Home Malware Programs Adware Coupon Alerts

Coupon Alerts

Posted: November 13, 2013

Threat Metric

Ranking: 16,354
Threat Level: 2/10
Infected PCs: 9,389
First Seen: November 13, 2013
Last Seen: March 2, 2025
OS(es) Affected: Windows

Coupon Alerts Screenshot 1Coupon Alerts is an adware application known to display several pop-up ads attempting to offer users online savings our coupon deals. Coupon Alerts may be display at random causing an interruption of surfing the internet where it could have saving deals related to the site you are visiting. Additionally, Coupon Alerts ads may redirect users to unwanted sites where other ad deals are displayed. Stopping the constant Coupon Alerts ad pop-ups usually requires that the Coupon Alerts adware be removed from the system completely.

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Coupon Alerts may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\Coupon Alerts\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: 73fcdd7bdf2da7322ec435ec98cf5b63
Detection count: 23
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Coupon Alerts
Group: Malware file
Last Updated: June 11, 2014
%PROGRAMFILES(x86)%\Coupon Alerts\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 282.67 KB (282672 bytes)
MD5: 7225dbc4ce7c95a27bc83edc1968c61c
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Coupon Alerts
Group: Malware file
Last Updated: June 11, 2014
%PROGRAMFILES(x86)%\Coupon Alerts\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 345.64 KB (345648 bytes)
MD5: 2eea7a97ac744e159a621ea23999c055
Detection count: 16
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Coupon Alerts
Group: Malware file
Last Updated: June 11, 2014
CouponAlerts.exe File name: CouponAlerts.exe
Size: 1.09 MB (1092632 bytes)
MD5: 2fd16a287970bd63473619cd57f25e7b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 17, 2022

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{00B595DF-8592-45F8-A3A8-577D0497F0F6}{3BAD286E-058C-4D50-BEBF-14A4FDEC82E1}{3BDB28B6-0521-4D80-BB7C-E2A47BECC0E1}{60405004-E845-421D-B5B1-2038E04A9313}{CA201357-7C61-4A7F-B689-D044B70F3949}{CACB139B-7C2C-4A99-A4EE-72449D0FF549}{F791D8AE-47E8-40A5-A913-EB2D2AF29602}{F7E7D81D-4750-40CF-8498-4C2DE8F2EA02}HKEY..\..\..\..{RegistryKeys}SOFTWARE\37436SOFTWARE\Coupon AlertsSoftware\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311581142}Software\Microsoft\Internet Explorer\Approved Extensions\{F791D8AE-47E8-40A5-A913-EB2D2AF29602}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60405004-E845-421D-B5B1-2038E04A9313}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F791D8AE-47E8-40A5-A913-EB2D2AF29602}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F791D8AE-47E8-40A5-A913-EB2D2AF29602}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F791D8AE-47E8-40A5-A913-EB2D2AF29602}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110311581142}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{F791D8AE-47E8-40A5-A913-EB2D2AF29602}SOFTWARE\Wow6432Node\37436SOFTWARE\Wow6432Node\Coupon AlertsSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60405004-E845-421D-B5B1-2038E04A9313}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Coupon Alerts-bg.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{F791D8AE-47E8-40A5-A913-EB2D2AF29602}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{F791D8AE-47E8-40A5-A913-EB2D2AF29602}

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Coupon Alerts%LOCALAPPDATA%\Coupon Alerts%PROGRAMFILES%\Coupon Alerts%PROGRAMFILES(X86)%\Coupon Alerts%USERPROFILE%\AppData\LocalLow\{F791D8AE-47E8-40A5-A913-EB2D2AF29602}
Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.