Pricora

Pricora

Known Toolbar

by Kreapixel

What is Pricora?

Pricora is software application developed by Kreapixel. It is most commonly found on computers running Windows 7 with nearly 59.24% of installations running this operating system. Pricora's installer is typically 6.00 MB in size and installs around 21 files. The most common release is 1.28.153.2 with 57.96% of all installations currently using this version.

Pricora is most popular in France with 34.53% of installations residing in this country.

Pricora adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About Pricora?

Pricora is a web browser extension that enhances the browsing experience by offering search advertising and customized search and home pages. It is designed to effectively modify and protect the default browser search engine while providing additional features such as alternative error page functionality. The software is commonly installed through bundled offers within third-party software distributions, typically in collaboration with third-party publishers to optimize installation revenue. Pricora utilizes the Crossrider platform to deliver its toolbar and browser extension functionalities.

Multiple virus scanners have detected malware in Pricora.

utils.exe (MD5: a75b85924ed1c5f1ee31855ff9ce13ac) has been flagged by 30 scanners:
Scanner Software Result
Antiy-AVL AdWare/Win32.Lyckriks
avast! Win32:Dropper-gen [Drp]
Baidu-International Trojan.Win32.Agent.aTNv
Dr.Web Adware.Plugin.73
ESET-NOD32 Win32/Packed.ScrambleWrapper.C
Fortinet FortiGate Adware/Lyckriks
Jiangmin AdWare/Lyckriks.bf
Kaspersky not-a-virus:AdWare.Win32.Lyckriks
NANO AntiVirus Trojan.Win32.Plugin.cfnbjq
TrendMicro-HouseCall TROJ_GEN.R0C1H07I613
Vba32 AntiVirus AdWare.Lyckriks
Lavasoft Ad-Aware Adware.Generic.620958
AhnLab-V3 Adware/Win32.Lyckriks
AVG Generic5.AIIQ
Bitdefender Adware.Generic.620958
Emsisoft Anti-Malware Adware.Generic.620958 (B)
F-Secure Adware.Generic.620958
G Data Adware.Generic.620958
K7 AntiVirus Trojan ( 0048e2021 )
K7GW Trojan ( 0048e2021 )
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!A4867262FAD7
McAfee-GW-Edition Artemis!A4867262FAD7
MicroWorld-eScan Adware.Generic.620958
Sophos Generic PUA NK
Symantec Adware.FindLyrics
VIPRE Antivirus Crossrider (fs)
Bkav FE W32.Clod92f.Trojan.1d68
IKARUS anti.virus Virus.Win32.Dropper
Panda Antivirus Suspicious file
Pricora-updater.exe (MD5: 38d5a3a91582699f43193e3d754dece9) has been flagged by 22 scanners:
Scanner Software Result
avast! Win32:Dropper-gen [Drp]
AVG Generic_r.GS
Baidu-International HackTool.Win32.CrossRider.J
Bkav FE W32.Clod92f.Trojan.1d68
Dr.Web Trojan.Crossrider.32
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.J
Fortinet FortiGate Riskware/Fam.NB
G Data Win32.Trojan.Agent.AXRG70
IKARUS anti.virus Virus.Win32.Dropper
K7 AntiVirus Trojan ( 0048c68d1 )
K7GW Trojan ( 0048c68d1 )
McAfee RDN/Generic.dx!csh
McAfee-GW-Edition RDN/Generic.dx!csh
Panda Antivirus Suspicious file
Sophos Mal/Generic-S
TrendMicro-HouseCall TROJ_GEN.R0CBH06JQ13
VIPRE Antivirus Crossrider (fs)
Antiy-AVL AdWare/Win32.Lyckriks
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
NANO AntiVirus Trojan.Win32.Crossrider.cjzgqu
Symantec Adware.Crossid
Vba32 AntiVirus AdWare.Lyckriks
Pricora-firefoxinstaller.exe (MD5: 90c77712976c0de19d64935346afdb43) has been flagged by 15 scanners:
Scanner Software Result
Baidu-International Trojan.Win32.Toolbar.CrossRider.J
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.J
K7 AntiVirus Trojan
K7GW Trojan
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!90C77712976C
McAfee-GW-Edition Artemis!90C77712976C
Sophos Generic PUA KI
Symantec Adware.FindLyrics
TrendMicro-HouseCall TROJ_GEN.R0C1H05JQ13
VIPRE Antivirus Crossrider (fs)
Antiy-AVL Trojan/Win32.SGeneric
AVG Generic5.ANCJ
Dr.Web Trojan.Crossrider.7519
NANO AntiVirus Trojan.Win32.Crossrider.cwggpx
Pricora-enabler.exe (MD5: a78ba70748627e0cdec3f56231ec2629) has been flagged by 10 scanners:
Scanner Software Result
Antiy-AVL Trojan/Win32.SGeneric
AVG Generic5.ANCJ
Baidu-International Adware.Win32.CrossRider.X
Dr.Web Trojan.Crossrider.7519
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.X
NANO AntiVirus Trojan.Win32.Crossrider.cwggpx
Symantec Adware.Crossid
VIPRE Antivirus Crossrider (fs)
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
TrendMicro-HouseCall TROJ_GEN.F47V0930
Pricora-codedownloader.exe (MD5: d68d26c1bd7689866e1d152c342b94f2) has been flagged by 6 scanners:
Scanner Software Result
AVG Generic_r.GS
Baidu-International Trojan.Win32.Toolbar.alF
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.J
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
TrendMicro-HouseCall TROJ_GEN.F47V0930
VIPRE Antivirus Crossrider (fs)

Software Behaviors

Scheduled tasks:
  • Pricora-codedownloader.exe is scheduled as a task named 'ac516c89-ffce-40ee-8006-d9d923418e0b-6'.
  • ac516c89-ffce-40ee-8006-d9d923418e0b-4.exe is scheduled as a task named 'ac516c89-ffce-40ee-8006-d9d923418e0b-4'.
  • Pricora-enabler.exe is scheduled as a task named 'temp_Pricora-enabler'.

Startup Entries

Startup tasks:
  • Pricora-firefoxinstaller.exe is automatically launched at startup through a scheduled task named Pricora-firefoxinstaller.
  • Pricora-nova.exe is automatically launched at startup through a scheduled task named ac516c89-ffce-40ee-8006-d9d923418e0b-7.
  • Pricora-codedownloader.exe is automatically launched at startup through a scheduled task named ac516c89-ffce-40ee-8006-d9d923418e0b-1.
  • ac516c89-ffce-40ee-8006-d9d923418e0b-5.exe is automatically launched at startup through a scheduled task named ac516c89-ffce-40ee-8006-d9d923418e0b-5.
  • ac516c89-ffce-40ee-8006-d9d923418e0b-3.exe is automatically launched at startup through a scheduled task named ac516c89-ffce-40ee-8006-d9d923418e0b-3.
  • ac516c89-ffce-40ee-8006-d9d923418e0b-2.exe is automatically launched at startup through a scheduled task named ac516c89-ffce-40ee-8006-d9d923418e0b-2.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\pricora
Uninstaller:
C:\Program Files\Pricora\Uninstall.exe /fromcontrolpanel=1
Size:
6.00 MB
Language:
English

Pricora Executable Details

Primary executable:
utils.exe
Name:
Pricora
Path:
C:\Program Files\pricora\utils.exe
MD5:
a75b85924ed1c5f1ee31855ff9ce13ac
SHA-1:
–
SHA-256:
–
Files installed by Pricora
File Type Filename MD5
EXE
756f238d9d267a4a550f792f5522c68e
EXE
utils.exe
Malware
a75b85924ed1c5f1ee31855ff9ce13ac
EXE
819f3f119741ea0f20a53dcfb7d7b2be
DLL
ae7838ec3447b31e0ca7ecf1119b1da6
DLL
b887e66a7850792cdf91ad9b16148328
EXE
38d5a3a91582699f43193e3d754dece9
EXE
f4bd7fbebedd73cc7a3b467d3bc7d688
EXE
90c77712976c0de19d64935346afdb43
EXE
a78ba70748627e0cdec3f56231ec2629
EXE
d68d26c1bd7689866e1d152c342b94f2