Home Malware Programs Adware CouponDownloader

CouponDownloader

Posted: May 8, 2014

Threat Metric

Ranking: 10,955
Threat Level: 2/10
Infected PCs: 37,474
First Seen: May 8, 2014
Last Seen: October 7, 2023
OS(es) Affected: Windows


CouponDownloader is adware that may show disturbing pop-up ads when computer users are using search service websites such as Bing and Google by injecting or embedding over new advertisements in search results as well as a variety of websites that may be commercial. In Google Chrome, CouponDownloader may install itself as a browser extension, and in Internet Explorer it may run as a process and a Browser Helper Object (BHO). CouponDownloader may also embed itself as a Windows add-on. CouponDownloader may create an entry in the Add or Remove Programs of the Control Panel; however, deleting this entry might block CouponDownloader from running, but may not block ads from showing. CouponDownloader may repeatedly redirect PC users to unwanted websites. CouponDownloader may be created to generate advertising income from clicks on ads and raised Internet traffic.

Aliases

ApplicUnwnt [Comodo]WS.Reputation.1 [Symantec]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\CouponDownloader\CouponDownloaderService64(61).exe File name: CouponDownloaderService64(61).exe
Size: 172.54 KB (172544 bytes)
MD5: 829fa47407ac74851fcf63b31bb01b72
Detection count: 7,626
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\CouponDownloader\CouponDownloaderService64(61).exe
Group: Malware file
Last Updated: April 12, 2021
C:\Program Files\F2E59BED-97F5-4486-9726-66DE2DDE3B23\gohymlmtrh.dll File name: gohymlmtrh.dll
Size: 74.75 KB (74752 bytes)
MD5: 41450f8d63d90f0ade2b886bea2f0f16
Detection count: 7,546
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files\F2E59BED-97F5-4486-9726-66DE2DDE3B23\gohymlmtrh.dll
Group: Malware file
Last Updated: October 11, 2022
c:\Program Files\CouponDownloader\CouponDownloaderService.exe File name: CouponDownloaderService.exe
Size: 150.52 KB (150528 bytes)
MD5: df7307d14158f6eddd21f7165b4b17b3
Detection count: 7,029
File type: Executable File
Mime Type: unknown/exe
Path: c:\Program Files\CouponDownloader\CouponDownloaderService.exe
Group: Malware file
Last Updated: July 20, 2022
%PROGRAMFILES(x86)%\C78087A8-C960-4464-A618-3D351DF6C0D7\CouponDownloaderService64.exe File name: CouponDownloaderService64.exe
Size: 172.54 KB (172544 bytes)
MD5: c3efd5c040b8e37b7b9312897c8373dd
Detection count: 2,953
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\C78087A8-C960-4464-A618-3D351DF6C0D7\CouponDownloaderService64.exe
Group: Malware file
Last Updated: August 17, 2023
%PROGRAMFILES%\CouponDownloader\CouponDownloaderService.exe File name: CouponDownloaderService.exe
Size: 691.2 KB (691200 bytes)
MD5: 94f45d986293afe9f83f17ec8789e919
Detection count: 642
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponDownloader
Group: Malware file
Last Updated: July 4, 2014
C:\$Recycle.Bin\S-1-5-21-1733207508-253909591-943535783-1002\$RU57QC0\eexvlcbkbu64.exe File name: eexvlcbkbu64.exe
Size: 172.54 KB (172544 bytes)
MD5: b0c6f89372bdf56600af0eb73f8650ed
Detection count: 639
File type: Executable File
Mime Type: unknown/exe
Path: C:\$Recycle.Bin\S-1-5-21-1733207508-253909591-943535783-1002\$RU57QC0\eexvlcbkbu64.exe
Group: Malware file
Last Updated: October 11, 2022
%PROGRAMFILES%\004\rqpbhevlkc64.exe File name: rqpbhevlkc64.exe
Size: 709.12 KB (709120 bytes)
MD5: de0e0d3717a2ed1f023b779dfec581bb
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\004
Group: Malware file
Last Updated: May 19, 2014
%PROGRAMFILES%\004\rqpbhevlkc32.exe File name: rqpbhevlkc32.exe
Size: 545.79 KB (545792 bytes)
MD5: 6a9ce204031906751fe2be80abb550f7
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\004
Group: Malware file
Last Updated: May 19, 2014
%PROGRAMFILES%\CouponDownloader\CouponDownloaderService64.exe File name: CouponDownloaderService64.exe
Size: 172.54 KB (172544 bytes)
MD5: 00ef3d0a8ed8e0e15a5609cc801fbfc7
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponDownloader
Group: Malware file
Last Updated: July 9, 2014

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Coupon DownloaderSoftware\Coupon DownloaderSOFTWARE\CouponDownloaderSOFTWARE\Wow6432Node\CouponDownloaderSYSTEM\ControlSet001\services\vulsrsebjh64SYSTEM\ControlSet002\services\vulsrsebjh64SYSTEM\CurrentControlSet\services\vulsrsebjh64HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}coupon downloader{813BA625-B0FA-48D8-9B75-59759C88C219}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\CouponDownloader%PROGRAMFILES%\4B5F3986-688D-4EE0-8390-82983E6E96A7%PROGRAMFILES%\CouponDownloader%PROGRAMFILES%\F2E59BED-97F5-4486-9726-66DE2DDE3B23%PROGRAMFILES%\coupon downloader%PROGRAMFILES(x86)%\4B5F3986-688D-4EE0-8390-82983E6E96A7%PROGRAMFILES(x86)%\CouponDownloader%PROGRAMFILES(x86)%\F2E59BED-97F5-4486-9726-66DE2DDE3B23%PROGRAMFILES(x86)%\coupon downloader
Loading...