ShoppingHelperToolbar.exe

ShoppintHelper

The application ShoppingHelperToolbar.exe has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from d3d6wi7c7pa6m0.cloudfront.net and multiple other hosts.
Publisher:
ShoppintHelper

Product:
ShoppintHelper

Version:
1.0

MD5:
3031801798d3494d51404d2083fca153

SHA-1:
31c8a22a70a2a75026c6ede767b0b67f5c67b4d2

SHA-256:
a7827b773c9c92e4c645c32a79cc5547f87526871aaa50e892782853cc5286cb

Scanner detections:
13 / 68

Status:
Adware

Analysis date:
10/1/2026 11:44:38 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AVG
2014.0.3543

Baidu Antivirus
Trojan.Win32.StartPage
4.0.3.131126

Kaspersky
Trojan.Win32.StartPage
14.0.0.3808

Malwarebytes
PUP.Optional.ShoppingHelper.A
v2013.11.26.03

McAfee
Artemis!3031801798D3
5600.7181

NANO AntiVirus
Trojan.Win32.StartPage.cjcqcx
0.28.0.57029

Norman
Suspicious_Gen4.ERRYU
11.20131126

Panda Antivirus
Trj/OCJ.D
13.08.29.12

Reason Heuristics
PUP.ShoppintHelper.V
14.3.1.0

Rising Antivirus
PE:Trojan.Win32.Generic.15A265D0!362964432
23.00.65.131227

Trend Micro House Call
TROJ_GEN.R0CBH07KO13
7.2.241

Vba32 AntiVirus
Trojan.StartPage
3.12.24.3

VIPRE Antivirus
Adware.Linkury
24566

File size:
8.4 MB (8,860,446 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\shoppinghelpertoolbar.exe

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:1qAogzrJ+4CJ/txhO1JFvFsR+YnQD8upggrd4T26MyeT8kf5H/8HiLihc:1qG9+5fO1JFd4sbpggh4T26Jofd/8CL7

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9988

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file ShoppingHelperToolbar.exe has been seen being distributed by the following 2 URLs.

Remove ShoppingHelperToolbar.exe - Powered by Reason Core Security