rootgenius.exe

Free Virus Soft

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application rootgenius.exe, “Prime Installer ” by Free Virus Soft has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. The file has been seen being downloaded from secure.distapp19.com.
Publisher:
Prime Installer   (signed by Free Virus Soft)

Product:
Prime Installer

Description:
Prime Installer

Version:
3.5.9.2

MD5:
6c233c75297deddc32eb43736b34f6da

SHA-1:
a16eb1fa7021530356b5f39ff5b8b514cf84e91b

SHA-256:
bca242241ea851fba1a270b4822ecc066202d23227e032902762c43a554fa69d

Scanner detections:
19 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 6:00:03 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Ibryte.BM
6505244

Avira AntiVirus
Adware/iBryte.bxpj
7.11.206.68

AVG
Adware AdPlugin.CIO
2014.0.4257

Bitdefender
Adware.Ibryte.BM
1.0.20.160

Clam AntiVirus
Win.Adware.Ibryte-7821
0.98/20033

Dr.Web
Trojan.DownLoader12.15685
9.0.1.05190

Emsisoft Anti-Malware
Adware.Ibryte.BM
9.0.0.4799

ESET NOD32
Win32/Adware.iBryte.BY application
7.0.302.0

F-Prot
W32/S-dcc1cb3e
v6.4.7.1.166

F-Secure
Adware.Ibryte.BM
5.13.68

G Data
Adware.Ibryte.BM
15.2.25

Malwarebytes
PUP.Optional.SwiftBrowse
v2015.02.01.03

MicroWorld eScan
Adware.Ibryte.BM
16.0.0.96

NANO AntiVirus
Trojan.Win32.DownLoader12.dnihtg
0.30.0.65070

Norman
IBryte.URL
11.20150207

nProtect
Adware.Ibryte.BM
15.02.05.01

Panda Antivirus
Generic Suspicious
15.02.07.11

Reason Heuristics
PUP.Installer.Adknowledge
15.2.10.11

VIPRE Antivirus
Threat.4798837
36666

File size:
443.9 KB (454,528 bytes)

Product version:
3.5.9.2

Copyright:
Copyright (C) Prime Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Common path:
C:\users\{user}\downloads\rootgenius.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/24/2014 2:00:00 AM

Valid to:
3/25/2015 1:59:59 AM

Subject:
CN=Free Virus Soft, O=Free Virus Soft, STREET="4600 Madison Ave, 10th FL", L=Kansas City, S=Missouri, PostalCode=64112, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C7C7950B1D1328B35E2542BD153CE6CF

File PE Metadata
Compilation timestamp:
2/1/2015 9:00:29 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:F00NGK8PRLCnC1GEmtdfpAcNATqJNV51/fYcw:NQcnC1GrtVpAEQANV51/fYcw

Entry address:
0x1A363

Entry point:
E8, 5D, 98, 00, 00, E9, 78, FE, FF, FF, CC, CC, CC, 68, D0, A3, 41, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, EC, B5, 43, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 8B, 73, 08, 33, 35, EC...
 
[+]

Code size:
183.5 KB (187,904 bytes)

The file rootgenius.exe has been seen being distributed by the following URL.

Remove rootgenius.exe - Powered by Reason Core Security