ShopAtHomeHelper.exe

ShopAtHome.com Browser App

ShopAtHome.com (Belcaro Group, Inc.)

The application ShopAtHomeHelper.exe, “ShopAtHome.com Cash Back Helper” by ShopAtHome.com (Belcaro Group,) has been detected as a potentially unwanted program by 13 anti-malware scanners.
Publisher:
ShopAtHome.com  (signed by ShopAtHome.com (Belcaro Group, Inc.))

Product:
ShopAtHome.com Browser App

Description:
ShopAtHome.com Cash Back Helper

Version:
7.0.4.15

MD5:
0a4ee6e52ded75625d65ba659f9c9e1e

SHA-1:
b8a52dc857f0bf1a513708c68e321e5e9921c1b2

SHA-256:
0a371ab8a634e7edf9632f06d33b9681082f0bdcab5075708cd7ec5818078f2c

Scanner detections:
13 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 3:00:06 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.ShopAtHome.1
373

Bitdefender
Gen:Variant.Adware.ShopAtHome.1
1.0.20.140

Boost by Reason
Optional.ShopAtHomeBelcaroGroup
188838

Dr.Web
Adware.Shopper.957
9.0.1.028

Emsisoft Anti-Malware
Gen:Variant.Adware.ShopAtHome
8.16.01.28.09

F-Secure
Gen:Variant.Adware.ShopAtHome.1
11.2016-28-01_5

G Data
Win32.Adware.ShopAtHome
16.1.25

Malwarebytes
PUP.Optional.ShopAtHome
v2016.01.28.09

MicroWorld eScan
Gen:Variant.Adware.ShopAtHome.1
17.0.0.84

Reason Heuristics
PUP.ShopAtHome.ShopAtHomeBelcaroGroup (M)
16.1.28.9

Sophos
SAHAgent (PUA)
4.98

SUPERAntiSpyware
PUP.ShopAtHome/Variant
9358

Trend Micro House Call
TROJ_GEN.F47V1021
7.2.28

File size:
1.2 MB (1,263,760 bytes)

Product version:
7.0.4.15

Copyright:
(c) ShopAtHome.com. All rights reserved.

Original file name:
ShopAtHomeHelper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\shopathome\shopathomehelper\shopathomehelper.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
6/25/2013 8:00:00 PM

Valid to:
6/26/2014 7:59:59 PM

Subject:
CN="ShopAtHome.com (Belcaro Group, Inc.)", O="ShopAtHome.com (Belcaro Group, Inc.)", L=Greenwood Village, S=Colorado, C=US, SERIALNUMBER=19871692567, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Colorado, OID.1.3.6.1.4.1.311.60.2.1.3=US

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
237B0D903D7BC26FE5D98F5F4AAF5E42

File PE Metadata
Compilation timestamp:
12/16/2013 3:09:15 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:NbTdIjvTruwWXXoruCYTCXiSRROz0dGY4gTG1/M7O39OPSZ:NbTdILTru3XorKTCXi+00x4gTGOPSZ

Entry address:
0x7873E

Entry point:
E8, DF, B6, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 2C, A1, 44, C6, 50, 00, 33, C5, 89, 45, FC, 56, FF, 75, 0C, 8B, 75, 08, 8D, 4D, D4, E8, 70, A9, FF, FF, 85, F6, 75, 24, E8, F7, BE, FF, FF, C7, 00, 16, 00, 00, 00, E8, 05, 31, 00, 00, 80, 7D, E0, 00, 74, 07, 8B, 45, DC, 83, 60, 70, FD, D9, EE, EB, 35, 83, C6, 02, 0F, B7, 06, 6A, 08, 50, E8, 8E, 73, 00, 00, 59, 59, 85, C0, 75, EC, 8D, 45, D4, 50, 8D, 45, E4, 56, 50, E8, 0D, B7, 00, 00, DD, 40, 10, 83, C4, 0C, 80, 7D, E0, 00, 74, 07, 8B, 45...
 
[+]

Entropy:
6.4700

Code size:
805.5 KB (824,832 bytes)

Remove ShopAtHomeHelper.exe - Powered by Reason Core Security