Should I block it?

60%
60% of PCs block this file from running.
Possible reason:
Performance resource utilization

VersionsAdditional versions

18,1,7,644 1.87%
18,1,7,598 0.93%
18,1,0,443 0.93%
18,0,5,292 0.93%
18,0,5,292 0.93%
17,3,2,101 0.93%
17,3,0,49 0.93%
17, 1, 2, 1 0.93%
17, 1, 2, 1 1.87%
17, 1, 0, 27 0.93%
17, 0, 1, 12 10.28%
17, 0, 1, 12 9.35%
17, 0, 0, 12 2.80%
17, 0, 0, 12 7.48%
15, 5, 0, 2 3.74%
15, 5, 0, 2 3.74%
15, 4, 0, 5 2.80%
15, 4, 0, 5 1.87%
15, 3, 0, 11 12.15%
15, 3, 0, 11 6.54%
15, 2, 0, 5 15.89%
15, 2, 0, 5 10.28%
15, 1, 0, 2 1.87%

Relationships

Parent process
Child process

PE structurePE file structure

Show functions
Import table
advapi32.dll
ConvertStringSidToSidW, RegisterServiceCtrlHandlerW, SetServiceStatus, RegOpenKeyExW, RegNotifyChangeKeyValue, RegCloseKey, OpenProcessToken, RegCreateKeyExW, RegQueryValueExW, CryptDecrypt, CryptDestroyKey, CryptAcquireContextA, CryptDeriveKey, RegSetKeySecurity, AddAccessAllowedAce, InitializeAcl, GetNamedSecurityInfoW, SetNamedSecurityInfoW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, CryptHashData, CryptDestroyHash, CryptCreateHash, CryptReleaseContext, CryptAcquireContextW, CryptGetHashParam, GetLengthSid, GetTokenInformation, RegSetValueExW, RegLoadKeyW, AdjustTokenPrivileges, RegEnumKeyExW, RegFlushKey, RegDeleteValueW, LookupAccountSidW, LookupPrivilegeValueW, RegDeleteKeyW, StartServiceCtrlDispatcherW, RegQueryInfoKeyW, RegUnLoadKeyW, RegEnumValueW
crypt32.dll
CryptMsgGetParam, CertCloseStore, CertFindCertificateInStore, CertFreeCertificateContext, CertGetNameStringW, CryptQueryObject, CryptMsgClose, CryptProtectData
kernel32.dll
DllMain
ole32.dll
CoCreateInstance, StringFromGUID2, CoCreateGuid, CoUninitialize, CoInitialize
shell32.dll
SHGetFolderPathW, SHGetFolderPathA, SHGetSpecialFolderPathW
shlwapi.dll
UrlUnescapeW, PathFileExistsW, PathIsDirectoryW
user32.dll
wsprintfW, PostMessageW, EnumWindows, GetClassNameW, IsWindow, GetSystemMetrics
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
wininet.dll
HttpAddRequestHeadersW, HttpQueryInfoW, HttpOpenRequestW, InternetOpenW, InternetReadFile, InternetConnectW, HttpSendRequestW, InternetSetOptionW, InternetCloseHandle
wintrust.dll
WinVerifyTrust

toolbarupdater.exe

ToolbarU Application by AVG Technologies (Signed)

Remove toolbarupdater.exe
Version:   17, 1, 0, 27
MD5:   a837a57e927c7a76e9f0010fbed5104c
SHA1:   e614547e95d669206e9660132d73bdb96696fa33
SHA256:   4d0c717b6a041c84759b23ba4b887f48a797b2f964100dcf53772dad839e3ccd

Overview

toolbarupdater.exe runs as a service under the name vToolbarUpdater18.1.0 (vToolbarUpdater17.1.0) with extensive SYSTEM privileges (full administrator access). The file is digitally signed by AVG Technologies which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:toolbarupdater.exe
Publisher:AVG Secure Search
Product name:ToolbarU Application
Typical file path:C:\Program Files\common files\avg secure search\vtoolbarupdater\15.2.0\toolbarupdater.exe
Original name:ToolbarU.exe
File version:17, 1, 0, 27
Size:1.57 MB (1,643,696 bytes)
Build date:9/17/2013 7:45 AM
Certificate
Issued to:AVG Technologies
Authority (CA):VeriSign
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • vToolbarUpdater18.1.0
  • 'vToolbarUpdater17.1.0'
  • 'vToolbarUpdater17.0.12'
  • 'vToolbarUpdater15.3.0'
  • 'vToolbarUpdater15.2.0'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00043435%
0.028634%
Kernel CPU:0.00019399%
0.013761%
User CPU:0.00024037%
0.014873%
Kernel CPU time:5,834 ms/min
100,923,805ms/min
CPU cycles:64,816/sec
17,470,203/sec
Memory
Private memory:4.88 MB
21.59 MB
Private (maximum):10.14 MB
Private (minimum):6.55 MB
Non-paged memory:4.88 MB
21.59 MB
Virtual memory:76.01 MB
140.96 MB
Virtual memory (peak):84.76 MB
169.69 MB
Working set:7.89 MB
18.61 MB
Working set (peak):10.17 MB
37.95 MB
Page faults:32,849/min
2,039/min
I/O
I/O read transfer:51 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:281 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:557 Bytes/sec
448.09 KB/min
I/O other operations:20/sec
1,671/min
Resource allocations
Threads:12
12
Handles:207
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:"C:\Program Files\common files\avg secure search\vtoolbarupdater\17.1.0\toolbarupdater.exe"
Owner:SYSTEM
Windows Service
Service name:vToolbarUpdater17.1.0
Display name:vToolbarUpdater18.1.0
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
wow64.dll
Total CPU:0.00050451%
0.272967%
Kernel CPU:0.00043674%
0.107585%
User CPU:0.00006777%
0.165382%
CPU cycles:6,918/sec
5,741,424/sec
Memory:252 KB
1.16 MB
ntdll.dll
Total CPU:0.00010651%
Kernel CPU:0.00007989%
User CPU:0.00002663%
CPU cycles:2,390/sec
Memory:1.66 MB
ToolbarUpdater.exe (main module)
Total CPU:0.00005271%
Kernel CPU:0.00005020%
User CPU:0.00000251%
CPU cycles:656/sec
Memory:1.58 MB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 33.96%
Windows 7 Ultimate 27.36%
Microsoft Windows XP 11.32%
Windows 7 Professional 7.55%
Windows 8 6.60%
Windows Vista Home Premium 4.72%
Windows 8 Pro with Media Center 1.89%
Windows 8 Single Language 1.89%
Windows 8.1 Pro with Media Center 0.94%
Windows 7 Home Basic 0.94%
Windows Vista Ultimate 0.94%
Windows 8 Pro 0.94%
Windows Vista Home Basic 0.94%

Distribution by countryDistribution by country

United States installs about 39.42% of ToolbarU Application.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 23.62%
Hewlett-Packard 14.96%
ASUS 12.60%
Toshiba 12.60%
Dell 11.02%
Sony 6.30%
Lenovo 4.72%
Gateway 3.15%
Intel 3.15%
GIGABYTE 2.36%
Compaq 1.57%
American Megatrends 1.57%
Samsung 1.57%
Alienware 0.79%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE