Clip-High_D_06

Clip-High_D_06

Known Adware

by Kimahri Software inc.

What is Clip-High_D_06?

Clip-High_D_06 is software application developed by Kimahri Software inc.. It is most commonly found on computers running Windows 7 with nearly 48.25% of installations running this operating system. Clip-High_D_06's installer is typically 10.00 MB in size and installs around 607 files. The most common release is 1.36.01.22 with 20.18% of all installations currently using this version.

Clip-High_D_06 is most popular in the United States with 55.86% of installations residing in this country.

Clip-High_D_06 adds 4 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About Clip-High_D_06?

Clip-High is an adware browser application that injects banner ads and contextual link ads onto web pages. The ads are displayed on various web browsers such as Internet Explorer, Firefox, and Chrome, and may appear on any website, regardless of affiliation with the publisher. Users may encounter up to 10 in-text ads, 4 banner ads, and/or a transitional ad while browsing. This program is typically bundled with third-party download managers that use deceptive tactics to install the software. In addition to displaying ads, Clip-High can modify browser settings, including security settings, the homepage, and the search provider, a practice known as web browser hijacking. Furthermore, the extension reports user behavior, including visited URLs and domains, as well as interactions with displayed advertisements, to a controlling server. Clip-High is commonly bundled with additional unwanted programs through third-party download managers.

Multiple virus scanners have detected malware in Clip-High_D_06.

39d3b0d5-865f-47ce-aae4-57c29a29671e-4.exe (MD5: 79cefba5c9a48ac6bbfa7263ddf9e2d5) has been flagged by 15 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
Baidu-International Adware.Win32.CrossRider.bAK
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
G Data Win32.Application.Plush.A
IKARUS anti.virus AdWare.Adload
Malwarebytes PUP.Optional.ClipHD.A
Panda Antivirus PUP/PlusHD
VIPRE Antivirus Crossrider (fs)
AVG Generic.E0F
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.32916
Avira ADWARE/CrossRider.Gen2
Qihoo-360 HEUR/Malware.QVM10.Gen
F-Prot W32/S-9ad4719b!Eldorado
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
39d3b0d5-865f-47ce-aae4-57c29a29671e-2.exe (MD5: a97aa5e6db80890a34fc644b1d5b5ac6) has been flagged by 24 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
Baidu-International Adware.Win32.CrossRider.bAJ
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
F-Prot W32/A-eb9ef301!Eldorado
G Data Win32.Application.Plush.A
IKARUS anti.virus AdWare.Adload
Malwarebytes PUP.Optional.ClipHD.A
Panda Antivirus PUP/PlusHD
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
VIPRE Antivirus Crossrider (fs)
avast! Win32:Malware-gen
AVG Generic.B92
Avira ADWARE/CrossRider.Gen4
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.37121
NANO AntiVirus Trojan.Win32.Crossrider.dhaqjn
Kingsoft AntiVirus Win32.Troj.NSIS.ck.(kcloud)
Symantec WS.Reputation.1
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Tencent Nsis.Adware.Adwapper.Lpbq
McAfee Artemis!ABF1600CBAB7
McAfee-GW-Edition Artemis
Qihoo-360 HEUR/Malware.QVM10.Gen
39d3b0d5-865f-47ce-aae4-57c29a29671e-11.exe (MD5: 26f76726cc47cbe2d02877be416025b9) has been flagged by 37 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Avira AntiVir ADWARE/CrossRider.Gen2
Baidu-International Adware.Win32.CrossRider.bAK
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
F-Secure Gen:Variant.Adware.Kazy.374062
G Data Gen:Variant.Adware.Kazy.374062
IKARUS anti.virus AdWare.Adload
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.ClipHD.A
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Panda Antivirus PUP/PlusHD
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos Generic PUA GG
VIPRE Antivirus Crossrider (fs)
AVG Generic.D77
Avira Adware/CrossRider.pq
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.31451
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
NANO AntiVirus Riskware.Win32.Crossrider.deksfj
Rising Antivirus PE:Malware.Obscure!1.9C59
Tencent Nsis.Adware.Adwapper.Ligk
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
avast! Win32:Crossrider-AH [PUP]
Fortinet FortiGate Adware/Adwapper
McAfee Artemis!BB6702EA4A24
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
Jiangmin Trojan.NSIS.GoogUpdate.br
AhnLab-V3 PUP/Win32.CrossRider
Comodo Security ApplicUnwnt
TrendMicro-HouseCall Suspicious_GEN.F47V0719
Symantec WS.Reputation.1
F-Prot W32/A-eb9ef301!Eldorado
Vba32 AntiVirus Trojan.GoogUpdate
Zillya Trojan.GoogUpdate.Win32.3303
39d3b0d5-865f-47ce-aae4-57c29a29671e-10.exe (MD5: 69b5dc10155b7e5b213cdd3afd2a2fb7) has been flagged by 35 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
Baidu-International Adware.Win32.CrossRider.BAG
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AG
Fortinet FortiGate Riskware/Toolbar_CrossRider
G Data Win32.Application.Plush.A
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Malwarebytes PUP.Optional.ClipHD.A
McAfee Artemis!69B5DC10155B
McAfee-GW-Edition Artemis!69B5DC10155B
Panda Antivirus PUP/PlusHD
Sophos Generic PUA AN
TrendMicro-HouseCall Suspicious_GEN.F47V0719
VIPRE Antivirus Crossrider (fs)
Antiy-AVL Trojan/NSIS.GoogUpdate.dx
AVG Generic.C04
Avira ADWARE/CrossRider.Gen7
AVware Crossrider (fs)
Kaspersky Trojan.NSIS.GoogUpdate.dx
Qihoo-360 Win32/Trojan.fc9
Symantec WS.Reputation.1
AhnLab-V3 PUP/Win32.CrossRider
Dr.Web Trojan.Crossrider.31451
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
NANO AntiVirus Riskware.Win32.Crossrider.dekzxz
Tencent Nsis.Adware.Adwapper.Apwx
Rising Antivirus PE:Malware.Obscure!1.9C59
F-Prot W32/A-eb9ef301!Eldorado
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374109
Bitdefender Gen:Variant.Adware.Kazy.374109
F-Secure Gen:Variant.Adware.Kazy.374109
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
avast! Win32:Malware-gen
Vba32 AntiVirus Trojan.GoogUpdate
Zillya Trojan.GoogUpdate.Win32.3303
371f63c2-8581-401a-aaa6-54d6db76016a-7.exe (MD5: 09474fda3c4b684e69327b96f2f92626) has been flagged by 8 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.pq
AVG Generic.D77
AVware Crossrider (fs)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Malwarebytes PUP.Optional.ClipHD.A
Panda Antivirus Trj/Genetic.gen
VIPRE Antivirus Crossrider (fs)

Software Behaviors

Scheduled tasks:
  • Clip-High_D_06-nova.exe is scheduled as a task named '731b28ed-138e-45a5-af8b-7ef590e61293-6'.
  • b9c5ec7b-7eb5-47b7-a3df-c4dc960f0043-2.exe is scheduled as a task named 'temp_b9c5ec7b-7eb5-47b7-a3df-c4dc960f0043-2'.
  • a25b4f19-83a7-4c9b-a55b-b4f98aaca0bb-5.exe is scheduled as a task named 'a25b4f19-83a7-4c9b-a55b-b4f98aaca0bb-5'.
  • 8f89ff86-13db-47a9-8f3c-164520256ef0-11.exe is scheduled as a task named '8f89ff86-13db-47a9-8f3c-164520256ef0-11'.

Startup Entries

Startup tasks:
  • Clip-High_D_06-codedownloader.exe is automatically launched at startup through a scheduled task named 8ce6ff09-e65b-486e-8418-ae5df54b1e86-1.
  • 8ce6ff09-e65b-486e-8418-ae5df54b1e86-5.exe is automatically launched at startup through a scheduled task named 8ce6ff09-e65b-486e-8418-ae5df54b1e86-5_user.
  • 8ce6ff09-e65b-486e-8418-ae5df54b1e86-4.exe is automatically launched at startup through a scheduled task named 8ce6ff09-e65b-486e-8418-ae5df54b1e86-4.
  • fede06ff-beeb-44c4-8cb2-6188969e79b4.exe is automatically launched at startup through a scheduled task named fede06ff-beeb-44c4-8cb2-6188969e79b4.
  • 91c3e3c6-70f2-425c-8dc7-7eae086c7fba-7.exe is automatically launched at startup through a scheduled task named 91c3e3c6-70f2-425c-8dc7-7eae086c7fba-1.
  • 91c3e3c6-70f2-425c-8dc7-7eae086c7fba-6.exe is automatically launched at startup through a scheduled task named 91c3e3c6-70f2-425c-8dc7-7eae086c7fba-6.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\clip-high_d_06
Uninstaller:
C:\Program Files\Clip-High_D_06\Uninstall.exe /fcp=1
Size:
10.00 MB
Language:
English

Clip-High_D_06 Executable Details

Primary executable:
utils.exe
Name:
Clip-High_D_06
Path:
C:\Program Files\clip-high_d_06\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by Clip-High_D_06
File Type Filename MD5
DLL
0900b6c72905788aca613f89fe739bd3
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
DLL
5e8e81170731f5521bf540e5e374b011
DLL
06bef001533cc9b2aee78e0315432f94
EXE
a0bdc8051a740904d9e5f24d697f6875
DLL
054eb97126c57f5476abc3c6f8586eab
DLL
55bbde7f48a5ef7a8254bfeb3a5a39d7
DLL
9161b2db6facc5aa59f5eae689ec05af
EXE
79cefba5c9a48ac6bbfa7263ddf9e2d5
EXE
a97aa5e6db80890a34fc644b1d5b5ac6