RocketBrowser is a software usually installed without your knowledge with the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
Identified : 10/03/2015.

0_Features

– It belongs to a family of PUP (Potentially Unwanted Program).
– A polluteware is a software that pollutes storage and/or the Base of registers.
– An Adware is a program that adds other programs without the knowledge of the user.
– Vendor : PUP.Optional

0_Main_Actions

– It installs as a process launched at startup of the system (RP),
– It settled in the Base of registers to be launched each time with the system (O4),
– It Place multiple shortcuts application, Desktop, QuickLaunch, Taskbar (O4GS),
– It installs as a service to be launched each time the system (O23),(SS/SR),
– It installs as a program (O42),
– It creates to many registry keys ‘Software’,
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45),
– It creates multiple files users (O61),
– It changes the execution of a “ShellOpenCommand” Registry (O67)
– It modifies the startup of browsers Mozilla Firefox and Internet Explorer (O68),
– It creates an active incoming connection in the application of the firewall Windows exceptions (O87),
– It creates registry keys Tracing (O100),
– It creates keys from registry CLSID (O101),

0_Zhpdiag

[MD5.C13910A7D61DE275B129098869D1293D] – (The RocketBrowser Authors – RocketBrowser) — C:\Users\Coolman\AppData\Local\RocketUpdate.exe [364032] [PID.2311] [MD5.1B5A14A0FD16F0C369EDAE0A79C0951F] – (…) — C:\Users\Coolman\AppData\Local\RocketUpdate.exe [364038] [PID.2452] O4 – GS\Quicklaunch [Coolman]: Launch Internet Explorer Browser.lnk . (.The RocketBrowser Authors – RocketBrowser.) C:\Users\Coolman\AppData\Local\RocketBrowser\Application\Rocketbrowser.exe
O4 – GS\Quicklaunch [Coolman]: RocketBrowser.lnk . (.The RocketBrowser Authors – RocketBrowser.) C:\Users\Coolman\AppData\Local\RocketBrowser\Application\Rocketbrowser.exe
O23 – Service: RocketBrowserUpdateService (RocketBrowserUpdateService) . (…) – C:\Users\Coolman\AppData\Local\RocketUpdate.exe
O42 – Logiciel: RocketBrowser – (.RocketBrowser.) [HKCU] — RocketBrowser
HKCU\SOFTWARE\Rocket Browser
O43 – CFD: 10/07/2014 – [] D — C:\Users\Coolman\AppData\Local\Rocket
O43 – CFD: 04/07/2015 – 14:06:32 – [] D — C:\Users\rodolphe8866\AppData\Local\RocketBrowser
O43 – CFD: 23/06/2015 – 03:13:09 – [] —-D C:\Users\Coolman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RocketBrowser
HKLM\SYSTEM\CurrentControlSet\Services\RocketBrowserUpdateService
SR – | Auto 16/06/2015 364032 | (RocketBrowserUpdateService) . (…) – C:\Users\Coolman\AppData\Local\RocketUpdate.exe
O61 – LFC: 2015/06/30 14:23:48 A . (..) — C:\Users\rodolphe8866\AppData\Local\RocketUpdate.exe [364032] O67 – Shell Spawning: [HKCU\..\open\Command] (…) — C:\Users\Coolman\AppData\Local\RocketBrowser\Application\RocketBrowser.exe
O68 – StartMenuInternet: [HKLM\..\Shell\open\Command] (…) — C:\Users\Coolman\AppData\Local\Rocket\Application\rocket.exe
O68 – StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (…) — C:\Users\Coolman\AppData\Local\Rocket\Application\rocket.exe
O68 – StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (…) — C:\Users\Coolman\AppData\Local\Rocket\Application\rocket.exe
O68 – StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (…) — C:\Users\Coolman\AppData\Local\Rocket\Application\rocket.exe
O87 – FAEL: “{E2E2A785-4FBB-4279-BB28-61628ABBB616}” [In-None-P17-TRUE] .(.The RocketBrowser Authors – RocketBrowser.) — C:\Users\Coolman\AppData\Local\RocketBrowser\Application\Rocketbrowser.exe
C:\Users\Coolman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RocketBrowser
C:\Users\Coolman\AppData\Local\RocketBrowser
C:\Users\Coolman\AppData\Local\Rocket
C:\Users\Coolman\AppData\Local\Rocket\Application\rocket.exe
C:\Users\Coolman\AppData\Local\RocketUpdate.exe

0_Alias

PUP.Optional.RocketBrowser.A [ Malwarebytes Antimalware ] Adware.Boxore

Remove_Software

– Remove software in Windows Configuration Panel,
0_ZHPcleaner
Remove with ZHPcleaner
ZHPCleaner_EN2
0_Zhpdiag
Diagnose with ZHPDiag
ZHPDiag_2-300x220

2016-12-30T07:34:16+00:00 Categories: Adware, Polluteware, PUP|Tags: , , |Comments Off on PUP.Optional.RocketBrowser