updater.exe

Ziggy Networks (Bright Circle Investments Ltd)

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application updater.exe, “updater 2.6.9, 2013” by Ziggy Networks (Bright Circle Investments) has been detected as adware by 7 anti-malware scanners. This file is typically installed with the program Doctor PC by Dragon Big Lab which is a potentially unwanted software program. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Doctor PC  (signed by Ziggy Networks (Bright Circle Investments Ltd))

Product:
Doctor PC

Description:
updater 2.6.9, 2013

Version:
2.6.9

MD5:
77cc8e129cfa9a1bb790e671a5cb27bd

SHA-1:
7a942495bf90a23bac8a67c1485dcfb5b6d6ac02

SHA-256:
adcb77732bb91b20f747cb5124390c8c8a1ad44785beca02cb4e6b991766289f

Scanner detections:
7 / 68

Status:
Adware

Explanation:
May modify the web browser's settings including changing the homepage and search provider in addition to delivering ads (by injecting banner and text-links directly in the webpage).

Analysis date:
11/27/2024 1:51:43 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
PUA.Win32.CrossRider
4.0.3.15126

Bkav FE
W32.HfsAdware
1.3.0.6379

ESET NOD32
Win32/Toolbar.CrossRider.BM potentially unwanted application
7.0.302.0

F-Secure
Win32.Sality.3
5.13.68

Malwarebytes
PUP.Optional.DrPC.A
v2015.01.26.06

Reason Heuristics
Adware.BrightCircle.ZiggyNetworksBrightCircleInvestments
15.1.30.0

VIPRE Antivirus
Threat.4789396
36694

File size:
423.5 KB (433,672 bytes)

Product version:
2.6.9

Copyright:
Copyright (C) 2015 Doctor PC

Original file name:
updater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\doctor pc\doctor pc 2.6.9\install\011ff20\updater.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/16/2014 1:00:00 AM

Valid to:
12/17/2015 12:59:59 AM

Subject:
CN=Ziggy Networks (Bright Circle Investments Ltd), O=Ziggy Networks (Bright Circle Investments Ltd), STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BBB0E0273DE6CDFEF0992B8F1F6BE5C9

File PE Metadata
Compilation timestamp:
10/7/2014 5:01:18 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:+GDVPVmyTCYbbLe+Bz1iE1/M7xbQE9VP/lXHDx4QygWM2Hvw:+GCyTCYbbfB1iEm7xME95RF4hw

Entry address:
0x10F92

Entry point:
E8, EE, 75, 00, 00, E9, 79, FE, FF, FF, 68, 00, 10, 41, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 44, 10, 44, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 8B, 73, 08, 33, 35...
 
[+]

Code size:
227.5 KB (232,960 bytes)

The file updater.exe has been discovered within the following program.

Doctor PC  by Dragon Big Lab
About 57% of users remove it
 
Powered by Should I Remove It?

Remove updater.exe - Powered by Reason Core Security