frameworkbho.dll

Framework

Gratifying Apps

This file is a support library for an advertising-based software package (potentially unwanted/adware) distributed by 50onRed used to hijack the Internet browser search provider. The module frameworkbho.dll by Gratifying Apps has been detected as adware by 9 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Browser Guard BHO’. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links.
Publisher:
Gratifying Apps  (signed and verified)

Product:
Framework

Description:
FrameworkBHO

Version:
1.1.0.0

MD5:
550de188eb8a8989a4b804e67775523c

SHA-1:
525c359ecda52d13b74fac20d86f9f0eaad6a62b

SHA-256:
115816362bfdd44dd5f19b7445e17658170b3363e0e229cb8e91075526fcd521

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Analysis date:
4/19/2024 1:28:28 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.SmartApps
7.1.1

AVG
Actuallyapps
2016.0.3183

Dr.Web
Adware.GamePlayLabs.41
9.0.1.05190

ESET NOD32
Win32/AdWare.SmartApps.H application
7.0.302.0

IKARUS anti.virus
PUA.SmartApps
t3scan.1.8.3.0

NANO AntiVirus
Riskware.Win32.Agent.dijihz
0.28.6.63726

Reason Heuristics
Adware.GamePlayLabs.BHO.50OnRed
15.3.2.3

Vba32 AntiVirus
AdWare.Agent
3.12.26.3

VIPRE Antivirus
Threat.4750557
31208

File size:
347.1 KB (355,432 bytes)

Product version:
1.1.0.0

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\browser guard\frameworkbho.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
4/30/2014 1:00:00 AM

Valid to:
5/1/2015 12:59:59 AM

Subject:
CN=Gratifying Apps, O=Gratifying Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0BC7E6EB474AD9514161F0DF4C0D2268

File PE Metadata
Compilation timestamp:
6/30/2014 7:57:12 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:yIcKOnEJ8C8Ska8qKpekm+eVbb5D4Z01Xaf:yWJ8st8q0m+s5N1Xaf

Entry address:
0x24845

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 30, 8A, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 78, A4, 04, 10, E8, 4C, DD, FF, FF, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 28, 20, 05, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 8C, C2, 03, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
221 KB (226,304 bytes)

Internet Explorer BHO
Display name:
Browser Guard BHO

CLSID:
{FCED84AA-0E0F-497E-9DD0-536082F684DB}


Remove frameworkbho.dll - Powered by Reason Core Security