frameworkbho.dll

Framework

Actually Apps

This file is a support library for an advertising-based software package (potentially unwanted/adware) distributed by 50onRed used to hijack the Internet browser search provider. The module frameworkbho.dll by Actually Apps has been detected as adware by 7 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Coupon Server BHO’. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links.
Publisher:
Actually Apps  (signed and verified)

Product:
Framework

Description:
FrameworkBHO

Version:
1.1.0.0

MD5:
b905e9d9f47397306acad56eda4ed2e3

SHA-1:
9abe9c8b88d594d8650d5614ac05a1b96635214c

SHA-256:
7c0fadf5b83fcc158db5be7d3169df8e5972a118abeab9912034d301a27d0bc7

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Analysis date:
4/19/2024 8:52:54 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.SmartApps
7.1.1

AVG
Actuallyapps
2015.0.3305

Dr.Web
Adware.GamePlayLabs.41
9.0.1.05190

IKARUS anti.virus
PUA.SmartApps
t3scan.1.8.3.0

Reason Heuristics
Adware.GamePlayLabs.BHO.M
14.10.31.3

Vba32 AntiVirus
AdWare.Agent
3.12.26.3

VIPRE Antivirus
Threat.4750557
31208

File size:
348.2 KB (356,584 bytes)

Product version:
1.1.0.0

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\coupon server\frameworkbho.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
4/30/2014 2:00:00 AM

Valid to:
5/1/2015 1:59:59 AM

Subject:
CN=Actually Apps, O=Actually Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
76114195147F3D93DF9D38DD306DA63A

File PE Metadata
Compilation timestamp:
6/30/2014 8:57:12 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:tIcKOnEJ8C8Ska8qKpekm+eVEb5D4Z41Xaj:tWJ8st8q0m+T591Xaj

Entry address:
0x24845

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 30, 8A, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 78, A4, 04, 10, E8, 4C, DD, FF, FF, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 28, 20, 05, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 8C, C2, 03, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
221 KB (226,304 bytes)

Internet Explorer BHO
Display name:
Coupon Server BHO

CLSID:
{F791D8AE-47E8-40A5-A913-EB2D2AF29602}


Remove frameworkbho.dll - Powered by Reason Core Security