BeeCoupons is a software usually installed without your knowledge with the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
Identified : 10/03/2014.


– It belongs to a family of PUP (Potentially Unwanted Program).
– A polluteware is a software that pollutes storage and/or the Base of registers.
– A toolbar is an additional internet browser bar.
– An Adware is a program that adds other programs without the knowledge of the user.
– Vendor : PUP.Optional


– It installs a plugin of the browser Google Chrome (G2),
– It installs a program of extension for browser Mozilla Firefox (M2),
– It installs a plugin of the browser Mozilla Firefox (P2),
– It is installed as a BHO (Browser Helper Object) of internet browser (O2),
– It installs as a process launched at startup of the system (RP),
– It installs as a program (O42),
– It creates to many registry keys ‘Software’,
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45),
– It creates multiple files users (O61),


G2 – GCE: Preference [User Data\Default] [gcbkfpidjhchgnokamccdemjfamackdh] Bee Coupons v.1.0, (Activé )
O2 – BHO: Bee Coupons BHO [64Bits] – {FC4DBA8C-2CC8-4741-BCE5-ADAC3EEA50B0} . (.FrameworkBHO.) — C:\Program Files (x86)\Bee Coupons\FrameworkBHO.dll
O42 – Logiciel: Bee Coupons – (.Smart Apps.) [HKLM][64Bits] — Bee Coupons
O43 – CFD: 27/01/2014 – 10:36:22 – [1,043] —-D C:\Program Files (x86)\Bee Coupons
O43 – CFD: 27/01/2014 – 10:36:24 – [1,058] —-D C:\Users\Coolman\AppData\Local\Bee Coupons
O61 – LFC: 13/02/2014 – 01:10:20 —A- . (…) — C:\Users\Coolman\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcbkfpidjhchgnokamccdemjfamackdh\1.0_0\AppFramework\appAPI_browseraction.js [802]
O61 – LFC: 13/02/2014 – 01:10:20 —A- . (…) — C:\Users\Coolman\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcbkfpidjhchgnokamccdemjfamackdh\1.0_0\AppFramework\appAPI_common.js [6351]
O61 – LFC: 13/02/2014 – 01:10:20 —A- . (…) — C:\Users\Coolman\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcbkfpidjhchgnokamccdemjfamackdh\1.0_0\AppFramework\appAPI_content.js [1253]
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Bee Coupons
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC4DBA8C-2CC8-4741-BCE5-ADAC3EEA50B0}
C:\Users\Coolman\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcbkfpidjhchgnokamccdemjfamackdh
C:\Program Files (x86)\Bee Coupons
C:\Program Files (x86)\Bee Coupons\FrameworkBHO.dll
C:\Users\Coolman\AppData\Local\Bee Coupons


PUP.Optional.BeeCoupons.A [ Malwarebytes Antimalware ]
GamePlayLabs (fs) [VIPRE]


– Remove software in Windows Configuration Panel,
Remove with ZHPcleaner
Diagnose with ZHPDiag