hq-video-profession-1.3-chromeinstaller.exe

HQ-Video-Profession-1.3

HQ-Video

The application hq-video-profession-1.3-chromeinstaller.exe, “HQ-Video-Profession-1.3 exe” has been detected as adware by 8 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. The file utilizes the Crossrider browser extension platform. ChromeInstaller is the component designed to install and manage the extension's Google Chrome integration.
Publisher:
HQ-Video

Product:
HQ-Video-Profession-1.3

Description:
HQ-Video-Profession-1.3 exe

Version:
1000.1000.1000.1000

MD5:
9b5e54939fe648845463a843b5f1d408

SHA-1:
96d04d2fac48af3018b82e2e497f5f59e70ccb67

SHA-256:
b22171e5cb99a92730bea529c89609ead33803964c35ba4304183e4941054143

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform. It will download and install the extension for Gogole Chrome.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/18/2024 1:54:16 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic5
2015.0.3546

Baidu Antivirus
Adware.Win32.CrossRider
4.0.3.1433

Emsisoft Anti-Malware
Generic.Viking.FEBC7C0A
8.14.03.03.02

ESET NOD32
Win32/Toolbar.CrossRider (variant)
8.9490

K7 AntiVirus
Trojan
13.176.11311

Reason Heuristics
PUP.Crossrider.Task.g
14.8.15.15

Trend Micro House Call
TROJ_GEN.R047H05BO14
7.2.62

VIPRE Antivirus
Crossrider
27000

File size:
1.9 MB (2,019,328 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
HQ-Video-Profession-1.3.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\hq-video-profession-1.3\hq-video-profession-1.3-chromeinstaller.exe

File PE Metadata
Compilation timestamp:
2/4/2014 10:20:44 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:T4fTDyAZfupR8klJcN5ce9yRWEhNVWApS9pTsUzn+nPRx:T47rZfupR8klJc7N9yRWEhNVe

Entry address:
0xFA6CE

Entry point:
E8, D6, 0B, 01, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 85, F6, 78, 09, E8, 09, 0D, 01, 00, 3B, 30, 7C, 07, E8, 00, 0D, 01, 00, 8B, 30, E8, F3, 0C, 01, 00, 8B, 04, B0, 5E, 5D, C3, 55, 8B, EC, 56, E8, 2D, 60, 00, 00, 8B, F0, 85, F6, 75, 07, B8, 10, C6, 55, 00, EB, 26, 53, 57, 33, FF, BB, 86, 00, 00, 00, 39, 7E, 24, 75, 1B, 6A, 01, 53, E8, 80, 33, 00, 00, 59, 59, 89, 46, 24, 85, C0, 75, 0A, B8, 10, C6, 55, 00, 5F, 5B, 5E, 5D, C3, FF, 75, 08, 8B, 76, 24, E8, 90, FF, FF, FF, 50, 53, 56, E8, 9D, DF...
 
[+]

Code size:
1.1 MB (1,177,088 bytes)

Scheduled Task
Task name:
HQ-Video-Profession-1.3-chromeinstaller

Trigger:
Logon (Runs on logon)

Action:
hq-video-profession-1.3-chromeinstaller.exe \rawdata=m21xt7lb4j7nhggkosiipun2xxgby4ltdfgtyae5a


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to update.srvstatsdata.com  (69.16.175.42:80)

 
http://update.srvstatsdata.com/installer_updates/007934/update.json

TCP (HTTP):
Connects to stats.srvstatsdata.com  (176.32.99.41:80)

TCP (HTTP):
Connects to app-static.crossrider.com  (69.16.175.10:80)

Remove hq-video-profession-1.3-chromeinstaller.exe - Powered by Reason Core Security