HttpHandle302.dll

ShopAtHome.com Browser App

ShopAtHome.com (Belcaro Group, Inc)

The module HttpHandle302.dll, “ShopAtHome.com 302 handler” by ShopAtHome.com (Belcaro Group, Inc) has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program ShopAtHome.com Helper by Belcaro Group Inc. which is a potentially unwanted software program.
Publisher:
ShopAtHome.com  (signed by ShopAtHome.com (Belcaro Group, Inc))

Product:
ShopAtHome.com Browser App

Description:
ShopAtHome.com 302 handler

Version:
1.0.0.1

MD5:
69702fd2d2649db6cfa837955e88bb16

SHA-1:
2697dd43dc5830a84e42bdd2bd4b7ac51ca4a682

SHA-256:
fdff9a2e5fffbfe37beb93d8655ac3274fc069d1b8cd8c14229669004473699f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/24/2024 8:29:11 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ShopAtHome
16.7.28.10

File size:
4.1 MB (4,327,568 bytes)

Product version:
1.0.0.1

Copyright:
(c) ShopAtHome.com. All rights reserved.

Original file name:
HttpHandle302.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\shopathome\shopathomehelper\httphandle302.dll

Digital Signature
Authority:
Symantec Corporation

Valid from:
5/21/2013 8:00:00 PM

Valid to:
6/6/2014 7:59:59 PM

Subject:
CN="ShopAtHome.com (Belcaro Group, Inc)", O="ShopAtHome.com (Belcaro Group, Inc)", L=Greenwood Village, S=Colorado, C=US, SERIALNUMBER=19871692567, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Colorado, OID.1.3.6.1.4.1.311.60.2.1.3=US

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
05AACC1DBAF989DD6997926C9649BAEF

File PE Metadata
Compilation timestamp:
6/12/2013 1:05:24 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:FOZ+izFgjkZAGqyYV+qByrdkK3P8Fc9+MkCXlAhVb/zXHyZDybxd1gq9ZG6VyYs:FjjkZszVxyV3P8Fl0SyZDyN4eZG6VS

Entry address:
0xB228

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 8E, 37, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 6A, 0C, 68, 80, 89, 01, 10, E8, 89, 01, 00, 00, 6A, 0E, E8, 7D, 39, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, 40, BA, 01, 10, BA, 3C, BA, 01, 10, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, 1C, F2, FF, FF, 59, FF, 76, 04, E8, 13, F2, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00...
 
[+]

Entropy:
0.3110

Code size:
65 KB (66,560 bytes)

The file HttpHandle302.dll has been discovered within the following program.

ShopAtHome.com Helper  by Belcaro Group Inc.
This is the helper application that is installed with the ShopAtHome Toolbar (Browser App).
www.shopathome.com
68% remove it
 
Powered by Should I Remove It?

Remove HttpHandle302.dll - Powered by Reason Core Security