Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

faccc 3.23%
de70e 3.23%
9b165 3.23%
8b7f5 3.23%
58f9d 16.13%
ebffe 3.23%
b1ec8 3.23%
5e01b 3.23%
ce2c4 3.23%
49792 3.23%
6d7c4 3.23%
ed068 12.90%
1ba41 6.45%
4f887 19.35%
d7539 3.23%
2e615 3.23%
d0c38 6.45%
(Note, Bit Cocktail Ltd. publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetSidSubAuthority, GetSidSubAuthorityCount, GetSidIdentifierAuthority, IsValidSid, GetTokenInformation, OpenProcessToken, ControlService, StartServiceW, DeleteService, OpenServiceW, CloseServiceHandle, CreateServiceW, OpenSCManagerW, SetServiceStatus, RegisterServiceCtrlHandlerW, StartServiceCtrlDispatcherW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegEnumKeyExW, RegQueryInfoKeyW, RegCloseKey, RegDeleteKeyW, RegQueryValueExW
kernel32.dll
LocalFree, LocalAlloc, GetVersionExW, GetCurrentProcess, HeapAlloc, GetProcessHeap, CloseHandle, GetTempPathW, HeapFree, GetSystemTime, SystemTimeToFileTime, FindResourceExW, GetFileAttributesW, FindFirstFileW, FindNextFileW, DeleteFileW, FindClose, CreateFileW, RemoveDirectoryW, LCMapStringA, GetStringTypeW, LockResource, GetCurrentDirectoryW, CreateThread, Sleep, InterlockedIncrement, InterlockedDecrement, DeleteCriticalSection, InitializeCriticalSection, GetModuleFileNameW, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, MultiByteToWideChar, GetLastError, EnterCriticalSection, RaiseException, LeaveCriticalSection, lstrcmpiW, GetModuleHandleW, GetProcAddress, lstrlenW, FreeLibrary, LCMapStringW, FileTimeToSystemTime, GetModuleHandleA, WriteConsoleA, lstrlenA, CreateFileA, GetStringTypeA, WriteConsoleW, GetConsoleOutputCP, HeapDestroy, HeapReAlloc, HeapSize, GetSystemTimeAsFileTime, CreateDirectoryW, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetStartupInfoW, RtlUnwind, VirtualFree, VirtualAlloc, HeapCreate, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, SetFilePointer, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, InitializeCriticalSectionAndSpinCount, LoadLibraryA, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, WideCharToMultiByte, GetConsoleCP, GetConsoleMode, SetStdHandle, FlushFileBuffers, GetLocaleInfoA
ole32.dll
CoTaskMemFree, CoCreateInstance, CoInitialize, CoTaskMemRealloc, CoTaskMemAlloc, CoUninitialize
shell32.dll
ShellExecuteExW
urlmon.dll
URLDownloadToFileW
user32.dll
CharNextW

extensionupdaterservice.exe

By Bit Cocktail Ltd. (Signed)

Remove extensionupdaterservice.exe
MD5:   ed068a3787b67008b96b994f78302264
SHA1:   4fca7346b0bfcc61d35c55ad6ed372ef71038470
SHA256:   50e23d036f435c911aef20e30eb133a579498edf034915c62935f237bf714bca
Warning 4 antivirus scanners has detected malware.

What is extensionupdaterservice.exe?

Plazy Updater is the software updater program which runs in the background of Windows and automatically starts up when your PC boots. It checks for software udpates and automatically downloads and installs them if found.

Overview

extensionupdaterservice.exe is malware that runs as a service under the name Web Assistant (Updater By SweetPacks) within the local user context. It is installed with a couple of know programs including Updater By SweetPacks 2.0.0.566 published by SweetIM Technologies Ltd., Updater By SweetPacks 2.0.0.583 from SweetIM Technologies Ltd. and Updater By SweetPacks 2.0.0.583 by SweetIM Technologies Ltd.. The file is digitally signed by Bit Cocktail Ltd. which was issued by the Thawte certificate authority (CA).

DetailsDetails

File name:extensionupdaterservice.exe
Typical file path:C:\Program Files\plazy\extensionupdaterservice.exe
Size:184.34 KB (188,760 bytes)
Certificate
Issued to:Bit Cocktail Ltd.
Authority (CA):Thawte
Expiration date:Thursday, January 16, 2014
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
SweetIM Technologies Ltd.
  67% remove
Updater By SweetPacks (from Perion) is designed to monitor and keep the SweetPacks programs automatically up to date. It checks for software updates and automatically downloads and installs them if found. It does so by adding a startup entry to the registry to automatically load each time a user logs into windows and remotely checks its server for updates by adding a Windows firewall exception. If an update is found it will silently ins...

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • Web Assistant
  • 'Updater By SweetPacks'
  • 'Web Assistant Updater'

MalwareMalware detections

Based on 40+ industry antivirus scanners, 4 of them detected the following malware.
Antivirus engineEngine versionDetection
ESET NOD32 7.9341 a variant of Win32/Toolbar.BitCocktail.B
Kingsoft 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
Malwarebytes 1.75.0.1 PUP.Optional.SweetPacks.A
ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.188760

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 26.67%
Windows Vista Home Premium 23.33%
Windows 8 16.67%
Windows 7 Ultimate N 13.33%
Microsoft Windows XP 6.67%
Windows 8 Pro 3.33%
Windows 7 Ultimate 3.33%
Windows 7 Starter 3.33%
Windows 7 Professional 3.33%

Distribution by countryDistribution by country

United States installs about 73.33% of extensionupdaterservice.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Toshiba 51.85%
Hewlett-Packard 25.93%
Gateway 7.41%
Sony 7.41%
ASUS 7.41%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE