ShopAtHomeUpdater.exe

ShopAtHome.com Browser App

ShopAtHome.com (Belcaro Group, Inc.)

The application ShopAtHomeUpdater.exe, “ShopAtHome.com Cash Back Updater” by ShopAtHome.com (Belcaro Group,) has been detected as a potentially unwanted program by 15 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ShopAtHomeUpdater’. This file is typically installed with the program ShopAtHome.com Helper by Belcaro Group Inc. which is a potentially unwanted software program.
Publisher:
ShopAtHome.com  (signed by ShopAtHome.com (Belcaro Group, Inc.))

Product:
ShopAtHome.com Browser App

Description:
ShopAtHome.com Cash Back Updater

Version:
7.0.4.10

MD5:
7a7e32f9c28808af743af6ff7738e332

SHA-1:
34c9fa7044dba284d578943bd68a5d80f04d62fd

SHA-256:
5424a1789e57dc3eaccd4c959219bc49ab5c0614617b67ff537d9cf64361dc5b

Scanner detections:
15 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 11:44:53 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.ShopAtHome.1
396

AVG
Generic
2017.0.2874

Bitdefender
Gen:Variant.Adware.ShopAtHome.1
1.0.20.20

Bkav FE
W32.Clod028.Trojan
1.3.0.4613

Emsisoft Anti-Malware
Gen:Variant.Adware.ShopAtHome
8.16.01.04.02

F-Secure
Gen:Variant.Adware.ShopAtHome.1
11.2016-04-01_2

G Data
Gen:Variant.Adware.ShopAtHome
16.1.22

Malwarebytes
PUP.Optional.ShopAtHome.A
v2016.01.04.02

McAfee
Artemis!4E86C7797513
5600.6530

MicroWorld eScan
Gen:Variant.Adware.ShopAtHome.1
17.0.0.12

nProtect
Adware.Shopathome.H
14.06.03.01

Reason Heuristics
PUP.ShopAtHome.ShopAtHomeBelcaroGroup (M)
16.1.4.14

Sophos
SAHAgent
4.98

Trend Micro House Call
TROJ_GEN.F47V0131
7.2.4

VIPRE Antivirus
ShopAtHome
34194

File size:
180.6 KB (184,976 bytes)

Product version:
7.0.4.10

Copyright:
(c) ShopAtHome.com. All rights reserved.

Original file name:
ShopAtHomeUpdater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\shopathome\shopathomehelper\shopathomeupdater.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
6/25/2013 5:00:00 PM

Valid to:
6/26/2014 4:59:59 PM

Subject:
CN="ShopAtHome.com (Belcaro Group, Inc.)", O="ShopAtHome.com (Belcaro Group, Inc.)", L=Greenwood Village, S=Colorado, C=US, SERIALNUMBER=19871692567, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Colorado, OID.1.3.6.1.4.1.311.60.2.1.3=US

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
237B0D903D7BC26FE5D98F5F4AAF5E42

File PE Metadata
Compilation timestamp:
10/4/2013 10:40:57 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:UcwsNQrcGzz8uAXOhftOUgVPxe4zBabGJh8i/JVTNGVWuIWkxIH6ba9Lwt:Ucws3Gzp5uUgVPxegabGJv/nNGqKKiO

Entry address:
0x104C0

Entry point:
E8, B0, 71, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 4C, A1, 40, 92, 42, 00, 33, C5, 89, 45, FC, 53, 33, DB, 57, 8B, F9, 89, 5D, C0, 89, 5D, BC, 3B, FB, 75, 1A, E8, 82, 09, 00, 00, C7, 00, 16, 00, 00, 00, E8, 8F, 25, 00, 00, 83, CA, FF, 8B, C2, E9, 65, 02, 00, 00, 8B, 47, 14, 99, 8B, C8, 8B, C2, 89, 4D, D0, 83, C1, BB, 89, 45, D4, 83, D0, FF, 56, 3B, C3, 0F, 87, 37, 02, 00, 00, 72, 0C, 81, F9, 08, 04, 00, 00, 0F, 87, 29, 02, 00, 00, 8B, 47, 10, 3B, C3, 7C, 05, 83, F8, 0B, 7E, 46, 99, 6A, 0C...
 
[+]

Entropy:
6.4164

Code size:
129.5 KB (132,608 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ShopAtHomeUpdater

Command:
C:\users\{user}\appdata\roaming\shopathome\shopathomehelper\shopathomeupdater.exe


The file ShopAtHomeUpdater.exe has been discovered within the following program.

ShopAtHome.com Helper  by Belcaro Group Inc.
This is the helper application that is installed with the ShopAtHome Toolbar (Browser App).
www.shopathome.com
68% remove it
 
Powered by Should I Remove It?

Remove ShopAtHomeUpdater.exe - Powered by Reason Core Security