ocdll.dll

Offercast - APN Install Manager

ask.com

This installer is part of the Ask.com (APN) network which will install the Ask.com branded toolbar or browser extension which will take control of the web browser's search functions. The module ocdll.dll by ask.com has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Offercast APN Install Manager installer. It is also typically executed from the user's temporary directory.
Publisher:
ask.com  (signed and verified)

Product:
Offercast - APN Install Manager

Version:
3.13.0.19884

MD5:
4d91444f13521ea42e0f4e7cd4c38eac

SHA-1:
bc2cf95a94818fb32398f32ac49488ddf954a3a5

SHA-256:
1ff0dbfb46b12973029405b42ab8999f1eb72181b794d8cecdfee9041cd42603

Scanner detections:
1 / 68

Status:
Adware

Explanation:
This is the APN Offercast install manager which will offer the user to opt-out of installing the Ask.com Toolbar as part of the setup routine.

Analysis date:
11/4/2024 5:13:39 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Ask (M)
16.12.14.8

File size:
1.2 MB (1,306,039 bytes)

Product version:
3.13.0.19884

Copyright:
2010 (c) Ask.com. All rights reserved.

Original file name:
AskInstaller.dll

File type:
Dynamic link library (Win32 DLL)

Installer:
Offercast APN Install Manager

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ocdll.dll

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
7/12/2016 5:00:00 PM

Valid to:
9/11/2019 4:59:59 PM

Subject:
CN=ask.com, O=ask.com, L=Oakland, S=California, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
1C1D236C74BFAA30055CD178EE0CD663

File PE Metadata
Compilation timestamp:
7/20/2016 3:29:01 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0xBF31F

Entry point:
E9, AE, D8, FB, FF, 0C, 01, 75, 05, E8, F5, CC, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 20, 57, 11, 10, E8, 72, 10, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, A4, DE, 11, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, E0, 7C, 0E, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.7446

Packer / compiler:
Mew, 0x11 SE v1.2

Code size:
917.5 KB (939,520 bytes)

Remove ocdll.dll - Powered by Reason Core Security