Plus-HD-9.5

Plus-HD-9.5

Known Adware

by Kimahri Software inc.

What is Plus-HD-9.5?

Plus-HD-9.5 is software application developed by Kimahri Software inc.. It is most commonly found on computers running Windows 7 with nearly 63.39% of installations running this operating system. Plus-HD-9.5's installer is typically 8.00 MB in size and installs around 155 files. The most common release is 1.34.4.10 with 23.21% of all installations currently using this version.

Plus-HD-9.5 is most popular in the United States with 32.33% of installations residing in this country.

Plus-HD-9.5 adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About Plus-HD-9.5?

plus-hd is a software program that injects advertisements into the user's web browser. These advertisements may appear as banners, coupons, or text links that are not part of the original web page content. The program communicates with its servers to check for new offers and to monitor the user's browsing activity, recording domain names, displayed advertisements, and clicked ads. Additionally, the software may generate alerts and pop-ups suggesting the installation of ad-supported browser extensions or other applications.

Multiple virus scanners have detected malware in Plus-HD-9.5.

utils.exe (MD5: e59803d2f25e1b4d75ff51eac6d9d55f) has been flagged by 50 scanners:
Scanner Software Result
AegisLab AdWare.NSIS.Indirect
AhnLab-V3 PUP/Win32.MulDrop
Baidu-International PUA.Win32.VMDetector.BE
Bkav FE HW32.Packed
ESET-NOD32 Win32/Packed.VMDetector.I
G Data NSIS.Adware.Crossrider
Malwarebytes PUP.Optional.CrossRider.A
McAfee Artemis!E59803D2F25E
McAfee-GW-Edition Artemis
Symantec WS.Reputation
Vba32 AntiVirus Trojan.GoogUpdate
Lavasoft Ad-Aware Gen:Application.Heur.Zv1@mKr92loO
Antiy-AVL RiskWare[WebToolbar]/Win32.CrossRider.bfy
Arcabit Application.Heur.EDD79A
avast! Win32:Crossrider-AP [PUP]
AVG Crossrider.CM
Avira ADWARE/CrossRider.gr
AVware Crossrider (fs)
Bitdefender Gen:Application.Heur.Zv1@mKr92loO
CAT-QuickHeal PUA.GoogleUpdate.A5
Clam AntiVirus Win.Adware.Plush-14
Comodo Security Application.Win32.CrossRider.CK
Cyren W32/AdLoad.AK2.gen!Eldorado
Dr.Web Trojan.Crossrider1.32446
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/AdLoad.AK2.gen!Eldorado
F-Secure Gen:Application.Heur.Zv1@mKr92loO
IKARUS anti.virus Gen.AdWare.Plush
K7 AntiVirus Unwanted-Program ( 004ae5bf1 )
K7GW Unwanted-Program ( 004ae5bf1 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.bfy
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
MicroWorld-eScan Gen:Application.Heur.Zv1@mKr92loO
NANO AntiVirus Riskware.Win32.AdLoad.dbkwct
Panda Antivirus Trj/Genetic.gen
SUPERAntiSpyware Adware.CrossRider/Variant
Tencent Win32.Adware.Bp-browser.Luqs
Total Defense Heur/TrojanHorse.ZCGN!suspicious
Trend Micro TROJ_GEN.R0C1C0EG215
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.37
Jiangmin Adware/Adload.azr
Qihoo-360 Win32/Virus.Adware.cd4
Rising Antivirus PE:Trojan.Win32.Generic.1747F776!390592374
Sophos AppRider
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJM14
Agnitum Outpost PUA.AdLoad!
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Emsisoft Anti-Malware Gen:Adware.Plush.1 (B)
Avira AntiVir Adware/CrossRider.A.13977
6020ef0a-1fb7-4bf2-9695-dbf8a2d8a198-5.exe (MD5: 6eef194443376ba9d307a97d6791e1bd) has been flagged by 49 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.Cu1@medp7HdO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL RiskWare[WebToolbar]/Win32.CrossRider.bfy
Arcabit Application.Heur.EB64C3
avast! Win32:Crossrider-U [PUP]
AVG Crossrider.ADZ
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.Agent.Elnx
Bitdefender Gen:Application.Heur.Cu1@medp7HdO
Bkav FE W32.HfsAdware.A3A2
CAT-QuickHeal PUA.GoogleUpdate.A5
Comodo Security ApplicUnwnt
Cyren W32/S-d541cc5c!Eldorado
Dr.Web Trojan.Crossrider1.32446
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH potentially unwanted
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/S-d541cc5c!Eldorado
F-Secure Gen:Application.Heur.Cu1@medp7HdO
G Data Gen:Application.Heur.Cu1@medp7HdO
IKARUS anti.virus Gen.AdWare.Plush
Jiangmin Adware/Adload.azr
K7 AntiVirus Unwanted-Program ( 004afada1 )
K7GW Unwanted-Program ( 004afada1 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.bfy
Malwarebytes PUP.Optional.HDPlus.A
McAfee Artemis!6EEF19444337
McAfee-GW-Edition Artemis!PUP
MicroWorld-eScan Gen:Application.Heur.Cu1@medp7HdO
NANO AntiVirus Riskware.Win32.AdLoad.dcslwr
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.cd4
Rising Antivirus PE:Trojan.Win32.Generic.1747F776!390592374
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Trojan.ADH.2
Tencent Win32.Adware.Bp-browser.Luqs
Trend Micro TROJ_GEN.R0C1C0EG215
VIPRE Antivirus Crossrider (fs)
Zillya Adware.AdLoad.Win32.352
Clam AntiVirus Win.Adware.Plush-27
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Sophos AppRider
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJM14
Vba32 AntiVirus AdWare.AdLoad
Total Defense Heur/TrojanHorse.ZCFV!suspicious
Agnitum Outpost PUA.AdLoad!
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Emsisoft Anti-Malware Gen:Adware.Plush.1 (B)
Avira AntiVir Adware/CrossRider.A.13977
6020ef0a-1fb7-4bf2-9695-dbf8a2d8a198-4.exe (MD5: b95288e3492dd6b9e3eb8043d463d5f4) has been flagged by 48 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.Yu1@murCLOeO
AhnLab-V3 Win-PUP/CrossRider
Antiy-AVL RiskWare[WebToolbar]/Win32.CrossRider.bfy
avast! Win32:Crossrider-AI [PUP]
AVG Crossrider.TL
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.AK
Bitdefender Gen:Application.Heur.Yu1@murCLOeO
Bkav FE W32.HfsAdware.A3A2
CAT-QuickHeal PUA.GoogleUpdate.A5
Comodo Security ApplicUnwnt
Cyren W32/S-d541cc5c!Eldorado
Dr.Web Trojan.Crossrider.37031
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK potentially unwanted
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/S-d541cc5c!Eldorado
F-Secure Gen:Application.Heur.Yu1@murCLOeO
G Data Gen:Application.Heur.Yu1@murCLOeO
Jiangmin Adware/Adload.bac
K7 AntiVirus Unwanted-Program ( 004afad91 )
K7GW Unwanted-Program ( 004afad91 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.bfy
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.HDPlus.A
McAfee Artemis!B95288E3492D
MicroWorld-eScan Gen:Application.Heur.Yu1@murCLOeO
NANO AntiVirus Riskware.Win32.AdLoad.dcsljb
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.807
SUPERAntiSpyware Adware.Crossrider/Variant
Symantec Trojan.ADH.2
Tencent Win32.Adware.Bp-browser.Luqs
Trend Micro TROJ_GEN.R0C1C0EJO14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJO14
VIPRE Antivirus Crossrider (fs)
Zillya Adware.AdLoad.Win32.409
Avira ADWARE/CrossRider.gr
Rising Antivirus PE:Malware.CrossRider!6.214D
Sophos AppRider
McAfee-GW-Edition BehavesLike.Win32.AdwareCross.th
Agnitum Outpost PUA.CrossRider!
Arcabit Application.Heur.E5DC08
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Vba32 AntiVirus AdWare.AdLoad
Emsisoft Anti-Malware Gen:Adware.Plush.1 (B)
Clam AntiVirus Win.Trojan.Agent-726472
IKARUS anti.virus Gen.AdWare.Plush
Avira AntiVir Adware/CrossRider.A.13977
6020ef0a-1fb7-4bf2-9695-dbf8a2d8a198-3.exe (MD5: ccf943964d59efd4ea9eb5b5177c7a77) has been flagged by 49 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.Zv1@mKr92loO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL RiskWare[WebToolbar]/Win32.CrossRider.bfy
Arcabit Application.Heur.EDD79A
avast! Win32:Crossrider-AP [PUP]
AVG Crossrider.CM
Avira ADWARE/CrossRider.gr
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.AK
Bitdefender Gen:Application.Heur.Zv1@mKr92loO
Bkav FE W32.HfsAdware.A3A2
CAT-QuickHeal PUA.GoogleUpdate.A5
Clam AntiVirus Win.Adware.Plush-14
Comodo Security Application.Win32.CrossRider.CK
Cyren W32/AdLoad.AK2.gen!Eldorado
Dr.Web Trojan.Crossrider1.32446
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK potentially unwanted
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/AdLoad.AK2.gen!Eldorado
F-Secure Gen:Application.Heur.Zv1@mKr92loO
G Data Gen:Application.Heur.Zv1@mKr92loO
IKARUS anti.virus Gen.AdWare.Plush
K7 AntiVirus Unwanted-Program ( 004ae5bf1 )
K7GW Unwanted-Program ( 004ae5bf1 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.bfy
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.HDPlus.A
McAfee Artemis!CCF943964D59
McAfee-GW-Edition Artemis!PUP
MicroWorld-eScan Gen:Application.Heur.Zv1@mKr92loO
NANO AntiVirus Riskware.Win32.AdLoad.dbkwct
Panda Antivirus Trj/Genetic.gen
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Trojan.ADH.2
Tencent Win32.Adware.Bp-browser.Luqs
Total Defense Heur/TrojanHorse.ZCGN!suspicious
Trend Micro TROJ_GEN.R0C1C0EG215
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.37
Jiangmin Adware/Adload.azr
Qihoo-360 Win32/Virus.Adware.cd4
Rising Antivirus PE:Trojan.Win32.Generic.1747F776!390592374
Sophos AppRider
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJM14
Vba32 AntiVirus AdWare.AdLoad
Agnitum Outpost PUA.AdLoad!
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Emsisoft Anti-Malware Gen:Adware.Plush.1 (B)
Avira AntiVir Adware/CrossRider.A.13977
6020ef0a-1fb7-4bf2-9695-dbf8a2d8a198-2.exe (MD5: b962dac58f7625e66e71242bdd8598f0) has been flagged by 44 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.wu1@kuK03qfO
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Crossrider-T [PUP]
AVG Generic_r.OG
Avira Adware/CrossRider.A.5009
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.bAJ
Bitdefender Gen:Application.Heur.wu1@kuK03qfO
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/S-9ad4719b!Eldorado
F-Secure Gen:Application.Heur.wu1@kuK03qfO
G Data Gen:Application.Heur.wu1@kuK03qfO
K7 AntiVirus Trojan ( 004a85b01 )
K7GW Trojan ( 004a85b01 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.bfy
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.HDPlus.A
McAfee Artemis!B962DAC58F76
McAfee-GW-Edition BehavesLike.Win32.PUP.fh
MicroWorld-eScan Gen:Application.Heur.wu1@kuK03qfO
NANO AntiVirus Riskware.Win32.AdLoad.dbveux
Qihoo-360 Win32/Virus.Adware.705
Sophos AppRider
Symantec Trojan.ADH.2
Trend Micro TROJ_GEN.R0C1C0EJO14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJO14
Vba32 AntiVirus AdWare.AdLoad
VIPRE Antivirus Crossrider (fs)
Zillya Backdoor.PePatch.Win32.38492
Antiy-AVL not-a-virus:WebToolbar.Win32.CroRi.bei
Emsisoft Anti-Malware Gen:Adware.Plush.1 (B)
Panda Antivirus PUP/PlusHD
Bkav FE W32.CrossRiderJ.Adware
Cyren W32/S-4462d246!Eldorado
Dr.Web Adware.Toolbar.369
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Rising Antivirus PE:Malware.Adload!6.1D39
Clam AntiVirus Win.Trojan.Agent-726472
Tencent Win32.Adware.Bp-browser.Luqs
IKARUS anti.virus Gen.AdWare.Plush
Avira AntiVir Adware/CrossRider.A.13977
Agnitum Outpost PUA.Toolbar.Crossrider!

Software Behaviors

Scheduled tasks:
  • 0abf19b6-c6cf-4b9a-8f0d-e6cdc23f7c75-4.exe is scheduled as a task named '0abf19b6-c6cf-4b9a-8f0d-e6cdc23f7c75-4'.

Startup Entries

Startup tasks:
  • Plus-HD-9.5-codedownloader.exe is automatically launched at startup through a scheduled task named dcceac7c-4f75-42a2-99fa-40f65721f6e0-1.
  • a35edfbf-4f73-469d-a1ae-5c314ec25c1b-5.exe is automatically launched at startup through a scheduled task named a35edfbf-4f73-469d-a1ae-5c314ec25c1b-5.
  • a35edfbf-4f73-469d-a1ae-5c314ec25c1b-3.exe is automatically launched at startup through a scheduled task named a35edfbf-4f73-469d-a1ae-5c314ec25c1b-3.
  • 0ec38cc3-95a7-4a9f-a7e6-3ee1721a9345-5.exe is automatically launched at startup through a scheduled task named 0ec38cc3-95a7-4a9f-a7e6-3ee1721a9345-5.
  • 0ec38cc3-95a7-4a9f-a7e6-3ee1721a9345-4.exe is automatically launched at startup through a scheduled task named 0ec38cc3-95a7-4a9f-a7e6-3ee1721a9345-4.
  • 0ec38cc3-95a7-4a9f-a7e6-3ee1721a9345-3.exe is automatically launched at startup through a scheduled task named 0ec38cc3-95a7-4a9f-a7e6-3ee1721a9345-3.

Software Details

URL:
https://plus-hd.com
Support:
–
Installation path:
C:\Program Files\plus-hd-9.5
Uninstaller:
C:\Program Files\Plus-HD-9.5\Uninstall.exe /fcp=1
Size:
8.00 MB
Language:
English

Plus-HD-9.5 Executable Details

Primary executable:
utils.exe
Name:
Plus-HD-9.5
Path:
C:\Program Files\plus-hd-9.5\utils.exe
MD5:
e59803d2f25e1b4d75ff51eac6d9d55f
SHA-1:
–
SHA-256:
–
Files installed by Plus-HD-9.5
File Type Filename MD5
DLL
0900b6c72905788aca613f89fe739bd3
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
DLL
5e8e81170731f5521bf540e5e374b011
DLL
06bef001533cc9b2aee78e0315432f94
EXE
e59803d2f25e1b4d75ff51eac6d9d55f
DLL
054eb97126c57f5476abc3c6f8586eab
DLL
55bbde7f48a5ef7a8254bfeb3a5a39d7
DLL
9161b2db6facc5aa59f5eae689ec05af
EXE
c167d6aea65ccd90c438f99a8ebc075f
EXE
6eef194443376ba9d307a97d6791e1bd