V-9.1HD

V-9.1HD

Known Adware

by Evangelion Group

What is V-9.1HD?

V-9.1HD is software application developed by Evangelion Group. It is most commonly found on computers running Windows 10 with nearly 47.17% of installations running this operating system. V-9.1HD's installer is typically 11.00 MB in size and installs around 265 files. The most common release is 1.35.3.9 with 28.30% of all installations currently using this version.

V-9.1HD is most popular in the United States with 31.25% of installations residing in this country.

About V-9.1HD?

Plus-HD-9.1c (Freeven) is a program known for its adware behavior, affecting web browsers by altering settings and injecting display ads. It may modify search provider settings and insert new banner ads or additional advertisements on webpages. Moreover, it can generate pop-up ad formats through hyper-text links. The advertisements are generally of low quality and are not relevant to the visited webpages. Removing this adware can be challenging through the standard installer, as it may not fully reset the affected browser settings.

Multiple virus scanners have detected malware in V-9.1HD.

64a7e692-8af9-461d-a40f-a7856dfff1f2.exe (MD5: 33df16899fe25a6c4636b88fcb89a647) has been flagged by 46 scanners:
Scanner Software Result
AhnLab-V3 Win-PUP/CrossRider
Antiy-AVL Trojan/NSIS.GoogUpdate
avast! Win32:Crossrider-AI [PUP]
AVG Generic.727
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BAG
CAT-QuickHeal Trojan.NSIS.r5
Dr.Web Trojan.Crossrider.32360
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AG
Fortinet FortiGate W32/GoogUpdate.AG!tr
F-Prot W32/S-9ad4719b!Eldorado
G Data Win32.Adware.Crossrider.R
K7 AntiVirus Unwanted-Program ( 004a9d081 )
K7GW Unwanted-Program ( 004a9d081 )
Kaspersky Trojan.NSIS.GoogUpdate.ck
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Malwarebytes PUP.Optional.PlusH.A
McAfee Artemis!33DF16899FE2
McAfee-GW-Edition BehavesLike.Win32.BadFile.fh
NANO AntiVirus Trojan.Win32.Crossrider.deuylg
nProtect Trojan/W32.Agent.336752
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Sophos AppRider
Symantec Trojan.Gen
Trend Micro TROJ_GEN.R0C1C0EJO14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJO14
Vba32 AntiVirus AdWare.Adwapper
VIPRE Antivirus Crossrider (fs)
Zillya Adware.Adwapper.Win32.62
Clam AntiVirus Win.Adware.Crossrider-93
Tencent Nsis.Trojan.Googupdate.Swkz
Agnitum Outpost PUA.Toolbar.CrossRider!
Comodo Security ApplicUnwnt
Rising Antivirus PE:Trojan.Win32.Generic.177B991A!393976090
Panda Antivirus Trj/Genetic.gen
Lavasoft Ad-Aware Gen:Variant.Adware.Plush.2
Bitdefender Gen:Variant.Adware.Plush.2
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.2 (B)
F-Secure Gen:Variant.Adware.Plush.2
IKARUS anti.virus Trojan.GoogUpdate
MicroWorld-eScan Gen:Variant.Adware.Plush.2
AegisLab Troj.W32.Vilsel
Avira AntiVir Adware/CrossRider.A.16680
Jiangmin Adware/Adload.ayz
SUPERAntiSpyware Trojan.Agent/Gen-Plush
4646bc31-612a-4a37-8b6a-57379082350b.exe (MD5: ad68822eb1494d0f98566cfcd93c5fe7) has been flagged by 37 scanners:
Scanner Software Result
avast! Win32:Crossrider-M [PUP]
AVG Generic.727
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.32360
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AG
F-Prot W32/S-9ad4719b!Eldorado
IKARUS anti.virus not-a-virus:AdWare.Adwapper
K7 AntiVirus Adware ( 004a90bc1 )
K7GW Adware ( 004a90bc1 )
Kaspersky Trojan.NSIS.GoogUpdate.ck
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Malwarebytes PUP.Optional.PlusHD.A
NANO AntiVirus Trojan.Win32.Crossrider.deuylg
Panda Antivirus Trj/Genetic.gen
Symantec WS.Reputation.1
Tencent Nsis.Trojan.Googupdate.Loro
VIPRE Antivirus Crossrider (fs)
Zillya Adware.Adwapper.Win32.62
Fortinet FortiGate W32/GoogUpdate.AN!tr
G Data Win32.Adware.Crossrider.L
McAfee Artemis!16C349C17A74
McAfee-GW-Edition BehavesLike.Win32.BadFile.dh
Qihoo-360 Win32/Trojan.921
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos Generic PUA OA
Baidu-International Adware.Win32.CrossRider.bAJ
Vba32 AntiVirus AdWare.AdLoad
AegisLab Troj.W32.Gen
AhnLab-V3 PUP/Win32.Toolbar
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
Jiangmin Adware/Adload.ayz
Avira AntiVir Adware/CrossRider.A.17879
TrendMicro-HouseCall Suspicious_GEN.F47V0708
SUPERAntiSpyware Trojan.Agent/Gen-Plush
nProtect Trojan/W32.Agent.1214832
Comodo Security ApplicUnwnt
44e236e4-ce71-4d11-84c3-0dca27ae587d-7.exe (MD5: 18ccd9e1e07eee2654b34510e1961541) has been flagged by 42 scanners:
Scanner Software Result
avast! Win32:Crossrider-M [PUP]
AVG Generic.727
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.31757
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AM
F-Prot W32/S-9ad4719b!Eldorado
IKARUS anti.virus Trojan.GoogUpdate
K7 AntiVirus Adware ( 004a90bb1 )
K7GW Adware ( 004a90bb1 )
Kaspersky Trojan.NSIS.GoogUpdate.ck
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Malwarebytes PUP.Optional.PlusHD.A
McAfee Artemis!18CCD9E1E07E
McAfee-GW-Edition Artemis
NANO AntiVirus Trojan.Win32.Crossrider.denouv
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA FN
Symantec WS.Reputation.1
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.2143
Lavasoft Ad-Aware Gen:Variant.Adware.Plush.1
AhnLab-V3 PUP/Win32.CrossRider
Bitdefender Gen:Variant.Adware.Plush.1
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
F-Secure Gen:Variant.Adware.Plush.1
G Data Gen:Variant.Adware.Plush.1
MicroWorld-eScan Gen:Variant.Adware.Plush.1
Qihoo-360 Win32/Trojan.921
Vba32 AntiVirus AdWare.Adwapper
Avira AntiVir Adware/CrossRider.A.16680
Tencent Nsis.Trojan.Googupdate.Dzty
AegisLab Troj.W32.Vilsel
Baidu-International PUA.Win32.CrossRider.bAJ
Rising Antivirus PE:Malware.Obscure!1.9C59
Fortinet FortiGate W32/GoogUpdate.AN!tr
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
Jiangmin Adware/Adload.ayz
TrendMicro-HouseCall Suspicious_GEN.F47V0708
SUPERAntiSpyware Trojan.Agent/Gen-Plush
nProtect Trojan/W32.Agent.1214832
Comodo Security ApplicUnwnt
44e236e4-ce71-4d11-84c3-0dca27ae587d-6.exe (MD5: c1fa9db431000c940678c7d2d599a48c) has been flagged by 44 scanners:
Scanner Software Result
Antiy-AVL Trojan/NSIS.GoogUpdate
avast! Win32:Crossrider-M [PUP]
AVG Generic.727
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AV
G Data Win32.Adware.Crossrider.N
K7 AntiVirus Unwanted-Program ( 004a9d061 )
K7GW Unwanted-Program ( 004a9d061 )
Kaspersky Trojan.NSIS.GoogUpdate.ck
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Malwarebytes PUP.Optional.PlusH.A
McAfee Artemis!C1FA9DB43100
McAfee-GW-Edition BehavesLike.Win32.BadFile.jh
NANO AntiVirus Riskware.Win32.Crossrider.dgeggn
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Sophos AppRider
Symantec Adware.Crossid
Trend Micro TROJ_GEN.R08NC0OJI14
TrendMicro-HouseCall TROJ_GEN.R08NC0OJI14
Vba32 AntiVirus AdWare.Adwapper
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.2142
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.444130
AegisLab Troj.Banker.W32.Lohmys
AhnLab-V3 Win-PUP/CrossRider
Baidu-International PUA.Win32.CrossRider.bAK
Bitdefender Gen:Variant.Adware.Kazy.444130
Dr.Web Trojan.Crossrider.28676
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.444130 (B)
F-Prot W32/S-9ad4719b!Eldorado
F-Secure Gen:Variant.Adware.Kazy.444130
MicroWorld-eScan Gen:Variant.Adware.Kazy.444130
Clam AntiVirus Win.Trojan.Crossrider-24
nProtect Trojan/W32.Agent.373104
Rising Antivirus PE:Malware.Obscure!1.9C59
IKARUS anti.virus PUA.CrossRider
Panda Antivirus Trj/Genetic.gen
Comodo Security Application.Win32.Plush.GRI
Avira AntiVir Adware/CrossRider.A.16680
Tencent Nsis.Trojan.Googupdate.Dzty
Fortinet FortiGate W32/GoogUpdate.AN!tr
Jiangmin Adware/Adload.ayz
SUPERAntiSpyware Trojan.Agent/Gen-Plush
44e236e4-ce71-4d11-84c3-0dca27ae587d-5.exe (MD5: 6f784ee7abeacab3d2cca2d7eb9cb285) has been flagged by 46 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Plush.2
avast! Win32:Crossrider-M [PUP]
AVG Generic.727
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Bitdefender Gen:Variant.Adware.Plush.2
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.2 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AN
F-Prot W32/S-9ad4719b!Eldorado
F-Secure Gen:Variant.Adware.Plush.2
G Data Gen:Variant.Adware.Plush.2
IKARUS anti.virus Trojan.GoogUpdate
K7 AntiVirus Adware ( 004a90bd1 )
K7GW Adware ( 004a90bd1 )
Kaspersky Trojan.NSIS.GoogUpdate.ck
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Malwarebytes PUP.Optional.PlusHD.A
MicroWorld-eScan Gen:Variant.Adware.Plush.2
NANO AntiVirus Riskware.Win32.Crossrider.denqib
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM10.Gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos Generic PUA HB
Symantec WS.Reputation.1
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.2163
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 Win-PUP/CrossRider
Baidu-International PUA.Win32.CrossRider.bAP
Comodo Security ApplicUnwnt
Fortinet FortiGate Riskware/CrossRider
McAfee Artemis!AB0B2FCEB9A7
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
nProtect Trojan/W32.Agent.1281904
Tencent Nsis.Trojan.Googupdate.Llqx
Trend Micro TROJ_GEN.R0C1C0EJV14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJV14
Vba32 AntiVirus AdWare.Adwapper
AegisLab Troj.W32.Vilsel
Dr.Web Trojan.Crossrider.32358
Antiy-AVL Trojan/NSIS.GoogUpdate
CAT-QuickHeal Trojan.NSIS.r5
Clam AntiVirus Win.Trojan.Crossrider-24
Avira AntiVir Adware/CrossRider.A.16680
Jiangmin Adware/Adload.ayz
SUPERAntiSpyware Trojan.Agent/Gen-Plush

Startup Entries

Startup tasks:
  • cce52788-383c-46f4-9bc3-bc0a737db7be-7.exe is automatically launched at startup through a scheduled task named cce52788-383c-46f4-9bc3-bc0a737db7be-1.
  • cce52788-383c-46f4-9bc3-bc0a737db7be-6.exe is automatically launched at startup through a scheduled task named cce52788-383c-46f4-9bc3-bc0a737db7be-6.
  • cce52788-383c-46f4-9bc3-bc0a737db7be-5.exe is automatically launched at startup through a scheduled task named cce52788-383c-46f4-9bc3-bc0a737db7be-5_user.
  • cce52788-383c-46f4-9bc3-bc0a737db7be-4.exe is automatically launched at startup through a scheduled task named cce52788-383c-46f4-9bc3-bc0a737db7be-4.
  • cce52788-383c-46f4-9bc3-bc0a737db7be-11.exe is automatically launched at startup through a scheduled task named cce52788-383c-46f4-9bc3-bc0a737db7be-3.
  • cce52788-383c-46f4-9bc3-bc0a737db7be-2.exe is automatically launched at startup through a scheduled task named cce52788-383c-46f4-9bc3-bc0a737db7be-2.

Software Details

URL:
https://crossrider.com/install/61776-plus-hd-9-1c
Support:
–
Installation path:
C:\Program Files\v-9.1hd
Uninstaller:
C:\Program Files\V-9.1HD\Uninstall.exe /fcp=1
Size:
11.00 MB
Language:
English

V-9.1HD Executable Details

Primary executable:
utils.exe
Name:
V-9.1HD
Path:
C:\Program Files\v-9.1hd\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by V-9.1HD
File Type Filename MD5
DLL
0900b6c72905788aca613f89fe739bd3
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
DLL
5e8e81170731f5521bf540e5e374b011
DLL
06bef001533cc9b2aee78e0315432f94
EXE
a0bdc8051a740904d9e5f24d697f6875
DLL
054eb97126c57f5476abc3c6f8586eab
DLL
55bbde7f48a5ef7a8254bfeb3a5a39d7
DLL
9161b2db6facc5aa59f5eae689ec05af
EXE
311cc65faf6f60718ffe7d50cf8c35b0
EXE
a9875da7b92281c8ca6b62c4ba31079f