sfx.exe

7-Zip

Igor Pavlov

The application sfx.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. The program is a setup application that uses the 7z Setup installer, however the file is not signed with an authenticode signature from a trusted source. This file is typically installed with the program PriceFountain (remove only) by DealPly Technologies Ltd. which is a potentially unwanted software program.
Publisher:
Igor Pavlov

Product:
7-Zip

Description:
7z Console SFX

Version:
9.20

MD5:
ff5829edf44df4826c83d5b4d72dc5c6

SHA-1:
eef4f5117dfda70a0769db69f8bd422d4ea73d64

SHA-256:
65cfd874a435a12188c19212e2fdb1c2c1b2bae641ce10681c758eee1189de81

Scanner detections:
10 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 3:05:43 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/DealPly.Q.7
7.11.180.174

avast!
Win32:Malware-gen
2014.9-141024

Baidu Antivirus
Adware.Win32.DealPly
4.0.3.141024

Dr.Web
Trojan.DownLoader11.37503
9.0.1.0297

ESET NOD32
Win32/DealPly (variant)
8.10605

Fortinet FortiGate
Adware/DealPly
10/24/2014

F-Prot
W32/A-3442f84d
v6.4.7.1.166

Kaspersky
not-a-virus:AdWare.Win32.DealPly
14.0.0.3055

McAfee
Artemis!FF5829EDF44D
5600.6968

Sophos
Generic PUA PO
4.98

File size:
829.9 KB (849,795 bytes)

Product version:
9.20

Copyright:
Copyright (c) 1999-2010 Igor Pavlov

Original file name:
7z.sfx.exe

File type:
Executable application (Win32 EXE)

Installer:
7z Setup

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\pricefountain\sfx.exe

File PE Metadata
Compilation timestamp:
11/18/2010 11:27:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

CTPH (ssdeep):
24576:3Xi6kgaINVplsrmDU514YHabdO4Uldiq2CDWJ:3XiTcN3lY8lxOrDqCDWJ

Entry address:
0x1C1F2

Entry point:
55, 8B, EC, 6A, FF, 68, E0, FE, 41, 00, 68, EC, C1, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 20, 53, 56, 57, 89, 65, E8, 83, 65, FC, 00, 6A, 01, FF, 15, E4, F0, 41, 00, 59, 83, 0D, 30, A7, 42, 00, FF, 83, 0D, 34, A7, 42, 00, FF, FF, 15, E8, F0, 41, 00, 8B, 0D, 08, 87, 42, 00, 89, 08, FF, 15, EC, F0, 41, 00, 8B, 0D, 04, 87, 42, 00, 89, 08, A1, F0, F0, 41, 00, 8B, 00, A3, 2C, A7, 42, 00, E8, D5, 00, 00, 00, 83, 3D, A0, 63, 42, 00, 00, 75, 0C, 68, 32, C3, 41, 00, FF, 15, F4, F0...
 
[+]

Entropy:
7.8912

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
119 KB (121,856 bytes)

The file sfx.exe has been discovered within the following program.

PriceFountain (remove only)  by DealPly Technologies Ltd.
Price Fountain (SaveSense) is an adware extension that will deliver ads to the browser on web pages that are not affiliated with the ads or the extension.
www.pricefountain.com
76% remove it
 
Powered by Should I Remove It?

Remove sfx.exe - Powered by Reason Core Security