batbrowse.ffupdate.dll

Venturium

FFUpdate is the Mozilla Firefox plugin manager for the Venturium branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module batbrowse.ffupdate.dll by Venturium has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Venturium  (signed and verified)

Version:
1.0.5996.42249

MD5:
5536ecba31e62df72c94e962d0aef020

SHA-1:
956a74837aed317cefd60f427c243c9faad233de

SHA-256:
662a96b04c649aea4b3511bc6de3ea59fb67299ed903e81455d99cf1cff6107e

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
1/1/2025 7:07:40 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.3.15.1

File size:
560.2 KB (573,632 bytes)

Product version:
1.0.5996.42249

Original file name:
2016060207.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\batbrowse\bin\plugins\batbrowse.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/22/2015 2:00:00 AM

Valid to:
10/22/2016 1:59:59 AM

Subject:
CN=Venturium, O=Venturium, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0B7073E5E548F366B68A9EB750109DC2

File PE Metadata
Compilation timestamp:
6/2/2016 9:28:24 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x8BF7E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
552 KB (565,248 bytes)

Remove batbrowse.ffupdate.dll - Powered by Reason Core Security