How to remove WFini.exe
WFini.exe
The module WFini.exe has been detected as Adware.ELEX
File Details
Product Name: | WFini |
Company Name: | WFini LIMITED |
MD5: | 832743a6df072b64154c417ffb55d2ff |
Size: | 529 KB |
First Published: | 2017-06-06 13:13:52 (7 years ago) |
Latest Published: | 2018-08-29 08:11:57 (6 years ago) |
Status: | Adware.ELEX (on last analysis) | |
Analysis Date: | 2018-08-29 08:11:57 (6 years ago) |
Overview
Signed By: | Junyan Li |
Status: | Valid |
Common Places:
%windir%\temp\iste2c0.tmp\tools |
%windir%\temp\ist653.tmp\tools |
%sysdrive%\adwcleaner\quarantine\files\klntbvpkmfmkdfbostldfnrfjfaohnyk |
%system%\_sspm |
%windir%\temp\istbf3d.tmp\tools |
%commonappdata%\mwinpm |
%sysdrive%\adwcleaner\quarantine\files\cdobotflssuavyngomznsfmoqvzhqmwg |
%windir%\temp\istcb50.tmp\tools |
%windir%\temp\ist86cc.tmp\tools |
%sysdrive%\adwcleaner\quarantine\files\ebdtockywcknfigeidgqlzgjcfpuhuux |
File Names:
wpm.exe |
WFini.exe |
Geography:
17.9% | ||
17.9% | ||
14.3% | ||
10.7% | ||
10.7% | ||
7.1% | ||
7.1% | ||
3.6% | ||
3.6% | ||
3.6% | ||
3.6% |
OS Version:
Windows 7 | 53.6% | |
Windows 8.1 | 21.4% | |
Windows 8 | 14.3% | |
Windows 10 | 10.7% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x0004889d |
PE Sections:
Name | Size of data | MD5 |
.text | 417280 | 81aec4d27f57c75be77234ce4bcf8182 |
.rdata | 93184 | 1bf7796ad3b2b1d5bf6fae135a42691f |
.data | 13312 | db507e0d44ab7d435a2112cbc20fde42 |
.rsrc | 11264 | 3bd8a25d9e7f9be0526083a102edd9f5 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for WFini.exe