Home Malware Programs Adware Adware.Pricora

Adware.Pricora

Posted: July 29, 2013

Threat Metric

Ranking: 8,136
Threat Level: 2/10
Infected PCs: 122,942
First Seen: July 29, 2013
Last Seen: February 19, 2025
OS(es) Affected: Windows

Pricora Ads is an adware program distributed mainly towards residents of Europe, with its primary distribution vehicle consisting of the ever-popular software bundle. Different variants of Pricora Ads have been known to modify your Web browser in different ways, and, in some cases, even may not show any symptoms at all while being installed. However, the presence of Pricora Ads usually is detectable through additional browser advertisements. No matter what Pricora Ads does or doesn't do to your browser, deleting Pricora Ads with reliable anti-adware tools is recommended by malware experts for keeping the security and performance of your computer optimized.

Pricora Ads: the Advertising Hidden Inside Your Download

Pricora Ads may affect browsers in multiple regions throughout the world, but its current distribution model is pointed solidly at French-speaking citizens. Pricora Ads generally doesn't install itself as a separate program and requires the consensual download and installation of an unrelated product that happens to be bundled with Pricora Ads. In all current reports, malware experts have been unable to find cases where Pricora Ads announced its installation prior to the actual event, which leads to most victims only being aware of any problems once Pricora Ads starts showing its advertisements.

Pricora Ads currently is specific to the Chrome Web browser and has been known to show various different advertising functions throughout its development history. Common symptoms of Pricora Ads include Web page-injection attacks that add advertising banners to social network sites like Facebook, as well as adding keyword-based hyperlinks to third party offers. These modifications can't be disabled through Pricora Ads, and Pricora Ads also will, predictably, try to prevent itself from being removed. This last attribute, in particular, causes malware experts to consider Pricora Ads a low-level PC threat that may be a danger to your computer – or, at a minimum, an unnecessary performance hog.

Alleviating Your Computer of Pricora Ads – Whether or not You See Any Actual Pricora Ads

Pricora Ads doesn't always modify Chrome to display its advertisements, which may be an intentional attempt to conceal itself, or merely a coding error on the part of its developers. If you're in the habit of installing software from sources that may include adware bundles (which malware experts never would recommend), you should use anti-malware products to detect potential Pricora Ads installations and, of course, remove Pricora Ads when it's needed.

Obviously, Pricora Ads is mostly a worry for residents of France and neighboring regions of Europe, but that doesn't mean Pricora Ads is incapable of modifying Chrome for PCs located in the United States or elsewhere. Avoiding risky download sources is a bare minimum security protocol that's always encouraged for keeping your PC protected. Even if doing so is impractical or impossible for any of various reasons, malware researchers still would note that scanning a bundle with a good anti-malware product should be enough to detect a possible Pricora Ads installer before the installation happens.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\Pricora 10.4\Pricora 10.4-codedownloader.exe File name: Pricora 10.4-codedownloader.exe
Size: 505.34 KB (505344 bytes)
MD5: 8d5384f9954d751ac63b0b22f154629b
Detection count: 119
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Pricora 10.4
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES(x86)%\Pricora 1.4\Pricora 1.4-updater.exe File name: Pricora 1.4-updater.exe
Size: 391.68 KB (391680 bytes)
MD5: 795dd3cd3bb21c3bd2f0d4ef393c758d
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Pricora 1.4
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES%\Pricora 10.4\Pricora 10.4-bho.dll File name: Pricora 10.4-bho.dll
Size: 495.1 KB (495104 bytes)
MD5: 4d069a6ef22f7a338be1c24588f49fe0
Detection count: 87
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Pricora 10.4
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES(x86)%\Pricora 1.4\978c0b23-2b4e-4c29-ba6b-19685ebc6dee-3.exe File name: 978c0b23-2b4e-4c29-ba6b-19685ebc6dee-3.exe
Size: 1.86 MB (1861120 bytes)
MD5: e83ef307f8a7148a138e16b113c9c136
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Pricora 1.4
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES(x86)%\Pricora 1.4\Pricora 1.4-codedownloader.exe File name: Pricora 1.4-codedownloader.exe
Size: 477.69 KB (477696 bytes)
MD5: da9c7d4b561652f7de27ad1c7feed8d3
Detection count: 83
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Pricora 1.4
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES(x86)%\Pricora 1.4\Pricora 1.4-bho64.dll File name: Pricora 1.4-bho64.dll
Size: 660.99 KB (660992 bytes)
MD5: cc83219919601eecf24dc1c43be0d472
Detection count: 82
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Pricora 1.4
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES(x86)%\Pricora 10.4\Pricora 10.4-bho64.dll File name: Pricora 10.4-bho64.dll
Size: 660.99 KB (660992 bytes)
MD5: 259fea20ed8b8a53a8d81f9c52e7fe94
Detection count: 44
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Pricora 10.4
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES(x86)%\Pricora\Pricora-codedownloader.exe File name: Pricora-codedownloader.exe
Size: 477.69 KB (477696 bytes)
MD5: ae13905a989f2649067a5f4db8c2d41a
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Pricora
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES(x86)%\Pricora\ac516c89-ffce-40ee-8006-d9d923418e0b-2.exe File name: ac516c89-ffce-40ee-8006-d9d923418e0b-2.exe
Size: 334.33 KB (334336 bytes)
MD5: 3ecdc1f73936a74daf935bc4b22957ba
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Pricora
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES(x86)%\Pricora\ac516c89-ffce-40ee-8006-d9d923418e0b-3.exe File name: ac516c89-ffce-40ee-8006-d9d923418e0b-3.exe
Size: 1.86 MB (1861120 bytes)
MD5: ed9fa6b460d486b943acf964643b6acc
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Pricora
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES(x86)%\Pricora\Pricora-bho64.dll File name: Pricora-bho64.dll
Size: 660.99 KB (660992 bytes)
MD5: b0abb781a38693057d91805078c1a35f
Detection count: 12
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Pricora
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES(x86)%\pricora 10.4\pricora 10.4-bg.exe File name: pricora 10.4-bg.exe
Size: 557.56 KB (557568 bytes)
MD5: edf522064174d77dfc604291cb6c4ad8
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\pricora 10.4
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES%\Pricora 1.1\65aac781-686f-47b0-b4aa-6f93c7c3543c-2.exe File name: 65aac781-686f-47b0-b4aa-6f93c7c3543c-2.exe
Size: 358.91 KB (358912 bytes)
MD5: 8c1996392c013d14fa2d34b401fdbdd6
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Pricora 1.1
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES(x86)%\Pricora 1.1\Pricora 1.1-bho64.dll File name: Pricora 1.1-bho64.dll
Size: 949.24 KB (949248 bytes)
MD5: bfa9492311f4a284877a675d78dfa1e2
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Pricora 1.1
Group: Malware file
Last Updated: April 1, 2020
%PROGRAMFILES(x86)%\Pricora 1.4\Pricora 1.4-firefoxinstaller.exe File name: Pricora 1.4-firefoxinstaller.exe
Size: 947.2 KB (947200 bytes)
MD5: 9821555d878d2d1e14be36a9c9b611f3
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Pricora 1.4
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES%\Pricora 4.1\Pricora 4.1-codedownloader.exe File name: Pricora 4.1-codedownloader.exe
Size: 984.57 KB (984576 bytes)
MD5: edc02cecca56034c0e02155ccba9c64c
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Pricora 4.1
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES%\Pricora 4.1\Pricora 4.1-enabler.exe File name: Pricora 4.1-enabler.exe
Size: 854.52 KB (854528 bytes)
MD5: 57c3025c279e6a6d9bf99ca8bbada4c5
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Pricora 4.1
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES(x86)%\Pricora 1.4\Uninstall.exe File name: Uninstall.exe
Size: 78.84 KB (78848 bytes)
MD5: b1f95ec8168236e7efb8e487ef4c7905
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Pricora 1.4
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES%\Pricora 4.1\Pricora 4.1-chromeinstaller.exe File name: Pricora 4.1-chromeinstaller.exe
Size: 460.8 KB (460800 bytes)
MD5: 0f855c2864c04893fd828b90a6d385af
Detection count: 4
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Pricora 4.1
Group: Malware file
Last Updated: June 3, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{11111111-1111-1111-1111-110311541197}{11111111-1111-1111-1111-110311541199}{22222222-2222-2222-2222-220322542297}{22222222-2222-2222-2222-220322542299}{44444444-4444-4444-4444-440344544497}{44444444-4444-4444-4444-440344544499}{55555555-5555-5555-5555-550355545597}{55555555-5555-5555-5555-550355545599}{66666666-6666-6666-6666-660366546697}{66666666-6666-6666-6666-660366546699}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Pricora 1.1Software\AppDataLow\Software\Pricora 2.0SOFTWARE\Classes\CrossriderApp0035497.BHOSOFTWARE\Classes\CrossriderApp0035497.BHO.1SOFTWARE\Classes\CrossriderApp0035497.SandboxSOFTWARE\Classes\CrossriderApp0035497.Sandbox.1SOFTWARE\Classes\CrossriderApp0035499.BHOSOFTWARE\Classes\CrossriderApp0035499.BHO.1SOFTWARE\Classes\CrossriderApp0035499.SandboxSOFTWARE\Classes\CrossriderApp0035499.Sandbox.1Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Pricora 10.3Software\DeealSoftware\InstalledBrowserExtensions\Corporate Inc\35497Software\InstalledBrowserExtensions\Corporate Inc\35499Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311541197}Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311541199}Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110511501105}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{03ea9c34-31b2-42f3-bf3c-e5bbf252cf2d}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{04ecd17d-e1b3-4eda-b80d-de18f1ef5bd5}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{32f91432-f9a5-435a-84e2-225afcf4b836}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3aaa990b-b136-4424-9442-84aa3320fc0b}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4560b0a1-40d9-4fc8-bc6e-501ab89ebfb1}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5ccff5d3-96a1-492e-8b44-2a4fbf9c9188}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65968e1f-875f-4468-b638-b52c8563ebb1}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{66fe73c2-238d-4ebf-a9fb-9693306cd130}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{736edbef-747a-4f98-bafc-3321a1dc5150}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7cd495d4-1bd6-49da-8bad-42c78a4f6b2f}SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Pricora 10.3-bg.exeSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110311541197}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110311541199}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311541197}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311541199}SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pricora 1.1SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pricora 2.0SOFTWARE\Pricora 1.1SOFTWARE\Pricora 2.0SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{03ea9c34-31b2-42f3-bf3c-e5bbf252cf2d}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{04ecd17d-e1b3-4eda-b80d-de18f1ef5bd5}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{32f91432-f9a5-435a-84e2-225afcf4b836}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3aaa990b-b136-4424-9442-84aa3320fc0b}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4560b0a1-40d9-4fc8-bc6e-501ab89ebfb1}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5ccff5d3-96a1-492e-8b44-2a4fbf9c9188}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65968e1f-875f-4468-b638-b52c8563ebb1}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{66fe73c2-238d-4ebf-a9fb-9693306cd130}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{736edbef-747a-4f98-bafc-3321a1dc5150}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7cd495d4-1bd6-49da-8bad-42c78a4f6b2f}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Pricora 10.3-bg.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Pricora 1.1SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Pricora 2.0SOFTWARE\Wow6432Node\Pricora 1.1SOFTWARE\Wow6432Node\Pricora 10.3SOFTWARE\Wow6432Node\Pricora 2.0

Additional Information

The following directories were created:
%PROGRAMFILES%\Pricora 1.1%PROGRAMFILES%\Pricora 10.3%PROGRAMFILES%\Pricora 2.0%PROGRAMFILES(X86)%\Pricora 1.1%PROGRAMFILES(X86)%\Pricora 2.0%USERPROFILE%\AppData\LocalLow\Pricora 1.1%USERPROFILE%\AppData\LocalLow\Pricora 2.0%appdata%\Pricora 2.0
The following URL's were detected:
Pricora
Loading...