Home Malware Programs Adware TakeTheCoupon

TakeTheCoupon

Posted: May 21, 2014

Threat Metric

Ranking: 11,614
Threat Level: 2/10
Infected PCs: 10,694
First Seen: May 21, 2014
Last Seen: October 15, 2023
OS(es) Affected: Windows


TakeTheCoupon is an adware threat that may display unwanted advertisements when PC users are using search engines such as Bing and Google and numerous other popular websites that use third-party advertising. In Google Chrome, TheCoupon may install itself as a browser extension and in Internet Explorer it may load as a process and a Browser Helper Object (BHO). TakeTheCoupon may also add itself as a Windows add-on. TakeTheCoupon may create an entry in the Add or Remove Programs of the Control Panel; however, deleting this entry might prevent it from running, but may not prevent ads from displaying. While the computer user visits his favourite online shopping websites, the browser add-on of TakeTheCoupon may automatically scan for discount coupons, deals, and promotions, giving online shoppers the benefit of comparison, and ensuring they only purchase what suits they budgets. TakeTheCoupon may scan the Web to get the best deals from all the PC user's favorite shopping websites, giving him the advantage of sale item prices, deals and promotions from shopping websites.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\TakeTheCouupOn\VI7L.x64.dll File name: VI7L.x64.dll
Size: 471.55 KB (471552 bytes)
MD5: abc5ea1f44f01f3006f8595ce96ce014
Detection count: 94
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TakeTheCouupOn
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\Dados de aplicativos\TakeTheCoupon\tWBvRn0.dll File name: tWBvRn0.dll
Size: 426.49 KB (426496 bytes)
MD5: 4c272bb0295ad27b55a64a896fc6170c
Detection count: 94
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Dados de aplicativos\TakeTheCoupon
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TAkeThheCoupon\3K65.dll File name: 3K65.dll
Size: 424.96 KB (424960 bytes)
MD5: 07b285891d065c560ca24cc9d82c5b1b
Detection count: 84
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TAkeThheCoupon
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TakeTheCouppon\Sez.dll File name: Sez.dll
Size: 427.52 KB (427520 bytes)
MD5: 0b48dfe297be419dd1c2ac923dfced4c
Detection count: 80
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TakeTheCouppon
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\Application Data\TakeTheCoupoN\_vss.dll File name: _vss.dll
Size: 425.47 KB (425472 bytes)
MD5: dc3cefaedeefdddd32a72e12255ca05e
Detection count: 66
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Application Data\TakeTheCoupoN
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TakeTheCOupon\yc1AiCtqq.x64.dll File name: yc1AiCtqq.x64.dll
Size: 475.13 KB (475136 bytes)
MD5: de152d526a716f735d4cd0c39bdd9231
Detection count: 66
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TakeTheCOupon
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TAkeTHeeCouppoN\DlI0c4PMQO.x64.dll File name: DlI0c4PMQO.x64.dll
Size: 472.57 KB (472576 bytes)
MD5: 6be003b079bdc93a6484e2169d023988
Detection count: 66
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TAkeTHeeCouppoN
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TakeTheCOOupoN\4.dll File name: 4.dll
Size: 427 KB (427008 bytes)
MD5: d70fb2974cfd4ab4c7854f183788924c
Detection count: 54
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TakeTheCOOupoN
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TakeThheCoeupoon\t.x64.dll File name: t.x64.dll
Size: 474.62 KB (474624 bytes)
MD5: 3a5ec791076bef2d094d38b0961885dd
Detection count: 45
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TakeThheCoeupoon
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TaKeTheCouponn\h.x64.dll File name: h.x64.dll
Size: 472.57 KB (472576 bytes)
MD5: d299bf77887318ea9493e2dd0b58d085
Detection count: 33
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TaKeTheCouponn
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TakeTheCoUpon\94mT8ap1H.x64.dll File name: 94mT8ap1H.x64.dll
Size: 475.64 KB (475648 bytes)
MD5: 0dc9267659969c528e635c7b3776ff41
Detection count: 33
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TakeTheCoUpon
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TakeTheCoupon\lcIIDokD.dll File name: lcIIDokD.dll
Size: 424.44 KB (424448 bytes)
MD5: d48b3bad2e32d0bf6e32047b3e58d55f
Detection count: 26
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TakeTheCoupon
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TakeTheCCoupoon\o0UvryG3c.x64.dll File name: o0UvryG3c.x64.dll
Size: 475.64 KB (475648 bytes)
MD5: 27daa66c626e68559b731924c6d135c2
Detection count: 23
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TakeTheCCoupoon
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TaKeTheeCoupon\MDpszNS.x64.dll File name: MDpszNS.x64.dll
Size: 477.18 KB (477184 bytes)
MD5: 026d6ecbc8c9ca2752d7a88a5e9b1f55
Detection count: 16
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TaKeTheeCoupon
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TakeTheCoupon\QytPhjyl.x64.dll File name: QytPhjyl.x64.dll
Size: 472.57 KB (472576 bytes)
MD5: 22416c4e172b403cebefaf3e1f8508a2
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TakeTheCoupon
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\Dados de aplicativos\TAkeTheCiouPon\0Q6tV.dll File name: 0Q6tV.dll
Size: 425.98 KB (425984 bytes)
MD5: ccfe141c333e6ee0d186fbe716720c68
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Dados de aplicativos\TAkeTheCiouPon
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TakeThheCCoupon\8WNNN6V.x64.dll File name: 8WNNN6V.x64.dll
Size: 475.13 KB (475136 bytes)
MD5: 13aadb528d7ae58a0db80644f5c88b4c
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TakeThheCCoupon
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TTAkkeTheCoupon\UQEniypjW.dll File name: UQEniypjW.dll
Size: 423.93 KB (423936 bytes)
MD5: 6bdd25060065e53ce71faa4fe87b1f3e
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\TTAkkeTheCoupon
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\TakeTHeCoupon\x3Rf.exe File name: x3Rf.exe
Size: 540.16 KB (540160 bytes)
MD5: 8f1459b3848fbae0db229ef2f83057d5
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\TakeTHeCoupon
Group: Malware file
Last Updated: June 4, 2014
C:\ProgramData\takethecoupon\tB.exe File name: C:\ProgramData\takethecoupon\tB.exe
MD5: f5bff621c4c58358b36f8526dec8a264
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\ProgramData\takethecoupon\tB.exetB.x64.dll File name: C:\ProgramData\takethecoupon\tB.exetB.x64.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\ProgramData\takethecoupon\tB.exetB.dll File name: C:\ProgramData\takethecoupon\tB.exetB.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\ProgramData\takethecoupon\tB.exetB.exe File name: C:\ProgramData\takethecoupon\tB.exetB.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{05467047-038C-E04B-2270-2B9DF766301F}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\TakeTheCoupon%PROGRAMFILES%\TakeTheCoupon%PROGRAMFILES(x86)%\TakeTheCoupon
The following URL's were detected:
TakeTheCokeTheCoup
Loading...