Home Malware Programs Adware Couponarific

Couponarific

Posted: July 10, 2014

Threat Metric

Ranking: 14,801
Threat Level: 2/10
Infected PCs: 51,428
First Seen: July 10, 2014
Last Seen: October 9, 2023
OS(es) Affected: Windows


Couponarific is an adware program that may display several ads on your system when it is installed that try to offer various savings and coupon deals for shopping online. The Couponarific ads may consist of pop-ups, pop-unders and banners that could have extensive media content on them. In some instances the Couponarific ads could slow performance of your web browser making it difficult to surf the internet. Use of the Couponarific ads or clicking on them may redirect your web browser to load a questionable site or a page that tries to offer other coupon and online shopping savings deals. Removal of the Couponarific program and any related plugins or add-on components is warranted to stop the Couponarific ads from appearing on your computer.

Aliases

Trojan.DownLoad3.35108 [DrWeb]WS.Reputation.1 [Symantec]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\010\mfqtdpwmjj32.exe File name: mfqtdpwmjj32.exe
Size: 596.97 KB (596976 bytes)
MD5: ba41a84e9ed90ad537ff7925fb28736f
Detection count: 3,918
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\010
Group: Malware file
Last Updated: November 23, 2019
%PROGRAMFILES%\010\swvlkarcui32.exe File name: swvlkarcui32.exe
Size: 596.97 KB (596976 bytes)
MD5: c504514530e9f802cd0079c477532859
Detection count: 1,258
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\010
Group: Malware file
Last Updated: November 25, 2014
%PROGRAMFILES%\0892ccea-3029-46f2-bd98-f3177431f5f8\xtloowpkjv.exe File name: xtloowpkjv.exe
Size: 161.28 KB (161280 bytes)
MD5: 6057a140621a8fcc14f572dea4621e04
Detection count: 979
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\0892ccea-3029-46f2-bd98-f3177431f5f8\xtloowpkjv.exe
Group: Malware file
Last Updated: August 3, 2022
%PROGRAMFILES%\010\batexxadvl32.exe File name: batexxadvl32.exe
Size: 682.99 KB (682992 bytes)
MD5: 19f1ac0a30569daa86dbc53e7d90d424
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\010
Group: Malware file
Last Updated: December 8, 2014
%PROGRAMFILES%\010\wcejvfgvem32.exe File name: wcejvfgvem32.exe
Size: 682.99 KB (682992 bytes)
MD5: 409777cf0492dba4162ac352ed28ae98
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\010
Group: Malware file
Last Updated: December 5, 2014
%PROGRAMFILES(x86)%\9ECA058F-09E5-4762-9227-86A2DD0FB969\updater_zkurwblqyk.exe File name: updater_zkurwblqyk.exe
Size: 483.32 KB (483328 bytes)
MD5: 14c6c0b77bba789d3256ad333edafda0
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\9ECA058F-09E5-4762-9227-86A2DD0FB969
Group: Malware file
Last Updated: November 4, 2014
%PROGRAMFILES%\010\hpsnytkwtm32.exe File name: hpsnytkwtm32.exe
Size: 682.99 KB (682992 bytes)
MD5: bca608a0962467ac33f99a88effa57cb
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\010
Group: Malware file
Last Updated: March 26, 2016

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\CouponARificSOFTWARE\couponarificSOFTWARE\Wow6432Node\656C4FBB-6D62-4880-9183-2D9C3161E1B6SOFTWARE\Wow6432Node\couponarificSYSTEM\ControlSet001\services\CouponArificService64SYSTEM\ControlSet001\services\updater_zkurwblqykSYSTEM\ControlSet002\services\CouponArificService64SYSTEM\ControlSet002\services\updater_zkurwblqykSYSTEM\CurrentControlSet\services\CouponArificService64SYSTEM\CurrentControlSet\services\updater_zkurwblqykHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}656C4FBB-6D62-4880-9183-2D9C3161E1B6CouponARific

Additional Information

The following directories were created:
%PROGRAMFILES%\116FC117-A4FD-4F86-9840-14C9CD63BFCE%PROGRAMFILES%\140E047B-FCAA-4924-844B-C7BF54847A16%PROGRAMFILES%\1999B073-71E4-44A4-953E-52B10808112C%PROGRAMFILES%\23BD2FDA-B46A-4A13-853B-2785D8E0BA56%PROGRAMFILES%\2C24168A-AEF7-4868-818A-2652A8AD4410%PROGRAMFILES%\35556262-902E-49AE-8622-66E14F1F041C%PROGRAMFILES%\38402C13-488C-4881-8EF1-52F3C056692B%PROGRAMFILES%\61B895DB-510E-45B8-8975-A9C6B941421C%PROGRAMFILES%\656C4FBB-6D62-4880-9183-2D9C3161E1B6%PROGRAMFILES%\9ECA058F-09E5-4762-9227-86A2DD0FB969%PROGRAMFILES%\CouponArific%PROGRAMFILES%\D20D4C68-AA2B-472D-B53D-683DF0DF4B16%PROGRAMFILES(x86)%\116FC117-A4FD-4F86-9840-14C9CD63BFCE%PROGRAMFILES(x86)%\1999B073-71E4-44A4-953E-52B10808112C%PROGRAMFILES(x86)%\23BD2FDA-B46A-4A13-853B-2785D8E0BA56%PROGRAMFILES(x86)%\2C24168A-AEF7-4868-818A-2652A8AD4410%PROGRAMFILES(x86)%\35556262-902E-49AE-8622-66E14F1F041C%PROGRAMFILES(x86)%\38402C13-488C-4881-8EF1-52F3C056692B%PROGRAMFILES(x86)%\61B895DB-510E-45B8-8975-A9C6B941421C%PROGRAMFILES(x86)%\656C4FBB-6D62-4880-9183-2D9C3161E1B6%PROGRAMFILES(x86)%\9ECA058F-09E5-4762-9227-86A2DD0FB969%PROGRAMFILES(x86)%\D20D4C68-AA2B-472D-B53D-683DF0DF4B16
Loading...