externalwrapper.exe

Dictionary Toolbar

Dictionary.com

This installer is part of the Ask.com (APN) network which will install the Ask.com branded toolbar or browser extension which will take control of the web browser's search functions. The application externalwrapper.exe, “Wrapper Application” by Dictionary.com has been detected as adware by 3 anti-malware scanners. The program is a setup application that uses the APN Stub installer. This version of the installer will bundle the Ask.com Toolbar, a potentially unwanted web browser extension.
Publisher:
Ask  (signed by Dictionary.com)

Product:
Dictionary Toolbar

Description:
Wrapper Application

Version:
1.9.1.0

MD5:
23bf60ec67d3a5a09ccc029588093ca1

SHA-1:
1540418b0869adc120f55a0ae3c9eb7421b91ce8

Scanner detections:
3 / 68

Status:
Adware

Explanation:
Bundles that Ask.com toolbar as a third-party offer, a web browser extension that may modify a user's search and home pages.

Analysis date:
4/25/2024 5:07:05 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
PUA.Win32.AskToolbar
4.0.3.1514

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant)
9.10501

Reason Heuristics
PUP.Toolbar.Dictionary.P
14.7.28.0

File size:
2.9 MB (2,992,080 bytes)

Product version:
1.9.1.0

Copyright:
Copyright (C) 2010 Ask.com.

Original file name:
wrapper.exe

File type:
Executable application (Win32 EXE)

Installer:
APN Stub

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\externalwrapper.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/15/2009 7:00:00 PM

Valid to:
12/16/2011 6:59:59 PM

Subject:
CN=Dictionary.com, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Dictionary.com, L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
345BD4AD5F18CB3CF53744DDDB3E0903

File PE Metadata
Compilation timestamp:
10/5/2010 4:09:30 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:wblT6fkbVCs/2cex8CfdVY36EfrTzcZzelGfHs1OpaJfeTMyCwMWr2ZEtyfW8WJL:wbgfjDYKEgZMGfHs1RFUMgVsW8WBew3l

Entry address:
0xA8C2

Entry point:
E8, 0E, 74, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A4, 01, 00, 00, 81, F9, 00, 01, 00, 00, 72, 1F, 83, 3D, F8, 2C, 42, 00, 00, 74, 16, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 08, 5E, 5F, 5D, E9, DB, 74, 00, 00, F7, C7, 03, 00, 00, 00, 75, 15, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 2A, F3, A5, FF, 24, 95, 44, AA, 40, 00, 90, 8B, C7, BA, 03, 00, 00, 00, 83, E9, 04, 72, 0C, 83, E0...
 
[+]

Entropy:
7.6345

Code size:
88.5 KB (90,624 bytes)

Remove externalwrapper.exe - Powered by Reason Core Security