GrtSCouponApp

GrtSCouponApp

Known Toolbar

by InstalleRex-WebPick

What is GrtSCouponApp?

GrtSCouponApp is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 65.22% of installations running this operating system. GrtSCouponApp's installer is typically 531.00 KB in size and installs around 19 files. The most common release is 3.1.0.1281 with 17.39% of all installations currently using this version.

GrtSCouponApp is most popular in the United States with 58.17% of installations residing in this country.

About GrtSCouponApp?

The Great Coupon software is an adware extension designed to integrate with web browsers such as Internet Explorer, Chrome, and Firefox. Upon installation, it runs as a background process and injects additional advertisements into popular search engines like Bing and Google. Despite creating an entry in Add or Remove Programs, removing this entry may not completely stop the adware from running or prevent ads from displaying. The program is also known for replacing existing ads on web pages with its own, and it utilizes the InstalleRex download manager from WebPicks Holdings to install itself on users' PCs. It is important to note that InstalleRex is associated with the distribution of potentially unwanted applications, including ad-supported extensions and web browser toolbars.

Multiple virus scanners have detected malware in GrtSCouponApp.

3Aw2.exe (MD5: a84d5bc892e7f990b60de1e812a57bb4) has been flagged by 4 scanners:
Scanner Software Result
AVG Generic_r.HC
Malwarebytes PUP.Optional.MultiPlug.A
Panda Antivirus Suspicious file
Sophos MultiPlug
aQy.exe (MD5: b762b67e59693ce11d0d861fd9e9a0a9) has been flagged by 6 scanners:
Scanner Software Result
AVG Generic_r.HC
ByteHero BDV Trojan.Exception.gen.101
Malwarebytes PUP.Optional.MultiPlug.A
Panda Antivirus Suspicious file
TrendMicro-HouseCall TROJ_GEN.F47V0119
Sophos MultiPlug
7_.exe (MD5: 926838555c7e13f295fda017b3fa3ea9) has been flagged by 17 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.Agent
AVG Generic5.ALKI
Baidu-International Adware.Win32.MultiPlug.40
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.37
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.K.gen
K7 AntiVirus Adware ( 00490ca81 )
K7GW Adware ( 00490ca81 )
Malwarebytes PUP.Optional.Multiplug
McAfee Artemis!926838555C7E
McAfee-GW-Edition Artemis!926838555C7E
Panda Antivirus Suspicious file
TrendMicro-HouseCall TROJ_GEN.F47V0106
VIPRE Antivirus Trojan.Win32.Generic!BT
ViRobot Adware.Agent.539136
ByteHero BDV Trojan.Exception.gen.101
Sophos MultiPlug
3LkVZZwt.exe (MD5: 9c354249e2b00af7362d8eecaee9b2b2) has been flagged by 36 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.Agent
avast! Win32:Adware-gen [Adw]
AVG Generic5
Baidu-International Adware.Win32.MultiPlug.40
Bkav FE W32.DropperMsilB.Trojan
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.K.gen
Fortinet FortiGate Riskware/MultiPlug_K
IKARUS anti.virus Trojan.SuspectCRC
K7 AntiVirus Adware
K7GW Adware ( 00490ca81 )
Malwarebytes PUP.Optional.Multiplug
McAfee Artemis!9C354249E2B0
McAfee-GW-Edition Artemis!9C354249E2B0
Panda Antivirus Suspicious file
Symantec Trojan.Gen
TrendMicro-HouseCall TROJ_GEN.R0CBH05A614
VIPRE Antivirus Trojan.Win32.Generic!BT
Lavasoft Ad-Aware Application.Generic.582628
Agnitum Outpost Adware.MegaSearch!M/jO5MsDxDM
Avira AntiVir SPR/Tool.498176
Antiy-AVL AdWare/Win32.MegaSearch
Bitdefender Application.Generic.582628
CAT-QuickHeal Adware.Megasearch.at (Not a Virus)
G Data Application.Generic.582628
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
Kingsoft AntiVirus Win32.Troj.MegaSearch.at.(kcloud)
MicroWorld-eScan Application.Generic.582628
NANO AntiVirus Riskware.Win32.MegaSearch.cscrfp
Qihoo-360 Win32/Virus.Adware.422
Sophos Generic PUA BA
Trend Micro TROJ_GEN.F0C2C00LT13
Vba32 AntiVirus AdWare.MegaSearch
ViRobot Adware.Agent.498176.A
Dr.Web Trojan.Crossrider.37
ByteHero BDV Trojan.Exception.gen.101
hVE.exe (MD5: 06cfeaa6556d9264ef303884935ddfe2) has been flagged by 35 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.582628
Agnitum Outpost Adware.MegaSearch!M/jO5MsDxDM
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir SPR/Tool.498176
Antiy-AVL AdWare/Win32.MegaSearch
avast! Win32:Malware-gen
AVG Generic5.AKQI
Baidu-International Adware.Win32.MegaSearch.40
Bitdefender Application.Generic.582628
Bkav FE W32.WonintLTD.Trojan
CAT-QuickHeal Adware.Megasearch.at (Not a Virus)
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.K.gen
Fortinet FortiGate Adware/Megasearch
G Data Application.Generic.582628
IKARUS anti.virus Win32.AdWare
K7 AntiVirus Adware ( 00490ca81 )
K7GW Adware ( 00490ca81 )
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
Kingsoft AntiVirus Win32.Troj.MegaSearch.at.(kcloud)
Malwarebytes PUP.Optional.MultiPlug.A
McAfee PUP-FFY!06CFEAA6556D
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
MicroWorld-eScan Application.Generic.582628
NANO AntiVirus Riskware.Win32.MegaSearch.cscrfp
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.422
Sophos Generic PUA BA
Trend Micro TROJ_GEN.F0C2C00LT13
TrendMicro-HouseCall TROJ_GEN.F0C2C00LT13
Vba32 AntiVirus AdWare.MegaSearch
VIPRE Antivirus Trojan.Win32.Generic!BT
ViRobot Adware.Agent.498176.A
Dr.Web Trojan.Crossrider.37
ByteHero BDV Trojan.Exception.gen.101

Software Details

URL:
https://optonthing.info
Support:
–
Installation path:
C:\ProgramData\grtscouponapp
Uninstaller:
"C:\ProgramData\GrtSCouponApp\3LkVZZwt.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
531.00 KB
Language:
English

GrtSCouponApp Executable Details

Primary executable:
3LkVZZwt.exe
Name:
GrtSCouponApp
Path:
C:\ProgramData\grtscouponapp\3LkVZZwt.exe
MD5:
9c354249e2b00af7362d8eecaee9b2b2
SHA-1:
–
SHA-256:
–
Files installed by GrtSCouponApp
File Type Filename MD5
EXE
aQy.exe
Malware
b762b67e59693ce11d0d861fd9e9a0a9
EXE
9c354249e2b00af7362d8eecaee9b2b2
EXE
926838555c7e13f295fda017b3fa3ea9
EXE
926838555c7e13f295fda017b3fa3ea9
EXE
9c354249e2b00af7362d8eecaee9b2b2
EXE
7_.exe
Malware
926838555c7e13f295fda017b3fa3ea9
EXE
9c354249e2b00af7362d8eecaee9b2b2
EXE
9c354249e2b00af7362d8eecaee9b2b2
EXE
hVE.exe
Malware
06cfeaa6556d9264ef303884935ddfe2