roboot64.exe

FastAgain PC Booster

Fiorentino Media Inc.

The application roboot64.exe by Fiorentino Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Activeris  (signed by Fiorentino Media Inc.)

Product:
FastAgain PC Booster

Version:
1.0.0.0

MD5:
ac0c02783e2b157fc0c41985e429eaff

SHA-1:
580a239b4c96015d8ea9a1993d73e9896585bcb9

SHA-256:
0b252100f763d7e265708dffe086d89cda21d0b87ae9c0cc0dadf7f9920cf8da

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 5:04:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.FiorentinoMedia.I
14.8.21.13

File size:
20.2 KB (20,712 bytes)

Copyright:
© 2012 Activeris, Portions (C) Systweak Inc. All rights reserved.

Trademarks:
FastAgain PC Booster

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\roboot64.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/24/2012 5:00:00 PM

Valid to:
1/24/2013 4:59:59 PM

Subject:
CN=Fiorentino Media Inc., O=Fiorentino Media Inc., STREET=7904 E. Chaparral Road, STREET=STE A110-430, L=Scottsdale, S=AZ, PostalCode=85250, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009CB8D8E313806C1914ADA02E4DB86602

File PE Metadata
Compilation timestamp:
2/14/2012 6:15:51 AM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
384:xTpZOM3WQNBZOVUL3CeGtY3mirILECxV8+OA521S5:ng8LBZoLIILZ8+D21i

Entry address:
0x248C

Entry point:
48, 83, EC, 68, 48, 8D, 0D, 59, EF, FF, FF, E8, DC, F3, FF, FF, 48, 8D, 0D, 8D, EF, FF, FF, E8, D0, F3, FF, FF, 48, 8D, 0D, C1, EF, FF, FF, E8, C4, F3, FF, FF, 48, 8D, 0D, 35, EF, FF, FF, E8, B8, F3, FF, FF, 48, 8D, 0D, B9, F0, FF, FF, E8, AC, F3, FF, FF, E8, 27, 02, 00, 00, 33, D2, 48, 8D, 4C, 24, 30, 44, 8D, 42, 30, C6, 44, 24, 78, 00, E8, CE, 0A, 00, 00, 33, D2, 48, 8D, 44, 24, 30, 48, 89, 44, 24, 28, 48, 83, 64, 24, 20, 00, 8D, 4A, 02, 41, B9, 00, 10, 00, 00, 41, B8, 00, 00, 10, 00, C7, 44, 24, 30, 30...
 
[+]

Entropy:
6.1091

Code size:
9.5 KB (9,728 bytes)

Remove roboot64.exe - Powered by Reason Core Security