PUA

PUP.Optional.PriceFountain removal instruction

Malware Removal

The PUP.Optional.PriceFountain is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.PriceFountain virus can do?

  • Unconventionial language used in binary resources: Hebrew
  • Authenticode signature is invalid
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system

How to determine PUP.Optional.PriceFountain?


File Info:

name: EF23504BA2BFE5C41B83.mlw
path: /opt/CAPEv2/storage/binaries/b054187f233d684d7a2793a3091f3d42c0b5e776603f5558a4c9e5300d58241f
crc32: E4D7BF8A
md5: ef23504ba2bfe5c41b835d1a293672d1
sha1: 76c47fbe6e8f8ee3e19a118f755d44232749a783
sha256: b054187f233d684d7a2793a3091f3d42c0b5e776603f5558a4c9e5300d58241f
sha512: 9eeb4257356e83241ed2ab34b06372f4b17a66a01f3d59deb7cfb0e3aca32062e24a8ad2417f3f3a28ba90b28ae0e1fe37f0384e526b7e33605ba0f92ec0fb26
ssdeep: 6144:h1+QfoBzcfPdGXskqpACIXIwSiEvLlOxVLR2HNcOgknxS7oJ:h4BzcfPdD+CIXNSiEvoxKNi7oJ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T165744A01B286E071D8BE01B869386B77153EAE518BEAC9D7E3C449AE4D700D19F73763
sha3_384: ba6c21c2895f153a820a644da8ffc5021b6e82c829dbc7d7388bfeb95d2b481cbac32ccc9f000704d2dc98b92bade903
ep_bytes: 558bec837d0c017505e83f9f0000ff75
timestamp: 2015-12-03 12:00:33

Version Info:

FileVersion: 1.1.0.9
InternalName: prfo.dll
LegalCopyright: Copyright (C) 2014
OriginalFilename: prfo.dll
ProductVersion: 1.1.0.9
Translation: 0x0009 0x04b0

PUP.Optional.PriceFountain also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.PriceFountain.1
CAT-QuickHealPUP.PriceFountain.D5
SkyhighPUP-FGA
ALYacGen:Variant.Adware.PriceFountain.1
SangforTrojan.Win32.Save.a
BitDefenderThetaGen:NN.ZedlaF.36680.vu8@amcvLzmO
SymantecAdware.DealPly
ESET-NOD32a variant of Win32/DealPly.CI potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:VHO:AdWare.Win32.DealPly.gen
BitDefenderGen:Variant.Adware.PriceFountain.1
NANO-AntivirusVirus.Win32.Gen.ccmw
SUPERAntiSpywarePUP.PriceFountain/Variant
AvastWin32:BrowseFox-AIE [Adw]
TencentMalware.Win32.Gencirc.10b0e710
SophosPriceFountain (PUA)
F-SecureHeuristic.HEUR/AGEN.1302012
DrWebAdware.DealPly.260
VIPREGen:Variant.Adware.PriceFountain.1
TrendMicroADW_DEALPLY.SMCI
EmsisoftGen:Variant.Adware.PriceFountain.1 (B)
IkarusPUA.DealPly
WebrootPua.Adware.Pricefountain
GoogleDetected
AviraHEUR/AGEN.1302012
Antiy-AVLGrayWare[AdWare]/Win32.DealPly.ci
MicrosoftBrowserModifier:Win32/Prifou
XcitiumApplication.Win32.DealPly.E@6765lz
ArcabitTrojan.Adware.PriceFountain.1
ZoneAlarmnot-a-virus:VHO:AdWare.Win32.DealPly.gen
GDataWin32.Adware.DealPly.S
VaristW32/S-ed781133!Eldorado
AhnLab-V3PUP/Win32.Dealply.R174855
McAfeePUP-FGA
VBA32BScope.Adware.DealPly
MalwarebytesPUP.Optional.PriceFountain
TrendMicro-HouseCallADW_DEALPLY.SMCI
RisingAdware.DealPly!1.A3EF (CLASSIC)
YandexTrojan.GenAsa!xcoWdO98RL4
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/DealPly
AVGWin32:BrowseFox-AIE [Adw]
DeepInstinctMALICIOUS

How to remove PUP.Optional.PriceFountain?

PUP.Optional.PriceFountain removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment