Home Malware Programs Adware Framed Display

Framed Display

Posted: September 22, 2014

Threat Metric

Ranking: 7,732
Threat Level: 2/10
Infected PCs: 16,034
First Seen: September 22, 2014
Last Seen: October 15, 2023
OS(es) Affected: Windows


Framed Display is a variant of the Yontoo Adware, a Web-browsing add-on that displays extra advertisements and may hijack your browser. Members of this family are noteworthy for their poor distribution and advertising practices, which could allow Framed Display to be installed by default and endanger your PC with unsafe content. Unless you find strong reasons for making use of Framed Display, deleting Framed Display with dedicated anti-adware software is the action most often encouraged by malware analysts.

A Social Display for Your New Advertisements

Yontoo Adware is a large family of browser add-ons that deliver advertisements, with or without any additional features that may or may not benefit your PC. Symptoms typical to this family include search engine hijacks that redirect you to unwanted search sites, changes to Facebook Web pages and additional in-browser advertisements that load via an additional graphics layer. This layer may imitate the format of a Facebook page or otherwise falsely imply that its advertisements deliver themselves through that site. Framed Display is one of the many adware products based on this standard template, and, like many of its relatives, may be installed automatically.

Framed Display includes a BHO component for Internet Explorer, as well as a separate component for Firefox. Some reports have indicated that Framed Display may be developing variants of itself for Chrome, although malware experts have yet to confirm this information. Linux and OS X-based Web browsers are incompatible with all known versions of Framed Display.

Framed Display was a recently-developed variant with digital signatures indicating its origin in 2014. However, malware experts found many, if not all anti-adware programs including various detection entries for Framed Display, along with separate components (such as its automatic update module). Most detections of Framed Display will identify Framed Display as either adware or as a Potentially Unwanted Program.

Pulling a Framed Display Off of Your Browser's Wall

Framed Display's bandwidth and system resource demands may harm your Web-browsing performance, and malware analysts find more security issues than advantages from Framed Display's unblockable advertisements. Yontoo Adware of any brand name ordinarily is a drawback to any browser that Framed Display affects, even if Framed Display installs itself with your full permission. More common installation methods than consensual ones include bundles with other applications and torrent-seeded archives, which Web install Framed Display automatically.

Framed Display may include a standardized entry for the Windows Control Panel – but Framed Display may block all uninstall attempts made through that utility. Many anti-adware and some anti-malware products have reasonable records for detecting and deleting Framed Display. Recently-identified PUPs like Framed Display also should be removed only after you've installed updates to your security software, which can enable a complete and accurate detection of all of its files.

Aliases

Generic.7F2 [AVG]Adware/Win32.SwiftBrowse [AhnLab-V3]GrayWare[AdWare:not-a-virus]/Win32.Kranet [Antiy-AVL]Generic PUA FM [Sophos]Artemis!PUP [McAfee-GW-Edition]Trojan.BPlug.281 [DrWeb]Win.Adware.Agent-22685 [ClamAV]Win32:Adware-BYZ [PUP] [Avast]Artemis!BF66026AF3F4 [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\Framed Display\updateFramedDisplay.exe File name: updateFramedDisplay.exe
Size: 521.97 KB (521976 bytes)
MD5: dc7536791ea47f8f01b96554652a8547
Detection count: 1,288
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Framed Display
Group: Malware file
Last Updated: October 16, 2014
%PROGRAMFILES%\Framed Display\bin\FramedDisplay.BOASHelper.exe File name: FramedDisplay.BOASHelper.exe
Size: 1.64 MB (1649912 bytes)
MD5: 197bd81ce37dd3bba17ce9a28e21f2d0
Detection count: 710
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Framed Display\bin
Group: Malware file
Last Updated: November 14, 2019
%PROGRAMFILES(x86)%\Framed Display\bin\utilFramedDisplay.exe File name: utilFramedDisplay.exe
Size: 522.48 KB (522488 bytes)
MD5: daabde9fe7588d4547d1132ed277f882
Detection count: 438
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Framed Display\bin
Group: Malware file
Last Updated: October 16, 2014
%PROGRAMFILES(x86)%\Framed Display\bin\utilFramedDisplay.exe File name: utilFramedDisplay.exe
Size: 522.48 KB (522488 bytes)
MD5: 88997c6367f4109eecb7fea7db368ff6
Detection count: 398
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Framed Display\bin
Group: Malware file
Last Updated: October 16, 2014
%PROGRAMFILES(x86)%\Framed Display\bin\FramedDisplay.BrowserAdapter64.exe File name: FramedDisplay.BrowserAdapter64.exe
Size: 114.93 KB (114936 bytes)
MD5: b9f23a1d1ead8f759350d846142335ef
Detection count: 370
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Framed Display\bin
Group: Malware file
Last Updated: October 16, 2014
%PROGRAMFILES(x86)%\Framed Display\bin\FramedDisplay.BOASPRT.exe File name: FramedDisplay.BOASPRT.exe
Size: 1.78 MB (1786616 bytes)
MD5: 2347cb599720c0544747d62fa6404213
Detection count: 358
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Framed Display\bin
Group: Malware file
Last Updated: November 14, 2019
%PROGRAMFILES%\Framed Display\bin\FramedDisplay.BrowserAdapter.exe File name: FramedDisplay.BrowserAdapter.exe
Size: 98.55 KB (98552 bytes)
MD5: d7f454b635c325df1ebe989da569ebd7
Detection count: 356
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Framed Display\bin
Group: Malware file
Last Updated: October 16, 2014
%PROGRAMFILES(x86)%\Framed Display\bin\utilFramedDisplay.exe File name: utilFramedDisplay.exe
Size: 524.02 KB (524024 bytes)
MD5: 852b75aafb457d239109fade4b5688ed
Detection count: 173
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Framed Display\bin
Group: Malware file
Last Updated: November 3, 2014
%ALLUSERSPROFILE%\Application Data\ecbaef90-5696-41e1-a1c3-3e8112ce2840\maintainer.exe File name: maintainer.exe
Size: 123.64 KB (123640 bytes)
MD5: 18d9e57756fa5957136ff8c904ded3f8
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data\ecbaef90-5696-41e1-a1c3-3e8112ce2840
Group: Malware file
Last Updated: November 5, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{05b5ef3f-4c6a-426e-b77e-48ebb3e721f1}{457C58FE-9FCB-4767-9419-1BC4932370D7}{5B81129C-6563-411B-A509-6BBB01EC25FF}{6AC2E1F6-094A-4F79-A012-23F0E0C35622}{7e9ae6ab-9e90-4f08-8f29-915a78d969bf}{A6CEB2DE-65F7-46FE-89DA-446DD487F293}{c02e2d64-25b6-49a8-a438-dcbd4a390103}HKEY..\..\..\..{RegistryKeys}Software\Framed DisplaySoftware\Microsoft\Internet Explorer\Approved Extensions\{05b5ef3f-4c6a-426e-b77e-48ebb3e721f1}Software\Microsoft\Internet Explorer\Approved Extensions\{7E9AE6AB-9E90-4F08-8F29-915A78D969BF}SOFTWARE\Microsoft\Tracing\FramedDisplay_RASAPI32SOFTWARE\Microsoft\Tracing\FramedDisplay_RASMANCSSOFTWARE\Microsoft\Tracing\updateFramedDisplay_RASAPI32SOFTWARE\Microsoft\Tracing\updateFramedDisplay_RASMANCSSOFTWARE\Microsoft\Tracing\utilFramedDisplay_RASAPI32SOFTWARE\Microsoft\Tracing\utilFramedDisplay_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{05b5ef3f-4c6a-426e-b77e-48ebb3e721f1}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{05B5EF3F-4C6A-426E-B77E-48EBB3E721F1}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7E9AE6AB-9E90-4F08-8F29-915A78D969BF}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{05B5EF3F-4C6A-426E-B77E-48EBB3E721F1}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7E9AE6AB-9E90-4F08-8F29-915A78D969BF}SOFTWARE\Wow6432Node\Framed DisplaySOFTWARE\Wow6432Node\Microsoft\Tracing\FramedDisplay_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\FramedDisplay_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateFramedDisplay_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateFramedDisplay_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilFramedDisplay_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilFramedDisplay_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{05b5ef3f-4c6a-426e-b77e-48ebb3e721f1}SYSTEM\ControlSet001\services\eventlog\Application\Util Framed DisplaySYSTEM\ControlSet001\services\Update Framed DisplaySYSTEM\ControlSet001\services\Util Framed DisplaySYSTEM\ControlSet002\services\eventlog\Application\Update Framed DisplaySYSTEM\ControlSet002\services\eventlog\Application\Util Framed DisplaySYSTEM\ControlSet002\services\Util Framed DisplaySYSTEM\CurrentControlSet\services\eventlog\Application\Update Framed DisplaySYSTEM\CurrentControlSet\services\eventlog\Application\Util Framed DisplaySYSTEM\CurrentControlSet\services\Update Framed DisplaySYSTEM\CurrentControlSet\services\Util Framed DisplayHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Framed Display

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\ecbaef90-5696-41e1-a1c3-3e8112ce2840%ALLUSERSPROFILE%\ecbaef90-5696-41e1-a1c3-3e8112ce2840%PROGRAMFILES%\Framed Display%PROGRAMFILES(x86)%\Framed Display%TEMP%\Framed Display
The following URL's were detected:
frameddisplay.com
Loading...