linkidoo.ffupdate.dll

LinkiDoo

FFUpdate is the Mozilla Firefox plugin manager for the LinkiDoo branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module linkidoo.ffupdate.dll by LinkiDoo has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
LinkiDoo  (signed and verified)

Version:
1.0.5468.42176

MD5:
c72c1f203ea08f555329d95a8f1d2d82

SHA-1:
dd6d9b3df1738ea0d49be1ce381ff14b32cfc197

SHA-256:
1ac187e54e163d3e699570438fddf4a282428f71361d9618ec4d48c4f00aef9f

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
12/23/2024 10:38:24 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.2.14.4

File size:
546.7 KB (559,856 bytes)

Product version:
1.0.5468.42176

Original file name:
LinkiDoo.FFUpdate2014122207.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\linkidoo\bin\plugins\linkidoo.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/5/2014 12:00:00 AM

Valid to:
12/5/2015 11:59:59 PM

Subject:
CN=LinkiDoo, O=LinkiDoo, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3EDD1381EA3A264E875F2CD9FAE7AFDD

File PE Metadata
Compilation timestamp:
12/22/2014 7:25:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

Entry address:
0x8891E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.4992

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
538.5 KB (551,424 bytes)

Remove linkidoo.ffupdate.dll - Powered by Reason Core Security