frameworkbho.dll

Framework

Exciting Apps

This file is a support library for an advertising-based software package (potentially unwanted/adware) distributed by 50onRed used to hijack the Internet browser search provider. The module frameworkbho.dll by Exciting Apps has been detected as adware by 11 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘ProtectedBrowsing BHO’. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links.
Publisher:
Exciting Apps  (signed and verified)

Product:
Framework

Description:
FrameworkBHO

Version:
1.1.0.0

MD5:
6eab8f17c5b1e8f90163e7cb00840297

SHA-1:
efd5cfd018593eb8bf7c44ca35733216ed7f1583

SHA-256:
4e4908116de14adf687b26cf079104048f456d43effb25846de6c53d1c819972

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Analysis date:
4/27/2024 1:53:19 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.SmartApps
7.1.1

avast!
Win32:Malware-gen
2014.9-160209

AVG
AdPlugin
2017.0.2838

ESET NOD32
Win32/AdWare.SmartApps (variant)
10.9686

IKARUS anti.virus
AdWare.DealDropper
t3scan.1.6.1.0

K7 AntiVirus
Adware
13.185.13943

Reason Heuristics
Adware.GamePlayLabs.50OnRed (M)
16.2.9.19

Trend Micro House Call
TROJ_GEN.F47V0310
7.2.40

Vba32 AntiVirus
AdWare.Agent
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
28760

Zillya! Antivirus
Adware.Agent.Win32.15086
2.0.0.1977

File size:
459.6 KB (470,624 bytes)

Product version:
1.1.0.0

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\protectedbrowsing\frameworkbho.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/18/2014 1:00:00 AM

Valid to:
3/26/2015 12:59:59 AM

Subject:
CN=Exciting Apps, O=Exciting Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
534682E2D442EC8EA3320856DF2214DC

Registration
CLSIDs:
{442430FB-08D1-4ECE-8100-8B072607B6B5}, {7411C9AB-757D-4DC6-93E4-180588290D7C}

COM registered:
Yes

File PE Metadata
Compilation timestamp:
6/20/2014 2:07:23 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:XsezEEpzmcqBDg590zdtyq+XADnw9czxOuJ:8epIB+0zdtp+wDnw9czxB

Entry address:
0x376C5

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 62, 9C, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 40, 50, 06, 10, E8, 1C, 06, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, D0, C2, 06, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, BC, 5B, 05, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
317.5 KB (325,120 bytes)

Internet Explorer BHO
Display name:
ProtectedBrowsing BHO

CLSID:
{7411C9AB-757D-4DC6-93E4-180588290D7C}


Remove frameworkbho.dll - Powered by Reason Core Security