Home Malware Programs Adware Rock Turner

Rock Turner

Posted: April 1, 2014

Threat Metric

Ranking: 17,039
Threat Level: 2/10
Infected PCs: 9,108
First Seen: April 1, 2014
Last Seen: August 24, 2023
OS(es) Affected: Windows


Rock Turner is adware that may display numerous pop-up ads carrying discount coupons, offers, sales and special deals that supposedly save the computer user's money while he is performing online shopping. Usually, Rock Turner may spread and enter the computer system using misleading techniques such as packaging itself as an additional program together with other freeware. After Rock Turner is installed on the computer system, it may alter the default browser settings and result in continuous redirects to suspicious websites. These websites, through the use of related adware, may show various random pop-up advertisements or advertisements linked to the computer user's surfing routine on the PC. Pop-up ads from Rock Turner may be seen when the PC user is browsing the Web using Internet Explorer, Mozilla Firefox, and Google Chrome. Rock Turner may substitute the default start page and search provider or a new tab window with a questionable website. Once installed on the PC, Rock Turner may embed an unwanted browser extension, plug-in or add-on on the Web browser.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\Rock Turner\bin\utilRockTurner.exe File name: utilRockTurner.exe
Size: 317.72 KB (317728 bytes)
MD5: f648748795c1caf8b44c28b4f8f3c6a6
Detection count: 4,078
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Rock Turner\bin
Group: Malware file
Last Updated: October 16, 2014
%PROGRAMFILES(x86)%\Rock Turner\bin\RockTurner.BrowserAdapter.exe File name: RockTurner.BrowserAdapter.exe
Size: 96.54 KB (96544 bytes)
MD5: db74dd89744423e52826d244dbf6c6be
Detection count: 1,480
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Rock Turner\bin
Group: Malware file
Last Updated: October 16, 2014
%PROGRAMFILES(x86)%\Rock Turner\bin\RockTurner.PurBrowse64.exe File name: RockTurner.PurBrowse64.exe
Size: 287 KB (287008 bytes)
MD5: 97711b647d1877be3456683e87dd25d2
Detection count: 1,197
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Rock Turner\bin
Group: Malware file
Last Updated: May 31, 2020
%ProgramFiles%\Rock Turner\RockTurner.dll File name: RockTurner.dll
Size: 249.63 KB (249632 bytes)
MD5: 4d5afe4cedde05f9e26fd683d4d303c9
Detection count: 27
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ProgramFiles%\Rock Turner
Group: Malware file
Last Updated: April 10, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{439B077B-D2A9-4E21-990C-495495B05AA8}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{71426648-DD49-4529-BB57-E065F96D8DCE}Software\Microsoft\Internet Explorer\Approved Extensions\{A2ED2793-22C8-45CD-8C9F-A3AF7009D3F9}SOFTWARE\Microsoft\Tracing\updateRockTurner_RASAPI32SOFTWARE\Microsoft\Tracing\updateRockTurner_RASMANCSSoftware\Rock TurnerSOFTWARE\Wow6432Node\Microsoft\Tracing\updateRockTurner_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateRockTurner_RASMANCSSOFTWARE\Wow6432Node\Rock TurnerSYSTEM\ControlSet001\services\eventlog\Application\Update Rock TurnerSYSTEM\ControlSet001\services\Update Rock TurnerSYSTEM\ControlSet002\services\eventlog\Application\Update Rock TurnerSYSTEM\ControlSet002\services\Update Rock TurnerSYSTEM\CurrentControlSet\services\eventlog\Application\Update Rock TurnerSYSTEM\CurrentControlSet\services\Update Rock TurnerHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Rock Turner

Additional Information

The following directories were created:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\gokaheihjicnkmpomlllahalnhmdliil%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Extension Settings\gokaheihjicnkmpomlllahalnhmdliil%LOCALAPPDATA%\Google\Chrome\User Data\Default\databases\chrome-extension_gokaheihjicnkmpomlllahalnhmdliil_0%PROGRAMFILES%\Rock Turner%PROGRAMFILES(x86)%\Rock Turner
The following URL's were detected:
Rock Turner
Loading...