browserappsplus2.1-bg.exe

BrowserAppsPlus2.1

BadFinger Project (BrightCircle Investments Limited)

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application browserappsplus2.1-bg.exe, “BrowserAppsPlus2.1 exe” by BadFinger Project (BrightCircle Investments Limited) has been detected as adware by 22 anti-malware scanners. Part of the Corssrider web browser platform, the BG executable is a background process that manage various function of the installed extensions in user's browser including managing installation, updates and remote code downloads. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
App  (signed by BadFinger Project (BrightCircle Investments Limited))

Product:
BrowserAppsPlus2.1

Description:
BrowserAppsPlus2.1 exe

Version:
1000.1000.1000.1000

MD5:
0dde7302d11d07ebbd9b1698c82ccbdb

SHA-1:
876c317182749b070dfe8d17aa1ca094d06b3b27

SHA-256:
6b2ac8a12d9567a22c40946cf827cc10e676ab8077ef34cf5cb24ced7519b639

Scanner detections:
22 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements. Distributed through the Brightcircle investments brand.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is BadFinger Project (BrightCircle Investments Limited).

Analysis date:
4/25/2024 10:22:32 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.Ou1@kqEwiNii
775

Avira AntiVirus
ADWARE/CrossRider.Gen7
7.11.195.126

AVG
Generic
2015.0.3253

Baidu Antivirus
PUA.Win32.CrossRider
4.0.3.141221

Bitdefender
Gen:Application.Heur.Ou1@kqEwiNii
1.0.20.1775

ESET NOD32
Win32/Toolbar.CrossRider.BA potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/CrossRider
12/21/2014

F-Secure
Gen:Application.Heur.Ou1@kqEwiNii
11.2014-21-12_1

G Data
Gen:Application.Heur.Ou1@kqEwiNii
14.12.24

K7 AntiVirus
Unwanted-Program
13.188.14395

Kaspersky
not-a-virus:AdWare.NSIS.Adwapper
15.0.0.543

Malwarebytes
PUP.Optional.BrowserAppsPlus.A
v2014.12.21.10

McAfee
Artemis!D9C2434DFA10
5600.6909

MicroWorld eScan
Gen:Application.Heur.Ou1@kqEwiNii
15.0.0.1065

NANO AntiVirus
Riskware.Win32.Crossrider.djqngq
0.28.6.63850

Panda Antivirus
Trj/Genetic.gen
14.12.21.10

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Crossrider.BadFingerProjectBrightCircleInvestmentsLimited.U
14.12.21.22

Rising Antivirus
PE:Malware.Obscure!1.9C59
23.00.65.141219

Sophos
Generic PUA EG
4.98

Trend Micro House Call
Suspicious_GEN.F47V1212
7.2.355

VIPRE Antivirus
Crossrider
35730

File size:
605.5 KB (620,000 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
BrowserAppsPlus2.1.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\browserappsplus2.1\browserappsplus2.1-bg.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/16/2014 4:00:00 PM

Valid to:
11/17/2015 3:59:59 PM

Subject:
CN=BadFinger Project (BrightCircle Investments Limited), O=BadFinger Project (BrightCircle Investments Limited), STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6623FAFCAC357577A31D90C1E567E9A7

File PE Metadata
Compilation timestamp:
12/14/2014 5:07:13 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:v7GCX0FIqXhInr11rldDo6xqQPpTaVyiA:v7dSBarvZdnqQhTN

Entry address:
0x52115

Entry point:
E8, A2, C7, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 98, 0B, 49, 00, E8, 55, 49, 00, 00, E8, C9, 1C, 00, 00, 0F, B7, F0, 6A, 02, E8, 35, C7, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 25, 4F, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.4659

Code size:
477 KB (488,448 bytes)

Remove browserappsplus2.1-bg.exe - Powered by Reason Core Security