BWSRappSev2

BWSRappSev2

Known Adware

by BrightCircle Investments Limited

What is BWSRappSev2?

BWSRappSev2 is software application developed by BrightCircle Investments Limited. It is most commonly found on computers running Windows 10 with nearly 80.00% of installations running this operating system. BWSRappSev2's installer is typically 7.00 MB in size and installs around 10 files.

BWSRappSev2 is most popular in the United States with 50.00% of installations residing in this country.

About BWSRappSev2?

Our software is an adware program that functions as a web browser plugin, designed to inject and display advertisements to the user. This includes various forms of ads such as banner ads, text-links, coupons, and other offers. The program delivers these ads by injecting them into the user's web browser, as well as displaying popups outside of the browser.

Multiple virus scanners have detected malware in BWSRappSev2.

utils.exe (MD5: 7b3e7c047cc43b0b30ca4c51cc6b0a75) has been flagged by 42 scanners:
Scanner Software Result
Agnitum Outpost Riskware.VMDetector
avast! Win32:Malware-gen
Baidu-International PUA.Win32.CrossRider.bBW
Bkav FE HW32.Packed
Dr.Web Trojan.Crossrider1.9878
ESET-NOD32 Win32/Packed.VMDetector.I potentially unwanted
Fortinet FortiGate PossibleThreat
G Data NSIS.Adware.Crossrider
Malwarebytes PUP.Optional.CrossRider.A
McAfee Artemis!7B3E7C047CC4
McAfee-GW-Edition Artemis
NANO AntiVirus Trojan.Win32.MLW.dmvkgg
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM20.1.Malware.Gen
Symantec WS.Reputation
TrendMicro-HouseCall Suspicious_GEN.F47V0123
Lavasoft Ad-Aware Gen:Application.Heur.6u1@mqm5g9hO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.ljd
Arcabit Application.Heur.E36A6D
AVG Generic.9A1
Avira ADWARE/CrossRider.ZZ
AVware Crossrider (fs)
Bitdefender Gen:Application.Heur.6u1@mqm5g9hO
CAT-QuickHeal PUA.BrightCircle.OD6
Comodo Security Application.Win32.CrossRider.KS
Cyren W32/S-95be3f30!Eldorado
F-Prot W32/S-95be3f30!Eldorado
F-Secure Gen:Application.Heur.6u1@mqm5g9hO
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
K7 AntiVirus Trojan ( 0040f9ff1 )
K7GW Unwanted-Program ( 0040f9ff1 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.ljd
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
MicroWorld-eScan Gen:Application.Heur.6u1@mqm5g9hO
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos Generic PUA IJ
SUPERAntiSpyware Adware.CrossRider/Variant
Tencent Trojan.Win32.Qudamah.Gen.3
Trend Micro TROJ_GEN.F0C2C00AU15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2309
BWSRappSev2-codedownloader.exe (MD5: a4cba6c7020c0ce30059d233ef8b5a0e) has been flagged by 17 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.fv1@m0aO0QjO
AhnLab-V3 PUP/Win32.CrossRider
AVG Generic.9A1
Avira ADWARE/CrossRider.Gen4
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.bBM
Bitdefender Gen:Application.Heur.fv1@m0aO0QjO
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.BM
F-Secure Gen:Application.Heur.fv1@m0aO0QjO
G Data Gen:Application.Heur.fv1@m0aO0QjO
IKARUS anti.virus Gen.Application.Heur
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.ljd
MicroWorld-eScan Gen:Application.Heur.fv1@m0aO0QjO
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Tencent Win32.Adware.Bp-browser.Luqs
VIPRE Antivirus Crossrider (fs)
BWSRappSev2-bho.dll (MD5: e019060aeeb55026f3476c933260f449) has been flagged by 41 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.My9@mSCkk9ei
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.ljd
Arcabit Application.Heur.ED9EB5
avast! Win32:Crossrider-CC [PUP]
AVG Toolbar.Crossrider.Y
Avira ADWARE/CrossRider.ZZ
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.BA
Bitdefender Gen:Application.Heur.My9@mSCkk9ei
Bkav FE W32.HfsAdware.BDE5
CAT-QuickHeal PUA.BrightCircle.OD6
Comodo Security Application.Win32.CrossRider.BMK
Cyren W32/S-c19140ac!Eldorado
Dr.Web Trojan.Crossrider1.23042
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.BA potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/S-c19140ac!Eldorado
F-Secure Gen:Application.Heur.My9@mSCkk9ei
G Data Gen:Application.Heur.My9@mSCkk9ei
K7 AntiVirus Trojan ( 004af5321 )
K7GW Trojan ( 004af5321 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.ljd
Malwarebytes PUP.Optional.InstallCore.C
McAfee Artemis!E019060AEEB5
McAfee-GW-Edition BehavesLike.Win32.BadFile.jh
MicroWorld-eScan Gen:Application.Heur.My9@mSCkk9ei
NANO AntiVirus Trojan.Win32.Crossrider1.dnlyho
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos Generic PUA DN
Symantec Adware.Crossid
Tencent Trojan.Win32.Qudamah.Gen.13
Trend Micro TROJ_GEN.R0C1C0OB915
TrendMicro-HouseCall TROJ_GEN.R0C1C0OB915
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2952
SUPERAntiSpyware Adware.CrossRider/Variant
IKARUS anti.virus Gen.Application.Heur
9ccba8ed-8ce2-4b0a-8136-661ea57bb541-5.exe (MD5: 4e242074fa342866048e0a004a9fedb0) has been flagged by 38 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.jv1@mupW0JeO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.ljd
Arcabit Application.Heur.E4C2C8
avast! Win32:PUP-gen [PUP]
AVG Toolbar.Crossrider.AA
Avira ADWARE/CrossRider.ZZ
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.BM
Bitdefender Gen:Application.Heur.jv1@mupW0JeO
Bkav FE W32.HfsAdware.BDE5
CAT-QuickHeal PUA.BrightCircle.OD6
Cyren W32/Application.GIQQ-0506
Dr.Web Trojan.Crossrider1.23042
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CC potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Secure Gen:Application.Heur.jv1@mupW0JeO
G Data Gen:Application.Heur.jv1@mupW0JeO
K7 AntiVirus Trojan ( 004afbb41 )
K7GW Trojan ( 004afbb41 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.ljd
Malwarebytes PUP.Optional.InstallCore.C
McAfee Artemis!4E242074FA34
McAfee-GW-Edition BehavesLike.Win32.BrowseFox.th
MicroWorld-eScan Gen:Application.Heur.jv1@mupW0JeO
NANO AntiVirus Riskware.Win32.CrossRider.dmvwjf
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Rising Antivirus PE:Malware.CrossRider!6.233A
Sophos Generic PUA MG
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.5
Trend Micro TROJ_GEN.R000C0OB915
TrendMicro-HouseCall TROJ_GEN.R000C0OB915
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2301
IKARUS anti.virus Gen.Application.Heur

Startup Entries

Startup tasks:
  • BWSRappSev2-codedownloader.exe is automatically launched at startup through a scheduled task named 9ccba8ed-8ce2-4b0a-8136-661ea57bb541-1.
  • 9ccba8ed-8ce2-4b0a-8136-661ea57bb541-5.exe is automatically launched at startup through a scheduled task named 9ccba8ed-8ce2-4b0a-8136-661ea57bb541-5_user.
  • 9ccba8ed-8ce2-4b0a-8136-661ea57bb541-2.exe is automatically launched at startup through a scheduled task named 9ccba8ed-8ce2-4b0a-8136-661ea57bb541-2.

Software Details

URL:
Support:
Installation path:
C:\Program Files\bwsrappsev2
Uninstaller:
C:\Program Files\BWSRappSev2\Uninstall.exe /fcp=1
Size:
7.00 MB
Language:
English

BWSRappSev2 Executable Details

Primary executable:
utils.exe
Name:
BWSRappSev2
Path:
C:\Program Files\bwsrappsev2\utils.exe
MD5:
7b3e7c047cc43b0b30ca4c51cc6b0a75
SHA-1:
SHA-256:
Files installed by BWSRappSev2
File Type Filename MD5
EXE
937f5e244af05acdc64635685909978d
EXE
7b3e7c047cc43b0b30ca4c51cc6b0a75
XPI
cd4a24fdc9626c500ffb9b394229cd68
XPI
1cc9969871da1a5e8045a18f3712e411
EXE
ab3c991e172f1bac99d0f5906ad9fd85
EXE
a4cba6c7020c0ce30059d233ef8b5a0e
DLL
c450dfdad7f1f89271e63de4a2afebce
DLL
e019060aeeb55026f3476c933260f449
EXE
bfa9e31aeea152de96c750e49d17efae
EXE
4e242074fa342866048e0a004a9fedb0