Should I block it?

40%
40% of PCs block this file from running.
Possible reason:
Performance resource utilization

VersionsAdditional versions

1000.1000.1000.1000 66.67%
1000.1000.1000.1000 33.33%
(Note, Engaging Apps publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegSetValueExW, RegCreateKeyExW, RegEnumKeyExW, RegDeleteValueW, RegDeleteKeyW, RegQueryValueExW, RegCloseKey, RegOpenKeyExW, RegQueryInfoKeyW
kernel32.dll
IsValidLocale, EnumSystemLocalesA, GetVersion, GetProcAddress, GetModuleHandleW, InterlockedDecrement, lstrlenW, InterlockedIncrement, DebugBreak, OutputDebugStringW, lstrlenA, RaiseException, GetLastError, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, MultiByteToWideChar, GetFileAttributesW, LoadLibraryW, lstrcmpiW, FreeLibrary, SizeofResource, LoadResource, FindResourceW, LoadLibraryExW, GetModuleFileNameW, FindClose, FindNextFileW, FindFirstFileW, GetTempPathW, CloseHandle, Sleep, CreateMutexW, GetConsoleMode, GetConsoleCP, GetFileType, SetHandleCount, HeapReAlloc, WriteConsoleW, SetStdHandle, CreateFileW, SetEndOfFile, FlushFileBuffers, ReadFile, SetFilePointer, WideCharToMultiByte, GetProcessHeap, FreeEnvironmentStringsW, GetStringTypeW, IsValidCodePage, GetLocaleInfoA, GetUserDefaultLCID, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, GetOEMCP, GetEnvironmentStringsW, GetACP, HeapSize, ExitProcess, GetLocaleInfoW, GetStdHandle, InterlockedExchange, InitializeCriticalSection, EncodePointer, DecodePointer, HeapFree, RtlUnwind, HeapAlloc, GetSystemTimeAsFileTime, GetCommandLineW, HeapSetInformation, GetStartupInfoW, LCMapStringW, GetCPInfo, IsProcessorFeaturePresent, HeapCreate, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, WriteFile
ole32.dll
CoTaskMemRealloc, CoCreateInstance, CoTaskMemFree, CoUninitialize, CoTaskMemAlloc, CoInitialize
shell32.dll
ShellExecuteExW, SHGetFolderPathW
shlwapi.dll
UrlEscapeW
user32.dll
wvsprintfW, DestroyWindow, CharNextW, LoadStringW, wsprintfW
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
wininet.dll
InternetSetOptionW, HttpSendRequestW, HttpOpenRequestW, InternetConnectW, InternetCloseHandle, InternetCrackUrlW, InternetOpenW, InternetReadFile

updater21806.exe

Deals Plugin Extension by Engaging Apps (Signed)

Remove updater21806.exe
Version:   1000.1000.1000.1000
MD5:   88f17fda2c034052fec50ff8c53c0acd
SHA1:   bf3c20758049feb12e050ff734caea0faa59952d

Overview

updater21806.exe executes as a process with the local user's privileges. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). The file is digitally signed by Engaging Apps which was issued by the Thawte certificate authority (CA).

DetailsDetails

File name:updater21806.exe
Publisher:Innovative Apps
Product name:Deals Plugin Extension
Description:Deals Plugin Extension exe
Typical file path:C:\Documents and Settings\user\Local\updater21806\updater21806.exe
Original name:Deals Plugin Extension.exe
File version:1000.1000.1000.1000
Size:214.38 KB (219,528 bytes)
Build date:10/14/2013 5:52 AM
Certificate
Issued to:Engaging Apps
Authority (CA):Thawte
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'Updater21806.exe' → C:\Documents and Settings\user\Local\Updater21806\Updater21806.exe /extensionid=21806 /extensionname='Deals Plugin Extension' /chromeid=bbhgoadfgiandmaieopaphefb
Scheduled tasks
  • The task 'Updater21806.exe' in the path '\Updater21806.exe'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 33.33%
Windows 7 Professional 33.33%
Microsoft Windows XP 33.33%

Distribution by countryDistribution by country

Panama installs about 33.33% of Deals Plugin Extension.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 66.67%
Samsung 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE