74,139,804 programs installed

Should I remove SS211?

What percent of users and experts removed it?
83% remove it17% keep it
Overall Sentiment
What do people think about it?
(click star to rate)
How common is it?
United States Rank #42,529
Reach 0.0006%
Lifespan of installation (until removal)
< 7.23 days
64.20 days >
Average installed length: 33.73 days


VersionDistribution 100.00%


What is SS211?

smart-splus is an adware web browser application that displays banner ads as well as contextual link ads that are injected in the web page. The ads are injected by the web browser plugin (IE, FF and Chrome) and will display on any web site, even those not associated or affiliated with the publisher. On web pages there may be up to 10 intext ads and/or 4 banner ad and/or a transitional ad. The application is usually bundled by 3rd-party download managers that utilize deceptive advertising techniques in order to install the software. In addition to ads, the program will also modify the browser settings which could include lowering the normal security settings of the browser as well as changing the home page and search provider (known as web browser hijacking). The extension will also report back to the controlling server analytics which may include the behavior of the user on the Internet and reports back URLs and domains visited as well as what advertisements are displayed and clicked on. This adware is mostly bundled with 3rd party download managers that include a number of additional offers, all potentially unwanted programs.


During setup, the program registers itself to launch on boot through a Windows Schedule Task in order to automatically start-up (this is typically done to avoid any UAC prompts). It adds a Browser Helper Object (BHO) to Internet Explorer. A scheduled task is added to Windows Task Scheduler in order to launch the program at various scheduled times (the schedule varies depending on the version). The main program executable is utils.exe. Typically most users end up uninstalling this just after a few days. The software installer includes 27 files and is usually about 11.97 MB (12,546,351 bytes).

The program is built using the Crossrider framework, a cross browser monetization platform used to deploy a toolbar and extension for modern web browsers with monetization features including browser search and homepage redirection, contextual coupons and in-line text advertising. Crossrider extensions include background processes to monitor, update and automatically download new features/code without direct user interaction.
  • Possible malware installed by this program
  • Automatically starts with Windows
  • Loads into the web browser
  • Built on the Crossrider toolbar platform and potentially unwanted
  • May inject ads in the web browser
  • 'Offers' to modify the browser's home and search pages by default
  • Difficult to remove as it will reinstall itself
  • Typically distributed through a pay-per-install bundle
  • Injects advertisements unassociated with the underlying web page
  • Hijacks the web browser's home page
  • Hijacks the browser's default search provider
  • The experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in SS211.
67300ee8-e28c-4f3d-bd62-265caf3ab494-11.exe (4c145d29ea65cf8156014700ed3eb378) has been flagged by the following 25 scanners:
Anti-Virus softwareVersionDetection
Lavasoft Ad-Aware 912 Trojan.Generic.11446894
Avira AntiVir Adware/CrossRider.A.15595
Baidu-International Adware.Win32.CrossRider.bAK
Bitdefender Trojan.Generic.11446894
Comodo Security 18991 ApplicUnwnt
Emsisoft Anti-Malware Trojan.Generic.11446894
ESET-NOD32 8.10160 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate 8/7/2014 Riskware/Toolbar_CrossRider
F-Secure 11.2014-07-08_5 Trojan.Generic.11446894
G Data 14.8.24 Trojan.Generic.11446894
IKARUS anti.virus t3scan. not-a-virus:WebToolbar.CrossRider
K7 AntiVirus 13.181.12846 Trojan
K7GW 13.181.12846 Trojan ( 0049c2ce1 )
McAfee 5600.7046 Artemis!4C145D29EA65
McAfee-GW-Edition 7.7046 Artemis!4C145D29EA65
MicroWorld-eScan Trojan.Generic.11446894
NANO AntiVirus Riskware.Win32.AdLoad.dbtdxq
nProtect Trojan.Generic.11446894
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.88a
Sophos 4.98 Generic PUA AC
Symantec 8/7/2014 rev. 5 Trojan.Gen
Trend Micro 10.465.07 TROJ_GEN.R047C0OGF14
TrendMicro-HouseCall 7.2.219 TROJ_GEN.R047C0OGF14
VIPRE Antivirus 31654 Crossrider (fs)
67300ee8-e28c-4f3d-bd62-265caf3ab494-2.exe (7f30e88dce8496fdc8702f354da39fdf) has been flagged by the following 25 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware Trojan.Generic.11460401
Avira AntiVir Adware/CrossRider.A.15793
Baidu-International Adware.Win32.CrossRider.bAJ
Bitdefender 7.2 Trojan.Generic.11460401
Comodo Security 18993 ApplicUnwnt
Emsisoft Anti-Malware Trojan.Generic.11460401 (B)
ESET-NOD32 10160 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-eb9ef301!Eldorado
F-Secure 11.0.19100.45 Trojan.Generic.11460401
G Data 24 Trojan.Generic.11460401
IKARUS anti.virus T3. not-a-virus:WebToolbar.CrossRider
K7 AntiVirus 9.181.12846 Trojan ( 0049bf0b1 )
K7GW 9.181.12846 Trojan ( 0049bf0b1 )
McAfee Artemis!7F30E88DCE84
McAfee-GW-Edition 2013 Artemis!7F30E88DCE84
MicroWorld-eScan Trojan.Generic.11460401
NANO AntiVirus Riskware.Win32.AdLoad.dbvcgn
nProtect 2014-07-27.01 Trojan.Generic.11460401
Qihoo-360 Win32/Virus.Adware.a74
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos 4.98.0 AppRider
Symantec 20131.1.5.61 WS.Reputation.1
TrendMicro-HouseCall 9.700.0.1001 TROJ_GEN.R047B01GN14
VIPRE Antivirus 31654 Crossrider (fs)
SS211-nova.exe (6af3296e00332503fe14d8c2ad0b00e7) has been flagged by the following 14 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware Gen:Variant.Kazy.397338
Baidu-International Adware.Win32.CrossRider.bAE
Bitdefender 7.2 Gen:Variant.Kazy.397338
Emsisoft Anti-Malware Gen:Variant.Kazy.397338 (B)
ESET-NOD32 10017 a variant of Win32/Toolbar.CrossRider.AE
F-Secure 11.0.19100.45 Gen:Variant.Kazy.397338
G Data 24 Gen:Variant.Kazy.397338
Kingsoft AntiVirus 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!6AF3296E0033
McAfee-GW-Edition 2013 Artemis!6AF3296E0033
MicroWorld-eScan Gen:Variant.Kazy.397338
Qihoo-360 Win32/Trojan.236
Symantec 20131.1.5.61 WS.Reputation.1
VIPRE Antivirus 30770 Crossrider (fs)
SS211-codedownloader.exe (9c5b4f9e2dcab18d13b075f0d06e6707) has been flagged by the following 13 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware Gen:Variant.Kazy.402573
Baidu-International Adware.Win32.CrossRider.bAJ
Bitdefender 7.2 Gen:Variant.Kazy.402573
Emsisoft Anti-Malware Gen:Variant.Kazy.402573 (B)
ESET-NOD32 10029 a variant of Win32/Toolbar.CrossRider.AJ
F-Secure 11.0.19100.45 Gen:Variant.Kazy.402573
G Data 24 Gen:Variant.Kazy.402573
Kingsoft AntiVirus 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
MicroWorld-eScan Gen:Variant.Kazy.402573
NANO AntiVirus Riskware.Win32.AdLoad.dbtcto
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos 4.98.0 AppRider
VIPRE Antivirus 30856 Crossrider (fs)
SS211-bho.dll (ce34993e288dbf3970f52942b51a675d) has been flagged by the following 13 scanners:
Anti-Virus softwareSoftware versionDetection
Agnitum Outpost PUA.Toolbar.CrossRider!
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic5.AYEO
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossRider.bAF
Comodo Security 19042 ApplicUnwnt
ESET-NOD32 10186 a variant of Win32/Toolbar.CrossRider.AF
F-Prot W32/A-eb9ef301!Eldorado
IKARUS anti.virus T3. AdWare.Plush
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos 4.98.0 AppRider
Symantec 20131.1.5.61 WS.Reputation.1
VIPRE Antivirus 31802 Crossrider (fs)
67300ee8-e28c-4f3d-bd62-265caf3ab494-5.exe (525c3ad6517d4fd7455d67dc36a5a27c) has been flagged by the following 10 scanners:
Anti-Virus softwareSoftware versionDetection
Avira AntiVir Adware/CrossRider.A.15579
Baidu-International Adware.Win32.CrossRider.bAH
Comodo Security 18809 ApplicUnwnt
ESET-NOD32 10065 a variant of Win32/Toolbar.CrossRider.AH
Fortinet FortiGate Riskware/Toolbar_CrossRider
NANO AntiVirus Riskware.Win32.AdLoad.dbtctb
Rising Antivirus PE:Malware.Obscure!1.9C59
Symantec 20131.1.5.61 WS.Reputation.1
TrendMicro-HouseCall 9.700.0.1001 Suspicious_GEN.F47V0701
VIPRE Antivirus 31094 Crossrider (fs)
cdb57a21-44db-4327-b163-91e500e22164-5.exe (60b61162f7598f72eddfd90e89225713) has been flagged by the following 8 scanners:
Anti-Virus softwareSoftware versionDetection
Baidu-International Adware.Win32.CrossRider.BAH
Clam AntiVirus Win.Adware.Agent-7475
ESET-NOD32 10086 a variant of Win32/Toolbar.CrossRider.AH
IKARUS anti.virus T3. AdWare.Adload
NANO AntiVirus Riskware.Win32.AdLoad.dbqwyf
Rising Antivirus PE:Malware.Obscure!1.9C59
VIPRE Antivirus 31204 Crossrider (fs)
Zillya Adware.AdLoad.Win32.125
67300ee8-e28c-4f3d-bd62-265caf3ab494-4.exe (7035d9e9327c6e9439c84fe46eed3f39) has been flagged by the following 5 scanners:
Anti-Virus softwareSoftware versionDetection
Baidu-International Adware.Win32.CrossRider.bAG
ESET-NOD32 10029 a variant of Win32/Toolbar.CrossRider.AK
Panda Antivirus Trj/Genetic.gen
Symantec 20131.1.5.61 Trojan.Gen.2
VIPRE Antivirus 30852 Crossrider (fs)
       View all 113 all detections
SS211 has been found to be bundled with 3rd party software. If you have not purposefully installed this, you should be safe uninstalling it.
Find out how to remove SS211.

Program detailsProgram details

Displayed publisher: smart-splus
URL: crossrider.com
Installation folder: C:\Program Files\ss211
Uninstaller: C:\Program Files\SS211\Uninstall.exe /fcp=1
Warning, the included uninstaller may not work, it is highly recommended to use Reason Core Security.
Estimated size: 11.97 MB

Program filesFiles installed by SS211

Program executable:utils.exe
Path:C:\Program Files\ss211\utils.exe
Additional files:
  • (Malware detected) 67300ee8-e28c-4f3d-bd62-265caf3ab494-11.exe (by smart-splus) - SS211 (SS211 exe)
  • (Malware detected) 67300ee8-e28c-4f3d-bd62-265caf3ab494-2.exe (by smart-splus)
  • (Malware detected) 67300ee8-e28c-4f3d-bd62-265caf3ab494-4.exe
  • (Malware detected) 67300ee8-e28c-4f3d-bd62-265caf3ab494-5.exe
  • 8440f9df-2266-4191-b20b-1b5d5525140f-11.exe
  • 8440f9df-2266-4191-b20b-1b5d5525140f-2.exe
  • 8440f9df-2266-4191-b20b-1b5d5525140f-4.exe
  • 8440f9df-2266-4191-b20b-1b5d5525140f-5.exe
  • cdb57a21-44db-4327-b163-91e500e22164-11.exe
  • cdb57a21-44db-4327-b163-91e500e22164-2.exe
  • cdb57a21-44db-4327-b163-91e500e22164-4.exe
  • (Malware detected) cdb57a21-44db-4327-b163-91e500e22164-5.exe
  • db187c3d-dd2b-4ed4-a656-aff130599119-11.exe
  • db187c3d-dd2b-4ed4-a656-aff130599119-2.exe
  • db187c3d-dd2b-4ed4-a656-aff130599119-5.exe
  • f62f1ba4-a4c0-46f4-9eb7-f5ea445a98e1-11.exe
  • f62f1ba4-a4c0-46f4-9eb7-f5ea445a98e1-2.exe
  • f62f1ba4-a4c0-46f4-9eb7-f5ea445a98e1-4.exe
  • f62f1ba4-a4c0-46f4-9eb7-f5ea445a98e1-5.exe
  • SS211-bg.exe
  • SS211-bho.dll - SS211 BHO
  • SS211-bho64.dll
  • SS211-codedownloader.exe
  • SS211-nova.exe
  • SS211-nova.dll
  • Uninstall.exe

Program behaviorsBehaviors exhibited

2 Internet Explorer BHOs
  • SS211-bho64.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'SS211' with the class of {11111111-1111-1111-1111-110411891118} (CrossriderApp0048918).
  • SS211-bho.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'SS211' with the class of {11111111-1111-1111-1111-110411891118} (CrossriderApp0048918).
Scheduled Task
  • 8440f9df-2266-4191-b20b-1b5d5525140f-2.exe is scheduled as a task named 'temp_8440f9df-2266-4191-b20b-1b5d5525140f-2'.
18 Scheduled Tasks (Boot/Login)
  • SS211-codedownloader.exe is automatically launched at startup through a scheduled task named db187c3d-dd2b-4ed4-a656-aff130599119-6.
  • SS211-nova.exe is automatically launched at startup through a scheduled task named db187c3d-dd2b-4ed4-a656-aff130599119-7.
  • db187c3d-dd2b-4ed4-a656-aff130599119-5.exe is automatically launched at startup through a scheduled task named db187c3d-dd2b-4ed4-a656-aff130599119-5_user.
  • db187c3d-dd2b-4ed4-a656-aff130599119-11.exe is automatically launched at startup through a scheduled task named db187c3d-dd2b-4ed4-a656-aff130599119-3.
  • db187c3d-dd2b-4ed4-a656-aff130599119-2.exe is automatically launched at startup through a scheduled task named db187c3d-dd2b-4ed4-a656-aff130599119-2.
  • f62f1ba4-a4c0-46f4-9eb7-f5ea445a98e1-5.exe is automatically launched at startup through a scheduled task named f62f1ba4-a4c0-46f4-9eb7-f5ea445a98e1-5_user.
  • Plus 12 more

How do I remove SS211?

Quickly and completely remove SS211 from your computer by downloading "Should I Remove It?", its 100% FREE and installs in seconds (click the button below).
Download "Should I Remove It?", it's FREE!Remove SS211 from your computer.
Or, you can uninstall SS211 from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program SS211, click it, and then do one of the following:
    • Windows Vista/7/8: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove SS211.
  4. If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.

How do I reset my web browser?

If your web browser homepage and search settings have been modfied by SS211 you can restore them to their previous default settings.
Microsoft Internet Explorer
Mozilla Firefox
Google Chrome
Scan your PC for malware
If you do not have a good anti-virus program, please consider installing one. Below are some we highly recommend.

Win 7 (SP1) 38%
Win Vista (SP2) 25%
Scheduled task? Yes
(Runs on Windows boot)
Uninstall it 83%
Keep it 17%

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows 7 37.50%
Windows 8 37.50%
Windows Vista 25.00%
Which OS releases does it run on?
Windows 8.1 25.00%
Windows Vista Home Premiu... 25.00%
Windows 7 Enterprise N 12.50%
Windows 7 Home Premium 12.50%
Windows 7 Professional 12.50%
Windows 8.1 Pro with Medi... 12.50%

Distribution by countryGeography

100.00% of installs come from the United States
Which countries install it?
  United States 100.00%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
Hewlett-Packard 62.50%
Dell 25.00%
Acer 12.50%
Common models
HP Pavilion dv9700 Notebo... 12.50%
HP Pavilion 17 Notebook P... 12.50%
HP Compaq Elite 8300 SFF 12.50%
HP 15 Notebook PC 12.50%
eMachines eME528 12.50%
Dell Latitude E6400 12.50%


user comment
No one has commented yet. Help others learn more about this software, share your comments.