7eca1cd8-2a95-4759-9c0f-ae713062040a-11.exe

Super Radio

BadFinger Project (BrightCircle Investments Limited)

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application 7eca1cd8-2a95-4759-9c0f-ae713062040a-11.exe by BadFinger Project (BrightCircle Investments Limited) has been detected as adware by 21 anti-malware scanners. This file is typically installed with the program Super Radio by BrightCircle Investments Limited which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Buca Apps  (signed by BadFinger Project (BrightCircle Investments Limited))

Product:
Super Radio

Description:
Super Radio exe

Version:
1000.1000.1000.1000

MD5:
b90d911c0e39dcde52da5deb5d504d56

SHA-1:
7b23412a65a3f1005e9c48949885cd831e1c0647

SHA-256:
d5fd2b1b1b250d2134e9338b2bb635718b57fec6f4d11acc46e2c7d27132d7eb

Scanner detections:
21 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
11/2/2024 1:28:09 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.2v1@k8jlsylO
780

avast!
Win32:Adware-gen [Adw]
2014.9-141216

AVG
Generic
2015.0.3258

Baidu Antivirus
PUA.Win32.CrossRider
4.0.3.141216

Bitdefender
Gen:Application.Heur.2v1@k8jlsylO
1.0.20.1750

Comodo Security
Application.Win32.Plush.GRI
20390

Emsisoft Anti-Malware
Gen:Application.Heur.2v1@kWHYsamO
8.14.12.18.03

ESET NOD32
Win32/Toolbar.CrossRider.BM (variant)
8.10887

Fortinet FortiGate
Adware/Adwapper
12/18/2014

F-Secure
Gen:Application.Heur.2v1@k8jlsylO
11.2014-16-12_3

G Data
Gen:Application.Heur.2v1@k8jlsylO
14.12.24

IKARUS anti.virus
Trojan.GoogUpdate
t3scan.1.8.5.0

K7 AntiVirus
Unwanted-Program
13.188.14354

Kaspersky
not-a-virus:AdWare.NSIS.Adwapper
14.0.0.2786

Malwarebytes
v2014.12.18.03

MicroWorld eScan
Gen:Application.Heur.2v1@k8jlsylO
15.0.0.1050

Norman
Gen:Application.Heur.2v1@kWHYsamO
11.20141218

Panda Antivirus
Trj/Genetic.gen
14.12.18.03

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Adware.Crossrider.Brightcircle
15.3.1.16

Sophos
Generic PUA DC
4.98

File size:
1.9 MB (1,945,568 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Super Radio.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\super radio\7eca1cd8-2a95-4759-9c0f-ae713062040a-11.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/17/2014 12:00:00 AM

Valid to:
11/17/2015 11:59:59 PM

Subject:
CN=BadFinger Project (BrightCircle Investments Limited), O=BadFinger Project (BrightCircle Investments Limited), STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6623FAFCAC357577A31D90C1E567E9A7

File PE Metadata
Compilation timestamp:
12/15/2014 11:05:35 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:PuqEqRZUb9A35sqmb5ddZpfpSU2TsbZ1V1DzF:Aq8Ruqq0TUw

Entry address:
0xEEDF1

Entry point:
E8, 67, FD, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 85, F6, 78, 09, E8, 9A, FE, 00, 00, 3B, 30, 7C, 07, E8, 91, FE, 00, 00, 8B, 30, E8, 84, FE, 00, 00, 8B, 04, B0, 5E, 5D, C3, 55, 8B, EC, 56, E8, 83, 5C, 00, 00, 8B, F0, 85, F6, 75, 07, B8, 60, ED, 54, 00, EB, 26, 53, 57, 33, FF, BB, 86, 00, 00, 00, 39, 7E, 24, 75, 1B, 6A, 01, 53, E8, 9D, 2E, 00, 00, 59, 59, 89, 46, 24, 85, C0, 75, 0A, B8, 60, ED, 54, 00, 5F, 5B, 5E, 5D, C3, FF, 75, 08, 8B, 76, 24, E8, 90, FF, FF, FF, 50, 53, 56, E8, FE, EA...
 
[+]

Code size:
1.1 MB (1,125,376 bytes)

The file 7eca1cd8-2a95-4759-9c0f-ae713062040a-11.exe has been discovered within the following programs.

Super Radio  by BrightCircle Investments Limited
Super Radio from BadFinger Project (BrightCircle) is an adware app for the browser that uses the Crossrider framework to distribute ads in the browser.
80% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ip-50-63-202-32.ip.secureserver.net  (50.63.202.32:80)

Remove 7eca1cd8-2a95-4759-9c0f-ae713062040a-11.exe - Powered by Reason Core Security