hqtotals-bho64.dll

HQTotalS

HQplustotalS

The module hqtotals-bho64.dll has been detected as adware by 7 anti-malware scanners. This file is typically installed with the program HQTotalS by Kimahri Software inc. which is a potentially unwanted software program. This is the 64-bit verison of the Browser Helper Object (BHO) for the Crossrider web browser platform for Internet Explorer. Instead of utilizing a traditional IE Toolbar, Crossrider installs a BHO in the browser in order to manage the functionality of HQplustotalS addon.
Publisher:
HQplustotalS

Product:
HQTotalS

Description:
HQTotalS BHO

Version:
1000.1000.1000.1000

MD5:
d92c320fa8591df279df97a559884523

SHA-1:
15997f30df10405762cb2c0aa8453df68827d30d

SHA-256:
34c452fa6cd7292a97b0c32bc7b34c1a94a7236af6c38a99460d47b79e55500a

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform. It will run as a BHO in Internet Explorer.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
3/21/2014 11:07:58 AM UTC  (eight months ago)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win64.Crossrider
4.0.3.14321

ESET NOD32
Win64/Toolbar.Crossrider (variant)
8.9624

herdProtect (fuzzy)
2014.5.15.7

Malwarebytes
PUP.Optional.Freeven.A
v2014.03.21.07

Reason Heuristics
PUP.Crossrider.HQplustotalS.O
14.3.21.7

Trend Micro House Call
TROJ_GEN.F47V0317
7.2.80

VIPRE Antivirus
Crossrider
27940

File size:
658.5 KB (674,304 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
HQTotalS.dll

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\Program Files\hqtotals\hqtotals-bho64.dll

Registration
CLSIDs:
{11111111-1111-1111-1111-110511311172}, {22222222-2222-2222-2222-220522312272}

ProgIDs:
CrossriderApp0053172.BHO.1, CrossriderApp0053172.Sandbox.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
3/16/2014 3:06:31 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:brjjZh4f54SIPEwGGR64UqQhLTgY1Xpsil5W1ZJ77P+XoIkKFcmDlhvU1QqcJTrV:f4ubjUAtE6ueQ7FTmTpo+iTvmk4T2

Entry address:
0x4CCB8

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, 6B, D2, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, 03, 00, 00, 00, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 20, 4C, 89, 40, 18, 89, 50, 10, 48, 89, 48, 08, 56, 57, 41, 56, 48, 83, EC, 50, 49, 8B, F0, 8B, DA, 4C, 8B, F1, BA, 01, 00, 00, 00, 89, 50, B8, 85, DB, 75, 0F, 39, 1D, 6C, 0F, 05, 00, 75, 07, 33, C0, E9, D2, 00, 00, 00, 8D, 43, FF...
 
[+]

Entropy:
6.1429

Code size:
425.5 KB (435,712 bytes)

The file hqtotals-bho64.dll has been discovered within the following program.

HQTotalS  by Kimahri Software inc.
HQTotalS is an adware web browser application that displays banner ads as well as contextual link ads that are injected in the web page.
84% remove it
 
Powered by Should I Remove It?

The following files closely match hqtotals-bho64.dll based on a fuzzy CTPH.

5 / 68      (Adware)
free ven-bho64.dll (free ven by freeven)  [100% match]  (2aaa0c6c773f310821c4c7f619d36779a5eb5074)

6 / 68      (Adware)
plushd8.1-bho64.dll (plushd8.1)  [100% match]  (33c154f75431e15aadf509b4349c0a8f621bdcc6)

4 / 68      (Adware)
media enhance-bho64.dll (media enhance by freeven)  [100% match]  (12f49dc3e08b4b77485d7784b280a627246509e7)

9 / 68      (Adware)
hqtotal1.2-bho64.dll (HQTotal1.2 by HQTotal)  [100% match]  (6bd8f0aa26d7d3d6e41b8ee1e9d5d7a6dd25b543)

6 / 68      (Adware)
video-high-bho64.dll (video-high by videohq)  [100% match]  (54702944be1e311fbe4259c1068a2839adc11e80)

5 / 68      (Adware)
hdshop-bho64.dll (hdshop by hdplus)  [100% match]  (f1f79dcb8064fafc9f82146add1bddcf5aa13fe5)

6 / 68      (Adware)
hdtotal1.1-bho64.dll (hdtotal1.1 by hdtotal)  [100% match]  (5c245fadae62e985223c286eab908da10b6980d5)

3 / 68      (Adware)
hdtotals-bho64.dll (HDTotalS by HDplustotalS)  [100% match]  (1c3fc77267515762cebc02be6a79835382da53d2)

5 / 68      (Adware)
hdtotal1.2-bho64.dll (hdtotal1.2 by hdtotal)  [100% match]  (f245671fae2ef4e5801fad2ee5f0216a745d8f90)

4 / 68      (Adware)
plus-hd-9.3-bho64.dll (Plus-HD-9.3 by Plus HD)  [100% match]  (a35df877d574d87727c63bdd6a619bb44b5b57b1)

6 / 68      (Adware)
addplushd-bho64.dll (addplushd by hdideo)  [100% match]  (9e5d244d4905c8c6683c0e67462d60c123c3c3c9)

4 / 68      (Adware)
hqtotals-chromeinstaller.exe  (f15d4d3a6aff37a1c428de26946b638054eaf98e)

14 / 68    (Adware)
hqtotals-codedownloader.exe  (747f60863ec1229cbef0ad8cebc468a344140148)

6 / 68      (Adware)
hqtotals-enabler.exe  (9b6f1181b0f299713a90d2c42a45cb40683b929c)

6 / 68      (Adware)
hqtotals-firefoxinstaller.exe  (7ecb96d5b1dcd1b8f5c4f9a4798510a05b02003b)

6 / 68      (Adware)
hqtotals-updater.exe  (38f2a724c77ddf8de0b083b3aa20aeca678f0e70)

7 / 68      (Adware)
hqtotals-bho.dll  (b2b82189c7601c86d588da477c0de27352df3fd0)

7 / 68      (Adware)
hqtotals-bg.exe  (f5bd07e30dc5698a4e0924696d96c1926ed6775f)

Detection Incidence by Country