How to remove 4z_ask.exe
4z_ask.exe
The module 4z_ask.exe has been detected as Adware.ELEX
File Details
Product Name: | Offercast - APN Install Manager |
Company Name: | Ask.com |
MD5: | f3eb31f6051ea6f7bc6ecb3028940216 |
Size: | 1 MB |
First Published: | 2017-05-28 14:06:43 (7 years ago) |
Latest Published: | 2020-06-15 15:23:44 (4 years ago) |
Status: | Adware.ELEX (on last analysis) | |
Analysis Date: | 2020-06-15 15:23:44 (4 years ago) |
Overview
Signed By: | Taiwan Shui Mu Chih Ching Technology Limited |
Status: | Valid |
Common Places:
%localappdata%\temp{671bcfb8-da91-4e40-8f21-4e450ea60ff9}\omigazip_patch |
%localappdata%\temp{02067b7d-4349-42e7-afc9-7b0c1e789077}\omigazip_patch |
%localappdata%\temp{c77b7737-b737-43af-85b0-c6070dfbb73f}\omigazip_patch |
%localappdata%\temp{bf60d214-b25c-4321-af52-8f5e71489622}\omigazip_patch |
%localappdata%\temp{dffc802c-a421-48d1-a2d3-a3bf8295c2b3}\omigazip_patch |
%localappdata%\temp{60927398-ec35-43b0-82f1-2536aba4f2ba} |
%temp%\{7afe46a0-dd59-46c9-802f-6bfaf0c05795}\{5b6bbcd1-0163-4e6a-bc86-dd37a1a3f0cc} |
%temp%\{877708ae-3364-4760-9f9e-0cefe5d78c7a}\{e0f5a814-ac13-4ae1-a630-3d60d0a0a33b} |
%temp%\{e4f98226-440c-4ee9-95a5-f5c645a1692c}\{03c7817c-3648-4bdd-b03b-938d7b0179e2} |
%temp%\{30fdee37-1949-4917-8d38-6eeaa86eff68}\{b7829c5a-b099-40e2-8c30-72d4299697e8} |
Geography:
42.9% | ||
14.3% | ||
9.5% | ||
9.5% | ||
9.5% | ||
4.8% | ||
4.8% | ||
4.8% |
OS Version:
Windows 7 | 63.6% | |
Windows 8.1 | 18.2% | |
Windows 10 | 9.1% | |
Windows 8 | 4.5% | |
Windows XP | 4.5% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x00079eb4 |
PE Sections:
Name | Size of data | MD5 |
.text | 639488 | 059aa2302068cf62d73ba51770723784 |
.rdata | 143872 | 764d331ba040a2ab7b3455f15dbbb0c6 |
.data | 22528 | c9e04799a6659650d211036f8d7327c0 |
.rsrc | 210432 | f4b713f2f6bb83a0630535dacd1bf398 |
.reloc | 49664 | e9f398e5e167c245e7d374c43ac920bd |
More information:
Download GridinSoft
Anti-Malware - Removal tool for 4z_ask.exe