adanak.ffupdate.dll

Adanak

FFUpdate is the Mozilla Firefox plugin manager for the Adanak branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module adanak.ffupdate.dll by Adanak has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Adanak  (signed and verified)

Version:
1.0.5975.12074

MD5:
b6e60d1255af6fa2f0cfdceda072edd0

SHA-1:
83e93c6b49536db441d73cb9139a72013ef1652c

SHA-256:
afbf8e7c821f886541e02002ff4286c52947235fc5b68dc213c7f0fd59127222

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
11/23/2024 11:20:06 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.3.6.14

File size:
549.2 KB (562,408 bytes)

Product version:
1.0.5975.12074

Original file name:
2016051114.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\adanak\bin\plugins\adanak.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/23/2015 5:30:00 AM

Valid to:
6/22/2016 5:29:59 AM

Subject:
CN=Adanak, O=Adanak, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0C16ABA3C547AD068A6AA5F218316288

File PE Metadata
Compilation timestamp:
5/11/2016 8:12:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x89332

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.4861

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
541 KB (553,984 bytes)

Remove adanak.ffupdate.dll - Powered by Reason Core Security