ViewPlay.FFUpdate.dll

ViewPlay

FFUpdate is the Mozilla Firefox plugin manager for the ViewPlay branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module ViewPlay.FFUpdate.dll by ViewPlay has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
ViewPlay  (signed and verified)

Version:
1.0.5427.31625

MD5:
d49770b23811be013d0e987ce92ee292

SHA-1:
59a511dc0637fe0b59f1c37708180786c25956dc

SHA-256:
4787e2bae13ba0950a3f331f866f76ee7bb5092727ba9d90fecf4ee44a3b1131

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
4/29/2024 7:11:47 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.3.8.11

File size:
546.2 KB (559,336 bytes)

Product version:
1.0.5427.31625

Original file name:
ViewPlay.FFUpdate.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\viewplay\bin\plugins\viewplay.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/3/2014 4:00:00 PM

Valid to:
1/3/2016 3:59:59 PM

Subject:
CN=ViewPlay, O=ViewPlay, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
22FA04D7BCBAB5B547C2A93BFC95F6C3

File PE Metadata
Compilation timestamp:
11/10/2014 5:34:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

Entry address:
0x88636

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 6D, 00, 00, 00, 78, 86, 08, 00, 78, 68, 08, 00, 52, 53, 44, 53, E3, 12, 2E, AD, E9, 39, CD, 42, 89, F5, B9, 82, 81, 69, 04, AA, 01, 00, 00, 00, 44, 3A, 5C, 55, 74, 69, 6C, 69, 74, 69, 65, 73, 5C, 34, 71, 79, 62, 71, 7A, 6E, 6E, 2E, 73, 6F, 68, 5C, 44, 65, 73, 6B, 74, 6F, 70, 5C, 44, 65, 73, 6B...
 
[+]

Entropy:
7.4990

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
538 KB (550,912 bytes)

Remove ViewPlay.FFUpdate.dll - Powered by Reason Core Security