pfnfd_1_10_0_13.sys

Phrase Finder Driver x64

PHRASEFINDER

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The file pfnfd_1_10_0_13.sys by PHRASEFINDER has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a Windows 64-bit kernel mode device driver named “pfnfd_1_10_0_13”.
Publisher:
Phrase Finder  (signed by PHRASEFINDER)

Product:
Phrase Finder Driver x64

Version:
1.10.0.13

MD5:
d8284b6220526c6611d2c50542c19546

SHA-1:
03109e16260de9b9250b5091c0ae33e8221a6dc8

SHA-256:
fb692ff50ca590fbf10bc10a80bca4b61ea7be5aa2689943abed4824d40d7f5e

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 1:02:09 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InfoAtoms (M)
16.11.22.7

File size:
56.9 KB (58,232 bytes)

Product version:
1.10.0.13

Copyright:
Copyright (C) 2015

Original file name:
pfnfd.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\pfnfd_1_10_0_13.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/4/2014 5:45:11 PM

Valid to:
9/4/2016 3:20:25 PM

Subject:
E=support@phrasefinderapp.com, CN=PHRASEFINDER, O=PHRASEFINDER, L=Dover, S=DE, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112137C4F7456ECE3D7C3EA998E1558D1585

File PE Metadata
Compilation timestamp:
8/21/2012 7:34:56 PM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
1536:jiBIL6sCyo5oIUo0I77nPaXq4Fs+hMeGlDOtcRnUJ:2C6sCysD7L+Fs+hYOtcRnUJ

Entry address:
0x10008

Entry point:
48, 8B, 05, F1, D0, FF, FF, 49, B9, 32, A2, DF, 2D, 99, 2B, 00, 00, 48, 85, C0, 74, 05, 49, 3B, C1, 75, 2F, 4C, 8D, 05, D6, D0, FF, FF, 48, B8, 20, 03, 00, 00, 80, F7, FF, FF, 48, 8B, 00, 49, 33, C0, 49, B8, FF, FF, FF, FF, FF, FF, 00, 00, 49, 23, C0, 49, 0F, 44, C1, 48, 89, 05, AE, D0, FF, FF, 48, F7, D0, 48, 89, 05, AC, D0, FF, FF, E9, DB, B0, FF, FF, CC, CC, CC, B0, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, B4, 04, 01, 00, 10, C0, 00, 00, A0, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, D6, 04, 01, 00...
 
[+]

Code size:
44 KB (45,056 bytes)

Driver
Display name:
pfnfd_1_10_0_13

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI


Remove pfnfd_1_10_0_13.sys - Powered by Reason Core Security