diglobrowser.exe

Rollnon

This is the Verti bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application diglobrowser.exe by Rollnon has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the Verti Setup installer.
Publisher:
Rollnon  (signed and verified)

Version:
1.0.0.5

MD5:
da3015be80280db28855b3c1bccf7731

SHA-1:
c68aaf146e6e20b838c27787c6e1b737035bca94

SHA-256:
3e34f2ccfcbf2d53896edf3a0b83d9515dc17fc6c7824b07d8e165f3e007f312

Scanner detections:
10 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/27/2024 12:16:33 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150430

ESET NOD32
Win32/Verti (variant)
9.10120

G Data
Win32.Trojan.Agent.8ILWUR
15.4.24

herdProtect (fuzzy)
2015.7.30.18

IKARUS anti.virus
PUA.Verti
t3scan.1.6.1.0

McAfee
Artemis!DA3015BE8028
5600.6779

Qihoo 360 Security
HEUR/Malware.QVM10.Gen
1.0.0.1015

Reason Heuristics
Threat.Verti.Bundler
15.4.30.17

Trend Micro House Call
Suspicious_GEN.F47V0801
7.2.120

VIPRE Antivirus
Ignition Installer
31390

File size:
599.5 KB (613,912 bytes)

Product version:
1.0.0.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Verti Setup

Language:
English (United States)

Common path:
C:\users\{user}\downloads\diglobrowser.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/26/2014 8:00:00 PM

Valid to:
5/27/2015 7:59:59 PM

Subject:
CN=Rollnon, O=Rollnon, STREET=3600 136th Pl SE, L=Bellevue, S=WA, PostalCode=98006, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6C8BE128901FD5CAC240ACBD1CC43ABC

File PE Metadata
Compilation timestamp:
7/18/2014 1:54:25 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:+vX6+kw1Zvx3OhIYkeRpMDNIMQQi9M6nR0zqXRa7aezjTu:bovx+hMQMhS7nOzqXU7aezjTu

Entry address:
0x22715

Entry point:
E8, A6, A5, 00, 00, E9, 89, FE, FF, FF, 6A, 0C, 68, 10, 01, 48, 00, E8, 55, 2C, 00, 00, 6A, 0E, E8, E6, 9E, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, 1C, A0, 48, 00, BA, 18, A0, 48, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, AB, B4, FF, FF, 59, FF, 76, 04, E8, A2, B4, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, 44, 2C, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, B2, 9D, 00, 00, 59, C3, CC, 8B, 54, 24, 04, 8B...
 
[+]

Entropy:
6.6688

Code size:
401 KB (410,624 bytes)

Remove diglobrowser.exe - Powered by Reason Core Security