NExtCoup

NExtCoup

Known Toolbar

by InstalleRex-WebPick

What is NExtCoup?

NExtCoup is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 63.27% of installations running this operating system. NExtCoup's installer is typically 683.00 KB in size and installs around 47 files. The most common release is 2.1.0.1195 with 18.37% of all installations currently using this version.

NExtCoup is most popular in the United States with 32.59% of installations residing in this country.

About NExtCoup?

NextCoup is a robust web browser extension developed by JustPlug.It and distributed through the WebPick (InstalleRex) download and install manager. This cross-browser extension contains various parts including a Windows service, an auto-starting component, and a browser toolbar/plugin. Its primary function is to deliver advertisements in the form of banner ads, hyper-text links, and popups to the browser. It is important to note that some versions of NextCoup may also interfere with existing advertising on websites and inject affiliate codes into links as coupon offers. These advertisements can range from deceptive malvertising ads for supposed updates of common programs to unwanted pop-up ads. Downloading NextCoup may result in the installation of bundled adware utilities and additional browser extensions, as well as modifications to the browser's default security settings. Therefore, users should exercise caution when considering the installation of the NextCoup browser extension.

Multiple virus scanners have detected malware in NExtCoup.

7U.exe (MD5: 18c75d6e6235019d9d92dd51ff43cc3b) has been flagged by 14 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:Dropper-gen [Drp]
ByteHero BDV Trojan.Exception.gen.101
Dr.Web Trojan.Crossrider.5139
McAfee Artemis!18C75D6E6235
McAfee-GW-Edition Artemis!18C75D6E6235
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.F47V0317
VIPRE Antivirus JustPlugIt (fs)
Malwarebytes PUP.Optional.Multiplug
ViRobot Adware.Agent.695808
Baidu-International Adware.Win32.BHO.77
AVG Generic5.AVLQ
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
IOza74Zg9U.exe (MD5: 028c1a42ac6ff8fc1798d94718ed480f) has been flagged by 25 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.621135
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:MultiPlug-AD [PUP]
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.45
Bitdefender Application.Generic.621135
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.T
G Data Application.Generic.621135
K7GW Adware ( 004976341 )
Malwarebytes PUP.Optional.MultiPlug.A
MicroWorld-eScan Application.Generic.621135
TrendMicro-HouseCall TROJ_GEN.F47V0416
VIPRE Antivirus Trojan.Win32.Generic!BT
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.146103 (B)
F-Secure Gen:Variant.Adware.Graftor.146103
IKARUS anti.virus PUA.Generic
Panda Antivirus Trj/Genetic.gen
Avira AntiVir TR/Crypt.EPACK.Gen2
McAfee Artemis!B1F78E265F3F
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
Symantec WS.Reputation.1
ByteHero BDV Trojan.Exception.gen.101
Dr.Web Trojan.Crossrider.5139
ViRobot Adware.Agent.695808
oD9mTf4.exe (MD5: dc0ac7dbdcbbb8b2561ba9b8ccab3d37) has been flagged by 9 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
Malwarebytes PUP.Optional.Multiplug
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
Symantec WS.Reputation.1
ViRobot Adware.Agent.695808
Baidu-International Adware.Win32.BHO.77
TrendMicro-HouseCall TROJ_GEN.F47V0519
AVG Generic5.AVLQ
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
D0zcx5rxUN.exe (MD5: a6786c28986b3261f026078a4c098436) has been flagged by 22 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.61989
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir TR/Crypt.EPACK.Gen2
Baidu-International Trojan.Win32.a.bgen
Bitdefender Gen:Variant.Adware.61989
Emsisoft Anti-Malware Gen:Variant.Adware.61989 (B)
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AG
F-Secure Gen:Variant.Adware.61989
G Data Gen:Variant.Adware.61989
Malwarebytes PUP.Optional.MultiPlug
MicroWorld-eScan Gen:Variant.Adware.61989
AVG Generic5.AQUI
Comodo Security Application.Win32.MultiPlug.SJ
McAfee Artemis!B1F78E265F3F
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.F47V0402
VIPRE Antivirus Trojan.Win32.Generic!BT
avast! Win32:Dropper-gen [Drp]
ByteHero BDV Trojan.Exception.gen.101
Dr.Web Trojan.Crossrider.5139
ViRobot Adware.Agent.695808
5bIvfXqFT.exe (MD5: 548e90ec0f1c80a218e085bdcdc8035e) has been flagged by 33 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.678619
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Trojan/Win32.Preloader
avast! Win32:Dropper-gen [Drp]
AVG Generic5.AZDH
Baidu-International PUA.Win32.CRXDrop.77
Bitdefender Application.Generic.678619
Bkav FE W32.CureivantLTAS.Adware
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AG
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.678619
G Data Application.Generic.678619
K7 AntiVirus Adware ( 0049c94b1 )
K7GW Adware ( 0049c94b1 )
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic.bfr!ho
McAfee-GW-Edition RDN/Generic.bfr!ho
MicroWorld-eScan Application.Generic.678619
Panda Antivirus Trj/CI.A
Sophos Generic PUA EH
TrendMicro-HouseCall TROJ_GEN.R0CBH06GJ14
VIPRE Antivirus Trojan.Win32.Generic!BT
Qihoo-360 Win32/Trojan.Dropper.c9f
Symantec WS.Reputation.1
Avira AntiVir SPR/Tool.461312.1
Antiy-AVL Trojan/Win32.SGeneric
ByteHero BDV Trojan.Exception.gen.101
IKARUS anti.virus Win32.SuspectCrc
AVware Trojan.Win32.Generic!BT
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.146103 (B)
Dr.Web Trojan.Crossrider.5139
ViRobot Adware.Agent.695808

Software Details

URL:
https://nextcoup.info
Support:
–
Installation path:
C:\ProgramData\nextcoup
Uninstaller:
"C:\ProgramData\NExtCoup\JKHq.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
683.00 KB
Language:
English

NExtCoup Executable Details

Primary executable:
JKHq.exe
Name:
NExtCoup
Path:
C:\ProgramData\nextcoup\JKHq.exe
MD5:
815b3303270ea4ce5a226f0e011f1bd5
SHA-1:
–
SHA-256:
–
Files installed by NExtCoup
File Type Filename MD5
EXE
90403d362277231c8ece1c4da79cb667
EXE
5b288612fe43837c7a6b439eaed297d8
EXE
7U.exe
Adware
18c75d6e6235019d9d92dd51ff43cc3b
EXE
028c1a42ac6ff8fc1798d94718ed480f
EXE
dc0ac7dbdcbbb8b2561ba9b8ccab3d37
EXE
dc0ac7dbdcbbb8b2561ba9b8ccab3d37
EXE
dc0ac7dbdcbbb8b2561ba9b8ccab3d37
EXE
a6786c28986b3261f026078a4c098436
EXE
548e90ec0f1c80a218e085bdcdc8035e
EXE
be5c16f6998f6d7473150524c8338c62