HQTotalS

HQTotalS

Known Adware

by Kimahri Software inc.

What is HQTotalS?

HQTotalS is software application developed by Kimahri Software inc.. It is most commonly found on computers running Windows 7 with nearly 48.72% of installations running this operating system. HQTotalS's installer is typically 643.00 KB in size and installs around 12 files.

HQTotalS is most popular in the United States with 65.31% of installations residing in this country.

HQTotalS adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About HQTotalS?

HQTotalS is a web browser application that displays banner ads and contextual link ads injected into web pages. The ads are generated by the web browser plugin for IE, FF, and Chrome, and may appear on any website regardless of affiliation with the publisher. Users may encounter up to 10 intext ads, 4 banner ads, and/or a transitional ad on web pages. This application is commonly bundled with 3rd-party download managers that use misleading advertising techniques to install the software. In addition to displaying ads, HQTotalS may modify browser settings, such as lowering security levels and changing the home page and search provider, resulting in web browser hijacking. Furthermore, the extension reports user behavior and analytics back to a controlling server, which may include visited URLs and domains, as well as ad interaction data. This adware is frequently bundled with multiple potentially unwanted programs within 3rd party download manager packages.

Multiple virus scanners have detected malware in HQTotalS.

utils.exe (MD5: 130f62ec4d9d9c570df253ef1d80121a) has been flagged by 28 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.Adware
avast! Win32:Dropper-gen [Drp]
Baidu-International Trojan.Win32.VMDetector.E
Bkav FE HW32.CDB
Dr.Web Trojan.Crossrider.4794
ESET-NOD32 Win32/Toolbar.CrossRider.AB
K7 AntiVirus Trojan
K7GW Trojan ( 004973ed1 )
Malwarebytes PUP.Optional.CrossRider.A
McAfee Artemis!130F62EC4D9D
McAfee-GW-Edition Artemis!130F62EC4D9D
Norman Suspicious_Gen4.GCNAA
Symantec WS.Reputation
TrendMicro-HouseCall TROJ_GEN.F47V0318
Lavasoft Ad-Aware Trojan.Generic.11165362
AVG MultiBundle.W
Bitdefender Trojan.Generic.11165362
Emsisoft Anti-Malware Trojan.Generic.11165362 (B)
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11165362
G Data Trojan.Generic.11165362
IKARUS anti.virus Trojan.SuspectCRC
MicroWorld-eScan Trojan.Generic.11165362
NANO AntiVirus Trojan.Win32.Crossrider.cwgjyt
nProtect Trojan.Generic.11165362
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider
VIPRE Antivirus Crossrider (fs)
Sophos AppRider
HQTotalS-updater.exe (MD5: 01e5e6be31244ccea1ee64005d0a7f03) has been flagged by 25 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11165362
AVG MultiBundle.W
Baidu-International Adware.Win32.CrossRider.AC
Bitdefender Trojan.Generic.11165362
Dr.Web Trojan.Crossrider.7209
Emsisoft Anti-Malware Trojan.Generic.11165362 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11165362
G Data Trojan.Generic.11165362
IKARUS anti.virus Trojan.SuspectCRC
K7 AntiVirus Trojan ( 004984e91 )
K7GW Trojan ( 004984e91 )
Malwarebytes PUP.Optional.HQTotalS.A
McAfee RDN/Generic.dx!d2r
McAfee-GW-Edition RDN/Generic.dx!d2r
MicroWorld-eScan Trojan.Generic.11165362
NANO AntiVirus Trojan.Win32.Crossrider.cwgjyt
nProtect Trojan.Generic.11165362
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider
TrendMicro-HouseCall TROJ_GEN.F47V0317
VIPRE Antivirus Crossrider (fs)
avast! Win32:Malware-gen
Symantec WS.Reputation.1
Sophos AppRider
HQTotalS-firefoxinstaller.exe (MD5: a39c655569e01c36e37ea1f7929596d1) has been flagged by 2 scanners:
Scanner Software Result
Malwarebytes PUP.Optional.HQTotalS.A
VIPRE Antivirus Crossrider (fs)
HQTotalS-enabler.exe (MD5: 197cc14fff4fc7eb14b77d712d34efc7) has been flagged by 23 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11164385
avast! Win32:Malware-gen
AVG MultiBundle.U
Baidu-International Adware.Win32.CrossRider.AC
Bitdefender Trojan.Generic.11164385
Dr.Web Trojan.Crossrider.950
Emsisoft Anti-Malware Trojan.Generic.11164385 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11164385
G Data Trojan.Generic.11164385
IKARUS anti.virus Trojan.SuspectCRC
K7 AntiVirus Trojan ( 004984e91 )
K7GW Trojan ( 004984e91 )
Malwarebytes PUP.Optional.HQTotalS.A
McAfee Artemis!197CC14FFF4F
McAfee-GW-Edition Artemis!197CC14FFF4F
MicroWorld-eScan Trojan.Generic.11164385
nProtect Trojan.Generic.11164385
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.F47V0317
VIPRE Antivirus Crossrider (fs)
Sophos AppRider
HQTotalS-codedownloader.exe (MD5: 490824502954caf31708d92aa6c36b11) has been flagged by 4 scanners:
Scanner Software Result
avast! Win32:Dropper-gen [Drp]
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AA
VIPRE Antivirus Crossrider (fs)
Malwarebytes PUP.Optional.HQTotalS.A

Software Behaviors

Scheduled tasks:
  • HQTotalS-enabler.exe is scheduled as a task named 'temp_HQTotalS-enabler'.

Startup Entries

Startup tasks:
  • HQTotalS-updater.exe is automatically launched at startup through a scheduled task named HQTotalS-updater.
  • HQTotalS-codedownloader.exe is automatically launched at startup through a scheduled task named HQTotalS-codedownloader.
  • HQTotalS-firefoxinstaller.exe is automatically launched at startup through a scheduled task named HQTotalS-firefoxinstaller.
  • HQTotalS-enabler.exe is automatically launched at startup through a scheduled task named HQTotalS-enabler.
  • HQTotalS-chromeinstaller.exe is automatically launched at startup through a scheduled task named HQTotalS-chromeinstaller.

Software Details

URL:
Support:
Installation path:
C:\Program Files\HQTotalS
Uninstaller:
C:\Program Files\HQTotalS\Uninstall.exe /fromcontrolpanel=1
Size:
643.00 KB
Language:
English

HQTotalS Executable Details

Primary executable:
utils.exe
Name:
HQTotalS
Path:
C:\Program Files\HQTotalS\utils.exe
MD5:
130f62ec4d9d9c570df253ef1d80121a
SHA-1:
SHA-256:
Files installed by HQTotalS
File Type Filename MD5
DLL
144187ed70a6a1e820354e9b7e73ceec
EXE
895a01979454e09f9ebbe848f416596b