MPlayerplus

MPlayerplus

Known Adware

by Kimahri Software inc.

What is MPlayerplus?

MPlayerplus is software application developed by Kimahri Software inc.. It is most commonly found on computers running Windows 7 with nearly 50.00% of installations running this operating system. MPlayerplus's installer is typically 9.00 MB in size and installs around 15 files.

MPlayerplus is most popular in the United States with 22.50% of installations residing in this country.

About MPlayerplus?

The MPlayerplus Freeven adware is designed to inject advertising into the user's Internet browser by operating as an extension and/or add-on. It delivers search-related ads, banner and video ads, text-links (roll-overs), and popup ads, typically injecting them into the header or footer of web pages. Additionally, it has the capability to convert words on viewed pages into hyperlinks linked to advertisements. This software is classified as adware and/or a PUP based on its behavior, and is distributed through third party installers. According to the End User License Agreement (EULA), the installation of the Extensions may prompt changes to the user's Internet browser settings. These changes, if approved, can be reconfigured at any time by the user through the options dialog available on the Internet browser. Modifications may include altering the homepage, default search engine, and page displayed when opening a new tab.

Multiple virus scanners have detected malware in MPlayerplus.

utils.exe (MD5: 615560d8505fb173795fccac9a57bda4) has been flagged by 22 scanners:
Scanner Software Result
Baidu-International Trojan.Win32.VMDetector.bE
Bkav FE HW32.CDB
ESET-NOD32 a variant of Win32/Packed.VMDetector.E
Malwarebytes PUP.Optional.crossRider.A
The Hacker Backdoor/DsBot.boi
TrendMicro-HouseCall TROJ_GE.23D29F61
Avira AntiVir Adware/CrossRider.A.3946
Bitdefender Gen:Variant.Adware.Kazy.374109
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Gen:Variant.Adware.Kazy.374109
G Data Gen:Variant.Adware.Kazy.374109
McAfee Adware-CrossR!2A097FCC7A5F
McAfee-GW-Edition Adware-CrossR!2A097FCC7A5F
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
Panda Antivirus PUP/PlusHD
Sophos AppRider
Symantec Trojan.ADH.2
VIPRE Antivirus Crossrider (fs)
Antiy-AVL Trojan/Win32.TSGeneric
Qihoo-360 Win32/Virus.Adware.550
MPlayerplus-nova.exe (MD5: 2e13cac6ed0e76eb99bbe63bc37b80f9) has been flagged by 20 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.A.3978
Antiy-AVL Trojan/Win32.TSGeneric
Baidu-International Adware.Win32.CrossRider.BAE
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AE
Fortinet FortiGate Riskware/Toolbar_CrossRider
G Data Win32.Application.Plush.A
Malwarebytes PUP.Optional.MPlayerplus.A
McAfee Artemis!2E13CAC6ED0E
McAfee-GW-Edition Artemis!2E13CAC6ED0E
Panda Antivirus PUP/PlusHD
Qihoo-360 Win32/Virus.Adware.550
Sophos Generic PUA HL
Symantec Adware.BL
TrendMicro-HouseCall TROJ_GEN.F47V0515
VIPRE Antivirus Crossrider (fs)
Comodo Security ApplicUnwnt
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
MPlayerplus-codedownloader.exe (MD5: 2a097fcc7a5f9c85391515c278008049) has been flagged by 20 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.A.3946
Baidu-International Adware.Win32.CrossRider.bAC
Bitdefender Gen:Variant.Adware.Kazy.374109
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Gen:Variant.Adware.Kazy.374109
G Data Gen:Variant.Adware.Kazy.374109
Malwarebytes PUP.Optional.MPlayerplus.A
McAfee Adware-CrossR!2A097FCC7A5F
McAfee-GW-Edition Adware-CrossR!2A097FCC7A5F
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
Panda Antivirus PUP/PlusHD
Sophos AppRider
Symantec Trojan.ADH.2
TrendMicro-HouseCall TROJ_GEN.F47V0515
VIPRE Antivirus Crossrider (fs)
Antiy-AVL Trojan/Win32.TSGeneric
Qihoo-360 Win32/Virus.Adware.550
MPlayerplus-bho.dll (MD5: e9bf46b3b14080e54ea5c6b7bc017661) has been flagged by 12 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.A.3950
Baidu-International Adware.Win32.AddLyrics.aai
Comodo Security ApplicUnwnt
Fortinet FortiGate Adware/CrossR
G Data Win32.Application.Plush.B
McAfee Adware-CrossR!E9BF46B3B140
McAfee-GW-Edition Adware-CrossR!E9BF46B3B140
Panda Antivirus PUP/PlusHD
Sophos AppRider
TrendMicro-HouseCall TROJ_GEN.F47V0515
VIPRE Antivirus Crossrider (fs)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
b831afd9-f083-41b9-9e89-e4a308fff6ee-5.exe (MD5: c11f4afffbd6426db75a681a6272d0f6) has been flagged by 7 scanners:
Scanner Software Result
Baidu-International Adware.Win32.CrossRider.bAC
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
G Data Win32.Application.Plush.A
McAfee Adware-CrossR!C11F4AFFFBD6
McAfee-GW-Edition Adware-CrossR!C11F4AFFFBD6
Panda Antivirus PUP/PlusHD
VIPRE Antivirus Crossrider (fs)

Startup Entries

Startup tasks:
  • MPlayerplus-codedownloader.exe is automatically launched at startup through a scheduled task named b831afd9-f083-41b9-9e89-e4a308fff6ee-6.
  • MPlayerplus-nova.exe is automatically launched at startup through a scheduled task named b831afd9-f083-41b9-9e89-e4a308fff6ee-7.
  • b831afd9-f083-41b9-9e89-e4a308fff6ee-5.exe is automatically launched at startup through a scheduled task named b831afd9-f083-41b9-9e89-e4a308fff6ee-5.
  • b831afd9-f083-41b9-9e89-e4a308fff6ee-4.exe is automatically launched at startup through a scheduled task named b831afd9-f083-41b9-9e89-e4a308fff6ee-4.
  • b831afd9-f083-41b9-9e89-e4a308fff6ee-3.exe is automatically launched at startup through a scheduled task named b831afd9-f083-41b9-9e89-e4a308fff6ee-3.
  • b831afd9-f083-41b9-9e89-e4a308fff6ee-2.exe is automatically launched at startup through a scheduled task named b831afd9-f083-41b9-9e89-e4a308fff6ee-2.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\mplayerplus
Uninstaller:
C:\Program Files\MPlayerplus\Uninstall.exe /fcp=1
Size:
9.00 MB
Language:
English

MPlayerplus Executable Details

Primary executable:
utils.exe
Name:
MPlayerplus
Path:
C:\Program Files\mplayerplus\utils.exe
MD5:
615560d8505fb173795fccac9a57bda4
SHA-1:
–
SHA-256:
–
Files installed by MPlayerplus
File Type Filename MD5
EXE
305e362525f470d163c26b705c82d5a8
EXE
c11f4afffbd6426db75a681a6272d0f6
EXE
c74621f2bdb461ad92078d24b6c14fc3
EXE
c94b7582163d16259b19c923b192940e
EXE
430e05a44b24038737c54697e2fe8550