vbobho.dll

Ziftr Alerts - formerly FreePriceAlerts.com

myVBO LLC

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The module vbobho.dll by myVBO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
myVBO LLC  (signed and verified)

Product:
Ziftr Alerts - formerly FreePriceAlerts.com

Version:
3.1.0.0

MD5:
1025d45e2d759b4125cdb896cd87c3bd

SHA-1:
33c529b9f450fc7dae1e0c7674a9c5d4e44097be

SHA-256:
ca9e243f262668681b66cba27800cb57b30021c635c814704a47c91a1d3d1a00

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 12:45:15 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.myVBO.G
14.7.27.14

File size:
819 KB (838,672 bytes)

Product version:
3.1.0.0

Copyright:
MyVBO LLC

Original file name:
vbobho.dll

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\Program Files\ziftr alerts\win64\vbobho.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/6/2013 2:00:00 AM

Valid to:
5/12/2015 1:59:59 AM

Subject:
CN=myVBO LLC, OU=FreePriceAlerts, O=myVBO LLC, L=Peterborough, S=New Hampshire, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6839CFCEA583E27C0222A8CEDE5E2DAF

File PE Metadata
Compilation timestamp:
5/16/2013 7:58:49 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:Y+k0jQwln1Q4ioQHEZOA1Aijty2JvNsMymwyaiJREmQEawCK8CMf6QzeMtBs:Y+ksIG+2JvWRyaiJRAZS+Ps

Entry address:
0x6FA3C

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, DF, 02, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, 8B, FE, FF, FF, CC, CC, CC, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, 48, 8D, 0D, 91, E7, 04, 00, FF, 15, 2B, 76, 01, 00, 4C, 8B, 1D, 7C, E8, 04, 00, 4C, 89, 5C, 24, 58, 45, 33, C0, 48, 8D, 54, 24, 60, 48, 8B, 4C, 24, 58, E8, 55, 03, 00, 00, 48, 89, 44, 24, 50, 48, 83, 7C, 24...
 
[+]

Entropy:
6.0768

Code size:
530 KB (542,720 bytes)

Remove vbobho.dll - Powered by Reason Core Security