GorillaPrice is a browser add-on, which provides web users with various coupons, savings, and offers. GorillaPrice is valuable to many online shoppers because it helps to save money through a variety of deals and coupons. However, GorillaPrice is considered to be an adware application by security researchers. Numerous PC users are not aware of how GorillaPrice entered the computer. Therefore, GorillaPrice is categorized as GorillaPrice Virus by some computer users. GorillaPrice usually comes bundled with freeware or shareware programs.

When GorillaPrice invades the targeted computer, it displays annoying pop-up ads on the screen of the PC. These advertisements pose a threat to the attacked computer system if the PC user tempts to click on links. Malware creators are using unknown services like GorillaPrice to distribute various malware infections to vulnerable computers. GorillaPrice is also used by scammers to earn money from the pay-per-click technique. GorillaPrice also records the victim’s browsing actions on the hacked web browser. GorillaPrice keeps track of the affected computer user’s browsing habits, knows the most visited websites, and knows which products the victimized web user searches the most.


Generic6.PID [AVG]Win32.Risk.Agent.Pbpd [Tencent]RDN/Generic PUP.x!c2y [McAfee-GW-Edition]Adware.GorillaPrice.Win32.106 [Zillya]ApplicUnwnt [Comodo]Win32:Injector-COO [Trj] [Avast]TROJ_GEN.R00UC0OBF15 [TrendMicro-HouseCall]Trojan.Gen.2 [Symantec]Adware ( 004bb5b41 ) [K7AntiVirus]Adware/Agent.207872 [Avira]

More aliases (33)

Technical Details

File System Modifications

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98168995-CA43-4c33-BE81-99E6694468A4}SOFTWARE\Mozilla\Firefox\extensions, value: {a131ab52-77f3-4bd7-acc7-e2dfdfd298f0}Software\NetNucleousSOFTWARE\Wow6432Node\GorillaPriceSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{98068995-CA43-4c33-BE80-99E6694468A4}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\GorillaPriceSOFTWARE\Wow6432Node\Mozilla\Firefox\extensions, value: {a131ab52-77f3-4bd7-acc7-e2dfdfd298f0}SYSTEM\ControlSet001\services\GorillaPriceSYSTEM\ControlSet001\Services\GrillaPriceSYSTEM\ControlSet002\Services\GrillaPriceSYSTEM\CurrentControlSet\Services\GorillaPriceSYSTEM\CurrentControlSet\Services\GrillaPrice
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path} {a131ab52-77f3-4bd7-acc7-e2dfdfd298f0}{98168995-CA43-4c33-BE81-99E6694468A4}
Posted: August 1, 2013 | By
Threat Metric
Threat Level: 5/10
Detection Count: 57,794

