dpcextsetup.exe

CR7 Team (Bright Circle Investments Ltd)

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application dpcextsetup.exe by CR7 Team (Bright Circle Investments) has been detected as adware by 33 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:

MD5:
fc5b1216d4ef1940aa98cedcbf5b38d6

SHA-1:
62362345ab22df787f9e54e25e47d696230cd774

SHA-256:
827c0554e00e8711825e73b00ef4319d6813f19d7bdfecda1eb6cb781561f7d5

Scanner detections:
33 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements. Distributed through the Brightcircle investments brand.

Analysis date:
4/25/2024 11:10:53 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Zusy.127996
675

AhnLab V3 Security
PUP/Win32.CrossRider
2015.03.28

avast!
Win32:Adware-gen [Adw]
2014.9-150401

AVG
Generic_r
2016.0.3153

Bitdefender
Gen:Variant.Adware.Zusy.127996
1.0.20.455

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
TrojWare.Win32.TrojanDropper.Addrop.A
21560

Dr.Web
Trojan.Crossrider1.23077
9.0.1.091

Emsisoft Anti-Malware
Gen:Variant.Adware.Zusy.127996
8.15.04.01.11

ESET NOD32
Win32/TrojanDropper.Addrop (variant)
9.11388

Fortinet FortiGate
W32/Addrop.A!tr
4/1/2015

F-Prot
W32/S-7dbe4916
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Zusy
11.2015-01-04_4

G Data
Gen:Variant.Adware.Zusy.127996
15.4.25

IKARUS anti.virus
Trojan-Dropper.Win32.Addrop
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.202.15407

Kaspersky
Trojan-Dropper.Win32.Agent
14.0.0.2258

Malwarebytes
v2015.04.01.11

McAfee
Artemis!FC5B1216D4EF
5600.6809

MicroWorld eScan
Gen:Variant.Adware.Zusy.127996
16.0.0.273

NANO AntiVirus
Trojan.Win32.Agent.dorknv
0.30.8.659

nProtect
Trojan-Dropper/W32.Agent.211872.C
15.03.27.01

Panda Antivirus
Trj/Genetic.gen
15.04.01.11

Qihoo 360 Security
HEUR/QVM20.1.Malware.Gen
1.0.0.1015

Quick Heal
TrojanDropper.Agent.r2
4.15.14.00

Reason Heuristics
Adware.BrightCircle.Installer
15.4.1.12

Rising Antivirus
PE:Malware.CrossRider!6.1CE3
23.00.65.15330

Sophos
Generic PUA GC
4.98

Trend Micro House Call
TROJ_GEN.F0C2C00C515
7.2.91

Trend Micro
TROJ_GEN.F0C2C00C515
10.465.01

Vba32 AntiVirus
TrojanDropper.Agent
3.12.26.3

VIPRE Antivirus
Crossrider
38834

ViRobot
Trojan.Win32.Agent.207280[h]
2014.3.20.0

File size:
206.9 KB (211,872 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\doctorpclab.com\dpcextsetup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/16/2014 1:00:00 AM

Valid to:
12/17/2015 12:59:59 AM

Subject:
CN=CR7 Team (Bright Circle Investments Ltd), O=CR7 Team (Bright Circle Investments Ltd), STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FBFD4A5FBC2F4538E5DF7603F1B0A48C

File PE Metadata
Compilation timestamp:
2/1/2015 7:46:10 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:Px+lnVLQcSs3O5imkPqNIpjqNgNYrGWsnKjtn7:JutIXkiqpjQIOsngl7

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, A0, 00, 00, 00, C7, 45, F4, 00, 00, 00, 00, EB, 09, 8B, 45, F4, 83, C0, 01, 89, 45, F4, 81, 7D, F4, 80, 00, 00, 00, 7D, 12, B9, 01, 00, 00, 00, 6B, D1, 00, C6, 84, 15, 60, FF, FF, FF, 00, EB, DC, 68, 80, 00, 00, 00, 8D, 85, 60, FF, FF, FF, 50, 6A, 00, FF, 15, 14, 20, 40, 00, 6A, 00, 68, 80, 00, 00, 00, 6A, 02, 6A, 00, 6A, 00, 68, 00, 00, 00, 40, 68, 52, 20, 40, 00, FF, 15, 1C, 20, 40, 00, 89, 45, E8, 0F, B7, 0D, 2C, 20, 40, 00, 89, 4D, F0, 8B, 55, F0, C1, E2, 04, 89, 55, F0, A1, 4E, 20...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
512 Bytes (512 bytes)

Remove dpcextsetup.exe - Powered by Reason Core Security