ocdll.dll

Offercast - APN Install Manager

ask.com

This installer is part of the Ask.com (APN) network which will install the Ask.com branded toolbar or browser extension which will take control of the web browser's search functions. The module ocdll.dll by ask.com has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Offercast APN Install Manager installer. It is also typically executed from the user's temporary directory.
Publisher:
ask.com  (signed and verified)

Product:
Offercast - APN Install Manager

Version:
3.13.0.19884

MD5:
5fdece279ade5c94be352ed819092bb5

SHA-1:
d1ceb0f8fca15daa794d8829108e4f9d81535bd4

SHA-256:
88fbb14d5537c3daea9475155732ae6146e108b18205d9a443f04ce2ab02a65e

Scanner detections:
1 / 68

Status:
Adware

Explanation:
This is the APN Offercast install manager which will offer the user to opt-out of installing the Ask.com Toolbar as part of the setup routine.

Analysis date:
12/24/2024 12:03:19 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Ask (M)
16.9.5.2

File size:
1.2 MB (1,249,264 bytes)

Product version:
3.13.0.19884

Copyright:
2010 (c) Ask.com. All rights reserved.

Original file name:
AskInstaller.dll

File type:
Dynamic link library (Win32 DLL)

Installer:
Offercast APN Install Manager

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ocdll.dll

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
7/12/2016 7:00:00 PM

Valid to:
9/11/2019 6:59:59 PM

Subject:
CN=ask.com, O=ask.com, L=Oakland, S=California, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
1C1D236C74BFAA30055CD178EE0CD663

File PE Metadata
Compilation timestamp:
8/11/2016 6:46:39 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:SHRGJpApaswszcPBDDMMvgm3tdcV/24hpWS5x5AdiupaRpIo8T+rWM2kRd:iMHrTPBjj4SS5PAZpafN8TQWM2kRd

Entry address:
0xBF31F

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, F5, CC, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 20, 57, 11, 10, E8, 72, 10, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, A4, DE, 11, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, E0, 7C, 0E, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
917.5 KB (939,520 bytes)

Remove ocdll.dll - Powered by Reason Core Security