Ask.com

Publisher Information

Ask.com is a software developer located in Oakland, California in the United States*. The company is a primary distributor of potentially unwanted software. Ask.com is a toolbar distribution and monetization platform that provides publishers the ability to create white-label toolbars using the APN (Ask Partner Network) platform. Ask in turn provides web search using partners such as Google. Thre are 5 additional code signing certificates issued to this publisher.
Remove Ask.com Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
6/20/2011 2:00:00 AM

Valid to:
6/19/2014 1:59:59 AM

Subject:
CN=Ask.com, OU=Distribution, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Ask.com, L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0965f2ac7236c7e1bdca44ed139b273a

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Ask.Installer (M), PUP.Ask (M), PUP.Ask.TODOCompanyname.Installer (M), PUP.Ask.Toolbar (M), PUP.Ask.APN.Installer (M)
100.00%

Dr.Web
Win32.Expiro.80, Adware.Downware.1417, Trojan.Crossrider.27621, Trojan.DownLoader7.16675, Adware.Downware.1661
32.00%

ESET NOD32
Win32/Bundled.Toolbar.Ask.G potentially unsafe application, Win32/Expiro.AY virus, Win32/Bundled.Toolbar.Ask potentially unsafe application
26.00%

Antiy Labs AVL
Virus/Win32.Expiro.nr, Trojan/Win32.Autoit
26.00%

AVG
Win32/Expiro, Generic
26.00%

NANO AntiVirus
Virus.Win32.Expiro.clnvwd, Trojan.Win32.Generic.deinoc, Trojan.Win32.Downware.crduvi
22.00%

Trend Micro House Call
PE_EXPIRO.AR, TROJ_GEN.F47V0824, Suspicious_GEN.F47V1024
22.00%

Avira AntiVirus
TR/Trash.Gen, TR/Patched.Gen
20.00%

F-Prot
W32/Expiro.BG, W32/Patched.Y.gen
20.00%

AegisLab AV Signature
W32.Expiro, AdWare.W32.Sushi
20.00%

1 / 68      (PUP)
saupdate.exe  (facaa463194634016ad061f2e693660d)

1 / 68      (PUP)
precache.exe  (87c17974b32563eb37d0d395100c5072)

38 / 68    (PUP)
Updater.exe (Updater by Ask)  (d0936b060c87cd945431a54bf3985af9)

1 / 68      (PUP)
searchresultstoolbar.new2.exe (Search Results Toolbar)  (0762cf4e98745650364956d6d73f3fb8)

1 / 68      (PUP)
tmp00000095419644b67337d6f0  (ce37cbf6e193c054c163628405150418)

38 / 68    (PUP)
Updater.exe (Updater by Ask)  (45c8e611c40af695669544f776d547d4)

1 / 68      (PUP)

1 / 68      (PUP)
wrapper.exe (Ask Toolbar by Ask)  (6c92805b1c99797d2b6f6886867aea41)

1 / 68      (PUP)

1 / 68      (PUP)
taskscheduler.exe  (24d543424fbe6802ef9d2e6a41314f6c)

13 / 68    (PUP)
atstpip.exe (Offercast - APN Install Manager by Ask.com)  (e1173079885d13d3a78111038c33d34f)

1 / 68      (PUP)

1 / 68      (PUP)
tmp0000000362f14255f4dd186f  (73e99568ea46da60d2f1d337272ebcae)

8 / 68      (PUP)
setup.exe (Ask Toolbar by Ask)  (0e2a39f6427edfad6dbfedc0bed2fc3b)

38 / 68    (PUP)
Updater.exe (Updater by Ask)  (183dd00f1e062bd08616f0052b3d3b29)

38 / 68    (PUP)
Updater.exe (Updater by Ask)  (183dd00f1e062bd08616f0052b3d3b29)

1 / 68      (PUP)
tmp000000055f115c61eecaa090  (e10bd34e82afeef127ed6f13cb0f740f)

1 / 68      (PUP)

1 / 68      (PUP)
taskscheduler.exe  (6f24803ea9ea0e743707421b474d254c)

38 / 68    (PUP)
Updater.exe (Updater by Ask)  (1acba585d47fb69c12f26074517efe5a)

1 / 68      (PUP)
taskscheduler.exe  (7e6ba54dce41c7fdbb901497ca3ebc00)

1 / 68      (PUP)

1 / 68      (PUP)
updatetask.exe  (71e54aee60f7a7a1ed9e16232f2ead4d)

1 / 68      (PUP)

1 / 68      (PUP)
precache.exe  (2365fcf094c3f5ac0ffef66d87c97193)

1 / 68      (PUP)
new6482.tmp.exe (Ask Toolbar by Ask.com)  (093e29e726d3f30f65325cc3a8a3cb0f)

1 / 68      (PUP)

1 / 68      (PUP)
513047b.msi  (11ea4da7410b0e0b0aa0cdc2f6ce0e59)

10 / 68    (PUP)
apntoolbarinstaller.exe (Ask Toolbar by Ask)  (5a435164bb415762cc3a69e80e53f5ea)

6 / 68      (PUP)
apnstub.exe (AskStub Application by Ask.com)  (90a2530ad5b7af2973ab43d66f39134a)

 
Latest 30 of 969 files

Downloads URLs for files signed by Ask.com.

1 / 68      (PUP)

The certificates below are also signed by Ask.com.

071C9C2CC792BCB19C804C3655D4DE1F  (Jun 02, 2014 to Aug 01, 2016)

10B9E2525844B965BFD1932E5265E605  (Sep 07, 2015 to Jul 31, 2016)

0E92120309E5E292CD4FFE132C48D3D8  (Jan 23, 2014 to Jun 19, 2014)

286F8A30E2EAC6965B936F826A05305D  (Jun 17, 2008 to Jun 18, 2011)

00A14100010020D9D7891D7DD5115F  (Jul 13, 2006 to Jul 13, 2008)

The following publishers (by Authenticode signature organization name) are related.

Remove Ask.com Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Ask.com by VeriSign, Inc. on June 20, 2011 with the serial number '0965f2ac7236c7e1bdca44ed139b273a'.