frameworkbho.dll

Framework

Gratifying Apps

This file is a support library for an advertising-based software package (potentially unwanted/adware) distributed by 50onRed used to hijack the Internet browser search provider. The module frameworkbho.dll by Gratifying Apps has been detected as adware by 8 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Surf Safely BHO’. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links.
Publisher:
Gratifying Apps  (signed and verified)

Product:
Framework

Description:
FrameworkBHO

Version:
1.1.0.0

MD5:
05f86009b4d21ef4178bc1cb9b2f0c25

SHA-1:
a4d47527a54ebbfd4d13509891039b98489b9c8d

SHA-256:
a188831f0eab6e745e23254ca5ee63fb8a85e0a63db9df3d0635b2cd64195469

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Analysis date:
4/23/2024 6:08:03 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.SmartApps
7.1.1

AVG
Actuallyapps
2015.0.3307

Dr.Web
Adware.GamePlayLabs.41
9.0.1.05190

ESET NOD32
Win32/AdWare.SmartApps (variant)
8.10646

IKARUS anti.virus
PUA.SmartApps
t3scan.1.8.3.0

Reason Heuristics
Adware.GamePlayLabs.BHO.M
14.10.28.13

Vba32 AntiVirus
AdWare.Agent
3.12.26.3

VIPRE Antivirus
Threat.4750557
31208

File size:
347.3 KB (355,672 bytes)

Product version:
1.1.0.0

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\surf safely\frameworkbho.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
4/30/2014 1:00:00 AM

Valid to:
5/1/2015 12:59:59 AM

Subject:
CN=Gratifying Apps, O=Gratifying Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0BC7E6EB474AD9514161F0DF4C0D2268

File PE Metadata
Compilation timestamp:
6/30/2014 7:57:12 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:NIcKOnEJ8C8Ska8qKpekm+eVtb5D4Zu1XaX:NWJ8st8q0m+O5b1XaX

Entry address:
0x24845

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 30, 8A, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 78, A4, 04, 10, E8, 4C, DD, FF, FF, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 28, 20, 05, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 8C, C2, 03, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.5324

Developed / compiled with:
Microsoft Visual C++

Code size:
221 KB (226,304 bytes)

Internet Explorer BHO
Display name:
Surf Safely BHO

CLSID:
{6C85A1C9-0F93-4B46-BE67-D409D64C7E67}


Remove frameworkbho.dll - Powered by Reason Core Security