Plus-HD-9.6

Plus-HD-9.6

Known Adware

by Kimahri Software inc.

What is Plus-HD-9.6?

Plus-HD-9.6 is software application developed by Kimahri Software inc.. It is most commonly found on computers running Windows 7 with nearly 59.72% of installations running this operating system. Plus-HD-9.6's installer is typically 9.00 MB in size and installs around 41 files. The most common release is 1.34.5.29 with 56.19% of all installations currently using this version.

Plus-HD-9.6 is most popular in India with 10.65% of installations residing in this country.

Plus-HD-9.6 adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About Plus-HD-9.6?

Plus HD is a web browser extension and Browser Helper Object designed to enhance the user's interaction with various websites by rendering graphics, text, or interactive content in the browser. This software is sponsored by advertising and may cause additional ads to appear while browsing certain websites, including price comparison ads, coupons, pop-ups, banners, inline text, or transitional ads. However, it is important to note that Plus HD is commonly identified as an unwanted application by various malware vendors due to its adware-like behavior, which includes injecting a significant number of advertisements into the user's web browser and modifying the browser's home and search pages as well as 'New Tab' pages to serve advertising and search content.

Multiple virus scanners have detected malware in Plus-HD-9.6.

utils.exe (MD5: 155d4c15a2618880475b329aa2c505c3) has been flagged by 50 scanners:
Scanner Software Result
Baidu-International PUA.Win32.VMDetector.bE
Bkav FE HW32.CDB
ESET-NOD32 probably a variant of Win32/Packed.VMDetector.E
Malwarebytes PUP.Optional.CrossRider.A
TrendMicro-HouseCall TROJ_GEN.F47V0603
Lavasoft Ad-Aware Win32.Ramnit.N
Agnitum Outpost Win32.Nimnul.Gen.2
AhnLab-V3 Win32/Ramnit.F
Avira AntiVir W32/Ramnit.C
Antiy-AVL Virus/Win32.Nimnul.a
avast! Win32:RmnDrp
AVG Win32/Zbot.G
Bitdefender Win32.Ramnit.N
CAT-QuickHeal W32.Ramnit.BA
Clam AntiVirus W32.Ramnit-1
CMC Antivirus Virus.Win32.Ramit.1!O
Commtouch SDK W32/Ramnit.D
Comodo Security Virus.Win32.Ramnit.K
Dr.Web Win32.Siggen.7
Emsisoft Anti-Malware Win32.Ramnit.N (B)
Fortinet FortiGate W32/Ramnit.C
F-Prot W32/Ramnit.D
F-Secure Win32.Ramnit.N
G Data Win32.Ramnit.N
IKARUS anti.virus Virus.Win32.Ramnit
Jiangmin Win32/IRCNite.wi
K7 AntiVirus Virus ( 001d9d511 )
K7GW Virus ( 001d9d511 )
Kaspersky Virus.Win32.Nimnul.a
Kingsoft AntiVirus Win32.Ramnit.lx.30720
McAfee W32/Ramnit.a
McAfee-GW-Edition Heuristic.LooksLike.Win32.SuspiciousPE.N
Microsoft Security Essentials Virus:Win32/Ramnit.I
MicroWorld-eScan Win32.Ramnit.N
NANO AntiVirus Virus.Win32.Nimnul.bmnup
Norman Virut.HL
nProtect Virus/W32.SpyEye
Panda Antivirus W32/Cosmu.C
Qihoo-360 Virus.Win32.Ramnit.A
Rising Antivirus PE:Win32.Ramnit.i!1075353400
Sophos W32/Ramnit-A
Symantec W32.Ramnit.B!inf
Tencent Virus.Win32.Dropper.k
Total Defense Win32/Ramnit.C
Trend Micro PE_RAMNIT.DEN
Vba32 AntiVirus Virus.Win32.Nimnul.b
VIPRE Antivirus Virus.Win32.Ramnit.b (v)
ViRobot Win32.Nimnul.A
Zillya Virus.Nimnul.Win32.2
The Hacker W32/Virtob.Gen(F)
Plus-HD-9.6-novainstaller.exe (MD5: 1cee95ea2fb844353bfd72aad0a9760d) has been flagged by 22 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Adware.Plush.1
Avira AntiVir Adware/CrossRider.A.571
Bitdefender Gen:Adware.Plush.1
Emsisoft Anti-Malware Gen:Adware.Plush.1 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
F-Secure Gen:Adware.Plush.1
G Data Gen:Adware.Plush.1
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.PlusHD.A
MicroWorld-eScan Gen:Adware.Plush.1
Qihoo-360 Win32/Virus.Adware.bc4
Sophos AppRider
VIPRE Antivirus Crossrider (fs)
Antiy-AVL Trojan/Win32.TSGeneric
AVG Generic.BEF
Fortinet FortiGate Riskware/Toolbar_CrossRider
TrendMicro-HouseCall TROJ_GEN.F47V0603
Baidu-International Adware.Win32.CrossRider.AA
Symantec WS.Reputation.1
IKARUS anti.virus AdWare.Agent
McAfee Artemis!9D88E714440E
McAfee-GW-Edition Artemis!9D88E714440E
Plus-HD-9.6-nova.exe (MD5: a234bc5ec2a3972746386fdbfb3d624b) has been flagged by 48 scanners:
Scanner Software Result
Lavasoft Ad-Aware Win32.Virtob.Gen.12
Agnitum Outpost Win32.Virut.AB.Gen
AhnLab-V3 Win32/Virut.F
Avira AntiVir W32/Virut.Gen
Antiy-AVL Virus/Win32.Virut.ce
avast! Win32:Vitro
AVG Win32/Virut.AN
Bitdefender Win32.Virtob.Gen.12
Bkav FE W32.Vetor.PE
CAT-QuickHeal W32.Virut.G
CMC Antivirus Virus.Win32.Virut.1!O
Commtouch SDK W32/Injector.A.gen!Eldorado
Dr.Web Win32.Virut.56
Emsisoft Anti-Malware Win32.Virtob.Gen.12 (B)
ESET-NOD32 Win32/Virut.NBP
Fortinet FortiGate W32/FakeAV.RQ!tr
F-Prot W32/Injector.A.gen!Eldorado
F-Secure Win32.Virtob.Gen.12
G Data Win32.Virtob.Gen.12
IKARUS anti.virus Virus.Win32.Virut
Jiangmin Win32/Virut.bt
K7 AntiVirus Virus ( f10002001 )
K7GW Virus ( f10002001 )
Kaspersky Virus.Win32.Virut.ce
Malwarebytes PUP.Optional.HDPlus.A
McAfee W32/Virut.n.gen
McAfee-GW-Edition Heuristic.LooksLike.Win32.Suspicious.J!80
Microsoft Security Essentials Virus:Win32/Virut.BO
MicroWorld-eScan Win32.Virtob.Gen.12
NANO AntiVirus Virus.Win32.Virut.hpeg
Norman Virut.HL
nProtect Virus/W32.Virut.Gen
Panda Antivirus W32/Sality.AO
Qihoo-360 Virus.Win32.Virut.O
Rising Antivirus PE:Win32.Virut.cx!1553679
Sophos W32/Scribble-B
Symantec W32.Virut.CF
Tencent Virus.Win32.Virut.Gen.200006
The Hacker W32/Virtob.Gen(F)
Total Defense Win32/Virut.17408
Trend Micro PE_VIRUX.R-3
TrendMicro-HouseCall PE_VIRUX.R-3
Vba32 AntiVirus Virus.Virut.14
VIPRE Antivirus Virus.Win32.Virut.ce (v)
ViRobot Win32.Virut.AM
Baidu-International Adware.Win32.CrossRider.bAC
Comodo Security ApplicUnwnt
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Plus-HD-9.6-codedownloader.exe (MD5: 97061a03e82b7e08c2c12489eb18f339) has been flagged by 50 scanners:
Scanner Software Result
Lavasoft Ad-Aware Win32.Ramnit.N
Agnitum Outpost Win32.Nimnul.Gen.2
AhnLab-V3 Win32/Ramnit.F
Avira AntiVir W32/Ramnit.C
Antiy-AVL Virus/Win32.Nimnul.a
avast! Win32:RmnDrp
AVG Win32/Zbot.G
Baidu-International Virus.Win32.Nimnul.$a
Bitdefender Win32.Ramnit.N
Bkav FE W32.Tmgrtext.PE
CAT-QuickHeal W32.Ramnit.BA
Clam AntiVirus W32.Ramnit-1
CMC Antivirus Virus.Win32.Ramit.1!O
Commtouch SDK W32/Ramnit.D
Comodo Security Virus.Win32.Ramnit.K
Dr.Web Win32.Siggen.7
Emsisoft Anti-Malware Win32.Ramnit.N (B)
ESET-NOD32 Win32/Ramnit.H
Fortinet FortiGate W32/Ramnit.C
F-Prot W32/Ramnit.D
F-Secure Win32.Ramnit.N
G Data Win32.Ramnit.N
IKARUS anti.virus Virus.Win32.Ramnit
Jiangmin Win32/IRCNite.wi
K7 AntiVirus Virus ( 001d9d511 )
K7GW Virus ( 001d9d511 )
Kaspersky Virus.Win32.Nimnul.a
Kingsoft AntiVirus Win32.Ramnit.lx.30720
Malwarebytes Virus.Ramnit
McAfee W32/Ramnit.a
McAfee-GW-Edition Heuristic.LooksLike.Win32.SuspiciousPE.J
Microsoft Security Essentials Virus:Win32/Ramnit.I
MicroWorld-eScan Win32.Ramnit.N
NANO AntiVirus Virus.Win32.Nimnul.bmnup
Norman Virut.HL
nProtect Virus/W32.SpyEye
Panda Antivirus W32/Cosmu.C
Qihoo-360 Virus.Win32.Ramnit.A
Rising Antivirus PE:Win32.Ramnit.i!1075353400
Sophos W32/Ramnit-A
Symantec W32.Ramnit.B!inf
Tencent Virus.Win32.Dropper.k
Total Defense Win32/Ramnit.C
Trend Micro PE_RAMNIT.DEN
TrendMicro-HouseCall PE_RAMNIT.DEN
Vba32 AntiVirus Virus.Win32.Nimnul.b
VIPRE Antivirus Virus.Win32.Ramnit.b (v)
ViRobot Win32.Nimnul.A
Zillya Virus.Nimnul.Win32.2
The Hacker W32/Virtob.Gen(F)
Plus-HD-9.6-bho64.dll (MD5: 9d88e714440e853680f180d46a4e7312) has been flagged by 9 scanners:
Scanner Software Result
Antiy-AVL Trojan/Win32.TSGeneric
Baidu-International Adware.Win64.Crossrider.BE
ESET-NOD32 a variant of Win64/Toolbar.Crossrider.E
IKARUS anti.virus AdWare.Agent
Malwarebytes PUP.Optional.HDPlus.A
McAfee Artemis!9D88E714440E
McAfee-GW-Edition Artemis!9D88E714440E
TrendMicro-HouseCall TROJ_GEN.F47V0515
VIPRE Antivirus Crossrider (fs)

Software Behaviors

Scheduled tasks:
  • Plus-HD-9.6-nova.exe is scheduled as a task named 'temp_bd69fe80-f1b1-4f8f-b1a7-9e87900f7877-7'.
  • bd69fe80-f1b1-4f8f-b1a7-9e87900f7877-2.exe is scheduled as a task named 'temp_bd69fe80-f1b1-4f8f-b1a7-9e87900f7877-2'.

Startup Entries

Startup tasks:
  • 3cfa399a-1ff4-480c-9750-a200a41bf35a-5.exe is automatically launched at startup through a scheduled task named 05c44d44-a188-434a-91e3-0b3d4fc15d44-5.
  • 3cfa399a-1ff4-480c-9750-a200a41bf35a-4.exe is automatically launched at startup through a scheduled task named 05c44d44-a188-434a-91e3-0b3d4fc15d44-4.
  • Plus-HD-9.6-codedownloader.exe is automatically launched at startup through a scheduled task named f8ed2ea5-d2ce-448f-8f39-00d0cdd359dc-6.
  • Plus-HD-9.6-nova.exe is automatically launched at startup through a scheduled task named f8ed2ea5-d2ce-448f-8f39-00d0cdd359dc-7.
  • 964d7bdd-91f3-416c-b74a-1489f42d35d2-5.exe is automatically launched at startup through a scheduled task named f8ed2ea5-d2ce-448f-8f39-00d0cdd359dc-5.
  • 964d7bdd-91f3-416c-b74a-1489f42d35d2-4.exe is automatically launched at startup through a scheduled task named f8ed2ea5-d2ce-448f-8f39-00d0cdd359dc-4.

Software Details

URL:
https://www.plus-hd.com
Support:
–
Installation path:
C:\Program Files\plus-hd-9.6
Uninstaller:
C:\Program Files\Plus-HD-9.6\Uninstall.exe /fcp=1
Size:
9.00 MB
Language:
English

Plus-HD-9.6 Executable Details

Primary executable:
utils.exe
Name:
Plus-HD-9.6
Path:
C:\Program Files\plus-hd-9.6\utils.exe
MD5:
155d4c15a2618880475b329aa2c505c3
SHA-1:
–
SHA-256:
–
Files installed by Plus-HD-9.6
File Type Filename MD5
EXE
9d5e4139cfc3d51e3f95395b76c7c329
EXE
7bc7f44c3d83507cb13bc9f5e2e27da9
EXE
9d5e4139cfc3d51e3f95395b76c7c329
EXE
5e6978718f028a6194cb90322d42a104
EXE
222a94f142164981006c178bbd224d6d
EXE
7bc7f44c3d83507cb13bc9f5e2e27da9
EXE
7581a8bab0513b76e8f383c734e638e4
EXE
ac1f5c30431193b77dd5373abaa83254
EXE
264498e0b0fc9b4606dacc0af081823c
EXE
429cffa7989010dc16879c6e2bf09f20