Updater.exe

Updater

Ask.com

This is a component of the Ask.com toolbar, a browser extension that will modify the default web browser's search provider, home page and various other settings. The application Updater.exe by Ask.com has been detected as a potentially unwanted program by 2 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ApnUpdater’. Additionally, the file is typically installed by a number of programs including Ask Toolbar by Ask.com and KMPlayer Toolbar by Ask.com, both potentially unwanted software.
Publisher:
Ask  (signed by Ask.com)

Product:
Updater

Description:
Ask Updater

Version:
1.4.467612

MD5:
b33be1ccbc5c9fe20c639c734454b211

SHA-1:
42ca3c478c8f3b7a091c8f4050c16f8acd20f251

SHA-256:
169bd85f829f82e2d017bea8c64d125b663cc6b08c739271472ec5edd1fd5a09

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 4:41:56 AM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.Startup.Ask.H
188838

Reason Heuristics
PUP.Startup.Ask.H
14.8.8.2

File size:
1.6 MB (1,648,048 bytes)

Product version:
1.4.467612

Copyright:
(c) Ask. All rights reserved.

Original file name:
Updater.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\ask.com\updater\updater.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/20/2011 3:00:00 AM

Valid to:
6/19/2014 2:59:59 AM

Subject:
CN=Ask.com, OU=Distribution, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Ask.com, L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0965F2AC7236C7E1BDCA44ED139B273A

File PE Metadata
Compilation timestamp:
12/24/2013 1:38:26 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:PAHfOikOB3YgpvHnJZNl9CK6MXLvqxfFWhEsd2uY:wf55YEfn74XKexNSEzuY

Entry address:
0xAF391

Entry point:
E8, F3, DA, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A4, 01, 00, 00, 81, F9, 00, 01, 00, 00, 72, 1F, 83, 3D, C0, D7, 4F, 00, 00, 74, 16, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 08, 5E, 5F, 5D, E9, BE, 82, 00, 00, F7, C7, 03, 00, 00, 00, 75, 15, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 2A, F3, A5, FF, 24, 95, 14, F5, 4A, 00, 90, 8B, C7, BA, 03, 00, 00, 00, 83, E9, 04, 72, 0C, 83...
 
[+]

Entropy:
6.1057

Code size:
817 KB (836,608 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ApnUpdater

Command:
"C:\Program Files\ask.com\updater\updater.exe"


The file Updater.exe has been discovered within the following programs.

Ask Toolbar  by Ask.com
The Ask Toolbar is a web-browser add-on that can appear as an extra bar added to the browser's window and/or menu. It is often installed (sometimes without warning) during the installation of other software. Ask.
help.ask.com/link/portal/30015/30018/Article/1/How-do-I-remove-the-Ask-com-Toolbar
81% remove it
Ask Toolbar Updater  by Ask.com
The Ask Toolbar Updater is designed to periodically (once a day) check for an install updates to the toolbar without the interaction of the user. The Ask Toolbar and other applications are increasingly being bundled with programs; most notably freeware.
75% remove it
aTube Toolbar  by Ask.com
aTube Toolbar is a web browser extension and Browser helper Object (for Internet Explorer) that delivers contextual based advertising to the web browser. In addition it will modify the user's browser home and search pages as well as 'New Tab' pages to push advertising and search.
66% remove it
Avery Toolbar  by Ask.com
Avery Toolbar , powered by ASK, is a web-browser add-on that can appear as an extra bar added to the browser's window and/or menu. It is often installed (sometimes without warning) during the installation of other software.
sp.ask.com/toolbar
82% remove it
CutePDF Editor Toolbar, powered by ASK, is a web-browser add-on that can appear as an extra bar added to the browser's window and/or menu. It is often installed (sometimes without warning) during the installation of other software.
78% remove it
This toolbar is typiclaly bundled with the installation of the free Foxit PDF Creator software. Foxit PDF Creator Toolbar is a software utility that installs with the Ask.com internet browser toolbar and keeps it automatically updated.
66% remove it
Foxit Toolbar  by Ask.com
Foxit Toolbar gets installed through bundled software. The default settings will automatically install the Foxit Toolbar as soon as you install the host bundler software on your PC.
67% remove it
KMPlayer Toolbar  by Ask.com
This toolbar is typiclaly bundled with the installation of the free KMPlayer software. KMPlayer Toolbar gets installed through bundled software. The default settings will automatically install the KMPlayer Toolbar as soon as you install the host bundler software on your PC.
www.kmpmedia.net
74% remove it
Sopcast Ask Toolbar  by Ask.com
Sopcast Ask Toolbar, powered by ASK, is a web-browser add-on that can appear as an extra bar added to the browser's window and/or menu. It is often installed (sometimes without warning) during the installation of other software.
75% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to a23-79-107-244.deploy.static.akamaitechnologies.com  (23.79.107.244:80)

TCP (HTTP):

TCP (HTTP):
Connects to a104-67-44-116.deploy.static.akamaitechnologies.com  (104.67.44.116:80)

TCP (HTTP):
Connects to a104-103-105-67.deploy.static.akamaitechnologies.com  (104.103.105.67:80)

TCP (HTTP):
Connects to a184-27-23-218.deploy.static.akamaitechnologies.com  (184.27.23.218:80)

TCP (HTTP):
Connects to a104-122-215-222.deploy.static.akamaitechnologies.com  (104.122.215.222:80)

TCP (HTTP):
Connects to a88-221-100-112.deploy.akamaitechnologies.com  (88.221.100.112:80)

TCP (HTTP):
Connects to a23-66-151-219.deploy.static.akamaitechnologies.com  (23.66.151.219:80)

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):
Connects to a104-93-100-248.deploy.static.akamaitechnologies.com  (104.93.100.248:80)

TCP (HTTP):
Connects to a104-88-195-199.deploy.static.akamaitechnologies.com  (104.88.195.199:80)

TCP (HTTP):

TCP (HTTP):
Connects to a96-16-199-226.deploy.akamaitechnologies.com  (96.16.199.226:80)

TCP (HTTP):
Connects to a23-57-200-172.deploy.static.akamaitechnologies.com  (23.57.200.172:80)

TCP (HTTP):
Connects to a23-48-113-147.deploy.static.akamaitechnologies.com  (23.48.113.147:80)

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

Remove Updater.exe - Powered by Reason Core Security