49698
  • [UDP] listens on port 2687

  • MalwareMalware detections

    Based on 40+ industry antivirus scanners, 3 of them detected the following malware.
    Antivirus engineEngine versionDetection
    Antiy Labs AVL 2.0.3.7 Trojan/Win32.Agent
    nProtect 2013-02-22.01 Trojan/W32.Agent.188760
    ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.188760

    ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.02045133%
    0.028634%
    Kernel CPU:0.01630664%
    0.013761%
    User CPU:0.00414469%
    0.014873%
    Kernel CPU time:955 ms/min
    100,923,805ms/min
    Context switches:8/sec
    284/sec
    Memory
    Private memory:10.11 MB
    21.59 MB
    Private (maximum):562.67 KB
    Private (minimum):486.67 KB
    Non-paged memory:10.11 MB
    21.59 MB
    Virtual memory:52.9 MB
    140.96 MB
    Virtual memory (peak):55.28 MB
    169.69 MB
    Working set:590.67 KB
    18.61 MB
    Working set (peak):5.11 MB
    37.95 MB
    Resource allocations
    Threads:5
    12
    Handles:153
    600
    GUI GDI count:4
    103
    GUI USER count:2
    49

    BehaviorsProcess properties

    Integrety level:System
    Platform:32-bit
    Command line:"C:\Program Files\web assistant\extensionupdaterservice.exe"
    Owner:SYSTEM
    Windows Service
    Display name:IB Updater Updater
    Parent process:services.exe (Services and Controller app by Microsoft)

    ResourcesThreads

    Averages
     
    ExtensionUpdaterService.exe (main module)
    Total CPU:0.02078107%
    0.272967%
    Kernel CPU:0.01847537%
    0.107585%
    User CPU:0.00230570%
    0.165382%
    CPU cycles:1,240,821/sec
    5,741,424/sec
    Context switches:3/sec
    79/sec
    Memory:204 KB
    1.16 MB
    ADVAPI32.dll
    Total CPU:0.00297167%
    Kernel CPU:0.00297167%
    User CPU:0.00000000%
    CPU cycles:82,645/sec
    Memory:764 KB
    sechost.dll
    Total CPU:0.00031687%
    Kernel CPU:0.00015843%
    User CPU:0.00015843%
    CPU cycles:81,721/sec
    Memory:100 KB
    WININET.dll
    Total CPU:0.00015843%
    Kernel CPU:0.00015843%
    User CPU:0.00000000%
    CPU cycles:16,916/sec
    Memory:980 KB

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 26.47%
    Microsoft Windows XP 20.59%
    Windows 7 Ultimate N 17.65%
    Windows 7 Ultimate 11.76%
    Windows 7 Professional 8.82%
    Windows Vista Ultimate 5.88%
    Windows 8 Release Preview 5.88%
    Windows Vista Home Premium 2.94%

    Distribution by countryDistribution by country

    United States installs about 41.38% of extensionupdaterservice.exe.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Hewlett-Packard 50.00%
    GIGABYTE 50.00%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE