HQTotalS

HQTotalS

Known Adware

by Kimahri Software inc.

What is HQTotalS?

HQTotalS is software application developed by Kimahri Software inc.. It is most commonly found on computers running Windows 7 with nearly 48.72% of installations running this operating system. HQTotalS's installer is typically 643.00 KB in size and installs around 12 files.

HQTotalS is most popular in the United States with 65.31% of installations residing in this country.

HQTotalS adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About HQTotalS?

HQTotalS is a web browser application that displays banner ads and contextual link ads injected into web pages. The ads are generated by the web browser plugin for IE, FF, and Chrome, and may appear on any website regardless of affiliation with the publisher. Users may encounter up to 10 intext ads, 4 banner ads, and/or a transitional ad on web pages. This application is commonly bundled with 3rd-party download managers that use misleading advertising techniques to install the software. In addition to displaying ads, HQTotalS may modify browser settings, such as lowering security levels and changing the home page and search provider, resulting in web browser hijacking. Furthermore, the extension reports user behavior and analytics back to a controlling server, which may include visited URLs and domains, as well as ad interaction data. This adware is frequently bundled with multiple potentially unwanted programs within 3rd party download manager packages.

Multiple virus scanners have detected malware in HQTotalS.

utils.exe (MD5: 130f62ec4d9d9c570df253ef1d80121a) has been flagged by 28 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.Adware
avast! Win32:Dropper-gen [Drp]
Baidu-International Trojan.Win32.VMDetector.E
Bkav FE HW32.CDB
Dr.Web Trojan.Crossrider.4794
ESET-NOD32 Win32/Toolbar.CrossRider.AB
K7 AntiVirus Trojan
K7GW Trojan ( 004973ed1 )
Malwarebytes PUP.Optional.CrossRider.A
McAfee Artemis!130F62EC4D9D
McAfee-GW-Edition Artemis!130F62EC4D9D
Norman Suspicious_Gen4.GCNAA
Symantec WS.Reputation
TrendMicro-HouseCall TROJ_GEN.F47V0318
Lavasoft Ad-Aware Trojan.Generic.11165362
AVG MultiBundle.W
Bitdefender Trojan.Generic.11165362
Emsisoft Anti-Malware Trojan.Generic.11165362 (B)
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11165362
G Data Trojan.Generic.11165362
IKARUS anti.virus Trojan.SuspectCRC
MicroWorld-eScan Trojan.Generic.11165362
NANO AntiVirus Trojan.Win32.Crossrider.cwgjyt
nProtect Trojan.Generic.11165362
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider
VIPRE Antivirus Crossrider (fs)
Sophos AppRider
HQTotalS-updater.exe (MD5: 01e5e6be31244ccea1ee64005d0a7f03) has been flagged by 25 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11165362
AVG MultiBundle.W
Baidu-International Adware.Win32.CrossRider.AC
Bitdefender Trojan.Generic.11165362
Dr.Web Trojan.Crossrider.7209
Emsisoft Anti-Malware Trojan.Generic.11165362 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11165362
G Data Trojan.Generic.11165362
IKARUS anti.virus Trojan.SuspectCRC
K7 AntiVirus Trojan ( 004984e91 )
K7GW Trojan ( 004984e91 )
Malwarebytes PUP.Optional.HQTotalS.A
McAfee RDN/Generic.dx!d2r
McAfee-GW-Edition RDN/Generic.dx!d2r
MicroWorld-eScan Trojan.Generic.11165362
NANO AntiVirus Trojan.Win32.Crossrider.cwgjyt
nProtect Trojan.Generic.11165362
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider
TrendMicro-HouseCall TROJ_GEN.F47V0317
VIPRE Antivirus Crossrider (fs)
avast! Win32:Malware-gen
Symantec WS.Reputation.1
Sophos AppRider
HQTotalS-firefoxinstaller.exe (MD5: a39c655569e01c36e37ea1f7929596d1) has been flagged by 2 scanners:
Scanner Software Result
Malwarebytes PUP.Optional.HQTotalS.A
VIPRE Antivirus Crossrider (fs)
HQTotalS-enabler.exe (MD5: 197cc14fff4fc7eb14b77d712d34efc7) has been flagged by 23 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11164385
avast! Win32:Malware-gen
AVG MultiBundle.U
Baidu-International Adware.Win32.CrossRider.AC
Bitdefender Trojan.Generic.11164385
Dr.Web Trojan.Crossrider.950
Emsisoft Anti-Malware Trojan.Generic.11164385 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11164385
G Data Trojan.Generic.11164385
IKARUS anti.virus Trojan.SuspectCRC
K7 AntiVirus Trojan ( 004984e91 )
K7GW Trojan ( 004984e91 )
Malwarebytes PUP.Optional.HQTotalS.A
McAfee Artemis!197CC14FFF4F
McAfee-GW-Edition Artemis!197CC14FFF4F
MicroWorld-eScan Trojan.Generic.11164385
nProtect Trojan.Generic.11164385
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.F47V0317
VIPRE Antivirus Crossrider (fs)
Sophos AppRider
HQTotalS-codedownloader.exe (MD5: 490824502954caf31708d92aa6c36b11) has been flagged by 4 scanners:
Scanner Software Result
avast! Win32:Dropper-gen [Drp]
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AA
VIPRE Antivirus Crossrider (fs)
Malwarebytes PUP.Optional.HQTotalS.A

Software Behaviors

Scheduled tasks:
  • HQTotalS-enabler.exe is scheduled as a task named 'temp_HQTotalS-enabler'.

Startup Entries

Startup tasks:
  • HQTotalS-updater.exe is automatically launched at startup through a scheduled task named HQTotalS-updater.
  • HQTotalS-codedownloader.exe is automatically launched at startup through a scheduled task named HQTotalS-codedownloader.
  • HQTotalS-firefoxinstaller.exe is automatically launched at startup through a scheduled task named HQTotalS-firefoxinstaller.
  • HQTotalS-enabler.exe is automatically launched at startup through a scheduled task named HQTotalS-enabler.
  • HQTotalS-chromeinstaller.exe is automatically launched at startup through a scheduled task named HQTotalS-chromeinstaller.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\HQTotalS
Uninstaller:
C:\Program Files\HQTotalS\Uninstall.exe /fromcontrolpanel=1
Size:
643.00 KB
Language:
English

HQTotalS Executable Details

Primary executable:
utils.exe
Name:
HQTotalS
Path:
C:\Program Files\HQTotalS\utils.exe
MD5:
130f62ec4d9d9c570df253ef1d80121a
SHA-1:
–
SHA-256:
–
Files installed by HQTotalS
File Type Filename MD5
EXE
7537091b013cdb61f52928e9b9caf72e
EXE
utils.exe
Malware
130f62ec4d9d9c570df253ef1d80121a
XPI
cc29001832ec685646c9ceff0282c293
CRX
6917788e8373bae301ea96cac37cbb96
EXE
01e5e6be31244ccea1ee64005d0a7f03
EXE
a39c655569e01c36e37ea1f7929596d1
EXE
197cc14fff4fc7eb14b77d712d34efc7
EXE
490824502954caf31708d92aa6c36b11
EXE
42c189f9eef5238361e4ccfb74da149e
DLL
d92c320fa8591df279df97a559884523