7eca1cd8-2a95-4759-9c0f-ae713062040a-4.exe

Super Radio

BadFinger Project (BrightCircle Investments Limited)

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application 7eca1cd8-2a95-4759-9c0f-ae713062040a-4.exe by BadFinger Project (BrightCircle Investments Limited) has been detected as adware by 22 anti-malware scanners. This file is typically installed with the program Super Radio by BrightCircle Investments Limited which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Buca Apps  (signed by BadFinger Project (BrightCircle Investments Limited))

Product:
Super Radio

Description:
Super Radio exe

Version:
1000.1000.1000.1000

MD5:
beb9b8c5806012781b19ec73ae562216

SHA-1:
e1aaf9171928e13cd479688f46dd4a82d47329b1

SHA-256:
d44ed5429c1d503d8e6d13bfcbcfb2d9bee94a0097a1d93750feec3b5e397145

Scanner detections:
22 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/19/2024 2:41:07 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.qv1@kqfky4dO
780

Avira AntiVirus
ADWARE/CrossRider.Gen4
7.11.196.28

avast!
Win32:Adware-gen [Adw]
2014.9-141216

AVG
Generic
2015.0.3258

Baidu Antivirus
PUA.Win32.CrossRider
4.0.3.141216

Bitdefender
Gen:Application.Heur.qv1@kqfky4dO
1.0.20.1750

Dr.Web
Trojan.Crossrider.47389
9.0.1.0352

Emsisoft Anti-Malware
Gen:Application.Heur.qv1@kSS9NCkO
8.14.12.18.03

ESET NOD32
Win32/Toolbar.CrossRider.BM (variant)
8.10887

Fortinet FortiGate
Adware/Adwapper
12/18/2014

F-Secure
Gen:Application.Heur.qv1@kqfky4dO
11.2014-16-12_3

G Data
Gen:Application.Heur.qv1@kqfky4dO
14.12.24

IKARUS anti.virus
PUA.Toolbar.CrossRider
t3scan.1.8.5.0

K7 AntiVirus
Unwanted-Program
13.188.14354

Kaspersky
not-a-virus:AdWare.NSIS.Adwapper
14.0.0.2786

Malwarebytes
v2014.12.18.03

MicroWorld eScan
Gen:Application.Heur.qv1@kqfky4dO
15.0.0.1050

Norman
Gen:Application.Heur.qv1@kSS9NCkO
11.20141218

Panda Antivirus
Generic Suspicious
14.12.16.08

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Adware.Crossrider.Brightcircle
15.3.1.16

Sophos
Generic PUA JP
4.98

File size:
1.3 MB (1,318,880 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Super Radio.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\super radio\7eca1cd8-2a95-4759-9c0f-ae713062040a-4.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/17/2014 12:00:00 AM

Valid to:
11/17/2015 11:59:59 PM

Subject:
CN=BadFinger Project (BrightCircle Investments Limited), O=BadFinger Project (BrightCircle Investments Limited), STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6623FAFCAC357577A31D90C1E567E9A7

File PE Metadata
Compilation timestamp:
12/15/2014 11:04:39 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:0fstgduGrp4uziYrBpEjv5owxOU0zK1KHzThrnHYrppSOSTPo:0fcsuC41tjv5owEznH14rppSOSTPo

Entry address:
0xCAB4B

Entry point:
E8, C5, E4, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 85, F6, 78, 09, E8, F8, E5, 00, 00, 3B, 30, 7C, 07, E8, EF, E5, 00, 00, 8B, 30, E8, E2, E5, 00, 00, 8B, 04, B0, 5E, 5D, C3, 55, 8B, EC, 56, E8, 99, 43, 00, 00, 8B, F0, 85, F6, 75, 07, B8, A0, 53, 52, 00, EB, 26, 53, 57, 33, FF, BB, 86, 00, 00, 00, 39, 7E, 24, 75, 1B, 6A, 01, 53, E8, 72, 2D, 00, 00, 59, 59, 89, 46, 24, 85, C0, 75, 0A, B8, A0, 53, 52, 00, 5F, 5B, 5E, 5D, C3, FF, 75, 08, 8B, 76, 24, E8, 90, FF, FF, FF, 50, 53, 56, E8, 9A, D2...
 
[+]

Code size:
934 KB (956,416 bytes)

The file 7eca1cd8-2a95-4759-9c0f-ae713062040a-4.exe has been discovered within the following programs.

Super Radio  by BrightCircle Investments Limited
Super Radio from BadFinger Project (BrightCircle) is an adware app for the browser that uses the Crossrider framework to distribute ads in the browser.
80% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ip-50-63-202-32.ip.secureserver.net  (50.63.202.32:80)

Remove 7eca1cd8-2a95-4759-9c0f-ae713062040a-4.exe - Powered by Reason Core Security