ocdll.dll

Offercast - APN Install Manager

ask.com

This installer is part of the Ask.com (APN) network which will install the Ask.com branded toolbar or browser extension which will take control of the web browser's search functions. The module ocdll.dll by ask.com has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Offercast APN Install Manager installer. It is also typically executed from the user's temporary directory.
Publisher:
ask.com  (signed and verified)

Product:
Offercast - APN Install Manager

Version:
3.13.0.19884

MD5:
d1f7f1b5a936c560efff958257b05506

SHA-1:
5d0369324b82fd86869cccb80fcb7f2dde4f688b

SHA-256:
88fbb14d5537c3daea9475155732ae6146e108b18205d9a443f04ce2ab02a65e

Scanner detections:
1 / 68

Status:
Adware

Explanation:
This is the APN Offercast install manager which will offer the user to opt-out of installing the Ask.com Toolbar as part of the setup routine.

Analysis date:
12/24/2024 12:21:45 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Ask (M)
17.1.31.5

File size:
1.2 MB (1,249,264 bytes)

Product version:
3.13.0.19884

Copyright:
2010 (c) Ask.com. All rights reserved.

Original file name:
AskInstaller.dll

File type:
Dynamic link library (Win32 DLL)

Installer:
Offercast APN Install Manager

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ocdll.dll

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
7/12/2016 9:00:00 PM

Valid to:
9/11/2019 8:59:59 PM

Subject:
CN=ask.com, O=ask.com, L=Oakland, S=California, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
1C1D236C74BFAA30055CD178EE0CD663

File PE Metadata
Compilation timestamp:
8/11/2016 8:46:39 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0xBF31F

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, F5, CC, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 20, 57, 11, 10, E8, 72, 10, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, A4, DE, 11, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, E0, 7C, 0E, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
917.5 KB (939,520 bytes)

Remove ocdll.dll - Powered by Reason Core Security