Berta Dress Apps (Bright Circle Investments Ltd)

Publisher Information

Berta Dress Apps (Bright Circle Investments Ltd) is a software publisher located in Nicosia, CY*. The company is a primary distributor of unwanted software. Part of the Brightcircle group of adware web browser extensions that utilize the Crossrider framework. These extensions are also known as Freven and are designed to utilize the framework in order to inject advertising banners in the underlying web browsers white space or by overlaying new ads over existing ones. Brightcircle distributes its software through malvertising practices such as displaying web pages taht tell the user that various core Windows software is out-dated and needs updating as well as drive-by downloads.
Authority:
COMODO CA Limited

Valid from:
12/16/2014 1:00:00 AM

Valid to:
12/17/2015 12:59:59 AM

Subject:
CN=Berta Dress Apps (Bright Circle Investments Ltd), O=Berta Dress Apps (Bright Circle Investments Ltd), STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009c113f566de374d0ef1f22b0b717d3dc

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.BrightCircle (M), Adware.Crossrider (M), PUP.Brightcircle (M)
100.00%

1 / 68      (Adware)
winservice86-bho64.dll (winservice86 by Corporate Inc)  (b6644d8db60c95471490178ca67661d4)

1 / 68      (Adware)
winservice86-bho.dll (winservice86 by Corporate Inc)  (15605e6a9d2f48f82966f58388ba8e46)

1 / 68      (Adware)
iydfltydgmhdtk.exe (by Ercknlpju)  (f8bede0e026ba4f81da887a83cf35f1d)

1 / 68      (Adware)
441040 (CinemaHd For Pro 2.4cV17.01 by Cinema HDV17.01)  (a24fbe6ec8ac46bb1c0cdf7bce3072df)

1 / 68      (Adware)

1 / 68      (Adware)
feqhyhqlkwkl.exe (by Rnafjnn)  (e29d32dffbe3161022550dd298330e0a)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
WebSocket4Net.dll (WebSocket4Net)  (dc67e4ee54ac048883061114e9280ab3)

1 / 68      (Adware)
Newtonsoft.Json.dll (Json.NET by Newtonsoft)  (92522e4c36bc5f1721d25313ee7da2e8)

1 / 68      (Adware)

1 / 68      (Adware)
caf6c60f-6026-4d9f-9eaa-84ec01ab24f6.exe (Torpedo)  (18e9e367740b4534523d22141861c172)

1 / 68      (Adware)

1 / 68      (Adware)
uninstall.exe  (0a09686c33ce5cbc4960b6bc8351a3e7)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
97a0975f-d372-4328-adeb-87f2a289ab01.dll  (46020eab3990075e914b8c475f3dd47d)

1 / 68      (Adware)
85533611-1471-4fb3-919f-ba7fd8bd01b2.dll  (41e5c5c46e4c46d86dea223a48979566)

1 / 68      (Adware)
farrvcxtlki.exe (by Fiionjycnw)  (48be671b7075990621d63d774e86cf15)

1 / 68      (Adware)
32633.exe (Id-Sxdles by Kjsaxviwxpxakn & co)  (242ba4ee2444a0c8f4ba73dbce91f37f)

1 / 68      (Adware)

1 / 68      (Adware)
jatjlmn.exe (HD-Quality-3.1V19.01)  (b3457768b44f6e0c52e2717693b59462)

1 / 68      (Adware)
browserv3appplus-bg.exe (BrowserV3AppPlus by BRWApServV2)  (902f87b2b79a06e6c19ffcfdbecbd30a)

1 / 68      (Adware)
uninstall.exe  (48de135da6a180908827f40218d6d28e)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
2f6543d4-7d42-4ad5-87c1-0f3f7f89a761.dll  (9f913411febea7f406f9c354f9159dc2)

1 / 68      (Adware)

1 / 68      (Adware)

 
Latest 30 of 6,478 files

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to Berta Dress Apps (Bright Circle Investments Ltd) by COMODO CA Limited on December 16, 2014 with the serial number '009c113f566de374d0ef1f22b0b717d3dc'.