unicoupons

unicoupons

Known Toolbar

by InstalleRex-WebPick

What is unicoupons?

unicoupons is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 51.04% of installations running this operating system. unicoupons's installer is typically 633.00 KB in size and installs around 54 files.

unicoupons is most popular in the United States with 99.39% of installations residing in this country.

About unicoupons?

This adware program is a JustPlug.It web browser extension that is distributed through the WebPick (InstalleRex) download and install manager. It is commonly bundled with various adware offers and functions as a cross-browser extension with multiple components, including a Windows service, an auto-starting component, and a browser toolbar/plugin. Its primary purpose is to inject advertisements in the browser in the form of banner ads, hyper-text links, and pop-ups. Some versions may also interfere with existing advertising on websites and insert affiliate codes in links as coupon offers. Upon installation, the program creates a folder with a randomized name in either Program Files or ProgramData, and each included file is also given a unique, randomized name. The displayed advertisements may include deceptive malvertising ads promoting 'required' updates for common programs and unwanted pop-up advertisements. Furthermore, downloading the program may result in the installation of bundled adware utilities and additional browser extensions. Certain components of this program also have the capability to modify the browser's default security settings.

Multiple virus scanners have detected malware in unicoupons.

c.exe (MD5: 59e778761fcc79548bbb3cdc5e47ff5b) has been flagged by 21 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Strictor.61989
AhnLab-V3 Trojan/Win32.Preloader
Avira TR/Crypt.EPACK.Gen2
Baidu-International Adware.Win32.MultiPlug.bBN
Bitdefender Gen:Variant.Adware.Strictor.61989
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.BN
F-Secure Gen:Variant.Adware.Strictor.61989
G Data Gen:Variant.Adware.Strictor.61989
Malwarebytes PUP.Optional.MultiPlug
McAfee-GW-Edition BehavesLike.Win32.Adware.jh
MicroWorld-eScan Gen:Variant.Adware.Strictor.61989
Panda Antivirus Trj/Genetic.gen
AVG Generic_r.TN
IKARUS anti.virus PUA.Multiplug
K7 AntiVirus Adware ( 004a921f1 )
K7GW Adware ( 004a921f1 )
McAfee Artemis!5B2A2E54737A
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0907
Antiy-AVL Trojan/Win32.SGeneric
j.exe (MD5: 4093b564f2e1195a2fe2290b4218afdb) has been flagged by 39 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Strictor.61989
AegisLab Troj.W32.Gen
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Trojan/Win32.Preloader
Antiy-AVL Trojan/Win32.SGeneric
avast! Win32:Adware-gen [Adw]
AVG Generic5.BJTP
Avira TR/Crypt.EPACK.Gen2
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.bBN
Bitdefender Gen:Variant.Adware.Strictor.61989
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.BN
Fortinet FortiGate Riskware/MultiPlug
F-Secure Gen:Variant.Adware.Strictor.61989
G Data Gen:Variant.Adware.Strictor.61989
K7 AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!cmx
McAfee-GW-Edition BehavesLike.Win32.Downloader.jh
MicroWorld-eScan Gen:Variant.Adware.Strictor.61989
NANO AntiVirus Trojan.Win32.EPACK.denyxj
Qihoo-360 Win32/Trojan.e54
Rising Antivirus PE:Trojan.Win32.Generic.1742C76D!390252397
Sophos Generic PUA ME
Symantec Trojan.Gen
Trend Micro TROJ_SPNR.35JG14
TrendMicro-HouseCall TROJ_SPNR.35JG14
VIPRE Antivirus Trojan.Win32.Generic!BT
Panda Antivirus Trj/Genetic.gen
Vba32 AntiVirus AdWare.Agent
Kaspersky not-a-virus:AdWare.Win32.Agent.espp
Tencent Win32.Adware.Agent.Svra
IKARUS anti.virus Win32.SuspectCrc
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
F-Prot W32/A-4a0379ef!Eldorado
Norman Suspicious_Gen5.AUTMM
u7S7izkWj.exe (MD5: 912268224957d91a61cbbd5ccdb14e26) has been flagged by 33 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Strictor.61989
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Trojan/Win32.Preloader
Antiy-AVL Trojan/Win32.TSGeneric
avast! Win32:Adware-gen [Adw]
AVG Generic5.BJNX
Avira TR/Crypt.EPACK.28354
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.BBN
Bitdefender Gen:Variant.Adware.Strictor.61989
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)
Fortinet FortiGate Riskware/MultiPlug
F-Secure Gen:Variant.Adware.Strictor.61989
G Data Gen:Variant.Adware.Strictor.61989
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!cmx
McAfee-GW-Edition BehavesLike.Win32.Adware.jh
MicroWorld-eScan Gen:Variant.Adware.Strictor.61989
Norman Troj_Generic.VQNQO
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM08.Gen
Symantec Trojan.Gen
VIPRE Antivirus Trojan.Win32.Generic!BT
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.BN
IKARUS anti.virus not-a-virus:AdWare.Agent
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Rising Antivirus PE:Trojan.Win32.Generic.17412456!390145110
Sophos Generic PUA NB
TrendMicro-HouseCall TROJ_GEN.R072H09IA14
AegisLab AdWare.Win64.MegaSearch
FJObqVc.exe (MD5: e82711d00b009e21b5d79efb11a41edb) has been flagged by 21 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Strictor.61989
AhnLab-V3 Trojan/Win32.Preloader
Avira TR/Crypt.EPACK.Gen2
Baidu-International Adware.Win32.MultiPlug.bBN
Bitdefender Gen:Variant.Adware.Strictor.61989
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.BN
F-Secure Gen:Variant.Adware.Strictor.61989
G Data Gen:Variant.Adware.Strictor.61989
Malwarebytes PUP.Optional.MultiPlug
McAfee-GW-Edition BehavesLike.Win32.Adware.jh
MicroWorld-eScan Gen:Variant.Adware.Strictor.61989
Panda Antivirus Trj/Genetic.gen
AVG Generic_r.TN
IKARUS anti.virus PUA.Multiplug
K7 AntiVirus Adware ( 004a921f1 )
K7GW Adware ( 004a921f1 )
McAfee Artemis!5B2A2E54737A
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0907
Antiy-AVL Trojan/Win32.SGeneric
F4uWcZ6C_.exe (MD5: 635cb5d678a60649b001160eee29ac99) has been flagged by 43 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Strictor.61989
AegisLab Troj.W32.Gen
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Trojan/Win32.Preloader
avast! Win32:Adware-gen [Adw]
AVG Generic_r.TO
Avira TR/Crypt.EPACK.Gen2
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.bBN
Bitdefender Gen:Variant.Adware.Strictor.61989
Clam AntiVirus Win.Adware.Strictor-127
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.BN
Fortinet FortiGate Riskware/MultiPlug
F-Secure Gen:Variant.Adware.Strictor.61989
G Data Gen:Variant.Adware.Strictor.61989
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!cn3
McAfee-GW-Edition BehavesLike.Win32.Downloader.jh
MicroWorld-eScan Gen:Variant.Adware.Strictor.61989
NANO AntiVirus Trojan.Win32.EPACK.dfbaww
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Trojan.Win32.Generic.1748A35B!390636379
Sophos Generic PUA LM
Symantec WS.Reputation.1
Trend Micro TROJ_GEN.R000C0PIP14
TrendMicro-HouseCall TROJ_GEN.R000C0PIP14
Vba32 AntiVirus AdWare.Agent
VIPRE Antivirus Trojan.Win32.Generic!BT
ViRobot Trojan.Win32.S.Generic.630784
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
CAT-QuickHeal AdWare.JS.r6 (Not a Virus)
Dr.Web Adware.Siggen.31198
Kaspersky not-a-virus:AdWare.JS.MultiPlug.s
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Tencent Js.Adware.Multiplug.Hrys
Qihoo-360 Win32/Trojan.e54
IKARUS anti.virus Win32.SuspectCrc
F-Prot W32/A-4a0379ef!Eldorado
Norman Suspicious_Gen5.AUTMM

Software Details

URL:
–
Support:
–
Installation path:
C:\ProgramData\unicoupons
Uninstaller:
"C:\ProgramData\unicoupons\w1.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
633.00 KB
Language:
English

unicoupons Executable Details

Primary executable:
w1.exe
Name:
unicoupons
Path:
C:\ProgramData\unicoupons\w1.exe
MD5:
d86951e59c545bddfcd115e399cfc2d4
SHA-1:
–
SHA-256:
–
Files installed by unicoupons
File Type Filename MD5
DLL
b89d59d8c1109462bb01c1be835a5b00
DLL
ZNR7l.dll
Malware
06d0d7c3bb5b0b3477379e5f2ea381e6
DLL
8426ecfacc4a2a6901773fbc3d457729
DLL
087b39664356daa5b6aa9c6d25031504
DLL
3c10f95e9f2f5e10a893018a5c9257ee
DLL
b9497bd494cdfdb7270c8deee24e8418
EXE
B9p.exe
Malware
5e164e98b2c551a7c6bfae90be4da159
DLL
7f083492901d68353b235cded25b25df
EXE
d62717160a2dffb0c6a53b625e69663d
DLL
0869f9e5430e1b545b4fb4f30cb5b945