BrowserSafeguard with RocketTab

BrowserSafeguard with RocketTab

Known Toolbar

by Adknowledge, Inc.

What is BrowserSafeguard with RocketTab?

BrowserSafeguard with RocketTab is software application developed by Adknowledge, Inc.. It is most commonly found on computers running Windows 7 with nearly 60.37% of installations running this operating system. BrowserSafeguard with RocketTab's installer is typically 5.00 MB in size and installs around 6 files.

BrowserSafeguard with RocketTab is most popular in the United States with 88.49% of installations residing in this country.

BrowserSafeguard with RocketTab adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About BrowserSafeguard with RocketTab?

BrowserSafeguard is a software distributed through OptimumInstaller / InstallIQ, a pay-per-install download bundler from the company. It is ad-supported and offers various additional software, such as toolbars and extensions, through Adknowledge's advertising network during installation. It has been flagged as malicious by several antivirus vendors. Symptoms of infection may include: - Text on web pages turning into hyperlinks - Pop-up ads with red "click here" buttons when hovering over links - Installation of unwanted adware programs without the user's knowledge - Browser popups recommending fake updates or other software - Slow web page downloads due to multiple ads.

Multiple virus scanners have detected malware in BrowserSafeguard with RocketTab.

uninstall.exe (MD5: 2d4b9d1cc2bcaf11528ebbb38d969050) has been flagged by 44 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.170753
Agnitum Outpost PUA.iBryte!
AhnLab-V3 PUP/Win32.IBryte
ALYac Gen:Variant.Adware.Graftor.170753
Antiy-AVL GrayWare[AdWare:not-a-virus]/MSIL.iBryte
Arcabit Trojan.Adware.Graftor.D29B01
avast! Win32:PUP-gen [PUP]
AVG Downloader.DDI
Avira ADWARE/iBryte.251392.2
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.MSIL.iBryte.N
Bitdefender Gen:Variant.Adware.Graftor.170753
CAT-QuickHeal AdWare.MSIL.r5 (Not a Virus)
Comodo Security ApplicUnwnt
Cyren W32/S-88b5fb50!Eldorado
Dr.Web Trojan.iBryte.301
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.170753 (B)
ESET-NOD32 a variant of MSIL/Adware.iBryte.Z
Fortinet FortiGate Adware/IBryte
F-Prot W32/S-88b5fb50!Eldorado
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.170753
IKARUS anti.virus not-a-virus:AdWare.MSIL.iBryte
Jiangmin AdWare/MSIL.bjw
K7 AntiVirus Adware ( 004b20c21 )
K7GW Adware ( 004b20c21 )
Kaspersky not-a-virus:AdWare.MSIL.iBryte.x
McAfee RDN/Generic PUP.x!cr3
McAfee-GW-Edition BehavesLike.Win32.Almanahe.dc
MicroWorld-eScan Gen:Variant.Adware.Graftor.170753
NANO AntiVirus Riskware.Win32.IBryte.dmgumw
Panda Antivirus Trj/Genetic.gen
Sophos iBryte Desktop
Symantec Trojan.Gen.2
Tencent Msil.Adware.Ibryte.Hsjb
Trend Micro TROJ_GEN.F0C2C00AI15
Vba32 AntiVirus AdWare.MSIL.iBryte
VIPRE Antivirus Trojan.Win32.Generic!BT
ViRobot Adware.Agent.251392.C[h]
Zillya Adware.iBryte.Win32.5922
Malwarebytes PUP.Optional.RocketTab.PrxySvrRST
Rising Antivirus PE:Trojan.Win32.Generic.17E9F83C!401209404
SUPERAntiSpyware Adware.iBryte/Variant
TrendMicro-HouseCall TROJ_SPNR.0BGD14
Client.exe (MD5: 31d0d8ecbf4732a510a7cc1758684504) has been flagged by 38 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Mikey.1422
Agnitum Outpost PUA.Agent!
AhnLab-V3 Adware/Win32.Mikey
ALYac Gen:Variant.Adware.Mikey.1422
Antiy-AVL Trojan/Win32.TSGeneric
Arcabit Trojan.Adware.Mikey.D58E
avast! Win32:IBryte-JU [PUP]
AVG Downloader.DCC
Avira ADWARE/iBryte.Gen4
AVware iBryte
Bitdefender Gen:Variant.Adware.Mikey.1422
Comodo Security ApplicUnwnt
Dr.Web Adware.iBryte.619
Emsisoft Anti-Malware Gen:Variant.Adware.Mikey.1422 (B)
ESET-NOD32 a variant of Win32/Adware.iBryte.CD
Fortinet FortiGate Adware/IBryte
F-Secure Gen:Variant.Adware.Mikey
G Data Gen:Variant.Adware.Mikey.1422
K7 AntiVirus Adware ( 004b32eb1 )
K7GW Adware ( 004b32eb1 )
Malwarebytes PUP.Optional.RocketTab.PrxySvrRST
McAfee Artemis!31D0D8ECBF47
McAfee-GW-Edition BehavesLike.Win32.CryptDoma.vh
MicroWorld-eScan Gen:Variant.Adware.Mikey.1422
NANO AntiVirus Riskware.Win32.IBryte.dtmxmu
Panda Antivirus Trj/CI.A
Rising Antivirus PE:Trojan.Win32.Generic.17E9F83C!401209404
Sophos Generic PUA AB (PUA)
SUPERAntiSpyware Adware.iBryte/Variant
Symantec Adware.Rockettab
Tencent Win32.Risk.Adware.Lkds
Trend Micro TROJ_GEN.R0C1C0DB115
VIPRE Antivirus iBryte
Zillya Adware.iBryte.Win32.6852
Baidu-International Adware.MSIL.iBryte.BD
IKARUS anti.virus PUA.BrowserSafeGuard
Kaspersky not-a-virus:AdWare.MSIL.RocketTab.c
TrendMicro-HouseCall TROJ_SPNR.0BGD14
BrowserSafeguard.exe (MD5: 9d21832cbdffc67c0ab91e13925e65f4) has been flagged by 47 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11056917
avast! Win32:Dropper-gen [Drp]
Bitdefender Trojan.Generic.11056917
Emsisoft Anti-Malware Trojan.Generic.11056917 (B)
F-Secure Trojan.Generic.11056917
G Data Trojan.Generic.11056917
IKARUS anti.virus Trojan.SuspectCRC
McAfee Artemis!3532E14F4B82
McAfee-GW-Edition Artemis!3532E14F4B82
MicroWorld-eScan Trojan.Generic.11056917
Norman Suspicious_Gen4.GBICJ
nProtect Trojan.Generic.11056917
Qihoo-360 Win32/Trojan.Dropper.c9f
TrendMicro-HouseCall TROJ_GEN.F47V0312
VIPRE Antivirus AdKnowledge (fs)
Comodo Security UnclassifiedMalware
Agnitum Outpost PUA.iBryte!
AhnLab-V3 PUP/Win32.IBryte
ALYac Gen:Variant.Adware.Graftor.170753
Antiy-AVL GrayWare[AdWare:not-a-virus]/MSIL.iBryte
Arcabit Trojan.Adware.Graftor.D29B01
AVG Downloader.DDI
Avira ADWARE/iBryte.251392.2
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.MSIL.iBryte.N
CAT-QuickHeal AdWare.MSIL.r5 (Not a Virus)
Cyren W32/S-88b5fb50!Eldorado
Dr.Web Trojan.iBryte.301
ESET-NOD32 a variant of MSIL/Adware.iBryte.Z
Fortinet FortiGate Adware/IBryte
F-Prot W32/S-88b5fb50!Eldorado
Jiangmin AdWare/MSIL.bjw
K7 AntiVirus Adware ( 004b20c21 )
K7GW Adware ( 004b20c21 )
Kaspersky not-a-virus:AdWare.MSIL.iBryte.x
NANO AntiVirus Riskware.Win32.IBryte.dmgumw
Panda Antivirus Trj/Genetic.gen
Sophos iBryte Desktop
Symantec Trojan.Gen.2
Tencent Msil.Adware.Ibryte.Hsjb
Trend Micro TROJ_GEN.F0C2C00AI15
Vba32 AntiVirus AdWare.MSIL.iBryte
ViRobot Adware.Agent.251392.C[h]
Zillya Adware.iBryte.Win32.5922
Malwarebytes PUP.Optional.RocketTab.PrxySvrRST
Rising Antivirus PE:Trojan.Win32.Generic.17E9F83C!401209404
SUPERAntiSpyware Adware.iBryte/Variant

Software Behaviors

Scheduled tasks:
  • uninstall.BrowserSafeguard.exe is scheduled as a task named 'BrowserSafeguard Update Task' (runs daily at 18:16:22).
  • BrowserSafeguard.exe is scheduled as a task with the class '{593E3D21-FD4B-4BE6-97AB-58D510AF1779}' (runs on registration).

Startup Entries

Startup tasks:
  • uninstall.BrowserSafeguard.exe is automatically launched at startup through a scheduled task named BrowserSafeguard Update Task.
Registry entries:
  • uninstall.BrowserSafeguard.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'BrowserSafeguard Update Task' and executes as "C:\users\user\appdata\Local\BrowserSafeguard\uninstall.BrowserSafeguard.exe" /CheckUpdate=true.
  • BrowserSafeguard.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'BrowserSafeguard' and executes as "C:\users\user\appdata\Local\BrowserSafeguard\BrowserSafeguard.exe".

Software Details

URL:
https://www.browsersafeguard.com
Support:
https://www.browsersafeguard.com/legal/terms
Installation path:
C:\Program Files\Browsersafeguard
Uninstaller:
"C:\Program Files\Browsersafeguard\uninstall.browsersafeguard.exe" /u /UserID=9b0e32e7-5561-49c9-a578-9a3ca90afc4c /SourceID=google_znes-display-us-72
Size:
5.00 MB
Language:
English

BrowserSafeguard with RocketTab Executable Details

Primary executable:
BrowserSafeguard.exe
Name:
BrowserSafeguard with RocketTab
Path:
C:\Program Files\Browsersafeguard\BrowserSafeguard.exe
MD5:
9d21832cbdffc67c0ab91e13925e65f4
SHA-1:
–
SHA-256:
–
Files installed by BrowserSafeguard with RocketTab
File Type Filename MD5
EXE
2d4b9d1cc2bcaf11528ebbb38d969050
EXE
02783f258cb37ad93452f834d8113818
EXE
Client.exe
Malware
31d0d8ecbf4732a510a7cc1758684504
EXE
e118dff41585b70576da4576e4756589
EXE
60a7d95d88ca38a9c58fe037205256d8
EXE
9d21832cbdffc67c0ab91e13925e65f4