7eca1cd8-2a95-4759-9c0f-ae713062040a-2.exe

Super Radio

BadFinger Project (BrightCircle Investments Limited)

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application 7eca1cd8-2a95-4759-9c0f-ae713062040a-2.exe by BadFinger Project (BrightCircle Investments Limited) has been detected as adware by 21 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. This file is typically installed with the program Super Radio by BrightCircle Investments Limited which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Buca Apps  (signed by BadFinger Project (BrightCircle Investments Limited))

Product:
Super Radio

Description:
Super Radio exe

Version:
1000.1000.1000.1000

MD5:
f8f0e4c9d8e49573af18542e2b99f919

SHA-1:
9b703b015dfd9a9d13d6efb70f343b5e01c02d52

SHA-256:
a9d018212094626082b0e2654ce9a5f728c328c98c170aaa4f8c44da89908c05

Scanner detections:
21 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
11/23/2024 5:16:18 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.2u1@kyREQ3cO
6175498

AhnLab V3 Security
PUP/Win32.CrossRider
2014.12.18

Avira AntiVirus
ADWARE/CrossRider.Gen4
7.11.196.118

AVG
Generic
2015.0.3257

Baidu Antivirus
PUA.Win32.CrossRider
4.0.3.141217

Bitdefender
Gen:Application.Heur.2u1@kyREQ3cO
1.0.20.1755

Emsisoft Anti-Malware
Gen:Application.Heur.2u1@kyREQ3cO
9.0.0.4668

ESET NOD32
Win32/Toolbar.CrossRider.BM potentially unwanted application
7.0.302.0

F-Secure
Riskware.Gen:Application.Heur.2u1@kyREQ3cO
5.13.68

G Data
Gen:Application.Heur.2u1@kyREQ3cO
14.12.24

IKARUS anti.virus
Trojan.GoogUpdate
t3scan.1.8.5.0

K7 AntiVirus
Unwanted-Program
13.188.14368

Kaspersky
not-a-virus:AdWare.NSIS.Adwapper
15.0.0.543

Malwarebytes
PUP.Optional.CinemaGoPro.A
v2014.12.18.04

McAfee
Trojan.Artemis!F8F0E4C9D8E4
16.8.708.2

MicroWorld eScan
Gen:Application.Heur.2u1@kyREQ3cO
15.0.0.1053

Norman
Gen:Application.Heur.2u1@kyREQ3cO
04.12.2014 14:30:06

Panda Antivirus
Trj/Genetic.gen
14.12.17.02

Qihoo 360 Security
Win32/Application.4df
1.0.0.1015

Reason Heuristics
Adware.Crossrider.Task.Brightcircle
15.3.1.16

Sophos
Generic PUA MI
4.98

File size:
875 KB (895,968 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Super Radio.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\super radio\7eca1cd8-2a95-4759-9c0f-ae713062040a-2.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/17/2014 1:00:00 AM

Valid to:
11/18/2015 12:59:59 AM

Subject:
CN=BadFinger Project (BrightCircle Investments Limited), O=BadFinger Project (BrightCircle Investments Limited), STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6623FAFCAC357577A31D90C1E567E9A7

File PE Metadata
Compilation timestamp:
12/15/2014 12:04:40 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:j6Q+3/PB09xkt43VM2ehDEzKgLkpyEvNHaCFg5pfUZlzqpSSXZcpTZNH:j6QJxkt43V5V4NHaCCnUl2pSSpQTL

Entry address:
0x81AE0

Entry point:
E8, 1B, B1, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, F8, 2B, 4D, 00, E8, 3A, 4E, 00, 00, E8, C2, 42, 00, 00, 0F, B7, F0, 6A, 02, E8, AE, B0, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, D3, 53, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
616.5 KB (631,296 bytes)

Scheduled Task
Task name:
7eca1cd8-2a95-4759-9c0f-ae713062040a-2

Trigger:
Logon (Runs on logon)


The file 7eca1cd8-2a95-4759-9c0f-ae713062040a-2.exe has been discovered within the following program.

Super Radio  by BrightCircle Investments Limited
Super Radio from BadFinger Project (BrightCircle) is an adware app for the browser that uses the Crossrider framework to distribute ads in the browser.
80% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ip-50-63-202-32.ip.secureserver.net  (50.63.202.32:80)

Remove 7eca1cd8-2a95-4759-9c0f-ae713062040a-2.exe - Powered by Reason Core Security