DolphinDeals.FirstRun.exe

FirstRun

Dolphin Deals

The Yontoo branded FirstRun executable is distributed as part of a Yontoo product bundle and is desigend to install components of this ad-supported (injection) program as well as 'call home' to inform the server that the extension was installed and may request additional instructions. The application DolphinDeals.FirstRun.exe by Dolphin Deals has been detected as adware by 22 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Dolphin Deals  (signed and verified)

Product:
FirstRun

Version:
1.0.0.0

MD5:
2804c757c27eb69600820ecf040b9219

SHA-1:
92adf4ab0827a9bb72969a985a4ab2944c0f19f9

SHA-256:
66427dfb5d293e32c45a9f8b43789655f322b60f97dfa7acc599aee423e92edc

Scanner detections:
22 / 68

Status:
Adware

Explanation:
Part of the Yontoo ad injection web browser add-on.

Analysis date:
4/19/2024 10:43:17 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.SwiftBrowse.CO
6475091

AhnLab V3 Security
Win-PUP/BrowseFox.Gen
2015.01.29

Avira AntiVirus
ADWARE/BrowseFox.Gen
7.11.173.134

AVG
Generic
2016.0.3215

Baidu Antivirus
Adware.MSIL.BrowseFox
4.0.3.15128

Bitdefender
Adware.SwiftBrowse.CO
1.0.20.140

Comodo Security
Application.Win32.BrowseFox.JL
19574

Dr.Web
Trojan.BPlug.183
9.0.1.028

Emsisoft Anti-Malware
Adware.SwiftBrowse.CO
9.0.0.4799

ESET NOD32
MSIL/BrowseFox.L potentially unwanted application
7.0.302.0

F-Secure
Adware.SwiftBrowse.CO
5.13.68

G Data
Adware.SwiftBrowse.CO
15.1.24

IKARUS anti.virus
AdWare.MPlug
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.185.14120

Kaspersky
not-a-virus:HEUR:AdWare.MSIL.Kranet
14.0.0.2572

Malwarebytes
v2015.01.28.12

McAfee
BrowseFox
5600.6871

MicroWorld eScan
Adware.SwiftBrowse.CO
16.0.0.84

Norman
Adware.SwiftBrowse.CO
03.12.2014 13:20:04

nProtect
Adware.SwiftBrowse.CO
14.11.14.01

Reason Heuristics
Adware.Yontoo.DolphinDeals
15.1.28.12

VIPRE Antivirus
Yontoo
33304

File size:
1.5 MB (1,596,712 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
DolphinDeals.FirstRun.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\dolphin deals\dolphindeals.firstrun.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/29/2014 4:30:00 AM

Valid to:
4/30/2015 4:29:59 AM

Subject:
CN=Dolphin Deals, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Dolphin Deals, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7B2BB0FC5A785F21B05232FFFBC2969A

File PE Metadata
Compilation timestamp:
11/1/2014 5:07:26 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:JXZa4lXAngkUJClDUDt2JS6duzoK5CZ8uZ79e:JXZLw/UWUDB6UkK5Ot9e

Entry address:
0x1858F2

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 69, 00, 00, 00, 34, 59, 18, 00, 34, 3B, 18, 00, 52, 53, 44, 53, D8, 7F, 84, 83, 70, 40, 2E, 4C, 8E, 31, 36, 25, 39, AD, B7, 49, 01, 00, 00, 00, 44, 3A, 5C, 55, 74, 69, 6C, 69, 74, 69, 65, 73, 5C, 6E, 78, 76, 78, 69, 64, 76, 77, 2E, 75, 30, 31, 5C, 44, 65, 73, 6B, 74, 6F, 70, 5C, 46, 69, 72, 73...
 
[+]

Entropy:
7.8391

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.5 MB (1,587,712 bytes)

Remove DolphinDeals.FirstRun.exe - Powered by Reason Core Security