HD+v2.1

HD+v2.1

Known Toolbar

by Vegeta Pop

What is HD+v2.1?

HD+v2.1 is software application developed by Vegeta Pop. It is most commonly found on computers running Windows 7 with nearly 51.43% of installations running this operating system. HD+v2.1's installer is typically 3.00 MB in size and installs around 80 files.

HD+v2.1 is most popular in India with 12.04% of installations residing in this country.

HD+v2.1 adds 5 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About HD+v2.1?

HD+ is a browser toolbar/extension that delivers third-party ads to the user's browser on non-affiliated web pages. The ads may appear as new ads or overlay existing ads on the page. Some of these ads may prompt the user to download potentially unwanted software or make purchases from affiliated vendors. Clicking on any offers, including coupons, may redirect the user to advertiser pages and drop affiliate cookies on the user's computer. Additionally, HD+ communicates with a remote server to track user browsing habits, including visited domains, viewed pages, and interactions with advertisements. Please be aware of these functionalities when using this software.

Multiple virus scanners have detected malware in HD+v2.1.

utils.exe (MD5: 203ad5c6c22988734c2d4ddb095d71b0) has been flagged by 48 scanners:
Scanner Software Result
AegisLab AdWare.NSIS.Indirect
Agnitum Outpost Trojan.Crossrider
AhnLab-V3 PUP/Win32.MulDrop
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win64.SearchSuite
Avira ADWARE/CrossRider.Gen2
Bkav FE HW32.Packed
Dr.Web Trojan.Crossrider.31777
ESET-NOD32 Win32/Packed.VMDetector.I
G Data NSIS.Adware.Crossrider
IKARUS anti.virus AdWare.CrossRider
Malwarebytes PUP.Optional.CrossRider.A
McAfee Artemis!203AD5C6C229
McAfee-GW-Edition Artemis
NANO AntiVirus Trojan.Win32.Crossrider.dfnoho
Qihoo-360 HEUR/Malware.QVM20.Gen
Symantec WS.Reputation
Tencent Win32.Trojan.Adpush.Omds
TrendMicro-HouseCall Suspicious_GEN.F47V0812
Vba32 AntiVirus Trojan.GoogUpdate
Lavasoft Ad-Aware Gen:Application.Heur.Ky9@mi0HYMki
avast! Win32:Crossrider-AK [PUP]
AVG Vegetapop.B27
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.AF
Bitdefender Gen:Application.Heur.Ky9@mi0HYMki
Comodo Security ApplicUnwnt
Cyren W32/A-ee826839!Eldorado
Fortinet FortiGate Riskware/CroRi
F-Prot W32/A-ee826839!Eldorado
F-Secure Gen:Application.Heur.Ky9@mi0HYMki
Jiangmin Trojan/GoogUpdate.ht
K7 AntiVirus Trojan ( 0049eec71 )
K7GW Trojan ( 0049eec71 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.bba
Kingsoft AntiVirus Win32.Troj.CroRi.a.(kcloud)
MicroWorld-eScan Gen:Application.Heur.Ky9@mi0HYMki
Panda Antivirus Trj/Chgt.B
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Trend Micro TROJ_GEN.R0C1C0EJG14
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CroRi.Win32.142
Arcabit Application.Heur.EF0A1C
CAT-QuickHeal PUA.GoogleUpdate.A5
SUPERAntiSpyware Adware.CrossRider/Variant
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.2 (B)
ViRobot Adware.CrossRider.496456
Avira AntiVir ADWARE/CrossRider.Gen2
HD+v2.1-codedownloader.exe (MD5: 57e253de865817557761e366d057a8d4) has been flagged by 39 scanners:
Scanner Software Result
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL Trojan/NSIS.GoogUpdate
avast! Win32:Crossrider-AI [PUP]
AVG Vegetapop.B27
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossRider.AQuA
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/S-9ad4719b!Eldorado
G Data Win32.Adware.Crossrider.N
K7 AntiVirus Trojan ( 0049ee4f1 )
K7GW Trojan ( 0049ee4f1 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.bba
Malwarebytes PUP.Optional.PlusHD.A
McAfee Artemis!57E253DE8658
McAfee-GW-Edition BehavesLike.Win32.BadFile.hh
NANO AntiVirus Riskware.Win32.CrossRider.dfompx
Panda Antivirus Trj/Chgt.B
Qihoo-360 Win32/Virus.WebToolbar.85b
Sophos AppRider
Symantec Adware.Crossid
TrendMicro-HouseCall TROJ_GEN.F0C2H00IN14
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.49
Comodo Security ApplicUnwnt
Tencent Win32.Trojan.Adpush.Ajtx
Trend Micro ADW_VEGETAP
Dr.Web Trojan.Crossrider.28232
IKARUS anti.virus Trojan.GoogUpdate
Kingsoft AntiVirus Win32.Troj.CroRi.b.(kcloud)
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374109
Bitdefender Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
F-Secure Gen:Variant.Adware.Kazy.374109
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
Rising Antivirus PE:Malware.Obscure!1.9C59
Avira AntiVir ADWARE/CrossRider.Gen2
HD+v2.1-bho.dll (MD5: 5e1c4d1922e87b540faa4ad4d14150b4) has been flagged by 47 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.Ky9@mi0HYMki
Agnitum Outpost Trojan.GoogUpdate!
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CroRi
avast! Win32:Crossrider-AK [PUP]
AVG Vegetapop.B27
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.AF
Bitdefender Gen:Application.Heur.Ky9@mi0HYMki
Bkav FE W32.HfsAdware.E3F4
Comodo Security ApplicUnwnt
Cyren W32/A-ee826839!Eldorado
Dr.Web Trojan.Crossrider.60687
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AF potentially unwanted
Fortinet FortiGate Riskware/CroRi
F-Prot W32/A-ee826839!Eldorado
F-Secure Gen:Application.Heur.Ky9@mi0HYMki
G Data Gen:Application.Heur.Ky9@mi0HYMki
IKARUS anti.virus not-a-virus:WebToolbar.CroRi
Jiangmin Trojan/GoogUpdate.ht
K7 AntiVirus Trojan ( 0049eec71 )
K7GW Trojan ( 0049eec71 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.bba
Kingsoft AntiVirus Win32.Troj.CroRi.a.(kcloud)
Malwarebytes PUP.Optional.PlusHD.A
McAfee Artemis!5E1C4D1922E8
MicroWorld-eScan Gen:Application.Heur.Ky9@mi0HYMki
NANO AntiVirus Trojan.Win32.Toolbar.deifvb
Panda Antivirus Trj/Chgt.B
Qihoo-360 Win32/Virus.WebToolbar.463
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.13
Trend Micro TROJ_GEN.R0C1C0EJG14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJG14
Vba32 AntiVirus Trojan.GoogUpdate
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CroRi.Win32.142
Arcabit Application.Heur.EF0A1C
CAT-QuickHeal PUA.GoogleUpdate.A5
McAfee-GW-Edition PUP-FSD
SUPERAntiSpyware Adware.CrossRider/Variant
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.2 (B)
ViRobot Adware.CrossRider.496456
Avira AntiVir ADWARE/CrossRider.Gen2
e5658fe1-9b25-45a0-8a47-b0b779956f4a-7.exe (MD5: 95d5b8d4e6ad7975fbaaf1457902f1b9) has been flagged by 39 scanners:
Scanner Software Result
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Crossrider-AI [PUP]
AVG Vegetapop.B27
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossRider.Ay
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/S-9ad4719b!Eldorado
G Data Win32.Adware.Crossrider.N
K7 AntiVirus Trojan ( 0049ee4f1 )
K7GW Trojan ( 0049ee4f1 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.bba
Malwarebytes PUP.Optional.PlusHD.A
McAfee Artemis!95D5B8D4E6AD
McAfee-GW-Edition BehavesLike.Win32.PUP.hh
NANO AntiVirus Riskware.Win32.CrossRider.dfompx
Sophos AppRider
Symantec Adware.Crossid
Trend Micro TROJ_GEN.R0C1C0EJB14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJB14
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.49
Antiy-AVL Trojan/NSIS.GoogUpdate
Kingsoft AntiVirus Win32.Troj.CroRi.b.(kcloud)
Qihoo-360 Win32/Virus.WebToolbar.d9e
Dr.Web Trojan.Crossrider.28232
IKARUS anti.virus Trojan.GoogUpdate
Tencent Win32.Trojan.Adpush.Qpnw
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374109
Bitdefender Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
F-Secure Gen:Variant.Adware.Kazy.374109
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Avira AntiVir ADWARE/CrossRider.Gen2
e5658fe1-9b25-45a0-8a47-b0b779956f4a-6.exe (MD5: cc3762f91c5bac0126e6ca795c9b0a0f) has been flagged by 8 scanners:
Scanner Software Result
AVG Vegetapop.B27
AVware Crossrider (fs)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AE
F-Prot W32/A-04c00d5a!Eldorado
IKARUS anti.virus PUA.PlusHD
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Trojan.e1c
VIPRE Antivirus Crossrider (fs)

Software Behaviors

Scheduled tasks:
  • c7d50b1d-2690-4014-92c0-4801c6396a16-6.exe is scheduled as a task named 'temp_c7d50b1d-2690-4014-92c0-4801c6396a16-6'.
  • c7d50b1d-2690-4014-92c0-4801c6396a16-5.exe is scheduled as a task named 'c7d50b1d-2690-4014-92c0-4801c6396a16-5_user'.
  • c7d50b1d-2690-4014-92c0-4801c6396a16-11.exe is scheduled as a task named 'c7d50b1d-2690-4014-92c0-4801c6396a16-3'.
  • 57d05856-1a6c-44dc-9873-1df40136a5ad-2.exe is scheduled as a task named 'temp_57d05856-1a6c-44dc-9873-1df40136a5ad-2'.
  • 9b52645e-3270-43ef-8b28-641c299b2721-6.exe is scheduled as a task named '731b28ed-138e-45a5-af8b-7ef590e61293-6'.

Startup Entries

Startup tasks:
  • 9b52645e-3270-43ef-8b28-641c299b2721-6.exe is automatically launched at startup through a scheduled task named 5d2076bc-d559-4c68-aca0-29a2e5982b96-7.
  • c7d50b1d-2690-4014-92c0-4801c6396a16-5.exe is automatically launched at startup through a scheduled task named c7d50b1d-2690-4014-92c0-4801c6396a16-5_user.
  • c7d50b1d-2690-4014-92c0-4801c6396a16-11.exe is automatically launched at startup through a scheduled task named c7d50b1d-2690-4014-92c0-4801c6396a16-3.
  • 2a902762-9e6c-45d9-8488-dd7c7472f764-7.exe is automatically launched at startup through a scheduled task named 2a902762-9e6c-45d9-8488-dd7c7472f764-1.
  • 2a902762-9e6c-45d9-8488-dd7c7472f764-6.exe is automatically launched at startup through a scheduled task named 2a902762-9e6c-45d9-8488-dd7c7472f764-6.
  • 2a902762-9e6c-45d9-8488-dd7c7472f764-5.exe is automatically launched at startup through a scheduled task named 2a902762-9e6c-45d9-8488-dd7c7472f764-5_user.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\HD+v2.1
Uninstaller:
C:\Program Files\HD+v2.1\Uninstall.exe /fcp=1
Size:
3.00 MB
Language:
English

HD+v2.1 Executable Details

Primary executable:
utils.exe
Name:
HD+v2.1
Path:
C:\Program Files\HD+v2.1\utils.exe
MD5:
203ad5c6c22988734c2d4ddb095d71b0
SHA-1:
–
SHA-256:
–
Files installed by HD+v2.1
File Type Filename MD5
EXE
ba007511519a0348852819c9c2f41936
EXE
bad8fdb1be360e2fa4d3aed9654dc620
EXE
77d774a5599fca6cea4be4848501dd35
EXE
423b358206ccfd4d5a17e05a193dca05
EXE
b4250b15c3658fbe7c3019c31348f3be
EXE
b3299713ecab67bba97c9e8460b30894
EXE
de13cd5f560111e141c7609a4414d37c
EXE
9766b177b8b6034d99cb522c4ee3812a
EXE
2f25e08777e8852010d78c8bd978b743
EXE
5e0e28c326984403992a1d319fcbce7b