Home Malware Programs Potentially Unwanted Programs (PUPs) The CouponXplorer Toolbar

The CouponXplorer Toolbar

Posted: April 29, 2014

Threat Metric

Ranking: 1,465
Threat Level: 1/10
Infected PCs: 70,195
First Seen: April 29, 2014
Last Seen: October 17, 2023
OS(es) Affected: Windows

CouponXplorer Toolbar is a web browser application add-on that displays a toolbar for quickly accessing coupon deals throughout the Internet. Created by the Mindspark Interactive Network, which is known for marketing toolbar applications and add-ons for your web browser, CouponXplorer Toolbar attempts to give computer users quick access to deals or coupon offers that can be found on the Internet, in addition to a search feature to find discounts on particular products that you desire. CouponXplorer Toolbar's search feature is known to use the MyWay.com Internet search engine to query results. Computer users may discover a means of disabling CouponXplorer Toolbar or removing it by digging into their web browser application settings.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{004F2608-3092-40C2-B880-1FD74DDA6B9A}{0297a026-3011-46d3-ad62-bb9a7612aea7}{0CD246B5-EC5A-4601-9A8F-C6D21742BB86}{131a1f72-5c50-43cf-ba3e-3ac75df1188b}{15F335C1-5CC0-4786-ABB9-06E727FF2D42}{1B4CF49B-8B69-4A90-8B51-D2088E1EC1BA}{1B749406-A17C-4A1C-9E87-E1E94A0C1A52}{1BCF3F83-F9A0-4075-B0BC-53128BBC228F}{23905799-4E4E-457F-8EEA-88A514D38DCA}{2c76e19a-5b10-4018-92dd-54de302114f9}{3852AB8E-1CA9-4B29-846F-092CA8D97969}{4025F9A4-91CE-4F20-8486-8A3D95564DB3}{41040243-9338-4C91-9457-AD11F56F48E1}{4132189A-73C7-4D3E-A8C2-82EF57842DAC}{46861ec7-fd7a-4197-b4a2-223196de2dcb}{48708b86-3672-46f9-89cf-680f8e807b91}{4ad0f9ab-db53-49fa-9c03-42e6ae1f0c7c}{4B6F98D4-3D4D-4D72-A89B-7B75207AF16D}{4E60D532-F00E-495B-BD0F-75F1B96CC714}{5128A486-0AED-4F8D-B1C0-1E0FF64CD1D0}{5bb649a4-1c05-4e18-b7a0-80a0fd29d8d7}{60727c6e-2fcb-4562-8685-7c59f5ea0c16}{627d42c1-e006-4bf2-bb79-d5fc6e0e01f0}{65c72339-fb1d-4155-84e1-9afacee02d6f}{697FA9F6-DA51-4F3C-8F01-FD5DAAFC18E5}{746c749a-528c-4e31-bc96-848c0d909fb4}{7535D37C-1554-4681-9F4B-055922B2F800}{76e9f00f-6852-44fc-b406-bb452f232a1b}{787ED5A2-18E3-49F2-BCFA-8E2344087D50}{7d69ed06-0171-4379-9528-08df51092727}{8221AC18-699F-46C9-8A89-0916CBDB5005}{85F06DCB-A179-4732-8BB6-DA65B0243C8A}{8D4ECA6C-82AC-4E26-B86D-E251635FFA72}{927c6290-8b1f-4673-9046-658843fea0d0}{97B4338F-DF52-45F6-9EA5-BA99A9883A78}{99395F16-43C8-461E-A1AC-36AC80EF13E4}{99CA1314-FC92-47C3-916A-9A4C31C13108}{9b138bf3-1d40-4e7e-84bb-2975198ad938}{9B500682-83D6-4252-BA71-20AA34A74A06}{9D51D472-88C3-4E12-93EA-8AEAFC57B227}{ae1fb1ef-c142-48d2-8bfa-2730b43e8bea}{B12E159D-74BA-45B7-AE12-F6D1A71F9E50}{b1c38f5a-506f-4f75-80d7-292903e8f87a}{b32e7dc1-4d99-4480-844a-06c15df31ed4}{B4685AA8-DBDD-4D8E-9A16-51B64646026A}{BB925FE4-7161-454F-88EE-7F58C40F549C}{BC337AE7-FF46-4D10-B1B6-E3E6E75CFB85}{BCDBD520-9E35-4093-A71F-8033FF14DDEA}{BE1EDE40-9C0B-4913-BF21-09F7AB5E270E}{BEEED033-0126-4DC6-A531-9060E3410521}{C0F279E1-1CBB-4FBE-B2E8-4E817D20D3EC}{C517F70B-242E-4408-BD38-1C8CAA053C62}{cf91f897-175f-43e3-8369-bd3ba14eee7b}{D0584866-E0CD-41C8-93EC-5CD3E02E0F9D}{D9581ECE-B29B-45E1-8EB7-F64EEA35D087}{E2B831BC-CF08-4227-AEAE-82A1C259F1BC}{E4E06D99-5021-4A4C-A55F-E3C33E66E74A}{FB9C1615-175B-48E3-813D-212E676B9F9E}{FCCC0AFD-B6BD-40A4-8A01-2A4B934C0546}File name without pathcouponxplorer.dl.myway[1].xmlcouponxplorer.dl.tb.ask[1].xmlCouponXplorer.lnkhttp_couponxplorer.dl.myway.com_0.localstoragehttp_couponxplorer.dl.myway.com_0.localstorage-journalhttp_couponxplorer.dl.tb.ask.com_0.localstoragehttp_couponxplorer.dl.tb.ask.com_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\CouponXplorerSoftware\Microsoft\Internet Explorer\Approved Extensions\{0297A026-3011-46D3-AD62-BB9A7612AEA7}Software\Microsoft\Internet Explorer\Approved Extensions\{65C72339-FB1D-4155-84E1-9AFACEE02D6F}Software\Microsoft\Internet Explorer\Approved Extensions\{7D69ED06-0171-4379-9528-08DF51092727}Software\Microsoft\Internet Explorer\DOMStorage\couponxplorer.dl.myway.comSoftware\Microsoft\Internet Explorer\DOMStorage\couponxplorer.dl.tb.ask.comSoftware\Microsoft\Internet Explorer\SearchScopes\{5a1d0d31-749c-4186-a295-4106e6e7b26a}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{65C72339-FB1D-4155-84E1-9AFACEE02D6F}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{65c72339-fb1d-4155-84e1-9afacee02d6f}Software\Microsoft\Internet Explorer\URLSearchHooks\{9b138bf3-1d40-4e7e-84bb-2975198ad938}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0297a026-3011-46d3-ad62-bb9a7612aea7}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{7d69ed06-0171-4379-9528-08df51092727}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2c76e19a-5b10-4018-92dd-54de302114f9}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{46861ec7-fd7a-4197-b4a2-223196de2dcb}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5bb649a4-1c05-4e18-b7a0-80a0fd29d8d7}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BEEED033-0126-4DC6-A531-9060E3410521}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{cf91f897-175f-43e3-8369-bd3ba14eee7b}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0297A026-3011-46D3-AD62-BB9A7612AEA7}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{65C72339-FB1D-4155-84E1-9AFACEE02D6F}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7D69ED06-0171-4379-9528-08DF51092727}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0297A026-3011-46D3-AD62-BB9A7612AEA7}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{65C72339-FB1D-4155-84E1-9AFACEE02D6F}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7D69ED06-0171-4379-9528-08DF51092727}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF91F897-175F-43E3-8369-BD3BA14EEE7B}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{131a1f72-5c50-43cf-ba3e-3ac75df1188b}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1b4cf49b-8b69-4a90-8b51-d2088e1ec1ba}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{342c5ca1-0a51-476e-bebb-923bdb3309b8}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b0f55b80-947d-4ba0-ad42-3f3923a87ed9}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d0584866-e0cd-41c8-93ec-5cd3e02e0f9d}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ead4279d-844b-4e80-a125-be6a16647f18}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{5a1d0d31-749c-4186-a295-4106e6e7b26a}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{65c72339-fb1d-4155-84e1-9afacee02d6f}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0297a026-3011-46d3-ad62-bb9a7612aea7}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{7d69ed06-0171-4379-9528-08df51092727}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2c76e19a-5b10-4018-92dd-54de302114f9}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{46861ec7-fd7a-4197-b4a2-223196de2dcb}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5bb649a4-1c05-4e18-b7a0-80a0fd29d8d7}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BEEED033-0126-4DC6-A531-9060E3410521}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{cf91f897-175f-43e3-8369-bd3ba14eee7b}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}CouponXplorerCouponXplorer_5zbar Uninstall FirefoxCouponXplorer_5zbar Uninstall Internet ExplorerCouponXplorerTooltab Uninstall Internet Explorer

Additional Information

The following directories were created:
%APPDATA%\CouponXplorer%LOCALAPPDATA%\CouponXplorerTooltab
The following URL's were detected:
CouponXplorer
Loading...