vbobho.dll

Ziftr Alerts - formerly FreePriceAlerts.com

myVBO LLC

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The module vbobho.dll by myVBO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Ziftr Alerts - formerly FreePriceAlerts.com’. This file is typically installed with the program Ziftr Alerts - formerly FreePriceAlerts.com 3.1.0 by myVBO LLC which is a potentially unwanted software program.
Publisher:
myVBO LLC  (signed and verified)

Product:
Ziftr Alerts - formerly FreePriceAlerts.com

Version:
3.1.0.0

MD5:
4f3ad88c171fdd52e42840a69f071327

SHA-1:
1d34a5470c62bee4538dea5d005c47bd617d8ca4

SHA-256:
d95e37a458cc5bc1fd80d3ab9a2e01f8bba789235dc1c61330384dff88c1a245

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/19/2024 8:44:24 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BHO.myVBO.G
14.7.27.14

File size:
603.5 KB (618,000 bytes)

Product version:
3.1.0.0

Copyright:
MyVBO LLC

Original file name:
vbobho.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\ziftr alerts\vbobho.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/6/2013 2:00:00 AM

Valid to:
5/12/2015 1:59:59 AM

Subject:
CN=myVBO LLC, OU=FreePriceAlerts, O=myVBO LLC, L=Peterborough, S=New Hampshire, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6839CFCEA583E27C0222A8CEDE5E2DAF

Registration
CLSIDs:
{35186E3E-7E28-41A3-B258-94A66234C1ED}, {A7C0A55C-300E-4193-8FB5-5DB8E6533D35}, {C671912C-1650-4D5E-B5B8-E3E886754078}

ProgIDs:
vbobho.PopupEventHandler.1, FreePriceAlerts.Band.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
5/16/2013 7:42:14 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:PBaxqPVw/fNkfG3dIaTmGgVi7FxOyCxxpvNY6Wn/Ih368moDzX3DUDKOzS7L4Rhh:1PVweu2d33vDUe/7LAyY

Entry address:
0x5C5AF

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 77, 03, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, 68, 44, BF, 05, 10, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 0C, 08, 08, 10, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, CC, CC...
 
[+]

Entropy:
6.3103

Code size:
407.5 KB (417,280 bytes)

Internet Explorer BHO
CLSID:
{A7C0A55C-300E-4193-8FB5-5DB8E6533D35}

CLSID name:
Ziftr Alerts - formerly FreePriceAlerts.com


The file vbobho.dll has been discovered within the following program.

This toolbar/web browser extension is ad/search-supported that is typically installed as an optional offer, users generally have this bundled with 3rd party software.
www.Ziftr.com
75% remove it
 
Powered by Should I Remove It?

Remove vbobho.dll - Powered by Reason Core Security