Threat Database Adware Rock Turner

Rock Turner

By GoldSparrow in Adware

Threat Scorecard

Ranking: 13,113
Threat Level: 20 % (Normal)
Infected Computers: 3,889
First Seen: April 1, 2014
Last Seen: August 24, 2023
OS(es) Affected: Windows

Rock Turner is known to be adware that may show unwanted pop-up advertisements including offers, discount coupons, special deals and sales that allegedly save money while computer users are shopping online. Mainly, Rock Turner may circulate and insert itself into the PC using tricky tactics such as bundling itself as an extra application to free software. Once it is integrated into the PC, Rock Turner may modify the default browser settings and forcibly divert PC users to unreliable websites. These websites, with the help of associated adware, may show random pop-up advertisements or advertisements pertaining to the PC user's browsing activity on the computer system. Rock Turner may gather browsing details about the computer user's surfing habits and use them for targeted advertising intentions. Upon installation on the Web browser, Rock Turner may insert an unwanted browser add-on, extension or plug-in. The pop-up ads delivered by Rock Turner may be displayed when PC users are surfing online using Internet Explorer, Mozilla Firefox, and Google Chrome Web browsers.

SpyHunter Detects & Remove Rock Turner

File System Details

Rock Turner may create the following file(s):
# File Name MD5 Detections
1. utilRockTurner.exe f648748795c1caf8b44c28b4f8f3c6a6 1,741
2. RockTurner.BrowserAdapter.exe db74dd89744423e52826d244dbf6c6be 632
3. RockTurner.PurBrowse64.exe 97711b647d1877be3456683e87dd25d2 511
4. RockTurner.dll 4d5afe4cedde05f9e26fd683d4d303c9 0

Registry Details

Rock Turner may create the following registry entry or registry entries:
CLSID
{439B077B-D2A9-4E21-990C-495495B05AA8}
Software\Microsoft\Internet Explorer\Approved Extensions\{71426648-DD49-4529-BB57-E065F96D8DCE}
Software\Microsoft\Internet Explorer\Approved Extensions\{A2ED2793-22C8-45CD-8C9F-A3AF7009D3F9}
SOFTWARE\Microsoft\Tracing\updateRockTurner_RASAPI32
SOFTWARE\Microsoft\Tracing\updateRockTurner_RASMANCS
Software\Rock Turner
SOFTWARE\Wow6432Node\Microsoft\Tracing\updateRockTurner_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\updateRockTurner_RASMANCS
SOFTWARE\Wow6432Node\Rock Turner
SYSTEM\ControlSet001\services\eventlog\Application\Update Rock Turner
SYSTEM\ControlSet001\services\Update Rock Turner
SYSTEM\ControlSet002\services\eventlog\Application\Update Rock Turner
SYSTEM\ControlSet002\services\Update Rock Turner
SYSTEM\CurrentControlSet\services\eventlog\Application\Update Rock Turner
SYSTEM\CurrentControlSet\services\Update Rock Turner

Directories

Rock Turner may create the following directory or directories:

%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\gokaheihjicnkmpomlllahalnhmdliil
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Extension Settings\gokaheihjicnkmpomlllahalnhmdliil
%LOCALAPPDATA%\Google\Chrome\User Data\Default\databases\chrome-extension_gokaheihjicnkmpomlllahalnhmdliil_0
%PROGRAMFILES%\Rock Turner
%PROGRAMFILES(x86)%\Rock Turner

URLs

Rock Turner may call the following URLs:

Rock Turner

Trending

Most Viewed

Loading...