DiscountLocator

DiscountLocator

Known Toolbar

by InstalleRex-WebPick

What is DiscountLocator?

DiscountLocator is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 46.51% of installations running this operating system. DiscountLocator's installer is typically 1.00 MB in size and installs around 57 files.

DiscountLocator is most popular in the United States with 45.10% of installations residing in this country.

About DiscountLocator?

DiscountLocator is an ad-supported program designed to deliver additional advertisements to users while they are using search engines such as Bing and Google. It functions as a Chrome extension and as a process in Internet Explorer, along with operating as a Browser Helper Object. It also integrates itself as a Windows add-on. Despite creating an entry in the Control Panel's Add or Remove Programs section, merely deleting this entry may not fully halt the adware's operation or prevent advertisements from being displayed. Once installed, DiscountLocator injects additional ads into search results and various web pages with third-party advertising, especially when users utilize Bing or Google search. The software utilizes the InstalleRex download and install manager from WebPicks Holdings, which is commonly used to distribute Pay Per Install monetized software, often including undesired toolbars and web browser extensions.

Multiple virus scanners have detected malware in DiscountLocator.

WGq2YATHdzP2kf.dll (MD5: 7e61fef6948fc1aa1cb31d42b274cefb) has been flagged by 51 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.169592
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 PUP/Win32.Generic
ALYac Gen:Variant.Adware.Graftor.169592
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.MultiPlug
avast! Win32:Adware-gen [Adw]
AVG Generic6.DVX
Avira ADWARE/MultiPlug.Gen
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.Gen
Bitdefender Gen:Variant.Adware.Graftor.169592
CAT-QuickHeal AdWare.MultiPlug.r6 (Not a Virus)
Comodo Security Application.Win32.AdWare.MultiPlug.VB
Cyren W32/Adware.PQHS-5641
Dr.Web Trojan.Crossrider.48916
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.169592 (B)
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
Fortinet FortiGate Riskware/MultiPlug
G Data Gen:Variant.Adware.Graftor.169592
Jiangmin Adware/Agent.aksh
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.oaqo
Malwarebytes PUP.Optional.Multiplug
McAfee RDN/Generic.bfr!et
McAfee-GW-Edition BehavesLike.Win32.Downloader.hm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Gen:Variant.Adware.Graftor.169592
NANO AntiVirus Riskware.Win32.MultiPlug.dlltzy
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA LP
SUPERAntiSpyware Adware.MultiPlug/Variant
Symantec Adware.Popuppers
Tencent Trojan.Win32.Qudamah.Gen.12
Trend Micro ADW_MULTIPLUG
TrendMicro-HouseCall ADW_MULTIPLUG
Vba32 AntiVirus AdWare.MultiPlug
VIPRE Antivirus Trojan.Win32.Generic!BT
ViRobot Adware.Agent.512512.A[h]
Zillya Adware.MultiPlug.Win32.102470
F-Prot W32/S-71786d78!Eldorado
F-Secure Gen:Variant.Adware.Graftor
Qihoo-360 Win32/Virus.Adware.5c6
nProtect Trojan/W32.Agent.784384.AZ
Bkav FE W32.DropperAgentK.Trojan
IKARUS anti.virus Trojan.SuspectCRC
Norman Agent.BLMHC
Rising Antivirus PE:Trojan.Win32.Generic.178FA8B2!395290802
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Arcabit Application.Generic.DEB9DE
AegisLab AdWare.W32.MegaSearch
QfuHseBiYHVzlJ.exe (MD5: 974ad54281862631c28e0c587bc49ce0) has been flagged by 33 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.12382416
Agnitum Outpost Trojan.Agent!5IjaxXFm/IY
ALYac Trojan.Generic.12382416
avast! Other:Malware-gen [Trj]
Avira TR/Agent.167424
AVware Trojan.Win32.Generic!BT
Baidu-International PUA.Win32.GoSave.81
Bitdefender Trojan.Generic.12382416
Cyren W32/Trojan.MGGV-0097
Dr.Web Trojan.Siggen6.26453
Emsisoft Anti-Malware Trojan.Generic.12382416 (B)
F-Secure Trojan.Generic.12382416
G Data Trojan.Generic.12382416
IKARUS anti.virus AdWare.Agent.Bubit
McAfee RDN/Generic.grp!ia
McAfee-GW-Edition BehavesLike.Win32.Dropper.ch
MicroWorld-eScan Trojan.Generic.12382416
NANO AntiVirus Trojan.Win32.Siggen6.dpenfa
Norman Suspicious_Gen4.HJRUN
nProtect Trojan.Generic.12382416
Panda Antivirus Trj/Genetic.gen
Trend Micro ADW_MULTIPLUG
TrendMicro-HouseCall ADW_MULTIPLUG
VIPRE Antivirus Trojan.Win32.Generic!BT
AegisLab AdWare.W32.MegaSearch
AhnLab-V3 PUP/Win32.101Alemi
AVG Generic5.CINV
Comodo Security Application.Win32.MultiPlug.BNJ
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.BN
Fortinet FortiGate Riskware/MultiPlug
Malwarebytes PUP.Optional.MultiPlug
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Sophos Generic PUA EI
afmVXvkA3mlAlS.exe (MD5: 8af622327e2c6ef36dd2b147ec7d25b7) has been flagged by 51 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Agent.PKA
Agnitum Outpost Trojan.DR.Agent!HFLlzXAkfgc
ALYac Adware.Agent.PKA
Antiy-AVL Worm[:HEUR]/Win32.AGeneric
avast! Win32:GenMaliciousA-PR [Trj]
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.BuyNsave.81
Bitdefender Adware.Agent.PKA
Bkav FE W32.DropperAgentK.Trojan
CAT-QuickHeal TrojanDropper.Agent.r6
Cyren W32/Trojan.ZFUB-5796
Dr.Web Trojan.Siggen6.25854
Emsisoft Anti-Malware Adware.Agent.PKA (B)
Fortinet FortiGate W32/Agent.OEVL!tr
G Data Adware.Agent.PKA
IKARUS anti.virus Trojan.SuspectCRC
Jiangmin TrojanDropper.Agent.cjft
K7 AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Kaspersky Trojan.Win32.Cosmu.csae
Malwarebytes Trojan.Agent
McAfee RDN/Generic Dropper!vq
McAfee-GW-Edition BehavesLike.Win32.Dropper.ch
MicroWorld-eScan Adware.Agent.PKA
NANO AntiVirus Trojan.Win32.Agent.dkkkip
Norman Agent.BLMHC
nProtect Adware.Agent.PKA
Panda Antivirus Trj/Zbot.AC
Sophos BHO Persistent Uninstaller
SUPERAntiSpyware Trojan.Agent/Gen-Dropper
Symantec Trojan.Gen
Tencent Win32.Trojan.Cosmu.Efbi
Trend Micro ADW_TELGIP
TrendMicro-HouseCall ADW_TELGIP
Vba32 AntiVirus TrojanDropper.Agent
VIPRE Antivirus Trojan.Win32.Generic!BT
ViRobot Dropper.A.Agent.165888.I[h]
Zillya Dropper.Agent.Win32.177212
AhnLab-V3 PUP/Win32.Generic
AVG Generic5.CJTW
Avira ADWARE/MultiPlug.Gen
Comodo Security Application.Win32.AdWare.MultiPlug.VB
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
F-Prot W32/S-71786d78!Eldorado
F-Secure Gen:Variant.Adware.Graftor
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.178FA8B2!395290802
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Arcabit Application.Generic.DEB9DE
AegisLab AdWare.W32.MegaSearch
fodU2A8LfvHOR4.dll (MD5: 61689c87ee6244ba9cfb5a5ef4b2f4a0) has been flagged by 51 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.120870
Agnitum Outpost PUA.MultiPlug
AhnLab-V3 PUP/Win32.Generic
ALYac Gen:Variant.Adware.120870
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
avast! Win32:MultiPlug-LV [PUP]
AVG Generic6
Avira ADWARE/MultiPlug.Gen
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.Gen
Bitdefender Gen:Variant.Adware.120870
CAT-QuickHeal Browser.RestrictsControl.SL4
Comodo Security Application.Win32.AdWare.MultiPlug.VB
Cyren W32/S-71786d78!Eldorado
Dr.Web Trojan.Crossrider.48287
Emsisoft Anti-Malware Gen:Variant.Adware.120870
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
Fortinet FortiGate Riskware/MultiPlug
F-Prot W32/S-71786d78
F-Secure Gen:Variant.Adware.120870
G Data Gen:Variant.Adware.120870
Jiangmin AdWare/MultiPlug.boia
K7 AntiVirus Adware
K7GW Adware ( 004a07251 )
Kaspersky not-a-virus:AdWare.Win32.MultiPlug
Malwarebytes PUP.Optional.MultiPlug
McAfee MultiPlug
McAfee-GW-Edition BehavesLike.Win32.Downloader.bm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Gen:Variant.Adware.120870
NANO AntiVirus Riskware.Win32.MultiPlug.dklkhk
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Sophos Generic PUA JC
SUPERAntiSpyware Adware.Graftor/Variant
Symantec Trojan.Gen
Tencent Trojan.Win32.Qudamah.Gen.12
Trend Micro TROJ_GEN.R02KC0EA715
TrendMicro-HouseCall TROJ_GEN.R02KC0EA715
Vba32 AntiVirus AdWare.MultiPlug
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.MultiPlug.Win32.76598
ViRobot Adware.Agent.512512.A[h]
nProtect Trojan/W32.Agent.784384.AZ
Bkav FE W32.DropperAgentK.Trojan
IKARUS anti.virus Trojan.SuspectCRC
Norman Agent.BLMHC
Rising Antivirus PE:Trojan.Win32.Generic.178FA8B2!395290802
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Arcabit Application.Generic.DEB9DE
AegisLab AdWare.W32.MegaSearch
afmVXvkA3mlAlS.x64.dll (MD5: 9d912442d31ce9cae92171fbf92e6d88) has been flagged by 39 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.944645
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win64.MultiPlug
avast! Win64:Adware-gen [Adw]
AVG Generic_r.WU
Avira ADWARE/Adware.Gen
AVware Win64.Adware.MultiPlug
Baidu-International Adware.Win32.MultiPlug.Gen
Bitdefender Application.Generic.944645
Comodo Security ApplicUnwnt
Cyren W64/Application.KYZY-2902
ESET-NOD32 a variant of Win64/Adware.MultiPlug.E
Fortinet FortiGate Adware/MultiPlug
F-Secure Application.Generic.944645
G Data Application.Generic.944645
Kaspersky not-a-virus:AdWare.Win64.MultiPlug.en
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!cqc
McAfee-GW-Edition BehavesLike.Win64.Downloader.cm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Application.Generic.944645
Panda Antivirus Trj/CI.A
SUPERAntiSpyware Adware.MultiPlug/Variant
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R0C1C0EA115
TrendMicro-HouseCall TROJ_GEN.R0C1C0EA115
Vba32 AntiVirus AdWare.Win64.MultiPlug
VIPRE Antivirus Win64.Adware.MultiPlug
Agnitum Outpost Trojan.Agent!5IjaxXFm/IY
ALYac Trojan.Generic.12382416
Dr.Web Trojan.Siggen6.26453
Emsisoft Anti-Malware Trojan.Generic.12382416 (B)
IKARUS anti.virus AdWare.Agent.Bubit
NANO AntiVirus Trojan.Win32.Siggen6.dpenfa
Norman Suspicious_Gen4.HJRUN
nProtect Trojan.Generic.12382416
AegisLab AdWare.W32.MegaSearch
AhnLab-V3 PUP/Win32.101Alemi
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Sophos Generic PUA EI

Software Details

URL:
–
Support:
–
Installation path:
C:\ProgramData\discountlocator
Uninstaller:
"C:\ProgramData\DiscountLocator\RPK.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
1.00 MB
Language:
English

DiscountLocator Executable Details

Primary executable:
RPK.exe
Name:
DiscountLocator
Path:
C:\ProgramData\discountlocator\RPK.exe
MD5:
ad5ff5118cb8130330db74a50a4ab357
SHA-1:
–
SHA-256:
–
Files installed by DiscountLocator
File Type Filename MD5
DLL
388feac0c3abaf35d451edd34e89b2d4
DLL
7e61fef6948fc1aa1cb31d42b274cefb
DLL
1e170c1f8b2896dfc3b439db88fdf46e
DLL
afbfc4da12c91ea1cac1775dc3ec5144
DLL
cdaf7f3a01d1eb2c00ceaa87c56bf2ea
EXE
974ad54281862631c28e0c587bc49ce0
EXE
8af622327e2c6ef36dd2b147ec7d25b7
DLL
61689c87ee6244ba9cfb5a5ef4b2f4a0
EXE
4abcac1eb111b2788f36023711e193e0
DLL
9d912442d31ce9cae92171fbf92e6d88