Home Malware Programs Adware Adware.Coupon Caddy

Adware.Coupon Caddy

Posted: April 2, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 520
First Seen: April 2, 2013
Last Seen: April 3, 2023
OS(es) Affected: Windows

Coupon Caddy Screenshot 1Coupon Caddy is a potentially unwanted program created by 215 apps for Internet Explorer, Mozilla Firefox and Google Chrome that is usually added when Internet users install other free programs. Coupon Caddy will display ads, coupons and sponsored links via a pop-up box on Amazon, Walmart, Ebay and other shopping websites that web users are visiting. These pop-up ads will be displayed as boxes, which involve a variety of coupons that are available or as underlined keywords, which when clicked will illustrate a pop-up ad that states it is sent to the affected computer user by Coupon Caddy. When Internet users install free programs, they will also install Coupon Caddy. When installed, Coupon Caddy will illustrate a box, which involves related keyword suggestions, ads and sponsored links, in the right top part of the compromised web browser, whenever the PC user will surf Facebook, Expedia, Best Buy or any other similar websites.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{11111111-1111-1111-1111-110111271149}{22222222-2222-2222-2222-220122272249}{44444444-4444-4444-4444-440144274449}{55555555-5555-5555-5555-550155275549}{66666666-6666-6666-6666-660166276649}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Coupon CaddySOFTWARE\Classes\CrossriderApp0012749.BHOSOFTWARE\Classes\CrossriderApp0012749.BHO.1SOFTWARE\Classes\CrossriderApp0012749.SandboxSOFTWARE\Classes\CrossriderApp0012749.Sandbox.1SOFTWARE\Coupon CaddySoftware\Cr_Installer\12749Software\InstalledBrowserExtensions\215 Apps\12749SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater12749.exeSOFTWARE\Wow6432Node\Coupon CaddySOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110111271149}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110111271149}SOFTWARE\Wow6432Node\Microsoft\Tracing\Coupon Caddy_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Coupon Caddy_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110111271149}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Coupon Caddy

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Coupon Caddy%LOCALAPPDATA%\Coupon Caddy%LOCALAPPDATA%\Updater12749%PROGRAMFILES%\Coupon Caddy%PROGRAMFILES(x86)%\Coupon Caddy
The following URL's were detected:
Coupon Caddy
Loading...