SearchVortex.FFUpdate.dll

Search Vortex

FFUpdate is the Mozilla Firefox plugin manager for the Search Vortex branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module SearchVortex.FFUpdate.dll by Search Vortex has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Search Vortex  (signed and verified)

Version:
1.0.5420.19465

MD5:
7097ee3d16a979123ac8718496da8b8e

SHA-1:
fe2ecab375c48cf1f5d44eb5afcd13d40cc1881b

SHA-256:
5bdf33ece0433f49329d7a4397b8c1d6376e735e76ef83d31c4887708f1d6bd7

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
5/23/2024 12:31:11 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.3.13.22

File size:
546.2 KB (559,352 bytes)

Product version:
1.0.5420.19465

Original file name:
SearchVortex.FFUpdate.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\search vortex\bin\plugins\searchvortex.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/2/2014 9:00:00 PM

Valid to:
1/12/2015 9:59:59 PM

Subject:
CN=Search Vortex, O=Search Vortex, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
71476B8D983F107DED3C6D8A73EF8C77

File PE Metadata
Compilation timestamp:
11/3/2014 4:48:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

Entry address:
0x8861E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 71, 00, 00, 00, 60, 86, 08, 00, 60, 68, 08, 00, 52, 53, 44, 53, CC, D1, 0A, EF, A6, CB, 29, 49, 85, 16, 7E, F2, 2B, F4, 33, 9E, 01, 00, 00, 00, 44, 3A, 5C, 55, 74, 69, 6C, 69, 74, 69, 65, 73, 5C, 68, 6D, 79, 78, 6D, 33, 7A, 76, 2E, 35, 63, 6A, 5C, 44, 65, 73, 6B, 74, 6F, 70, 5C, 44, 65, 73, 6B...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
538 KB (550,912 bytes)

Remove SearchVortex.FFUpdate.dll - Powered by Reason Core Security