productdeals.ffupdate.dll

Product Deals

FFUpdate is the Mozilla Firefox plugin manager for the Product Deals branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module productdeals.ffupdate.dll by Product Deals has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Product Deals  (signed and verified)

Version:
1.0.5708.22951

MD5:
76537ec2d37d722e50c2f93e3e326f71

SHA-1:
9f6ca13b87fa2d1daa8bbdc8802f5534c9b18527

SHA-256:
8423b199f7578de096937b09031d2141bb284cfec6c99dac0d085a2af9b9e3ca

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
12/25/2024 12:04:55 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yontoo (M)
17.3.12.15

File size:
518.7 KB (531,192 bytes)

Product version:
1.0.5708.22951

Original file name:
2015081820.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\product deals\bin\plugins\productdeals.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/9/2015 9:00:00 PM

Valid to:
3/9/2016 8:59:59 PM

Subject:
CN=Product Deals, O=Product Deals, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
08DB250BF6350B54DDDEF1061C8BCE6D

File PE Metadata
Compilation timestamp:
8/18/2015 5:45:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x818EE

Entry point:
FF, 25, 00, 20, 00, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
510.5 KB (522,752 bytes)

Remove productdeals.ffupdate.dll - Powered by Reason Core Security