FpaUtility.dll

Ziftr Alerts (formerly FreePriceAlerts.com) Utility Library

myVBO LLC

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The module FpaUtility.dll by myVBO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Ziftr Alerts - formerly FreePriceAlerts.com 3.1.0 by myVBO LLC which is a potentially unwanted software program.
Publisher:
myVBO LLC  (signed and verified)

Product:
Ziftr Alerts (formerly FreePriceAlerts.com) Utility Library

Version:
3.01.000.0

MD5:
c2591466531f40c8dc15408f547e12df

SHA-1:
04e44371e8e8fade8469dd0f6374a81409fa69ad

SHA-256:
33c3bec9ecd28e49854fb47a0612671cf5f481b8f31c1b61808bbe0dc16a0b17

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 4:25:37 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.myVBO.K
14.7.27.14

File size:
75.5 KB (77,328 bytes)

Product version:
3.01.000.0

Copyright:
Copyright (c) 2013 MyVBO LLC - All Rights Reserved

Original file name:
FpaUtility.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\ziftr alerts\fpautility.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/6/2013 2:00:00 AM

Valid to:
5/12/2015 1:59:59 AM

Subject:
CN=myVBO LLC, OU=FreePriceAlerts, O=myVBO LLC, L=Peterborough, S=New Hampshire, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6839CFCEA583E27C0222A8CEDE5E2DAF

File PE Metadata
Compilation timestamp:
5/16/2013 12:16:16 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:7HelDdUfaa3ZdQTjyE0faOZBZS2EZ6gbS:7HelDdjDjyE0faOZeXbS

Entry address:
0x12CAE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.8861

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
67.5 KB (69,120 bytes)

The file FpaUtility.dll has been discovered within the following program.

This toolbar/web browser extension is ad/search-supported that is typically installed as an optional offer, users generally have this bundled with 3rd party software.
www.Ziftr.com
75% remove it
 
Powered by Should I Remove It?

Remove FpaUtility.dll - Powered by Reason Core Security