PlusSTotal-9.4

PlusSTotal-9.4

Known Adware

by Kimahri Software inc.

What is PlusSTotal-9.4?

PlusSTotal-9.4 is software application developed by Kimahri Software inc.. It is most commonly found on computers running Windows 7 with nearly 62.50% of installations running this operating system. PlusSTotal-9.4's installer is typically 9.00 MB in size and installs around 157 files. The most common release is 1.34.7.1 with 35.42% of all installations currently using this version.

PlusSTotal-9.4 is most popular in the United States with 97.2% of installations residing in this country.

PlusSTotal-9.4 adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About PlusSTotal-9.4?

This adware operates as an extension and/or add-on within the user's Internet browser, injecting advertising in various forms such as search-related ads, banner and video ads, in-text ads and links, transitional, interstitial and full page ads. These ads and features are not affiliated with the website being visited and are injected into the header or footer area of the web page. Additionally, the software converts words on webpages into hyperlinks that lead to advertisements. Classified as adware and/or a PUP based on its behavior, this software is commonly distributed through third-party download managers and installers, often included as an additional or sponsored offer.

Multiple virus scanners have detected malware in PlusSTotal-9.4.

70bd18d2-120a-40a4-888d-6023dce2ee5a-11.exe (MD5: 949c506cd9474e061413aab9019689a0) has been flagged by 19 scanners:
Scanner Software Result
AVG Generic.332
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
IKARUS anti.virus AdWare.Adload
Malwarebytes PUP.Optional.PlusHD.A
NANO AntiVirus Riskware.Win32.AdLoad.dcabgp
Panda Antivirus Trj/Genetic.gen
Symantec Trojan.ADH.2
VIPRE Antivirus Crossrider (fs)
Bitdefender Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
F-Secure Gen:Variant.Adware.Kazy.374109
G Data Gen:Variant.Adware.Kazy.374109
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
Avira AntiVir ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win64.Crossrider.BF
Rising Antivirus PE:Malware.Obscure!1.9C59
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Sophos AppRider
6b93058f-1fc5-4421-a112-e0f0546afe14-5.exe (MD5: 5cfc4945a386cb16fa28f562bca83615) has been flagged by 24 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.CrossRider
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAH
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
IKARUS anti.virus AdWare.Adload
Malwarebytes PUP.Optional.PlusHD.A
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Symantec Trojan.ADH.2
VIPRE Antivirus Crossrider (fs)
avast! Win32:Adware-gen [Adw]
G Data Win32.Application.Plush.A
Jiangmin Adware/Adload.avl
NANO AntiVirus Riskware.Win32.AdLoad.dbduhk
Sophos AppRider
F-Prot W32/A-eb9ef301!Eldorado
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
F-Secure Gen:Variant.Adware.Kazy.374062
AVware Crossrider (fs)
Kaspersky Trojan.NSIS.GoogUpdate.ck
6b93058f-1fc5-4421-a112-e0f0546afe14-4.exe (MD5: 4c245667f2af3468e03fd1efaeaf5c2a) has been flagged by 19 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAK
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Malwarebytes PUP.Optional.PlusHD.A
Panda Antivirus Trj/Genetic.gen
Symantec Trojan.ADH.2
VIPRE Antivirus Crossrider (fs)
IKARUS anti.virus AdWare.Adload
NANO AntiVirus Riskware.Win32.AdLoad.dcabgp
Bitdefender Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
F-Secure Gen:Variant.Adware.Kazy.374109
G Data Gen:Variant.Adware.Kazy.374109
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
AVware Crossrider (fs)
Rising Antivirus PE:Malware.Obscure!1.9C59
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Sophos AppRider
6b93058f-1fc5-4421-a112-e0f0546afe14-2.exe (MD5: 4b18b90e460b11c06112e5754d78c412) has been flagged by 33 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAJ
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
F-Prot W32/A-eb9ef301!Eldorado
IKARUS anti.virus AdWare.Adload
Malwarebytes PUP.Optional.PlusHD.A
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Symantec Trojan.ADH.2
VIPRE Antivirus Crossrider (fs)
avast! Win32:Crossrider-M [PUP]
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Kaspersky Trojan.NSIS.GoogUpdate.ck
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
McAfee Artemis!857BE54B08D4
McAfee-GW-Edition BehavesLike.Win32.BadFile.jh
Qihoo-360 Win32/Trojan.921
Tencent Nsis.Trojan.Googupdate.Hwmx
Dr.Web Trojan.Crossrider.27726
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
G Data Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
K7GW Adware ( 0049f20c1 )
NANO AntiVirus Riskware.Win32.AdLoad.dbqhel
AhnLab-V3 PUP/Win32.CrossRider
Jiangmin Adware/Adload.avl
6b93058f-1fc5-4421-a112-e0f0546afe14-11.exe (MD5: cfa5579a125525c87370fafe10908571) has been flagged by 14 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAK
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
IKARUS anti.virus AdWare.Adload
Malwarebytes PUP.Optional.PlusHD.A
Panda Antivirus Trj/Genetic.gen
VIPRE Antivirus Crossrider (fs)
NANO AntiVirus Riskware.Win32.AdLoad.dbrdvm
Rising Antivirus PE:Malware.Obscure!1.9C59
Symantec WS.Reputation.1
G Data Win32.Application.Plush.A
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Sophos AppRider

Software Behaviors

Scheduled tasks:
  • PlusSTotal-9.4-nova.exe is scheduled as a task named 'temp_5080a2b2-dabd-433f-85c7-5f714c227b28-7'.
  • 5080a2b2-dabd-433f-85c7-5f714c227b28-2.exe is scheduled as a task named 'temp_5080a2b2-dabd-433f-85c7-5f714c227b28-2'.
  • PlusSTotal-9.4-novainstaller.exe is scheduled as a task named '8fb073d1-4c4e-4614-85b9-94de43c9266d-6'.

Startup Entries

Startup tasks:
  • 0773f67d-35e4-4d8a-9a81-d51fa80a445c-4.exe is automatically launched at startup through a scheduled task named 0773f67d-35e4-4d8a-9a81-d51fa80a445c-4.
  • PlusSTotal-9.4-codedownloader.exe is automatically launched at startup through a scheduled task named d54992d9-331e-46e5-a1c9-beeb90488aed-6.
  • PlusSTotal-9.4-nova.exe is automatically launched at startup through a scheduled task named d54992d9-331e-46e5-a1c9-beeb90488aed-7.
  • d54992d9-331e-46e5-a1c9-beeb90488aed-5.exe is automatically launched at startup through a scheduled task named d54992d9-331e-46e5-a1c9-beeb90488aed-5.
  • d54992d9-331e-46e5-a1c9-beeb90488aed-4.exe is automatically launched at startup through a scheduled task named d54992d9-331e-46e5-a1c9-beeb90488aed-4.
  • d54992d9-331e-46e5-a1c9-beeb90488aed-3.exe is automatically launched at startup through a scheduled task named d54992d9-331e-46e5-a1c9-beeb90488aed-3.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\plusstotal-9.4
Uninstaller:
C:\Program Files\PlusSTotal-9.4\Uninstall.exe /fcp=1
Size:
9.00 MB
Language:
English

PlusSTotal-9.4 Executable Details

Primary executable:
utils.exe
Name:
PlusSTotal-9.4
Path:
C:\Program Files\plusstotal-9.4\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by PlusSTotal-9.4
File Type Filename MD5
EXE
8983f7b27f7a9bdf20fd8e07b8350478
EXE
24e58c67ded3c6a7db394b0289d8ebe2
EXE
f95ec96fb24dd02948ce4cec3d20bb58
EXE
2988a269c12cad9070096205c99f1074
EXE
d1ef8fc6aafd2188d1296c14f382bebf
EXE
765109c64fe9e7581e5b90604b3a5e4b
EXE
1f2020faded14fd617756e7c1a8cf672
EXE
7ab8e696c6e1b636a743a9f7deb911a2
EXE
b1f295343059790b8937c8a07c62ad01
EXE
dc5bc0600a7145486eead2905b85ad94