NExtCoup

NExtCoup

Known Toolbar

by InstalleRex-WebPick

What is NExtCoup?

NExtCoup is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 63.27% of installations running this operating system. NExtCoup's installer is typically 683.00 KB in size and installs around 47 files. The most common release is 2.1.0.1195 with 18.37% of all installations currently using this version.

NExtCoup is most popular in the United States with 32.59% of installations residing in this country.

About NExtCoup?

NextCoup is a robust web browser extension developed by JustPlug.It and distributed through the WebPick (InstalleRex) download and install manager. This cross-browser extension contains various parts including a Windows service, an auto-starting component, and a browser toolbar/plugin. Its primary function is to deliver advertisements in the form of banner ads, hyper-text links, and popups to the browser. It is important to note that some versions of NextCoup may also interfere with existing advertising on websites and inject affiliate codes into links as coupon offers. These advertisements can range from deceptive malvertising ads for supposed updates of common programs to unwanted pop-up ads. Downloading NextCoup may result in the installation of bundled adware utilities and additional browser extensions, as well as modifications to the browser's default security settings. Therefore, users should exercise caution when considering the installation of the NextCoup browser extension.

Multiple virus scanners have detected malware in NExtCoup.

7U.exe (MD5: 18c75d6e6235019d9d92dd51ff43cc3b) has been flagged by 14 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:Dropper-gen [Drp]
ByteHero BDV Trojan.Exception.gen.101
Dr.Web Trojan.Crossrider.5139
McAfee Artemis!18C75D6E6235
McAfee-GW-Edition Artemis!18C75D6E6235
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.F47V0317
VIPRE Antivirus JustPlugIt (fs)
Malwarebytes PUP.Optional.Multiplug
ViRobot Adware.Agent.695808
Baidu-International Adware.Win32.BHO.77
AVG Generic5.AVLQ
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
IOza74Zg9U.exe (MD5: 028c1a42ac6ff8fc1798d94718ed480f) has been flagged by 25 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.621135
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:MultiPlug-AD [PUP]
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.45
Bitdefender Application.Generic.621135
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.T
G Data Application.Generic.621135
K7GW Adware ( 004976341 )
Malwarebytes PUP.Optional.MultiPlug.A
MicroWorld-eScan Application.Generic.621135
TrendMicro-HouseCall TROJ_GEN.F47V0416
VIPRE Antivirus Trojan.Win32.Generic!BT
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.146103 (B)
F-Secure Gen:Variant.Adware.Graftor.146103
IKARUS anti.virus PUA.Generic
Panda Antivirus Trj/Genetic.gen
Avira AntiVir TR/Crypt.EPACK.Gen2
McAfee Artemis!B1F78E265F3F
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
Symantec WS.Reputation.1
ByteHero BDV Trojan.Exception.gen.101
Dr.Web Trojan.Crossrider.5139
ViRobot Adware.Agent.695808
oD9mTf4.exe (MD5: dc0ac7dbdcbbb8b2561ba9b8ccab3d37) has been flagged by 9 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
Malwarebytes PUP.Optional.Multiplug
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
Symantec WS.Reputation.1
ViRobot Adware.Agent.695808
Baidu-International Adware.Win32.BHO.77
TrendMicro-HouseCall TROJ_GEN.F47V0519
AVG Generic5.AVLQ
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
D0zcx5rxUN.exe (MD5: a6786c28986b3261f026078a4c098436) has been flagged by 22 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.61989
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir TR/Crypt.EPACK.Gen2
Baidu-International Trojan.Win32.a.bgen
Bitdefender Gen:Variant.Adware.61989
Emsisoft Anti-Malware Gen:Variant.Adware.61989 (B)
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AG
F-Secure Gen:Variant.Adware.61989
G Data Gen:Variant.Adware.61989
Malwarebytes PUP.Optional.MultiPlug
MicroWorld-eScan Gen:Variant.Adware.61989
AVG Generic5.AQUI
Comodo Security Application.Win32.MultiPlug.SJ
McAfee Artemis!B1F78E265F3F
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.F47V0402
VIPRE Antivirus Trojan.Win32.Generic!BT
avast! Win32:Dropper-gen [Drp]
ByteHero BDV Trojan.Exception.gen.101
Dr.Web Trojan.Crossrider.5139
ViRobot Adware.Agent.695808
5bIvfXqFT.exe (MD5: 548e90ec0f1c80a218e085bdcdc8035e) has been flagged by 33 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.678619
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Trojan/Win32.Preloader
avast! Win32:Dropper-gen [Drp]
AVG Generic5.AZDH
Baidu-International PUA.Win32.CRXDrop.77
Bitdefender Application.Generic.678619
Bkav FE W32.CureivantLTAS.Adware
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AG
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.678619
G Data Application.Generic.678619
K7 AntiVirus Adware ( 0049c94b1 )
K7GW Adware ( 0049c94b1 )
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic.bfr!ho
McAfee-GW-Edition RDN/Generic.bfr!ho
MicroWorld-eScan Application.Generic.678619
Panda Antivirus Trj/CI.A
Sophos Generic PUA EH
TrendMicro-HouseCall TROJ_GEN.R0CBH06GJ14
VIPRE Antivirus Trojan.Win32.Generic!BT
Qihoo-360 Win32/Trojan.Dropper.c9f
Symantec WS.Reputation.1
Avira AntiVir SPR/Tool.461312.1
Antiy-AVL Trojan/Win32.SGeneric
ByteHero BDV Trojan.Exception.gen.101
IKARUS anti.virus Win32.SuspectCrc
AVware Trojan.Win32.Generic!BT
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.146103 (B)
Dr.Web Trojan.Crossrider.5139
ViRobot Adware.Agent.695808

Software Details

URL:
https://nextcoup.info
Support:
–
Installation path:
C:\ProgramData\nextcoup
Uninstaller:
"C:\ProgramData\NExtCoup\JKHq.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
683.00 KB
Language:
English

NExtCoup Executable Details

Primary executable:
JKHq.exe
Name:
NExtCoup
Path:
C:\ProgramData\nextcoup\JKHq.exe
MD5:
815b3303270ea4ce5a226f0e011f1bd5
SHA-1:
–
SHA-256:
–
Files installed by NExtCoup
File Type Filename MD5
EXE
OT.exe
Malware
0e40283546a07f8655a29d2dd0eb47b2
EXE
7d1fbaee90ee5a343eade834b60dffb8
EXE
0c04e2c8473c5055c0b78944520806a3
EXE
6d3fd4a94b133387ec5382bab7414eb2
EXE
5Ib.exe
Malware
6d3fd4a94b133387ec5382bab7414eb2
EXE
1907e507d6ef5666d0bb269a05f27cff
EXE
1907e507d6ef5666d0bb269a05f27cff
EXE
1907e507d6ef5666d0bb269a05f27cff
EXE
822b6218dace16adaeef0a2dafb9b357
EXE
ec23e83d367281290af0228ffa7eada8