Home Malware Programs Adware PriceFountain

PriceFountain

Posted: September 11, 2014

Threat Metric

Ranking: 7,926
Threat Level: 2/10
Infected PCs: 144,116
First Seen: September 11, 2014
Last Seen: March 10, 2025
OS(es) Affected: Windows


PriceFountain ads are part of an adware program that may display random ads attempting to provide discounts or savings for shopping on the internet. Use of the PriceFountain ads may cause redirects to other sites that may prove to be unwanted in some situations in their repeated offers of coupon deals or other methods of supposedly saving money when shopping on popular commerce sites on the internet. The PriceFountain ads in their pop-up or banner forms may be stopped by detecting all components or plugins related to PriceFountain and then removing them. This process may be done automatically through an antispyware application.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Local\PriceFountain\PriceFountainIE.dll.vir File name: PriceFountainIE.dll.vir
Size: 88.06 KB (88064 bytes)
MD5: 7593be8c6ebf14ceead30f14004daf0c
Detection count: 8,052
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Local\PriceFountain\PriceFountainIE.dll.vir
Group: Malware file
Last Updated: December 13, 2023
C:\Users\<username>\AppData\Local\~TreasonsHayers\treasonshayersupdater.exe.196737.gzquar File name: treasonshayersupdater.exe.196737.gzquar
Size: 511.48 KB (511488 bytes)
MD5: f51b38b72aad104861c2761b31fa6d57
Detection count: 274
Mime Type: unknown/gzquar
Path: C:\Users\<username>\AppData\Local\~TreasonsHayers\treasonshayersupdater.exe.196737.gzquar
Group: Malware file
Last Updated: November 24, 2021
%APPDATA%\{5B261E9F-D119-BDB0-81BC-0281DA260C72}\pricefountainupdateverupdate.exe File name: pricefountainupdateverupdate.exe
Size: 340.99 KB (340992 bytes)
MD5: 701af2a68cd925ab2e5f4fe8d5e00dad
Detection count: 150
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\{5B261E9F-D119-BDB0-81BC-0281DA260C72}
Group: Malware file
Last Updated: July 13, 2017
C:\WINDOWS\System32\MRT\2168C094-1DFC-43A9-B58E-EB323313845B\FilesStash\A15D2028-577E-4962-2370-BE1A747E3FBD_1d20f0cfe92c76e File name: A15D2028-577E-4962-2370-BE1A747E3FBD_1d20f0cfe92c76e
Size: 480.25 KB (480256 bytes)
MD5: 949f60bbf7c3435f3e3bb2219c44bc2b
Detection count: 122
Path: C:\WINDOWS\System32\MRT\2168C094-1DFC-43A9-B58E-EB323313845B\FilesStash\A15D2028-577E-4962-2370-BE1A747E3FBD_1d20f0cfe92c76e
Group: Malware file
Last Updated: January 28, 2022
%LOCALAPPDATA%\PriceFountain\PriceFountainIE.dll File name: PriceFountainIE.dll
Size: 199.52 KB (199525 bytes)
MD5: fc0d6bf2f31137e0ba953a5c79928af0
Detection count: 94
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\PriceFountain
Group: Malware file
Last Updated: February 13, 2016
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Local\PriceFountain\pricefountainw.exe.vir File name: pricefountainw.exe.vir
Size: 464.38 KB (464384 bytes)
MD5: 7562a40072dffc3365b45f5ddbbd8fd4
Detection count: 54
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Local\PriceFountain\pricefountainw.exe.vir
Group: Malware file
Last Updated: April 30, 2021
C:\Users\<username>\AppData\Roaming\PriceFountain\UpdateProc\bkup.dat File name: bkup.dat
Size: 18.83 KB (18839 bytes)
MD5: c8be2d8f2af522c5e2f6865378a947b8
Detection count: 33
File type: Data file
Mime Type: unknown/dat
Path: C:\Users\<username>\AppData\Roaming\PriceFountain\UpdateProc
Group: Malware file
Last Updated: July 7, 2017
%SystemDrive%\Users\<username>\AppData\Local\PriceFountain\pricefountain.exe File name: pricefountain.exe
Size: 627.71 KB (627712 bytes)
MD5: bf9223344cf805a417f13e6fb8011774
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Local\PriceFountain
Group: Malware file
Last Updated: April 12, 2016
prfo.dll File name: prfo.dll
Size: 650.75 KB (650752 bytes)
MD5: d2671ea6a02a33bd0fbf5e5f9ae248f8
Detection count: 12
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 4, 2019
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Local\PriceFountain\pricefountain.exe.vir File name: pricefountain.exe.vir
Size: 623.1 KB (623104 bytes)
MD5: b4faedd0b50a04fc4c9c8e3299f83f53
Detection count: 7
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Local\PriceFountain\pricefountain.exe.vir
Group: Malware file
Last Updated: July 29, 2020
%LOCALAPPDATA%\PriceFountain\pricefountainw.exe File name: pricefountainw.exe
Size: 464.38 KB (464384 bytes)
MD5: a5eb422fd7cd518492566fcc7271ecac
Detection count: 3
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\PriceFountain
Group: Malware file
Last Updated: March 19, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{b608cc98-54de-4775-96c9-097de398500c}File name without pathPriceFountainUpdateVer.exePriceFountainUpdateVerUpdate.exeRegexp file mask%WINDIR%\System32\Tasks\Price Fountain%WINDIR%\System32\Tasks\PriceFountainUpdateVer%WINDIR%\System32\Tasks\PriceFountainV2%WINDIR%\Tasks\Price Fountain.job%WINDIR%\Tasks\PriceFountainUpdateVer.jobHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{b608cc98-54de-4775-96c9-097de398500c}Software\Microsoft\Internet Explorer\DOMStorage\pricefountain.comSoftware\Microsoft\Internet Explorer\DOMStorage\www.pricefountain.comSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Price Fountain.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Price Fountain.job.fpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\PriceFountainUpdateVer.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\PriceFountainUpdateVer.job.fpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PFExeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Price FountainSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PriceFountainUpdateVerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PriceFountainV2Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B608CC98-54DE-4775-96C9-097DE398500C}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B608CC98-54DE-4775-96C9-097DE398500C}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PriceFountainSoftware\Microsoft\Windows\CurrentVersion\Run\pricefountainw.exeSoftware\PrcFountainSoftware\PriceFountainSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\PriceFountainHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}BawdierNeuterPrice FountainPriceFountainPriceFountainUpdateVer

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\PriceFountain%APPDATA%\PriceFountain%APPDATA%\PriceFountainUpdateVer%LOCALAPPDATA%\BawdierNeuter%LOCALAPPDATA%\DieresisPeach%LOCALAPPDATA%\KrishnaRheums%LOCALAPPDATA%\PriceFountain%LOCALAPPDATA%\TorchierIncidental%PROGRAMFILES%\PriceFountain%PROGRAMFILES(x86)%\PriceFountain%Temp%\PriceFountain%UserProfile%\Local Settings\Application Data\PriceFountain
The following URL's were detected:
PriceFountainpricefountain.com
Loading...