Plus-HD-9.6

Plus-HD-9.6

Known Adware

by Kimahri Software inc.

What is Plus-HD-9.6?

Plus-HD-9.6 is software application developed by Kimahri Software inc.. It is most commonly found on computers running Windows 7 with nearly 59.72% of installations running this operating system. Plus-HD-9.6's installer is typically 9.00 MB in size and installs around 41 files. The most common release is 1.34.5.29 with 56.19% of all installations currently using this version.

Plus-HD-9.6 is most popular in India with 10.65% of installations residing in this country.

Plus-HD-9.6 adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About Plus-HD-9.6?

Plus HD is a web browser extension and Browser Helper Object designed to enhance the user's interaction with various websites by rendering graphics, text, or interactive content in the browser. This software is sponsored by advertising and may cause additional ads to appear while browsing certain websites, including price comparison ads, coupons, pop-ups, banners, inline text, or transitional ads. However, it is important to note that Plus HD is commonly identified as an unwanted application by various malware vendors due to its adware-like behavior, which includes injecting a significant number of advertisements into the user's web browser and modifying the browser's home and search pages as well as 'New Tab' pages to serve advertising and search content.

Multiple virus scanners have detected malware in Plus-HD-9.6.

utils.exe (MD5: 155d4c15a2618880475b329aa2c505c3) has been flagged by 50 scanners:
Scanner Software Result
Baidu-International PUA.Win32.VMDetector.bE
Bkav FE HW32.CDB
ESET-NOD32 probably a variant of Win32/Packed.VMDetector.E
Malwarebytes PUP.Optional.CrossRider.A
TrendMicro-HouseCall TROJ_GEN.F47V0603
Lavasoft Ad-Aware Win32.Ramnit.N
Agnitum Outpost Win32.Nimnul.Gen.2
AhnLab-V3 Win32/Ramnit.F
Avira AntiVir W32/Ramnit.C
Antiy-AVL Virus/Win32.Nimnul.a
avast! Win32:RmnDrp
AVG Win32/Zbot.G
Bitdefender Win32.Ramnit.N
CAT-QuickHeal W32.Ramnit.BA
Clam AntiVirus W32.Ramnit-1
CMC Antivirus Virus.Win32.Ramit.1!O
Commtouch SDK W32/Ramnit.D
Comodo Security Virus.Win32.Ramnit.K
Dr.Web Win32.Siggen.7
Emsisoft Anti-Malware Win32.Ramnit.N (B)
Fortinet FortiGate W32/Ramnit.C
F-Prot W32/Ramnit.D
F-Secure Win32.Ramnit.N
G Data Win32.Ramnit.N
IKARUS anti.virus Virus.Win32.Ramnit
Jiangmin Win32/IRCNite.wi
K7 AntiVirus Virus ( 001d9d511 )
K7GW Virus ( 001d9d511 )
Kaspersky Virus.Win32.Nimnul.a
Kingsoft AntiVirus Win32.Ramnit.lx.30720
McAfee W32/Ramnit.a
McAfee-GW-Edition Heuristic.LooksLike.Win32.SuspiciousPE.N
Microsoft Security Essentials Virus:Win32/Ramnit.I
MicroWorld-eScan Win32.Ramnit.N
NANO AntiVirus Virus.Win32.Nimnul.bmnup
Norman Virut.HL
nProtect Virus/W32.SpyEye
Panda Antivirus W32/Cosmu.C
Qihoo-360 Virus.Win32.Ramnit.A
Rising Antivirus PE:Win32.Ramnit.i!1075353400
Sophos W32/Ramnit-A
Symantec W32.Ramnit.B!inf
Tencent Virus.Win32.Dropper.k
Total Defense Win32/Ramnit.C
Trend Micro PE_RAMNIT.DEN
Vba32 AntiVirus Virus.Win32.Nimnul.b
VIPRE Antivirus Virus.Win32.Ramnit.b (v)
ViRobot Win32.Nimnul.A
Zillya Virus.Nimnul.Win32.2
The Hacker W32/Virtob.Gen(F)
Plus-HD-9.6-novainstaller.exe (MD5: 1cee95ea2fb844353bfd72aad0a9760d) has been flagged by 22 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Adware.Plush.1
Avira AntiVir Adware/CrossRider.A.571
Bitdefender Gen:Adware.Plush.1
Emsisoft Anti-Malware Gen:Adware.Plush.1 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
F-Secure Gen:Adware.Plush.1
G Data Gen:Adware.Plush.1
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.PlusHD.A
MicroWorld-eScan Gen:Adware.Plush.1
Qihoo-360 Win32/Virus.Adware.bc4
Sophos AppRider
VIPRE Antivirus Crossrider (fs)
Antiy-AVL Trojan/Win32.TSGeneric
AVG Generic.BEF
Fortinet FortiGate Riskware/Toolbar_CrossRider
TrendMicro-HouseCall TROJ_GEN.F47V0603
Baidu-International Adware.Win32.CrossRider.AA
Symantec WS.Reputation.1
IKARUS anti.virus AdWare.Agent
McAfee Artemis!9D88E714440E
McAfee-GW-Edition Artemis!9D88E714440E
Plus-HD-9.6-nova.exe (MD5: a234bc5ec2a3972746386fdbfb3d624b) has been flagged by 48 scanners:
Scanner Software Result
Lavasoft Ad-Aware Win32.Virtob.Gen.12
Agnitum Outpost Win32.Virut.AB.Gen
AhnLab-V3 Win32/Virut.F
Avira AntiVir W32/Virut.Gen
Antiy-AVL Virus/Win32.Virut.ce
avast! Win32:Vitro
AVG Win32/Virut.AN
Bitdefender Win32.Virtob.Gen.12
Bkav FE W32.Vetor.PE
CAT-QuickHeal W32.Virut.G
CMC Antivirus Virus.Win32.Virut.1!O
Commtouch SDK W32/Injector.A.gen!Eldorado
Dr.Web Win32.Virut.56
Emsisoft Anti-Malware Win32.Virtob.Gen.12 (B)
ESET-NOD32 Win32/Virut.NBP
Fortinet FortiGate W32/FakeAV.RQ!tr
F-Prot W32/Injector.A.gen!Eldorado
F-Secure Win32.Virtob.Gen.12
G Data Win32.Virtob.Gen.12
IKARUS anti.virus Virus.Win32.Virut
Jiangmin Win32/Virut.bt
K7 AntiVirus Virus ( f10002001 )
K7GW Virus ( f10002001 )
Kaspersky Virus.Win32.Virut.ce
Malwarebytes PUP.Optional.HDPlus.A
McAfee W32/Virut.n.gen
McAfee-GW-Edition Heuristic.LooksLike.Win32.Suspicious.J!80
Microsoft Security Essentials Virus:Win32/Virut.BO
MicroWorld-eScan Win32.Virtob.Gen.12
NANO AntiVirus Virus.Win32.Virut.hpeg
Norman Virut.HL
nProtect Virus/W32.Virut.Gen
Panda Antivirus W32/Sality.AO
Qihoo-360 Virus.Win32.Virut.O
Rising Antivirus PE:Win32.Virut.cx!1553679
Sophos W32/Scribble-B
Symantec W32.Virut.CF
Tencent Virus.Win32.Virut.Gen.200006
The Hacker W32/Virtob.Gen(F)
Total Defense Win32/Virut.17408
Trend Micro PE_VIRUX.R-3
TrendMicro-HouseCall PE_VIRUX.R-3
Vba32 AntiVirus Virus.Virut.14
VIPRE Antivirus Virus.Win32.Virut.ce (v)
ViRobot Win32.Virut.AM
Baidu-International Adware.Win32.CrossRider.bAC
Comodo Security ApplicUnwnt
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Plus-HD-9.6-codedownloader.exe (MD5: 97061a03e82b7e08c2c12489eb18f339) has been flagged by 50 scanners:
Scanner Software Result
Lavasoft Ad-Aware Win32.Ramnit.N
Agnitum Outpost Win32.Nimnul.Gen.2
AhnLab-V3 Win32/Ramnit.F
Avira AntiVir W32/Ramnit.C
Antiy-AVL Virus/Win32.Nimnul.a
avast! Win32:RmnDrp
AVG Win32/Zbot.G
Baidu-International Virus.Win32.Nimnul.$a
Bitdefender Win32.Ramnit.N
Bkav FE W32.Tmgrtext.PE
CAT-QuickHeal W32.Ramnit.BA
Clam AntiVirus W32.Ramnit-1
CMC Antivirus Virus.Win32.Ramit.1!O
Commtouch SDK W32/Ramnit.D
Comodo Security Virus.Win32.Ramnit.K
Dr.Web Win32.Siggen.7
Emsisoft Anti-Malware Win32.Ramnit.N (B)
ESET-NOD32 Win32/Ramnit.H
Fortinet FortiGate W32/Ramnit.C
F-Prot W32/Ramnit.D
F-Secure Win32.Ramnit.N
G Data Win32.Ramnit.N
IKARUS anti.virus Virus.Win32.Ramnit
Jiangmin Win32/IRCNite.wi
K7 AntiVirus Virus ( 001d9d511 )
K7GW Virus ( 001d9d511 )
Kaspersky Virus.Win32.Nimnul.a
Kingsoft AntiVirus Win32.Ramnit.lx.30720
Malwarebytes Virus.Ramnit
McAfee W32/Ramnit.a
McAfee-GW-Edition Heuristic.LooksLike.Win32.SuspiciousPE.J
Microsoft Security Essentials Virus:Win32/Ramnit.I
MicroWorld-eScan Win32.Ramnit.N
NANO AntiVirus Virus.Win32.Nimnul.bmnup
Norman Virut.HL
nProtect Virus/W32.SpyEye
Panda Antivirus W32/Cosmu.C
Qihoo-360 Virus.Win32.Ramnit.A
Rising Antivirus PE:Win32.Ramnit.i!1075353400
Sophos W32/Ramnit-A
Symantec W32.Ramnit.B!inf
Tencent Virus.Win32.Dropper.k
Total Defense Win32/Ramnit.C
Trend Micro PE_RAMNIT.DEN
TrendMicro-HouseCall PE_RAMNIT.DEN
Vba32 AntiVirus Virus.Win32.Nimnul.b
VIPRE Antivirus Virus.Win32.Ramnit.b (v)
ViRobot Win32.Nimnul.A
Zillya Virus.Nimnul.Win32.2
The Hacker W32/Virtob.Gen(F)
Plus-HD-9.6-bho64.dll (MD5: 9d88e714440e853680f180d46a4e7312) has been flagged by 9 scanners:
Scanner Software Result
Antiy-AVL Trojan/Win32.TSGeneric
Baidu-International Adware.Win64.Crossrider.BE
ESET-NOD32 a variant of Win64/Toolbar.Crossrider.E
IKARUS anti.virus AdWare.Agent
Malwarebytes PUP.Optional.HDPlus.A
McAfee Artemis!9D88E714440E
McAfee-GW-Edition Artemis!9D88E714440E
TrendMicro-HouseCall TROJ_GEN.F47V0515
VIPRE Antivirus Crossrider (fs)

Software Behaviors

Scheduled tasks:
  • Plus-HD-9.6-nova.exe is scheduled as a task named 'temp_bd69fe80-f1b1-4f8f-b1a7-9e87900f7877-7'.
  • bd69fe80-f1b1-4f8f-b1a7-9e87900f7877-2.exe is scheduled as a task named 'temp_bd69fe80-f1b1-4f8f-b1a7-9e87900f7877-2'.

Startup Entries

Startup tasks:
  • 3cfa399a-1ff4-480c-9750-a200a41bf35a-5.exe is automatically launched at startup through a scheduled task named 05c44d44-a188-434a-91e3-0b3d4fc15d44-5.
  • 3cfa399a-1ff4-480c-9750-a200a41bf35a-4.exe is automatically launched at startup through a scheduled task named 05c44d44-a188-434a-91e3-0b3d4fc15d44-4.
  • Plus-HD-9.6-codedownloader.exe is automatically launched at startup through a scheduled task named f8ed2ea5-d2ce-448f-8f39-00d0cdd359dc-6.
  • Plus-HD-9.6-nova.exe is automatically launched at startup through a scheduled task named f8ed2ea5-d2ce-448f-8f39-00d0cdd359dc-7.
  • 964d7bdd-91f3-416c-b74a-1489f42d35d2-5.exe is automatically launched at startup through a scheduled task named f8ed2ea5-d2ce-448f-8f39-00d0cdd359dc-5.
  • 964d7bdd-91f3-416c-b74a-1489f42d35d2-4.exe is automatically launched at startup through a scheduled task named f8ed2ea5-d2ce-448f-8f39-00d0cdd359dc-4.

Software Details

URL:
https://www.plus-hd.com
Support:
–
Installation path:
C:\Program Files\plus-hd-9.6
Uninstaller:
C:\Program Files\Plus-HD-9.6\Uninstall.exe /fcp=1
Size:
9.00 MB
Language:
English

Plus-HD-9.6 Executable Details

Primary executable:
utils.exe
Name:
Plus-HD-9.6
Path:
C:\Program Files\plus-hd-9.6\utils.exe
MD5:
155d4c15a2618880475b329aa2c505c3
SHA-1:
–
SHA-256:
–
Files installed by Plus-HD-9.6
File Type Filename MD5
EXE
d6e02a5c81f46d3afdc995879e7dc181
EXE
utils.exe
Malware
155d4c15a2618880475b329aa2c505c3
DLL
b7e7656a1df842c2b9894ee9308f3f85
XPI
8f6881b6c838af594da8bc629e37e366
CRX
f0ab1ba1fc823e1efc946e27ca7076af
CRX
4702167a853f888e04c47d996ead2f4a
EXE
1cee95ea2fb844353bfd72aad0a9760d
EXE
a234bc5ec2a3972746386fdbfb3d624b
EXE
97061a03e82b7e08c2c12489eb18f339
DLL
9d88e714440e853680f180d46a4e7312