Jotzey.FFUpdate.dll

Jotzey

FFUpdate is the Mozilla Firefox plugin manager for the Jotzey branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module Jotzey.FFUpdate.dll by Jotzey has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Jotzey  (signed and verified)

Version:
1.0.5182.28943

MD5:
0228fd0bc2358daf6a24c520071318dc

SHA-1:
796e8b597f3c9e060f9e666341845dd9a16a613b

SHA-256:
615313a706ad380551ca7aa357b2b4bde4e7ed05039bed8242ac1775cee04915

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
4/25/2024 10:17:37 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Jotzey.O
14.3.15.3

File size:
448.8 KB (459,544 bytes)

Product version:
1.0.5182.28943

Original file name:
Jotzey.FFUpdate.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\jotzey\bin\plugins\jotzey.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/11/2014 4:00:00 PM

Valid to:
1/12/2015 3:59:59 PM

Subject:
CN=Jotzey, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Jotzey, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4C7B335D1F24250859B4B5C0085A062C

File PE Metadata
Compilation timestamp:
3/10/2014 10:05:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:igwCwCC+md+IXaII1ypsk4GskCfeRtTm5RY66XZf:igw0PePXMypsBkCmRg5RbCf

Entry address:
0x70116

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6743

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
440.5 KB (451,072 bytes)

Remove Jotzey.FFUpdate.dll - Powered by Reason Core Security