Rockettab

Rockettab

Known Adware

by Rich River Media, LLC

What is Rockettab?

Rockettab is software application developed by Rich River Media, LLC. It is most commonly found on computers running Windows 7 with nearly 49.75% of installations running this operating system. Rockettab's installer is typically 4.00 MB in size and installs around 7 files. The most common release is 2.0 with 4.47% of all installations currently using this version.

Rockettab is most popular in the United States with 71.08% of installations residing in this country.

Rockettab adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About Rockettab?

RocketTab is a program created by Adknowledge, Inc. that includes the 'BrowserSafeguard' feature designed to protect the user's web browser from threats. It does this by creating a local proxy server, routing all Internet traffic through it, and injecting advertising into the user's web browser. This includes various ads in the HTML of displaying web pages as well as text-links, banner ads, and other ad formats. The program is distributed by Adknowledge, Inc. and is supported via text advertising.

Multiple virus scanners have detected malware in Rockettab.

uninstall.exe (MD5: 17bdbea3321f0d7c842d2a1e1ff92448) has been flagged by 47 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.iBryte.10
Agnitum Outpost PUA.iBryte
AhnLab-V3 PUP/Win32.IBryte
ALYac Gen:Variant.Adware.iBryte.10
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.iBryte
Arcabit Trojan.Adware.iBryte.10
avast! Win32:PUP-gen [PUP]
AVG Downloader
Avira ADWARE/iBryte.Gen
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.MSIL.iBryte.N
Bitdefender Gen:Variant.Adware.iBryte.10
Bkav FE HW32.Packed
CAT-QuickHeal AdWare.iBryte.g5 (Not a Virus)
Comodo Security UnclassifiedMalware
Emsisoft Anti-Malware Gen:Variant.Adware.iBryte.10
ESET-NOD32 a variant of MSIL/Adware.iBryte.N
Fortinet FortiGate Adware/IBryte
F-Secure Gen:Variant.Adware.iBryte
G Data Gen:Variant.Adware.iBryte.10
IKARUS anti.virus PUA.Downloader
Jiangmin Adware/iBryte.hjtv
K7 AntiVirus Adware
K7GW Adware ( 004b20c21 )
Kaspersky not-a-virus:AdWare.Win32.iBryte
Malwarebytes PUP.Optional.RocketTab.PrxySvrRST
McAfee PUP-FST
McAfee-GW-Edition BehavesLike.Win32.Almanahe.vc
MicroWorld-eScan Gen:Variant.Adware.iBryte.10
NANO AntiVirus Riskware.Win32.IBryte.dltiln
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.17EBA268!401318504
Sophos Generic PUA OC (PUA)
Symantec Trojan.Gen
Trend Micro TROJ_SPNR.0BAM15
TrendMicro-HouseCall TROJ_SPNR.0BAM15
Vba32 AntiVirus AdWare.iBryte
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.iBryte.Win32.6199
Cyren W32/Adware.VIAQ-6751
Dr.Web Adware.iBryte.576
SUPERAntiSpyware Adware.iBryte/Variant
ViRobot Adware.Agent.2647552[h]
F-Prot W32/S-9bc34199
nProtect Adware.Agent.PAJ
Tencent Win32.Risk.Adware.Dzuj
Client.exe (MD5: 7cee867f453c566c7ba04652ebdeb616) has been flagged by 39 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Mikey.1422
Agnitum Outpost PUA.Agent!
AhnLab-V3 Adware/Win32.Mikey
ALYac Gen:Variant.Adware.Mikey.1422
Arcabit Trojan.Adware.Mikey.D58E
avast! Win32:IBryte-JP [PUP]
AVG Downloader.DCE
Avira ADWARE/iBryte.Gen4
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.Agent.Elnx
Bitdefender Gen:Variant.Adware.Mikey.1422
CAT-QuickHeal AdWare.iBryte.g5 (Not a Virus)
Comodo Security ApplicUnwnt
Cyren W32/Adware.VIAQ-6751
Dr.Web Adware.iBryte.576
Emsisoft Anti-Malware Gen:Variant.Adware.Mikey.1422 (B)
ESET-NOD32 a variant of Win32/Adware.iBryte.CD
Fortinet FortiGate MSIL/IBryte.A
F-Secure Gen:Variant.Adware.Mikey
G Data Gen:Variant.Adware.Mikey.1422
Jiangmin Adware/iBryte.hnnn
K7 AntiVirus Adware ( 004b32eb1 )
K7GW Adware ( 004b32eb1 )
Kaspersky not-a-virus:AdWare.Win32.iBryte.jlr
Malwarebytes PUP.Optional.RocketTab.PrxySvrRST
McAfee Artemis!7CEE867F453C
McAfee-GW-Edition BehavesLike.Win32.CryptDoma.vh
MicroWorld-eScan Gen:Variant.Adware.Mikey.1422
NANO AntiVirus Riskware.Win32.IBryte.dlufjx
Panda Antivirus Generic Suspicious
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.17EC9DCE!401382862
Sophos Mal/Wintrim-A
SUPERAntiSpyware Adware.iBryte/Variant
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R000C0EAM15
VIPRE Antivirus Trojan.Win32.Generic!BT
ViRobot Adware.Agent.2647552[h]
Zillya Adware.iBryte.Win32.6303
BrowserSafeguard.exe (MD5: c9b4e288d6e7af76ef2f5d8c99047660) has been flagged by 44 scanners:
Scanner Software Result
Baidu-International Trojan.MSIL.iBryte.BF
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of MSIL/Adware.iBryte.F
TrendMicro-HouseCall Suspicious_GEN.F47V0809
Lavasoft Ad-Aware Gen:Variant.Adware.iBryte.10
Agnitum Outpost PUA.iBryte!
AhnLab-V3 PUP/Win32.IBryte
ALYac Gen:Variant.Adware.iBryte.10
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.iBryte
Arcabit Trojan.Adware.iBryte.10
avast! Win32:PUP-gen [PUP]
AVG Downloader.DCB
Avira ADWARE/iBryte.Gen
AVware Trojan.Win32.Generic!BT
Bitdefender Gen:Variant.Adware.iBryte.10
Bkav FE HW32.Packed.6237
CAT-QuickHeal AdWare.iBryte.g5 (Not a Virus)
Emsisoft Anti-Malware Gen:Variant.Adware.iBryte.10 (B)
Fortinet FortiGate Adware/IBryte
F-Secure Gen:Variant.Adware.iBryte
G Data Gen:Variant.Adware.iBryte.10
IKARUS anti.virus PUA.Downloader
Jiangmin Adware/iBryte.hjtv
K7 AntiVirus Adware ( 004b20c21 )
K7GW Adware ( 004b20c21 )
Kaspersky not-a-virus:AdWare.Win32.iBryte.jjw
Malwarebytes PUP.Optional.RocketTab.PrxySvrRST
McAfee PUP-FST
McAfee-GW-Edition BehavesLike.Win32.Almanahe.vc
MicroWorld-eScan Gen:Variant.Adware.iBryte.10
NANO AntiVirus Riskware.Win32.IBryte.dltiln
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.17EBA268!401318504
Sophos Generic PUA OC (PUA)
Symantec Trojan.Gen.2
Trend Micro TROJ_SPNR.0BAM15
Vba32 AntiVirus AdWare.iBryte
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.iBryte.Win32.6199
Cyren W32/Adware.VIAQ-6751
Dr.Web Adware.iBryte.576
SUPERAntiSpyware Adware.iBryte/Variant
ViRobot Adware.Agent.2647552[h]

Software Behaviors

Scheduled tasks:
  • uninstall.exe is scheduled as a task named 'RocketTab Update Task' (Next runs on 8/3/2016 at 3:17 PM).

Startup Entries

Startup tasks:
  • uninstall.exe is automatically launched at startup through a scheduled task named RocketTab Update Task.
Registry entries:
  • uninstall.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'RocketTab Update Task' and executes as "C:\users\user\appdata\Local\Search Extensions\uninstall.exe" /CheckUpdate=true.
  • Client.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'RocketTab' and executes as "C:\users\user\appdata\Local\Search Extensions\Client.exe".

Software Details

URL:
https://rockettab.com
Support:
–
Installation path:
C:\Program Files\Browsersafeguard
Uninstaller:
"C:\Program Files\Browsersafeguard\uninstall.BrowserSafeguard.exe" /u=true /UserID=08c6703e-2cd3-4864-a3ce-3bc355a0d954 /SourceID=browsersafeguard-roc
Size:
4.00 MB
Language:
English

Rockettab Executable Details

Primary executable:
BrowserSafeguard.exe
Name:
Rockettab
Path:
C:\Program Files\Browsersafeguard\BrowserSafeguard.exe
MD5:
c9b4e288d6e7af76ef2f5d8c99047660
SHA-1:
–
SHA-256:
–
Files installed by Rockettab
File Type Filename MD5
EXE
17bdbea3321f0d7c842d2a1e1ff92448
EXE
02783f258cb37ad93452f834d8113818
EXE
7cee867f453c566c7ba04652ebdeb616
EXE
e118dff41585b70576da4576e4756589
EXE
0edb6614a108a0f0308f790260509a10
EXE
c9b4e288d6e7af76ef2f5d8c99047660
DLL
e73db987c7ac58148b0decbab491018a