vbobho.dll

Ziftr Alerts - formerly FreePriceAlerts.com

myVBO LLC

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The module vbobho.dll by myVBO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Ziftr Alerts - formerly FreePriceAlerts.com’.
Publisher:
myVBO LLC  (signed and verified)

Product:
Ziftr Alerts - formerly FreePriceAlerts.com

Version:
3.2.0.0

MD5:
17360784f9ad58d1e47572db463889fd

SHA-1:
01339a6d0544b97bdb8f69ce1f9acdde0931bd09

SHA-256:
6363479c8723b5a3c02514ea8479a3a8fb9ab4deea5568dfae311d404c88dfc5

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/23/2024 11:05:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BHO.myVBO.G
14.7.27.14

File size:
612 KB (626,704 bytes)

Product version:
3.2.0.0

Copyright:
MyVBO LLC

Original file name:
vbobho.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\ziftr alerts\vbobho.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/6/2013 3:00:00 AM

Valid to:
5/12/2015 2:59:59 AM

Subject:
CN=myVBO LLC, OU=FreePriceAlerts, O=myVBO LLC, L=Peterborough, S=New Hampshire, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6839CFCEA583E27C0222A8CEDE5E2DAF

Registration
CLSIDs:
{35186E3E-7E28-41A3-B258-94A66234C1ED}, {A7C0A55C-300E-4193-8FB5-5DB8E6533D35}, {C671912C-1650-4D5E-B5B8-E3E886754078}

ProgIDs:
vbobho.PopupEventHandler.1, FreePriceAlerts.Band.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
7/11/2013 6:11:30 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:043sS2YUahki4tK/TlJcrK2nL3hSkCTBRGhkmP9cduKy8I1Q68k7/nByi/6w:0+sS2YUa+i4krlJ0Ke31zP0y8I1gy/nl

Entry address:
0x5DF7F

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 77, 03, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, 68, 14, D9, 05, 10, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, C4, 38, 08, 10, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, CC, CC...
 
[+]

Entropy:
6.3245

Code size:
414.5 KB (424,448 bytes)

Internet Explorer BHO
CLSID:
{A7C0A55C-300E-4193-8FB5-5DB8E6533D35}

CLSID name:
Ziftr Alerts - formerly FreePriceAlerts.com


Remove vbobho.dll - Powered by Reason Core Security