webconnect.ffupdate.dll

Web Layers

FFUpdate is the Mozilla Firefox plugin manager for the Web Layers branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module webconnect.ffupdate.dll by Web Layers has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Web Layers  (signed and verified)

Version:
1.0.6094.31621

MD5:
7d867b15d50bf17619520385e8a45349

SHA-1:
af2bd8e139a1c13a48a0d28635ed86e2ac9d3d49

SHA-256:
7edf7f11d0172d1706f7be38b1c58ffcfee7e873fd2c238daa1657131794921c

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
5/1/2024 2:20:56 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yontoo (M)
17.3.11.16

File size:
549.4 KB (562,600 bytes)

Product version:
1.0.6094.31621

Original file name:
2016090801.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\webconnect\bin\plugins\webconnect.ffupdate.dll

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
8/4/2015 5:30:00 AM

Valid to:
10/3/2016 5:29:59 AM

Subject:
CN=Web Layers, O=Web Layers, L=Santa Monica, S=California, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
2B5CEE8A350D1CE33516994DA29EC29D

File PE Metadata
Compilation timestamp:
9/8/2016 7:04:08 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x8945A

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.4863

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
541.5 KB (554,496 bytes)

Remove webconnect.ffupdate.dll - Powered by Reason Core Security