FpaUtility.dll

Ziftr Alerts (formerly FreePriceAlerts.com) Utility Library

myVBO LLC

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The module FpaUtility.dll by myVBO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
myVBO LLC  (signed and verified)

Product:
Ziftr Alerts (formerly FreePriceAlerts.com) Utility Library

Version:
3.02.000.0

MD5:
a48389c5aee5ab514b1077c7d3dd3663

SHA-1:
1e61481e28ea932f029e9c6165e1033f86bc2e6e

SHA-256:
6f06a671754c53fcc520ee4b6a790e9177f4b4b659285c991802147290b4118c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/16/2024 9:26:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.myVBO.K
14.7.27.14

File size:
88.5 KB (90,640 bytes)

Product version:
3.02.000.0

Copyright:
Copyright (c) 2013 MyVBO LLC - All Rights Reserved

Original file name:
FpaUtility.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\ziftr alerts\fpautility.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/6/2013 3:00:00 AM

Valid to:
5/12/2015 2:59:59 AM

Subject:
CN=myVBO LLC, OU=FreePriceAlerts, O=myVBO LLC, L=Peterborough, S=New Hampshire, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6839CFCEA583E27C0222A8CEDE5E2DAF

File PE Metadata
Compilation timestamp:
7/11/2013 6:21:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:oZ/EJs+YIlx9T8AAAAAAAAAAAAAAAAAAAAAAAAAAAAh+aYbDDTzalPLDZQu6+CQS:oZ/Eb58AAAAAAAAAAAAAAAAAAAAAAAAa

Entry address:
0x1610E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.9392

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
80.5 KB (82,432 bytes)

Remove FpaUtility.dll - Powered by Reason Core Security