Home Malware Programs Adware BobyZoom

BobyZoom

Posted: March 19, 2015

Threat Metric

Threat Level: 2/10
Infected PCs: 14,612
First Seen: March 16, 2015
Last Seen: November 21, 2023
OS(es) Affected: Windows

BobyZoom is promoted as a useful tool that enables users to zoom in on any picture while they browse the Internet. At first glance, BobyZoom may seem like a handy application. However, facts point to the other direction; BobyZoom is an adware-laced application that is seen as a monetization platform. Adware apps such as BobyZoom are capable of displaying several types of additional commercial advertisements that are tailored according to your preferences. BobyZoom is also known to collect search terms, clicked ads, visited web pages, IP address, browser type and OS version. Data collection by BobyZoom is for the purpose of developing and displaying 'content and advertising (such as targeted ads, display ads, pops, coupons, price comparison, in-line text and content recommendations) tailored to your interests on our websites and other websites'.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\bobyzoom\1.1.0.30\bzagnt.exe File name: bzagnt.exe
Size: 589.29 KB (589296 bytes)
MD5: 9227c19dfea3f20a5e5dae0f3ca8614a
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\bobyzoom\1.1.0.30
Group: Malware file
Last Updated: March 26, 2016
%ALLUSERSPROFILE%\bobyzoom\1.1.0.30\bzwdg.exe File name: bzwdg.exe
Size: 242.67 KB (242672 bytes)
MD5: 804d7ae5c657c4a9559ea5b49c1140c6
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\bobyzoom\1.1.0.30
Group: Malware file
Last Updated: March 26, 2016
%ALLUSERSPROFILE%\bobyzoom\1.1.0.30\bz32.exe File name: bz32.exe
Size: 220.16 KB (220160 bytes)
MD5: 81f218c798bef6d2bf0422518848d59f
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\bobyzoom\1.1.0.30
Group: Malware file
Last Updated: March 26, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\bobyzoomSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Tempo Runner bzdap.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Tempo Runner bzdap.job.fpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Tempo Runner bzdapSOFTWARE\Wow6432Node\bobyzoom_30

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\bobyzoom%USERPROFILE%\AppData\LocalLow\bobyzoom%appdata%\bobyzoom
Loading...