Home Malware Programs Adware RoyalCoupon

RoyalCoupon

Posted: August 12, 2014

Threat Metric

Ranking: 9,004
Threat Level: 2/10
Infected PCs: 6,448
First Seen: August 7, 2014
Last Seen: September 20, 2023
OS(es) Affected: Windows


RoyalCoupon is an adware program that could render several banner or pop-up ads attempting to offer coupon deals or offers through shopping on the internet. The RoyalCoupon ads may be rather enticing where they could monitor sites you have visited and relay an ad related to whatever products you may have viewed in the past. The RoyalCoupon adware could have several components loaded on your system causing the random RoyalCoupon ads to display. Usually this happens due to installing random freeware apps or bundled software programs downloaded from the internet. Removing the RoyalCoupon adware and stopping its related ads may require use of an updated and trusted antispyware application designed to remove adware from a Windows PC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\RoyalCoupon\J.dll File name: J.dll
Size: 427 KB (427008 bytes)
MD5: 035e75f23cab6410e3deaaa8f4ab4df8
Detection count: 262
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\RoyalCoupon
Group: Malware file
Last Updated: August 7, 2014
%ALLUSERSPROFILE%\RoyalCoupon\V.x64.dll File name: V.x64.dll
Size: 475.13 KB (475136 bytes)
MD5: 5303516389c9e02d4f2f590022fcd9a2
Detection count: 211
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\RoyalCoupon
Group: Malware file
Last Updated: August 7, 2014
%ALLUSERSPROFILE%\RRoyAlCoupon\6Z8.x64.dll File name: 6Z8.x64.dll
Size: 476.16 KB (476160 bytes)
MD5: c0cc744ecd72125b38497c4f0c584982
Detection count: 80
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\RRoyAlCoupon
Group: Malware file
Last Updated: August 7, 2014
%ALLUSERSPROFILE%\RoyalCoupoN\GF97.x64.dll File name: GF97.x64.dll
Size: 474.11 KB (474112 bytes)
MD5: 57a0a462fd88a0397653f2f0566cd0c7
Detection count: 26
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\RoyalCoupoN
Group: Malware file
Last Updated: August 7, 2014
%ALLUSERSPROFILE%\Datos de programa\RoyalCoupon\wsU9EUvu.dll File name: wsU9EUvu.dll
Size: 426.49 KB (426496 bytes)
MD5: 34521f63dd256f1fd50e52cb08cb3071
Detection count: 21
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Datos de programa\RoyalCoupon
Group: Malware file
Last Updated: August 7, 2014
%ALLUSERSPROFILE%\RoyALCoupon\MJLRONiNo.dll File name: MJLRONiNo.dll
Size: 425.47 KB (425472 bytes)
MD5: 431cc9fd0f32e88d631b4b7b5eef0928
Detection count: 16
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\RoyALCoupon
Group: Malware file
Last Updated: August 7, 2014
%ALLUSERSPROFILE%\RoyalCouponn\QTL.x64.dll File name: QTL.x64.dll
Size: 471.04 KB (471040 bytes)
MD5: fe545927386cfd508d3e1db5dce67c0f
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\RoyalCouponn
Group: Malware file
Last Updated: August 7, 2014

Registry Modifications

The following newly produced Registry Values are:

HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{40DC4B27-4588-C56F-7737-D03A0ACE4383}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\RoyalCoupon%ALLUSERSPROFILE%\RoyalCoupon%PROGRAMFILES%\RoyalCoupon%PROGRAMFILES(x86)%\RoyalCoupon
Loading...