unicoupons

unicoupons

Known Toolbar

by InstalleRex-WebPick

What is unicoupons?

unicoupons is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 51.04% of installations running this operating system. unicoupons's installer is typically 633.00 KB in size and installs around 54 files.

unicoupons is most popular in the United States with 99.39% of installations residing in this country.

About unicoupons?

This adware program is a JustPlug.It web browser extension that is distributed through the WebPick (InstalleRex) download and install manager. It is commonly bundled with various adware offers and functions as a cross-browser extension with multiple components, including a Windows service, an auto-starting component, and a browser toolbar/plugin. Its primary purpose is to inject advertisements in the browser in the form of banner ads, hyper-text links, and pop-ups. Some versions may also interfere with existing advertising on websites and insert affiliate codes in links as coupon offers. Upon installation, the program creates a folder with a randomized name in either Program Files or ProgramData, and each included file is also given a unique, randomized name. The displayed advertisements may include deceptive malvertising ads promoting 'required' updates for common programs and unwanted pop-up advertisements. Furthermore, downloading the program may result in the installation of bundled adware utilities and additional browser extensions. Certain components of this program also have the capability to modify the browser's default security settings.

Multiple virus scanners have detected malware in unicoupons.

c.exe (MD5: 59e778761fcc79548bbb3cdc5e47ff5b) has been flagged by 21 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Strictor.61989
AhnLab-V3 Trojan/Win32.Preloader
Avira TR/Crypt.EPACK.Gen2
Baidu-International Adware.Win32.MultiPlug.bBN
Bitdefender Gen:Variant.Adware.Strictor.61989
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.BN
F-Secure Gen:Variant.Adware.Strictor.61989
G Data Gen:Variant.Adware.Strictor.61989
Malwarebytes PUP.Optional.MultiPlug
McAfee-GW-Edition BehavesLike.Win32.Adware.jh
MicroWorld-eScan Gen:Variant.Adware.Strictor.61989
Panda Antivirus Trj/Genetic.gen
AVG Generic_r.TN
IKARUS anti.virus PUA.Multiplug
K7 AntiVirus Adware ( 004a921f1 )
K7GW Adware ( 004a921f1 )
McAfee Artemis!5B2A2E54737A
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0907
Antiy-AVL Trojan/Win32.SGeneric
j.exe (MD5: 4093b564f2e1195a2fe2290b4218afdb) has been flagged by 39 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Strictor.61989
AegisLab Troj.W32.Gen
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Trojan/Win32.Preloader
Antiy-AVL Trojan/Win32.SGeneric
avast! Win32:Adware-gen [Adw]
AVG Generic5.BJTP
Avira TR/Crypt.EPACK.Gen2
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.bBN
Bitdefender Gen:Variant.Adware.Strictor.61989
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.BN
Fortinet FortiGate Riskware/MultiPlug
F-Secure Gen:Variant.Adware.Strictor.61989
G Data Gen:Variant.Adware.Strictor.61989
K7 AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!cmx
McAfee-GW-Edition BehavesLike.Win32.Downloader.jh
MicroWorld-eScan Gen:Variant.Adware.Strictor.61989
NANO AntiVirus Trojan.Win32.EPACK.denyxj
Qihoo-360 Win32/Trojan.e54
Rising Antivirus PE:Trojan.Win32.Generic.1742C76D!390252397
Sophos Generic PUA ME
Symantec Trojan.Gen
Trend Micro TROJ_SPNR.35JG14
TrendMicro-HouseCall TROJ_SPNR.35JG14
VIPRE Antivirus Trojan.Win32.Generic!BT
Panda Antivirus Trj/Genetic.gen
Vba32 AntiVirus AdWare.Agent
Kaspersky not-a-virus:AdWare.Win32.Agent.espp
Tencent Win32.Adware.Agent.Svra
IKARUS anti.virus Win32.SuspectCrc
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
F-Prot W32/A-4a0379ef!Eldorado
Norman Suspicious_Gen5.AUTMM
u7S7izkWj.exe (MD5: 912268224957d91a61cbbd5ccdb14e26) has been flagged by 33 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Strictor.61989
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Trojan/Win32.Preloader
Antiy-AVL Trojan/Win32.TSGeneric
avast! Win32:Adware-gen [Adw]
AVG Generic5.BJNX
Avira TR/Crypt.EPACK.28354
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.BBN
Bitdefender Gen:Variant.Adware.Strictor.61989
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)
Fortinet FortiGate Riskware/MultiPlug
F-Secure Gen:Variant.Adware.Strictor.61989
G Data Gen:Variant.Adware.Strictor.61989
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!cmx
McAfee-GW-Edition BehavesLike.Win32.Adware.jh
MicroWorld-eScan Gen:Variant.Adware.Strictor.61989
Norman Troj_Generic.VQNQO
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM08.Gen
Symantec Trojan.Gen
VIPRE Antivirus Trojan.Win32.Generic!BT
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.BN
IKARUS anti.virus not-a-virus:AdWare.Agent
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Rising Antivirus PE:Trojan.Win32.Generic.17412456!390145110
Sophos Generic PUA NB
TrendMicro-HouseCall TROJ_GEN.R072H09IA14
AegisLab AdWare.Win64.MegaSearch
FJObqVc.exe (MD5: e82711d00b009e21b5d79efb11a41edb) has been flagged by 21 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Strictor.61989
AhnLab-V3 Trojan/Win32.Preloader
Avira TR/Crypt.EPACK.Gen2
Baidu-International Adware.Win32.MultiPlug.bBN
Bitdefender Gen:Variant.Adware.Strictor.61989
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.BN
F-Secure Gen:Variant.Adware.Strictor.61989
G Data Gen:Variant.Adware.Strictor.61989
Malwarebytes PUP.Optional.MultiPlug
McAfee-GW-Edition BehavesLike.Win32.Adware.jh
MicroWorld-eScan Gen:Variant.Adware.Strictor.61989
Panda Antivirus Trj/Genetic.gen
AVG Generic_r.TN
IKARUS anti.virus PUA.Multiplug
K7 AntiVirus Adware ( 004a921f1 )
K7GW Adware ( 004a921f1 )
McAfee Artemis!5B2A2E54737A
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0907
Antiy-AVL Trojan/Win32.SGeneric
F4uWcZ6C_.exe (MD5: 635cb5d678a60649b001160eee29ac99) has been flagged by 43 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Strictor.61989
AegisLab Troj.W32.Gen
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Trojan/Win32.Preloader
avast! Win32:Adware-gen [Adw]
AVG Generic_r.TO
Avira TR/Crypt.EPACK.Gen2
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.bBN
Bitdefender Gen:Variant.Adware.Strictor.61989
Clam AntiVirus Win.Adware.Strictor-127
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.BN
Fortinet FortiGate Riskware/MultiPlug
F-Secure Gen:Variant.Adware.Strictor.61989
G Data Gen:Variant.Adware.Strictor.61989
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!cn3
McAfee-GW-Edition BehavesLike.Win32.Downloader.jh
MicroWorld-eScan Gen:Variant.Adware.Strictor.61989
NANO AntiVirus Trojan.Win32.EPACK.dfbaww
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Trojan.Win32.Generic.1748A35B!390636379
Sophos Generic PUA LM
Symantec WS.Reputation.1
Trend Micro TROJ_GEN.R000C0PIP14
TrendMicro-HouseCall TROJ_GEN.R000C0PIP14
Vba32 AntiVirus AdWare.Agent
VIPRE Antivirus Trojan.Win32.Generic!BT
ViRobot Trojan.Win32.S.Generic.630784
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
CAT-QuickHeal AdWare.JS.r6 (Not a Virus)
Dr.Web Adware.Siggen.31198
Kaspersky not-a-virus:AdWare.JS.MultiPlug.s
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Tencent Js.Adware.Multiplug.Hrys
Qihoo-360 Win32/Trojan.e54
IKARUS anti.virus Win32.SuspectCrc
F-Prot W32/A-4a0379ef!Eldorado
Norman Suspicious_Gen5.AUTMM

Software Details

URL:
–
Support:
–
Installation path:
C:\ProgramData\unicoupons
Uninstaller:
"C:\ProgramData\unicoupons\w1.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
633.00 KB
Language:
English

unicoupons Executable Details

Primary executable:
w1.exe
Name:
unicoupons
Path:
C:\ProgramData\unicoupons\w1.exe
MD5:
d86951e59c545bddfcd115e399cfc2d4
SHA-1:
–
SHA-256:
–
Files installed by unicoupons
File Type Filename MD5
EXE
e82711d00b009e21b5d79efb11a41edb
EXE
635cb5d678a60649b001160eee29ac99
DLL
c.x64.dll
Malware
6e0f4b68a1ce73382b71394c0d438291
DLL
4fd7d350d7efb1c31b5789a66e311155
DLL
B9p.dll
Malware
c24e2972111cd32508356a0033b0908f
DLL
ea44694f74d1411c94510d6a7de34477
DLL
a735db92bb05460f657bf37e8d16d048
EXE
ZNR7l.exe
Malware
a2a190e05361bc582813d102996e62b0
DLL
8536edf610723f63431ceb8780b1b09b
DLL
9277212faa6909c47acac64eca97019a