3809.exe

NightWish Center (Bright Circle Investments Ltd)

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application 3809.exe by NightWish Center (Bright Circle Investments) has been detected as adware by 22 anti-malware scanners. This file is typically installed with the program Crossbrowse by CLARALABSOFTWARE which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:

Version:
104.0.0.0

MD5:
2c73fbb63b80797b8517e008409e268b

SHA-1:
ea78361f2a9d20ea65cced854d41eff7abaa0ee7

SHA-256:
df94f332d24b1d9d033979a2a64d5413743d5eab887da8aa83b5c5470f67df71

Scanner detections:
22 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/18/2025 8:58:01 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.CrossRider
7.1.1

AhnLab V3 Security
PUP/Win32.CrossRider
2015.05.10

AVG
Crossrider
2016.0.3091

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.1561

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Trojan.Crossrider-242
0.98/21511

Comodo Security
ApplicUnwnt
22057

Dr.Web
Trojan.Crossrider1.25393
9.0.1.0152

ESET NOD32
Win32/Toolbar.CrossRider.CL potentially unwanted (variant)
9.11602

Fortinet FortiGate
Riskware/CrossRider
6/1/2015

K7 AntiVirus
Adware
13.203.15859

Malwarebytes
PUP.Optional.Crossrider
v2015.06.01.07

McAfee
Artemis!2C73FBB63B80
5600.6747

NANO AntiVirus
Trojan.Win32.Crossrider1.dqjhpi
0.30.24.1357

Panda Antivirus
Trj/Genetic.gen
15.06.01.07

Reason Heuristics
Adware.BrightCircle.NightWishCenterBrightCircleInvestments
15.6.1.19

Sophos
AppRider
4.98

Trend Micro House Call
TROJ_GEN.R00GC0ODQ15
7.2.152

Trend Micro
TROJ_GEN.R00GC0ODQ15
10.465.01

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Crossrider
40086

Zillya! Antivirus
Adware.CrossRider.Win32.5421
2.0.0.2173

File size:
1.7 MB (1,819,104 bytes)

Product version:
104.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\3809.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/15/2014 4:00:00 PM

Valid to:
12/16/2015 3:59:59 PM

Subject:
CN=NightWish Center (Bright Circle Investments Ltd), O=NightWish Center (Bright Circle Investments Ltd), STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B30349E6AD66949988B51360F031BFB4

File PE Metadata
Compilation timestamp:
3/25/2015 10:19:54 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:Id9zuD1k9KOEBGlW5SeYyBoaTXpSkLQ07Jz4nmeXtD:w9W1xIW59YyBodb

Entry address:
0x119810

Entry point:
E8, D2, 10, 01, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, A4, 6D, 5A, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 48, AE, 59, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, A4, 6D, 5A, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00...
 
[+]

Entropy:
6.6317

Code size:
1.3 MB (1,317,888 bytes)

The file 3809.exe has been discovered within the following program.

Crossbrowse  by CLARALABSOFTWARE
87% remove it
 
Powered by Should I Remove It?

Remove 3809.exe - Powered by Reason Core Security