84,488,480 programs installed

Should I remove TakeTheCouPon?

What percent of users and experts removed it?
83% remove it17% keep it
Overall Sentiment
What do people think about it?
(click star to rate)
How common is it?
Reach 0.0004%


What is TakeTheCouPon?

TakeTheCoupon is an adware program will display extra advertisements when users are using search engines such as Bing and Google. In Chrome, it installs itself as an extension and in Internet Explorer it runs as a process as well as a Browser Helper Object. It also adds itself as a Windows add-on. The program creates an entry in the Add or Remove Programs of the Control Panel however deleting this entry might stop the adware running, but will not stop ads from displaying. Once installed, This adware displays ads if a user searches using Bing or Google by injecting or inserting over new ads in search as well as various web pages that use 3rd party advertising. The software users the InstalleRex download and install manager from WebPicks Holdings used to distribute Pay Per Install monetized software, typically unwanted toolbars and web browser extensions.

About  (from InstalleRex-WebPick)

While you visit your favourite online shopping sites, the browser add-on automatically scans for coupons, deals, and promotions, giving online shoppers the benefit of comparison, and assuring they only purchase what suits their budgets. This tool scans the Web to get the best deals from All Your favorite shopping sites...  Read more
  • Possible malware installed by this program
  • Loads into the web browser
  • Typically distributed through a pay-per-install bundle
  • Injects advertisements unassociated with the underlying web page
  • The experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in TakeTheCouPon.
tB.exe (f5bff621c4c58358b36f8526dec8a264) has been flagged by the following 25 scanners:
Anti-Virus softwareVersionDetection
Agnitum Outpost 7.1.1 Adware.MegaSearch
AhnLab-V3 2014.01.06 Trojan/Win32.Preloader
Antiy-AVL AdWare/Win32.MegaSearch
avast! 2014.9-140126 Win32:Adware-gen [Adw]
AVG 2015.0.3582 Generic5
Baidu-International Adware.Win32.MegaSearch.aBc
Bkav FE W32.Clod3fd.Trojan
Comodo Security 17558 ApplicUnwnt
ESET-NOD32 8.9255 a variant of Win32/AdWare.MultiPlug.K.gen
Fortinet FortiGate 1/26/2014 Adware/Megasearch
IKARUS anti.virus t3scan.2.2.29 Win32.AdWare
K7 AntiVirus 13.175.10735 Adware
K7GW 13.175.10735 Adware ( 00490ca81 )
Kaspersky not-a-virus:AdWare.Win32.MegaSearch
Kingsoft AntiVirus 331020.49267 Win32.Troj.MegaSearch.at.(kcloud)
Malwarebytes v2014.01.26.03 PUP.Optional.CRXDrop.A
McAfee 5600.7238 Artemis!F5BFF621C4C5
McAfee-GW-Edition 7.7238 Artemis!F5BFF621C4C5
Panda Antivirus Trj/Genetic.gen
Sophos 4.96 Generic PUA BJ
Symantec 1/26/2014 rev. 1 Trojan.Gen
Trend Micro 10.465.26 TROJ_GEN.F0C2C00A414
TrendMicro-HouseCall 7.2.26 TROJ_GEN.F0C2C00A414
Vba32 AntiVirus BScope.Trojan.Agent
VIPRE Antivirus 25126 Trojan.Win32.Generic!BT
yAKdTZBTiZ.exe (1b63b4e4fe4be0d8607d362c3d2f2677) has been flagged by the following 35 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.146103
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 2014.08.05.00 Trojan/Win32.Preloader
Avira AntiVir Adware/Graftor.146103
Antiy-AVL Trojan/Win32.SGeneric
avast! 8.0.1489.320 Win32:Dropper-gen [Drp]
AVG Generic5.AZJV
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.81
Bitdefender 7.2 Gen:Variant.Adware.Graftor.146103
Bkav FE W32.CanpaktiLTAAI.Adware
CAT-QuickHeal 14.00 AdWare.MultiPlug.r5 (Not a Virus)
Comodo Security 19086 ApplicUnwnt
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.146103 (B)
ESET-NOD32 10205 a variant of Win32/AdWare.MultiPlug.AG
Fortinet FortiGate Riskware/MultiPlug
F-Secure 11.0.19100.45 Gen:Variant.Adware.Graftor.146103
G Data 24 Gen:Variant.Adware.Graftor.146103
IKARUS anti.virus T3. PUA.Generic
K7 AntiVirus 9.182.12951 Adware ( 0049c94b1 )
K7GW 9.182.12951 Adware ( 0049c94b1 )
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.bqfl
Kingsoft AntiVirus 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic.bfr!ho
MicroWorld-eScan Gen:Variant.Adware.Graftor.146103
NANO AntiVirus Riskware.Win32.Graftor.dcodwf
Panda Antivirus Trj/Genetic.gen
Sophos 4.98.0 Generic PUA IB
Symantec 20131.1.5.61 WS.Reputation.1
Tencent Win32.Risk.Adware.Dzkd
Trend Micro 9.740.0.1012 TROJ_SPNR.14GN14
TrendMicro-HouseCall 9.700.0.1001 TROJ_SPNR.14GN14
Vba32 AntiVirus AdWare.MultiPlug
VIPRE Antivirus 31936 Trojan.Win32.Generic!BT
5l45kLxUh.x64.dll (2399176cdc9056ed5fc364c12b555b23) has been flagged by the following 23 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware Application.Generic.626740
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 2014.06.19.00 Trojan/Win64.Preloader
Avira AntiVir APPL/Multiplug.C.403968
Antiy-AVL Trojan/Win32.SGeneric
avast! 8.0.1489.320 Win64:Adware-gen [Adw]
AVG Generic_r.KM
Baidu-International Adware.Win64.MultiPlug.81
Bitdefender 7.2 Application.Generic.626740
Comodo Security 18590 ApplicUnwnt
ESET-NOD32 9962 a variant of Win64/Adware.MultiPlug.C
F-Secure 11.0.19100.45 Application.Generic.626740
G Data 24 Application.Generic.626740
IKARUS anti.virus T3. AdWare.MultiPlug
Malwarebytes PUP.Optional.MultiPlug.A
McAfee RDN/Generic PUP.x!cd3
McAfee-GW-Edition 2013 RDN/Generic PUP.x!cd3
MicroWorld-eScan Application.Generic.626740
Panda Antivirus Trj/CI.A
Qihoo-360 Win32/Trojan.Adware.814
Tencent Win64.Adware.Multiplug.Hqlt
TrendMicro-HouseCall 9.700.0.1001 TROJ_GEN.R03WH06F114
VIPRE Antivirus 30420 Win64.Adware.MultiPlug
5l45kLxUh.exe (83c728a3d4b56127985b096478a943f8) has been flagged by the following 21 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware Application.Generic.623657
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 2014.05.30.00 Dropper/Win32.Preloader
Avira AntiVir SPR/Tool.460800.1
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.81
Bitdefender 7.2 Application.Generic.623657
Bkav FE W32.PatgeasM.Trojan
Comodo Security 18367 Application.Win32.MultiPlug.SJ
Fortinet FortiGate 4 Riskware/MultiPlug
F-Secure 11.0.19100.45 Application.Generic.623657
G Data 24 Application.Generic.623657
K7 AntiVirus 9.178.12244 Adware ( 004976341 )
K7GW 9.178.12244 Adware ( 004976341 )
Malwarebytes 1.75.0001 PUP.Optional.MultiPlug.A
McAfee RDN/Generic.dx!dcf
McAfee-GW-Edition 2013 Heuristic.BehavesLike.Win32.Suspicious.H
MicroWorld-eScan Application.Generic.623657
Panda Antivirus Trj/Genetic.gen
TrendMicro-HouseCall 9.700-1001 TROJ_GEN.R0CBH06ES14
VIPRE Antivirus 29736 Trojan.Win32.Generic!BT
yAKdTZBTiZ.dll (938a58a18228d9c556965deb4f74e494) has been flagged by the following 18 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 2014.08.02.00 Adware/Win32.Agent
avast! 8.0.1489.320 Win32:Dropper-gen [Drp]
AVG Generic5.AZJT
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.81
Comodo Security 19052 ApplicUnwnt
ESET-NOD32 10192 a variant of Win32/AdWare.MultiPlug.AY
Fortinet FortiGate Riskware/MultiPlug
IKARUS anti.virus T3. PUA.Generic
K7 AntiVirus 9.182.12926 Adware ( 0049c94b1 )
K7GW 9.182.12926 Adware ( 0049c94b1 )
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!chv
McAfee-GW-Edition 2013 RDN/Generic PUP.x!chv
Sophos 4.98.0 Generic PUA NF
Trend Micro 9.740.0.1012 ADW_MULTIPLUG
TrendMicro-HouseCall 9.700.0.1001 ADW_MULTIPLUG
VIPRE Antivirus 31840 Trojan.Win32.Generic!BT
H_EN.x64.dll (f304e79ecc51db8c3bbc11388ff4548a) has been flagged by the following 14 scanners:
Anti-Virus softwareSoftware versionDetection
AegisLab 1.5 AdWare.Win64.MegaSearch
AhnLab-V3 2014.10.27.04 Trojan/Win64.Preloader
AVG Generic_r.KM
AVware Win64.Adware.MultiPlug
Baidu-International Adware.Win64.MultiPlug.81
Comodo Security 19918 ApplicUnwnt
ESET-NOD32 10625 a variant of Win64/Adware.MultiPlug.B
K7 AntiVirus 9.185.13813 Adware ( 004a86af1 )
K7GW 9.185.13813 Adware ( 004a86af1 )
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!cf3
McAfee-GW-Edition v2014.2 BehavesLike.Win64.Downloader.fm
TrendMicro-HouseCall 9.700.0.1001 TROJ_GEN.R0E6H06J614
VIPRE Antivirus 34276 Win64.Adware.MultiPlug
yAKdTZBTiZ.x64.dll (1fa387fdb51a2204bdc2bbf808b583d5) has been flagged by the following 12 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 2014.08.02.00 Trojan/Win64.Preloader
avast! 8.0.1489.320 Win64:Malware-gen
AVG Generic_r.QB
AVware Win64.Adware.MultiPlug
Baidu-International PUA.Win32.CRXDrop.77
ESET-NOD32 10190 a variant of Win64/Adware.MultiPlug.D
IKARUS anti.virus T3. PUA.Multiplug
Malwarebytes PUP.Optional.Preload
McAfee Artemis!1FA387FDB51A
McAfee-GW-Edition 2013 Artemis!1FA387FDB51A
TrendMicro-HouseCall 9.700.0.1001 Suspicious_GEN.F47V0708
VIPRE Antivirus 31820 Win64.Adware.MultiPlug
tB.dll (1550537f5aee53fec3b74eb4605f8483) has been flagged by the following 11 scanners:
Anti-Virus softwareSoftware versionDetection
Avira AntiVir ADWARE/Adware.Gen
AVG Generic5.ALFJ
Baidu-International Adware.Win32.MultiPlug.40
Comodo Security 17589 ApplicUnwnt
ESET-NOD32 9277 a variant of Win32/AdWare.MultiPlug.N
K7 AntiVirus 9.175.10807 Adware ( 004923a41 )
K7GW 9.175.10807 Adware ( 004923a41 )
Malwarebytes PUP.Optional.MultiPlug.A
Rising Antivirus PE:Malware.Adware!6.1293
TrendMicro-HouseCall 9.700.0.1001 TROJ_GEN.F47V1230
VIPRE Antivirus 25302 JustPlugIt (fs)
USSf.exe (6cb0e030d27ab41c08823d43767436ea) has been flagged by the following 10 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware Gen:Variant.Graftor.150430
AhnLab-V3 2014.08.10.00 Trojan/Win32.Preloader
avast! 8.0.1489.320 Win32:MultiPlug-BG [PUP]
AVG Generic_r.QQ
Baidu-International Trojan.Win32.MultiPlug.BAG
Bitdefender 7.2 Gen:Variant.Graftor.150430
Emsisoft Anti-Malware Gen:Variant.Graftor.150430 (B)
ESET-NOD32 10230 a variant of Win32/AdWare.MultiPlug.AG
G Data 24 Gen:Variant.Graftor.150430
MicroWorld-eScan Gen:Variant.Graftor.150430
5l45kLxUh.dll (5337ab32d06451b51b031fad03674a73) has been flagged by the following 9 scanners:
Anti-Virus softwareSoftware versionDetection
AVG Generic_r.KL
Baidu-International Adware.Win32.MultiPlug.81
Comodo Security 18367 ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 9866 a variant of Win32/AdWare.MultiPlug.T
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.bfk
Malwarebytes 1.75.0001 PUP.Optional.MultiPlug.A
Sophos 4.98.0 Generic PUA GP
TrendMicro-HouseCall 9.700-1001 TROJ_GEN.R03WH07EQ14
VIPRE Antivirus 29736 Trojan.Win32.Generic!BT
H_EN.dll (bd9fb537d3d37af56a526b60e5ab0166) has been flagged by the following 9 scanners:
Anti-Virus softwareSoftware versionDetection
Antiy-AVL Trojan/Win32.TGeneric
avast! 8.0.1489.320 Win32:Adware-gen [Adw]
AVG Generic_r.KL
Baidu-International Adware.Win32.MultiPlug.81
ESET-NOD32 9954 a variant of Win32/AdWare.MultiPlug.Y
McAfee Artemis!BD9FB537D3D3
McAfee-GW-Edition 2013 Artemis!BD9FB537D3D3
Symantec 20131.1.5.61 Trojan.Gen.2
TrendMicro-HouseCall 9.700.0.1001 Suspicious_GEN.F47V0611
H_EN.exe (584cad63d062e99c0a4b07d334fbd440) has been flagged by the following 8 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 2014.06.18.00 Dropper/Win32.Preloader
Antiy-AVL Trojan/Win32.TGeneric
AVG Generic5.AVYG
ESET-NOD32 9962 a variant of Win32/AdWare.MultiPlug.Y
McAfee Artemis!584CAD63D062
McAfee-GW-Edition 2013 Artemis!584CAD63D062
TrendMicro-HouseCall 9.700.0.1001 Suspicious_GEN.F47V0611
VIPRE Antivirus 30414 Trojan.Win32.Generic!BT
gBryF.exe (ef38514253e4dafb6823f236bc47bb5f) has been flagged by the following 7 scanners:
Anti-Virus softwareSoftware versionDetection
AVG Generic5.AOBP
Comodo Security 17878 ApplicUnwnt
ESET-NOD32 9495 a variant of Win32/AdWare.MultiPlug.S
Malwarebytes 1.75.0001 PUP.Optional.MultiPlug.A
Qihoo-360 HEUR/Malware.QVM10.Gen
Trend Micro 9.740-1012 ADW_MULTIPLUG
TrendMicro-HouseCall 9.700-1001 ADW_MULTIPLUG
tB.x64.dll (9e0383fb82ce83bd785951c20f3fe959) has been flagged by the following 4 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 2013.12.31.00 Trojan/Win32.Preloader
Baidu-International Adware.Win64.MultiPlug.A
ESET-NOD32 9234 a variant of Win64/Adware.MultiPlug.A
Malwarebytes PUP.Optional.MultiPlug.A
       View all 206 all detections
TakeTheCouPon has been found to be bundled with 3rd party software. If you have not purposefully installed this, you should be safe uninstalling it.

Program detailsProgram details

Displayed publisher: TakeTheCoupon
URL: justplug.it
Installation folder: C:\ProgramData\takethecoupon
Uninstaller: "C:\ProgramData\TakeTheCouPon\tB.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Estimated size: 1.34 MB

Program filesFiles installed by TakeTheCouPon

Program executable:tB.exe (Malware detected)
Additional files:
  • (Malware detected) gBryF.exe (by system Retrieval cluster) - system Retrieval cluster (often)
  • (Malware detected) tB.exe (by Setup)
  • (Malware detected) USSf.exe (by program a and object) - program a and object (much)
  • (Malware detected) 5l45kLxUh.dll (by memory Databases) - memory Databases (managing dedicated are database)
  • (Malware detected) 5l45kLxUh.x64.dll (by memory Databases)
  • (Malware detected) H_EN.exe (by of of comprise) - of of comprise (requirements)
  • (Malware detected) yAKdTZBTiZ.dll (by or is software) - or is software (management)
  • (Malware detected) yAKdTZBTiZ.exe (by its particular) - its particular (concerned)
  • (Malware detected) yAKdTZBTiZ.x64.dll (by or is software)
  • (Malware detected) H_EN.dll (by DBMS is a a) - DBMS is a a
  • (Malware detected) H_EN.x64.dll (by DBMS is a a)
  • (Malware detected) 5l45kLxUh.exe (by computers) - computers (also)
  • (Malware detected) tB.dll
  • (Malware detected) tB.x64.dll

Program behaviorsBehaviors exhibited

8 Internet Explorer BHOs
  • 5l45kLxUh.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'TicTACooupona' with the class of {83E1DFAE-322A-8D10-05FB-E4C2E70B8930}.
  • yAKdTZBTiZ.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'RanddomiPraice' with the class of {B358B6D3-476B-9DAD-17F1-1B7799A31D4A}.
  • yAKdTZBTiZ.x64.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'EnjeOyCoupOn' with the class of {A015F795-836A-E45C-75AD-49D76A6EAA44}.
  • 5l45kLxUh.x64.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'KienGCCoupon' with the class of {04B72E27-5544-D3F3-5967-12E8E863B5F1}.
  • tB.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'FuindBestDeal' with the class of {9A09C003-191B-B8DD-079A-8383CF72792F}.
  • H_EN.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'DigeiSaveur' with the class of {6B64D11F-813D-8B95-280F-601829D07EEC}.
  • Plus 2 more

How do I remove TakeTheCouPon?

You can uninstall TakeTheCouPon from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8/10: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program TakeTheCouPon, click it, and then do one of the following:
    • Windows Vista/7/8/10: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove TakeTheCouPon.
  4. If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.

How do I reset my web browser?

If your web browser homepage and search settings have been modfied by TakeTheCouPon you can restore them to their previous default settings.
Microsoft Internet Explorer
Mozilla Firefox
Google Chrome

Win 7 (SP1) 57%
Win 7 14%
Uninstall it 83%
Keep it 17%
United States

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows 7 71.43%
Windows XP 14.29%
Windows Vista 14.29%
Which OS releases does it run on?
Windows 7 Ultimate 42.86%
Microsoft Windows XP 14.29%
Windows 7 Home Premium 14.29%
Windows 7 Starter 14.29%
Windows Vista Home Basic 14.29%

Distribution by countryGeography

41.67% of installs come from the United States
Which countries install it?
  United States 41.67%
  Argentina 8.33%
  Canada 8.33%
  Colombia 8.33%
  Indonesia 8.33%
  Peru 8.33%
  Taiwan 8.33%
  South Africa 8.33%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
Hewlett-Packard 40.00%
Toshiba 20.00%
Dell 20.00%
ASUS 20.00%
Common models
TOSHIBA Satellite C645D 20.00%
HP Compaq 6510b (KE130EA#... 20.00%
Hewlett-Packard 420-1040l... 20.00%
ECS A780GM-A 20.00%
Dell Inspiron 1545 20.00%

comments2 comments

user comment
user comment
lukeover a year ago
I've tryed to delete this app a lot of time. It seems impossible
user comment
Harry_Machinover a year ago
This is possibly the most annoying adware in the world. I'll be watching a video on youtube, and an advert will open on that same tab. It's not even pop-ups, iit's just a bombardment of adverts at every possible chance it gets. I've deleted everything associated with it on my computer, and it still re-installs itself. Be wary of this.