Adware

SigAdware.Ask.com removal instruction

Malware Removal

The SigAdware.Ask.com is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What SigAdware.Ask.com virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
apnmedia.ask.com
ocsp.verisign.com
crl.verisign.com
csc3-2010-crl.verisign.com
websearch.ask.com
img.apnanalytics.com
phn.apnanalytics.com
anx.apnanalytics.com
tbapi.search.ask.com

How to determine SigAdware.Ask.com?


File Info:

crc32: F43F7B34
md5: b9010329b2f4134cc29ecdb4ba57025f
name: CuteWriter.exe
sha1: 91ec186153fb33a4562204e4be5631168c2ba206
sha256: 7ff0d1d856b0747bf87e78fdb5bd571f1baa49fd2795714e73d7d565b5340db5
sha512: 834a9d3b3c36082518226fde0576d3f7f05be753dbde320ebc38201a1ac1d2fca8654c1a69b7f9ee2df96ca037980d5a1b04ad84a8dbb21bba4602664ae3dba9
ssdeep: 98304:P1aovjE5he149vK9Ijcne3nYIonKLDPPulq3J9Zyy+RUwrF:9amYrtjcne3Y9GDPmAJ2O
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 2.8.0.8
CompanyName: Acro Software Inc.
Comments:
ProductName: CutePDF Writer
ProductVersion: 2.8.0.8
FileDescription: CutePDF Writer Setup
Translation: 0x0000 0x04b0

SigAdware.Ask.com also known as:

CylanceUnsafe
Kasperskynot-a-virus:WebToolbar.Win32.Asparnet.dnq
ComodoApplicUnwnt@#1ef15iuvwka65
EmsisoftApplication.Toolbar (A)
JiangminWebToolbar.Asparnet.ei
Antiy-AVLRiskWare[Toolbar]/Win32.Bundled.ask
MicrosoftPUA:Win32/Vigua.A
VBA32SigAdware.Ask.com
ESET-NOD32a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe
YandexPUA.Toolbar.Ask!
FortinetRiskware/Asparnet
MaxSecureTrojan.Malware.12180268.susgen

How to remove SigAdware.Ask.com?

SigAdware.Ask.com removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment