pricEchop

pricEchop

Known Adware

by InstalleRex-WebPick

What is pricEchop?

pricEchop is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 63.83% of installations running this operating system. pricEchop's installer is typically 691.00 KB in size and installs around 97 files. The most common release is 4.3.0.1667 with 28.72% of all installations currently using this version.

pricEchop is most popular in the United States with 18.82% of installations residing in this country.

About pricEchop?

PriceChop is a web browser plugin supported by advertising and potentially bundled with third-party download managers to facilitate the installation of potentially unwanted software offers (PPI) and through malvertising practices. Its primary function is to deliver various forms of advertisements, such as banners, text hyper-links, inline text ads, and transitionals, to the user's browser. These ads are injected by the plugin and may appear in the header or footer of a web page, replacing any legitimate ads already present. The plugin also has the ability to display a slider in the top right-hand portion of the browser when the user visits a partner site, providing offers that, when clicked, redirect the user to advertiser pages while dropping affiliate cookies on the user's computer. The plugin communicates with a remote server to report the user's browsing habits, including the URLs and domains they visit, in order to update its advertisements. It collects and stores information about the web pages visited and activity on those pages, such as impressions, clicks, and search terms, some of which may be personally identifiable. This information may be used or shared with third parties for the purpose of displaying targeted advertisements, promotional material, and marketing to the user.

Multiple virus scanners have detected malware in pricEchop.

PLi58n5.exe (MD5: f8072abd7a0dbbfb409c9536ecdec1ca) has been flagged by 11 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.146103
AhnLab-V3 Trojan/Win32.Preloader
Baidu-International Adware.Win32.MultiPlug.bAG
Bitdefender Gen:Variant.Adware.Graftor.146103
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.146103 (B)
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AG
F-Secure Gen:Variant.Adware.Graftor.146103
G Data Gen:Variant.Adware.Graftor.146103
Malwarebytes PUP.Optional.MultiPlug
MicroWorld-eScan Gen:Variant.Adware.Graftor.146103
Panda Antivirus Trj/Genetic.gen
bUegnET.exe (MD5: c3dee947a4bc4a2251ef0138c3c72bc5) has been flagged by 30 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.673297
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir Adware/MultiPlug.AG
avast! Win32:Dropper-gen [Drp]
AVG Generic5.AZGM
Bitdefender Application.Generic.673297
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AG
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.673297
G Data Application.Generic.673297
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic.bfr!ho
McAfee-GW-Edition RDN/Generic.bfr!ho
MicroWorld-eScan Application.Generic.673297
Sophos Generic PUA DM
TrendMicro-HouseCall Suspicious_GEN.F47V0707
VIPRE Antivirus Trojan.Win32.Generic!BT
Baidu-International Trojan.Win32.MultiPlug.BAG
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.146103 (B)
IKARUS anti.virus PUA.Generic
Panda Antivirus Trj/Genetic.gen
Tencent Win32.Risk.Adware.Wrgf
AVware Trojan.Win32.Generic!BT
Symantec Trojan.Gen
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.ccbm
NANO AntiVirus Riskware.Win32.MultiPlug.ddnbyk
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Antiy-AVL Trojan/Win32.SGeneric
MOj4.exe (MD5: be5c16f6998f6d7473150524c8338c62) has been flagged by 22 scanners:
Scanner Software Result
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir Adware/MultiPlug.AG.74
Antiy-AVL Trojan/Win32.SGeneric
avast! Win32:Adware-gen [Adw]
AVG Generic5.AZVT
Baidu-International Adware.Win32.MultiPlug.81
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AG
Malwarebytes PUP.Optional.MultiPlug
McAfee Artemis!BE5C16F6998F
McAfee-GW-Edition Artemis!BE5C16F6998F
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0712
VIPRE Antivirus Trojan.Win32.Generic!BT
Lavasoft Ad-Aware Gen:Variant.Graftor.150563
Bitdefender Gen:Variant.Graftor.150563
Emsisoft Anti-Malware Gen:Variant.Graftor.150563 (B)
F-Secure Gen:Variant.Graftor.150563
G Data Gen:Variant.Graftor.150563
MicroWorld-eScan Gen:Variant.Graftor.150563
Panda Antivirus Trj/Genetic.gen
iZ4Vldh8NU.exe (MD5: 3adc690806b46d83d2badb63ef351a9c) has been flagged by 42 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.150430
Agnitum Outpost Riskware.ChromePatcher!
AhnLab-V3 Trojan/Win32.Preloader
Antiy-AVL Trojan/Win32.SGeneric
avast! Win32:Malware-gen
AVG Generic5.BFGV
Avira Adware/Graftor.150430.29
AVware Trojan.Win32.Generic!BT
Baidu-International Hacktool.Win32.ChromePatcher.aV
Bitdefender Gen:Variant.Adware.Graftor.150430
Bkav FE W32.DusfureLTG.Adware
CAT-QuickHeal RiskTool.ChromePatcher.r5 (Not a Virus)
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.150430 (B)
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.BN
Fortinet FortiGate Riskware/MultiPlug
F-Secure Gen:Variant.Adware.Graftor.150430
G Data Gen:Variant.Adware.Graftor.150430
IKARUS anti.virus Win32.SuspectCrc
K7 AntiVirus Adware ( 004a07251 )
K7GW Trojan ( 050000001 )
Kaspersky not-a-virus:RiskTool.Win32.ChromePatcher.er
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!clm
McAfee-GW-Edition BehavesLike.Win32.Expiro.hh
MicroWorld-eScan Gen:Variant.Adware.Graftor.150430
NANO AntiVirus Riskware.Win32.Graftor.ddudlz
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Trojan.Win32.Generic.17258346!388334406
Sophos Generic PUA GA
Symantec Trojan.Gen
Trend Micro TROJ_GEN.R0CBC0EHM14
TrendMicro-HouseCall TROJ_GEN.R0CBC0EHM14
Vba32 AntiVirus AdWare.Agent
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Backdoor.PePatch.Win32.40558
Qihoo-360 Win32/Virus.RiskTool.ae6
Avira AntiVir Adware/Graftor.146103.10
Tencent Win32.Risk.Adware.Alsn
ViRobot Adware.Graftor.578048
Norman Suspicious_Gen4.GWCSL
uofoh8.exe (MD5: 3341cab47ee090715a8347df8186a28a) has been flagged by 12 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Graftor.150430
AhnLab-V3 Trojan/Win32.Preloader
avast! Win32:Malware-gen
Bitdefender Gen:Variant.Graftor.150430
Emsisoft Anti-Malware Gen:Variant.Graftor.150430 (B)
F-Secure Gen:Variant.Graftor.150430
G Data Gen:Variant.Graftor.150430
Malwarebytes PUP.Optional.MultiPlug
MicroWorld-eScan Gen:Variant.Graftor.150430
Panda Antivirus Trj/Genetic.gen
Baidu-International Adware.Win32.MultiPlug.bAG
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AG

Software Details

URL:
https://price-chop.info
Support:
–
Installation path:
C:\ProgramData\pricechop
Uninstaller:
"C:\ProgramData\pricEchop\2SgdvQ6tHh.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
691.00 KB
Language:
English

pricEchop Executable Details

Primary executable:
2SgdvQ6tHh.exe
Name:
pricEchop
Path:
C:\ProgramData\pricechop\2SgdvQ6tHh.exe
MD5:
1b63b4e4fe4be0d8607d362c3d2f2677
SHA-1:
–
SHA-256:
–
Files installed by pricEchop
File Type Filename MD5
EXE
NaUW.exe
Malware
afda36c31a4224fc0e1869f8feac4ed4
EXE
594.exe
Malware
5b288612fe43837c7a6b439eaed297d8
EXE
26d64e2da87c1b05beb9ae368d4100f8
EXE
9Otk.exe
Malware
89950b026fe90cdd121906866b15788f
EXE
0d8165b5a716b172aeafc27fea577bc8
EXE
e892d85ebe8e66b1088d18a21c3da282
EXE
d068c3b02dc61fff62c60942f5f80c6e
EXE
heCF.exe
Malware
d068c3b02dc61fff62c60942f5f80c6e
EXE
b77836968f62d148ce6ca2d796e55e20
EXE
1b63b4e4fe4be0d8607d362c3d2f2677