frameworkbho.dll

Framework

Smart Apps

This file is a support library for an advertising-based software package (potentially unwanted/adware) distributed by 50onRed used to hijack the Internet browser search provider. The module frameworkbho.dll by Smart Apps has been detected as adware by 9 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Instant Savings App BHO’. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links.
Publisher:
Smart Apps  (signed and verified)

Product:
Framework

Description:
FrameworkBHO

Version:
1.0.0.0

MD5:
c5ca2cc620f2a04cfa4b7ad0eee2333a

SHA-1:
a500d0073112733529b7d6b5a3826ddc714c4e8e

SHA-256:
9e9106da47554194cbf76e40e3bf7a63ba3448ea9ba3078e7a508741215103b4

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Analysis date:
4/20/2024 12:35:56 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.SmartApps
7.1.1

AVG
AdPlugin
2016.0.3195

Comodo Security
ApplicUnwnt
19389

Emsisoft Anti-Malware
Android.Trojan.Boqx
8.15.02.17.09

ESET NOD32
Win32/AdWare.SmartApps (variant)
9.9698

IKARUS anti.virus
AdWare.DealDropper
t3scan.1.6.1.0

Reason Heuristics
Adware.GamePlayLabs.BHO.50OnRed
15.2.17.21

Trend Micro House Call
TROJ_GEN.F47V0310
7.2.48

VIPRE Antivirus
GamePlayLabs
22968

File size:
250.5 KB (256,552 bytes)

Product version:
1.0.0.0

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\instant savings app\frameworkbho.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/25/2013 11:00:00 AM

Valid to:
3/26/2014 10:59:59 AM

Subject:
CN=Smart Apps, O=Smart Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7CAFCF7841E5BDDF79F61691D678D0EC

File PE Metadata
Compilation timestamp:
8/7/2013 6:52:12 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:Eenq6O7eobyhAgxdiFh8AlqJ+hazxIUF4avJ1Bwf1P7esoXqKeNELQNs:zzkby2lFInlHvJ1Bwf1P7xRryLQNs

Entry address:
0x19E7D

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, F6, 5B, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 20, 6E, 03, 10, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 24, 6E, 03, 10, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, 94, 19, 00, 00, 85, C0, 75, 06, B8, 88, 6F, 03, 10, C3, 83, C0, 08, C3, E8, 81, 19, 00, 00, 85, C0, 75...
 
[+]

Entropy:
6.4599

Code size:
152 KB (155,648 bytes)

Internet Explorer BHO
Display name:
Instant Savings App BHO

CLSID:
{6EB4A4C0-6036-4D2E-B010-20707C4B62E8}


Remove frameworkbho.dll - Powered by Reason Core Security