backup-20140730-123529-868.dll

D

myVBO LLC

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The module backup-20140730-123529-868.dll, “FreePriceAlerts.com” by myVBO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
FreePriceAlerts.com  (signed by myVBO LLC)

Product:
D

Description:
FreePriceAlerts.com

Version:
2.3.0.3

MD5:
d156e3864c576835fbe156be5dce94fa

SHA-1:
a616ac769ac78517a1a808014779257c28670f60

SHA-256:
7900c4238d5f82845a6f53beec493b4d7700b40411653a5ac1769d55ebbd15da

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 12:06:58 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.myVBO.AA
14.8.13.18

File size:
640.6 KB (655,960 bytes)

Product version:
2.3.0.3

Copyright:
FreePriceAlerts.com

Original file name:
vbobho.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/10/2012 7:00:00 PM

Valid to:
5/11/2013 6:59:59 PM

Subject:
CN=myVBO LLC, OU=FreePriceAlerts, O=myVBO LLC, L=Peterborough, S=New Hampshire, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1D23E52C70371EBEA800A8FDB3606CF4

File PE Metadata
Compilation timestamp:
5/25/2012 12:50:56 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:HcH/6m8g5PHcmFsQfC3clsU1nag7lNvBM1KI/HLAnEq7kUKyqcgh:HcH/x8gJ82k0PBM1vH8nEq7kUKyqcgh

Entry address:
0x6384F

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 77, 03, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, 68, F4, 31, 06, 10, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, EC, 9A, 08, 10, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, CC, CC...
 
[+]

Entropy:
6.3842

Code size:
436 KB (446,464 bytes)

Remove backup-20140730-123529-868.dll - Powered by Reason Core Security