Extended Update
by installCore
What is Extended Update?
Extended Update is software application developed by installCore. It is most commonly found on computers running Windows 7 with nearly 46.16% of installations running this operating system. Extended Update's installer is typically 664.00 KB in size and installs around 45 files.
Extended Update is most popular in the United States with 84.99% of installations residing in this country.
Extended Update adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.
Multiple virus scanners have detected malware in Extended Update.
| Scanner Software | Version | Result |
|---|---|---|
| AVware | 1.5.0.16 | Trojan.Win32.Generic!BT |
| Baidu-International | 3.5.1.41473 | Adware.Win32.Visicom.81 |
| ESET-NOD32 | 10201 | a variant of Win32/Toolbar.Visicom.C |
| IKARUS anti.virus | T3.1.6.1.0 | PUA.SearchAndMedia |
| VIPRE Antivirus | 31916 | Trojan.Win32.Generic!BT |
| Scanner Software | Version | Result |
|---|---|---|
| AVware | 1.5.0.21 | Trojan.Win32.Generic!BT |
| ESET-NOD32 | 11432 | a variant of Win32/Bundled.Toolbar.Ask.K potentially unsafe |
| K7 AntiVirus | 9.202.15497 | Unwanted-Program ( 004b90b41 ) |
| K7GW | 9.202.15496 | Unwanted-Program ( 004b90b41 ) |
| Kaspersky | 15.0.1.10 | not-a-virus:WebToolbar.Win32.SearchSuite.w |
| VIPRE Antivirus | 39108 | Trojan.Win32.Generic!BT |
| Baidu-International | 3.5.1.41473 | Adware.Win32.Visicom.81 |
| IKARUS anti.virus | T3.1.6.1.0 | PUA.SearchAndMedia |
Software Behaviors
- Services:
-
- CVHSVC.EXE runs as a service named 'cvhsvc' (cvhsvc) "Client Virtualization Handler Service (unlocalized description)".
- CVHBS.EXE runs as a service named 'McAfee Application Installer Cleanup (0201661432130199)' (0201661432130199mcinstcleanup).
- Adobe AIR Updater.exe runs as a service named 'McAfee Application Installer Cleanup (0265021448337632)' (0265021448337632mcinstcleanup).
- atcliun.exe runs as a service named 'Optimizer Pro Crash Monitor' (70e6ca8c).
- Scheduled tasks:
-
- CVH.EXE is scheduled as a task with the class '{A39DACC4-31DF-466F-A88B-716DF45C2724}' (runs on registration).
- UpdateTask.exe is scheduled as a task named 'WSE_Vosteran' (runs daily at 3:32 PM).
- CVHBS.EXE is scheduled as a task named 'UpdaterEX' (runs daily at 3:07 PM).
- C2RICONS.EXE is scheduled as a task with the class '{C9D0AF2A-4179-4A5C-A53B-BA0FF5C4894F}' (runs on registration).
- CVHSVC.EXE is scheduled as a task with the class '{9CCF83FE-C6A1-43D4-AC4A-58785C8D2252}' (runs on registration).
- OFFICEVIRT.EXE is scheduled as a task with the class '{3B23BCDA-6BDB-437D-B180-6439CB4337D7}' (runs on registration).
Startup Entries
- Registry entries:
-
- CVH.EXE is loaded in the current user (HKCU) registry as an auto-starting executable named 'Microsoft Office Client Virtualization Handler' and executes as C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVH.EXE.
Software Details
- URL:
- https://www.installcore.com
- Support:
- –
- Installation path:
- C:\users\user\appdata\roaming\updaterex\updateproc
- Uninstaller:
- C:\users\user\appdata\Roaming\UpdaterEX\UpdateProc\UpdateTask.exe /Uninstall
- Size:
- 664.00 KB
- Language:
- English
Extended Update Executable Details
- Primary executable:
- UpdateTask.exe
- Name:
- Extended Update
- Path:
- C:\users\user\appdata\roaming\updaterex\updateproc\UpdateTask.exe
- MD5:
- 5f6f4ee3faa18ef7e386864cedf6dc06
- SHA-1:
- –
- SHA-256:
- –
| File Type | Filename | MD5 |
|---|---|---|
|
EXE
|
1b625cfe31f86be43f279cfffbfd4bf1 | |
|
DLL
|
81b31773039dd1fedace4fca1e5a45ed | |
|
DLL
|
b8663f27f4a8f009ed4b30232dbe36e2 | |
|
DLL
|
df868412f45988d2a262a85cb8ed9043 | |
|
DLL
|
395aec2e286c4520fd590b24434d4270 | |
|
EXE
|
86de6fc591b5ba79c342691d224765eb | |
|
DLL
|
fe847762bd5b4598412fb9e2480d160e | |
|
EXE
|
b4d1d62a09f09cb2dfd55628350cdafb | |
|
DLL
|
c05bd2ddf801125bd23176193f2a99ac | |
|
EXE
|
6ad80d3009381851120c29ac301765dc |