hqtotals-bg.exe

HQTotalS

HQplustotalS

The application hqtotals-bg.exe has been detected as adware by 7 anti-malware scanners. This file is typically installed with the program HQTotalS by Kimahri Software inc. which is a potentially unwanted software program. Part of the Corssrider web browser platform, the BG executable is a background process that manage various function of the installed extensions in user's browser including managing installation, updates and remote code downloads.
Publisher:
HQplustotalS

Product:
HQTotalS

Description:
HQTotalS exe

Version:
1000.1000.1000.1000

MD5:
895a01979454e09f9ebbe848f416596b

SHA-1:
f5bd07e30dc5698a4e0924696d96c1926ed6775f

SHA-256:
111ece3382bcf64d890ee6cf613f8f7b515b1bf68af933c71b33dbfa3fe79c3f

Scanner detections:
7 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
3/21/2014 10:42:20 AM UTC  (six months ago)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.CrossRider
4.0.3.14321

ESET NOD32
Win32/Toolbar.CrossRider.AA (variant)
8.9549

herdProtect (fuzzy)
2014.5.15.7

Malwarebytes
PUP.Optional.HDTotal.A
v2014.03.21.06

Reason Heuristics
PUP.Crossrider.HQplustotalS.L
14.3.21.6

Trend Micro House Call
TROJ_GEN.F47V0314
7.2.80

VIPRE Antivirus
Crossrider
27448

File size:
515.5 KB (527,872 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
HQTotalS.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\hqtotals\hqtotals-bg.exe

File PE Metadata
Compilation timestamp:
3/16/2014 3:06:15 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:jO32pCBTNxJ/9uM6ENsmUuDd7S5O7rgO1iIg12rrA9TBsy3qsLov:ympCBTNxJ/4H857OOvTm2rrA9TZ

Entry address:
0x45FDD

Entry point:
E8, 6D, B1, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 48, A9, 47, 00, E8, 6D, 01, 00, 00, E8, 0A, 13, 00, 00, 0F, B7, F0, 6A, 02, E8, 00, B1, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, A2, 11, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.4165

Code size:
400 KB (409,600 bytes)

The file hqtotals-bg.exe has been discovered within the following program.

HQTotalS  by Kimahri Software inc.
HQTotalS is an adware web browser application that displays banner ads as well as contextual link ads that are injected in the web page.
84% remove it
 
Powered by Should I Remove It?

The following files closely match hqtotals-bg.exe based on a fuzzy CTPH.

6 / 68      (Adware)
free ven-bg.exe (free ven by freeven)  [99% match]  (9e6e195fcb2b4deb071c6045a2c1cdc7a6556eda)

5 / 68      (Adware)
hqtotal1.2-bg.exe (HQTotal1.2 by HQTotal)  [99% match]  (3b0dafb3fc916ca12a2453f696593d79f09d1bbf)

4 / 68      (Adware)
hdvideo-bg.exe (hdvideo by video-high)  [99% match]  (0ebb09c6c44b8bfda02b93bc454bb4afa775a697)

4 / 68      (Adware)
hdshop-bg.exe (hdshop by hdplus)  [99% match]  (50f3e8d82295c20d9614052f892ff0e48e4a7cec)

5 / 68      (Adware)
plus-hd-9.2-bg.exe (Plus-HD-9.2 by Plus HD)  [99% match]  (95ad75b62c21ea0610309d355bfd7d7422605f38)

5 / 68      (Adware)
media enhance-bg.exe (media enhance by freeven)  [99% match]  (367a60af5e136f0074d5eb6b3acf424e4260d62d)

4 / 68      (Adware)
plushd8.1-bg.exe (plushd8.1)  [99% match]  (c2d07731e0612d1077ee840489a164e6838fa652)

7 / 68      (Adware)
hdtotal1.2-bg.exe (hdtotal1.2 by hdtotal)  [100% match]  (591612c0296a29c464f9b33dcb1ad5d041e0add2)

7 / 68      (Adware)
freeven-bg.exe (freeven)  [100% match]  (a96887e5572195fad383a639683a0f144ac7a10b)

3 / 68      (Adware)
hdtotals-bg.exe (HDTotalS by HDplustotalS)  [100% match]  (8518c66bb6388da3e5affd627ced8432f7c5bac2)

6 / 68      (Adware)
hdtotal1.1-bg.exe (hdtotal1.1 by hdtotal)  [99% match]  (3ff9b7dbc78d853e788d86223bdf4686f9646522)

6 / 68      (Adware)
video-high-bg.exe (video-high)  [99% match]  (49d58a9c0f182df773a2bc74459a3c2db3dad389)

11 / 68    (Adware)
plus-hd-9.3-bg.exe (Plus-HD-9.3 by Plus HD)  [99% match]  (8d0b65330357ced8a4b7f305010f354042139879)

4 / 68      (Adware)
hqtotals-chromeinstaller.exe  (f15d4d3a6aff37a1c428de26946b638054eaf98e)

14 / 68    (Adware)
hqtotals-codedownloader.exe  (747f60863ec1229cbef0ad8cebc468a344140148)

6 / 68      (Adware)
hqtotals-enabler.exe  (9b6f1181b0f299713a90d2c42a45cb40683b929c)

6 / 68      (Adware)
hqtotals-firefoxinstaller.exe  (7ecb96d5b1dcd1b8f5c4f9a4798510a05b02003b)

6 / 68      (Adware)
hqtotals-updater.exe  (38f2a724c77ddf8de0b083b3aa20aeca678f0e70)

7 / 68      (Adware)
hqtotals-bho.dll  (b2b82189c7601c86d588da477c0de27352df3fd0)

7 / 68      (Adware)
hqtotals-bho64.dll  (15997f30df10405762cb2c0aa8453df68827d30d)

Detection Incidence by Country