vbobho.dll

Ziftr Alerts - formerly FreePriceAlerts.com

myVBO LLC

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The module vbobho.dll by myVBO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Ziftr Alerts - formerly FreePriceAlerts.com’.
Publisher:
myVBO LLC  (signed and verified)

Product:
Ziftr Alerts - formerly FreePriceAlerts.com

Version:
3.1.0.0

MD5:
9822aef31641766d23ce6f976b953a23

SHA-1:
e7ad33e1feacc819ebbbe82254e44c2aa5c8eb80

SHA-256:
122caf6446a03c6ec4a20b8f334690737c7efc69af2fde6966df38aced9e6bf2

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 11:34:37 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick (M)
17.3.13.15

File size:
603.5 KB (618,000 bytes)

Product version:
3.1.0.0

Copyright:
MyVBO LLC

Original file name:
vbobho.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\ziftr alerts\vbobho.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/5/2013 8:00:00 PM

Valid to:
5/11/2015 7:59:59 PM

Subject:
CN=myVBO LLC, OU=FreePriceAlerts, O=myVBO LLC, L=Peterborough, S=New Hampshire, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6839CFCEA583E27C0222A8CEDE5E2DAF

Registration
CLSIDs:
{35186E3E-7E28-41A3-B258-94A66234C1ED}, {A7C0A55C-300E-4193-8FB5-5DB8E6533D35}, {C671912C-1650-4D5E-B5B8-E3E886754078}

ProgIDs:
vbobho.PopupEventHandler.1, FreePriceAlerts.Band.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
5/16/2013 1:42:14 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x5C5AF

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 77, 03, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, 68, 44, BF, 05, 10, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 0C, 08, 08, 10, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, CC, CC...
 
[+]

Entropy:
7.0547

Code size:
407.5 KB (417,280 bytes)

Internet Explorer BHO
CLSID:
{A7C0A55C-300E-4193-8FB5-5DB8E6533D35}

CLSID name:
Ziftr Alerts - formerly FreePriceAlerts.com


Remove vbobho.dll - Powered by Reason Core Security