boxrock.ffupdate.dll

Purchase Time

FFUpdate is the Mozilla Firefox plugin manager for the Purchase Time branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module boxrock.ffupdate.dll by Purchase Time has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Purchase Time  (signed and verified)

Version:
1.0.5919.29378

MD5:
e0cebdf604ead1806a7483e264f66331

SHA-1:
cf7edfe0d5b545f8cbe7f9b63be3d5b3abf500e9

SHA-256:
5ba9e0671bc05ff47c3d59d2a2b6f90ff6b7431279b20ec863595bc369954a04

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
11/27/2024 3:38:32 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.3.16.9

File size:
561.7 KB (575,176 bytes)

Product version:
1.0.5919.29378

Original file name:
2016031700.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\box rock\bin\plugins\boxrock.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/2/2015 7:00:00 AM

Valid to:
9/2/2016 6:59:59 AM

Subject:
CN=Purchase Time, O=Purchase Time, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2C18DC2083776C69B87EDA69E9A50527

File PE Metadata
Compilation timestamp:
3/17/2016 7:19:20 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x8C49A

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5013

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
553.5 KB (566,784 bytes)

Remove boxrock.ffupdate.dll - Powered by Reason Core Security