Rolimno.FFUpdate.dll

Rolimno

FFUpdate is the Mozilla Firefox plugin manager for the Rolimno branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module Rolimno.FFUpdate.dll by Rolimno has been detected as adware by 2 anti-malware scanners.
Publisher:
Rolimno  (signed and verified)

Version:
1.0.5144.37231

MD5:
a54144823ce0428e2e7b5d1fea063ae6

SHA-1:
dc10be238c6bb1c7221f1d9a4647e16d0fce6d58

SHA-256:
3cb9aa2bd0c09929a04b53d2732c29b42cadcc0b54af0436c9a66606d241b7c6

Scanner detections:
2 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
4/25/2024 10:01:31 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.BPlug.16
9.0.1.0204

Reason Heuristics
Adware.Yontoo.Rolimno.P
14.8.8.0

File size:
447.8 KB (458,520 bytes)

Product version:
1.0.5144.37231

Original file name:
Rolimno.FFUpdate.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\rolimno\bin\plugins\rolimno.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/12/2013 7:00:00 PM

Valid to:
8/13/2015 6:59:59 PM

Subject:
CN=Rolimno, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Rolimno, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0D2645238961D2084208FC4B5B89E7FD

File PE Metadata
Compilation timestamp:
1/31/2014 2:41:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:Q2SquyU+jlkFC9BY5tCYjus2U6WwvWRqwRHnPB:Q2SpYLmQYj7Mf+Rqup

Entry address:
0x6FCCA

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6793

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
439.5 KB (450,048 bytes)

Remove Rolimno.FFUpdate.dll - Powered by Reason Core Security