frameworkbho.dll

Framework

Exciting Apps

This file is a support library for an advertising-based software package (potentially unwanted/adware) distributed by 50onRed used to hijack the Internet browser search provider. The module frameworkbho.dll by Exciting Apps has been detected as adware by 11 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Browser Warden BHO’. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links.
Publisher:
Exciting Apps  (signed and verified)

Product:
Framework

Description:
FrameworkBHO

Version:
1.1.0.0

MD5:
0df97d6b415ff43cdd6fd912843e00d2

SHA-1:
bd52cd55a768be4fe035ccbf9b8173b279ecf4c1

SHA-256:
54845f21e7c78679f0c2fe1d717e971e5dd663a7e6efb0806eb20f116c58f2a6

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Analysis date:
4/20/2024 2:27:19 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.SmartApps
7.1.1

avast!
Win32:Malware-gen
2014.9-160212

AVG
AdPlugin
2017.0.2836

ESET NOD32
Win32/AdWare.SmartApps (variant)
10.9686

IKARUS anti.virus
AdWare.DealDropper
t3scan.1.6.1.0

K7 AntiVirus
Adware
13.185.13943

Reason Heuristics
Adware.GamePlayLabs.50OnRed (M)
16.2.12.5

Trend Micro House Call
TROJ_GEN.F47V0310
7.2.43

Vba32 AntiVirus
AdWare.Agent
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
28760

Zillya! Antivirus
Adware.Agent.Win32.15086
2.0.0.1977

File size:
347.1 KB (355,424 bytes)

Product version:
1.1.0.0

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\browser warden\frameworkbho.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/17/2014 9:00:00 PM

Valid to:
3/25/2015 8:59:59 PM

Subject:
CN=Exciting Apps, O=Exciting Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
534682E2D442EC8EA3320856DF2214DC

File PE Metadata
Compilation timestamp:
6/30/2014 3:57:12 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:WIcKOnEJ8C8Ska8qKpekm+eVRb5D4ZO1XaY:WWJ8st8q0m+25j1XaY

Entry address:
0x24845

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 30, 8A, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 78, A4, 04, 10, E8, 4C, DD, FF, FF, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 28, 20, 05, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 8C, C2, 03, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
221 KB (226,304 bytes)

Internet Explorer BHO
Display name:
Browser Warden BHO

CLSID:
{2C09954F-CDA8-4BD1-8794-1D543E050378}


Remove frameworkbho.dll - Powered by Reason Core Security