93dee4e5-3afd-4154-8946-08f2b5c75d55-11.exe

Robokid Technologies

By using the Crossrider framework, this web extension is loaded in the web browser and displays advertisments on web pages not affiliated by the extension or company. These unwanted advertisements are injected by the extension in the browser in the form of common ad types such as banners and text-links. The application 93dee4e5-3afd-4154-8946-08f2b5c75d55-11.exe by Robokid Technologies has been detected as adware by 20 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. This file is typically installed with the program V-9.1HD by Evangelion Group which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
V-9.1HD  (signed by Robokid Technologies)

Product:
V-9.1HD

Description:
V-9.1HD exe

Version:
1000.1000.1000.1000

MD5:
ee3d98e1af22506950bc591f809b151f

SHA-1:
0136e273605ecf294a9740b2ff99101a31f6e5fb

SHA-256:
c8d9215d4cad8ff69c47e8d700b72a441216c8d2d5bd1fd02b8826bb331fbb73

Scanner detections:
20 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements. Distributed through the Brightcircle investments brand.

Analysis date:
4/27/2024 12:17:21 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.W32.Vilsel
2.1.4+

AhnLab V3 Security
PUP/Win32.CrossRider
2014.10.23

Avira AntiVirus
Adware/CrossRider.gr
7.11.180.154

AVG
Generic
2015.0.3313

Baidu Antivirus
PUA.Win32.CrossRider
4.0.3.141022

Clam AntiVirus
Win.Trojan.Crossrider-71
0.98/21411

Comodo Security
Application.Win32.Plush.GRI
19873

Dr.Web
Trojan.Crossrider.27060
9.0.1.05190

ESET NOD32
Win32/Toolbar.CrossRider.AK potentially unwanted application
7.0.302.0

F-Prot
W32/A-06824249
v6.4.7.1.166

G Data
Win32.Adware.Crossrider
14.10.24

IKARUS anti.virus
Trojan.GoogUpdate
t3scan.1.7.8.0

K7 AntiVirus
Unwanted-Program
13.184.13741

Kaspersky
not-a-virus:WebToolbar.Win32.CroRi
15.0.0.494

Malwarebytes
PUP.Optional.PlusH.A
v2014.10.22.05

NANO AntiVirus
Trojan.Win32.Crossrider.ddhkzt
0.28.2.62841

Reason Heuristics
PUP.Crossrider.Task.h
14.10.22.17

Sophos
AppRider
4.98

VIPRE Antivirus
Threat.4789396
33706

Zillya! Antivirus
Trojan.Black.Win32.17701
2.0.0.1964

File size:
1.9 MB (1,944,088 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
V-9.1HD.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\v-9.1hd\93dee4e5-3afd-4154-8946-08f2b5c75d55-11.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/23/2014 1:00:00 AM

Valid to:
6/24/2015 12:59:59 AM

Subject:
CN=Robokid Technologies, O=Robokid Technologies, STREET=Athinodorou 3 Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00ECF35E880AD0F3BC6F82DFB1F2E84CC0

File PE Metadata
Compilation timestamp:
7/19/2014 11:04:34 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:CSFC64VdSEU6h1kl1BatpSvK/T5Uzn+nPRxS:RFCVdPRh1IL

Entry address:
0xE9184

Entry point:
E8, 42, 00, 01, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 85, F6, 78, 09, E8, 75, 01, 01, 00, 3B, 30, 7C, 07, E8, 6C, 01, 01, 00, 8B, 30, E8, 5F, 01, 01, 00, 8B, 04, B0, 5E, 5D, C3, 55, 8B, EC, 56, E8, 60, 5F, 00, 00, 8B, F0, 85, F6, 75, 07, B8, 10, CD, 54, 00, EB, 26, 53, 57, 33, FF, BB, 86, 00, 00, 00, 39, 7E, 24, 75, 1B, 6A, 01, 53, E8, 7A, 31, 00, 00, 59, 59, 89, 46, 24, 85, C0, 75, 0A, B8, 10, CD, 54, 00, 5F, 5B, 5E, 5D, C3, FF, 75, 08, 8B, 76, 24, E8, 90, FF, FF, FF, 50, 53, 56, E8, D9, ED...
 
[+]

Entropy:
6.8591

Code size:
1.1 MB (1,122,304 bytes)

Scheduled Task
Task name:
93dee4e5-3afd-4154-8946-08f2b5c75d55-11

Trigger:
Logon (Runs on logon)


The file 93dee4e5-3afd-4154-8946-08f2b5c75d55-11.exe has been discovered within the following program.

V-9.1HD  by Evangelion Group
Plus-HD-9.1c (Freeven) is an adware program that runs within the user's web browser and will modify various browser settings such as changing the search provider.
crossrider.com/install/61776-plus-hd-9-1c
86% remove it
 
Powered by Should I Remove It?

Remove 93dee4e5-3afd-4154-8946-08f2b5c75d55-11.exe - Powered by Reason Core Security