Home Malware Programs Adware Adware.50Coupons

Adware.50Coupons

Posted: May 6, 2014

Threat Metric

Ranking: 7,904
Threat Level: 2/10
Infected PCs: 13,797
First Seen: May 6, 2014
Last Seen: October 13, 2023
OS(es) Affected: Windows


50 Coupons is adware that may display unwanted advertisements when PC users are using search engines such as Bing and Google. In Google Chrome, Adware.50Coupons may install itself as a browser extension and in Internet Explorer it may run as a process and a Browser Helper Object (BHO). Adware.50Coupons may also insert itself as a Windows add-on. Adware.50Coupons may create an entry in the Add or Remove Programs of the Control Panel; however, deleting this entry might stop the adware running, but may not stop ads from displaying. Once installed, Adware.50Coupons may display unwanted ads if a computer user searches using Bing or Google by injecting ads in search and numerous other web pages that use third party advertising. Adware.50Coupons uses the InstalleRex download and install manager from WebPicks Holdings used to deliver Pay Per Install monetized application, usually unwanted toolbars and web browser extensions.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\50CoupOns\0GYCPuBq4X.tlb File name: 0GYCPuBq4X.tlb
Size: 3.83 KB (3832 bytes)
MD5: e35aa31c4eff2808fa1352b91d5801ee
Detection count: 95
Mime Type: unknown/tlb
Path: %PROGRAMFILES(x86)%\50CoupOns
Group: Malware file
Last Updated: May 6, 2014
%PROGRAMFILES(x86)%\50CoupOns\0GYCPuBq4X.dat File name: 0GYCPuBq4X.dat
Size: 3.97 KB (3972 bytes)
MD5: 53888d8c496175f83ae7e0a617867e57
Detection count: 93
File type: Data file
Mime Type: unknown/dat
Path: %PROGRAMFILES(x86)%\50CoupOns
Group: Malware file
Last Updated: May 6, 2014
%PROGRAMFILES(x86)%\50CoupOns\0GYCPuBq4X.x64.dll File name: 0GYCPuBq4X.x64.dll
Size: 473.6 KB (473600 bytes)
MD5: f43ac4b1e8d4421e7d94273c46e1614e
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\50CoupOns
Group: Malware file
Last Updated: August 17, 2022
C:\ProgramData\50coupouns\7Wqp68ior.exe File name: C:\ProgramData\50coupouns\7Wqp68ior.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\ProgramData\50coupouns\7Wqp68ior.dll File name: C:\ProgramData\50coupouns\7Wqp68ior.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\ProgramData\50coupouns\7Wqp68ior.x64.dll File name: C:\ProgramData\50coupouns\7Wqp68ior.x64.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\5500Coupons.5500CouponsSOFTWARE\Classes\5500Coupons.5500Coupons.1.8SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{79CC923D-792C-0CA1-BBA9-B946462CAC7E}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{CF987D06-1DCF-7B36-5B43-13BC8699C44C}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\50CoupOns%ALLUSERSPROFILE%\Application Data\50CoupOns%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\bpdabomaihmaiafdamjlmlgekmfomgmo%LOCALAPPDATA%\Packages\windows_ie_ac_001\AC\{79CC923D-792C-0CA1-BBA9-B946462CAC7E}%PROGRAMFILES%\50CoupOns%PROGRAMFILES%\50Couponse%PROGRAMFILES(x86)%\50CoupOns%PROGRAMFILES(x86)%\50Couponse
Loading...