Hijacker . Shop At Home Select (Summary)
Software Name: Shop At Home Select
Company Name: Shop At Home Select
Product Name: Shop At Home Select
Classification: Hijacker
Website: http://www.shopathomeselect.com
Brief:
Shop At Home Select is a Winsock2 Layered Service Provider that redirects visits to merchant sites in order to take the affiliate fees.
IMPORTANT!
Some of the Hijacker.Shop At Home Select components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of Shop At Home Select
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
Shop At Home Select might create following folders (and inject its files inside
the folders):
Shop At Home Select might create following files (some of the files might be
loaded in memory while the software is running):
- %SYSTEMDRIVE%\sahagent.log
- %WINDOWS%\Downloaded Program Files\lsp_.dll
- %WINDOWS%\Downloaded Program Files\sahuninstall_.exe
- %WINDOWS%\Downloaded Program Files\webinstaller.dll
- %SYSTEM%\sahdownloader.exe
- %WINDOWS%\SAHUninstall.exe
- %WINDOWS%\Downloaded Program Files\SAH.exe
- %WINDOWS%\system\sahagent.exe
- %WINDOWS%\system\sahdownloader.exe
- %WINDOWS%\Downloaded Program Files\SAHAgent_.exe
- %WINDOWS%\Downloaded Program Files\SahHtml_.exe
- %SYSTEM%\SahAgent.exe
- %SYSTEM%\SahHtml.exe
- %SYSTEM%\tmpmpt1.tmp
- %SYSTEM%\v.dat
- %SYSTEM%\vg.dat
- %SYSTEM%\vp.dat
- %SYSTEM%\vh.dat
- %PROFILE%\Local Settings\Temp\AcsProxyStub.exe
- %PROFILE%\Local Settings\Temp\netthink.sah
- %PROFILE%\Local Settings\Temp\run.exe
- %SYSTEMDRIVE%\temp\sahagent.exe
- %PROFILE%\Local Settings\Temp\cdt1001.sah
- %PROFILE%\Local Settings\Temp\fellymedia1002.sah
- %PROFILE%\Local Settings\Temp\isearchtech1003.sah
- %PROFILE%\Local Settings\Temp\sahagent.exe
- %SYSTEM%\GRInstall6.dll
- %WINDOWS%\Downloaded Program Files\GRInstall.inf
Shop At Home Select is often accompanied by the following tracking cookies:
Shop At Home Select might create following registry keys (and inject subkeys
and values):
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopAtHomeSelect Agent
- HKEY_LOCAL_MACHINE\SOFTWARE\VGroup
- HKEY_CLASSES_ROOT\CLSID\{30402FF4-3E71-4A1C-9B4B-1CD3486A9FB2}
- HKEY_CLASSES_ROOT\Interface\{4828C95F-C5DB-4AB6-A945-8D8EC44B98A8}
- HKEY_CLASSES_ROOT\Interface\{4E570F74-DEEE-4FCF-B960-FEEFA4B8C6FC}
- HKEY_CLASSES_ROOT\TypeLib\{CDE442A3-DC2C-467E-A311-B4BC775D86C5}
- HKEY_CLASSES_ROOT\WEBInstaller.execute
- HKEY_CLASSES_ROOT\WEBInstaller.execute.1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{30402FF4-3E71-4A1C-9B4B-1CD3486A9FB2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\*/lsp_.dll*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\*/SAHAgent_.exe*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\*/SahHtml_.exe*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\*/SAHUninstall_.exe*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\*/WEBInstaller.dll*
- HKEY_CLASSES_ROOT\CLSID\{5F3B3060-09E0-44C6-86F7-BC7B02B57BEE}
- HKEY_CLASSES_ROOT\GRInstall6.Installer
- HKEY_CLASSES_ROOT\GRInstall6.Installer.1
- HKEY_CLASSES_ROOT\TypeLib\{46138192-DF0A-4A02-B206-8FD94BF4A7C7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5F3B3060-09E0-44C6-86F7-BC7B02B57BEE}
Shop At Home Select might create following registry values:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|sahagent
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|*\WEBInstaller.dll
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|*\SahHtml_.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|*\SAHUninstall_.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|*\SAHAgent_.exe
Shop At Home Select might create registry values with following data:
n/a
Shop At Home Select might insert following entries in the HOSTS file:
n/a
Click
here to scan your computer for Shop At Home Select free of charge
|