84,488,480 programs installed

Should I remove SS211?

What percent of users and experts removed it?
83% remove it17% keep it
Overall Sentiment
Bad
What do people think about it?
(click star to rate)
How common is it?
United States Rank #48,747
Reach 0.0005%
Lifespan of installation (until removal)
< 7.23 days
197.15 days >
Average installed length: 103.59 days

Versions

VersionDistribution
1.34.6.10 100.00%

SS211

What is SS211?

smart-splus is an adware web browser application that displays banner ads as well as contextual link ads that are injected in the web page. The ads are injected by the web browser plugin (IE, FF and Chrome) and will display on any web site, even those not associated or affiliated with the publisher. On web pages there may be up to 10 intext ads and/or 4 banner ad and/or a transitional ad. The application is usually bundled by 3rd-party download managers that utilize deceptive advertising techniques in order to install the software. In addition to ads, the program will also modify the browser settings which could include lowering the normal security settings of the browser as well as changing the home page and search provider (known as web browser hijacking). The extension will also report back to the controlling server analytics which may include the behavior of the user on the Internet and reports back URLs and domains visited as well as what advertisements are displayed and clicked on. This adware is mostly bundled with 3rd party download managers that include a number of additional offers, all potentially unwanted programs.

Overview

During setup, the program registers itself to launch on boot through a Windows Schedule Task in order to automatically start-up (this is typically done to avoid any UAC prompts). It adds a Browser Helper Object (BHO) to Internet Explorer. A scheduled task is added to Windows Task Scheduler in order to launch the program at various scheduled times (the schedule varies depending on the version). The main program executable is utils.exe. Typically most users end up uninstalling this just after a few days. The software installer includes 30 files and is usually about 11.97 MB (12,546,351 bytes).

The program is built using the Crossrider framework, a cross browser monetization platform used to deploy a toolbar and extension for modern web browsers with monetization features including browser search and homepage redirection, contextual coupons and in-line text advertising. Crossrider extensions include background processes to monitor, update and automatically download new features/code without direct user interaction.
  • Possible malware installed by this program
  • Automatically starts with Windows
  • Loads into the web browser
  • Built on the Crossrider toolbar platform and potentially unwanted
  • May inject ads in the web browser
  • 'Offers' to modify the browser's home and search pages by default
  • Difficult to remove as it will reinstall itself
  • Typically distributed through a pay-per-install bundle
  • Injects advertisements unassociated with the underlying web page
  • Hijacks the web browser's home page
  • Hijacks the browser's default search provider
  • The experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in SS211.
67300ee8-e28c-4f3d-bd62-265caf3ab494-11.exe (4c145d29ea65cf8156014700ed3eb378) has been flagged by the following 25 scanners:
Anti-Virus softwareVersionDetection
Lavasoft Ad-Aware 912 Trojan.Generic.11446894
Avira AntiVir 7.11.164.42 Adware/CrossRider.A.15595
Baidu-International 4.0.3.1487 Adware.Win32.CrossRider.bAK
Bitdefender 1.0.20.1095 Trojan.Generic.11446894
Comodo Security 18991 ApplicUnwnt
Emsisoft Anti-Malware 8.14.08.07.04 Trojan.Generic.11446894
ESET-NOD32 8.10160 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate 8/7/2014 Riskware/Toolbar_CrossRider
F-Secure 11.2014-07-08_5 Trojan.Generic.11446894
G Data 14.8.24 Trojan.Generic.11446894
IKARUS anti.virus t3scan.1.6.1.0 not-a-virus:WebToolbar.CrossRider
K7 AntiVirus 13.181.12846 Trojan
K7GW 13.181.12846 Trojan ( 0049c2ce1 )
McAfee 5600.7046 Artemis!4C145D29EA65
McAfee-GW-Edition 7.7046 Artemis!4C145D29EA65
MicroWorld-eScan 15.0.0.657 Trojan.Generic.11446894
NANO AntiVirus 0.28.2.60990 Riskware.Win32.AdLoad.dbtdxq
nProtect 14.07.27.01 Trojan.Generic.11446894
Panda Antivirus 14.08.07.04 Trj/Genetic.gen
Qihoo-360 1.0.0.1015 Win32/Virus.Adware.88a
Sophos 4.98 Generic PUA AC
Symantec 8/7/2014 rev. 5 Trojan.Gen
Trend Micro 10.465.07 TROJ_GEN.R047C0OGF14
TrendMicro-HouseCall 7.2.219 TROJ_GEN.R047C0OGF14
VIPRE Antivirus 31654 Crossrider (fs)
67300ee8-e28c-4f3d-bd62-265caf3ab494-2.exe (7f30e88dce8496fdc8702f354da39fdf) has been flagged by the following 25 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Trojan.Generic.11460401
Avira AntiVir 7.11.164.42 Adware/CrossRider.A.15793
Baidu-International 3.5.1.41473 Adware.Win32.CrossRider.bAJ
Bitdefender 7.2 Trojan.Generic.11460401
Comodo Security 18993 ApplicUnwnt
Emsisoft Anti-Malware 3.0.0.600 Trojan.Generic.11460401 (B)
ESET-NOD32 10160 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate 5.1.152.0 Riskware/Toolbar_CrossRider
F-Prot 4.7.1.166 W32/A-eb9ef301!Eldorado
F-Secure 11.0.19100.45 Trojan.Generic.11460401
G Data 24 Trojan.Generic.11460401
IKARUS anti.virus T3.1.6.1.0 not-a-virus:WebToolbar.CrossRider
K7 AntiVirus 9.181.12846 Trojan ( 0049bf0b1 )
K7GW 9.181.12846 Trojan ( 0049bf0b1 )
McAfee 6.0.4.564 Artemis!7F30E88DCE84
McAfee-GW-Edition 2013 Artemis!7F30E88DCE84
MicroWorld-eScan 12.0.250.0 Trojan.Generic.11460401
NANO AntiVirus 0.28.2.60990 Riskware.Win32.AdLoad.dbvcgn
nProtect 2014-07-27.01 Trojan.Generic.11460401
Qihoo-360 1.0.0.1015 Win32/Virus.Adware.a74
Rising Antivirus 25.0.0.11 PE:Malware.Obscure!1.9C59
Sophos 4.98.0 AppRider
Symantec 20131.1.5.61 WS.Reputation.1
TrendMicro-HouseCall 9.700.0.1001 TROJ_GEN.R047B01GN14
VIPRE Antivirus 31654 Crossrider (fs)
SS211-nova.exe (6af3296e00332503fe14d8c2ad0b00e7) has been flagged by the following 14 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Variant.Kazy.397338
Baidu-International 3.5.1.41473 Adware.Win32.CrossRider.bAE
Bitdefender 7.2 Gen:Variant.Kazy.397338
Emsisoft Anti-Malware 3.0.0.600 Gen:Variant.Kazy.397338 (B)
ESET-NOD32 10017 a variant of Win32/Toolbar.CrossRider.AE
F-Secure 11.0.19100.45 Gen:Variant.Kazy.397338
G Data 24 Gen:Variant.Kazy.397338
Kingsoft AntiVirus 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
McAfee 6.0.4.564 Artemis!6AF3296E0033
McAfee-GW-Edition 2013 Artemis!6AF3296E0033
MicroWorld-eScan 12.0.250.0 Gen:Variant.Kazy.397338
Qihoo-360 1.0.0.1015 Win32/Trojan.236
Symantec 20131.1.5.61 WS.Reputation.1
VIPRE Antivirus 30770 Crossrider (fs)
SS211-codedownloader.exe (9c5b4f9e2dcab18d13b075f0d06e6707) has been flagged by the following 13 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Variant.Kazy.402573
Baidu-International 3.5.1.41473 Adware.Win32.CrossRider.bAJ
Bitdefender 7.2 Gen:Variant.Kazy.402573
Emsisoft Anti-Malware 3.0.0.600 Gen:Variant.Kazy.402573 (B)
ESET-NOD32 10029 a variant of Win32/Toolbar.CrossRider.AJ
F-Secure 11.0.19100.45 Gen:Variant.Kazy.402573
G Data 24 Gen:Variant.Kazy.402573
Kingsoft AntiVirus 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
MicroWorld-eScan 12.0.250.0 Gen:Variant.Kazy.402573
NANO AntiVirus 0.28.0.60577 Riskware.Win32.AdLoad.dbtcto
Rising Antivirus 25.0.0.11 PE:Malware.Obscure!1.9C59
Sophos 4.98.0 AppRider
VIPRE Antivirus 30856 Crossrider (fs)
SS211-bho.dll (ce34993e288dbf3970f52942b51a675d) has been flagged by the following 13 scanners:
Anti-Virus softwareSoftware versionDetection
Agnitum Outpost 5.5.1.3 PUA.Toolbar.CrossRider!
Avira AntiVir 7.11.164.220 ADWARE/CrossRider.Gen2
AVG 14.0.0.3986 Generic5.AYEO
AVware 1.5.0.16 Crossrider (fs)
Baidu-International 3.5.1.41473 Adware.Win32.CrossRider.bAF
Comodo Security 19042 ApplicUnwnt
ESET-NOD32 10186 a variant of Win32/Toolbar.CrossRider.AF
F-Prot 4.7.1.166 W32/A-eb9ef301!Eldorado
IKARUS anti.virus T3.1.6.1.0 AdWare.Plush
Rising Antivirus 25.0.0.11 PE:Malware.Obscure!1.9C59
Sophos 4.98.0 AppRider
Symantec 20131.1.5.61 WS.Reputation.1
VIPRE Antivirus 31802 Crossrider (fs)
67300ee8-e28c-4f3d-bd62-265caf3ab494-5.exe (525c3ad6517d4fd7455d67dc36a5a27c) has been flagged by the following 10 scanners:
Anti-Virus softwareSoftware versionDetection
Avira AntiVir 7.11.159.102 Adware/CrossRider.A.15579
Baidu-International 3.5.1.41473 Adware.Win32.CrossRider.bAH
Comodo Security 18809 ApplicUnwnt
ESET-NOD32 10065 a variant of Win32/Toolbar.CrossRider.AH
Fortinet FortiGate 5.1.152.0 Riskware/Toolbar_CrossRider
NANO AntiVirus 0.28.0.60698 Riskware.Win32.AdLoad.dbtctb
Rising Antivirus 25.0.0.11 PE:Malware.Obscure!1.9C59
Symantec 20131.1.5.61 WS.Reputation.1
TrendMicro-HouseCall 9.700.0.1001 Suspicious_GEN.F47V0701
VIPRE Antivirus 31094 Crossrider (fs)
cdb57a21-44db-4327-b163-91e500e22164-5.exe (60b61162f7598f72eddfd90e89225713) has been flagged by the following 8 scanners:
Anti-Virus softwareSoftware versionDetection
Baidu-International 3.5.1.41473 Adware.Win32.CrossRider.BAH
Clam AntiVirus 0.98.4.0 Win.Adware.Agent-7475
ESET-NOD32 10086 a variant of Win32/Toolbar.CrossRider.AH
IKARUS anti.virus T3.1.6.1.0 AdWare.Adload
NANO AntiVirus 0.28.0.60698 Riskware.Win32.AdLoad.dbqwyf
Rising Antivirus 25.0.0.11 PE:Malware.Obscure!1.9C59
VIPRE Antivirus 31204 Crossrider (fs)
Zillya 2.0.0.1855 Adware.AdLoad.Win32.125
67300ee8-e28c-4f3d-bd62-265caf3ab494-4.exe (7035d9e9327c6e9439c84fe46eed3f39) has been flagged by the following 5 scanners:
Anti-Virus softwareSoftware versionDetection
Baidu-International 3.5.1.41473 Adware.Win32.CrossRider.bAG
ESET-NOD32 10029 a variant of Win32/Toolbar.CrossRider.AK
Panda Antivirus 10.0.3.5 Trj/Genetic.gen
Symantec 20131.1.5.61 Trojan.Gen.2
VIPRE Antivirus 30852 Crossrider (fs)
       View all 113 all detections
SS211 has been found to be bundled with 3rd party software. If you have not purposefully installed this, you should be safe uninstalling it.

Program detailsProgram details

Displayed publisher: smart-splus
URL: crossrider.com
Installation folder: C:\Program Files\ss211
Uninstaller: C:\Program Files\SS211\Uninstall.exe /fcp=1
Estimated size: 11.97 MB

Program filesFiles installed by SS211

Program executable:utils.exe
Path:C:\Program Files\ss211\utils.exe
MD5:386af23e02e9fee8322210033af50e24
Additional files:
  • (Malware detected) 67300ee8-e28c-4f3d-bd62-265caf3ab494-11.exe (by smart-splus) - SS211 (SS211 exe)
  • (Malware detected) 67300ee8-e28c-4f3d-bd62-265caf3ab494-2.exe (by smart-splus)
  • (Malware detected) 67300ee8-e28c-4f3d-bd62-265caf3ab494-4.exe
  • (Malware detected) 67300ee8-e28c-4f3d-bd62-265caf3ab494-5.exe
  • 8440f9df-2266-4191-b20b-1b5d5525140f-11.exe
  • 8440f9df-2266-4191-b20b-1b5d5525140f-2.exe
  • 8440f9df-2266-4191-b20b-1b5d5525140f-4.exe
  • 8440f9df-2266-4191-b20b-1b5d5525140f-5.exe
  • cdb57a21-44db-4327-b163-91e500e22164-11.exe
  • cdb57a21-44db-4327-b163-91e500e22164-2.exe
  • cdb57a21-44db-4327-b163-91e500e22164-4.exe
  • (Malware detected) cdb57a21-44db-4327-b163-91e500e22164-5.exe
  • db187c3d-dd2b-4ed4-a656-aff130599119-11.exe
  • db187c3d-dd2b-4ed4-a656-aff130599119-2.exe
  • db187c3d-dd2b-4ed4-a656-aff130599119-5.exe
  • f62f1ba4-a4c0-46f4-9eb7-f5ea445a98e1-11.exe
  • f62f1ba4-a4c0-46f4-9eb7-f5ea445a98e1-2.exe
  • f62f1ba4-a4c0-46f4-9eb7-f5ea445a98e1-4.exe
  • f62f1ba4-a4c0-46f4-9eb7-f5ea445a98e1-5.exe
  • SS211-bg.exe
  • SS211-bho.dll - SS211 BHO
  • SS211-bho64.dll
  • SS211-codedownloader.exe
  • SS211-nova.exe
  • SS211-nova.dll
  • Uninstall.exe

Program behaviorsBehaviors exhibited

2 Internet Explorer BHOs
  • SS211-bho64.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'SS211' with the class of {11111111-1111-1111-1111-110411891118} (CrossriderApp0048918).
  • SS211-bho.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'SS211' with the class of {11111111-1111-1111-1111-110411891118} (CrossriderApp0048918).
Scheduled Task
  • 8440f9df-2266-4191-b20b-1b5d5525140f-2.exe is scheduled as a task named 'temp_8440f9df-2266-4191-b20b-1b5d5525140f-2'.
18 Scheduled Tasks (Boot/Login)
  • SS211-codedownloader.exe is automatically launched at startup through a scheduled task named db187c3d-dd2b-4ed4-a656-aff130599119-6.
  • SS211-nova.exe is automatically launched at startup through a scheduled task named db187c3d-dd2b-4ed4-a656-aff130599119-7.
  • db187c3d-dd2b-4ed4-a656-aff130599119-5.exe is automatically launched at startup through a scheduled task named db187c3d-dd2b-4ed4-a656-aff130599119-5_user.
  • db187c3d-dd2b-4ed4-a656-aff130599119-11.exe is automatically launched at startup through a scheduled task named db187c3d-dd2b-4ed4-a656-aff130599119-3.
  • db187c3d-dd2b-4ed4-a656-aff130599119-2.exe is automatically launched at startup through a scheduled task named db187c3d-dd2b-4ed4-a656-aff130599119-2.
  • f62f1ba4-a4c0-46f4-9eb7-f5ea445a98e1-5.exe is automatically launched at startup through a scheduled task named f62f1ba4-a4c0-46f4-9eb7-f5ea445a98e1-5_user.
  • Plus 12 more

How do I remove SS211?

You can uninstall SS211 from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8/10: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program SS211, click it, and then do one of the following:
    • Windows Vista/7/8/10: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove SS211.
  4. If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.

How do I reset my web browser?

If your web browser homepage and search settings have been modfied by SS211 you can restore them to their previous default settings.
Microsoft Internet Explorer
Mozilla Firefox
Google Chrome

OS VERSIONS
Win 7 (SP1) 33%
Win 7 11%
 
HOW IT STARTS
Scheduled task? Yes
(Runs on Windows boot)
 
USER ACTIONS
Uninstall it 83%
Keep it 17%

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows 7 44.44%
Windows 10 33.33%
Windows Vista 22.22%
Which OS releases does it run on?
Windows Vista Home Premiu... 22.22%
Windows 7 Home Premium 22.22%
Windows 8.1 22.22%
Windows 8.1 Pro with Medi... 11.11%
Windows 7 Professional 11.11%
Windows 7 Enterprise N 11.11%

Distribution by countryGeography

100.00% of installs come from the United States
Which countries install it?
  United States 100.00%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
Hewlett-Packard 55.56%
Dell 22.22%
Acer 11.11%
Lenovo 11.11%
Common models
LENOVO 4385 11.11%
HP Pavilion dv9700 Notebo... 11.11%
HP Pavilion 17 Notebook P... 11.11%
HP Compaq Elite 8300 SFF 11.11%
HP 15 Notebook PC 11.11%
eMachines eME528 11.11%

commentsComments

user comment
No one has commented yet. Help others learn more about this software, share your comments.