SearchVortex.FFUpdate.dll

Search Vortex

FFUpdate is the Mozilla Firefox plugin manager for the Search Vortex branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module SearchVortex.FFUpdate.dll by Search Vortex has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Search Vortex  (signed and verified)

Version:
1.0.5380.36016

MD5:
96c7d4964b111ccf7898b776b27179e4

SHA-1:
df031504ab9380829fc67cb0fc3274557143ff26

SHA-256:
2337652f568315e947522e049a8f8eda7e6629af2b7f25f042b818733f45a320

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
11/27/2024 3:50:58 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.2.24.22

File size:
450.8 KB (461,608 bytes)

Product version:
1.0.5380.36016

Original file name:
SearchVortex.FFUpdate.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\search vortex\bin\plugins\searchvortex.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/11/2014 10:00:00 PM

Valid to:
1/12/2015 9:59:59 PM

Subject:
CN=Search Vortex, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Search Vortex, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
14D448982B01DF7BA0C15573F03A229C

File PE Metadata
Compilation timestamp:
9/24/2014 6:00:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0x70996

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 10, 00, 00, 00, 18, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
442.5 KB (453,120 bytes)

Remove SearchVortex.FFUpdate.dll - Powered by Reason Core Security