ShopAtHomeUpdater.exe

ShopAtHome.com Browser App

ShopAtHome.com (Belcaro Group, Inc.)

The application ShopAtHomeUpdater.exe, “ShopAtHome.com Cash Back Updater” by ShopAtHome.com (Belcaro Group,) has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ShopAtHomeUpdater’. This file is typically installed with the program ShopAtHome.com Helper by Belcaro Group Inc. which is a potentially unwanted software program.
Publisher:
ShopAtHome.com  (signed by ShopAtHome.com (Belcaro Group, Inc.))

Product:
ShopAtHome.com Browser App

Description:
ShopAtHome.com Cash Back Updater

Version:
7.0.4.17

MD5:
739897e404f3a02253c844a65c5660f7

SHA-1:
da6f7a2590e4e88fdcad26e8a6f670deb1e9d341

SHA-256:
d20f35d7c69f78d2bbdd73e35598e0de41c12169a0f391241821a151dcb3f91f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 5:38:59 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ShopAtHome (M)
16.9.20.8

File size:
197.1 KB (201,872 bytes)

Product version:
7.0.4.17

Copyright:
(c) ShopAtHome.com. All rights reserved.

Original file name:
ShopAtHomeUpdater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\shopathome\shopathomehelper\shopathomeupdater.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
6/25/2013 8:00:00 PM

Valid to:
6/26/2014 7:59:59 PM

Subject:
CN="ShopAtHome.com (Belcaro Group, Inc.)", O="ShopAtHome.com (Belcaro Group, Inc.)", L=Greenwood Village, S=Colorado, C=US, SERIALNUMBER=19871692567, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Colorado, OID.1.3.6.1.4.1.311.60.2.1.3=US

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
237B0D903D7BC26FE5D98F5F4AAF5E42

File PE Metadata
Compilation timestamp:
1/14/2014 1:10:38 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:0Iv7fBKargyTdBqT5rINWH10ESvsQ/4sRMdacj5pFx+xIH6Hk1EiR:0IvYat+eNWV0E4//b8aS5prV+wEq

Entry address:
0x10520

Entry point:
E8, 50, 72, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 4C, A1, 40, D2, 42, 00, 33, C5, 89, 45, FC, 53, 33, DB, 57, 8B, F9, 89, 5D, C0, 89, 5D, BC, 3B, FB, 75, 1A, E8, 82, 09, 00, 00, C7, 00, 16, 00, 00, 00, E8, 2F, 26, 00, 00, 83, CA, FF, 8B, C2, E9, 65, 02, 00, 00, 8B, 47, 14, 99, 8B, C8, 8B, C2, 89, 4D, D0, 83, C1, BB, 89, 45, D4, 83, D0, FF, 56, 3B, C3, 0F, 87, 37, 02, 00, 00, 72, 0C, 81, F9, 08, 04, 00, 00, 0F, 87, 29, 02, 00, 00, 8B, 47, 10, 3B, C3, 7C, 05, 83, F8, 0B, 7E, 46, 99, 6A, 0C...
 
[+]

Entropy:
6.4614

Code size:
144.5 KB (147,968 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ShopAtHomeUpdater

Command:
C:\users\{user}\appdata\roaming\shopathome\shopathomehelper\shopathomeupdater.exe


The file ShopAtHomeUpdater.exe has been discovered within the following programs.

ShopAtHome.com Helper  by Belcaro Group Inc.
This is the helper application that is installed with the ShopAtHome Toolbar (Browser App).
www.shopathome.com
68% remove it
 
Powered by Should I Remove It?

Remove ShopAtHomeUpdater.exe - Powered by Reason Core Security