pfinst.exe

The application pfinst.exe has been detected as a potentially unwanted program by 17 anti-malware scanners.
MD5:
fabcec203b9a75a6f7f60c7380e43001

SHA-1:
a250c623bb2f21d3c77d2ed3df7254024310e031

SHA-256:
39a90febe2ccac64e0c27a18283fcb28baeddac210954f288b4837a9f1b00386

Scanner detections:
17 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 8:52:41 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Barys.9880
5570222

AhnLab V3 Security
PUP/Win32.DealPlay
2015.05.29

avast!
Adware-gen [Adw]
150525-2

AVG
Adware Generic6.ACDR
2014.0.4311

Baidu Antivirus
PUA.Win32.DealPly
4.0.3.15528

Bitdefender
Gen:Variant.Barys.9880
1.0.20.740

Dr.Web
Adware.DealPly.9
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Barys.9880
10.0.0.5366

ESET NOD32
Win32/DealPly.AC potentially unwanted application
7.0.302.0

F-Secure
Gen:Variant.Barys.9880
5.14.151

G Data
Gen:Variant.Barys.9880
15.5.25

IKARUS anti.virus
PUA.DealPly
t3scan.1.9.2.0

Kaspersky
not-a-virus:HEUR:AdWare.Win32.DealPly
14.0.0.1972

MicroWorld eScan
Gen:Variant.Barys.9880
16.0.0.444

NANO AntiVirus
Riskware.Win32.DealPly.dqbhhb
0.30.24.1636

Quick Heal
PUA.DealPly.01517
5.15.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
15.5.28.9

File size:
2 MB (2,098,173 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\pfinst.exe

File PE Metadata
Compilation timestamp:
3/26/2015 6:59:20 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:lxcVMrVQ7bLzjufxLKZ/KH5FqW9Yjk4wKm9YYYx:lxoMhQ7jZCZFHYjDwKQYYYx

Entry address:
0x93936

Entry point:
E8, 5C, 7B, 01, 00, E9, 35, FE, FF, FF, 55, 8B, EC, 8D, 45, 14, 50, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, 5C, B6, 4A, 00, E8, 60, 00, 00, 00, 83, C4, 14, 5D, C3, 55, 8B, EC, 8D, 45, 14, 50, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, 78, C7, 4A, 00, E8, 41, 00, 00, 00, 83, C4, 14, 5D, C3, 55, 8B, EC, 8D, 45, 10, 50, 6A, 00, FF, 75, 0C, FF, 75, 08, 68, 5C, B6, 4A, 00, E8, 23, 00, 00, 00, 83, C4, 14, 5D, C3, 55, 8B, EC, 8D, 45, 10, 50, 6A, 00, FF, 75, 0C, FF, 75, 08, 68, 78, C7, 4A, 00, E8, 05, 00, 00, 00, 83...
 
[+]

Code size:
815.5 KB (835,072 bytes)

Remove pfinst.exe - Powered by Reason Core Security