Adware.Pricemeter

By GoldSparrow in Adware

Threat Scorecard

Popularity Rank: 8,019
Threat Level: 20 % (Normal)
Infected Computers: 72,388
First Seen: April 4, 2014
Last Seen: April 9, 2026
OS(es) Affected: Windows

Adware.Pricemeter Image

Adware.Pricemeter is adware that may integrate itself into a computer bundled with other free programs downloaded from the Internet. Adware.Pricemeter may display numerous unwanted pop-up ads, which may contain deals, offers and discount coupons, on the computer. If the computer user clicks on the pop-up ads delivered by Adware.Pricemeter, it may continuously divert the PC user to unreliable websites that may be commercial. Adware.Pricemeter may advertise unknown websites, products and services. Adware.Pricemeter may also collect details about the PC user's surfing activity, search requests and websites he is visiting. These details may be valuable for marketing campaigns, especially, displaying targeted ads.

SpyHunter Detects & Remove Adware.Pricemeter

File System Details

Adware.Pricemeter may create the following file(s):
# File Name MD5 Detections
1. pricemeter.exe.vir d0635b097ff6622c6d1a685ebf50a50a 1,029
2. pricemeterw.exe.vir 9043dbe16d879c5f1403b2e6f9db1b85 610
3. PriceMeterUpdateVer.exe 5b8c171f34a454c574b408b9f7c56c91 331
4. trz7AFF.tmp 731d5021cc80657598f954a9007afd94 205
5. pricemeterd.exe.vir c96477ff16bb1b3885d125b2d4cb870b 58
6. uninst.exe 3d0765678274c38ed0dcc6d9581cc716 29
7. uninst.exe.vir abaca744eeee15157d2a1086fd4d1deb 21
8. pricemeter.exe 0742525dddb885ee0f50e92511d112e6 7
9. pricemeterd.exe 1dde7b5c2f8996fed299cd7a40505bf5 2
10. update~1.exe e0badd30b95a67576f7657ebdb4c7b79 1
11. PriceMeterLiveUpdate.exe efc13c7124f72000915d0119a980b27b 1
12. UpdateTask.exe 0bc06a11e719ff1f9fdd9896df5532b6 1
13. tmp.exe 3996fcad36ff46031ebe1956bb5415c0 1
14. PriceMeterExpressIE.dll dd511f3553e06d82d2f19e450365c815 1
More files

Registry Details

Adware.Pricemeter may create the following registry entry or registry entries:
CLSID
{00A154AE-6C33-4F1E-9057-242350540936}
{0DA40B75-6FEE-49BF-BDDE-E2598E786C8C}
{126C78A0-36E7-4697-A3AB-32706144398B}
{12FF3C6A-56FB-4B3E-858D-0877CD39B025}
{15DDC42D-13A8-432B-B31D-36A8FB50758F}
{1CD6E593-ABBF-45AC-9F94-21E8F1BDC10B}
{2B584AEB-6C8F-4238-89E4-850CFD7B2065}
{30A2947A-664F-440B-908D-E0FEDFEAE5DE}
{30D1E30D-B7F5-4C7A-8EDA-9F02966538A8}
{34BCEF11-CE38-48EC-9D08-5CC0557E8887}
{3B06CDDC-2ECB-45DC-B565-D41CC095BE40}
{3FD7EB0A-96B6-43E0-9D94-44929F3FD1B3}
{41C35ADE-DEDA-439F-8140-D53F2C76C963}
{4211E851-747F-4470-923D-6EF683EE79CA}
{45F8961E-1314-421E-9F00-BDDE18CF8EA0}
{4825ACAD-F495-4CDD-9603-9C91BABB2B88}
{4D2525EE-3B7B-44C6-8960-77843DBC67A3}
{553D53FA-59F3-44D0-ABC4-58F290DB70DC}
{59E8D94C-7A20-41AD-83CF-3E156D3AEB2F}
{5B60D1C0-453A-485D-AE91-61FAC9203719}
{5EF4F032-2DB4-48E9-B5A9-ADAC095E096A}
{6FE5D7AF-5812-4E08-BA22-9805FFE9F429}
{74930D00-2198-46FE-B6BC-FEEC60C666C9}
{781999CA-3F51-4A56-94CA-0C8A8E0100AF}
{89449F37-4AB2-46ED-A566-BB3A7797701B}
{8D73A258-9787-4AE7-9232-41036673FD0E}
{9D24562E-40EC-4E46-B57C-700352059B55}
{A39B7A1C-F58A-4C22-9015-E2C8EF1C31BA}
{AB121BE6-2299-4B9B-8545-9104ABA20717}
{B1F29F0C-2EC8-487B-97C2-8B8FEA6CEF14}
{C0756D99-64A1-4332-B783-A5A1B571D431}
{C0833ED4-281E-441C-B004-43752001A629}
{CF0A778A-DDA0-4492-9804-EF38C9A9F1A5}
{D1C6444C-CC06-4060-A486-736DEAFD9C16}
{D8746A3A-A372-4C8B-96E5-B58F6474EB19}
{DC330A23-4FBE-414C-AB3D-1C42056E5245}
{DCD71BA3-32C2-455F-8DF0-37EE26E0C395}
{E9C30691-5CE7-46BF-B940-C0125DA9E05B}
{F509ADC2-B40E-470F-A7B7-45191486B5CB}
{F654B5BE-1A20-48A6-BED0-7C9E29CB8099}
SOFTWARE\Classes\AppID\PriceMeterLiveUpdate.exe
SOFTWARE\Classes\AppID\{126C78A0-36E7-4697-A3AB-32706144398B}
SOFTWARE\Classes\AppID\{8D73A258-9787-4AE7-9232-41036673FD0E}
SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.updatepm.oneclickctrl.9
SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.updatepm.update3webcontrol.3
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{30D1E30D-B7F5-4C7A-8EDA-9F02966538A8}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{89449F37-4AB2-46ED-A566-BB3A7797701B}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F509ADC2-B40E-470F-A7B7-45191486B5CB}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PriceMeterLiveUpdate.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Price Meter Updater
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{89449F37-4AB2-46ED-A566-BB3A7797701B}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F509ADC2-B40E-470F-A7B7-45191486B5CB}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{89449F37-4AB2-46ED-A566-BB3A7797701B}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F509ADC2-B40E-470F-A7B7-45191486B5CB}
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PriceMeterW
SOFTWARE\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=3
SOFTWARE\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=9
Software\PriceMeter
SOFTWARE\PriceMeterLiveUpdate
Software\PriceMeterUpdater
SOFTWARE\Wow6432Node\Classes\AppID\PriceMeterLiveUpdate.exe
SOFTWARE\Wow6432Node\Classes\AppID\{126C78A0-36E7-4697-A3AB-32706144398B}
SOFTWARE\Wow6432Node\Classes\AppID\{8D73A258-9787-4AE7-9232-41036673FD0E}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{30D1E30D-B7F5-4C7A-8EDA-9F02966538A8}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{89449F37-4AB2-46ED-A566-BB3A7797701B}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F509ADC2-B40E-470F-A7B7-45191486B5CB}
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PriceMeterLiveUpdate.exe
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{89449F37-4AB2-46ED-A566-BB3A7797701B}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F509ADC2-B40E-470F-A7B7-45191486B5CB}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{89449F37-4AB2-46ED-A566-BB3A7797701B}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{F509ADC2-B40E-470F-A7B7-45191486B5CB}
SOFTWARE\Wow6432Node\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=3
SOFTWARE\Wow6432Node\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=9
SOFTWARE\Wow6432Node\PriceMeterLiveUpdate
SYSTEM\ControlSet001\services\pricemeterliveUpdate
SYSTEM\ControlSet001\services\pricemeterliveUpdatem
SYSTEM\CurrentControlSet\services\pricemeterliveUpdate
SYSTEM\CurrentControlSet\services\pricemeterliveUpdatem

Directories

Adware.Pricemeter may create the following directory or directories:

%ALLUSERSPROFILE%\Application Data\PriceMeterLiveUpdate
%ALLUSERSPROFILE%\PriceMeterLiveUpdate
%AppData%\Microsoft\Windows\Start Menu\Programs\PriceMeter
%AppData%\PriceMeterUpdater
%LOCALAPPDATA%\PriceMeter
%LOCALAPPDATA%\PriceMeterLiveUpdate
%PROGRAMFILES%\PriceMeterLiveUpdate
%PROGRAMFILES(x86)%\PriceMeterLiveUpdate
%UserProfile%\Local Settings\Application Data\PriceMeter
%UserProfile%\Local Settings\Application Data\PriceMeterLiveUpdate
%UserProfile%\Start Menu\Programs\PriceMeter

Analysis Report

General information

Family Name: Adware.Pricemeter
Signature status: No Signature

Known Samples

MD5: c65466321b74270ff5993a9c8d5bdf9d
SHA1: 3abb2a0f6a1c0155f68ba0e92aec72a0aac9a3df
SHA256: 105B6F4E0A811B318DBBA30D704678D90986BF18C5D59F31FD36B5D14034B2D5
File Size: 800.77 KB, 800768 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Pricé Metér
File Description Pricé Metér
File Version 1.1.6.1
Internal Name pm.exe
Legal Copyright Copyright © 2014 Price Metér
Legal Trademarks [283A699F] [default:default] Price Metér is a trademark or registered trademark in the U.S. and/or other countries.
Original Filename pm.exe
Product Name Pricé Metér
Product Version 1.1.6.1

File Traits

  • x86

Block Information

Total Blocks: 2,433
Potentially Malicious Blocks: 16
Whitelisted Blocks: 2,127
Unknown Blocks: 290

Visual Map

0 ? 0 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? ? ? 0 ? 0 ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? ? ? 0 ? 0 ? ? 1 ? 0 ? 0 0 0 0 0 0 ? ? ? ? 0 ? 0 ? ? 0 ? 0 ? x ? ? ? ? 0 ? ? ? ? 0 0 ? ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? x ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? ? ? ? ? 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 x 0 ? ? 0 ? ? ? ? ? ? ? 0 0 0 0 x x ? x 0 ? ? ? ? ? ? ? 0 ? 0 x 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 1 0 3 1 1 ? 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 2 3 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 2 2 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? ? 0 ? 0 ? ? 0 ? ? ? ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? ? 0 ? 0 0 ? ? ? 0 0 ? ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 ? ? 0 ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? 1 ? ? 0 0 0 0 0 ? ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? x ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? 0 0 0 ? x x ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 x x x ? ? 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 1 0 3 1 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 2 3 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 2 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

1 Comment

C:/users/AppData/Local/PriceMeter/libcef.dll

Trending

Most Viewed

Loading...