Kimahri Software inc.

Publisher Information

Kimahri Software inc. is a software developer located in Montreal, Quebec in Canada*. The company is a primary distributor of adware type software. The subdivision of Yuna Software (Messenger Plus!), Kimahri developes and distributes web brower extensions using the Crossrider platform which is considered adware as the extensions it delivers may inject advertisements in the Internet browsers it is installed in. Through 3rd-party bundling mechanism the software is typically distributed. There is one additional code signing certificate issued to this publisher.
Authority:
COMODO CA Limited

Valid from:
3/7/2013 1:00:00 AM

Valid to:
3/7/2016 12:59:59 AM

Subject:
CN=Kimahri Software inc., O=Kimahri Software inc., STREET=666 Sherbrooke Rue w, L=Montreal, S=Quebec, PostalCode=H3A 1E7, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00a1bb8569950c0b2080a11a0e2f618b33

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Crossrider.KimahriSoftwareinc.V, PUP.Crossrider.KimahriSoftwareinc.X, PUP.KimahriSoftwareinc.R, PUP.KimahriSoftwareinc.J, PUP.KimahriSoftwareinc.T, PUP.Crossrider.Task.g, PUP.Task.KimahriSoftwareinc.O, PUP.Installer.KimahriSoftwareinc.F, PUP.Crossrider.KimahriSoftwareinc.N, PUP.KimahriSoftwareinc.O, PUP.Crossrider.KimahriSoftwareinc.M, PUP.Crossrider.KimahriSoftwareinc.P, Adware.Task.KimahriSoftwareinc.Z, Adware.Task.KimahriSoftwareinc.BB, PUP.Crossrider.KimahriSoftwareinc.W, PUP.KimahriSoftwareinc.V
100.00%

VIPRE Antivirus
Threat.4789396, Crossrider, Trojan.Win32.Generic
94.00%

Panda Antivirus
PUP/PlusHD, Trj/Genetic.gen
94.00%

G Data
Gen:Application.Heur.Ay5@k437FYci, Gen:Adware.Plush, Win32.Application.Plush, Gen:Application.Heur.Zu1@kGsWS6fO, Gen:Application.Heur.Ky1@kKusxOoi
82.00%

avast!
Win32:Crossrider-F [PUP], Win32:Crossrider-AI [PUP], Win32:PUP-gen [PUP], Win32:Malware-gen, Win32:Crossrider-AG [PUP], Win32:Adware-gen [Adw]
72.00%

Dr.Web
Adware.Siggen.31029, Adware.Siggen.31030, Adware.Siggen.31031, Trojan.Crossrider.27207, Trojan.Crossrider.27693, Trojan.Crossrider.41
72.00%

Kaspersky
not-a-virus:WebToolbar.Win32.CroRi, not-a-virus:AdWare.Win32.Agent, not-a-virus:AdWare.Win32.Lyckriks
68.00%

Avira AntiVirus
ADWARE/CrossRider.Gen2, Adware/CrossRider.A.1071, Adware/CrossRider.A.4818, ADWARE/CrossRider.Gen4, Adware/CrossRider.A.8023
66.00%

Baidu Antivirus
Adware.Win32.CrossAd, Adware.Win32.CrossRider, Adware.Win64.Crossrider, Adware.Win32.AddLyrics, PUA.Win32.CrossRider
64.00%

Malwarebytes
PUP.Optional.PlusHD.A, PUP.Optional.HQPro.A, PUP.Optional.CrossRider, PUP.Optional.CrossRider.A, PUP.Optional.ScramblePacker.A, PUP.Optional.HQVideoPro.A, Adware.Packed.Ranver
64.00%

7 / 68      (Adware)
plus-hd-4.9-buttonutil64.exe (Plus-HD-4.9 by Plus HD)  (3dd66ff6eff85d760a46d3005a03c8dd)

5 / 68      (Adware)
plus-hd-4.9-buttonutil64.dll  (f88f59f8e31bc9c48173cfddc9c0ce2e)

2 / 68      (Adware)
plus-hd-2-6.exe (Lqbgyosm by Lckbllfbtkldjt)  (290d20dbfc7326f0ae5d8a1b3f4fcc82)

9 / 68      (Adware)
plus-hd-2.6-bho64.dll (Plus-HD-2.6 by Plus HD)  (fd56542481f13483bd797792292192ed)

9 / 68      (Adware)
plushd_2305_us-b94a4ffe.exe (by Iqgdsawawj)  (5c1f6ff465093bbbc3e8e4b841f8f5c4)

8 / 68      (Adware)
fps12.exe (by Vdlwwisxumfs)  (d87d4a009c94ff5db5c1e82c4ff37a10)

11 / 68    (Adware)
hqvideo_fr_1305-884f8b0a.exe (Stqojhuqy by Cyuezjiyfbdba)  (5ac7d05be4f3020d387ff86effe663b2)

39 / 68    (Adware)
plus-hd-1.3-bho.dll (Plus-HD-1.3 by Plus HD)  (5b83009504c6bb22c3a3fcd4ffb71a22)

28 / 68    (Adware)
plus-hd-1.3-updater.exe (Plus-HD-1.3 by Plus HD)  (e89e3e51a0a42a27e52e66387dbad8eb)

29 / 68    (Adware)
plus-hd-1.3-firefoxinstaller.exe (Plus-HD-1.3 by Plus HD)  (8b9487953f1dc22d861f6732c68d85d6)

30 / 68    (Adware)
plus-hd-1.3-enabler.exe (Plus-HD-1.3 by Plus HD)  (072441478e564dc94fa190f5ee6e2436)

31 / 68    (Adware)
plus-hd-1.3-codedownloader.exe (Plus-HD-1.3 by Plus HD)  (47c01f5dede98133801e07f9c767459f)

28 / 68    (Adware)
plus-hd-1.3-chromeinstaller.exe (Plus-HD-1.3 by Plus HD)  (28fc7d75247b75e727f29c685a5133c0)

11 / 68    (Adware)
uninstall.exe  (f3d96d835dc5a39634a8d8d4d0685f31)

20 / 68    (Adware)
plus-hd-4.9-helper.exe  (74c1b07ee90f98c969e5bfed34c92921)

30 / 68    (Adware)
plus-hd-4.9-buttonutil.exe (Plus-HD-4.9 by Plus HD)  (65529c76c6366dac840c1a9da11efd6e)

26 / 68    (Adware)
plus-hd-4.9-buttonutil.dll  (df2c9afff5d3577225de693199114f39)

38 / 68    (Adware)
plus-hd-4.9-bg.exe (Plus-HD-4.9 by Plus HD)  (4f7ea85152ff3ec04bc912681f11dd1a)

9 / 68      (Adware)
uninstall.exe  (7d2aa25eccc8e5796f1fa54854847196)

23 / 68    (Adware)
hq-video-pro-1.9-bho.dll (HQ-Video-Pro-1.9 by HQ-Video)  (6274497935f9cb832a380365bcbd68a5)

25 / 68    (Adware)

11 / 68    (Adware)
uninstall.exe  (4fbb8f11251d111fc9baf6f3176241c8)

1 / 68      (Adware)
fre_ven_s pro 23-nova.dll  (4252e6b5cc04367c0c0c6c48249f325b)

17 / 68    (Adware)
fre_ven_s pro 23-bho64.dll (Fre_Ven_s Pro 23 by setup)  (1d86a131e79a892f9a04b7e1993f831b)

23 / 68    (Adware)
fre_ven_s pro 23-bg.exe (Fre_Ven_s Pro 23 by setup)  (4a971566b352943a13b3b9d50695d9c1)

25 / 68    (Adware)
plus-hd-3.7-firefoxinstaller.exe (Plus-HD-3.7 by Plus HD)  (33c500bfd4742710020d6b4bedd27867)

27 / 68    (Adware)
plus-hd-3.7-codedownloader.exe (Plus-HD-3.7 by Plus HD)  (5a44a95f1b55008baf0f4219eadca0d5)

10 / 68    (Adware)
fre_ven_s pro 23-nova.exe (Fre_Ven_s Pro 23 by setup)  (2a5b9130dd08713896b79f8e7816071b)

24 / 68    (Adware)
uninstall.exe  (55faa9c65991631fe76f73ccf36c23bb)

15 / 68    (Adware)
hqvro-1.91-bho64.dll (HQVro-1.91 by HQVro1)  (6366949aabfd5ae29c7f1fba3c91b19b)

 
Latest 30 of 7,579 files

The following certificate is also signed by Kimahri Software inc..

07C63B61BAA996BF90FF340CD94B17DA  (Jun 20, 2012 to Jun 21, 2013)

The following publishers (by Authenticode signature organization name) are related.

30 of 30 publishers

Detection Incidence by Country
* Note, the details and description above are based on the code signing digital signature issued to Kimahri Software inc. by COMODO CA Limited on March 07, 2013 with the serial number '00a1bb8569950c0b2080a11a0e2f618b33'.