ShopAtHomeHelper.exe

ShopAtHome.com Browser App

ShopAtHome.com (Belcaro Group, Inc.)

The application ShopAtHomeHelper.exe, “ShopAtHome.com Cash Back Helper” by ShopAtHome.com (Belcaro Group,) has been detected as a potentially unwanted program by 12 anti-malware scanners.
Publisher:
ShopAtHome.com  (signed by ShopAtHome.com (Belcaro Group, Inc.))

Product:
ShopAtHome.com Browser App

Description:
ShopAtHome.com Cash Back Helper

Version:
7.0.5.20

MD5:
a40bf3988cedbe4d919e62b0ed80ff69

SHA-1:
6c2da2155aa235727d6c20a44cdc1c68ad3d18ce

SHA-256:
29d33253c50cd0513fdb3c86929b5ec4e763bc27519a44cf1ad2b65e51a52c9e

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
4/16/2024 3:38:10 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.ShopAtHome.1
409

Bitdefender
Gen:Variant.Adware.ShopAtHome.1
1.0.20.1780

Dr.Web
Adware.Shopper.957
9.0.1.0356

Emsisoft Anti-Malware
Gen:Variant.Adware.ShopAtHome
8.15.12.22.01

F-Secure
Gen:Variant.Adware.ShopAtHome.1
11.2015-22-12_3

G Data
Win32.Adware.ShopAtHome
15.12.25

Malwarebytes
PUP.Optional.ShopAtHome
v2015.12.22.01

MicroWorld eScan
Gen:Variant.Adware.ShopAtHome.1
16.0.0.1068

Reason Heuristics
PUP.ShopAtHome.ShopAtHomeBelcaroGroup (M)
15.12.22.13

Sophos
SAHAgent (PUA)
4.98

SUPERAntiSpyware
PUP.ShopAtHome/Variant
9432

Trend Micro House Call
TROJ_GEN.F47V1021
7.2.356

File size:
1.2 MB (1,303,184 bytes)

Product version:
7.0.5.20

Copyright:
(c) ShopAtHome.com. All rights reserved.

Original file name:
ShopAtHomeHelper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\shopathome\shopathomehelper\shopathomehelper.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
6/25/2013 8:00:00 PM

Valid to:
6/26/2014 7:59:59 PM

Subject:
CN="ShopAtHome.com (Belcaro Group, Inc.)", O="ShopAtHome.com (Belcaro Group, Inc.)", L=Greenwood Village, S=Colorado, C=US, SERIALNUMBER=19871692567, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Colorado, OID.1.3.6.1.4.1.311.60.2.1.3=US

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
237B0D903D7BC26FE5D98F5F4AAF5E42

File PE Metadata
Compilation timestamp:
3/10/2014 5:05:07 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:sVWn+Jef9ZdmMw52kZImWmszFkxNETx1+x4KYNtWJkVPQ1M:x+J29XmM2pszFkcTxgx4KYT+kVPQ1M

Entry address:
0x7DEDE

Entry point:
E8, CF, B6, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 2C, A1, 44, 56, 51, 00, 33, C5, 89, 45, FC, 56, FF, 75, 0C, 8B, 75, 08, 8D, 4D, D4, E8, 60, A9, FF, FF, 85, F6, 75, 24, E8, F7, BE, FF, FF, C7, 00, 16, 00, 00, 00, E8, A5, 31, 00, 00, 80, 7D, E0, 00, 74, 07, 8B, 45, DC, 83, 60, 70, FD, D9, EE, EB, 35, 83, C6, 02, 0F, B7, 06, 6A, 08, 50, E8, 75, 73, 00, 00, 59, 59, 85, C0, 75, EC, 8D, 45, D4, 50, 8D, 45, E4, 56, 50, E8, FD, B6, 00, 00, DD, 40, 10, 83, C4, 0C, 80, 7D, E0, 00, 74, 07, 8B, 45...
 
[+]

Entropy:
6.4616

Code size:
830 KB (849,920 bytes)

Remove ShopAtHomeHelper.exe - Powered by Reason Core Security