HDPlus-V1.9

HDPlus-V1.9

Known Adware

by Bright circle investments Ltd.

What is HDPlus-V1.9?

HDPlus-V1.9 is software application developed by Bright circle investments Ltd.. It is most commonly found on computers running Windows 7 with nearly 47.56% of installations running this operating system. HDPlus-V1.9's installer is typically 3.00 MB in size and installs around 23 files.

HDPlus-V1.9 is most popular in the United States with 9.82% of installations residing in this country.

HDPlus-V1.9 adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About HDPlus-V1.9?

Freeven HDPlus is a program that operates as adware within the user's web browser, making modifications to various browser settings including the search provider. Moreover, this adware injects display ads in the browser by introducing new banner ads and additional advertisements on top of existing ones, as well as inserting hyper-text links to display popup ad formats. These displayed ads are generally low quality and are not related to the underlying website being visited by the user. Removing HDPlus through the standard installer provided can be challenging as it may only remove certain parts of the program and fail to reset items such as hijacked search and home pages.

Multiple virus scanners have detected malware in HDPlus-V1.9.

utils.exe (MD5: f3c5f72b7687052b5ecec4f6f3224594) has been flagged by 42 scanners:
Scanner Software Result
Agnitum Outpost Trojan.Crossrider
AhnLab-V3 PUP/Win32.Solimba
Avira ADWARE/CrossRider.Gen2
Bkav FE HW32.Paked
Dr.Web Trojan.Crossrider.27982
G Data NSIS.Adware.Crossrider
IKARUS anti.virus AdWare.CrossRider
Malwarebytes PUP.Optional.CrossRider.A
NANO AntiVirus Trojan.Win32.Crossrider.deusvz
Qihoo-360 HEUR/Malware.QVM20.Gen
SUPERAntiSpyware Adware.Crossrider/Variant
Symantec WS.Reputation
Trend Micro ADW_CROSSRIDER
TrendMicro-HouseCall ADW_CROSSRIDER
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.444130
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
avast! Win32:Crossrider-AB [PUP]
AVG Brightcircle.599
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BAJ
Bitdefender Gen:Variant.Adware.Kazy.444130
Clam AntiVirus Win.Adware.Agent-8181
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.444130 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/S-9ad4719b!Eldorado
F-Secure Gen:Variant.Adware.Kazy.444130
K7 AntiVirus Trojan ( 0049ee4f1 )
K7GW Trojan ( 0049ee4f1 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.baz
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!61B095D5C8B2
McAfee-GW-Edition BehavesLike.Win32.BadFile.hh
MicroWorld-eScan Gen:Variant.Adware.Kazy.444130
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
VIPRE Antivirus Crossrider (fs)
ViRobot Adware.Agent.532024
Zillya Backdoor.PePatch.Win32.38322
Avira AntiVir ADWARE/CrossRider.Gen2
HDPlus-V1.9-nova.exe (MD5: 8162d28b5c288e9a8bce4d33253580da) has been flagged by 32 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.Toolbar
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
AVG Generic_r.PP
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossRider.bAE
Clam AntiVirus Win.Adware.961710
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AE
Fortinet FortiGate Riskware/Toolbar_CrossRider
IKARUS anti.virus PUA.PlusHD
K7 AntiVirus Trojan ( 0049ad331 )
K7GW Trojan ( 0049ad331 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.baz
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!8162D28B5C28
McAfee-GW-Edition BehavesLike.Win32.PUP.jh
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.0ea
Sophos Generic PUA LH
Symantec Trojan.ADH.2
Trend Micro ADW_CRORI
TrendMicro-HouseCall ADW_CRORI
VIPRE Antivirus Crossrider (fs)
Zillya Adware.AdLoad.Win32.266
Agnitum Outpost PUA.Toolbar.CrossRider!
Dr.Web Trojan.Crossrider.27985
NANO AntiVirus Riskware.Win32.AdLoad.dcbpei
F-Prot W32/S-9ad4719b!Eldorado
G Data Win32.Adware.Crossrider.L
Rising Antivirus PE:Malware.Obscure!1.9C59
Avira AntiVir ADWARE/CrossRider.Gen2
HDPlus-V1.9-codedownloader.exe (MD5: 61b095d5c8b2b88bc15bd697dab1c190) has been flagged by 40 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.444130
AhnLab-V3 PUP/Win32.Solimba
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
avast! Win32:Crossrider-AB [PUP]
AVG Brightcircle.599
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BAJ
Bitdefender Gen:Variant.Adware.Kazy.444130
Clam AntiVirus Win.Adware.Agent-8181
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.27741
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.444130 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/S-9ad4719b!Eldorado
F-Secure Gen:Variant.Adware.Kazy.444130
G Data Gen:Variant.Adware.Kazy.444130
K7 AntiVirus Trojan ( 0049ee4f1 )
K7GW Trojan ( 0049ee4f1 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.baz
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!61B095D5C8B2
McAfee-GW-Edition BehavesLike.Win32.BadFile.hh
MicroWorld-eScan Gen:Variant.Adware.Kazy.444130
NANO AntiVirus Riskware.Win32.AdLoad.dcbjmf
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.d46
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Symantec Trojan.ADH.2
Trend Micro TROJ_FRS.PMA000I214
TrendMicro-HouseCall TROJ_FRS.PMA000I214
VIPRE Antivirus Crossrider (fs)
ViRobot Adware.Agent.532024
Zillya Backdoor.PePatch.Win32.38322
IKARUS anti.virus PUA.CrossRider
SUPERAntiSpyware Trojan.Agent/Gen-Plush
Agnitum Outpost PUA.Toolbar.CrossRider!
Avira AntiVir ADWARE/CrossRider.Gen2
HDPlus-V1.9-bho.dll (MD5: e2c0b161b0095af036e738dc1e93c5e2) has been flagged by 32 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.Toolbar
AVG Brightcircle.599
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossRider.bAF
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AF
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-60e5da54!Eldorado
G Data Win32.Adware.Crossrider.K
IKARUS anti.virus AdWare.Plush
K7 AntiVirus Trojan ( 0049b8981 )
K7GW Trojan ( 0049b8981 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.baz
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!E2C0B161B009
McAfee-GW-Edition BehavesLike.Win32.PUP.hh
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.bcb
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Symantec Trojan.ADH.2
Trend Micro ADW_RIDECROSS
TrendMicro-HouseCall ADW_RIDECROSS
VIPRE Antivirus Crossrider (fs)
Zillya Backdoor.PePatch.Win32.38483
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
Clam AntiVirus Win.Adware.961710
Agnitum Outpost PUA.Toolbar.CrossRider!
Dr.Web Trojan.Crossrider.27985
NANO AntiVirus Riskware.Win32.AdLoad.dcbpei
Avira AntiVir ADWARE/CrossRider.Gen2
ea32a6d0-67de-418e-ac46-dd40f9ff034b-5.exe (MD5: 06c380aa79ff24518e4f9de79f8371e7) has been flagged by 12 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.CrossRider
Avira AntiVir Adware/CrossRider.A.18034
AVG Brightcircle.599
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
IKARUS anti.virus AdWare.Adload
NANO AntiVirus Riskware.Win32.AdLoad.dbqzhb
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.c52
Rising Antivirus PE:Malware.Obscure!1.9C59
VIPRE Antivirus Crossrider (fs)
F-Prot W32/A-eb9ef301!Eldorado
Sophos AppRider

Software Behaviors

Scheduled tasks:
  • ea32a6d0-67de-418e-ac46-dd40f9ff034b-2.exe is scheduled as a task named 'temp_ea32a6d0-67de-418e-ac46-dd40f9ff034b-2'.

Startup Entries

Startup tasks:
  • 076aded5-f718-45da-bdbb-b0e2050f5529-4.exe is automatically launched at startup through a scheduled task named 076aded5-f718-45da-bdbb-b0e2050f5529-4.
  • 076aded5-f718-45da-bdbb-b0e2050f5529-11.exe is automatically launched at startup through a scheduled task named 076aded5-f718-45da-bdbb-b0e2050f5529-3.
  • HDPlus-V1.9-codedownloader.exe is automatically launched at startup through a scheduled task named ea32a6d0-67de-418e-ac46-dd40f9ff034b-6.
  • HDPlus-V1.9-nova.exe is automatically launched at startup through a scheduled task named ea32a6d0-67de-418e-ac46-dd40f9ff034b-7.
  • ea32a6d0-67de-418e-ac46-dd40f9ff034b-5.exe is automatically launched at startup through a scheduled task named ea32a6d0-67de-418e-ac46-dd40f9ff034b-5_user.
  • ea32a6d0-67de-418e-ac46-dd40f9ff034b-4.exe is automatically launched at startup through a scheduled task named ea32a6d0-67de-418e-ac46-dd40f9ff034b-4.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\hdplus-v1.9
Uninstaller:
C:\Program Files\HDPlus-V1.9\Uninstall.exe /fcp=1
Size:
3.00 MB
Language:
English

HDPlus-V1.9 Executable Details

Primary executable:
utils.exe
Name:
HDPlus-V1.9
Path:
C:\Program Files\hdplus-v1.9\utils.exe
MD5:
f3c5f72b7687052b5ecec4f6f3224594
SHA-1:
–
SHA-256:
–
Files installed by HDPlus-V1.9
File Type Filename MD5
EXE
bf85fa2bc7f2751bddc939b247743f6e
EXE
f3c5f72b7687052b5ecec4f6f3224594
DLL
3c283060cc8636698dd16bebf50e50a6
XPI
0a95080ac83922e8de767499037118a4
CRX
43d5dabc615319c99ea627a133ee5cae
CRX
6b81fbc7bef1c3f85041a70147e73f14
EXE
8162d28b5c288e9a8bce4d33253580da
EXE
61b095d5c8b2b88bc15bd697dab1c190
DLL
5e78d0047b004c4fdda91f9556c1bd05
DLL
e2c0b161b0095af036e738dc1e93c5e2