Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

58fc6 4.17%
16ffd 12.50%
82505 4.17%
b794e 2.78%
00760 8.33%
e3f6b 8.33%
570c8 1.39%
79e7d 1.39%
ec63f 15.28%
8272d 11.11%
be557 2.78%
a6a9c 2.78%
9b7c6 1.39%
1df19 2.78%
60bc2 4.17%
ab52b 1.39%
f68f7 1.39%
c7acc 4.17%
8350b 1.39%
ccfee 1.39%
5b8c1 1.39%
7f57b 1.39%
1819d 1.39%
6611f 1.39%
12456 1.39%
(Note, Hoolapp publishes each variation of this file with the same version, but the hashes are unique.)

Relationships

updatetask.exe

By Hoolapp (Signed)

Remove updatetask.exe
MD5:   a6a9c1291b7762dbd95022af71a6dd35
SHA1:   84fe61acee90134c6bfbd3cecf1fb07bc22c997c
SHA256:   6df80aed2790d062b88ee56e745a7844884fcd39c725f96771a0c526aac7d379
Warning 14 antivirus scanners has detected malware.

Overview

updatetask.exe is malware that executes as a process with the local user's privileges. It is installed with a couple of know programs including Update for Zip Opener published by installCore, Update for Codec Pack from installCore and Update for Codec Pack by installCore. The file is digitally signed by Hoolapp which was issued by the COMODO CA Limited certificate authority (CA).

DetailsDetails

File name:updatetask.exe
Typical file path:C:\users\user\appdata\roaming\hoolappforandroid\updateproc\updatetask.exe
Size:99 KB (101,376 bytes)
Certificate
Issued to:Hoolapp
Authority (CA):COMODO CA Limited
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
installCore
  68% remove
The software uses the InstallCore Click run software which is an installer that bundles legitimate applications that may also offer additional third party applications that may be unwanted by the user. Such third party applications are typically installed onto users’ computers by default, but also include an option to ‘opt-out’ during or after the installation process. Typical bundled installs include DealPly as well as other potentiall...
installCore
  88% remove
Update for Codec Pack uses the InstallCore Click run software which is an installer that bundles legitimate applications that may also offer additional third party applications that may be unwanted by the user. Such third party applications are typically installed onto users’ computers by default, but also include an option to ‘opt-out’ during or after the installation process. Typical bundled installs include DealPly as well as other p...
installCore
  75% remove
Update for PDF Writer uses the InstallCore Click run software which is an installer that bundles legitimate applications that may also offer additional third party applications that may be unwanted by the user. Such third party applications are typically installed onto users’ computers by default, but also include an option to ‘opt-out’ during or after the installation process. Typical bundled installs include DealPly as well as other p...
installCore
  72% remove
Update for Mipony Download Manager is the update mechanism for the Install Core software which is an installer which bundles legitimate applications with offers for additional third party applications that may be unwanted by the user. Such third party applications are typically installed onto users’ computers by default, but may include an option to ‘opt-out’ during or after the installation process.
installCore
  80% remove
Update for Image Editor uses the InstallCore Click run software which is an installer that bundles legitimate applications that may also offer additional third party applications that may be unwanted by the user. Such third party applications are typically installed onto users’ computers by default, but also include an option to ‘opt-out’ during or after the installation process. Typical bundled installs include DealPly as well as other...
installCore
  75% remove
Update for Codec Package is the update mechanism for the Install Core software which is an installer which bundles legitimate applications with offers for additional third party applications that may be unwanted by the user. Such third party applications are typically installed onto users’ computers by default, but may include an option to ‘opt-out’ during or after the installation process.
installCore
  76% remove
Update for Zip Extractor uses the Install Core download Manager. Install Core Click run software is an installer which bundles applications with offers for additional third party programs that may be unwanted by the user including toolbars and browser extensions. Such third party programs are typically installed onto users’ computers by default, but may include an option to ‘opt-out’ during or after the installation process. The soft...
installCore
  83% remove
Update for PDF Creator uses the InstallCore Click run software which is an installer that bundles legitimate applications that may also offer additional third party applications that may be unwanted by the user. Such third party applications are typically installed onto users’ computers by default, but also include an option to ‘opt-out’ during or after the installation process. Typical bundled installs include DealPly as well as other ...
installCore
  88% remove
This uses the InstallCore download Manager. Install Core Click run software is an installer which bundles applications with offers for additional third party programs that may be unwanted by the user incuding toolbars and browser extensions. Such third party programs are typically installed onto users’ computers by default, but may include an option to ‘opt-out’ during or after the installation process.
installCore
  80% remove
This is a potentially unwanted background updater that is installed with a download manager and connects to info.updaterex.com for additional downloads and updated. The software is typically part of a software download bundle from the Install Core mechanism.
savesense.com
  83% remove
SaveSense injects price comparison advertisements based on the context of the web page a user is visiting. These advertisements are in the form of popup banner ads. From the Terms of Service: "SaveSense provides you with its services, which is a shopping comparative service that includes a downloadable browser add-on ("Software"), banners ads, and coupons that provide you with relevant Offers while you shop online, in order to help y...

BehaviorsBehaviors

Scheduled tasks
  • The task 'Price Meter Updater' runs daily in the path '\Price Meter Updater'
  • The task 'Speedial' runs daily in the path '\Speedial'
  • The task 'PriceMeterUpdater' runs daily in the path '\PriceMeterUpdater'
  • The task 'DigitalSite' runs daily in the path '\DigitalSite'
  • The task 'MetaCrawler' runs daily in the path '\MetaCrawler'
  • The task 'UpdaterEX' runs daily in the path '\UpdaterEX'
  • The job 'MySearchDial' runs daily in the path '\MySearchDial'
  • The task 'DealPly' runs daily in the path '\DealPly'
  • The job 'At1' runs weekly in the path 'C:\WINDOWS\Tasks\At1.job'
  • The job 'DSite' runs daily in the path '\DSite'
  • The task 'Hoolapp For Android' runs daily in the path '\Hoolapp For Android'
  • The job 'Funmoods' runs daily in the path '\Funmoods'
  • Entry path '\Funmoods'
  • Entry path '\Hoolapp For Android'
Network connections
  • [TCP] ec2-54-214-29-188.us-west-2.compute.amazonaws.com (54.214.29.188:80)

  • MalwareMalware detections

    Based on 40+ industry antivirus scanners, 14 of them detected the following malware.
    Antivirus engineEngine versionDetection
    AVG 13.0.0.3169 Delf.AMSI
    Bkav Security 1.3.0.4562 W32.Clod71f.Trojan.7736
    Comodo Internet Security 17314 Application.Win32.InstallCore.~AGT
    Dr.Web 8.13.11.25 Adware.Downware.1573
    ESET NOD32 7.9082 a variant of Win32/DealPly.H
    Fortinet 5.1.147.0 W32/Agent.AEMZ!tr
    Ikarus T3.1.5.6.0 Trojan-Dropper.Delf
    K7 AntiVirus 9.174.10272 Trojan ( 0048e3631 )
    K7GW 9.174.10272 Trojan ( 0048e3631 )
    Kingsoft 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
    Malwarebytes 1.75.0.1 PUP.Optional.DigitalSites.A
    Sophos 4.95.0 Troj/Agent-AEMZ
    Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.R0CBH07K213
    VIPRE Antivirus 23614 Trojan.Win32.Generic!BT

    ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.01976556%
    0.028634%
    Kernel CPU:0.01041698%
    0.013761%
    User CPU:0.00934857%
    0.014873%
    Kernel CPU time:156 ms/min
    100,923,805ms/min
    CPU cycles:1,383,232/sec
    17,470,203/sec
    Memory
    Private memory:4.57 MB
    21.59 MB
    Private (maximum):13.43 MB
    Private (minimum):976 KB
    Non-paged memory:4.57 MB
    21.59 MB
    Virtual memory:104 MB
    140.96 MB
    Virtual memory (peak):117.27 MB
    169.69 MB
    Working set:936 KB
    18.61 MB
    Working set (peak):13.59 MB
    37.95 MB
    Page faults:10,291/min
    2,039/min
    I/O
    I/O read transfer:15.04 KB/sec
    1.02 MB/min
    I/O read operations:5/sec
    343/min
    I/O other transfer:28.66 KB/sec
    448.09 KB/min
    I/O other operations:177/sec
    1,671/min
    Resource allocations
    Threads:3
    12
    Handles:259
    600
    GUI GDI count:28
    103
    GUI GDI peak:30
    142
    GUI USER count:21
    49
    GUI USER peak:22
    71

    BehaviorsProcess properties

    Integrety level:High
    Platform:64-bit
    Command line:C:\users\user\appdata\roaming\digita~1\update~1\update~1.exe /check
    Owner:User
    Parent process:taskeng.exe (Task Scheduler Engine by Microsoft)

    ResourcesThreads

    Averages
     
    updatetask.exe
    Total CPU:0.02753617%
    0.272967%
    Kernel CPU:0.01376808%
    0.107585%
    User CPU:0.01376808%
    0.165382%
    CPU cycles:852,598/sec
    5,741,424/sec
    Context switches:6/sec
    79/sec
    Memory:120 KB
    1.16 MB
    ntdll.dll
    Total CPU:0.00590733%
    Kernel CPU:0.00590733%
    User CPU:0.00000000%
    CPU cycles:30,970/sec
    Memory:1.66 MB

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 26.76%
    Windows 7 Ultimate 18.31%
    Microsoft Windows XP 12.68%
    Windows 8.1 8.45%
    Windows 8 8.45%
    Windows Vista Home Premium 5.63%
    Windows 8 Pro 4.23%
    Windows 7 Professional 4.23%
    Windows 7 Home Basic 2.82%
    Windows 8.1 Pro with Media Center 1.41%
    Windows 8.1 Enterprise 1.41%
    Windows 8.1 Single Language 1.41%
    Windows Developer Preview 1.41%
    Windows 8.1 Single Language Preview 1.41%
    Windows 8 Pro with Media Center 1.41%

    Distribution by countryDistribution by country

    United States installs about 30.99% of updatetask.exe.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 19.78%
    Acer 17.58%
    Lenovo 13.19%
    Hewlett-Packard 13.19%
    ASUS 10.99%
    Toshiba 8.79%
    GIGABYTE 4.40%
    Samsung 3.30%
    American Megatrends 3.30%
    MSI 2.20%
    Sony 2.20%
    Sahara 1.10%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE