Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryInfoKeyW, RegOpenKeyExW, RegQueryValueExW, OpenProcessToken, CreateProcessAsUserW, GetSidSubAuthorityCount, GetSidSubAuthority, RegSetValueExW, RegDeleteValueW, RegCreateKeyExW, RegEnumKeyExW, RegEnumValueW, RegDeleteKeyW, GetTokenInformation, RegCloseKey
crypt32.dll
CertCloseStore, CryptMsgClose, CertFindCertificateInStore, CryptMsgGetParam, CertFreeCertificateContext, CryptQueryObject
gdi32.dll
CreateCompatibleDC, CreateCompatibleBitmap, SelectObject, DeleteObject, BitBlt, DeleteDC, GetStockObject, GetObjectW, GetDeviceCaps, CreateSolidBrush
kernel32.dll
CreateEventW, SetCurrentDirectoryW, SetEvent, DeleteCriticalSection, RaiseException, InterlockedExchange, SwitchToThread, FindResourceW, Sleep, InitializeCriticalSectionAndSpinCount, SetLastError, CreateThread, WaitForSingleObject, LoadLibraryW, FreeLibrary, GetCommandLineW, CompareStringW, CreateFileW, SetNamedPipeHandleState, GetLocalTime, WriteFile, GetCommandLineA, GetFileSize, ReadFile, CreateMutexW, ReleaseMutex, ResetEvent, GetExitCodeThread, InterlockedExchangeAdd, InterlockedDecrement, CreateIoCompletionPort, TerminateThread, GetSystemInfo, PostQueuedCompletionStatus, GetQueuedCompletionStatus, InterlockedIncrement, CancelWaitableTimer, CreateWaitableTimerW, SetWaitableTimer, FindResourceExW, GetFileAttributesW, GlobalUnlock, GlobalLock, GlobalAlloc, MulDiv, lstrcmpW, SetFilePointer, GetCurrentDirectoryW, OpenMutexW, GetModuleHandleA, GlobalFree, InitializeSListHead, GetThreadTimes, LeaveCriticalSection, FlushFileBuffers, WriteConsoleW, SetStdHandle, GetConsoleMode, GetConsoleCP, IsValidLocale, EnumSystemLocalesA, GetLocaleInfoA, GetUserDefaultLCID, GetSystemTimeAsFileTime, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetLocaleInfoW, GetStdHandle, ExitProcess, TlsFree, IsValidCodePage, GetOEMCP, GetACP, HeapCreate, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, LCMapStringW, GetCPInfo, ExitThread, RtlUnwind, GetStartupInfoW, HeapSetInformation, FindClose, FindNextFileW, FindFirstFileW, GetModuleHandleExW, DeleteFileW, TlsSetValue, TlsGetValue, TlsAlloc, GetPrivateProfileSectionW, QueryPerformanceCounter, GetComputerNameW, UnmapViewOfFile, CreateFileMappingW, MapViewOfFileEx, OutputDebugStringW, ReleaseSemaphore, CreateSemaphoreW, InitializeCriticalSection, WideCharToMultiByte, GetStringTypeW, HeapSize, HeapReAlloc, HeapDestroy, InterlockedPopEntrySList, VirtualAlloc, VirtualFree, IsProcessorFeaturePresent, HeapAlloc, GetProcessHeap, HeapFree, InterlockedPushEntrySList, LoadLibraryA, LocalAlloc, EnterCriticalSection, GetCurrentThreadId, FlushInstructionCache, LockResource, LoadResource, SizeofResource, lstrlenW, lstrcatW, lstrcpyW, GetVersionExW, InterlockedCompareExchange, GetCurrentProcessId, GetModuleFileNameW, CreateDirectoryW, LocalFree, TerminateProcess, ResumeThread, GetModuleHandleW, GetProcAddress, GetExitCodeProcess, QueueUserAPC, GetCurrentThread, GetCurrentProcess, DuplicateHandle, CloseHandle, lstrlenA, MultiByteToWideChar, WaitForMultipleObjectsEx, GetTickCount, GetLastError
ole32.dll
OleUninitialize, OleInitialize, StringFromGUID2, CoReleaseMarshalData, CoGetClassObject, OleLockRunning, StringFromCLSID, CLSIDFromString, CoUnmarshalInterface, CreateStreamOnHGlobal, CoTaskMemFree, CoAddRefServerProcess, CoReleaseServerProcess, CoTaskMemAlloc, CoRevokeClassObject, CoCreateInstance, CoUninitialize, CoMarshalInterface, CLSIDFromProgID, CoGetCurrentLogicalThreadId, CoInitialize
rpcrt4.dll
RpcAsyncInitializeHandle, RpcServerRegisterIfEx, RpcServerUnregisterIf, RpcAsyncAbortCall, RpcServerUseProtseqEpW, RpcStringFreeW, RpcBindingFree, RpcBindingFromStringBindingW, RpcStringBindingComposeW, NdrAsyncServerCall, RpcAsyncCompleteCall, NdrAsyncClientCall
setupapi.dll
SetupGetFileCompressionInfoW, SetupDecompressOrCopyFileW
shlwapi.dll
PathRemoveFileSpecW, PathAppendW, StrChrW, PathCombineW, UrlCanonicalizeW, UrlUnescapeW, UrlCreateFromPathW, UrlIsW, SHDeleteKeyW, PathFindFileNameW, PathRenameExtensionW
urlmon.dll
CoInternetGetSecurityUrl, CoInternetGetSession
user32.dll
PostQuitMessage, CallMsgFilterW, TranslateMessage, PeekMessageW, FindWindowW, GetDlgItem, GetWindowRect, SetRect, IsRectEmpty, CopyRect, EnumDisplayMonitors, GetMonitorInfoW, SetDlgItemTextW, UnregisterClassA, SetWindowLongW, GetWindowLongW, MsgWaitForMultipleObjectsEx, DispatchMessageW, DefWindowProcW, CallWindowProcW, DestroyWindow, MessageBoxW, SetTimer, GetMessageW, KillTimer, PostThreadMessageW, GetActiveWindow, RegisterClassExW, GetClassInfoExW, SetClipboardData, GetClipboardData, CloseClipboard, OpenClipboard, BringWindowToTop, GetForegroundWindow, SetForegroundWindow, AdjustWindowRectEx, EqualRect, InflateRect, PostMessageW, SetParent, GetTopWindow, EnumChildWindows, RegisterWindowMessageW, GetWindowTextLengthW, GetWindowTextW, SetWindowTextW, BeginPaint, EndPaint, IsChild, GetFocus, SetFocus, GetWindow, SendMessageW, GetClassNameW, GetSysColor, SetWindowPos, RedrawWindow, CreateAcceleratorTableW, ClientToScreen, GetParent, ScreenToClient, MoveWindow, SetCapture, ReleaseCapture, FillRect, InvalidateRgn, InvalidateRect, GetDC, ReleaseDC, DestroyAcceleratorTable, GetClientRect, SetRectEmpty, GetDesktopWindow, ShowWindow, IsWindow, CharUpperW, CharNextW, CreateWindowExW, CreateDialogParamW, LoadCursorW
userenv.dll
UnloadUserProfile
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
wintrust.dll
WinVerifyTrust

CrExtPv4.exe

By Mindspark Interactive Network (Signed)

Remove CrExtPv4.exe
Version:   1.0.4.34
MD5:   7edafac1518da60b6da06d68affda75f
SHA1:   3a657aceb92289972efa3565b6fedd7238c3a4b1
SHA256:   9317c10f11cfe367b05b6672b474dfeb9c8f08400bc1e83c8ba307080b3476e0
Warning 3 antivirus scanners has detected malware.

What is CrExtPv4.exe?

MindSpark Toolbar Platform manages the myWebSearch Toolbar, a web-browser add-on that provides search functions to the browser menu as well as a toolbar. The toolbar automatically installed with iWon, allowing user to query myWebSearch search engine.

About CrExtPv4.exe (from Mindspark Interactive Network)

MyWebSearch brings together the most comprehensive collection of search tools available to provide you with the information you need when you need it. MyWebSearch allows you to search the web directly

DetailsDetails

File name:CrExtPv4.exe
Typical file path:C:\Program Files\DictionaryBoss\bar\1.bin\CrExtPv4.exe
Original name:CrExtProc.exe
File version:1.0.4.34
Size:1.23 MB (1,292,432 bytes)
Certificate
Issued to:Mindspark Interactive Network
Authority (CA):VeriSign
Effective date:Monday, April 9, 2012
Expiration date:Wednesday, May 6, 2015
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

MalwareMalware detections

Based on 40+ industry antivirus scanners, 3 of them detected the following malware.
Antivirus engineEngine versionDetection
AVG 2014.0.3629 Zango
Kingsoft 2013.1.8.219 Win32.Troj.Generic.a.(kcloud)
VIPRE Antivirus 16734 MyWebSearch.J (v) (not malicious)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.02811694%
0.028634%
Kernel CPU:0.01677389%
0.013761%
User CPU:0.01134305%
0.014873%
Kernel CPU time:2,061 ms/min
100,923,805ms/min
CPU cycles:645,559/sec
17,470,203/sec
Context switches:15/sec
284/sec
Memory
Private memory:11.24 MB
21.59 MB
Private (maximum):11.12 MB
Private (minimum):3.56 MB
Non-paged memory:11.24 MB
21.59 MB
Virtual memory:135.28 MB
140.96 MB
Virtual memory (peak):144.43 MB
169.69 MB
Working set:6.14 MB
18.61 MB
Working set (peak):21.6 MB
37.95 MB
Page faults:16,361/min
2,039/min
I/O
I/O read transfer:186 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:0 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:69 Bytes/sec
448.09 KB/min
I/O other operations:3/sec
1,671/min
Resource allocations
Threads:12
12
Handles:288
600
GUI GDI count:53
103
GUI GDI peak:60
142
GUI USER count:36
49
GUI USER peak:43
71

BehaviorsProcess properties

Integrety level:Low
Platform:32-bit
Command lines:
  • "C:\Program Files\totalrecipesearch_14\bar\1.bin\crextp14.exe" /context="91fbdd335935d6fab2f0f46ec3451b3a18a24a23¿totalrecipesearch_14¿0000018d400001000" /extensionversionstr="1.2.3" /browserversion="10.0.9200.16720" /browserversionstr="10.0.9200.16720"
  • "C:\Program Files\totalrecipesearch_14\bar\1.bin\crextp14.exe" /context="e437a5256462a30d394f92ef7f9b66af4601a2bd¿totalrecipesearch_14¿0000018d400001000" /extensionversionstr="1.1.2" /browserversion="10.0.9200.16720" /browserversionstr="10.0.9200.16720"
  • "C:\Program Files\filmfanatic\bar\1.bin\crextppa.exe" /context="91fbdd335935d6fab2f0f46ec3451b3a18a24a23¿filmfanatic¿00000043400001000" /extensionversionstr="1.2.2" /browserversion="10.0.9200.16453" /browserversionstr="10.0.9200.16453"
  • "C:\Program Files\couponalert_2p\bar\1.bin\crextp2p.exe" /context="0072613205726085b1c6214db362695a458cc3e5¿couponalert_2p¿0000003c800001000" /extensionversionstr="1.0.2" /browserversion="8.0.7601.17514" /browserversionstr="8.0.7601.17514"
  • "C:\Program Files\couponalert_2p\bar\1.bin\crextp2p.exe" /context="0072613205726085b1c6214db362695a458cc3e5¿couponalert_2p¿00000009000003000" /extensionversionstr="1.0.2" /browserversion="8.0.7601.17514" /browserversionstr="8.0.7601.17514"
  • "C:\progra~1\yourlo~2\bar\1.bin\crextp20.exe" /context="e060dccb724729a4d17ba3a0e443b752794583e0¿yourlocallotto1_20¿00000047400001000" /extensionversionstr="1.0.1" /browserversion="8.0.7601.17514" /browserversionstr="8.0.7601.17514"
  • "C:\Program Files\dictionaryboss\bar\1.bin\crextpv4.exe" /context="98c04b7e5a161d5bfabff90ad2d71698ba9029a2¿dictionaryboss¿0000006d400001000" /extensionversionstr="1.1" /browserversion="8.0.7601.17514" /browserversionstr="8.0.7601.17514"
  • (8 more)
Owner:User
Parent process:iexplore.exe (by Microsoft)

ResourcesThreads

Averages
 
CrExtPv4.exe (main module)
Total CPU:0.01129903%
0.272967%
Kernel CPU:0.00655217%
0.107585%
User CPU:0.00474685%
0.165382%
CPU cycles:456,772/sec
5,741,424/sec
Context switches:5/sec
79/sec
Memory:1.25 MB
1.16 MB
ntdll.dll
Total CPU:0.00014234%
Kernel CPU:0.00010488%
User CPU:0.00003746%
CPU cycles:5,576/sec
Memory:1.66 MB
wow64cpu.dll
Total CPU:0.00011238%
Kernel CPU:0.00000375%
User CPU:0.00010864%
CPU cycles:3,418/sec
Memory:32 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate N 57.14%
Windows 7 Home Premium 28.57%
Windows 8 14.29%

Distribution by countryDistribution by country

United States installs about 100.00% of CrExtPv4.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Toshiba 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE