PriceFountain

PriceFountain

Known Adware

by DealPly Technologies Ltd.

What is PriceFountain?

PriceFountain is software application developed by DealPly Technologies Ltd.. It is most commonly found on computers running Windows 10 with nearly 47.12% of installations running this operating system. PriceFountain's installer is typically 8.00 MB in size and installs around 9 files. The most common release is 1.0.8.6 with 35.84% of all installations currently using this version.

PriceFountain is most popular in the United States with 35.09% of installations residing in this country.

PriceFountain adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About PriceFountain?

Price Fountain (SaveSense) is an adware extension designed to deliver ads to the browser on web pages that are not associated with the ads or the extension. These ads may appear as new ads that would not typically be seen, or they may be displayed on top of existing ads on the underlying website. Users may also encounter redirects to download potentially unwanted software or make purchases from affiliate partners. When a coupon is displayed, clicking on any offers will lead to a redirect that drops affiliate cookies onto the user's computer and directs them to the advertiser's page or offer. Additionally, Price Fountain communicates with a remote server to track user habits, including visited domains, viewed pages, and interactions with advertisements. This information is used to personalize the ads and offers presented to the user.

Multiple virus scanners have detected malware in PriceFountain.

PriceFountainUpdateVer.exe (MD5: 519111134f14408bb92a6164591e132d) has been flagged by 39 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Symmi.50815
Agnitum Outpost PUA.DealPly!
AhnLab-V3 PUP/Win32.Dealply
ALYac Gen:Variant.Symmi.50815
Antiy-AVL Trojan/Win32.TSGeneric
Arcabit Trojan.Symmi.DC67F
avast! Win32:Adware-gen [Adw]
AVG DealApp.CWS
Avira ADWARE/DealPly.A.1410
AVware Trojan.Win32.Generic!BT
Baidu-International PUA.Win32.DealPly.Z
Bitdefender Gen:Variant.Symmi.50815
CAT-QuickHeal AdWare.DealPly.OD8
Comodo Security ApplicUnwnt
Cyren W32/Adware.SBVL-8860
Dr.Web Trojan.Click3.12983
Emsisoft Anti-Malware Gen:Variant.Symmi.50815 (B)
ESET-NOD32 a variant of Win32/DealPly.Z potentially unwanted
Fortinet FortiGate Adware/DealPly
F-Secure Gen:Variant.Symmi.50815
G Data Gen:Variant.Symmi.50815
K7 AntiVirus Trojan ( 004b1dda1 )
K7GW Trojan ( 004b1dda1 )
Kaspersky not-a-virus:AdWare.Win32.DealPly.brj
McAfee RDN/Generic PUP.z
McAfee-GW-Edition RDN/Generic PUP.z
MicroWorld-eScan Gen:Variant.Symmi.50815
NANO AntiVirus Riskware.Win32.DealPly.dmrhiz
Panda Antivirus Trj/CI.A
Qihoo-360 HEUR/QVM05.1.Malware.Gen
Sophos DealPly Updater
SUPERAntiSpyware Adware.DealPly/Variant
Symantec Trojan.Gen.2
Tencent Win32.Adware.Dealply.Sunp
Trend Micro ADW_DWNWARE
TrendMicro-HouseCall ADW_DWNWARE
Vba32 AntiVirus AdWare.DealPly
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.DealPly.Win32.175
pricefountainw.exe (MD5: 3c468afa5098869417ba975e7be0f53b) has been flagged by 43 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.12682638
Agnitum Outpost PUA.DealPly!
ALYac Trojan.Generic.12682638
Antiy-AVL Trojan/Win32.TSGeneric
Arcabit Trojan.Generic.DC1858E
avast! Win32:PUP-gen [PUP]
AVG Generic_r.ZL
Avira ADWARE/DealPly.462336
AVware Trojan.Win32.Generic!BT
Baidu-International PUA.Win32.DealPly.AC
Bitdefender Trojan.Generic.12682638
CAT-QuickHeal Adware.DealPly.r4 (Not a Virus)
Comodo Security ApplicUnwnt
Cyren W32/Adware.IXKF-7209
Dr.Web Adware.InstallCore.560
Emsisoft Anti-Malware Trojan.Generic.12682638 (B)
ESET-NOD32 a variant of Win32/DealPly.AC potentially unwanted
Fortinet FortiGate Riskware/DealPly
F-Secure Trojan.Generic.12682638
G Data Trojan.Generic.12682638
Jiangmin AdWare/DealPly.aub
K7 AntiVirus Trojan ( 004b41b41 )
K7GW Trojan ( 004b41b41 )
Kaspersky not-a-virus:AdWare.Win32.DealPly.bsn
Malwarebytes PUP.Optional.DealPly
McAfee RDN/Generic.grp!ia
McAfee-GW-Edition BehavesLike.Win32.Dropper.gh
MicroWorld-eScan Trojan.Generic.12682638
NANO AntiVirus Riskware.Win32.DealPly.dnninp
nProtect Trojan.Generic.12682638
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Trojan.Win32.Generic.18300CA3!405802147
Symantec Trojan.Gen.2
Tencent Win32.Adware.Dealply.Lkxq
Trend Micro ADW_DEALPLY
TrendMicro-HouseCall ADW_DEALPLY
Vba32 AntiVirus AdWare.DealPly
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.DealPly.Win32.234
AhnLab-V3 PUP/Win32.Dealply
Qihoo-360 HEUR/QVM05.1.Malware.Gen
Sophos DealPly Updater
SUPERAntiSpyware Adware.DealPly/Variant
pricefountain.exe (MD5: 8af543f361cc7ac6e666d5a4d436d200) has been flagged by 44 scanners:
Scanner Software Result
AegisLab AdWare.W32.Lollipop
Symantec WS.Reputation
Trend Micro ADW_METER
TrendMicro-HouseCall ADW_METER
Lavasoft Ad-Aware Trojan.Generic.12682638
Agnitum Outpost PUA.DealPly!
ALYac Trojan.Generic.12682638
Antiy-AVL Trojan/Win32.TSGeneric
Arcabit Trojan.Generic.DC1858E
avast! Win32:PUP-gen [PUP]
AVG Generic_r.ZL
Avira ADWARE/DealPly.462336
AVware Trojan.Win32.Generic!BT
Baidu-International PUA.Win32.DealPly.AC
Bitdefender Trojan.Generic.12682638
CAT-QuickHeal Adware.DealPly.r4 (Not a Virus)
Comodo Security ApplicUnwnt
Cyren W32/Adware.IXKF-7209
Dr.Web Adware.InstallCore.560
Emsisoft Anti-Malware Trojan.Generic.12682638 (B)
ESET-NOD32 a variant of Win32/DealPly.AC potentially unwanted
Fortinet FortiGate Riskware/DealPly
F-Secure Trojan.Generic.12682638
G Data Trojan.Generic.12682638
Jiangmin AdWare/DealPly.aub
K7 AntiVirus Trojan ( 004b41b41 )
K7GW Trojan ( 004b41b41 )
Kaspersky not-a-virus:AdWare.Win32.DealPly.bsn
Malwarebytes PUP.Optional.DealPly
McAfee RDN/Generic.grp!ia
McAfee-GW-Edition BehavesLike.Win32.Dropper.gh
MicroWorld-eScan Trojan.Generic.12682638
NANO AntiVirus Riskware.Win32.DealPly.dnninp
nProtect Trojan.Generic.12682638
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Trojan.Win32.Generic.18300CA3!405802147
Tencent Win32.Adware.Dealply.Lkxq
Vba32 AntiVirus AdWare.DealPly
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.DealPly.Win32.234
AhnLab-V3 PUP/Win32.Dealply
Qihoo-360 HEUR/QVM05.1.Malware.Gen
Sophos DealPly Updater
SUPERAntiSpyware Adware.DealPly/Variant

Software Behaviors

Scheduled tasks:
  • PriceFountainUpdateVer.exe is scheduled as a task named 'At4' (runs daily at 21.57).

Startup Entries

Registry entries:
  • pricefountainw.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'pricefountainw.exe' and executes as C:\users\user\appdata\Local\PriceFountain\pricefountainw.exe HKEY_CURRENT_USER Software\PriceFountain.

Software Details

URL:
https://www.pricefountain.com
Support:
Installation path:
C:\users\user\appdata\local\pricefountain
Uninstaller:
"C:\users\user\appdata\Local\PriceFountain\uninst.exe" /uninstall
Size:
8.00 MB
Language:
English

PriceFountain Executable Details

Primary executable:
pricefountain.exe
Name:
PriceFountain
Path:
C:\users\user\appdata\local\pricefountain\pricefountain.exe
MD5:
8af543f361cc7ac6e666d5a4d436d200
SHA-1:
SHA-256:
Files installed by PriceFountain
File Type Filename MD5
EXE
60f4d680c6b466396ac1a3e3eac4140c
EXE
519111134f14408bb92a6164591e132d
DLL
b0ffc541f6e32448d0243836c1d728c4
EXE
c46e8565e1f60ad1bd11713e4cf44ce6
EXE
3c468afa5098869417ba975e7be0f53b
EXE
8af543f361cc7ac6e666d5a4d436d200
DLL
0c980a2e3e8f73b1b52e21478474d07e
XPI
f5ca13f4319ab901f57e9f9dabb3c710
EXE
d1cca245ef1c2e16680df8007f6856c4