Laflurla.FirstRun.exe

FirstRun

Laflurla

The Yontoo branded FirstRun executable is distributed as part of a Yontoo product bundle and is desigend to install components of this ad-supported (injection) program as well as 'call home' to inform the server that the extension was installed and may request additional instructions. The application Laflurla.FirstRun.exe by Laflurla has been detected as adware by 20 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Laflurla  (signed and verified)

Product:
FirstRun

Version:
1.0.0.0

MD5:
4a8edb7566ae00d03314ca549c91d1b8

SHA-1:
1fb465412dbd3a84ff5b130e74ed67f43f9db76c

SHA-256:
0fa19497e70ea80e48c780397530342d0aa81d93d58c3288b7909a128c0c691c

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Part of the Yontoo ad injection web browser add-on.

Analysis date:
4/19/2024 3:55:54 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.BM
363

AhnLab V3 Security
Win-PUP/BrowseFox.Gen
2015.02.28

Avira AntiVirus
ADWARE/BrowseFox.Gen
7.11.212.228

AVG
Generic
2017.0.2841

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.1627

Bitdefender
Adware.BrowseFox.BM
1.0.20.190

Emsisoft Anti-Malware
Adware.BrowseFox.BM
8.16.02.07.10

ESET NOD32
MSIL/BrowseFox.D potentially unwanted application
10.7.0.302.0

F-Prot
W32/S-c5a74904
v6.4.7.1.166

F-Secure
Adware.BrowseFox.BM
11.2016-07-02_1

G Data
Adware.BrowseFox.BM
16.2.25

K7 AntiVirus
Adware
13.1915113

Kaspersky
not-a-virus:HEUR:AdWare.MSIL.Kranet
14.0.0.698

Malwarebytes
v2016.02.07.10

McAfee
Program.BrowseFox.a
5600.6497

MicroWorld eScan
Adware.BrowseFox.BM
17.0.0.114

NANO AntiVirus
Riskware.Win32.BPlug.djpkri
0.30.0.296

nProtect
Adware.BrowseFox.BM
15.02.27.01

Reason Heuristics
Adware.Yontoo.Laflurla (M)
16.2.7.10

VIPRE Antivirus
Yontoo
29314

File size:
1.1 MB (1,122,592 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
Laflurla.FirstRun.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\laflurla\laflurla.firstrun.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/3/2014 7:00:00 PM

Valid to:
2/4/2015 6:59:59 PM

Subject:
CN=Laflurla, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Laflurla, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0541E25DBE69A2BC84C39AB35093A301

File PE Metadata
Compilation timestamp:
4/19/2014 8:44:09 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:XxcUGSKn8VcTDf/Mv0m2Eu5XRQxR4UePqiv0dnwV+:XxZGvn8nvLPsRQxSyivYx

Entry address:
0x111C6A

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9248

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.1 MB (1,113,600 bytes)

Remove Laflurla.FirstRun.exe - Powered by Reason Core Security