PlusVid

PlusVid

Known Adware

by Kimahri Software inc.

What is PlusVid?

PlusVid is software application developed by Kimahri Software inc.. It is most commonly found on computers running Windows 7 with nearly 50.00% of installations running this operating system. PlusVid's installer is typically 11.00 MB in size and installs around 96 files. The most common release is 1.34.6.10 with 35.71% of all installations currently using this version.

PlusVid is most popular in the United States with 40.98% of installations residing in this country.

PlusVid adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About PlusVid?

This software is designed as adware that integrates into various web browsers including Internet Explorer, Chrome, and Firefox. It delivers advertising content on web pages that are not affiliated with the software or its partners. This can include banner and video ads, search-related ads, transitional and in-text ads, and links. The software also periodically updates itself and contacts a central server for instructions, additional advertising content, and reporting on user interactions and visited domains and web pages.

Multiple virus scanners have detected malware in PlusVid.

bce4c2d4-9280-4e3a-89a8-1564e7612468-11.exe (MD5: 4718cf0cca471e4516bb5079a9e8fc8b) has been flagged by 25 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAK
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
IKARUS anti.virus AdWare.Adload
Malwarebytes PUP.Optional.PlusVid.A
McAfee Artemis!4718CF0CCA47
McAfee-GW-Edition Artemis!4718CF0CCA47
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA FF
VIPRE Antivirus Crossrider (fs)
F-Prot W32/A-eb9ef301!Eldorado
Rising Antivirus PE:Malware.Obscure!1.9C59
Agnitum Outpost PUA.AdLoad!
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.fw
Qihoo-360 Win32/Virus.WebToolbar.be5
TrendMicro-HouseCall TROJ_GEN.R08NH07GO14
NANO AntiVirus Riskware.Win32.AdLoad.dbjxuu
Symantec WS.Reputation.1
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
Comodo Security ApplicUnwnt
Fortinet FortiGate Riskware/Toolbar_CrossRider
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
avast! Win32:Adware-gen [Adw]
9b531105-87ed-420c-a496-49c0c4b41ede-5.exe (MD5: 0412f5ffa2b5600451236300f139a0a0) has been flagged by 42 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Trojan.Heur.RP.su0@a0lnTTcO
Agnitum Outpost PUA.Toolbar.CrossRider!
Avira AntiVir Adware/CrossRider.A.4817
avast! Win32:Adware-gen [Adw]
AVG Generic_r.OF
Baidu-International Adware.Win32.CrossRider.BAC
Bitdefender Gen:Trojan.Heur.RP.su0@a0lnTTcO
Emsisoft Anti-Malware Gen:Trojan.Heur.RP.su0@a0lnTTcO (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Gen:Trojan.Heur.RP.su0@a0lnTTcO
G Data Gen:Trojan.Heur.RP.su0@a0lnTTcO
IKARUS anti.virus Trojan.Win32.Spy
K7 AntiVirus Trojan ( 004985a61 )
K7GW Trojan ( 004985a61 )
Kingsoft AntiVirus Win32.Troj.Undef.(kcloud)
Malwarebytes PUP.Optional.PlusVid.A
McAfee RDN/Generic PUP.x!cdv
McAfee-GW-Edition RDN/Generic PUP.x!cdv
MicroWorld-eScan Gen:Trojan.Heur.RP.su0@a0lnTTcO
Norman Troj_Generic.UAFUV
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.236
Sophos Generic PUA AL
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R0CBC0EEQ14
TrendMicro-HouseCall TROJ_GEN.R0CBC0EEQ14
VIPRE Antivirus Crossrider (fs)
AVware Crossrider (fs)
Comodo Security ApplicUnwnt
nProtect Trojan.Generic.11351862
Rising Antivirus PE:Trojan.Win32.Generic.16F37AC4!385055428
Avira ADWARE/CrossRider.Gen4
Bkav FE W32.ATVC_VuschekpoLTO.Trojan
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.cdz
Tencent Win32.Adware.Bp-browser.Luqs
Zillya Adware.CroRi.Win32.919
NANO AntiVirus Riskware.Win32.CrossRider.dbkpsg
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
AhnLab-V3 PUP/Win32.PlusHD
Clam AntiVirus Win.Adware.Agent-7333
F-Prot W32/A-eb9ef301!Eldorado
9b531105-87ed-420c-a496-49c0c4b41ede-4.exe (MD5: 8d3b4da5cb23a1fa3445509c18f5a1a8) has been flagged by 4 scanners:
Scanner Software Result
Baidu-International Adware.Win32.CrossRider.bAD
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AD
Malwarebytes PUP.Optional.PlusVid.A
VIPRE Antivirus Crossrider (fs)
9b531105-87ed-420c-a496-49c0c4b41ede-3.exe (MD5: 595f543568de5c173bd997da54cee3f0) has been flagged by 37 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11324387
Avira AntiVir Adware/CrossRider.A.4911
avast! Win32:Adware-gen [Adw]
Baidu-International Adware.Win32.CrossRider.BAD
Bitdefender Trojan.Generic.11324387
Emsisoft Anti-Malware Trojan.Generic.11324387 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AD
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11324387
G Data Trojan.Generic.11324387
IKARUS anti.virus Trojan.SuspectCRC
K7 AntiVirus Trojan ( 004988971 )
K7GW Trojan ( 004988971 )
Malwarebytes PUP.Optional.PlusVid.A
McAfee Artemis!595F543568DE
McAfee-GW-Edition Artemis!595F543568DE
MicroWorld-eScan Trojan.Generic.11324387
nProtect Trojan.Generic.11324387
Panda Antivirus Generic Malware
Qihoo-360 Win32/Virus.Adware.62d
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R01ZC0EF714
TrendMicro-HouseCall TROJ_GEN.R01ZC0EF714
VIPRE Antivirus Crossrider (fs)
Antiy-AVL Trojan/Win32.TSGeneric
AVG Generic_r.OG
Sophos AppRider
Clam AntiVirus Win.Adware.Agent-7333
NANO AntiVirus Riskware.Win32.CrossRider.dblcgv
Rising Antivirus PE:Malware.Obscure!1.9C59
Comodo Security ApplicUnwnt
Kingsoft AntiVirus Win32.Troj.Generic.v.(kcloud)
F-Prot W32/A-eb9ef301!Eldorado
AhnLab-V3 PUP/Win32.CrossRider
AVware Crossrider (fs)
Agnitum Outpost PUA.AdLoad!
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.fw
9b531105-87ed-420c-a496-49c0c4b41ede-2.exe (MD5: b553ba36be955ec85d485264e00810ca) has been flagged by 6 scanners:
Scanner Software Result
Baidu-International Adware.Win32.CrossRider.bAC
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
Malwarebytes PUP.Optional.PlusVid.A
Sophos AppRider
VIPRE Antivirus Crossrider (fs)
Avira AntiVir Adware/CrossRider.A.5241

Software Behaviors

Scheduled tasks:
  • PlusVid-nova.exe is scheduled as a task named '731b28ed-138e-45a5-af8b-7ef590e61293-6'.
  • 94547b4d-cc32-4514-abcb-346261d49951-5.exe is scheduled as a task named '94547b4d-cc32-4514-abcb-346261d49951-5'.

Startup Entries

Startup tasks:
  • PlusVid-nova.exe is automatically launched at startup through a scheduled task named 5d2076bc-d559-4c68-aca0-29a2e5982b96-7.
  • PlusVid-codedownloader.exe is automatically launched at startup through a scheduled task named 94547b4d-cc32-4514-abcb-346261d49951-1.
  • 94547b4d-cc32-4514-abcb-346261d49951-5.exe is automatically launched at startup through a scheduled task named 94547b4d-cc32-4514-abcb-346261d49951-5.
  • 94547b4d-cc32-4514-abcb-346261d49951-4.exe is automatically launched at startup through a scheduled task named 94547b4d-cc32-4514-abcb-346261d49951-4.
  • 94547b4d-cc32-4514-abcb-346261d49951-3.exe is automatically launched at startup through a scheduled task named 94547b4d-cc32-4514-abcb-346261d49951-3.
  • 94547b4d-cc32-4514-abcb-346261d49951-2.exe is automatically launched at startup through a scheduled task named 94547b4d-cc32-4514-abcb-346261d49951-2.

Software Details

URL:
https://crossrider.com/install/57020-plusvid
Support:
–
Installation path:
C:\Program Files\plusvid
Uninstaller:
C:\Program Files\PlusVid\Uninstall.exe /fcp=1
Size:
11.00 MB
Language:
English

PlusVid Executable Details

Primary executable:
PlusVid-bg.exe
Name:
PlusVid
Path:
C:\Program Files\plusvid\PlusVid-bg.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by PlusVid
File Type Filename MD5
EXE
cefc3e078723c760f6761f5587b3db4c
EXE
af1064a08dee5e578f4e39564f04c35a
EXE
858ba0320201dff1fb53dee58be24b10
EXE
33a14f5c8be47432e40b1d0d489fd4a6
EXE
bd981e7d43bef3ca0b3683c83b79440e
EXE
be7de579f290eb3b5b6e2d75437c4bad
EXE
f67cb676c7cef3c0a03740624038e316
EXE
a1e9219e8bb5f15a50a2869b9e34d0b9
EXE
a34a32db104ae03aad08cc9742e0bf5d
EXE
7c2ae48532f9cb3244d3b78c194c4010