PriceDownloader

PriceDownloader

Known Toolbar

by InstalleRex-WebPick

What is PriceDownloader?

PriceDownloader is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 (SP1) with nearly ~99% of installations running this operating system. PriceDownloader's installer is typically 1.00 MB in size and installs around 3 files.

PriceDownloader is most popular in the United States with 83.33% of installations residing in this country.

About PriceDownloader?

Price Downloader is a web browser extension that displays additional advertisements in search engines such as Bing and Google. It installs itself as an extension for Internet Explorer, Chrome, and Firefox, and runs as a background process. Although it creates an entry in Add or Remove Programs, removing this entry might stop the adware from running but will not stop ads from displaying. Once installed, it injects new ads into search results and various web pages that use 3rd party advertising, replacing existing ads with its own. The program utilizes the InstalleRex download manager from WebPicks Holdings for installation. InstalleRex is known for distributing potentially unwanted applications, web browser toolbars, and ad-supported extensions. The software is a variant of known adware (also known as SaveAs, SaveNShare, DownloadKeeper), but is re-branded to mask its origin, although it includes many of the same components.

Multiple virus scanners have detected malware in PriceDownloader.

OQdgDn.dll (MD5: e1d330228db3f4aab5582d1a294163f3) has been flagged by 15 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.Graftor
Avira AntiVir ADWARE/Adware.A.2611
AVG Generic5.AKZD
Baidu-International Adware.Win32.BHO.77
Bkav FE W32.Clod3d2.Trojan.2e5d
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.N
K7 AntiVirus Adware ( 004923a41 )
K7GW Adware ( 004923a41 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!E1D330228DB3
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
Rising Antivirus PE:Malware.Adware!6.1293
TrendMicro-HouseCall TROJ_GEN.F47V1222
VIPRE Antivirus JustPlugIt (fs)
OQdgDn.exe (MD5: 06cfeaa6556d9264ef303884935ddfe2) has been flagged by 34 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.582628
Agnitum Outpost Adware.MegaSearch
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir SPR/Tool.498176
Antiy-AVL AdWare/Win32.MegaSearch
avast! Win32:Malware-gen
AVG Generic5
Baidu-International Adware.Win32.MegaSearch.40
Bitdefender Application.Generic.582628
Bkav FE W32.WonintLTD.Trojan
CAT-QuickHeal Adware.Megasearch.at (Not a Virus)
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.K.gen
Fortinet FortiGate Adware/Megasearch
G Data Application.Generic.582628
IKARUS anti.virus Win32.AdWare
K7 AntiVirus Adware
K7GW Adware ( 00490ca81 )
Kaspersky not-a-virus:AdWare.Win32.MegaSearch
Kingsoft AntiVirus Win32.Troj.MegaSearch.at.(kcloud)
Malwarebytes PUP.Optional.MultiPlug.A
McAfee PUP-FFY!06CFEAA6556D
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
MicroWorld-eScan Application.Generic.582628
NANO AntiVirus Riskware.Win32.MegaSearch.cscrfp
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.422
Sophos Generic PUA BA
Trend Micro TROJ_GEN.F0C2C00LT13
TrendMicro-HouseCall TROJ_GEN.F0C2C00LT13
Vba32 AntiVirus AdWare.MegaSearch
VIPRE Antivirus Trojan.Win32.Generic!BT
ViRobot Adware.Agent.498176.A
Rising Antivirus PE:Malware.Adware!6.1293

Software Details

URL:
https://justplug.it
Support:
Installation path:
C:\ProgramData\pricedownloader
Uninstaller:
"C:\ProgramData\PriceDownloader\OQdgDn.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
1.00 MB
Language:
English

PriceDownloader Executable Details

Primary executable:
OQdgDn.exe
Name:
PriceDownloader
Path:
C:\ProgramData\pricedownloader\OQdgDn.exe
MD5:
06cfeaa6556d9264ef303884935ddfe2
SHA-1:
SHA-256:
Files installed by PriceDownloader
File Type Filename MD5
DLL
5a525639bc99f2961bf96f39a08b3f59
DLL
OQdgDn.dll
Malware
e1d330228db3f4aab5582d1a294163f3
EXE
06cfeaa6556d9264ef303884935ddfe2