PUA

About “PUAAdvertising:Win32/CouponarificAds” infection

Malware Removal

The PUAAdvertising:Win32/CouponarificAds is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUAAdvertising:Win32/CouponarificAds virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PUAAdvertising:Win32/CouponarificAds?


File Info:

name: F1DFEDEEB0D10D80E06F.mlw
path: /opt/CAPEv2/storage/binaries/f0c2bc9b4cb84d7acc614b961ec18de19a54247ee0ebd01cd8f44f1737a164a7
crc32: A4C152C2
md5: f1dfedeeb0d10d80e06f4750d19822e9
sha1: a5771bd90408ac54580af2f166ae519c97cbb1c1
sha256: f0c2bc9b4cb84d7acc614b961ec18de19a54247ee0ebd01cd8f44f1737a164a7
sha512: 8ff13daa9f135dfbebbdcb358509f5988a28683ec7c1f8c7470dfb3f2f34eb0ea627705c52b3cbb4a06bb7a444c5d0385eefbd3554453176b983741e80569ad0
ssdeep: 49152:UiJXWMtjSqqtWftokpxwQ8ooF8CC8Yk5IR/A2ZvDHwP2BG+1h6w+iIjPW:UiZWMwdQokUo1CYk5QvweBGKEw+LPW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108C5235A871C8871DACADCF04195B1FDC5BE7A007F09912076B6C495F9F8FAE390E90A
sha3_384: 413c98479b6148211a735355a1ee3e6bdf13e13252e16ab07f7ab34edaead0148343ab73dc677677751892c31df13e92
ep_bytes: 60be00f06f008dbe0020d0ff57eb0b90
timestamp: 2013-05-22 15:10:15

Version Info:

0: [No Data]

PUAAdvertising:Win32/CouponarificAds also known as:

Elasticmalicious (moderate confidence)
CAT-QuickHealPUA.Rbmftechno.Gen
K7AntiVirusTrojan-Downloader ( 00583a7f1 )
K7GWTrojan-Downloader ( 00583a7f1 )
VirITPUP.Win32.RBMF.A
ESET-NOD32a variant of Win32/Downloader.Agent.Q potentially unwanted
ClamAVWin.Malware.Todos-10003941-0
NANO-AntivirusRiskware.Win32.AdPeak.eleatp
SophosGeneric ML PUA (PUA)
DrWebAdware.AdPeak.25
Trapminemalicious.moderate.ml.score
EmsisoftApplication.Downloader (A)
JiangminWorm.Runouce.bb
GoogleDetected
VaristW32/A-961be342!Eldorado
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftPUAAdvertising:Win32/CouponarificAds
VBA32BScope.Adware.AdPeak
MalwarebytesMalware.AI.4165252881
RisingDownloader.Agent!8.B23 (TFE:5:7MCUQfrXn9P)
YandexRiskware.Agent!GCpfmLY6o5A
IkarusAdWare.Todos
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Downloader_Agent
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_70% (D)

How to remove PUAAdvertising:Win32/CouponarificAds?

PUAAdvertising:Win32/CouponarificAds removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment