apps hat-bho64.dll

Apps Hat

Sailor Project

This potentially unwanted Internet browser extension is built upon and distributed using the free Crossrider platform and will deliver advertisements to the web browser in various formats such as banner, text hyper-links, inline text and transitional ads. The module apps hat-bho64.dll by Sailor Project has been detected as adware by 6 anti-malware scanners. This is the 64-bit version of the Browser Helper Object (BHO) for the Crossrider web browser platform for Internet Explorer. Instead of utilizing a traditional IE Toolbar, Crossrider installs a BHO in the browser in order to manage the functionality of Nero addon. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Nero  (signed by Sailor Project)

Product:
Apps Hat

Description:
Apps Hat BHO

Version:
1000.1000.1000.1000

MD5:
7ea3d493423d6e539ec017a3bf1eb5a1

SHA-1:
1dd36a9daa8559edc6a0c351fa5c74f77099d57f

SHA-256:
57cc3b37768d1fcb04665057f6e571e6f06cb76cf278bd64129ee6df803ed77e

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform. It will run as a BHO in Internet Explorer. Distributed through the Brightcircle investments brand.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Sailor Project.

Analysis date:
4/24/2024 3:06:13 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/CrossRider.Gen2
7.11.163.230

ESET NOD32
Win64/Toolbar.Crossrider (variant)
8.10149

IKARUS anti.virus
AdWare.Adload
t3scan.1.6.1.0

Malwarebytes
PUP.Optional.AppsHat.A
v2014.07.25.01

Reason Heuristics
PUP.Crossrider.SailorProject.O
14.7.27.12

VIPRE Antivirus
Crossrider
31570

File size:
753.9 KB (771,944 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Apps Hat.dll

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\Program Files\apps hat\apps hat-bho64.dll

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/18/2014 2:00:00 AM

Valid to:
7/19/2015 1:59:59 AM

Subject:
CN=Sailor Project, O=Sailor Project, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
47C5F145C734CD3D086C0A102176F0A1

Registration
CLSIDs:
{11111111-1111-1111-1111-110411851159}, {22222222-2222-2222-2222-220422852259}

ProgIDs:
CrossriderApp0048559.BHO.1, CrossriderApp0048559.Sandbox.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
7/22/2014 12:06:08 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:ZIwANRx3FrJWIntkUoYpN6V45TQEgAuXjK24WkEh5aldSZVEKP5ggRFQWKGe5Lrw:olZk+pYWVFQwZtA9BnBSArQlWTxhzrYO

Entry address:
0x58D58

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, EB, CB, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, 03, 00, 00, 00, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 20, 4C, 89, 40, 18, 89, 50, 10, 48, 89, 48, 08, 56, 57, 41, 56, 48, 83, EC, 50, 49, 8B, F0, 8B, DA, 4C, 8B, F1, BA, 01, 00, 00, 00, 89, 50, B8, 85, DB, 75, 0F, 39, 1D, 3C, 9C, 05, 00, 75, 07, 33, C0, E9, D2, 00, 00, 00, 8D, 43, FF...
 
[+]

Entropy:
6.2124

Code size:
490.5 KB (502,272 bytes)

Remove apps hat-bho64.dll - Powered by Reason Core Security