Updater.exe

Updater

Ask.com

This is a component of the Ask.com toolbar, a browser extension that will modify the default web browser's search provider, home page and various other settings. The application Updater.exe by Ask.com has been detected as a potentially unwanted program by 2 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ApnUpdater’. Additionally, the file is typically installed by a number of programs including Avery Toolbar Updater by Ask.com and atualizador Ask Toolbar Updater by Ask.com, both potentially unwanted software.
Publisher:
Ask  (signed by Ask.com)

Product:
Updater

Description:
Ask Updater

Version:
5.15.4.23821

MD5:
1ca034e7feb38fb4f3484aec092c403f

SHA-1:
e9dd40de742d6dda879435e9dd0284a3d69f6ba1

SHA-256:
8d76e5ab31b4f3e12054f7ef1df9fc553e708f1126af5e6a5ca6433393cd40d3

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/30/2024 8:16:32 AM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.Startup.Ask.H
188838

Reason Heuristics
PUP.Startup.Ask.H
14.8.8.2

File size:
1.5 MB (1,564,872 bytes)

Product version:
5.15.4.23821

Copyright:
(c) Ask. All rights reserved.

Original file name:
Updater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ask.com\updater\updater.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/19/2011 5:00:00 PM

Valid to:
6/18/2014 4:59:59 PM

Subject:
CN=Ask.com, OU=Distribution, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Ask.com, L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0965F2AC7236C7E1BDCA44ED139B273A

File PE Metadata
Compilation timestamp:
6/6/2012 9:33:06 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:1wkTC6wQyT5/j5P4hHTepFiZiIR16OdL5OdUx:9TyT5/j949MFiZi41PL5J

Entry address:
0xA0FF7

Entry point:
E8, FD, D4, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A4, 01, 00, 00, 81, F9, 00, 01, 00, 00, 72, 1F, 83, 3D, 80, 86, 4E, 00, 00, 74, 16, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 08, 5E, 5F, 5D, E9, E6, 76, 00, 00, F7, C7, 03, 00, 00, 00, 75, 15, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 2A, F3, A5, FF, 24, 95, 84, 11, 4A, 00, 90, 8B, C7, BA...
 
[+]

Entropy:
6.0820

Code size:
753.5 KB (771,584 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ApnUpdater

Command:
"C:\Program Files\ask.com\updater\updater.exe"


The file Updater.exe has been discovered within the following programs.

The Ask Toolbar is a web-browser add-on that can appear as an extra bar added to the browser's window and/or menu. It is often installed (sometimes without warning) during the installation of other software. Ask.
sp.ask.com/toolbar
84% remove it
Ask Toolbar Updater  by Ask.com
The Ask Toolbar Updater is designed to periodically (once a day) check for an install updates to the toolbar without the interaction of the user. The Ask Toolbar and other applications are increasingly being bundled with programs; most notably freeware.
help.ask.com/link/portal/30015/30018/Article/1/How-do-I-remove-the-Ask-com-Toolbar
75% remove it
The Ask Toolbar and other applications are increasingly being bundled with programs; most notably freeware. It's usually installed during the installation of a program, and it's easy to miss the step where you can uncheck the Ask Toolbar option.
69% remove it
aTube Toolbar Updater  by Ask.com
aTube Toolbar Updater gets installed through bundled software. The default settings will automatically install the Auslogics Toolbar as soon as you install the host bundler software on your PC.
66% remove it
Auslogics Toolbar Updater gets installed through bundled software. The default settings will automatically install the Auslogics Toolbar as soon as you install the host bundler software on your PC.
87% remove it
Avery Toolbar Updater  by Ask.com
Avery Toolbar Updater gets installed through bundled software. The default settings will automatically install the Avery Toolbar as soon as you install the host bundler software on your PC.
85% remove it
CutePDF Editor Toolbar Updater is a software utility that installs with the Ask.com internet browser toolbar and keeps it automatically updated.
83% remove it
Foxit PDF Creator Updater installs with the Ask.com internet browser toolbar and keeps it automatically updated. Avira SearchFree Toolbar gets installed through bundled software.
73% remove it
KMPlayer Toolbar Updater is a software utility that installs with the Ask.com internet browser toolbar and keeps it automatically updated. KMPlayer Toolbar gets installed through bundled software.
80% remove it
MP3 Rocket Toolbar Updater installs with the Ask.com internet browser toolbar and keeps it automatically updated. The Toolbar gets installed through bundled software.
82% remove it
 
Latest 20 of 20 programs
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to a184-24-30-103.deploy.static.akamaitechnologies.com  (184.24.30.103:80)

TCP (HTTP):

TCP (HTTP):
Connects to a104-68-194-223.deploy.static.akamaitechnologies.com  (104.68.194.223:80)

TCP (HTTP):
Connects to a88-221-100-112.deploy.akamaitechnologies.com  (88.221.100.112:80)

TCP (HTTP):
Connects to a23-59-120-107.deploy.static.akamaitechnologies.com  (23.59.120.107:80)

TCP (HTTP):

TCP (HTTP):
Connects to a104-67-44-116.deploy.static.akamaitechnologies.com  (104.67.44.116:80)

TCP (HTTP):

TCP (HTTP):
Connects to a104-81-117-29.deploy.static.akamaitechnologies.com  (104.81.117.29:80)

TCP (HTTP):
Connects to a184-85-78-163.deploy.static.akamaitechnologies.com  (184.85.78.163:80)

TCP (HTTP):
Connects to a23-46-138-174.deploy.static.akamaitechnologies.com  (23.46.138.174:80)

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):
Connects to a104-123-200-93.deploy.static.akamaitechnologies.com  (104.123.200.93:80)

TCP (HTTP):

TCP (HTTP):
Connects to a184-50-215-34.deploy.static.akamaitechnologies.com  (184.50.215.34:80)

TCP (HTTP):

TCP (HTTP):
Connects to a104-122-229-56.deploy.static.akamaitechnologies.com  (104.122.229.56:80)

TCP (HTTP):
Connects to a104-105-218-249.deploy.static.akamaitechnologies.com  (104.105.218.249:80)

TCP (HTTP):

Remove Updater.exe - Powered by Reason Core Security