PacFunction

PacFunction

Known Adware

by Yontoo Technology, Inc.

What is PacFunction?

PacFunction is software application developed by Yontoo Technology, Inc.. It is most commonly found on computers running Windows 7 with nearly 54.73% of installations running this operating system. PacFunction's installer is typically 1.00 MB in size and installs around 11 files. The most common release is 2014.03.28.231718 with 12.94% of all installations currently using this version.

PacFunction is most popular in the United States with 32.8% of installations residing in this country.

About PacFunction?

TiltBrowser is a browser extension known for its Yontoo/Sambreel advertising injection adware. It is designed to transform random web page text into hyperlinks and generate browser popups suggesting fake updates or other software. The software is also known for displaying ads with red "click here" buttons when those links are hovered on. Furthermore, it is worth noting that the installation of TiltBrowser may result in the unwanted addition of other adware programs without the user's consent. As a consequence, web pages may experience decreased download speeds due to the excessive display of ads. The distribution of this software is commonly facilitated through download managers associated with Simply Tech Ltd, Install Lab ltd. (clickandownload.com), and CoolMirage Ltd. (torntv-tvv.org).

Multiple virus scanners have detected malware in PacFunction.

updatePacFunction.exe (MD5: d3362227a4bfba3792cfbb22ed699494) has been flagged by 26 scanners:
Scanner Software Result
Agnitum Outpost Riskware.Agent!
AhnLab-V3 PUP/Win32.SwiftBrowse
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/MSIL.Kranet
AVG Pafun.E1F
Avira ADWARE/BrowseFox.Gen7
AVware Yontoo (fs)
Baidu-International Adware.Win32.BrowseFox.bH
CAT-QuickHeal AdWare.MSIL.r3 (Not a Virus)
Comodo Security ApplicUnwnt
Dr.Web Trojan.BPlug.250
ESET-NOD32 a variant of Win32/BrowseFox.H
Fortinet FortiGate Adware/Kranet
K7 AntiVirus Trojan ( 0049f7ad1 )
K7GW Trojan ( 0049f7ad1 )
Kaspersky not-a-virus:HEUR:AdWare.MSIL.Kranet.heur
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.PacFunction.A
McAfee BrowseFox.c
McAfee-GW-Edition BehavesLike.Win32.Dropper.fh
nProtect Trojan-Clicker/W32.Agent.323360.B
Qihoo-360 Win32/Virus.Adware.e4c
Sophos Generic PUA LP
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R0C1C0EJH14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJH14
VIPRE Antivirus Yontoo (fs)
PacFunctionBHO.dll (MD5: 05bdaaa29e6b256cb966b90306ddc033) has been flagged by 39 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Agent.NYU
Agnitum Outpost PUA.Agent
Avira AntiVir APPL/BrowseFox.Gen2
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Agent
avast! Win32:PUP-gen [PUP]
AVG MalSign.Pafun
Bitdefender Adware.Agent.NYU
CAT-QuickHeal AdWare.Agent.r5 (Not a Virus)
Comodo Security Application.Win32.Altbrowse.AK
Dr.Web Trojan.BPlug.28
Emsisoft Anti-Malware Adware.Agent.NYU
ESET-NOD32 a variant of Win32/BrowseFox.F
Fortinet FortiGate Riskware/BrowseFox
F-Secure Adware.Agent.NYU
G Data Adware.Agent.NYU
IKARUS anti.virus AdWare.Agent
Jiangmin Adware/Agent.jaw
K7 AntiVirus Unwanted-Program
K7GW Unwanted-Program ( 00454f261 )
Kaspersky not-a-virus:AdWare.Win32.Agent
Kingsoft AntiVirus Win32.Troj.Agent.ah.(kcloud)
Malwarebytes PUP.Optional.PacFunction.A
McAfee Artemis!05BDAAA29E6B
McAfee-GW-Edition Artemis!05BDAAA29E6B
MicroWorld-eScan Adware.Agent.NYU
NANO AntiVirus Riskware.Win32.Agent.cqvnby
nProtect Adware.Agent.NYU
Sophos Generic PUA MH
SUPERAntiSpyware Adware.BrowseFox/Variant
TrendMicro-HouseCall TROJ_GEN.F47V0320
Vba32 AntiVirus AdWare.Agent
VIPRE Antivirus Yontoo (fs)
AhnLab-V3 PUP/Win32.SwiftBrowse
Avira ADWARE/BrowseFox.Gen7
AVware Yontoo (fs)
Baidu-International Adware.Win32.BrowseFox.bH
Qihoo-360 Win32/Virus.Adware.e4c
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R0C1C0EJH14

Software Behaviors

Services:
  • updatePacFunction.exe runs as a service named 'Update PacFunction' (Update PacFunction).

Software Details

URL:
https://pacfunction.info/support
Support:
https://mailto:
Installation path:
C:\Program Files\PacFunction
Uninstaller:
C:\Program Files\PacFunction\PacFunctionuninstall.exe
Size:
1.00 MB
Language:
English

PacFunction Executable Details

Primary executable:
PacFunction.FirstRun.exe
Name:
PacFunction
Path:
C:\Program Files\PacFunction\PacFunction.FirstRun.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by PacFunction
File Type Filename MD5
EXE
e92604e043f51c604b6d1ac3bcd3a202
DLL
67a8a7b8b939bb6fb03184f236f724ad
EXE
38dcf478cd6a59cb0d4cd280071c2fdd
EXE
d3362227a4bfba3792cfbb22ed699494
EXE
8375e6b6dbe2532c2adbb6175fd9e124
DLL
05bdaaa29e6b256cb966b90306ddc033
EXE
4080bdc9fd42659216f0af2eb8dd57b4
CRX
18097b2e9d61f5be0cb0ee1d9a44e6dd
EXE
01491e8e8e66aa349aa4119d56225760
DLL
767ed2ad70abcf38bc01409d394ac181