ChEapMe

ChEapMe

Known Toolbar

by InstalleRex-WebPick

What is ChEapMe?

ChEapMe is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 69.05% of installations running this operating system. ChEapMe's installer is typically 1.00 MB in size and installs around 47 files.

ChEapMe is most popular in the United States with 25.49% of installations residing in this country.

About ChEapMe?

CheapMe is a web browser extension developed by JustPlug.It and distributed through the WebPick InstalleRex download and install manager. This cross-browser extension comprises several components, including a Windows service, an auto-starting element, and a browser toolbar/plugin. Its primary function is to inject various forms of advertisements, such as banner ads, hyper-text links, and pop-ups, into the user's browser. It is worth noting that the program may come included with adware offer bundles and has the capability to hijack existing web advertising and inject affiliate codes into links. Upon installation, the program will install itself in a randomly named folder within Program Files or ProgramData, with each included file also having a unique, randomly generated name. The Windows Service runs with full administrator rights and connects to remote servers for updates. It has been observed that the program may display deceptive malvertising ads and unwanted pop-ups, while also installing bundled adware utilities and additional browser extensions. Furthermore, some versions of the program may modify the default security settings of the user's browser. It is also noted that certain versions of CheapMe may include a setup file signed by WEB PICK - INTERNET HOLDINGS LTD, which is the partner installer/distributor. Please note that our description includes all relevant and accurate information about the CheapMe software.

Multiple virus scanners have detected malware in ChEapMe.

1.exe (MD5: 1b63b4e4fe4be0d8607d362c3d2f2677) has been flagged by 45 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.146103
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir Adware/Graftor.146103
Antiy-AVL Trojan/Win32.SGeneric
avast! Win32:Dropper-gen [Drp]
AVG Generic5.AZJV
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.81
Bitdefender Gen:Variant.Adware.Graftor.146103
Bkav FE W32.CanpaktiLTAAI.Adware
CAT-QuickHeal AdWare.MultiPlug.r5 (Not a Virus)
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.146103 (B)
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AG
Fortinet FortiGate Riskware/MultiPlug
F-Secure Gen:Variant.Adware.Graftor.146103
G Data Gen:Variant.Adware.Graftor.146103
IKARUS anti.virus PUA.Generic
K7 AntiVirus Adware ( 0049c94b1 )
K7GW Adware ( 0049c94b1 )
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.bqfl
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic.bfr!ho
MicroWorld-eScan Gen:Variant.Adware.Graftor.146103
NANO AntiVirus Riskware.Win32.Graftor.dcodwf
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA IB
Symantec WS.Reputation.1
Tencent Win32.Risk.Adware.Dzkd
Trend Micro TROJ_SPNR.14GN14
TrendMicro-HouseCall TROJ_SPNR.14GN14
Vba32 AntiVirus AdWare.MultiPlug
VIPRE Antivirus Trojan.Win32.Generic!BT
McAfee-GW-Edition Mplug!2A05AAA38385
Norman Multiplug.A
nProtect Trojan.Generic.11089445
Qihoo-360 Win32/Trojan.Adware.273
Rising Antivirus PE:Adware.MultiPlug!6.166A
SUPERAntiSpyware Adware.Multiplug/Variant
ViRobot Adware.Agent.474112
AegisLab Troj.W32.Gen
Avira TR/Crypt.EPACK.Gen2
Dr.Web Trojan.Crossrider.8290
1.dll (MD5: 938a58a18228d9c556965deb4f74e494) has been flagged by 30 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.Agent
avast! Win32:Dropper-gen [Drp]
AVG Generic5.AZJT
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.81
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AY
Fortinet FortiGate Riskware/MultiPlug
IKARUS anti.virus PUA.Generic
K7 AntiVirus Adware ( 0049c94b1 )
K7GW Adware ( 0049c94b1 )
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!chv
McAfee-GW-Edition RDN/Generic PUP.x!chv
Sophos Generic PUA NF
Trend Micro ADW_MULTIPLUG
TrendMicro-HouseCall ADW_MULTIPLUG
VIPRE Antivirus Trojan.Win32.Generic!BT
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM10.Gen
G Data Win64.Adware.Megasearch.C
Symantec Adware.BL
Antiy-AVL Trojan/Win32.SGeneric
Lavasoft Ad-Aware Gen:Variant.Adware.61989
Avira AntiVir TR/Crypt.EPACK.Gen2
Bitdefender Gen:Variant.Adware.61989
Emsisoft Anti-Malware Gen:Variant.Adware.61989 (B)
F-Secure Gen:Variant.Adware.61989
MicroWorld-eScan Gen:Variant.Adware.61989
reDk6QC5.x64.dll (MD5: 2a05aaa383857ecbdd6100c34595b5df) has been flagged by 45 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11089445
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir ADWARE/Adware.Gen
Antiy-AVL Trojan/Win32.SGeneric
avast! Win64:Adware-gen [Adw]
AVG Generic_r.GX
Baidu-International Adware.Win64.MultiPlug.A
Bitdefender Trojan.Generic.11089445
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Trojan.Generic.11089445 (B)
ESET-NOD32 a variant of Win64/Adware.MultiPlug.A
F-Secure Trojan.Generic.11089445
G Data Trojan.Generic.11089445
IKARUS anti.virus AdWare.MultiPlug
K7 AntiVirus Adware ( 004922f61 )
K7GW Adware ( 004922f61 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Mplug!2A05AAA38385
McAfee-GW-Edition Mplug!2A05AAA38385
MicroWorld-eScan Trojan.Generic.11089445
Norman Multiplug.A
nProtect Trojan.Generic.11089445
Panda Antivirus Trj/CI.A
Qihoo-360 Win32/Trojan.Adware.273
Rising Antivirus PE:Adware.MultiPlug!6.166A
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.R0CBH06DC14
VIPRE Antivirus MPlug
ViRobot Adware.Agent.474112
AegisLab Troj.W32.Gen
Agnitum Outpost PUA.MultiPlug!
Avira TR/Crypt.EPACK.Gen2
AVware Trojan.Win32.Generic!BT
Fortinet FortiGate Riskware/MultiPlug
Trend Micro TROJ_GEN.R0C1C0OIC14
Vba32 AntiVirus AdWare.Agent
Bkav FE W32.ToolbarEscort.Adware
CAT-QuickHeal AdWare.BHO.r6 (Not a Virus)
Kaspersky not-a-virus:AdWare.Win32.BHO.bdnc
NANO AntiVirus Riskware.Win32.BHO.dbdfeq
Dr.Web Trojan.Crossrider.8290
Tencent Win32.Risk.Adware.Lmkl
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
reDk6QC5.dll (MD5: ea89a5cfcf37d160e1b20b40e5111e89) has been flagged by 38 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.607493
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Adware/Win32.Graftor
Avira AntiVir ADWARE/Adware.Gen
AVG Generic_r.GU
Baidu-International Adware.Win32.MultiPlug.N
Bitdefender Application.Generic.607493
Comodo Security ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.N
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.607493
G Data Application.Generic.607493
IKARUS anti.virus AdWare.MegaSearch
K7 AntiVirus Adware ( 004923a41 )
K7GW Adware ( 004923a41 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Adware-FHP
McAfee-GW-Edition Adware-FHP
MicroWorld-eScan Application.Generic.607493
NANO AntiVirus Riskware.Win32.MultiPlug.cvyxyu
Panda Antivirus Trj/CI.A
Rising Antivirus PE:Malware.Adware!6.1293
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
TrendMicro-HouseCall TROJ_GEN.R047H06CO14
VIPRE Antivirus JustPlugIt (fs)
avast! Win32:Adware-gen [Adw]
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Symantec Trojan.Gen.2
Trend Micro ADW_MULTIPLG
Antiy-AVL Trojan/Win32.SGeneric
Qihoo-360 Win32/Trojan.Adware.814
Tencent Win64.Adware.Multiplug.Hqlt
Bkav FE W32.MultiPlugCP.Adware
Norman Multiplug.A
AVware Trojan.Win32.Generic!BT
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
Emsisoft Anti-Malware Gen:Variant.Adware.61989 (B)
2Xv.x64.dll (MD5: bab49b61943c026b825a714d2175635a) has been flagged by 32 scanners:
Scanner Software Result
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir ADWARE/Adware.Gen
AVG Generic_r.GX
Baidu-International Adware.Win64.MultiPlug.40
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win64/Adware.MultiPlug.A
G Data Win64.Trojan.Multiplug.B
IKARUS anti.virus not-a-virus:AdWare.Win32.MegaSearch
K7 AntiVirus Adware ( 004922f61 )
K7GW Adware ( 004922f61 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee RDN/Generic PUP.x!brl
McAfee-GW-Edition RDN/Generic PUP.x!brl
Norman Multiplug.A
Qihoo-360 Win32/Trojan.Adware.273
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
Trend Micro ADW_MULTIPLG
TrendMicro-HouseCall ADW_MULTIPLG
VIPRE Antivirus Win64.Adware.MultiPlug
avast! Win32:Dropper-gen [Drp]
AVware Trojan.Win32.Generic!BT
Fortinet FortiGate Riskware/MultiPlug
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
Panda Antivirus Trj/Genetic.gen
Symantec Adware.BL
Antiy-AVL Trojan/Win32.SGeneric
Lavasoft Ad-Aware Gen:Variant.Adware.61989
Bitdefender Gen:Variant.Adware.61989
Emsisoft Anti-Malware Gen:Variant.Adware.61989 (B)
F-Secure Gen:Variant.Adware.61989
MicroWorld-eScan Gen:Variant.Adware.61989

Software Details

URL:
https://justplug.it
Support:
–
Installation path:
C:\ProgramData\cheapme
Uninstaller:
"C:\ProgramData\ChEapMe\o.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
1.00 MB
Language:
English

ChEapMe Executable Details

Primary executable:
o.exe
Name:
ChEapMe
Path:
C:\ProgramData\cheapme\o.exe
MD5:
e25e25ae7a8968c6ebd55c4705380920
SHA-1:
–
SHA-256:
–
Files installed by ChEapMe
File Type Filename MD5
EXE
1.exe
Malware
1b63b4e4fe4be0d8607d362c3d2f2677
EXE
851d6860dab7f0bc2f746da33c3019bc
DLL
1.dll
Adware
938a58a18228d9c556965deb4f74e494
DLL
bc62ff4aee6ae5c809ee40635db67480
DLL
665f040875b4e851a6b06d9c70a7d099
DLL
dc4675dde55ea3b6e7ac8c0ae99580b4
DLL
2a05aaa383857ecbdd6100c34595b5df
DLL
ea89a5cfcf37d160e1b20b40e5111e89
DLL
ba83f90acbe4b889f0bd3cf373a17e2a
DLL
cd9aab0f06554578af17b69df6d22fc6