Exciting Apps

Publisher Information

Exciting Apps is a software developer located in Philadelphia, Pennsylvania in the United States*. The company is a primary distributor of unwanted software. Exciting Apps (Red Online Marketing Group LP) is a advertising software producer of web browser add-ons designed to display ads and affiliate offers within the web pages of a web browser. The company re-distributes a few dozen of the same adware type programs through monetized bundled installations primarily using the Crossrider toolbar platform.
Remove Exciting Apps Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
3/18/2014 1:00:00 AM

Valid to:
3/26/2015 12:59:59 AM

Subject:
CN=Exciting Apps, O=Exciting Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
534682e2d442ec8ea3320856df2214dc

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.GamePlayLabs.50OnRed (M), PUP.50OnRed.ExcitingApps.Installer (M)
100.00%

Zillya! Antivirus
Adware.Agent.Win32.14987, Adware.Agent.Win32.15086, Adware.Agent.Win64.28
92.00%

VIPRE Antivirus
Trojan.Win32.Generic, Win64.Adware.SmartApps
88.00%

Antiy Labs AVL
GrayWare[AdWare:not-a-virus]/Win32.Agent, Trojan/Win32.SGeneric
88.00%

ESET NOD32
Win32/AdWare.SmartApps, Win32/AdWare.SmartApps (variant)
88.00%

IKARUS anti.virus
AdWare.Smartapps, AdWare.DealDropper, not-a-virus:AdWare.Agent
88.00%

AVG
Generic5, AdPlugin
88.00%

Bkav FE
W32.HfsAdware, W64.HfsAdware
62.00%

Trend Micro House Call
TROJ_GEN.F47V0310, Suspicious_GEN.F47V0702
62.00%

Jiangmin
Adware/Agent.afoi, Adware/Agent.trl
60.00%

24 / 68    (Adware)
frameworkengine.exe (Framework)  (d20fa3c8d12fd912616690ab9fe9d7aa)

18 / 68    (Adware)
frameworkbho64.dll (Framework)  (fbcf1b571ad0d6f8422b5349a8fb1cdd)

13 / 68    (Adware)
frameworkbho.dll (Framework)  (131d80a7778f1d9cd1bed9eb9bd1949c)

24 / 68    (Adware)
frameworkengine.exe (Framework)  (c95de4169c5c023dbafb80c900e4697e)

18 / 68    (Adware)
frameworkbho64.dll (Framework)  (24bd103a1ed1455e6509a4f9f375fca6)

13 / 68    (Adware)
frameworkbho.dll (Framework)  (ea098dcf6e5398d8a54df4c12272b349)

20 / 68    (Adware)
frameworkbho64.dll (Framework)  (d7fdf215720e513d4be2f90e05a9b4ec)

16 / 68    (Adware)
frameworkbho.dll (Framework)  (9eb12e13b9e8ddfdbb20e680b6697dc2)

1 / 68      (Adware)
setup_solid savings-1.0.20140523.exe  (cc12be97e42632cc6a4cb8f35763b3bd)

18 / 68    (Adware)
frameworkbho64.dll (Framework)  (ed4aeff157f68b77db0665f184411f08)

24 / 68    (Adware)
frameworkengine.exe (Framework)  (115d152d3a7f51c7e4ad350e6d8c4993)

30 / 68    (Adware)
frameworkbho64.dll (Framework)  (285e07eaad84069ba6b8dc9b9fd39883)

23 / 68    (Adware)
frameworkbho.dll (Framework)  (65c946235d4abf7fb2a4020998d267d7)

24 / 68    (Adware)
frameworkengine.exe (Framework)  (e506645922ec2d593edee539ca6d75bf)

13 / 68    (Adware)
frameworkbho.dll (Framework)  (0df97d6b415ff43cdd6fd912843e00d2)

18 / 68    (Adware)
frameworkbho64.dll (Framework)  (38d9bdbd1454d0cdb1a83fafd60dd550)

13 / 68    (Adware)
frameworkbho.dll (Framework)  (da33574fdfdf1db83d361f886963746a)

24 / 68    (Adware)
frameworkengine.exe (Framework)  (5739d6cc754639b0b1f7aa69ca01d431)

18 / 68    (Adware)
frameworkbho64.dll (Framework)  (4f5e5f215a11fa6abb91f908be66e275)

18 / 68    (Adware)
frameworkbho64.dll (Framework)  (e34d3e9d20ae88975d901bf7bb02f30c)

1 / 68      (Adware)
coupon server.exe  (247ebc99219412277d038def33487a73)

24 / 68    (Adware)
frameworkengine.exe (Framework)  (3ce3c172c63dc81c4b9fe9fb1c1ec332)

18 / 68    (Adware)
frameworkbho64.dll (Framework)  (9b211b2105dfce575947758c560f0da6)

13 / 68    (Adware)
frameworkbho.dll (Framework)  (6eab8f17c5b1e8f90163e7cb00840297)

24 / 68    (Adware)
frameworkengine.exe (Framework)  (c53d46ae7d60bc87c8a3338156a4cb43)

18 / 68    (Adware)
frameworkbho64.dll (Framework)  (ecc78a1caef52a363d91c706d04f8c16)

13 / 68    (Adware)
frameworkbho.dll (Framework)  (7f01acf798dba9e34ce0aa1d8d08ba01)

1 / 68      (Adware)
78dfbd4f-6f3e-4b6e-89d6-26214a1bb62d  (cd90822b468e2cb21ae915b31139ecc5)

1 / 68      (Adware)
savings_hen.exe  (f503888752831552da1d36f096177c29)

18 / 68    (Adware)
frameworkbho64.dll (Framework)  (4cfb22339e06693842ee10072389a09b)

 
Latest 30 of 217 files

Downloads URLs for files signed by Exciting Apps.

The following publishers (by Authenticode signature organization name) are related.

Remove Exciting Apps Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Exciting Apps by Thawte, Inc. on March 18, 2014 with the serial number '534682e2d442ec8ea3320856df2214dc'.