Extended Update
by installCore
What is Extended Update?
Extended Update is software application developed by installCore. It is most commonly found on computers running Windows 7 with nearly 46.16% of installations running this operating system. Extended Update's installer is typically 664.00 KB in size and installs around 45 files.
Extended Update is most popular in the United States with 84.99% of installations residing in this country.
Extended Update adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.
Multiple virus scanners have detected malware in Extended Update.
| Scanner Software | Version | Result |
|---|---|---|
| AVware | 1.5.0.16 | Trojan.Win32.Generic!BT |
| Baidu-International | 3.5.1.41473 | Adware.Win32.Visicom.81 |
| ESET-NOD32 | 10201 | a variant of Win32/Toolbar.Visicom.C |
| IKARUS anti.virus | T3.1.6.1.0 | PUA.SearchAndMedia |
| VIPRE Antivirus | 31916 | Trojan.Win32.Generic!BT |
| Scanner Software | Version | Result |
|---|---|---|
| AVware | 1.5.0.21 | Trojan.Win32.Generic!BT |
| ESET-NOD32 | 11432 | a variant of Win32/Bundled.Toolbar.Ask.K potentially unsafe |
| K7 AntiVirus | 9.202.15497 | Unwanted-Program ( 004b90b41 ) |
| K7GW | 9.202.15496 | Unwanted-Program ( 004b90b41 ) |
| Kaspersky | 15.0.1.10 | not-a-virus:WebToolbar.Win32.SearchSuite.w |
| VIPRE Antivirus | 39108 | Trojan.Win32.Generic!BT |
| Baidu-International | 3.5.1.41473 | Adware.Win32.Visicom.81 |
| IKARUS anti.virus | T3.1.6.1.0 | PUA.SearchAndMedia |
Software Behaviors
- Services:
-
- CVHSVC.EXE runs as a service named 'cvhsvc' (cvhsvc) "Client Virtualization Handler Service (unlocalized description)".
- CVHBS.EXE runs as a service named 'McAfee Application Installer Cleanup (0201661432130199)' (0201661432130199mcinstcleanup).
- Adobe AIR Updater.exe runs as a service named 'McAfee Application Installer Cleanup (0265021448337632)' (0265021448337632mcinstcleanup).
- atcliun.exe runs as a service named 'Optimizer Pro Crash Monitor' (70e6ca8c).
- Scheduled tasks:
-
- CVH.EXE is scheduled as a task with the class '{A39DACC4-31DF-466F-A88B-716DF45C2724}' (runs on registration).
- UpdateTask.exe is scheduled as a task named 'WSE_Vosteran' (runs daily at 3:32 PM).
- CVHBS.EXE is scheduled as a task named 'UpdaterEX' (runs daily at 3:07 PM).
- C2RICONS.EXE is scheduled as a task with the class '{C9D0AF2A-4179-4A5C-A53B-BA0FF5C4894F}' (runs on registration).
- CVHSVC.EXE is scheduled as a task with the class '{9CCF83FE-C6A1-43D4-AC4A-58785C8D2252}' (runs on registration).
- OFFICEVIRT.EXE is scheduled as a task with the class '{3B23BCDA-6BDB-437D-B180-6439CB4337D7}' (runs on registration).
Startup Entries
- Registry entries:
-
- CVH.EXE is loaded in the current user (HKCU) registry as an auto-starting executable named 'Microsoft Office Client Virtualization Handler' and executes as C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVH.EXE.
Software Details
- URL:
- https://www.installcore.com
- Support:
- –
- Installation path:
- C:\users\user\appdata\roaming\updaterex\updateproc
- Uninstaller:
- C:\users\user\appdata\Roaming\UpdaterEX\UpdateProc\UpdateTask.exe /Uninstall
- Size:
- 664.00 KB
- Language:
- English
Extended Update Executable Details
- Primary executable:
- UpdateTask.exe
- Name:
- Extended Update
- Path:
- C:\users\user\appdata\roaming\updaterex\updateproc\UpdateTask.exe
- MD5:
- 5f6f4ee3faa18ef7e386864cedf6dc06
- SHA-1:
- –
- SHA-256:
- –
| File Type | Filename | MD5 |
|---|---|---|
|
DLL
|
3bd4f1e8910d2b48ebdb29e53f5eb6c0 | |
|
DLL
|
88bb0a11bae0a48a121168358ba25e7e | |
|
EXE
|
0f5a46ce9049692d43e932fe443a7c47 | |
|
DLL
|
87ce629969ae811ad87f767ef4b991f3 | |
|
EXE
|
82f048f42a370b3bcd665a73212909f9 | |
|
DLL
|
8d2935f67d2c52e14de8ce2195896db2 | |
|
EXE
|
c7a51d3f93e2a7917c924111d80f4222 | |
|
DLL
|
ce5ce3cd7d99a1704c97265f75c6d748 | |
|
EXE
|
1fb5bae5a38d2cacccb40a82f5be6c90 | |
|
DLL
|
6ea7d39abe094facfe6c0727a6a67fa8 |