pricepeep_1.exe

betwikx

The application pricepeep_1.exe by betwikx has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory.
Publisher:
betwikx  (signed and verified)

MD5:
5cab5b54d52f37a1a5b66d6f203dd8f1

SHA-1:
dbc1bf92530f7c543e6af0383d8b469adeb44860

SHA-256:
69e99134921cd20e77b408986e40b872039b5f3bbe43dc34df2fb3f3434636db

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
1/2/2026 10:38:33 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
AdInject.Betwikx
2015.0.3533

Comodo Security
Heur.Suspicious
17137

Dr.Web
Adware.Shopper.297
9.0.1.075

Malwarebytes
Adware.Agent
v2014.03.16.05

Reason Heuristics
PUP.betwikx.L
14.3.16.17

VIPRE Antivirus
Pinball Corporation
22592

File size:
576 KB (589,776 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\pricepeep_1.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/28/2011 12:00:00 AM

Valid to:
11/26/2013 11:59:59 PM

Subject:
CN=betwikx, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=betwikx, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3A0ED371EEFB729EE95DA7D0B644B32B

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:DxB7HrBhw9V2eQxftVntpkiWmQ6ffKFG1wf/gYiTAXIDDahC7o:D77HrBh62RJtVAzmQGKo1wFWAXIXGCE

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9483

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove pricepeep_1.exe - Powered by Reason Core Security