pinetree.ffupdate.dll

Pine Tree

FFUpdate is the Mozilla Firefox plugin manager for the Pine Tree branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module pinetree.ffupdate.dll by Pine Tree has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Pine Tree  (signed and verified)

Version:
1.0.5788.35705

MD5:
e4cc752c706c579a4049e9e2819cb8c8

SHA-1:
f439b1178e82be0c00f7ed9da0fcf2cdb5f22563

SHA-256:
7b89818a72ec43a3f8fe74a59e8639dd730b89796705dc8950311a988e6394de

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
5/16/2024 5:16:15 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.3.16.3

File size:
557.2 KB (570,608 bytes)

Product version:
1.0.5788.35705

Original file name:
2015110703.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\pine tree\bin\plugins\pinetree.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/11/2015 9:00:00 AM

Valid to:
1/12/2016 8:59:59 AM

Subject:
CN=Pine Tree, O=Pine Tree, L=Sna Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7474B1E151ED589FE9418816EE9BA66C

File PE Metadata
Compilation timestamp:
11/7/2015 12:50:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x8B2B6

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5099

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
549 KB (562,176 bytes)

Remove pinetree.ffupdate.dll - Powered by Reason Core Security