Friday, 9 October 2015       

ShopAtHome Spyware/Adware Definition

Name: ShopAtHome
Category: Spyware
Alias:, ShopAtHomeSelect, SAHAgent, Golden Retriever Software, GRS
Advice: Remove
Risk: Elevated Risk Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge.
Description: ShopAtHome installs itself in the Winsock layer of your computer and redirects visits to merchant sites in order to take the affiliate fees from them automatically without your knowledge.

The SAHAgent installed by ShopAtHome is a Winsock 2 layered Service Provider which intercepts all incoming an outgoing network data and in cases modifies the data to insert its affiliate information in order to get sales credits for items you purchase. This type of spyware is also known as browser hijacking. The SAHAgent is always running and cannot be disabled without a full uninstall which is extremely difficult to do manually.

The software gathers and aggregates the userís Internet browsing behaviour and sends it to ShopAtHomeSelect servers.

From the FAQs at
Q: What is the Golden Retriever Software, and why should I install it?
A: Golden Retriever Software (GRS) is a program that was written to ensure that you maximize your cash-back rebates every time that you shop on-line. If you log directly on to the site of a merchant without going first to, and you make a purchase, that purchase is not eligible for the ShopAtHomeSelect cash-back rebate. If you have GRS installed on your computer, every time you log on to a ShopAtHomeSelect store, GRS will automatically take you through the site so that any purchases made from a participating store will be eligible for the rebate."

An extract from ShopAtHomeSelect.comís Privacy Policy:
"What Information We Collect and Why
Our goal at is to maximize the "Cash Back" rewards for our members and to provide them with as many benefits as possible. The primary way we do this is by utilizing the power of our consumer membership base to negotiate significant sales commissions from both well-known national retailers as well as specialty boutiques (our "Affiliate Merchants"). We then pass on as much of this commission to you, as a member, in the form of real cash.

Consequently, when you first register with, we ask you to provide your name, date of birth, street address, and E-mail address to determine your eligibility to be a member and to process your "Cash Back" rewards. We also ask for additional optional information on your interests, gender, and occupation. Based on this information, we can better determine what types of merchants and specials to pursue so that you will get the most out of your membership in However, you are under no obligation to provide us with this information-it is completely optional. may also collect certain information online and offline deriving from your navigation of and our Affiliate Merchants, including but not limited to the number and type of offers you have responded to and completed, so that we can make future relevant and personalized offers to you. uses cookie technology to understand general information on site traffic trends such as most frequently visited pages or Affiliate Merchants. This information is captured on an aggregate basis, is not specific to individual users, and enables to continually improve our Web site content and navigation.
The cookies also enable our Affiliate Merchants to recognize you as a member so that they can accurately process Qualified Purchases. (Please refer to our Membership Agreement for a full definition of a "Qualified Purchase."). may also collect certain informati

Signatures: process: bundle.exe: MD5 Hash: c1d6579e3d41801a0ba... process: cleansahagent.exe: MD5 Hash: a42a5286d27d2a2a741... process: sahagent.exe: MD5 Hash: c6456c0815bfa7f0e82... process: sahagent.exe: MD5 Hash: 52981ebe5e8680af3f4... process: sahhtml.exe: MD5 Hash: f52944f81b9ea236aa0... process: sahagent_.exe: MD5 Hash: ... process: sahdownloader_.exe: MD5 Hash: ... process: sahhtml_.exe: MD5 Hash: ... process: sahuninstall_.exe: MD5 Hash: ... process: sahdownloader.exe: MD5 Hash: ... process: bundle.exe: MD5 Hash: ... process: sahagent_.exe: MD5 Hash: 173627dcb381c93a38d... process: sahagent.exe: MD5 Hash: ... process: sahhtml.exe: MD5 Hash: 7149b70aed0585ca850... process: sahagent1019.exe: MD5 Hash: c947e1d5f8872596ca6... process: sahhtml_.exe: MD5 Hash: 7e0d2946d5f3c2b027c... process: sahuninstall_.exe: MD5 Hash: 6eff8c06bab02192730... process: sahagent1020.exe: MD5 Hash: 6c0405f8b9adad66ee8... process: sahhtml.exe: MD5 Hash: ... process: bundle.exe: MD5 Hash: a12f5cc77436d6286b0... process: sd.exe: MD5 Hash: 5b1f98ff51f1a523bc4... process: sahuninstall_.exe: MD5 Hash: 2462e8c2fdc6f3d83fb... process: sahagent_.exe: MD5 Hash: 862a81d5d5157fe1f67... process: sahhtml_.exe: MD5 Hash: 0a102e183b89df285ff... process: sahdownloader.exe: MD5 Hash: ... process: sahagent.exe: MD5 Hash: a634cf3f7b741452011... process: sahagent.exe: MD5 Hash: 84aec25f1c54a03ec7a... process: bundle.exe: MD5 Hash: ... process: bundle.exe: MD5 Hash: 61a956c596e887ada4c... process: sahagent-cdt1004.exe: MD5 Hash: 742b045130da50096d9... process: ap9h4qmo.exe: MD5 Hash: 22596badf6a415c3d70... process: ap9h4qmo.exe: MD5 Hash: 011214997dfe3923690... process: 1.exe: MD5 Hash: 74c9937509b7832c7b0... process: u6f6uftuc_.exe: MD5 Hash: fb06544d703e99401ec... process: a95kfrhe.exe: MD5 Hash: fb06544d703e99401ec... process: sahagent.exe: MD5 Hash: b837290089f8c47b792... process: umqltg4cl_.exe: MD5 Hash: 5a0806c940d860713ab... process: ridaq0qr.exe: MD5 Hash: 62814ae7e86b71471a3... process: 766vl14i.exe: MD5 Hash: f4ba502e2bbc6a637dd... process: oaq6q514.exe: MD5 Hash: 5a0806c940d860713ab... process: shop1003.exe: MD5 Hash: 163eff0abc1d0979923... process: adp8036_siac.exe: MD5 Hash: c9312bce1a61b92c71d... process: ap9h4qmo.exe: MD5 Hash: be80f9f0ea0107a5011... process: shop1004.exe: MD5 Hash: a6702a11a8a9c3b4388... process: ap9h4qmo.exe: MD5 Hash: 1a4170d3430dde68026... process: q451782.exe: MD5 Hash: a44c3ac899eec8d0f72... process: cc6p7pug.exe: MD5 Hash: fb06544d703e99401ec... process: %system%fraja2fs.exe: MD5 Hash: 4da2c53838d28e17822... process: ibecdbv8.exe: MD5 Hash: 22596badf6a415c3d70... process: sahagent[1].exe: MD5 Hash: ... process: sahagent[1].exe: MD5 Hash: ... process: sahagent.exe: MD5 Hash: 3f0aa5fea6a80cafa40... process: atrc8parb_.exe: MD5 Hash: d18cd4e460c8a5df6f2... process: umqltg4cl_.exe: MD5 Hash: 84dad2daf053a3082d0... process: hqrhil7kg_.exe: MD5 Hash: 4eb966220ab084ccc9a... process: update.exe: MD5 Hash: ab4973f384b273394e0... process: hqrhil7kg_.exe: MD5 Hash: f848dd7e972d0b56963... process: sahuninstall.exe: MD5 Hash: ... process: SahHtml_.exe: MD5 Hash: fc117188f3b506eb9c6... process: SAHUninstall_.exe: MD5 Hash: 593b43b7db7c9e3a8c8... process: sahage~1.exe: MD5 Hash: be36982590ad87efbfb... process: adp8038_siac.exe: MD5 Hash: 0670acc34ce3e9eefa7... process: shop1004.exe: MD5 Hash: 2b271238c31cafdb28d... process: abasa5jrp_.exe: MD5 Hash: c8e548cd52d6ca650a6... process: sahagent.exe: MD5 Hash: cf753125505743fd915... process: hochkaod3_.exe: MD5 Hash: 23ca5c37675a7e7ea27... process: u6f6uftuc_.exe: MD5 Hash: a1cf5073b563ec38507... process: grinstall.exe: MD5 Hash: b48807068fc943af21c... process: bundlep.exe: MD5 Hash: f3cc1d74ba298151154... process: sahagent-mediamotor1002.exe: MD5 Hash: afe7c5023f8fd33d69d... process: sahagent-mediamotor1003.exe: MD5 Hash: 1f115ef56f281da6958... process: update.exe: MD5 Hash: ee308fa95caf0b45adc... process: 36o1ogv0.exe: MD5 Hash: 7ee4d73ff5f9005fbe4... process: umqltg4cl_.exe: MD5 Hash: 47f42f7801fa19387ed... process: mksara4g.exe: MD5 Hash: c1d1c05bc464c0833ba... process: fg144pd9.exe : MD5 Hash: 7ee4d73ff5f9005fbe4... process: dkd3gcte.exe: MD5 Hash: 47f42f7801fa19387ed... process: abftllf4.exe: MD5 Hash: a325a6135d9720662b7... process: 5e5mkpqp.exe : MD5 Hash: c1d1c05bc464c0833ba... process: hffk9e1k.exe: MD5 Hash: 47f42f7801fa19387ed... process: sahagent.exe: MD5 Hash: a3f8b1d0fb60626dad0... process: sahagent.exe: MD5 Hash: fef652a86d583692e30... process: sahhtml.exe: MD5 Hash: fc117188f3b506eb9c6... process: sahhtml.exe: MD5 Hash: 7149b70aed0585ca850... process: sahhtml.exe: MD5 Hash: 3d9e62c8e8e03ef5d37... process: bwestfrontier1002.exe: MD5 Hash: 8a180641def5fd7c28f... process: bundle_mediamotor1004.exe: MD5 Hash: 39b1b11d6b41bbc1eed... process: sahagent.exe: MD5 Hash: 38f36d63d9eca5afdce... process: sahagent.exe: MD5 Hash: 173627dcb381c93a38d... process: q17i9a4j.exe: MD5 Hash: 4da2c53838d28e17822... process: g4s9hs1l.exe: MD5 Hash: 7ee4d73ff5f9005fbe4... process: 0s48o30s.exe : MD5 Hash: c1d1c05bc464c0833ba... process: dd2p6o45.exe: MD5 Hash: 47f42f7801fa19387ed... process: sahagent.exe: MD5 Hash: 13eee1655e538c27fc0... process: atrc8parb_.exe: MD5 Hash: 4dc02cd16abae30674b... process: hqrhil7kg_.exe: MD5 Hash: c1d1c05bc464c0833ba... process: umqltg4cl_.exe: MD5 Hash: 20f3bd2493f4e690684... process: hqrhil7kg_.exe: MD5 Hash: d6ab825ed00a424449a... process: umqltg4cl_.exe: MD5 Hash: 6300b3b7898edf12873... process: bundlep.exe: MD5 Hash: 29f4526a01798f2908d... process: q2iulfjv.exe: MD5 Hash: ccac6acdf45a3224e44... process: hxk8pjf7w.exe: MD5 Hash: c1cc63a82008016bc58... process: ur62l2y07.exe: MD5 Hash: 694ccd7aa231c40cb35... process: 3tbt6v4p.exe: MD5 Hash: 47f42f7801fa19387ed... process: 5uk57cbn.exe: MD5 Hash: a325a6135d9720662b7... process: fapsga72.exe: MD5 Hash: c1d1c05bc464c0833ba... process: ur62l2y07_.exe: MD5 Hash: 05cc727b7e166e2ae39... process: bundlelite.exe: MD5 Hash: b91aad7b299410fb4fc... process: aqg4knfz3_.exe: MD5 Hash: a62c2bb9b6456607479... process: zfxedct97.exe: MD5 Hash: 168f3aefdf1c4658be1... process: qapvjar.exe: MD5 Hash: 70e57e0f9f3dafcbdaa..
Type: Spyware - Spyware's primary purpose is to collect demographic and usage information from your computer, usually for advertising purposes. Spyware usually that 'sneaks' onto a system or performs other activities hidden to the user. Spyware programs are usually bundled as a hidden component and downloaded from the Internet. These modules are almost always installed on the system secretively and try to run secretively as well.

Top Spyware Visited Pages:
Advanced Email Monitoring
Axexx CHM
CommonSearch VCatch


Main Menu
Top Downloads
New Programs
Link to us
Spyware Definitions
Viruses Info
Contact us



- Privacy Policy -