askinstallchecker.exe

Install Checker

Ask.com

This is a component of the Ask.com toolbar, a browser extension that will modify the default web browser's search provider, home page and various other settings. The application askinstallchecker.exe has been detected as adware by 3 anti-malware scanners. This version of the file will bundle the Ask.com Toolbar, a potentially unwanted web browser extension. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address 199.36.102.106.df.iacapn.com on port 80 using the HTTP protocol.
Publisher:
Ask.com

Product:
Install Checker

Version:
1.5.0.0

MD5:
8e1d1a57db59decb22b114f03be5343f

SHA-1:
ab7569643847f4cd11651c043b196f932fb3eddf

SHA-256:
ded71a32c488d40bd02a509ef45f01cc02a4e704cdd5c3bc092cb57aceec3420

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
4/25/2024 7:27:51 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant)
8.9311

herdProtect (fuzzy)
2014.5.2.2

Reason Heuristics
PUP.Ask.R
14.3.16.16

File size:
242.9 KB (248,685 bytes)

Product version:
1.5.0.0

Copyright:
© 2008 Ask.com

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\askinstallchecker.exe

File PE Metadata
Compilation timestamp:
4/6/2010 12:33:24 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:L9Sc/cBP7ZyFQyNGhwPjVr88LkkPl5qcV21BSA5mffoL6xB3UCWT4zeNpdrhUu5z:L9+B9AHKyjVrTLkkP7qcXvxZzchp

Entry address:
0xDD66

Entry point:
E8, BB, 90, 00, 00, E9, 79, FE, FF, FF, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3, 8D, 41, FE, 8B, 4C, 24, 04, 2B, C1...
 
[+]

Entropy:
6.7299

Code size:
132.5 KB (135,680 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to 199.36.102.106.df.iacapn.com  (199.36.102.106:80)

TCP (HTTP):
Connects to 74.113.233.61.df.iaccap.com  (74.113.233.61:80)

Remove askinstallchecker.exe - Powered by Reason Core Security