DiscountLocator

DiscountLocator

Known Toolbar

by InstalleRex-WebPick

What is DiscountLocator?

DiscountLocator is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 46.51% of installations running this operating system. DiscountLocator's installer is typically 1.00 MB in size and installs around 57 files.

DiscountLocator is most popular in the United States with 45.10% of installations residing in this country.

About DiscountLocator?

DiscountLocator is an ad-supported program designed to deliver additional advertisements to users while they are using search engines such as Bing and Google. It functions as a Chrome extension and as a process in Internet Explorer, along with operating as a Browser Helper Object. It also integrates itself as a Windows add-on. Despite creating an entry in the Control Panel's Add or Remove Programs section, merely deleting this entry may not fully halt the adware's operation or prevent advertisements from being displayed. Once installed, DiscountLocator injects additional ads into search results and various web pages with third-party advertising, especially when users utilize Bing or Google search. The software utilizes the InstalleRex download and install manager from WebPicks Holdings, which is commonly used to distribute Pay Per Install monetized software, often including undesired toolbars and web browser extensions.

Multiple virus scanners have detected malware in DiscountLocator.

WGq2YATHdzP2kf.dll (MD5: 7e61fef6948fc1aa1cb31d42b274cefb) has been flagged by 51 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.169592
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 PUP/Win32.Generic
ALYac Gen:Variant.Adware.Graftor.169592
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.MultiPlug
avast! Win32:Adware-gen [Adw]
AVG Generic6.DVX
Avira ADWARE/MultiPlug.Gen
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.Gen
Bitdefender Gen:Variant.Adware.Graftor.169592
CAT-QuickHeal AdWare.MultiPlug.r6 (Not a Virus)
Comodo Security Application.Win32.AdWare.MultiPlug.VB
Cyren W32/Adware.PQHS-5641
Dr.Web Trojan.Crossrider.48916
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.169592 (B)
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
Fortinet FortiGate Riskware/MultiPlug
G Data Gen:Variant.Adware.Graftor.169592
Jiangmin Adware/Agent.aksh
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.oaqo
Malwarebytes PUP.Optional.Multiplug
McAfee RDN/Generic.bfr!et
McAfee-GW-Edition BehavesLike.Win32.Downloader.hm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Gen:Variant.Adware.Graftor.169592
NANO AntiVirus Riskware.Win32.MultiPlug.dlltzy
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA LP
SUPERAntiSpyware Adware.MultiPlug/Variant
Symantec Adware.Popuppers
Tencent Trojan.Win32.Qudamah.Gen.12
Trend Micro ADW_MULTIPLUG
TrendMicro-HouseCall ADW_MULTIPLUG
Vba32 AntiVirus AdWare.MultiPlug
VIPRE Antivirus Trojan.Win32.Generic!BT
ViRobot Adware.Agent.512512.A[h]
Zillya Adware.MultiPlug.Win32.102470
F-Prot W32/S-71786d78!Eldorado
F-Secure Gen:Variant.Adware.Graftor
Qihoo-360 Win32/Virus.Adware.5c6
nProtect Trojan/W32.Agent.784384.AZ
Bkav FE W32.DropperAgentK.Trojan
IKARUS anti.virus Trojan.SuspectCRC
Norman Agent.BLMHC
Rising Antivirus PE:Trojan.Win32.Generic.178FA8B2!395290802
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Arcabit Application.Generic.DEB9DE
AegisLab AdWare.W32.MegaSearch
QfuHseBiYHVzlJ.exe (MD5: 974ad54281862631c28e0c587bc49ce0) has been flagged by 33 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.12382416
Agnitum Outpost Trojan.Agent!5IjaxXFm/IY
ALYac Trojan.Generic.12382416
avast! Other:Malware-gen [Trj]
Avira TR/Agent.167424
AVware Trojan.Win32.Generic!BT
Baidu-International PUA.Win32.GoSave.81
Bitdefender Trojan.Generic.12382416
Cyren W32/Trojan.MGGV-0097
Dr.Web Trojan.Siggen6.26453
Emsisoft Anti-Malware Trojan.Generic.12382416 (B)
F-Secure Trojan.Generic.12382416
G Data Trojan.Generic.12382416
IKARUS anti.virus AdWare.Agent.Bubit
McAfee RDN/Generic.grp!ia
McAfee-GW-Edition BehavesLike.Win32.Dropper.ch
MicroWorld-eScan Trojan.Generic.12382416
NANO AntiVirus Trojan.Win32.Siggen6.dpenfa
Norman Suspicious_Gen4.HJRUN
nProtect Trojan.Generic.12382416
Panda Antivirus Trj/Genetic.gen
Trend Micro ADW_MULTIPLUG
TrendMicro-HouseCall ADW_MULTIPLUG
VIPRE Antivirus Trojan.Win32.Generic!BT
AegisLab AdWare.W32.MegaSearch
AhnLab-V3 PUP/Win32.101Alemi
AVG Generic5.CINV
Comodo Security Application.Win32.MultiPlug.BNJ
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.BN
Fortinet FortiGate Riskware/MultiPlug
Malwarebytes PUP.Optional.MultiPlug
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Sophos Generic PUA EI
afmVXvkA3mlAlS.exe (MD5: 8af622327e2c6ef36dd2b147ec7d25b7) has been flagged by 51 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Agent.PKA
Agnitum Outpost Trojan.DR.Agent!HFLlzXAkfgc
ALYac Adware.Agent.PKA
Antiy-AVL Worm[:HEUR]/Win32.AGeneric
avast! Win32:GenMaliciousA-PR [Trj]
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.BuyNsave.81
Bitdefender Adware.Agent.PKA
Bkav FE W32.DropperAgentK.Trojan
CAT-QuickHeal TrojanDropper.Agent.r6
Cyren W32/Trojan.ZFUB-5796
Dr.Web Trojan.Siggen6.25854
Emsisoft Anti-Malware Adware.Agent.PKA (B)
Fortinet FortiGate W32/Agent.OEVL!tr
G Data Adware.Agent.PKA
IKARUS anti.virus Trojan.SuspectCRC
Jiangmin TrojanDropper.Agent.cjft
K7 AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Kaspersky Trojan.Win32.Cosmu.csae
Malwarebytes Trojan.Agent
McAfee RDN/Generic Dropper!vq
McAfee-GW-Edition BehavesLike.Win32.Dropper.ch
MicroWorld-eScan Adware.Agent.PKA
NANO AntiVirus Trojan.Win32.Agent.dkkkip
Norman Agent.BLMHC
nProtect Adware.Agent.PKA
Panda Antivirus Trj/Zbot.AC
Sophos BHO Persistent Uninstaller
SUPERAntiSpyware Trojan.Agent/Gen-Dropper
Symantec Trojan.Gen
Tencent Win32.Trojan.Cosmu.Efbi
Trend Micro ADW_TELGIP
TrendMicro-HouseCall ADW_TELGIP
Vba32 AntiVirus TrojanDropper.Agent
VIPRE Antivirus Trojan.Win32.Generic!BT
ViRobot Dropper.A.Agent.165888.I[h]
Zillya Dropper.Agent.Win32.177212
AhnLab-V3 PUP/Win32.Generic
AVG Generic5.CJTW
Avira ADWARE/MultiPlug.Gen
Comodo Security Application.Win32.AdWare.MultiPlug.VB
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
F-Prot W32/S-71786d78!Eldorado
F-Secure Gen:Variant.Adware.Graftor
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.178FA8B2!395290802
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Arcabit Application.Generic.DEB9DE
AegisLab AdWare.W32.MegaSearch
fodU2A8LfvHOR4.dll (MD5: 61689c87ee6244ba9cfb5a5ef4b2f4a0) has been flagged by 51 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.120870
Agnitum Outpost PUA.MultiPlug
AhnLab-V3 PUP/Win32.Generic
ALYac Gen:Variant.Adware.120870
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
avast! Win32:MultiPlug-LV [PUP]
AVG Generic6
Avira ADWARE/MultiPlug.Gen
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.Gen
Bitdefender Gen:Variant.Adware.120870
CAT-QuickHeal Browser.RestrictsControl.SL4
Comodo Security Application.Win32.AdWare.MultiPlug.VB
Cyren W32/S-71786d78!Eldorado
Dr.Web Trojan.Crossrider.48287
Emsisoft Anti-Malware Gen:Variant.Adware.120870
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
Fortinet FortiGate Riskware/MultiPlug
F-Prot W32/S-71786d78
F-Secure Gen:Variant.Adware.120870
G Data Gen:Variant.Adware.120870
Jiangmin AdWare/MultiPlug.boia
K7 AntiVirus Adware
K7GW Adware ( 004a07251 )
Kaspersky not-a-virus:AdWare.Win32.MultiPlug
Malwarebytes PUP.Optional.MultiPlug
McAfee MultiPlug
McAfee-GW-Edition BehavesLike.Win32.Downloader.bm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Gen:Variant.Adware.120870
NANO AntiVirus Riskware.Win32.MultiPlug.dklkhk
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Sophos Generic PUA JC
SUPERAntiSpyware Adware.Graftor/Variant
Symantec Trojan.Gen
Tencent Trojan.Win32.Qudamah.Gen.12
Trend Micro TROJ_GEN.R02KC0EA715
TrendMicro-HouseCall TROJ_GEN.R02KC0EA715
Vba32 AntiVirus AdWare.MultiPlug
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.MultiPlug.Win32.76598
ViRobot Adware.Agent.512512.A[h]
nProtect Trojan/W32.Agent.784384.AZ
Bkav FE W32.DropperAgentK.Trojan
IKARUS anti.virus Trojan.SuspectCRC
Norman Agent.BLMHC
Rising Antivirus PE:Trojan.Win32.Generic.178FA8B2!395290802
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Arcabit Application.Generic.DEB9DE
AegisLab AdWare.W32.MegaSearch
afmVXvkA3mlAlS.x64.dll (MD5: 9d912442d31ce9cae92171fbf92e6d88) has been flagged by 39 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.944645
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win64.MultiPlug
avast! Win64:Adware-gen [Adw]
AVG Generic_r.WU
Avira ADWARE/Adware.Gen
AVware Win64.Adware.MultiPlug
Baidu-International Adware.Win32.MultiPlug.Gen
Bitdefender Application.Generic.944645
Comodo Security ApplicUnwnt
Cyren W64/Application.KYZY-2902
ESET-NOD32 a variant of Win64/Adware.MultiPlug.E
Fortinet FortiGate Adware/MultiPlug
F-Secure Application.Generic.944645
G Data Application.Generic.944645
Kaspersky not-a-virus:AdWare.Win64.MultiPlug.en
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!cqc
McAfee-GW-Edition BehavesLike.Win64.Downloader.cm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Application.Generic.944645
Panda Antivirus Trj/CI.A
SUPERAntiSpyware Adware.MultiPlug/Variant
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R0C1C0EA115
TrendMicro-HouseCall TROJ_GEN.R0C1C0EA115
Vba32 AntiVirus AdWare.Win64.MultiPlug
VIPRE Antivirus Win64.Adware.MultiPlug
Agnitum Outpost Trojan.Agent!5IjaxXFm/IY
ALYac Trojan.Generic.12382416
Dr.Web Trojan.Siggen6.26453
Emsisoft Anti-Malware Trojan.Generic.12382416 (B)
IKARUS anti.virus AdWare.Agent.Bubit
NANO AntiVirus Trojan.Win32.Siggen6.dpenfa
Norman Suspicious_Gen4.HJRUN
nProtect Trojan.Generic.12382416
AegisLab AdWare.W32.MegaSearch
AhnLab-V3 PUP/Win32.101Alemi
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Sophos Generic PUA EI

Software Details

URL:
–
Support:
–
Installation path:
C:\ProgramData\discountlocator
Uninstaller:
"C:\ProgramData\DiscountLocator\RPK.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
1.00 MB
Language:
English

DiscountLocator Executable Details

Primary executable:
RPK.exe
Name:
DiscountLocator
Path:
C:\ProgramData\discountlocator\RPK.exe
MD5:
ad5ff5118cb8130330db74a50a4ab357
SHA-1:
–
SHA-256:
–
Files installed by DiscountLocator
File Type Filename MD5
DLL
a95ebc7a0e8e651ddd1e1b07773b536c
EXE
c576a7663e2a3e6b19a1649ebdee44c1
EXE
ffaf3633064fdc65d6fba376b5aca176
EXE
b9c903b53e65e7c12ca50e1606207181
DLL
5e55435c2fcdc2c3132c15eba3e93296
DLL
20f530227a35c990e7473bf22068cfb7
DLL
36cddfd3d2717b327fc5f8baa561bfd0
EXE
cc490bd7632f76793fefdf767ca29f1f
DLL
15b1d0053054e33606c48c3be74b73fb
DLL
b44b1bc7a8aab6a7d7aab228332e49d9