extensionupdaterservice.exe

Fedorov Paul

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application extensionupdaterservice.exe by Fedorov Paul has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Update Service for advPlugin”.
Publisher:
Fedorov Paul  (signed and verified)

MD5:
cc83a45b1a3f65148af8cd549de0b4de

SHA-1:
3244e1142d348071ec2326daf6a3bdf4cff0cb7a

SHA-256:
bdcfbc0fc0680978db6bd0135433552602fab566f1c9f40c5ad1ae5e94815e3d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/4/2024 10:43:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Webpick (M)
16.12.19.4

File size:
134.4 KB (137,584 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\advplugin\basement\extensionupdaterservice.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
11/7/2014 5:00:00 AM

Valid to:
11/5/2015 4:59:59 AM

Subject:
CN=Fedorov Paul, OU=Individual Developer, O=No Organization Affiliation, L=Saint-Petersburg, S=US Minor Outlying Islands, C=RU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1F1C6CD90A38CE2585B8E44D4C5B4372

File PE Metadata
Compilation timestamp:
12/6/2014 11:26:38 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x85F4

Entry point:
E8, 24, 76, 00, 00, E9, 89, FE, FF, FF, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 80, 00, 00, 00, 72, 0E, 83, 3D, F4, 09, 42, 00, 00, 74, 05, E9, 8C, 76, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07, 83, C7, 01, 83, EA, 01, 75, F6, 8B, 44, 24, 08, 5F...
 
[+]

Code size:
89 KB (91,136 bytes)

Service
Display name:
Update Service for advPlugin

Type:
Win32OwnProcess


Remove extensionupdaterservice.exe - Powered by Reason Core Security