roguekiller.exe

RogueKiller

Adlice

This is installed with multiple programs including RogueKiller version 12 and RogueKiller version 11. The file has been seen being downloaded from www.adlice.com and multiple other hosts.
Publisher:
Adlice Software  (signed by Adlice)

Product:
RogueKiller

Description:
Anti~mal~ware tool

Version:
11.0.3.0

MD5:
e93732aaded314850baa69a5188d6997

SHA-1:
4c66c16c379b72cd38ff61b14ba375010ea28657

SHA-256:
ea846668a67db6dd243773bbd012d62e5aaf561bfc9a0ad7661a73561a66bf4a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 8:33:21 AM UTC  (today)

File size:
19.9 MB (20,834,376 bytes)

Product version:
11.0.3.0

Copyright:
Copyright Adlice Software(C) 2015

Original file name:
RogueKiller

Language:
French (France)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\roguekiller.exe.wb2xus8.partial

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
3/30/2015 8:00:00 PM

Valid to:
6/28/2018 8:00:00 AM

Subject:
CN=Adlice, O=Adlice, L=Orvault, S=Loire Atlantique, C=FR

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0730C248977813C25BB22568B51ED287

File PE Metadata
Compilation timestamp:
12/14/2015 3:50:14 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
393216:Fp1oBXl4X6iOm0e0Jsv6tWKFdu9CfWUxUXSI4:toBXm+4Cf

Entry address:
0x886BA3

Entry point:
E8, 61, EB, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, 9F, F3, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 20, 03, 3F, 01, FF, 15, 4C, F3, DF, 00, 85, C0, 75, 18, 56, E8, DA, 10, 00, 00, 8B, F0, FF, 15, 54, F4, DF, 00, 50, E8, 8A, 10, 00, 00, 59, 89, 06, 5E, 5D, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 20, 03, 3F, 01, 00, 75, 18, E8, 71, D9, 00, 00, 6A, 1E, E8, BB, D7, 00, 00, 68, FF, 00, 00, 00, E8, 3D, 01, 00, 00, 59, 59...
 
[+]

Code size:
10 MB (10,475,520 bytes)

The file roguekiller.exe has been discovered within the following programs.

RogueKiller version 11  by Adlice Software
adlice.com
About 9% of users remove it
RogueKiller version 12  by Adlice Software
About 6% of users remove it
 
Powered by Should I Remove It?

The file roguekiller.exe has been seen being distributed by the following 5 URLs.

http://www.adlice.com/fr/download/.../?wpdmdl=3744&ind=aHR0cDovL2Rvd25sb2FkLmFkbGljZS5jb20vUm9ndWVLaWxsZXIvUm9ndWVLaWxsZXIuZXhl

http://www.slunecnice.cz/sw/roguekiller/stahnout/33366/.../?md5=UoPV7a1hL7UNByz4drThfQ&expires=1450876607

Scan roguekiller.exe - Powered by Reason Core Security