Brightcircle Investments Limited

Publisher Information

Brightcircle Investments Limited is a software publisher located in Nicosia, Strovolos in CY*. The company is a primary distributor of unwanted software. Part of the Brightcircle group of adware web browser extensions that utilize the Crossrider framework. These extensions are also known as Freven and are designed to utilize the framework in order to inject advertising banners in the underlying web browsers white space or by overlaying new ads over existing ones. Brightcircle distributes its software through malvertising practices such as displaying web pages taht tell the user that various core Windows software is out-dated and needs updating as well as drive-by downloads.
Remove Brightcircle Investments Limited Malware - Powered by Reason Core Security
Authority:
GoDaddy.com, Inc.

Valid from:
3/8/2013 10:33:54 AM

Valid to:
3/8/2016 10:33:54 AM

Subject:
CN=Brightcircle Investments Limited, O=Brightcircle Investments Limited, L=Nicosia, S=Strovolos, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
047f36483dc84c

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.Crossrider.Brightcircle (M), PUP.Brightcircle.BrightcircleInvestments (M), PUP.Brightcircle.BrightcircleInvestments.Installer (M), Adware.Crossrider.Brightcircle.Installer (M)
100.00%

Malwarebytes
PUP.Optional.Feven.A, PUP.Optional.PlusHD.A
26.00%

VIPRE Antivirus
Crossrider, Threat.4789396
26.00%

McAfee Web Gateway
Adware-AddLyrics, Artemis!C98EA20543E3, Artemis!09E1271B51C6, PUP-FEJ!4D187F33C868
26.00%

McAfee
Adware-AddLyrics, Artemis!C98EA20543E3, Program.Adware-AddLyrics, Artemis!09E1271B51C6, PUP-FEJ!4D187F33C868
26.00%

AVG
Generic_r, Generic5, Adware Generic5, MalSign.Skodna, MultiBundle.N
26.00%

K7 Gateway Antivirus
Unwanted-Program , Riskware , Trojan
24.00%

Dr.Web
Trojan.Crossrider1.23864, Trojan.Crossrider.27, Trojan.Crossrider.6, Trojan.Crossrider.1, Adware.Siggen.31030, Trojan.Crossrider.950
22.00%

G Data
Gen:Application.Heur.Eu1@m0UGdFaO, Gen:Application.Heur.vu1@mmAFd2kO, Adware.AddLyrics.AO, Win32.Adware.Crossrider, Adware.CrossRider
22.00%

ESET NOD32
Win32/Toolbar.CrossRider.J potentially unwanted (variant), Win32/Toolbar.CrossRider (variant), Win64/Toolbar.Crossrider (variant)
22.00%

1 / 68      (Adware)
feven 1.1-firefoxinstaller.exe (Feven 1.1 by Feven)  (5928287a6627b099e6b341aecbbc680f)

19 / 68    (Adware)
feven 1.5-buttonutil64.exe (Feven 1.5 by Feven)  (425b210930efc6d3c8df5ff9b095be60)

1 / 68      (Adware)
feven 1.5-buttonutil64.dll  (1f540c4a424fbf88b4bbfd38cd685d81)

1 / 68      (Adware)
feven 1.5-buttonutil.dll  (c720a1012394d1016992072d41531160)

1 / 68      (Adware)
feven.exe (Ubifaallhld by Pxupbfnfcgmwee)  (f716fd5398b778732a596c0c8e05d625)

1 / 68      (Adware)
feven 1.1-buttonutil64.exe (Feven 1.1 by Feven)  (8f54a7899445cb3001109bd77663895b)

1 / 68      (Adware)
feven 1.1-buttonutil64.dll  (00886250f6d19a535ab7275ca6c3b95a)

25 / 68    (Adware)
feven 1.5-firefoxinstaller.exe (Feven 1.5 by Feven)  (fc07907b9788b73fc38cf39a820d3032)

28 / 68    (Adware)
feven 1.5-chromeinstaller.exe (Feven 1.5 by Feven)  (25d25fd9addd00d6bb0213423671e9b3)

1 / 68      (Adware)
uninstall.exe  (273cbba079657632021fe8c232e29413)

1 / 68      (Adware)
feven 1.1-helper.exe  (81091a2a2075caf2004965d8cccb84b8)

1 / 68      (Adware)
feven 1.1-firefoxinstaller.exe (Feven 1.1 by Feven)  (862ac35063c1c4a2e254fb9a464b7fdb)

1 / 68      (Adware)
feven 1.1-buttonutil.exe (Feven 1.1 by Feven)  (4937c5af00c45be35e671af39a2a75fd)

1 / 68      (Adware)
feven 1.1-buttonutil.dll  (6e6bd980d31c7dd829707c605937cc37)

1 / 68      (Adware)
feven 1.7-buttonutil64.dll  (aa906b167b904b2b6400c3d8f4452517)

1 / 68      (Adware)
feven 1.5-firefoxinstaller.exe (Feven 1.5 by Feven)  (3605d3198191f684cadbed6b7e8ebecd)

28 / 68    (Adware)
feven 1.5-chromeinstaller.exe (Feven 1.5 by Feven)  (51191e6f57fe8e44609d8b005e4e463b)

19 / 68    (Adware)
feven 1.5-buttonutil64.exe (Feven 1.5 by Feven)  (6109cec3d2519c21b1caa3b8c9b5f6ed)

1 / 68      (Adware)
feven 1.5-buttonutil64.dll  (c99d5a8ebfc5fbb8885b7a7e3ce479e5)

1 / 68      (Adware)
feven 1.2-buttonutil64.dll  (1fb2433a829fce997f21495a93caef7b)

1 / 68      (Adware)
feven 1.2-bho64.dll (Feven 1.2 by Feven)  (2b521fb9461090b4c393a39dd092e944)

1 / 68      (Adware)
feven 1.1-helper.exe  (09e790e16a89429e103d4f10199c511c)

1 / 68      (Adware)
feven 1.1-buttonutil64.exe (Feven 1.1 by Feven)  (44fe470693a8812ff656496d4d7efe79)

1 / 68      (Adware)
feven 1.1-buttonutil64.dll  (8aa4048b39631bafa4934309c946d423)

1 / 68      (Adware)
feven 1.1-buttonutil.exe (Feven 1.1 by Feven)  (f4078a420bf628819c58fc4b9a1b04df)

1 / 68      (Adware)
feven 1.1-buttonutil.dll  (24af3c09fdca719c8ad8fc8f59d8e9a0)

1 / 68      (Adware)
feven 1.1-bho64.dll (Feven 1.1 by Feven)  (cbd5c33775ecf05a35634043a81b74a5)

1 / 68      (Adware)
feven 1.1-bg.exe (Feven 1.1 by Feven)  (c47ad00caf94913f6a0eaff06868bbd7)

21 / 68    (Adware)
feven 1.7-bg.exe (Feven 1.7 by Feven)  (9e0c8f50f55848f2177276aaa89bb6fb)

1 / 68      (Adware)
feven 1.1-helper.exe  (63b7374cfbbeb5aefcd0060930c6eaef)

 
Latest 30 of 431 files

The following publishers (by Authenticode signature organization name) are related.

Remove Brightcircle Investments Limited Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Brightcircle Investments Limited by GoDaddy.com, Inc. on March 08, 2013 with the serial number '047f36483dc84c'.