utilrockresult.exe

RockResult

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application utilrockresult.exe by RockResult has been detected as adware by 8 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
RockResult  (signed and verified)

Version:
1.0.5379.4611

MD5:
397a90925fa1088b6334b4939aaaf8ff

SHA-1:
16eff2120a8bc97ba571fa3800fd1cb948108882

SHA-256:
1b3d1eacb865387b836b1a1fa396c82902bd7431e340bf902d851c4df94628c2

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/19/2024 11:41:47 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/BrowseFox.Gen7
7.11.173.236

AVG
Generic
2015.0.3342

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14923

ESET NOD32
Win32/BrowseFox (variant)
8.10451

Kaspersky
not-a-virus:HEUR:AdWare.MSIL.Kranet
14.0.0.3207

Malwarebytes
PUP.Optional.RockResult.A
v2014.09.23.02

Qihoo 360 Security
Win32/Virus.Adware.708
1.0.0.1015

Reason Heuristics
PUP.RockResult.O
14.9.23.14

File size:
317.8 KB (325,408 bytes)

Product version:
1.0.5379.4611

Original file name:
RockResult.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\rockresult\bin\utilrockresult.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
6/10/2014 1:00:00 AM

Valid to:
6/15/2015 1:00:00 PM

Subject:
CN=RockResult, O=RockResult, L=Santa Monica, S=California, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0D2151DAC91D7B014A2AAC028842CAD8

File PE Metadata
Compilation timestamp:
9/23/2014 4:33:59 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:Pxi/h4qQqvvAojml41YWvksXPN+yQRWgERAWvmDy93w8cgj7McUlJ8jxgqvQdZCr:Pxi/ZB8reZJ/j7eaQd1Afd

Entry address:
0x4F322

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.0865

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
309 KB (316,416 bytes)

Remove utilrockresult.exe - Powered by Reason Core Security