Home Malware Programs Adware GorillaPrice

GorillaPrice

Posted: August 1, 2013

Threat Metric

Ranking: 19,464
Threat Level: 5/10
Infected PCs: 101,518
First Seen: August 1, 2013
Last Seen: December 27, 2024
OS(es) Affected: Windows

GorillaPrice is a browser add-on, which provides web users with various coupons, savings, and offers. GorillaPrice is valuable to many online shoppers because it helps to save money through a variety of deals and coupons. However, GorillaPrice is considered to be an adware application by security researchers. Numerous PC users are not aware of how GorillaPrice entered the computer. Therefore, GorillaPrice is categorized as GorillaPrice Virus by some computer users. GorillaPrice usually comes bundled with freeware or shareware programs. When GorillaPrice invades the targeted computer, it displays annoying pop-up ads on the screen of the PC. These advertisements pose a threat to the attacked computer system if the PC user tempts to click on links. Malware creators are using unknown services like GorillaPrice to distribute various malware infections to vulnerable computers. GorillaPrice is also used by scammers to earn money from the pay-per-click technique. GorillaPrice also records the victim's browsing actions on the hacked web browser. GorillaPrice keeps track of the affected computer user's browsing habits, knows the most visited websites, and knows which products the victimized web user searches the most.

Aliases

Generic6.PID [AVG]RDN/Generic PUP.x!c2y [McAfee-GW-Edition]ApplicUnwnt [Comodo]Win32:Injector-COO [Trj] [Avast]Trojan.Gen.2 [Symantec]Adware ( 004bb5b41 ) [K7AntiVirus]Generic PUA NL [Sophos]WS.Reputation.1 [Symantec]Win32:Dropper-gen [Drp] [Avast]Generic6.MGL [AVG]Artemis!F0095C66445B [McAfee]BehavesLike.Win32.BadFile.ch [McAfee-GW-Edition]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\GorillaPrice\WatGorp.exe File name: WatGorp.exe
Size: 70.14 KB (70144 bytes)
MD5: 770616105a224fed755977eb86de74e4
Detection count: 6,415
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\GorillaPrice
Group: Malware file
Last Updated: December 7, 2021
%PROGRAMFILES%\GorillaPrice\GorillaPrice.exe File name: GorillaPrice.exe
Size: 624.12 KB (624128 bytes)
MD5: c7905e4b74338875c3e83984f4bc5921
Detection count: 6,399
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\GorillaPrice
Group: Malware file
Last Updated: November 14, 2016
%PROGRAMFILES(x86)%\GorillaPrice\GPI64Tool.exe File name: GPI64Tool.exe
Size: 262.65 KB (262656 bytes)
MD5: 2fee07aa67233c4206bb0ff3b35c0562
Detection count: 3,361
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\GorillaPrice
Group: Malware file
Last Updated: November 3, 2019
C:\Program Files (x86)\NetNucleous\GorillaPrice\GPCheck.exe File name: GPCheck.exe
Size: 1.58 MB (1580152 bytes)
MD5: 97e0a4ea3f659ce172398f78d9db8716
Detection count: 2,408
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\NetNucleous\GorillaPrice\GPCheck.exe
Group: Malware file
Last Updated: August 23, 2024
C:\Program Files (x86)\Windows NT\Accessories\WinUtilityHelper\wuhelper.exe File name: wuhelper.exe
Size: 139.77 KB (139776 bytes)
MD5: ed39bba17f83ea8433f7059f36a887f6
Detection count: 1,084
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\Windows NT\Accessories\WinUtilityHelper\wuhelper.exe
Group: Malware file
Last Updated: January 2, 2023
%PROGRAMFILES(x86)%\Windows NT\Accessories\bootmanager\bootmanager.exe File name: bootmanager.exe
Size: 107.52 KB (107520 bytes)
MD5: fef01c38e7eab2d03baf57f4c35729b9
Detection count: 553
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Windows NT\Accessories\bootmanager
Group: Malware file
Last Updated: October 3, 2017
%PROGRAMFILES(x86)%\Windows NT\Accessories\RuntimeManager\runtimemanager.exe File name: runtimemanager.exe
Size: 103.93 KB (103936 bytes)
MD5: 09a41ac411d3436e186a17e7ff788dc1
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Windows NT\Accessories\RuntimeManager
Group: Malware file
Last Updated: October 3, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{98168995-CA43-4c33-BE81-99E6694468A4}Regexp file mask%ALLUSERSPROFILE%\Microsoft\Windows\NetworkCacheMan\ntcache.exe%ALLUSERSPROFILE%\Microsoft\Windows\NetworkCacheManager\ntcache.exe%APPDATA%\Microsoft\Windows\UserChecker\uchecker.exe%appdata%\Mozilla\Firefox\{a131ab52-77f3-4bd7-acc7-e2dfdfd298f0}.xpiHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\NetNucleousSOFTWARE\GrillaPriceSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98168995-CA43-4c33-BE81-99E6694468A4}SOFTWARE\Mozilla\Firefox\extensions\{a131ab52-77f3-4bd7-acc7-e2dfdfd298f0}Software\NetNucleousSOFTWARE\Wow6432Node\GorillaPriceSOFTWARE\Wow6432Node\GrillaPriceSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{98068995-CA43-4c33-BE80-99E6694468A4}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\GorillaPriceSOFTWARE\Wow6432Node\Mozilla\Firefox\extensions\{a131ab52-77f3-4bd7-acc7-e2dfdfd298f0}SYSTEM\ControlSet001\services\GorillaPriceSYSTEM\ControlSet001\Services\GrillaPriceSYSTEM\ControlSet002\Services\GrillaPriceSYSTEM\CurrentControlSet\Services\GorillaPriceSYSTEM\CurrentControlSet\Services\GrillaPrice

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\GorillaPrice%ALLUSERSPROFILE%\Microsoft\Windows\MKStat%ALLUSERSPROFILE%\Microsoft\Windows\MKeeperStat%PROGRAMFILES%\GrillaPrice%PROGRAMFILES(X86)%\GorillaPrice%PROGRAMFILES(x86)%\GrillaPrice%PROGRAMFILES(x86)%\Windows Media Player\grillaprice%ProgramFiles%\GorillaPrice
The following URL's were detected:
GorillaPrice
Loading...