Threat Database Adware TermCoach Ads

TermCoach Ads

By GoldSparrow in Adware

Threat Scorecard

Popularity Rank: 7,636
Threat Level: 20 % (Normal)
Infected Computers: 3,758
First Seen: August 6, 2015
Last Seen: September 19, 2025
OS(es) Affected: Windows

The TermCoach software from Delaware Corporation is promoted to enhance your search operations on sites like Google, Bing, and Yahoo. Advertisers support the TermCoach software, and the only optimization you might get is the constant display of advertisements on web pages you visit. Therefore, security experts deem the TermCoach software as a Potentially Unwanted Program (PUP) that is not likely to improve your Internet experience and may cover your browser surface with numerous ads. The TermCoach software has an official website, but it is distributed through third-party software bundles predominantly. You may see the TermCoach software listed as a browser plug-in on the 'Programs and Features' list of your OS 'Control Panel'. Security experts note that the TermCoach app will use web beacons, DOM storage data, and session cookies to conduct behavioral marketing and help advertisers develop better marketing strategies. The TermCoach app will embed ads via in-text hyperlinks and will show you banners and floating ad-boxes on every page you browse. The TermCoach software functions as a redirect-gateway to content by third parties and you may be redirected to potentially compromise online services and shops. The TermCoach software functions similarly to CoupApp andDealz and may slow down your Web browser, which may irritate many web surfers. The TermCoach application may insert a registry key in Windows to be launched as a background service when you turn-on your PC. Many computer users may want to use a reliable anti-spyware tool to remove the TermCoach app efficiently.

SpyHunter Detects & Remove TermCoach Ads

File System Details

TermCoach Ads may create the following file(s):
# File Name MD5 Detections
1. tcfd_vw_1_10_0_24.sys cd9a3775389f5a1c27af9c21d73c752a 176

Registry Details

TermCoach Ads may create the following registry entry or registry entries:
Regexp file mask
%WINDIR%\system32\Drivers\TCFD_vt_1_10_0_[RANDOM CHARACTERS].sys
%WINDIR%\system32\Drivers\tcfd_vw_1_10_0_[RANDOM CHARACTERS].sys

Analysis Report

General information

Family Name: Adware.Term Coach
Signature status: Self Signed

Known Samples

MD5: 36ed838805973910b5847fa935b92df2
SHA1: 2b9a178e7681273c9afa7436c9a23a35e3c5909b
SHA256: 8F76CC1575A659CC4F2941EE58F3279305BA972339FAC2771064E7F77B3E6B1F
File Size: 1.08 MB, 1082352 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name TermCoach
File Description TermCoach Setup
File Version 1.10.0.22
Internal Name TermCoach-setup.exe
Legal Copyright (c) 2015 TermCoach
Original Filename TermCoach-setup.exe
Product Name TermCoach
Product Version 1.10.0.22

Digital Signatures

Signer Root Status
Term Coach GlobalSign CodeSigning CA - G2 Self Signed

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nso6917.tmp\inetc.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nso6917.tmp\nsisplugin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nso6917.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nso6917.tmp\uac.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsy6906.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\vitruvian-installer-processes-v0002 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\termcoach_1.10.0.22::nid BFEB5820-9643-42AD-A79F-071DFF4D8E64 RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetQueryOption
  • InternetSetOption

Trending

Most Viewed

Loading...