Home Malware Programs Adware PriceHorse

PriceHorse

Posted: October 7, 2014

Threat Metric

Ranking: 13,421
Threat Level: 2/10
Infected PCs: 21,711
First Seen: October 7, 2014
Last Seen: August 26, 2023
OS(es) Affected: Windows


PriceHorse is an adware program that may conduct various actions that prove to be unwanted due to its annoyances and being intrusive. Commonly the PriceHorse ads will load up when you are surfing the internet or viewing popular shopping sites. The PriceHorse ads may consist of ones that attempt to offer coupon deals or other ways of supposedly saving money by shopping on the internet. Stopping the PriceHorse advertisement pop-ups or banners may take use of an updated antimalware tool.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



F:\DATOS\AdwCleaner\Quarantine\C\Users\<username>\AppData\Local\pricehorse\pricehorse\1.3.17.0\playsetup.exe.vir File name: playsetup.exe.vir
Size: 532.36 KB (532360 bytes)
MD5: 0ddec5cd4610cf8d44cd592be9d64c21
Detection count: 7,556
Mime Type: unknown/vir
Path: F:\DATOS\AdwCleaner\Quarantine\C\Users\<username>\AppData\Local\pricehorse\pricehorse\1.3.17.0\playsetup.exe.vir
Group: Malware file
Last Updated: July 2, 2021
C:\System Volume Information\_restore{AF06D24E-1931-4DA8-A7D7-C41D7BB886B3}\RP222\A0065868.exe File name: A0065868.exe
Size: 627.56 KB (627560 bytes)
MD5: 478ca559df5aecece633ede1886a1698
Detection count: 7,410
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\_restore{AF06D24E-1931-4DA8-A7D7-C41D7BB886B3}\RP222\A0065868.exe
Group: Malware file
Last Updated: April 27, 2022
F:\DATOS\AdwCleaner\Quarantine\C\Users\<username>\AppData\Local\pricehorse\pricehorse\1.3.17.0\pricehorse.exe.vir File name: pricehorse.exe.vir
Size: 628.1 KB (628104 bytes)
MD5: aad07028bb2a9d9a0c3d54379ec4fe4b
Detection count: 3,942
Mime Type: unknown/vir
Path: F:\DATOS\AdwCleaner\Quarantine\C\Users\<username>\AppData\Local\pricehorse\pricehorse\1.3.17.0\pricehorse.exe.vir
Group: Malware file
Last Updated: July 2, 2021
%LOCALAPPDATA%\pricehorse\pricehorse\1.3.13.12\pricehorse.exe File name: pricehorse.exe
Size: 621.56 KB (621568 bytes)
MD5: aa256b4d7e1556808b60fdbc68e2b1e4
Detection count: 782
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\pricehorse\pricehorse\1.3.13.12
Group: Malware file
Last Updated: January 27, 2015

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\pricehorse.exeSOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Price-HorseSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Price-HorseSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Price-Horse UdpaterSoftware\Microsoft\Windows\CurrentVersion\Run\Price-HorseHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}pricehorse

Additional Information

The following directories were created:
%LOCALAPPDATA%\pricehorse
Loading...