HD+v2.1

HD+v2.1

Known Toolbar

by Vegeta Pop

What is HD+v2.1?

HD+v2.1 is software application developed by Vegeta Pop. It is most commonly found on computers running Windows 7 with nearly 51.43% of installations running this operating system. HD+v2.1's installer is typically 3.00 MB in size and installs around 80 files.

HD+v2.1 is most popular in India with 12.04% of installations residing in this country.

HD+v2.1 adds 5 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About HD+v2.1?

HD+ is a browser toolbar/extension that delivers third-party ads to the user's browser on non-affiliated web pages. The ads may appear as new ads or overlay existing ads on the page. Some of these ads may prompt the user to download potentially unwanted software or make purchases from affiliated vendors. Clicking on any offers, including coupons, may redirect the user to advertiser pages and drop affiliate cookies on the user's computer. Additionally, HD+ communicates with a remote server to track user browsing habits, including visited domains, viewed pages, and interactions with advertisements. Please be aware of these functionalities when using this software.

Multiple virus scanners have detected malware in HD+v2.1.

utils.exe (MD5: 203ad5c6c22988734c2d4ddb095d71b0) has been flagged by 48 scanners:
Scanner Software Result
AegisLab AdWare.NSIS.Indirect
Agnitum Outpost Trojan.Crossrider
AhnLab-V3 PUP/Win32.MulDrop
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win64.SearchSuite
Avira ADWARE/CrossRider.Gen2
Bkav FE HW32.Packed
Dr.Web Trojan.Crossrider.31777
ESET-NOD32 Win32/Packed.VMDetector.I
G Data NSIS.Adware.Crossrider
IKARUS anti.virus AdWare.CrossRider
Malwarebytes PUP.Optional.CrossRider.A
McAfee Artemis!203AD5C6C229
McAfee-GW-Edition Artemis
NANO AntiVirus Trojan.Win32.Crossrider.dfnoho
Qihoo-360 HEUR/Malware.QVM20.Gen
Symantec WS.Reputation
Tencent Win32.Trojan.Adpush.Omds
TrendMicro-HouseCall Suspicious_GEN.F47V0812
Vba32 AntiVirus Trojan.GoogUpdate
Lavasoft Ad-Aware Gen:Application.Heur.Ky9@mi0HYMki
avast! Win32:Crossrider-AK [PUP]
AVG Vegetapop.B27
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.AF
Bitdefender Gen:Application.Heur.Ky9@mi0HYMki
Comodo Security ApplicUnwnt
Cyren W32/A-ee826839!Eldorado
Fortinet FortiGate Riskware/CroRi
F-Prot W32/A-ee826839!Eldorado
F-Secure Gen:Application.Heur.Ky9@mi0HYMki
Jiangmin Trojan/GoogUpdate.ht
K7 AntiVirus Trojan ( 0049eec71 )
K7GW Trojan ( 0049eec71 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.bba
Kingsoft AntiVirus Win32.Troj.CroRi.a.(kcloud)
MicroWorld-eScan Gen:Application.Heur.Ky9@mi0HYMki
Panda Antivirus Trj/Chgt.B
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Trend Micro TROJ_GEN.R0C1C0EJG14
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CroRi.Win32.142
Arcabit Application.Heur.EF0A1C
CAT-QuickHeal PUA.GoogleUpdate.A5
SUPERAntiSpyware Adware.CrossRider/Variant
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.2 (B)
ViRobot Adware.CrossRider.496456
Avira AntiVir ADWARE/CrossRider.Gen2
HD+v2.1-codedownloader.exe (MD5: 57e253de865817557761e366d057a8d4) has been flagged by 39 scanners:
Scanner Software Result
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL Trojan/NSIS.GoogUpdate
avast! Win32:Crossrider-AI [PUP]
AVG Vegetapop.B27
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossRider.AQuA
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/S-9ad4719b!Eldorado
G Data Win32.Adware.Crossrider.N
K7 AntiVirus Trojan ( 0049ee4f1 )
K7GW Trojan ( 0049ee4f1 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.bba
Malwarebytes PUP.Optional.PlusHD.A
McAfee Artemis!57E253DE8658
McAfee-GW-Edition BehavesLike.Win32.BadFile.hh
NANO AntiVirus Riskware.Win32.CrossRider.dfompx
Panda Antivirus Trj/Chgt.B
Qihoo-360 Win32/Virus.WebToolbar.85b
Sophos AppRider
Symantec Adware.Crossid
TrendMicro-HouseCall TROJ_GEN.F0C2H00IN14
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.49
Comodo Security ApplicUnwnt
Tencent Win32.Trojan.Adpush.Ajtx
Trend Micro ADW_VEGETAP
Dr.Web Trojan.Crossrider.28232
IKARUS anti.virus Trojan.GoogUpdate
Kingsoft AntiVirus Win32.Troj.CroRi.b.(kcloud)
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374109
Bitdefender Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
F-Secure Gen:Variant.Adware.Kazy.374109
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
Rising Antivirus PE:Malware.Obscure!1.9C59
Avira AntiVir ADWARE/CrossRider.Gen2
HD+v2.1-bho.dll (MD5: 5e1c4d1922e87b540faa4ad4d14150b4) has been flagged by 47 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.Ky9@mi0HYMki
Agnitum Outpost Trojan.GoogUpdate!
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CroRi
avast! Win32:Crossrider-AK [PUP]
AVG Vegetapop.B27
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.AF
Bitdefender Gen:Application.Heur.Ky9@mi0HYMki
Bkav FE W32.HfsAdware.E3F4
Comodo Security ApplicUnwnt
Cyren W32/A-ee826839!Eldorado
Dr.Web Trojan.Crossrider.60687
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AF potentially unwanted
Fortinet FortiGate Riskware/CroRi
F-Prot W32/A-ee826839!Eldorado
F-Secure Gen:Application.Heur.Ky9@mi0HYMki
G Data Gen:Application.Heur.Ky9@mi0HYMki
IKARUS anti.virus not-a-virus:WebToolbar.CroRi
Jiangmin Trojan/GoogUpdate.ht
K7 AntiVirus Trojan ( 0049eec71 )
K7GW Trojan ( 0049eec71 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.bba
Kingsoft AntiVirus Win32.Troj.CroRi.a.(kcloud)
Malwarebytes PUP.Optional.PlusHD.A
McAfee Artemis!5E1C4D1922E8
MicroWorld-eScan Gen:Application.Heur.Ky9@mi0HYMki
NANO AntiVirus Trojan.Win32.Toolbar.deifvb
Panda Antivirus Trj/Chgt.B
Qihoo-360 Win32/Virus.WebToolbar.463
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.13
Trend Micro TROJ_GEN.R0C1C0EJG14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJG14
Vba32 AntiVirus Trojan.GoogUpdate
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CroRi.Win32.142
Arcabit Application.Heur.EF0A1C
CAT-QuickHeal PUA.GoogleUpdate.A5
McAfee-GW-Edition PUP-FSD
SUPERAntiSpyware Adware.CrossRider/Variant
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.2 (B)
ViRobot Adware.CrossRider.496456
Avira AntiVir ADWARE/CrossRider.Gen2
e5658fe1-9b25-45a0-8a47-b0b779956f4a-7.exe (MD5: 95d5b8d4e6ad7975fbaaf1457902f1b9) has been flagged by 39 scanners:
Scanner Software Result
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Crossrider-AI [PUP]
AVG Vegetapop.B27
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossRider.Ay
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/S-9ad4719b!Eldorado
G Data Win32.Adware.Crossrider.N
K7 AntiVirus Trojan ( 0049ee4f1 )
K7GW Trojan ( 0049ee4f1 )
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.bba
Malwarebytes PUP.Optional.PlusHD.A
McAfee Artemis!95D5B8D4E6AD
McAfee-GW-Edition BehavesLike.Win32.PUP.hh
NANO AntiVirus Riskware.Win32.CrossRider.dfompx
Sophos AppRider
Symantec Adware.Crossid
Trend Micro TROJ_GEN.R0C1C0EJB14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJB14
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.49
Antiy-AVL Trojan/NSIS.GoogUpdate
Kingsoft AntiVirus Win32.Troj.CroRi.b.(kcloud)
Qihoo-360 Win32/Virus.WebToolbar.d9e
Dr.Web Trojan.Crossrider.28232
IKARUS anti.virus Trojan.GoogUpdate
Tencent Win32.Trojan.Adpush.Qpnw
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374109
Bitdefender Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
F-Secure Gen:Variant.Adware.Kazy.374109
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Avira AntiVir ADWARE/CrossRider.Gen2
e5658fe1-9b25-45a0-8a47-b0b779956f4a-6.exe (MD5: cc3762f91c5bac0126e6ca795c9b0a0f) has been flagged by 8 scanners:
Scanner Software Result
AVG Vegetapop.B27
AVware Crossrider (fs)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AE
F-Prot W32/A-04c00d5a!Eldorado
IKARUS anti.virus PUA.PlusHD
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Trojan.e1c
VIPRE Antivirus Crossrider (fs)

Software Behaviors

Scheduled tasks:
  • c7d50b1d-2690-4014-92c0-4801c6396a16-6.exe is scheduled as a task named 'temp_c7d50b1d-2690-4014-92c0-4801c6396a16-6'.
  • c7d50b1d-2690-4014-92c0-4801c6396a16-5.exe is scheduled as a task named 'c7d50b1d-2690-4014-92c0-4801c6396a16-5_user'.
  • c7d50b1d-2690-4014-92c0-4801c6396a16-11.exe is scheduled as a task named 'c7d50b1d-2690-4014-92c0-4801c6396a16-3'.
  • 57d05856-1a6c-44dc-9873-1df40136a5ad-2.exe is scheduled as a task named 'temp_57d05856-1a6c-44dc-9873-1df40136a5ad-2'.
  • 9b52645e-3270-43ef-8b28-641c299b2721-6.exe is scheduled as a task named '731b28ed-138e-45a5-af8b-7ef590e61293-6'.

Startup Entries

Startup tasks:
  • 9b52645e-3270-43ef-8b28-641c299b2721-6.exe is automatically launched at startup through a scheduled task named 5d2076bc-d559-4c68-aca0-29a2e5982b96-7.
  • c7d50b1d-2690-4014-92c0-4801c6396a16-5.exe is automatically launched at startup through a scheduled task named c7d50b1d-2690-4014-92c0-4801c6396a16-5_user.
  • c7d50b1d-2690-4014-92c0-4801c6396a16-11.exe is automatically launched at startup through a scheduled task named c7d50b1d-2690-4014-92c0-4801c6396a16-3.
  • 2a902762-9e6c-45d9-8488-dd7c7472f764-7.exe is automatically launched at startup through a scheduled task named 2a902762-9e6c-45d9-8488-dd7c7472f764-1.
  • 2a902762-9e6c-45d9-8488-dd7c7472f764-6.exe is automatically launched at startup through a scheduled task named 2a902762-9e6c-45d9-8488-dd7c7472f764-6.
  • 2a902762-9e6c-45d9-8488-dd7c7472f764-5.exe is automatically launched at startup through a scheduled task named 2a902762-9e6c-45d9-8488-dd7c7472f764-5_user.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\HD+v2.1
Uninstaller:
C:\Program Files\HD+v2.1\Uninstall.exe /fcp=1
Size:
3.00 MB
Language:
English

HD+v2.1 Executable Details

Primary executable:
utils.exe
Name:
HD+v2.1
Path:
C:\Program Files\HD+v2.1\utils.exe
MD5:
203ad5c6c22988734c2d4ddb095d71b0
SHA-1:
–
SHA-256:
–
Files installed by HD+v2.1
File Type Filename MD5
EXE
81e63049e4c6de1e7ad886295ca0cc67
EXE
15f2251ac8709cd9b2475161e5eec1c7
EXE
6050be6ee3feb8ce58907f3fd030f00c
EXE
60a6f9a5f3e217076c5f1a1088385094
EXE
91bcedb97eba751c5764ee103d5d4849
EXE
70c851a72088fccba62640b549c0efef
EXE
3df9afe80ff9510eb3a677ca707ec5a6
EXE
5e02b35e0b1f1047798a0122e207b220
EXE
438fc2b8a74176911edce2e8de54850f
EXE
68491eb417819329803a76416c2db102