TakeTheCouPon

TakeTheCouPon

Known Toolbar

by InstalleRex-WebPick

What is TakeTheCouPon?

TakeTheCouPon is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 71.43% of installations running this operating system. TakeTheCouPon's installer is typically 1.00 MB in size and installs around 14 files.

TakeTheCouPon is most popular in the United States with 41.67% of installations residing in this country.

About TakeTheCouPon?

TakeTheCoupon is a software program that displays additional advertisements to users when they are using search engines such as Bing and Google. It installs itself as an extension in Chrome, as a process and Browser Helper Object in Internet Explorer, and as a Windows add-on. While it creates an entry in the Add or Remove Programs section of the Control Panel, removing this entry may not stop the adware from displaying ads. Once installed, TakeTheCoupon injects and inserts new ads into search results and various web pages that utilize third-party advertising. The adware uses the InstalleRex download and install manager from WebPicks Holdings to distribute Pay Per Install monetized software, including unwanted toolbars and web browser extensions.

Multiple virus scanners have detected malware in TakeTheCouPon.

tB.x64.dll (MD5: 9e0383fb82ce83bd785951c20f3fe959) has been flagged by 4 scanners:
Scanner Software Result
AhnLab-V3 Trojan/Win32.Preloader
Baidu-International Adware.Win64.MultiPlug.A
ESET-NOD32 a variant of Win64/Adware.MultiPlug.A
Malwarebytes PUP.Optional.MultiPlug.A
tB.dll (MD5: 1550537f5aee53fec3b74eb4605f8483) has been flagged by 26 scanners:
Scanner Software Result
Avira AntiVir ADWARE/Adware.Gen
AVG Generic5.ALFJ
Baidu-International Adware.Win32.MultiPlug.40
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.N
K7 AntiVirus Adware ( 004923a41 )
K7GW Adware ( 004923a41 )
Malwarebytes PUP.Optional.MultiPlug.A
Rising Antivirus PE:Malware.Adware!6.1293
TrendMicro-HouseCall TROJ_GEN.F47V1230
VIPRE Antivirus JustPlugIt (fs)
Lavasoft Ad-Aware Gen:Variant.Graftor.150430
AhnLab-V3 Trojan/Win32.Preloader
avast! Win32:MultiPlug-BG [PUP]
Bitdefender Gen:Variant.Graftor.150430
Emsisoft Anti-Malware Gen:Variant.Graftor.150430 (B)
G Data Gen:Variant.Graftor.150430
MicroWorld-eScan Gen:Variant.Graftor.150430
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.bfk
Sophos Generic PUA GP
Antiy-AVL Trojan/Win32.TGeneric
McAfee Artemis!BD9FB537D3D3
McAfee-GW-Edition Artemis!BD9FB537D3D3
Symantec Trojan.Gen.2
Qihoo-360 HEUR/Malware.QVM10.Gen
Trend Micro ADW_MULTIPLUG
5l45kLxUh.exe (MD5: 83c728a3d4b56127985b096478a943f8) has been flagged by 34 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.623657
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Dropper/Win32.Preloader
Avira AntiVir SPR/Tool.460800.1
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.81
Bitdefender Application.Generic.623657
Bkav FE W32.PatgeasM.Trojan
Comodo Security Application.Win32.MultiPlug.SJ
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.623657
G Data Application.Generic.623657
K7 AntiVirus Adware ( 004976341 )
K7GW Adware ( 004976341 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee RDN/Generic.dx!dcf
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
MicroWorld-eScan Application.Generic.623657
Panda Antivirus Trj/Genetic.gen
TrendMicro-HouseCall TROJ_GEN.R0CBH06ES14
VIPRE Antivirus Trojan.Win32.Generic!BT
avast! Win32:Dropper-gen [Drp]
AVware Trojan.Win32.Generic!BT
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AY
IKARUS anti.virus PUA.Generic
Sophos Generic PUA NF
Trend Micro ADW_MULTIPLUG
AegisLab AdWare.Win64.MegaSearch
Rising Antivirus PE:Malware.Adware!6.1293
Emsisoft Anti-Malware Gen:Variant.Graftor.150430 (B)
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.bfk
Antiy-AVL Trojan/Win32.TGeneric
Symantec Trojan.Gen.2
Qihoo-360 HEUR/Malware.QVM10.Gen
H_EN.x64.dll (MD5: f304e79ecc51db8c3bbc11388ff4548a) has been flagged by 29 scanners:
Scanner Software Result
AegisLab AdWare.Win64.MegaSearch
AhnLab-V3 Trojan/Win64.Preloader
AVG Generic_r.KM
AVware Win64.Adware.MultiPlug
Baidu-International Adware.Win64.MultiPlug.81
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win64/Adware.MultiPlug.B
K7 AntiVirus Adware ( 004a86af1 )
K7GW Adware ( 004a86af1 )
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!cf3
McAfee-GW-Edition BehavesLike.Win64.Downloader.fm
TrendMicro-HouseCall TROJ_GEN.R0E6H06J614
VIPRE Antivirus Win64.Adware.MultiPlug
avast! Win64:Malware-gen
IKARUS anti.virus PUA.Multiplug
Avira AntiVir ADWARE/Adware.Gen
Rising Antivirus PE:Malware.Adware!6.1293
Lavasoft Ad-Aware Gen:Variant.Graftor.150430
Bitdefender Gen:Variant.Graftor.150430
Emsisoft Anti-Malware Gen:Variant.Graftor.150430 (B)
G Data Gen:Variant.Graftor.150430
MicroWorld-eScan Gen:Variant.Graftor.150430
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.bfk
Sophos Generic PUA GP
Antiy-AVL Trojan/Win32.TGeneric
Symantec Trojan.Gen.2
Qihoo-360 HEUR/Malware.QVM10.Gen
Trend Micro ADW_MULTIPLUG
H_EN.dll (MD5: bd9fb537d3d37af56a526b60e5ab0166) has been flagged by 15 scanners:
Scanner Software Result
Antiy-AVL Trojan/Win32.TGeneric
avast! Win32:Adware-gen [Adw]
AVG Generic_r.KL
Baidu-International Adware.Win32.MultiPlug.81
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
McAfee Artemis!BD9FB537D3D3
McAfee-GW-Edition Artemis!BD9FB537D3D3
Symantec Trojan.Gen.2
TrendMicro-HouseCall Suspicious_GEN.F47V0611
AhnLab-V3 Dropper/Win32.Preloader
VIPRE Antivirus Trojan.Win32.Generic!BT
Comodo Security ApplicUnwnt
Malwarebytes PUP.Optional.MultiPlug.A
Qihoo-360 HEUR/Malware.QVM10.Gen
Trend Micro ADW_MULTIPLUG

Software Details

URL:
https://justplug.it
Support:
Installation path:
C:\ProgramData\takethecoupon
Uninstaller:
"C:\ProgramData\TakeTheCouPon\tB.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
1.00 MB
Language:
English

TakeTheCouPon Executable Details

Primary executable:
tB.exe
Name:
TakeTheCouPon
Path:
C:\ProgramData\takethecoupon\tB.exe
MD5:
f5bff621c4c58358b36f8526dec8a264
SHA-1:
SHA-256:
Files installed by TakeTheCouPon
File Type Filename MD5
DLL
5337ab32d06451b51b031fad03674a73
EXE
USSf.exe
Malware
6cb0e030d27ab41c08823d43767436ea
EXE
tB.exe
Adware
f5bff621c4c58358b36f8526dec8a264
EXE
ef38514253e4dafb6823f236bc47bb5f