Home Malware Programs Adware PriceCongress

PriceCongress

Posted: September 29, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 1,052
First Seen: August 11, 2014
Last Seen: July 4, 2023
OS(es) Affected: Windows


PriceCongress is an advertising platform and program that may be installed through the loading of random freeware or bundled software applications. In such a case, PriceCongress and its associated files or plugins may be loaded without the knowledge of the computer user. Once loaded, PriceCongress is apt to loading several advertisements that attempt to offer ways to supposedly save money by shopping on the internet. The use of PriceCongress ads may cause unwanted redirects to other sites or pages that attempt to offer other ways of supposedly saving money on shopping sites. Stopping the annoyances and interruptions causes by PriceCongress ads may require use of an antispyware tool to safely detect and remove PriceCongress.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\HomeTab\WRemoteUpdater.exe File name: WRemoteUpdater.exe
Size: 12.86 KB (12864 bytes)
MD5: eed15aaf74a7846dfa9298e123e07434
Detection count: 105
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\HomeTab\WRemoteUpdater.exe
Group: Malware file
Last Updated: August 31, 2023
%PROGRAMFILES(x86)%\PriceCongress\WConnectorSockets.exe File name: WConnectorSockets.exe
Size: 34.37 KB (34376 bytes)
MD5: 59f44b3136068e3afc7e842d8d47417e
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\PriceCongress
Group: Malware file
Last Updated: September 22, 2014
%PROGRAMFILES(x86)%\PriceCongress\IE\wdapimng.exe File name: wdapimng.exe
Size: 182.85 KB (182856 bytes)
MD5: 7ca294e73ae3ee9bf8a16a3b086020aa
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\PriceCongress\IE
Group: Malware file
Last Updated: September 22, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{269D7918-73C8-48B4-9F9C-AF7E1BC64116}{2769629f-e903-41bc-b9bd-b43ac39d03c2}{597a8da0-4a96-4fc5-806b-f49fdc3cd911}{636cfd90-9853-4927-a46d-692d4a161ddb}{9a713098-17a4-4199-b485-194a52f73062}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\AppID\PriceCongress.DLLSoftware\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{9a713098-17a4-4199-b485-194a52f73062}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{9a713098-17a4-4199-b485-194a52f73062}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9a713098-17a4-4199-b485-194a52f73062}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9a713098-17a4-4199-b485-194a52f73062}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9A713098-17A4-4199-B485-194A52F73062}Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{9a713098-17a4-4199-b485-194a52f73062}Software\PriceCongressSOFTWARE\Wow6432Node\Classes\AppID\PriceCongress.DLLSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{9a713098-17a4-4199-b485-194a52f73062}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{9a713098-17a4-4199-b485-194a52f73062}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{5f5dbef4-ecea-4406-bd19-65ce2df7151f}_is1

Additional Information

The following directories were created:
%PROGRAMFILES%\PriceCongress%PROGRAMFILES(x86)%\PriceCongress%USERPROFILE%\AppData\LocalLow\PriceCongress

Related Posts

Loading...