ptqtr.exe

Smart Inst

PLT

The application ptqtr.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from www.panningmanybanded.site.
Publisher:
PLT

Product:
Smart Inst

Description:
cmpnnt

Version:
74.226.127.143

MD5:
519d6c8d638d9a6e21a49704cf34ad9e

SHA-1:
6ed893caca87ec213196a3c3ec40082cbe7f4346

SHA-256:
964a27f0610a7ee3e9228b27edf7ef6fcecd412365b667a1e071bee68c0f8b88

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
5/12/2025 3:02:52 AM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Gen:Variant.Symmi.61223
11.5.0.6191

ESET NOD32
Win32/Amonetize.NY potentially unwanted application
8.0.319.0

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize
15.0.0.562

Norman
Gen:Variant.Razy.46251
02.04.2016 17:35:19

File size:
1.2 MB (1,305,088 bytes)

Product version:
74.226.127.143

Copyright:
Rights 2000

Trademarks:
Trd Mark

Original file name:
tinyinstall.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\ptqtr.exe

File PE Metadata
Compilation timestamp:
5/11/2016 4:37:25 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:Hs5Yert2vBM2WWf0kn8qclsX7rULbp87DSIFLR4uWcCip:HAwSfW8pqTgC7DSAV4uWcCi

Entry address:
0x679F

Entry point:
E8, 85, 51, 00, 00, E9, 39, FE, FF, FF, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 5F, 00, 00, 00, C7, 06, FC, 03, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 5F, 00, 00, 00, C7, 06, FC, 03, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, A0, 00, 00, 00, C7, 06, E4, 03, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 44, 00, 00, 00, C7, 06, E4, 03, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1...
 
[+]

Entropy:
6.8476

Code size:
116.5 KB (119,296 bytes)

The file ptqtr.exe has been seen being distributed by the following URL.

Remove ptqtr.exe - Powered by Reason Core Security