hqtotals-bho.dll

HQTotalS

HQplustotalS

This web browser extension uses the Crossrider toolbar creation and distribution platform. The module hqtotals-bho.dll has been detected as adware by 7 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘CrossriderApp0053172’. This file is typically installed with the program HQTotalS by Kimahri Software inc. which is a potentially unwanted software program. This is the Browser Helper Object (BHO) for the Crossrider web browser platform for Internet Explorer. Instead of utilizing a traditional IE Toolbar, it installs a BHO in the browser in order to manage the functionality of the addon.
Publisher:
HQplustotalS

Product:
HQTotalS

Description:
HQTotalS BHO

Version:
1.1.153.23

MD5:
144187ed70a6a1e820354e9b7e73ceec

SHA-1:
b2b82189c7601c86d588da477c0de27352df3fd0

SHA-256:
8eaf23ff7bba32083d12cf793d80766c11db1ed4f1d069df32e376e602991648

Scanner detections:
7 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
3/20/2014 9:30:22 PM UTC  (seven months ago)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.14515

herdProtect (fuzzy)
2014.5.15.4

Malwarebytes
PUP.Optional.HDTotal.A
v2014.03.20.05

Reason Heuristics
PUP.Crossrider.HQplustotalS.M
14.3.20.17

Sophos
AppRider
4.98

Trend Micro House Call
TROJ_GEN.F47V0328
7.2.135

VIPRE Antivirus
Crossrider
27916

File size:
490 KB (501,760 bytes)

Product version:
1.1.153.23

Copyright:
Copyright 2011

Original file name:
HQTotalS.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\hqtotals\hqtotals-bho.dll

File PE Metadata
Compilation timestamp:
3/16/2014 3:06:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:lBUIlh2A7YbWgFwSLWpPtkm5CMrWUs0JS6TPZWmpPE:lBUIlIAjgFwSLWpPtkm0MrWmJJTBWWPE

Entry address:
0x37BC2

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 52, BC, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 28, AE, 06, 10, E8, BF, 46, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, D0, 08, 07, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 28, BF, 05, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.4967

Developed / compiled with:
Microsoft Visual C++

Code size:
329 KB (336,896 bytes)

Internet Explorer BHO
Display name:
CrossriderApp0053172

CLSID:
{11111111-1111-1111-1111-110511311172}

CLSID name:
HQTotalS


The file hqtotals-bho.dll has been discovered within the following program.

HQTotalS  by Kimahri Software inc.
HQTotalS is an adware web browser application that displays banner ads as well as contextual link ads that are injected in the web page.
84% remove it
 
Powered by Should I Remove It?

The following files closely match hqtotals-bho.dll based on a fuzzy CTPH.

7 / 68      (Adware)
free ven-bho.dll (free ven by freeven)  [97% match]  (6a959ef485037bbf3f631c698749b29e51ea240c)

4 / 68      (Adware)
plushd8.1-bho.dll (plushd8.1)  [97% match]  (c1693c7db94f3ecd5aef364224c1eade29b04659)

4 / 68      (Adware)
free ven-bho.dll (free ven by freeven)  [97% match]  (c01d14929de8623c78f8cb2bb3624370d3ac077a)

4 / 68      (Adware)
addplushd-bho.dll (addplushd by hdideo)  [97% match]  (c8c224ac0c0a5d2c1b7bfdd7594ad5ad72884185)

6 / 68      (Adware)
hdtotal-bho.dll (HDTotal by HDplustotal)  [99% match]  (df57f01ea5f36a9aaf5ef76fa1f86da5f2b58480)

5 / 68      (Adware)
hdvideo-bho.dll (hdvideo by video-high)  [99% match]  (4fb9523c01dd55b6429d2a0643114efafbf66e68)

4 / 68      (Adware)
hdtotals-bho.dll (HDTotalS by HDplustotalS)  [99% match]  (590496a9e3efe68cb1f28a348c26f0cd29b9bc63)

7 / 68      (Adware)
hqtotal1.2-bho.dll (HQTotal1.2 by HQTotal)  [97% match]  (14bbc12efc06655c94dca7cd2c55abf10c269e57)

6 / 68      (Adware)
hdshop-bho.dll (hdshop by hdplus)  [97% match]  (96fffb11ca24c52dd91e3ee3d3de4f36ac5a8302)

3 / 68      (Adware)
media enhance-bho.dll (media enhance by freeven)  [97% match]  (a6a0593af665da4894709ba00c689288a225baf9)

4 / 68      (Adware)
hdtotal1.2-bho.dll (hdtotal1.2 by hdtotal)  [97% match]  (004ebaf8f253d854c39f25609dca86e5ba006b67)

5 / 68      (Adware)
hdtotal1.1-bho.dll (hdtotal1.1 by hdtotal)  [97% match]  (9bc18f1350fd93bb9b069801c03278cb1aff2693)

8 / 68      (Adware)
video-high-bho.dll (video-high by videohq)  [97% match]  (dc0a2b58ebcf5c5f8c78f2106408acc1aba84900)

9 / 68      (Adware)
hdtotal1.3-bho.dll (hdtotal1.3 by hdtotal)  [97% match]  (531eab44111487fd336cf59e293f0135b623dc07)

4 / 68      (Adware)
hqtotals-chromeinstaller.exe  (f15d4d3a6aff37a1c428de26946b638054eaf98e)

14 / 68    (Adware)
hqtotals-codedownloader.exe  (747f60863ec1229cbef0ad8cebc468a344140148)

6 / 68      (Adware)
hqtotals-enabler.exe  (9b6f1181b0f299713a90d2c42a45cb40683b929c)

6 / 68      (Adware)
hqtotals-firefoxinstaller.exe  (7ecb96d5b1dcd1b8f5c4f9a4798510a05b02003b)

6 / 68      (Adware)
hqtotals-updater.exe  (38f2a724c77ddf8de0b083b3aa20aeca678f0e70)

7 / 68      (Adware)
hqtotals-bg.exe  (f5bd07e30dc5698a4e0924696d96c1926ed6775f)

7 / 68      (Adware)
hqtotals-bho64.dll  (15997f30df10405762cb2c0aa8453df68827d30d)

Detection Incidence by Country