myVBO LLC

Publisher Information

myVBO LLC is a brand of publishers/developers run by WebPick Internet Holdings Ltd. located in Ramat Ha'Chayal Tel Aviv, Israel. The company is a primary distributor of unwanted software. myVBO LLC is a developer of WebPick Internet Holdings and publishes a number of adware web browser plugins designed to monitor web browser behavior and inject advertisements (banner, popups, text-links, etc.) in the browser by using the WebPick InstalleRex monetization delivery platform. These programs from myVBO LLC are typiclaly installed on a variety of names and misspellings and are very difficult to remove. According to WebPick, they use developers to sign their adware in order to "throw off competitors". There is one additional code signing certificate issued to this publisher.
Authority:
Thawte, Inc.

Valid from:
5/10/2012 8:00:00 PM

Valid to:
5/11/2013 7:59:59 PM

Subject:
CN=myVBO LLC, OU=FreePriceAlerts, O=myVBO LLC, L=Peterborough, S=New Hampshire, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1d23e52c70371ebea800a8fdb3606cf4

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.BHO.myVBO.G, PUP.myVBO.G, PUP.myVBO.S, PUP.myVBO.K, PUP.Installer.myVBO.h, PUP.Installer.myVBO.M, Adware.WebPick.Installer.M, PUP.myVBO.AA, Adware.AdInjector.Installer, PUP.WebPick.myVBO.Installer (M), PUP.WebPick (M), Adware (M)
100.00%

Comodo Security
Application.Win32.InstalleRex.KG
15.00%

Vba32 AntiVirus
Downloader.AdLoad, Downware.TSU
15.00%

Rising Antivirus
PE:PUF.InstallRex!1.9E4C, PE:Trojan.Win32.Fednu.upv!1075354744
15.00%

McAfee
PUP-FHQ!292844A6BC64, Artemis!D094E320E472
10.00%

Total Defense
Win32/Tnega.aDQSBaD
10.00%

F-Prot
W32/AddInstall.A, W32/InstallRex.B
10.00%

AhnLab V3 Security
Adware/Win32.StartPage
10.00%

Bkav FE
HW32.CDB
5.00%

MicroWorld eScan
Trojan.Generic.10455437
5.00%

1 / 68      (Adware)
freepricealertssetup.exe (FreePriceAlerts by myVBO)  (e852a3e66dd7e1fc61b55d67954a6e30)

1 / 68      (Adware)
freepricealertssetup.exe (FreePriceAlerts by myVBO)  (5895d2013337cd1f8d415852e1909280)

1 / 68      (Adware)
fpainstaller.exe (FreePriceAlerts by myVBO)  (55da1be50955a29d029aaea9d049cafc)

1 / 68      (Adware)
fpainstaller.exe (FreePriceAlerts by myVBO)  (0b8a8feb986aac36065d5b89608089b1)

1 / 68      (Adware)

1 / 68      (Adware)
freepricealertssetup.exe (FreePriceAlerts by myVBO)  (fef07118c42a1ebfa0fe00b9d721083a)

6 / 68      (Adware)
fpainstaller.exe (FreePriceAlerts by myVBO)  (98660b3768c44d2631d0bdc335979ec0)

1 / 68      (Adware)
fpainstaller.exe (FreePriceAlerts by myVBO)  (d0f5cdc513f115ddcc58d0fdef5dcb6b)

1 / 68      (Adware)
backup-20140730-123529-868.dll (D by FreePriceAlerts.com)  (d156e3864c576835fbe156be5dce94fa)

1 / 68      (Adware)
vbobho.dll (D by FreePriceAlerts.com)  (e661cbc6016a605e48648a879ff8c4e8)

7 / 68      (Adware)
fpainstaller.exe (FreePriceAlerts by myVBO)  (d094e320e4726a6b5a1057f7ffe1ee51)

2 / 68      (Adware)
fpainstaller.exe (FreePriceAlerts by myVBO)  (ab5c0e8db49c94c7d53781df12c410fa)

31 / 68    (Adware)

1 / 68      (Adware)
vbobho.dll (D by FreePriceAlerts.com)  (962f54e06cf79aaaf8b0d2a2f5dc3143)

1 / 68      (Adware)
FpaUtility.dll (FpaUpdater by FreePriceAlerts.com)  (eac17916a80dc0fe830c092ba4e6529d)

1 / 68      (Adware)
FpaUpdater.exe (FpaUpdater by FreePriceAlerts.com)  (6c9cd7f501713489da12a81d6132c6a9)

1 / 68      (Adware)
vbobho.dll (D by FreePriceAlerts.com)  (8d2d2b3ede13f300b19a2ae42b904b01)

1 / 68      (Adware)
fpaupdaterlauncher.exe  (21b5c86cfd32ff81b0b1f6ddddc1e7eb)

1 / 68      (Adware)
vbobho.dll (D by FreePriceAlerts.com)  (286abc3a6f0c80d427e85f7f4df8e55d)

1 / 68      (Adware)
vbobho.dll (D by FreePriceAlerts.com)  (879808e628c505b958d801f36fc64d33)

The following certificate is also signed by myVBO LLC.

6839CFCEA583E27C0222A8CEDE5E2DAF  (May 06, 2013 to May 12, 2015)

* Note, the details and description above are based on the code signing digital signature issued to myVBO LLC by Thawte, Inc. on May 10, 2012 with the serial number '1d23e52c70371ebea800a8fdb3606cf4'.