plus-hd-v1.5-nova.dll

Bright circle investments Ltd.

This adware utilizes the Crossrider extension platform and will inject advertisiments in the Internet browser and may modify core browser settings. Ads will be delivered as banners and contextual text-links and may promote other potentially unwanted software. The module plus-hd-v1.5-nova.dll by Bright circle investments has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Bright circle investments Ltd.  (signed and verified)

MD5:
a8a82cde0c1e6b5fb5938dd2fe9b63d0

SHA-1:
570ec1679e2b4a832f7dfc5dd917b9f6e7170011

SHA-256:
d110e279517ace976a42ec0000914573cf908b302440f8193f9305c40c2a9972

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 11:37:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.BrightCircle (M)
16.6.10.3

File size:
128.5 KB (131,568 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\plus-hd-v1.5\plus-hd-v1.5-nova.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/19/2014 2:00:00 AM

Valid to:
6/20/2015 1:59:59 AM

Subject:
CN=Bright circle investments Ltd., O=Bright circle investments Ltd., STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EF90FEF9AC8E258E5D30D0E08C84D37E

File PE Metadata
Compilation timestamp:
6/20/2014 12:06:20 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:YRvJtpwv2P9gXmRvWb9y3qvtKKB+1TgBkZELLfiOJ+Rcj9sWjcdzGEfdxD4Q4ckL:YRJtpgc9Z+b9Ht4CLLZJ+NzGmdp/4co

Entry address:
0x6718

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 05, 39, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 88, 9B, 01, 10, E8, D9, 14, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 4C, C2, 01, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 90, 50, 01, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
75 KB (76,800 bytes)

Remove plus-hd-v1.5-nova.dll - Powered by Reason Core Security