PUA

PUAAdvertising:Win32/CouponarificAds removal instruction

Malware Removal

The PUAAdvertising:Win32/CouponarificAds is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUAAdvertising:Win32/CouponarificAds virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PUAAdvertising:Win32/CouponarificAds?


File Info:

name: 2DC7FD15AEB7B0789B50.mlw
path: /opt/CAPEv2/storage/binaries/c7a301f28950056da8b3e9ea5eb1f05378ed5e9b46b6f1957cee86cd17427449
crc32: F9673228
md5: 2dc7fd15aeb7b0789b503132e66427db
sha1: 0eeeb2dd6ef0ec955492478a071c1b4ccb36dc56
sha256: c7a301f28950056da8b3e9ea5eb1f05378ed5e9b46b6f1957cee86cd17427449
sha512: 841a3996d354142bdb00bf459db86ebe325925af0400e0cb0b74bfa2c25256dd83383d59645e45ef8f4cab134634948a9ee349f57ebc8bca532b5c6ed5a9ccb7
ssdeep: 49152:q4GSyrTvB1wcOu8zcpt7Av5idjUnMjzyw9cvkX5fqpY:q45yrTZ1POuTtJ4Gzy2cvkX5fqpY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154C5336A0E98CD22F4CED8F0F5968944DC55F96A8AEE8C00CDF5876ED5FCAC2B459403
sha3_384: 2ba1f52ad088c2cb568d6cf0b48a343f5eced410486e42582981112ff337abe7e82476f8b981d09fa5a855c7f8c8ae1b
ep_bytes: 60be007070008dbe00a0cfff57eb0b90
timestamp: 2013-05-21 18:43:01

Version Info:

0: [No Data]

PUAAdvertising:Win32/CouponarificAds also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
CAT-QuickHealPUA.Rbmftechno.Gen
SkyhighGenericRXIT-AI!2DC7FD15AEB7
MalwarebytesMalware.AI.1692442151
K7GWUnwanted-Program ( 0058767c1 )
K7AntiVirusUnwanted-Program ( 0058767c1 )
VirITPUP.Win32.RBMF.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Downloader.Agent.Q potentially unwanted
ClamAVWin.Malware.Todos-10003941-0
NANO-AntivirusTrojan.Win32.DownLoad3.dnnevy
EmsisoftApplication.Downloader (A)
DrWebAdware.AdPeak.25
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusAdWare.Todos
JiangminWorm.Runouce.bb
VaristW32/A-961be342!Eldorado
Antiy-AVLGrayWare[AdWare]/Win32.CouponarificAds
MicrosoftPUAAdvertising:Win32/CouponarificAds
GoogleDetected
McAfeeGenericRXIT-AI!2DC7FD15AEB7
VBA32BScope.Adware.AdPeak
RisingDownloader.Agent!8.B23 (TFE:5:7MCUQfrXn9P)
YandexRiskware.Agent!93p7t/RVNO0
MaxSecureTrojan.W32.pse.zp9r3w_S13_364075
FortinetRiskware/Downloader_Agent
DeepInstinctMALICIOUS

How to remove PUAAdvertising:Win32/CouponarificAds?

PUAAdvertising:Win32/CouponarificAds removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment