ShopAtHome.com Toolbar

ShopAtHome.com Toolbar

Known Toolbar

by Belcaro Group Inc.

What is ShopAtHome.com Toolbar?

ShopAtHome.com Toolbar is software application developed by Belcaro Group Inc.. It is most commonly found on computers running Windows 7 with nearly 56.10% of installations running this operating system. ShopAtHome.com Toolbar's installer is typically 3.00 MB in size and installs around 23 files. The most common release is 7.10.2.10 with 18.33% of all installations currently using this version.

ShopAtHome.com Toolbar is most popular in the United States with 99.54% of installations residing in this country.

ShopAtHome.com Toolbar adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About ShopAtHome.com Toolbar?

The ShopAtHome.com Toolbar offers users the option to inject its content into search results within their web browser. This content will be clearly labeled as ShopAtHome.com content, and users will have the ability to disable this feature if they choose to do so.

Multiple virus scanners have detected malware in ShopAtHome.com Toolbar.

SRFF3.dll (MD5: 84ffd42c17931a9d1f8361e7680c78de) has been flagged by 2 scanners:
Scanner Software Result
Sophos SAHAgent
Vba32 AntiVirus Signed-Adware.Sahat
SRebates.dll (MD5: 017e694bf86cd554b0fca3b09957e15f) has been flagged by 4 scanners:
Scanner Software Result
Dr.Web Adware.Bho.3819
Sophos SAHAgent
TrendMicro-HouseCall TROJ_GEN.R0CBH0AKF13
Vba32 AntiVirus Signed-Adware.Sahat
SelectRebatesUninstall.exe (MD5: 388a88031cb58ff9ca2e879086ce7c15) has been flagged by 7 scanners:
Scanner Software Result
Agnitum Outpost Adware.ShopAtHome!PCKctLuS6mg
NANO AntiVirus Riskware.Win32.Sahat.riaqr
Norman ShopAtHome.A!genr
TrendMicro-HouseCall TROJ_GEN.R0CBH0AKB13
Vba32 AntiVirus Signed-Adware.Sahat
Dr.Web Adware.Bho.3819
Sophos SAHAgent
SelectRebatesDownload.exe (MD5: 589c85ad4b3fd73456f32eb9d58e2f9c) has been flagged by 9 scanners:
Scanner Software Result
Clam AntiVirus Adware.ShopAtHome-5
Kaspersky not-a-virus:WebToolbar.Win32.Sahat.ex
Norman ShopAtHome.A!genr
Sophos SAHAgent
Vba32 AntiVirus WebToolbar.Sahat
Agnitum Outpost Adware.ShopAtHome!PCKctLuS6mg
NANO AntiVirus Riskware.Win32.Sahat.riaqr
TrendMicro-HouseCall TROJ_GEN.R0CBH0AKB13
Dr.Web Adware.Bho.3819
SelectRebatesApi.exe (MD5: 5c2402121f5bf6b7f9e3fe302cb291a0) has been flagged by 17 scanners:
Scanner Software Result
avast! Win32:PUP-gen [PUP]
Bkav FE W32.Clod9b8.Trojan.e608
F-Prot W32/Adware.AGBE
K7 AntiVirus Adware ( 475d08bd0 )
Kingsoft AntiVirus Win32.Troj.Sahat.dk.(kcloud)
MicroWorld-eScan possible-Threat.AdWare.SAH (ES)
Norman ShopAtHome.A!genr
Sophos SAHAgent
TrendMicro-HouseCall TROJ_GEN.R0CBH0AKF13
Vba32 AntiVirus Adware.Sahat
Fortinet FortiGate Adware/ShopAtHomeSelect
Total Defense Win32/SillyAd.A
Clam AntiVirus Adware.ShopAtHome-5
Kaspersky not-a-virus:WebToolbar.Win32.Sahat.ex
Agnitum Outpost Adware.ShopAtHome!PCKctLuS6mg
NANO AntiVirus Riskware.Win32.Sahat.riaqr
Dr.Web Adware.Bho.3819

Software Behaviors

Scheduled tasks:
  • ShopAtHomeUn.exe is scheduled as a task with the class '{5604B5C8-8D22-43BF-B124-23CD715BBD91}' (runs on registration).

Software Details

URL:
https://www.shopathome.com
Support:
Installation path:
C:\users\user\appdata\Roaming\ShopAtHome\ShopAtHomeToolbar
Uninstaller:
C:\users\user\appdata\Roaming\ShopAtHome\ShopAtHomeToolbar\ShopAtHomeUninstall.exe
Size:
3.00 MB
Language:
English

ShopAtHome.com Toolbar Executable Details

Primary executable:
tbcore3U.dll
Name:
ShopAtHome.com Toolbar
Path:
C:\users\user\appdata\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll
MD5:
fc90360cc188aea5024c20b94cffd8df
SHA-1:
SHA-256:
Files installed by ShopAtHome.com Toolbar
File Type Filename MD5
DLL
017e694bf86cd554b0fca3b09957e15f
EXE
2a9896e49ed6d7f8cc8da308f146c3e0
EXE
388a88031cb58ff9ca2e879086ce7c15
EXE
589c85ad4b3fd73456f32eb9d58e2f9c
EXE
5c2402121f5bf6b7f9e3fe302cb291a0
EXE
0bf024e4f8fc508acfed092399f0fb4c
DLL
fc90360cc188aea5024c20b94cffd8df
EXE
a43edd97ae4bc43b769fdfed4e27065a
EXE
20f79d91772c3eef55e9545b98c57acb
EXE
3ca4885eb2c2c3bd58d6b4e7d639a3c8