Joomiweb.FFUpdate.dll

Joomiweb

FFUpdate is the Mozilla Firefox plugin manager for the Joomiweb branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module Joomiweb.FFUpdate.dll by Joomiweb has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Joomiweb  (signed and verified)

Version:
1.0.5085.34864

MD5:
f18954c8ae5ff6bdbccefece8dd7e8a7

SHA-1:
3ad52c321d0bec5baf0684c1eabb40ee839c19da

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
4/26/2024 5:05:19 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo.Joomiweb (M)
16.1.9.16

File size:
394.8 KB (404,248 bytes)

Product version:
1.0.5085.34864

Original file name:
Joomiweb.FFUpdate.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\joomiweb\bin\plugins\joomiweb.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/6/2013 5:00:00 PM

Valid to:
10/7/2014 4:59:59 PM

Subject:
CN=Joomiweb, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Joomiweb, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
35DBC6CAD8D4C87516D7F0D05A8891EA

File PE Metadata
Compilation timestamp:
12/3/2013 11:22:18 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:Wiw0VgvFnsq3AkDT5nIlRqQ6cd37lbUke:WAoazE1ISQzdrlbUke

Entry address:
0x6292A

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8017

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
386.5 KB (395,776 bytes)

Remove Joomiweb.FFUpdate.dll - Powered by Reason Core Security