idcsrv_x64.dll

IdcSrv

APN LLC

This is a component of the Ask.com toolbar, a browser extension that will modify the default web browser's search provider, home page and various other settings. The module idcsrv_x64.dll by APN has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. Additionally, the file is typically installed by a number of programs including Search App by Ask by APN, LLC and AVG Search App powered by Ask by APN, LLC, both potentially unwanted software.
Publisher:
APN  (signed by APN LLC)

Product:
IdcSrv

Description:
IDC Server

Version:
31.19.1.2516

MD5:
ab4a62655520bb9d1da87aad0ca35291

SHA-1:
1b5d95e997548e75e57b5f74f584aa67f8180cc7

SHA-256:
113d8e5b0080a26501bf4bdbde09c14804db33a50b62953da796da33ec8aa0ef

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 12:18:32 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Ask (M)
17.3.15.16

File size:
547.9 KB (561,032 bytes)

Product version:
31.19.1.2516

Copyright:
(c) APN LLC. All rights reserved.

Original file name:
IdcSrv.dll

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\Program Files\askpartnernetwork\toolbar\real1-sp\source\Program Files\askpartnernetwork\toolbar\updater\idc\idcsrv_x64.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/26/2015 2:00:00 AM

Valid to:
5/28/2018 1:59:59 AM

Subject:
CN=APN LLC, O=APN LLC, L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
74BAC30967391B08242D79F7F79449E2

File PE Metadata
Compilation timestamp:
4/21/2015 12:25:57 AM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x566EC

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, 6B, 7C, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, 03, 00, 00, 00, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 20, 4C, 89, 40, 18, 89, 50, 10, 48, 89, 48, 08, 56, 57, 41, 56, 48, 83, EC, 50, 49, 8B, F0, 8B, DA, 4C, 8B, F1, BA, 01, 00, 00, 00, 89, 50, B8, 85, DB, 75, 0F, 39, 1D, 88, CB, 02, 00, 75, 07, 33, C0, E9, D2, 00, 00, 00, 8D, 43, FF...
 
[+]

Entropy:
6.4406

Code size:
415.5 KB (425,472 bytes)

The file idcsrv_x64.dll has been discovered within the following programs.

Ask Shopping Toolbar  by APN LLC
This is an Ask.com ad-injection toolbar that is bundled with various 3rd-party programs and installers. From the site: "The enhanced shopping search experience includes rich content, a variety of product listings, and visual product search results.
help.ask.com/link/portal/30015/30018/Article/227/What-features-does-the-Shopping-Toolbar-by-Ask-offer
79% remove it
Ask Toolbar  by APN LLC
The Ask Toolbar is a web browser extension and toolbar that delivers contextual based advertising as well as modify the user's web browser home and search pages to provide advertising and search.
apn.ask.com
74% remove it
62% remove it
Avira SearchFree Toolbar  by Avira GmbH
The Avira SearchFree Toolbar is a web browser toolbar and extension that modifies the browsers search and home pages as well as delivers contextual based advertising. This toolbar currently supports Internet Explorer, Firefox and Chrome.
www.avira.com/en/avira-searchfree-toolbar
76% remove it
69% remove it
ooVoo Search App is an advertising-supported web browser toolbar that may modify the browser's home page, search provider and new tab pages.
www.apn.ask.com/products/toolbars
88% remove it
Search App by Ask  by APN, LLC
Publisher's description - “Quixey and Ask have entered into a deal in which apps from Quixey’s database, whether for mobile or the PC, will be integrated into search results. It’s going live today and should be rolling out now, although it’s not yet live for me.”
84% remove it
Shopping App by Ask  by APN, LLC
Publisher's description - “The Shopping Toolbar by Ask has the single purpose of enhancing a user’s online shopping experience by offering an enhanced shopping search experience, links to popular shopping sites and/or additional content such as coupons, special offers and the latest deals from many merchants.”
79% remove it
 
Powered by Should I Remove It?

Remove idcsrv_x64.dll - Powered by Reason Core Security