extensionupdaterservice.exe

Bit Cocktail Ltd.

The application extensionupdaterservice.exe by Bit Cocktail has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “IB Updater”. This file is typically installed with the program IB Updater 2.0.0.530 by Perion Network Ltd. which is a potentially unwanted software program.
Publisher:
Bit Cocktail Ltd.  (signed and verified)

MD5:
8b672417438380704e6a39b2f9d78ee8

SHA-1:
af6b38bf9c4acdf3069122eed8bdccae6fa433ad

SHA-256:
5d713d408e488d3190e8ae2563ba48b5fbea52c36cbc4bafaa642c408ee4c19c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/24/2024 8:17:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BitCocktail (M)
17.2.27.9

File size:
184.3 KB (188,760 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\ib updater\extensionupdaterservice.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/16/2012 6:00:00 PM

Valid to:
1/16/2013 5:59:59 PM

Subject:
CN=Bit Cocktail Ltd., O=Bit Cocktail Ltd., L=Herzeliya, S=Herzeliya, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
613E461899A05578474D1423CF9CC340

File PE Metadata
Compilation timestamp:
10/4/2012 7:06:36 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xAD21

Entry point:
E8, 3A, 57, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 00, 01, 00, 00, 72, 0E, 83, 3D, 20, 12, 42, 00, 00, 74, 05, E9, F1, 57, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07, 83, C7, 01, 83, EA, 01, 75, F6, 8B, 44...
 
[+]

Entropy:
6.1364

Code size:
98 KB (100,352 bytes)

Service
Display name:
IB Updater

Type:
Win32OwnProcess


The file extensionupdaterservice.exe has been discovered within the following program.

IB Updater 2.0.0.530  by Perion Network Ltd.
The IB (IncrediBar) Updater Service is designed to keep the Perion IncrediBar web browser toolbar (and other related products) up to date. The IB Updater Service runs in the background and periodically connects to the IncrediBar servers.
www.incredibar.com
80% remove it
 
Powered by Should I Remove It?

Remove extensionupdaterservice.exe - Powered by Reason Core Security