Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

fe546 17.65%
500d9 8.82%
b4ad3 8.82%
5941b 8.82%
f4a94 2.94%
8b672 35.29%
4f841 2.94%
93480 11.76%
27e40 2.94%
(Note, Bit Cocktail Ltd. publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetSidSubAuthority, GetSidSubAuthorityCount, GetSidIdentifierAuthority, IsValidSid, GetTokenInformation, OpenProcessToken, ControlService, StartServiceW, DeleteService, OpenServiceW, CloseServiceHandle, CreateServiceW, OpenSCManagerW, SetServiceStatus, RegisterServiceCtrlHandlerW, StartServiceCtrlDispatcherW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegEnumKeyExW, RegQueryInfoKeyW, RegCloseKey, RegDeleteKeyW, RegQueryValueExW
kernel32.dll
LocalFree, LocalAlloc, GetVersionExW, GetCurrentProcess, HeapAlloc, GetProcessHeap, CloseHandle, GetTempPathW, HeapFree, GetSystemTime, SystemTimeToFileTime, FindResourceExW, GetFileAttributesW, FindFirstFileW, FindNextFileW, DeleteFileW, FindClose, CreateFileW, RemoveDirectoryW, LCMapStringA, GetStringTypeW, LockResource, GetCurrentDirectoryW, CreateThread, Sleep, InterlockedIncrement, InterlockedDecrement, DeleteCriticalSection, InitializeCriticalSection, GetModuleFileNameW, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, MultiByteToWideChar, GetLastError, EnterCriticalSection, RaiseException, LeaveCriticalSection, lstrcmpiW, GetModuleHandleW, GetProcAddress, lstrlenW, FreeLibrary, LCMapStringW, FileTimeToSystemTime, GetModuleHandleA, WriteConsoleA, lstrlenA, CreateFileA, GetStringTypeA, WriteConsoleW, GetConsoleOutputCP, HeapDestroy, HeapReAlloc, HeapSize, GetSystemTimeAsFileTime, CreateDirectoryW, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetStartupInfoW, RtlUnwind, VirtualFree, VirtualAlloc, HeapCreate, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, SetFilePointer, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, InitializeCriticalSectionAndSpinCount, LoadLibraryA, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, WideCharToMultiByte, GetConsoleCP, GetConsoleMode, SetStdHandle, FlushFileBuffers, GetLocaleInfoA
ole32.dll
CoTaskMemFree, CoCreateInstance, CoInitialize, CoTaskMemRealloc, CoTaskMemAlloc, CoUninitialize
shell32.dll
ShellExecuteExW
urlmon.dll
URLDownloadToFileW
user32.dll
CharNextW

extensionupdaterservice.exe

By Bit Cocktail Ltd. (Signed)

Remove extensionupdaterservice.exe
MD5:   27e402c11c323a44c080cbd31182830a
SHA1:   41cbeaea8792cf5ccc4cd63eb2c1d8fb2302ea1b
SHA256:   d7cdfbc73f66a3e03bc7f5f4baf7f0a77ce710cf59984c8641c694a2bc9f932d
Warning 3 antivirus scanners has detected malware.

What is extensionupdaterservice.exe?

Bit Cocktail Web Assistant Updater is the software updater program which runs in the background of Windows and automatically starts up when your PC boots. It checks for software udpates and automatically downloads and installs them if found.

About extensionupdaterservice.exe (from Bit Cocktail Ltd.)

Bitcocktail is home to a variety of products that provide an engaging and productive experience online. Bitcocktail features a variety of social and entertainment destinations like Vidzy, Playzy, Expr

DetailsDetails

File name:extensionupdaterservice.exe
Typical file path:C:\Program Files\web assistant\extensionupdaterservice.exe
Size:184.34 KB (188,760 bytes)
Certificate
Issued to:Bit Cocktail Ltd.
Authority (CA):Thawte
Expiration date:Wednesday, January 16, 2013
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Perion Network Ltd.
  85% remove
The IB (IncrediBar) Updater Service is designed to keep the Perion IncrediBar web browser toolbar (and other related products) up to date. The IB Updater Service runs in the background and periodically connects to the IncrediBar servers. If an update is found it will automatically download and install updates for all Perion programs. The program runs a background Windows service with full administrator privileges under one of the fol...

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • IB Updater Updater

MalwareMalware detections

Based on 40+ industry antivirus scanners, 3 of them detected the following malware.
Antivirus engineEngine versionDetection
Kingsoft 2012.9.22.155 Win32.Troj.Agent2.(kcloud)
nProtect 2012-12-03.04 Trojan/W32.Agent.188760
ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.188760

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 26.47%
Microsoft Windows XP 20.59%
Windows 7 Ultimate N 17.65%
Windows 7 Ultimate 11.76%
Windows 7 Professional 8.82%
Windows Vista Ultimate 5.88%
Windows 8 Release Preview 5.88%
Windows Vista Home Premium 2.94%

Distribution by countryDistribution by country

United States installs about 41.38% of extensionupdaterservice.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 50.00%
GIGABYTE 50.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE