Home Malware Programs Bad Toolbars CouponAlert_2p

CouponAlert_2p

Posted: May 10, 2011

Threat Metric

Ranking: 6,500
Threat Level: 1/10
Infected PCs: 33,110
First Seen: May 10, 2011
Last Seen: October 16, 2023
OS(es) Affected: Windows

Aliases

not-a-virus:WebToolbar.Win32.MyWebSearch.tyq [Kaspersky]Win32:FunWeb-K [PUP] [Avast]Adware.Funweb-12 [ClamAV]Win32:PUP-gen [PUP] [Avast]Tool.InstallToolbar.5 [DrWeb]Win32:FunWeb-F [PUP] [Avast]Artemis!5AFBF0822A13 [McAfee]Win32.Trojan [eSafe]probably a variant of Win32/Adware.Softomate.AD [NOD32]Adware.Coupons.origin [DrWeb]W32/Softomate.A.gen!Eldorado [F-Prot]AdInstaller.FunWeb [AVG]AdWare/Win32.FunWeb.gen [Antiy-AVL]not-a-virus:AdWare.Win32.FunWeb.heur [Kaspersky]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pbarsvc.exe File name: 2pbarsvc.exe
Size: 28.76 KB (28766 bytes)
MD5: 0ddfb42668042b93298b4e1a1a49ea86
Detection count: 7,649
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pbrmon.exe File name: 2pbrmon.exe
Size: 20.48 KB (20480 bytes)
MD5: d187bd7494d9250921cdfc80da557636
Detection count: 6,830
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pSrcAs.dll File name: 2pSrcAs.dll
Size: 53.24 KB (53248 bytes)
MD5: 635999beb7443c8ae6bc2563855b3314
Detection count: 5,232
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pbar.dll File name: 2pbar.dll
Size: 684.03 KB (684032 bytes)
MD5: 44e666c4ceb04862b3d8874d546df311
Detection count: 5,195
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pmedint.exe File name: 2pmedint.exe
Size: 99.87 KB (99872 bytes)
MD5: 82da641e7046b289cd5bd1837f6db8f7
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pbarsvc.exe File name: 2pbarsvc.exe
Size: 222.68 KB (222682 bytes)
MD5: 85e9247291f76253fa3b4415e0c3daed
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pbarsvc.exe File name: 2pbarsvc.exe
Size: 112.13 KB (112136 bytes)
MD5: 766d063cbaea66756913a8f6ed3b1301
Detection count: 34
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pSrchMn.exe File name: 2pSrchMn.exe
Size: 42.53 KB (42536 bytes)
MD5: 33a924000cbff03490a14ecc261571be
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: May 28, 2021
%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pmedint.exe File name: 2pmedint.exe
Size: 20.59 KB (20598 bytes)
MD5: 1647e8afc7506772a78a4ec852883278
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES(x86)%\CouponAlert_2p\bar\1.bin\2pbarsvc.exe File name: 2pbarsvc.exe
Size: 42.5 KB (42504 bytes)
MD5: 3489caaacb6747ac2cafee3756b5a857
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES%\CouponAlert_2p\bar\2.bin\2pbrmon.exe File name: 2pbrmon.exe
Size: 101.37 KB (101376 bytes)
MD5: 48a712bc3075bd5c64595a69aaa0c566
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\2.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES%\CouponAlert_2p\bar\setups\Coupon Alert Installer(0006e060).exe File name: Coupon Alert Installer(0006e060).exe
Size: 90.23 KB (90230 bytes)
MD5: 23a41dabcb6e1c4da1f48d451c7cefff
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\setups
Group: Malware file
Last Updated: January 2, 2020
%PROGRAMFILES(x86)%\CouponAlert_2p\bar\5.bin\2pSrchMn.exe File name: 2pSrchMn.exe
Size: 42.53 KB (42536 bytes)
MD5: a55cf1d1d0a346b9282713beb4d00208
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\CouponAlert_2p\bar\5.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pSrchMn.exe File name: 2pSrchMn.exe
Size: 42.53 KB (42536 bytes)
MD5: c76414d0e3482c7658a0b937ffc458c2
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pbrmon.exe File name: 2pbrmon.exe
Size: 30.09 KB (30096 bytes)
MD5: a6946d14ee944b26077182788113cdd7
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{004EB151-885B-4A9E-A22D-CA98DD998D75}{041278C7-DF92-486D-AE85-921BDFC75A43}{0bdf6c42-132c-45f5-92de-dc13f40c6dab}{0F1794F2-900B-4C81-8146-9234E5CC5BE2}{1116A14B-F6A3-4FD9-A00E-FF8CF270EE48}{16fe2505-f2a0-4782-b035-af0e5188c02c}{1f0a2185-da7e-4614-91c0-dd5f4a76cb1b}{20BCCE5A-C687-46FF-8DD2-AD8235F5F2B4}{21D9997E-5D2A-4737-BCBA-C958C0590295}{23b38049-323f-443d-9732-f454e5b15b72}{2d205adf-c992-4eda-99c3-096e13f38ab4}{3276E8A8-A233-449B-A7EB-FCEE21246018}{3462c343-be19-4143-af70-cefb56f46fc6}{36A7148B-639E-423C-90BB-30B6E1A40BD7}{3a421c8f-e238-4aeb-8874-b8b5f2cc4772}{411b1946-3277-4a7f-9f60-745266360613}{4500a1b4-ae7b-41f0-afb6-b7139a8f950b}{457a4cb8-0391-409d-98b4-c4ccb2849670}{4d8eacbc-e293-4462-b91e-42ea5b54b743}{53CA18E7-5223-4358-9FD9-97C62C66C5BD}{58E64AEE-516A-4DFC-AC38-31C50E8AF0F1}{60e91567-ef8a-4520-bce2-83aba5256799}{60FC9013-4A5A-4306-9695-FCE0A6617F22}{61DAB0AD-AD23-4E40-84AC-7C6CE64D4EB3}{65D8E17B-312E-4E12-913B-A841A8631143}{6BDA50D2-5597-4C68-A842-9B857FCCDA49}{6CA3D0AB-F807-462C-BA7F-E27F07F91E32}{6F99D2AE-5C90-43C2-A2FE-81DBE512E2FC}{7717f4b3-397f-4ce5-9192-6effde3ac999}{7924FD2B-877C-4395-A063-A88AB887EA6D}{79583DE9-D0C2-44EF-AE0D-CBFA16C2A785}{7b9f8c21-46ec-4c0b-8683-e755ef84577a}{813AF603-8FB5-4F42-8DDA-3BBA24B473D0}{84576f6e-0660-4b4f-8918-bc6c975044d4}{860AF5D1-0735-409D-8E5F-E3E99356D7E9}{8867ac9b-4426-44a2-a693-c95850d3405c}{8997561D-CF0B-42C7-AAE6-78801B3ADC7F}{92580E8C-88F5-4551-9D9E-8147E7EE2C32}{95B3F577-D54A-4831-B2B4-8AACEEDA85CF}{A0636D37-97D0-4DC4-95A6-93AABA07437F}{A4116F8C-A634-4536-B9EF-6B9EBCC5BAE1}{A786F51D-B3C7-4F52-91EF-E1A892C2A2AE}{B27B89D7-65E1-4F23-89AA-02F8B7D0F525}{C7E7FB02-C4FD-446E-8F5B-463A049935BF}{cf9d6d4e-5496-438e-ba24-5a580a59f5a3}{D196831D-1A59-4B05-9D47-E4F488EF0499}{D244EAC5-A0F5-4859-A1F8-18ABC0AC3A00}{D7CE22AF-CCB3-423F-84D5-4D77152181F3}{DAFC4DAE-7794-4E16-9A98-F6001303DCD0}{def07acd-bcea-4269-933a-4087d20842bb}{E625B4C4-7359-4FE9-9022-5C4A2CEA0893}{EAB77009-B974-48DF-8229-E70CFAA11C69}{EBAA6283-B61F-4DDD-9659-56635433A307}{EBAF2B4F-510A-47C7-86BA-E7D94D1162F6}{ebbc4e43-292a-40df-88e3-3262b7521460}{EFB0C189-5077-4340-9838-AF7B8E792A54}{EFB4F034-3EB5-48D5-84DD-89BBCF9A182F}{F9D45087-1CF1-452E-9649-FDFDAC578E03}{FF2EBC1C-6579-41DB-91DD-945A1C8DB2D2}File name without pathhttp_couponalert.dl.tb.ask.com_0.localstoragehttp_couponalert.dl.tb.ask.com_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{3462C343-BE19-4143-AF70-CEFB56F46FC6}Software\Microsoft\Internet Explorer\Approved Extensions\{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}Software\Microsoft\Internet Explorer\Approved Extensions\{60E91567-EF8A-4520-BCE2-83ABA5256799}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16fe2505-f2a0-4782-b035-af0e5188c02c}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3a421c8f-e238-4aeb-8874-b8b5f2cc4772}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{60e91567-ef8a-4520-bce2-83aba5256799}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0bdf6c42-132c-45f5-92de-dc13f40c6dab}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{23b38049-323f-443d-9732-f454e5b15b72}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4623a8c4-150d-4983-8982-68c01e7d6541}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8867ac9b-4426-44a2-a693-c95850d3405c}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{95B3F577-D54A-4831-B2B4-8AACEEDA85CF}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{cf9d6d4e-5496-438e-ba24-5a580a59f5a3}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3462C343-BE19-4143-AF70-CEFB56F46FC6}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{60E91567-EF8A-4520-BCE2-83ABA5256799}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{23B38049-323F-443D-9732-F454E5B15B72}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3462C343-BE19-4143-AF70-CEFB56F46FC6}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4623A8C4-150D-4983-8982-68C01E7D6541}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{60E91567-EF8A-4520-BCE2-83ABA5256799}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16fe2505-f2a0-4782-b035-af0e5188c02c}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8ac668b9-43c7-4e92-8854-2f96cb0df8e2}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3a421c8f-e238-4aeb-8874-b8b5f2cc4772}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{60e91567-ef8a-4520-bce2-83aba5256799}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0bdf6c42-132c-45f5-92de-dc13f40c6dab}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{23b38049-323f-443d-9732-f454e5b15b72}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4623a8c4-150d-4983-8982-68c01e7d6541}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8867ac9b-4426-44a2-a693-c95850d3405c}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{95B3F577-D54A-4831-B2B4-8AACEEDA85CF}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{cf9d6d4e-5496-438e-ba24-5a580a59f5a3}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}CouponAlert_2pbar Uninstall Internet Explorer

Additional Information

The following URL's were detected:
Coupon Alert
Loading...