ApnSetup.exe

Stub Installer

APN LLC

This installer is part of the Ask.com (APN) network which will install the Ask.com branded toolbar or browser extension which will take control of the web browser's search functions. The application ApnSetup.exe by APN has been detected as a potentially unwanted program by 17 anti-malware scanners. The program is a setup application that uses the APN Stub installer. This version of the installer will bundle the Ask.com Toolbar, a potentially unwanted web browser extension.
Publisher:
Ask Partner Network  (signed by APN LLC)

Product:
Stub Installer

Version:
7.15.0.89

MD5:
07d8c061faea0fe27b38086f3789abdd

SHA-1:
c6684bd626e679204e8cb22df32ad6d722466285

SHA-256:
713193353d7be1f822d48b9a650d6126afdbf6bba6ead325b40c11c896d6f18e

Scanner detections:
17 / 68

Status:
Potentially unwanted

Explanation:
Bundles that Ask.com toolbar as a third-party offer, a web browser extension that may modify a user's search and home pages.

Analysis date:
4/26/2024 3:58:50 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Ask
7.1.1

avast!
Kukacka
2014.9-160215

Baidu Antivirus
Adware.Win32.AskToolbar
4.0.3.16215

Bkav FE
HW32.Pedka
1.3.0.4959

Dr.Web
Adware.Toolbar.579
9.0.1.046

ESET NOD32
Win32/Bundled.Toolbar.Ask.E potentially unsafe (variant)
10.12330

Fortinet FortiGate
Riskware/Ask
2/15/2016

G Data
Win32.Trojan.Agent.YA0M5C
16.2.24

IKARUS anti.virus
Win32.Malware
t3scan.2.2.29

Malwarebytes
PUP.Optional.APNToolBar
v2016.02.15.06

McAfee
Artemis!23F69DA31ECC
5600.6489

Microsoft Security Essentials
Threat.Undefined
1.199.375.0

Panda Antivirus
PUP/SearchResultsToolbar
16.02.15.06

Reason Heuristics
PUP.Ask.APN.Installer (M)
16.2.15.6

Trend Micro House Call
Suspicious_GEN.F47V0330
7.2.46

VIPRE Antivirus
Threat.4721115
40432

Zillya! Antivirus
Adware.Agent.Win32.67995
2.0.0.2421

File size:
3.2 MB (3,356,056 bytes)

Product version:
7.15.0.89

Copyright:
Copyright © 2013 Ask Partner Network. All rights reserved.

Original file name:
ApnSetup.exe

File type:
Executable application (Win32 EXE)

Installer:
APN Stub

Language:
English (United States)

Common path:
C:\ProgramData\apn\apn-stub\real5-y\apnsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/22/2014 10:00:00 PM

Valid to:
4/8/2015 8:59:59 PM

Subject:
CN=APN LLC, OU=Distribution, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=APN LLC, L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2F4E343161BC7EB67514D3DCEC434EA0

File PE Metadata
Compilation timestamp:
12/1/2014 8:22:36 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:B6Bs3v4rFymmcIOHIAZJVmlRWx7WvqTXo4:N3v4rEm7jBZJVmlRWFWiT7

Entry address:
0x46D25

Entry point:
E8, 2A, 5A, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 84, 9D, 47, 00, 75, 02, F3, C3, E9, AC, 5A, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, D7, 1A, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 21, 60, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 68, 5B, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 07, 1D, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73...
 
[+]

Code size:
389 KB (398,336 bytes)

Startup File (All Users Run Once)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

Name:
APN-Stub_REAL5-Y

Command:
"C:\ProgramData\apn\apn-stub\real5-y\apnsetup.exe" \install=real5-y \dtid=ayn130 \trgb=cr \type=sb-vantb \sa=1 \hpr=1 \cruu=aaaafdipcmcpaplbkhbembancdodgnna \log \local \noremoteic \geo=br \runonce \s


Remove ApnSetup.exe - Powered by Reason Core Security