apps hat-bho64.dll

Apps Hat

Sailor Project

This potentially unwanted Internet browser extension is built upon and distributed using the free Crossrider platform and will deliver advertisements to the web browser in various formats such as banner, text hyper-links, inline text and transitional ads. The module apps hat-bho64.dll by Sailor Project has been detected as adware by 17 anti-malware scanners. This is the 64-bit version of the Browser Helper Object (BHO) for the Crossrider web browser platform for Internet Explorer. Instead of utilizing a traditional IE Toolbar, Crossrider installs a BHO in the browser in order to manage the functionality of Nero addon. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Nero  (signed by Sailor Project)

Product:
Apps Hat

Description:
Apps Hat BHO

Version:
1000.1000.1000.1000

MD5:
6823dbcfeb5f5f9d789b607e634aed9e

SHA-1:
375a41e566852c5b9075b6f0095ab2edef90f351

SHA-256:
9baf884fdef6115f7dd9418fa91287f1d745c811fcde90c8716594a89f51195e

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform. It will run as a BHO in Internet Explorer. Distributed through the Brightcircle investments brand.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Sailor Project.

Analysis date:
4/18/2024 6:02:55 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.AdLoad
7.1.1

Avira AntiVirus
ADWARE/CrossRider.Gen2
7.11.164.106

avast!
Win32:Crossrider-N [PUP]
2014.9-140824

AVG
Generic
2015.0.3373

Baidu Antivirus
Trojan.Win32.GoogUpdate
4.0.3.14824

Dr.Web
Adware.Toolbar.232
9.0.1.0274

ESET NOD32
Win64/Toolbar.Crossrider (variant)
8.10265

IKARUS anti.virus
AdWare.Adload
t3scan.1.7.5.0

K7 AntiVirus
Trojan
13.180.12498

Kaspersky
Trojan.NSIS.GoogUpdate
14.0.0.3358

Malwarebytes
PUP.Optional.AppsHat.A
v2014.08.24.09

McAfee
Artemis!501F3553CAF5
5600.6991

Panda Antivirus
Adware/Goobzo
14.10.01.12

Qihoo 360 Security
Win32/Trojan.3b1
1.0.0.1015

Reason Heuristics
PUP.Crossrider.SailorProject.O
14.8.24.9

Trend Micro House Call
TROJ_GEN.F47V0115
7.2.274

VIPRE Antivirus
Crossrider
32266

File size:
863.4 KB (884,072 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Apps Hat.dll

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\Program Files\apps hat\apps hat-bho64.dll

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/18/2014 3:00:00 AM

Valid to:
7/19/2015 2:59:59 AM

Subject:
CN=Sailor Project, O=Sailor Project, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
47C5F145C734CD3D086C0A102176F0A1

Registration
CLSIDs:
{11111111-1111-1111-1111-110411851159}, {22222222-2222-2222-2222-220422852259}

ProgIDs:
CrossriderApp0048559.BHO.1, CrossriderApp0048559.Sandbox.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
8/14/2014 4:08:28 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:NkpgFdN7U2Xlq9pVQSNcMTILSVTeMXqEz:Nk6FdSyleXQSrTUGT96Ez

Entry address:
0x63238

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, EB, CB, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, 03, 00, 00, 00, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 20, 4C, 89, 40, 18, 89, 50, 10, 48, 89, 48, 08, 56, 57, 41, 56, 48, 83, EC, 50, 49, 8B, F0, 8B, DA, 4C, 8B, F1, BA, 01, 00, 00, 00, 89, 50, B8, 85, DB, 75, 0F, 39, 1D, BC, 79, 06, 00, 75, 07, 33, C0, E9, D2, 00, 00, 00, 8D, 43, FF...
 
[+]

Entropy:
6.2773

Code size:
573.5 KB (587,264 bytes)

Remove apps hat-bho64.dll - Powered by Reason Core Security