Home Malware Programs Potentially Unwanted Programs (PUPs) PlusVid or Ads by PlusVid

PlusVid or Ads by PlusVid

Posted: May 26, 2014

Threat Metric

Ranking: 19,584
Threat Level: 2/10
Infected PCs: 1,206
First Seen: May 27, 2014
Last Seen: January 29, 2025
OS(es) Affected: Windows


PlusVid is a potentially unwanted program/adware that is developed by Phoenix Media Inc. The PlusVid browser plug-in may state to improve a PC user's YouTube experience by setting the videos to the highest available quality. PlusVid may propagate and integrate itself into popular Web browsers such as Internet Explorer, Google Chrome, and Mozilla Firefox as optional tools bundled with free software. After installation, the PlusVid browser extension may reduce the Web browser's performance and generate and show disturbing ads such as discount coupons, price comparison ads, pop-unders/ups, inline text, banner, or transitional ads. The browser extension of PlusVid may track the PC user's Internet surfing habits on all websites visited.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\PlusVid\d12f8f2d-2ada-484f-a8f6-ae340a687fca-2.exe File name: d12f8f2d-2ada-484f-a8f6-ae340a687fca-2.exe
Size: 360.96 KB (360960 bytes)
MD5: 5b2f8f27479d6c5b1302079bf3668196
Detection count: 115
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\PlusVid
Group: Malware file
Last Updated: June 9, 2014
%PROGRAMFILES(x86)%\PlusVid\PlusVid-bho64.dll File name: PlusVid-bho64.dll
Size: 777.21 KB (777216 bytes)
MD5: 9456d5ed92e022fb01532bd3645d7f27
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\PlusVid
Group: Malware file
Last Updated: June 9, 2014
%PROGRAMFILES%\PlusVid\Uninstall.exe File name: Uninstall.exe
Size: 79.87 KB (79872 bytes)
MD5: c78cc29ea58fe191407886dab8ec72ab
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\PlusVid
Group: Malware file
Last Updated: June 9, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{11111111-1111-1111-1111-110511701120}{22222222-2222-2222-2222-220522702220}{44444444-4444-4444-4444-440544704420}{55555555-5555-5555-5555-550555705520}{66666666-6666-6666-6666-660566706620}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Crossrider\onBeforeNavigate\57020Software\AppDataLow\Software\Crossrider\onRequest\57020Software\AppDataLow\Software\PlusVidSOFTWARE\Classes\CrossriderApp0057020.BHOSOFTWARE\Classes\CrossriderApp0057020.BHO.1SOFTWARE\Classes\CrossriderApp0057020.SandboxSOFTWARE\Classes\CrossriderApp0057020.Sandbox.1Software\InstalledBrowserExtensions\Phoenix Media\57020Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110511701120}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{37acb366-df4b-444e-bdd1-f3726607d4b3}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4184f207-8903-4f7f-9c39-dc909361f9be}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{688d3298-84df-447c-9271-bfa4bdc1adca}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{aeae4b7f-2e12-4bcb-893d-b041dda99252}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511701120}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110511701120}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110511701120}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{37acb366-df4b-444e-bdd1-f3726607d4b3}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4184f207-8903-4f7f-9c39-dc909361f9be}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{688d3298-84df-447c-9271-bfa4bdc1adca}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{aeae4b7f-2e12-4bcb-893d-b041dda99252}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511701120}SOFTWARE\Wow6432Node\PlusVidHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}PlusVid

Additional Information

The following directories were created:
%PROGRAMFILES%\PlusVid%PROGRAMFILES(X86)%\PlusVid
Loading...