HD+v2.1

HD+v2.1

Known Toolbar

by Vegeta Pop

What is HD+v2.1?

HD+v2.1 is software application developed by Vegeta Pop. It is most commonly found on computers running Windows 7 with nearly 51.43% of installations running this operating system. HD+v2.1's installer is typically 3.00 MB in size and installs around 80 files.

HD+v2.1 is most popular in India with 12.04% of installations residing in this country.

HD+v2.1 adds 5 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About HD+v2.1?

HD+ is a browser toolbar/extension that delivers third-party ads to the user's browser on non-affiliated web pages. The ads may appear as new ads or overlay existing ads on the page. Some of these ads may prompt the user to download potentially unwanted software or make purchases from affiliated vendors. Clicking on any offers, including coupons, may redirect the user to advertiser pages and drop affiliate cookies on the user's computer. Additionally, HD+ communicates with a remote server to track user browsing habits, including visited domains, viewed pages, and interactions with advertisements. Please be aware of these functionalities when using this software.

Multiple virus scanners have detected malware in HD+v2.1.

utils.exe (MD5: 203ad5c6c22988734c2d4ddb095d71b0) has been flagged by 48 scanners:
Scanner Software Result
AegisLab AdWare.NSIS.Indirect
Agnitum Outpost Trojan.Crossrider
AhnLab-V3 PUP/Win32.MulDrop
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win64.SearchSuite
Avira ADWARE/CrossRider.Gen2
Bkav FE HW32.Packed
Dr.Web Trojan.Crossrider.31777
ESET-NOD32 Win32/Packed.VMDetector.I
G Data NSIS.Adware.Crossrider
IKARUS anti.virus AdWare.CrossRider
Malwarebytes PUP.Optional.CrossRider.A
McAfee Artemis!203AD5C6C229
McAfee-GW-Edition Artemis
NANO AntiVirus Trojan.Win32.Crossrider.dfnoho
Qihoo-360 HEUR/Malware.QVM20.Gen
Symantec WS.Reputation
Tencent Win32.Trojan.Adpush.Omds
TrendMicro-HouseCall Suspicious_GEN.F47V0812
Vba32 AntiVirus Trojan.GoogUpdate
Lavasoft Ad-Aware Gen:Application.Heur.Ky9@mi0HYMki
avast! Win32:Crossrider-AK [PUP]
AVG Vegetapop.B27
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.AF
Bitdefender Gen:Application.Heur.Ky9@mi0HYMki
Comodo Security ApplicUnwnt
Cyren W32/A-ee826839!Eldorado
Fortinet FortiGate Riskware/CroRi
F-Prot W32/A-ee826839!Eldorado
F-Secure Gen:Application.Heur.Ky9@mi0HYMki
Jiangmin Trojan/GoogUpdate.ht
K7 AntiVirus Trojan ( 0049eec71 )
K7GW Trojan ( 0049eec71 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.bba
Kingsoft AntiVirus Win32.Troj.CroRi.a.(kcloud)
MicroWorld-eScan Gen:Application.Heur.Ky9@mi0HYMki
Panda Antivirus Trj/Chgt.B
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Trend Micro TROJ_GEN.R0C1C0EJG14
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CroRi.Win32.142
Arcabit Application.Heur.EF0A1C
CAT-QuickHeal PUA.GoogleUpdate.A5
SUPERAntiSpyware Adware.CrossRider/Variant
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.2 (B)
ViRobot Adware.CrossRider.496456
Avira AntiVir ADWARE/CrossRider.Gen2
HD+v2.1-codedownloader.exe (MD5: 57e253de865817557761e366d057a8d4) has been flagged by 39 scanners:
Scanner Software Result
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL Trojan/NSIS.GoogUpdate
avast! Win32:Crossrider-AI [PUP]
AVG Vegetapop.B27
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossRider.AQuA
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/S-9ad4719b!Eldorado
G Data Win32.Adware.Crossrider.N
K7 AntiVirus Trojan ( 0049ee4f1 )
K7GW Trojan ( 0049ee4f1 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.bba
Malwarebytes PUP.Optional.PlusHD.A
McAfee Artemis!57E253DE8658
McAfee-GW-Edition BehavesLike.Win32.BadFile.hh
NANO AntiVirus Riskware.Win32.CrossRider.dfompx
Panda Antivirus Trj/Chgt.B
Qihoo-360 Win32/Virus.WebToolbar.85b
Sophos AppRider
Symantec Adware.Crossid
TrendMicro-HouseCall TROJ_GEN.F0C2H00IN14
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.49
Comodo Security ApplicUnwnt
Tencent Win32.Trojan.Adpush.Ajtx
Trend Micro ADW_VEGETAP
Dr.Web Trojan.Crossrider.28232
IKARUS anti.virus Trojan.GoogUpdate
Kingsoft AntiVirus Win32.Troj.CroRi.b.(kcloud)
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374109
Bitdefender Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
F-Secure Gen:Variant.Adware.Kazy.374109
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
Rising Antivirus PE:Malware.Obscure!1.9C59
Avira AntiVir ADWARE/CrossRider.Gen2
HD+v2.1-bho.dll (MD5: 5e1c4d1922e87b540faa4ad4d14150b4) has been flagged by 47 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.Ky9@mi0HYMki
Agnitum Outpost Trojan.GoogUpdate!
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CroRi
avast! Win32:Crossrider-AK [PUP]
AVG Vegetapop.B27
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.AF
Bitdefender Gen:Application.Heur.Ky9@mi0HYMki
Bkav FE W32.HfsAdware.E3F4
Comodo Security ApplicUnwnt
Cyren W32/A-ee826839!Eldorado
Dr.Web Trojan.Crossrider.60687
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AF potentially unwanted
Fortinet FortiGate Riskware/CroRi
F-Prot W32/A-ee826839!Eldorado
F-Secure Gen:Application.Heur.Ky9@mi0HYMki
G Data Gen:Application.Heur.Ky9@mi0HYMki
IKARUS anti.virus not-a-virus:WebToolbar.CroRi
Jiangmin Trojan/GoogUpdate.ht
K7 AntiVirus Trojan ( 0049eec71 )
K7GW Trojan ( 0049eec71 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.bba
Kingsoft AntiVirus Win32.Troj.CroRi.a.(kcloud)
Malwarebytes PUP.Optional.PlusHD.A
McAfee Artemis!5E1C4D1922E8
MicroWorld-eScan Gen:Application.Heur.Ky9@mi0HYMki
NANO AntiVirus Trojan.Win32.Toolbar.deifvb
Panda Antivirus Trj/Chgt.B
Qihoo-360 Win32/Virus.WebToolbar.463
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.13
Trend Micro TROJ_GEN.R0C1C0EJG14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJG14
Vba32 AntiVirus Trojan.GoogUpdate
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CroRi.Win32.142
Arcabit Application.Heur.EF0A1C
CAT-QuickHeal PUA.GoogleUpdate.A5
McAfee-GW-Edition PUP-FSD
SUPERAntiSpyware Adware.CrossRider/Variant
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.2 (B)
ViRobot Adware.CrossRider.496456
Avira AntiVir ADWARE/CrossRider.Gen2
e5658fe1-9b25-45a0-8a47-b0b779956f4a-7.exe (MD5: 95d5b8d4e6ad7975fbaaf1457902f1b9) has been flagged by 39 scanners:
Scanner Software Result
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Crossrider-AI [PUP]
AVG Vegetapop.B27
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossRider.Ay
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/S-9ad4719b!Eldorado
G Data Win32.Adware.Crossrider.N
K7 AntiVirus Trojan ( 0049ee4f1 )
K7GW Trojan ( 0049ee4f1 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.bba
Malwarebytes PUP.Optional.PlusHD.A
McAfee Artemis!95D5B8D4E6AD
McAfee-GW-Edition BehavesLike.Win32.PUP.hh
NANO AntiVirus Riskware.Win32.CrossRider.dfompx
Sophos AppRider
Symantec Adware.Crossid
Trend Micro TROJ_GEN.R0C1C0EJB14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJB14
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.49
Antiy-AVL Trojan/NSIS.GoogUpdate
Kingsoft AntiVirus Win32.Troj.CroRi.b.(kcloud)
Qihoo-360 Win32/Virus.WebToolbar.d9e
Dr.Web Trojan.Crossrider.28232
IKARUS anti.virus Trojan.GoogUpdate
Tencent Win32.Trojan.Adpush.Qpnw
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374109
Bitdefender Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
F-Secure Gen:Variant.Adware.Kazy.374109
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Avira AntiVir ADWARE/CrossRider.Gen2
e5658fe1-9b25-45a0-8a47-b0b779956f4a-6.exe (MD5: cc3762f91c5bac0126e6ca795c9b0a0f) has been flagged by 8 scanners:
Scanner Software Result
AVG Vegetapop.B27
AVware Crossrider (fs)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AE
F-Prot W32/A-04c00d5a!Eldorado
IKARUS anti.virus PUA.PlusHD
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Trojan.e1c
VIPRE Antivirus Crossrider (fs)

Software Behaviors

Scheduled tasks:
  • c7d50b1d-2690-4014-92c0-4801c6396a16-6.exe is scheduled as a task named 'temp_c7d50b1d-2690-4014-92c0-4801c6396a16-6'.
  • c7d50b1d-2690-4014-92c0-4801c6396a16-5.exe is scheduled as a task named 'c7d50b1d-2690-4014-92c0-4801c6396a16-5_user'.
  • c7d50b1d-2690-4014-92c0-4801c6396a16-11.exe is scheduled as a task named 'c7d50b1d-2690-4014-92c0-4801c6396a16-3'.
  • 57d05856-1a6c-44dc-9873-1df40136a5ad-2.exe is scheduled as a task named 'temp_57d05856-1a6c-44dc-9873-1df40136a5ad-2'.
  • 9b52645e-3270-43ef-8b28-641c299b2721-6.exe is scheduled as a task named '731b28ed-138e-45a5-af8b-7ef590e61293-6'.

Startup Entries

Startup tasks:
  • 9b52645e-3270-43ef-8b28-641c299b2721-6.exe is automatically launched at startup through a scheduled task named 5d2076bc-d559-4c68-aca0-29a2e5982b96-7.
  • c7d50b1d-2690-4014-92c0-4801c6396a16-5.exe is automatically launched at startup through a scheduled task named c7d50b1d-2690-4014-92c0-4801c6396a16-5_user.
  • c7d50b1d-2690-4014-92c0-4801c6396a16-11.exe is automatically launched at startup through a scheduled task named c7d50b1d-2690-4014-92c0-4801c6396a16-3.
  • 2a902762-9e6c-45d9-8488-dd7c7472f764-7.exe is automatically launched at startup through a scheduled task named 2a902762-9e6c-45d9-8488-dd7c7472f764-1.
  • 2a902762-9e6c-45d9-8488-dd7c7472f764-6.exe is automatically launched at startup through a scheduled task named 2a902762-9e6c-45d9-8488-dd7c7472f764-6.
  • 2a902762-9e6c-45d9-8488-dd7c7472f764-5.exe is automatically launched at startup through a scheduled task named 2a902762-9e6c-45d9-8488-dd7c7472f764-5_user.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\HD+v2.1
Uninstaller:
C:\Program Files\HD+v2.1\Uninstall.exe /fcp=1
Size:
3.00 MB
Language:
English

HD+v2.1 Executable Details

Primary executable:
utils.exe
Name:
HD+v2.1
Path:
C:\Program Files\HD+v2.1\utils.exe
MD5:
203ad5c6c22988734c2d4ddb095d71b0
SHA-1:
–
SHA-256:
–
Files installed by HD+v2.1
File Type Filename MD5
EXE
7d376cd3f5e4b5b1dd6c7f5d725dd917
EXE
203ad5c6c22988734c2d4ddb095d71b0
XPI
c61651fb56a30b67fea0a8f80a50dd2f
EXE
57e253de865817557761e366d057a8d4
DLL
56b242636b3642af52f535e47a4de8e4
DLL
5e1c4d1922e87b540faa4ad4d14150b4
EXE
ae6fa6245cbc2dbe173b35384f1b70d4
EXE
95d5b8d4e6ad7975fbaaf1457902f1b9
EXE
a55072be5f8abf6f5e0cf679d5b87b3e
EXE
cc3762f91c5bac0126e6ca795c9b0a0f