searchvortex.ffupdate.dll

Search Vortex

FFUpdate is the Mozilla Firefox plugin manager for the Search Vortex branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module searchvortex.ffupdate.dll by Search Vortex has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Search Vortex  (signed and verified)

Version:
1.0.5546.31043

MD5:
bde66e4673894efd638848ef9d6d97d9

SHA-1:
6dd6b456ccd03c41351000070603b77e50228596

SHA-256:
258231cb750dac78bdbe44324c2a5f1b046b9ecc242cfb5ca014a9f8d230fcd1

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
11/27/2024 2:50:51 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.3.14.8

File size:
588.2 KB (602,360 bytes)

Product version:
1.0.5546.31043

Original file name:
SearchVortex.FFUpdate2015031001.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\search vortex\bin\plugins\searchvortex.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/4/2015 10:00:00 PM

Valid to:
2/4/2016 9:59:59 PM

Subject:
CN=Search Vortex, O=Search Vortex, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6378D12A74B139F75511F7798DF77B19

File PE Metadata
Compilation timestamp:
3/9/2015 10:14:49 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

Entry address:
0x92ECE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
580 KB (593,920 bytes)

Remove searchvortex.ffupdate.dll - Powered by Reason Core Security