MPlayerplus_01

MPlayerplus_01

Known Adware

by Kimahri Software inc.

What is MPlayerplus_01?

MPlayerplus_01 is software application developed by Kimahri Software inc.. It is most commonly found on computers running Windows 7 with nearly 47.42% of installations running this operating system. MPlayerplus_01's installer is typically 1.00 MB in size and installs around 32 files.

MPlayerplus_01 is most popular in the United States with 18.39% of installations residing in this country.

MPlayerplus_01 adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About MPlayerplus_01?

This software is an adware application that inserts advertisements into the user's Internet browser by operating as an extension and/or add-on. The ads come in the form of search-related ads, banners, video ads, text-links (roll-overs), and some popup ads, typically appearing in the header or footer of web pages. Additionally, it converts words on viewed pages into hyperlinks linked to advertisements. As a result of its behavior, this application is classified as adware and/or a potentially unwanted program (PUP). It is distributed through third-party installers.

Multiple virus scanners have detected malware in MPlayerplus_01.

MPlayerplus_01-nova.exe (MD5: b11eb9dbf86a7b9aab34ac788ca08634) has been flagged by 21 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.A.4493
Baidu-International Adware.Win32.CrossRider.BAE
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AE
Fortinet FortiGate Riskware/Toolbar_CrossRider
G Data Win32.Application.Plush.A
Malwarebytes PUP.Optional.MPlayerplus.A
McAfee Artemis!B11EB9DBF86A
McAfee-GW-Edition Artemis!B11EB9DBF86A
Panda Antivirus PUP/PlusHD
Qihoo-360 Win32/Virus.Adware.42b
Sophos Generic PUA JI
Symantec Adware.BL
TrendMicro-HouseCall TROJ_GEN.F47V0520
VIPRE Antivirus Crossrider (fs)
AVG Generic5.ATZQ
Comodo Security ApplicUnwnt
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Antiy-AVL Trojan/Win32.TSGeneric
MPlayerplus_01-codedownloader.exe (MD5: 95355190f1a160cedde767259628e55c) has been flagged by 27 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Generic.945524
Avira AntiVir Adware/CrossRider.A.4540
avast! Win32:Adware-gen [Adw]
AVG Generic5.ATZO
Baidu-International Adware.Win32.CrossRider.bAC
Bitdefender Adware.Generic.945524
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Adware.Generic.945524 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Adware.Generic.945524
G Data Adware.Generic.945524
Malwarebytes PUP.Optional.MPlayerplus.A
McAfee Adware-CrossR!95355190F1A1
McAfee-GW-Edition Adware-CrossR!95355190F1A1
MicroWorld-eScan Adware.Generic.945524
Qihoo-360 Win32/Virus.Adware.4df
Sophos AppRider
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.R047H06EJ14
VIPRE Antivirus Crossrider (fs)
Antiy-AVL Trojan/Win32.TSGeneric
Panda Antivirus PUP/PlusHD
Agnitum Outpost PUA.Toolbar.CrossRider!
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
K7 AntiVirus Riskware ( 0040f01a1 )
K7GW Riskware ( 0040f01a1 )
MPlayerplus_01-bho64.dll (MD5: fba1b941c00080589de555a28746d4b6) has been flagged by 8 scanners:
Scanner Software Result
Antiy-AVL Trojan/Win32.TSGeneric
Baidu-International Adware.Win64.Crossrider.BD
ESET-NOD32 probably a variant of Win64/Toolbar.Crossrider.D
Malwarebytes PUP.Optional.MPlayerplus.A
Panda Antivirus PUP/PlusHD
Symantec Adware.BL
TrendMicro-HouseCall TROJ_GEN.F47V0520
VIPRE Antivirus Crossrider (fs)
MPlayerplus_01-bho.dll (MD5: 6351e7af6f0cc42fbc4d7206651e24c2) has been flagged by 23 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.A.4508
Antiy-AVL Trojan/Win32.TSGeneric
AVG Generic5.AUAL
Comodo Security ApplicUnwnt
Fortinet FortiGate Adware/CrossR
K7 AntiVirus Riskware ( 0040f01a1 )
K7GW Riskware ( 0040f01a1 )
Malwarebytes PUP.Optional.MPlayerplus.A
McAfee Adware-CrossR!6351E7AF6F0C
McAfee-GW-Edition Adware-CrossR!6351E7AF6F0C
Qihoo-360 Win32/Virus.Adware.389
Sophos AppRider
Symantec WS.Reputation.1
VIPRE Antivirus Crossrider (fs)
Baidu-International Adware.Win32.CrossRider.BAE
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AE
G Data Win32.Application.Plush.A
Panda Antivirus PUP/PlusHD
TrendMicro-HouseCall TROJ_GEN.F47V0520
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
d883c0dc-2aba-4df6-aa3c-a2aaf825f9e1-5.exe (MD5: d2024e1685655feae52c7745183087d0) has been flagged by 11 scanners:
Scanner Software Result
Baidu-International Adware.Win32.CrossRider.bAC
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
G Data Win32.Application.Plush.A
Malwarebytes PUP.Optional.MPlayerplus.A
McAfee Adware-CrossR!D2024E168565
McAfee-GW-Edition Adware-CrossR!D2024E168565
Panda Antivirus PUP/PlusHD
VIPRE Antivirus Crossrider (fs)
Antiy-AVL Trojan/Win32.TSGeneric
Symantec Adware.BL
TrendMicro-HouseCall TROJ_GEN.F47V0520

Software Behaviors

Scheduled tasks:
  • MPlayerplus_01-nova.exe is scheduled as a task named 'temp_2c8e2bd6-d8c1-46d2-8168-f87f7872f8a0-7'.
  • 2c8e2bd6-d8c1-46d2-8168-f87f7872f8a0-2.exe is scheduled as a task named 'temp_2c8e2bd6-d8c1-46d2-8168-f87f7872f8a0-2'.

Startup Entries

Startup tasks:
  • MPlayerplus_01-codedownloader.exe is automatically launched at startup through a scheduled task named 907aae6c-7e50-41db-a623-65e7692cdf44-6.
  • MPlayerplus_01-nova.exe is automatically launched at startup through a scheduled task named 907aae6c-7e50-41db-a623-65e7692cdf44-7.
  • 907aae6c-7e50-41db-a623-65e7692cdf44-4.exe is automatically launched at startup through a scheduled task named 907aae6c-7e50-41db-a623-65e7692cdf44-4.
  • 907aae6c-7e50-41db-a623-65e7692cdf44-3.exe is automatically launched at startup through a scheduled task named 907aae6c-7e50-41db-a623-65e7692cdf44-3.
  • 2c8e2bd6-d8c1-46d2-8168-f87f7872f8a0-5.exe is automatically launched at startup through a scheduled task named 2c8e2bd6-d8c1-46d2-8168-f87f7872f8a0-5.
  • 2c8e2bd6-d8c1-46d2-8168-f87f7872f8a0-4.exe is automatically launched at startup through a scheduled task named 2c8e2bd6-d8c1-46d2-8168-f87f7872f8a0-4.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\MPlayerplus_01
Uninstaller:
C:\Program Files\MPlayerplus_01\Uninstall.exe /fcp=1
Size:
1.00 MB
Language:
English

MPlayerplus_01 Executable Details

Primary executable:
utils.exe
Name:
MPlayerplus_01
Path:
C:\Program Files\MPlayerplus_01\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by MPlayerplus_01
File Type Filename MD5
EXE
529647337987617a2723e089f4ba1388
EXE
8a7b1ab5be94256b7a328d0a203223cf
EXE
4b694d28042bd6a59a9495a5cfa91b09
EXE
0e7dce35cf62340e570858af2257cca5
EXE
2f2d67ca42e1d89fb52fee78dfb14d7f
EXE
45100a9e32472cafe3a1dba82ea01a79
EXE
44b45aa2f17e5cef5fe5ce06d4e29128
EXE
be6438206da129598ca3b857ad2e451d
EXE
9eb41e6cfe1cc62e726118ef8f3ad623
EXE
130f3455db4c2e4290f7b8349b4abb11