PricePeep

By LoneStar in Adware
Published:
Last updated:

Threat Scorecard

Popularity Rank: 4,802
Threat Level: 20 % (Normal)
Infected Computers: 28,005
First Seen: December 3, 2012
Last Seen: October 3, 2026
OS(es) Affected: Windows

PricePeep is an adware application that shows its own ads on eBay, Amazon and other websites. These advertisements will be illustrated as boxes carrying various coupons that are available or as underlined keywords, which when clicked will display an advertisement that declares it is brought to the computer user by PricePeep. PricePeep can be installed on the affected computer by another application that had bundled in its installer the PricePeep adware. Program installers of some apps include optional installs, such as the particular PricePeep. Internet users should be very careful what they agree to install. They should always select for the custom installation and deselect anything that is not known, especially optional programs that they never wanted to download and install on their computer systems.

SpyHunter Detects & Remove PricePeep

File System Details

PricePeep may create the following file(s):
# File Name MD5 Detections
1. pricepeep.dll 572617912b3b0cc34af0abe6bd1a7c7d 49
2. PricePeepSetup.exe 83936f4f95dabc176f8b0e357784dace 2

Registry Details

PricePeep may create the following registry entry or registry entries:
CLSID
{1B97A696-5576-43AC-A73B-E1D2C78F21E8}
{38A066B0-DD5F-4226-AC4F-6A27C1BFB892}
{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408}
{75BF416E-4326-45B5-8A2D-AE32D05B930B}
{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}
File name without path
https_static.pricepeep00.pricepeep.net_0.localstorage
https_static.pricepeep00.pricepeep.net_0.localstorage-journal
static.pricepeep00.pricepeep[1].xml
Regexp file mask
%LOCALAPPDATA%\PricePeep.exe
Software\AppDataLow\Software\PricePeep
SOFTWARE\Classes\AppID\PricePeep.DLL
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\pricepeep.net
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\static.pricepeep00.pricepeep.net
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\pricepeep.net
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\static.pricepeep00.pricepeep.net
SOFTWARE\Classes\PricePeep.PricePeepBho
SOFTWARE\Classes\PricePeep.PricePeepBho.1
SOFTWARE\Classes\Wow6432Node\AppID\PricePeep.DLL
Software\Microsoft\Internet Explorer\DOMStorage\pricepeep.net
SOFTWARE\Microsoft\Internet Explorer\DOMStorage\static.pricepeep00.pricepeep.net
SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pricepeep.net
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}
SOFTWARE\Wow6432Node\Classes\AppID\PricePeep.DLL
SOFTWARE\Wow6432Node\Microsoft\Tracing\PricePeepSetup_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\PricePeepSetup_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}

Directories

PricePeep may create the following directory or directories:

%PROGRAMFILES%\PricePeep
%PROGRAMFILES(x86)%\PricePeep

URLs

PricePeep may call the following URLs:

PricePeep

Analysis Report

General information

Family Name: Adware.PricePeep
Signature status: Self Signed

Known Samples

MD5: f661ffec177f6158af6d98dc5336baab
SHA1: 4ffb1a90b200f234125150fefd1e6ac3b89af60b
SHA256: 59471034DA2A7D41D2723749BB7C8047CEA09627D1B7D0818D89EAF2C8662DDE
File Size: 449.30 KB, 449304 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Digital Signatures

Signer Root Status
betwikx VeriSign Class 3 Code Signing 2010 CA Self Signed

Files Modified

File Attributes
c:\program files (x86)\pricepeep\installer.ico Generic Write,Read Attributes
c:\program files (x86)\pricepeep\pricepeep.crx Generic Write,Read Attributes
c:\program files (x86)\pricepeep\pricepeep.dll Generic Write,Read Attributes
c:\program files (x86)\pricepeep\uninstall.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc40ea.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsc40ea.tmp\inetc.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc40ea.tmp\inetc.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsc40ea.tmp\o.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc40ea.tmp\o.txt_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsc40ea.tmp\system.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\nsc40ea.tmp\system.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsc40ea.tmp\uac.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc40ea.tmp\uac.dll Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pricepeep::installparameters RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\ctf\msutb::left ঔ RegNtPreCreateKey
Show More
HKCU\software\microsoft\ctf\msutb::top RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n  �v����Bx%�(�1`1�1HO@V�A��H[uN$a$b"hk`k�q�P���!���� ���3������m���V�$�8���l��&M�~B1_�i������A*�"C��| RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n! �v����Bx%�(�1`1�1HO@V�A��H[uN$a$b"he�vk`k�q�P���!���� ���3������m���V�$�8���l��&M�~B1_�i������A*�"C��| RegNtPreCreateKey
HKLM\software\wow6432node\google\chrome\extensions\licjnkifamhpbaefhdpacpmihicfbomb::path C:\Program Files (x86)\PricePeep\pricepeep.crx RegNtPreCreateKey
HKLM\software\wow6432node\google\chrome\extensions\licjnkifamhpbaefhdpacpmihicfbomb::version 2.1.132.0 RegNtPreCreateKey
HKLM\software\wow6432node\google\chrome\extensions\licjnkifamhpbaefhdpacpmihicfbomb::path C:\Program Files (x86)\PricePeep\pricepeep.crx RegNtPreCreateKey
HKLM\software\wow6432node\google\chrome\extensions\licjnkifamhpbaefhdpacpmihicfbomb::version 2.1.132.0 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pricepeep::lastversionie 9.11.19041.0 RegNtPreCreateKey
HKLM\software\classes\appid\{38a066b0-dd5f-4226-ac4f-6a27c1bfb892}:: PricePeep RegNtPreCreateKey
HKLM\software\classes\appid\dealscout.dll::appid {38A066B0-DD5F-4226-AC4F-6A27C1BFB892} RegNtPreCreateKey
HKLM\software\classes\pricepeep.pricepeepbho.1:: PricePeep RegNtPreCreateKey
HKLM\software\classes\pricepeep.pricepeepbho.1\clsid:: {FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} RegNtPreCreateKey
HKLM\software\classes\pricepeep.pricepeepbho:: PricePeep RegNtPreCreateKey
HKLM\software\classes\pricepeep.pricepeepbho\clsid:: {FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} RegNtPreCreateKey
HKLM\software\classes\pricepeep.pricepeepbho\curver:: PricePeep.PricePeepBho.1 RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{fd6d90c0-e6ee-4bc6-b9f7-9ed319698007}:: PricePeep RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{fd6d90c0-e6ee-4bc6-b9f7-9ed319698007}\progid:: PricePeep.PricePeepBho.1 RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{fd6d90c0-e6ee-4bc6-b9f7-9ed319698007}\versionindependentprogid:: PricePeep.PricePeepBho RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{fd6d90c0-e6ee-4bc6-b9f7-9ed319698007}\inprocserver32:: C:\Program Files (x86)\PricePeep\pricepeep.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{fd6d90c0-e6ee-4bc6-b9f7-9ed319698007}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{fd6d90c0-e6ee-4bc6-b9f7-9ed319698007}\typelib:: {3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408} RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\explorer\browser helper objects\{fd6d90c0-e6ee-4bc6-b9f7-9ed319698007}:: PricePeep RegNtPreCreateKey
HKLM\software\classes\typelib\{3bf3ded5-0fc8-4207-ac09-aa7b5af4e408}\1.0:: PricePeep 1.0 Type Library RegNtPreCreateKey
HKLM\software\classes\typelib\{3bf3ded5-0fc8-4207-ac09-aa7b5af4e408}\1.0\flags:: 0 RegNtPreCreateKey
HKLM\software\classes\typelib\{3bf3ded5-0fc8-4207-ac09-aa7b5af4e408}\1.0\0\win32:: C:\Program Files (x86)\PricePeep\pricepeep.dll RegNtPreCreateKey
HKLM\software\classes\typelib\{3bf3ded5-0fc8-4207-ac09-aa7b5af4e408}\1.0\helpdir:: C:\Program Files (x86)\PricePeep RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{1b97a696-5576-43ac-a73b-e1d2c78f21e8}:: IJigsawExternal RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{1b97a696-5576-43ac-a73b-e1d2c78f21e8}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{1b97a696-5576-43ac-a73b-e1d2c78f21e8}\typelib:: {3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{1b97a696-5576-43ac-a73b-e1d2c78f21e8}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{1b97a696-5576-43ac-a73b-e1d2c78f21e8}:: IJigsawExternal RegNtPreCreateKey
HKLM\software\classes\interface\{1b97a696-5576-43ac-a73b-e1d2c78f21e8}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{1b97a696-5576-43ac-a73b-e1d2c78f21e8}\typelib:: {3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408} RegNtPreCreateKey
HKLM\software\classes\interface\{1b97a696-5576-43ac-a73b-e1d2c78f21e8}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{75bf416e-4326-45b5-8a2d-ae32d05b930b}:: IHttpRequestEvent RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{75bf416e-4326-45b5-8a2d-ae32d05b930b}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{75bf416e-4326-45b5-8a2d-ae32d05b930b}\typelib:: {3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{75bf416e-4326-45b5-8a2d-ae32d05b930b}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{75bf416e-4326-45b5-8a2d-ae32d05b930b}:: IHttpRequestEvent RegNtPreCreateKey
HKLM\software\classes\interface\{75bf416e-4326-45b5-8a2d-ae32d05b930b}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{75bf416e-4326-45b5-8a2d-ae32d05b930b}\typelib:: {3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408} RegNtPreCreateKey
HKLM\software\classes\interface\{75bf416e-4326-45b5-8a2d-ae32d05b930b}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pricepeep::displayicon C:\Program Files (x86)\PricePeep\installer.ico RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pricepeep::displayname PricePeep RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pricepeep::displayversion 2.1.132.0 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pricepeep::uninstallstring C:\Program Files (x86)\PricePeep\uninstall.exe RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pricepeep::publisher betwikx LLC RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pricepeep::urlinfoabout http://www.getpricepeep.com/ RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n$ �v����Bx%�(�,=�1`1�1HO@V�A��H[uN$N�a$b"he�vk`k�qy�9�P���!���� ���3������m���V�$�8���l��&M�~B1_�i������A*�"C��| RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n$ �v����Bx%�(�,=�1`1�1HO@V�A��H[uN$N�a$b"he�vk`k�qy�9�P���!���� ���3������m���V�$�8���l��&M�~�B1_`�V�i������A*�"C��| RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n% �v ������Bx%�(�,=�1`1�1HO@V�A��H[uN$N�a$b"he�vk`k�qy�9�P���!���� ���3������m���V�$�8���l��&M�~�B1_`�V�i������A*�"C��| RegNtPreCreateKey

Windows API Usage

Category API
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetQueryOption
  • InternetReadFile