webconnect.ffupdate.dll

Web Layers

FFUpdate is the Mozilla Firefox plugin manager for the Web Layers branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module webconnect.ffupdate.dll by Web Layers has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Web Layers  (signed and verified)

Version:
1.0.6074.42245

MD5:
eeca9ea6eaa9c24db3b6ffaba29902cc

SHA-1:
7f32366fec562b5854905aae40454851772463b0

SHA-256:
304a3f8c67700ff5751c923ec2c6bd13146da5c272aaaa43b2862bdb9293f23a

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
4/30/2024 11:53:45 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yontoo (M)
17.3.11.23

File size:
561.4 KB (574,888 bytes)

Product version:
1.0.6074.42245

Original file name:
2016081907.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\webconnect\bin\plugins\webconnect.ffupdate.dll

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
8/4/2015 3:00:00 AM

Valid to:
10/3/2016 2:59:59 AM

Subject:
CN=Web Layers, O=Web Layers, L=Santa Monica, S=California, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
2B5CEE8A350D1CE33516994DA29EC29D

File PE Metadata
Compilation timestamp:
8/19/2016 10:28:16 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x8C46E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
553.5 KB (566,784 bytes)

Remove webconnect.ffupdate.dll - Powered by Reason Core Security