Home Malware Programs Bad Toolbars CouponAlert_2p

CouponAlert_2p

Posted: May 10, 2011

Threat Metric

Ranking: 7,900
Threat Level: 1/10
Infected PCs: 33,382
First Seen: May 10, 2011
Last Seen: March 10, 2025
OS(es) Affected: Windows

Aliases

not-a-virus:WebToolbar.Win32.MyWebSearch.tyq [Kaspersky]Win32:FunWeb-K [PUP] [Avast]Adware.Funweb-12 [ClamAV]Win32:PUP-gen [PUP] [Avast]Tool.InstallToolbar.5 [DrWeb]Win32:FunWeb-F [PUP] [Avast]Artemis!5AFBF0822A13 [McAfee]Win32.Trojan [eSafe]probably a variant of Win32/Adware.Softomate.AD [NOD32]Adware.Coupons.origin [DrWeb]W32/Softomate.A.gen!Eldorado [F-Prot]AdInstaller.FunWeb [AVG]AdWare/Win32.FunWeb.gen [Antiy-AVL]not-a-virus:AdWare.Win32.FunWeb.heur [Kaspersky]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pSrcAs.dll File name: 2pSrcAs.dll
Size: 53.24 KB (53248 bytes)
MD5: 635999beb7443c8ae6bc2563855b3314
Detection count: 5,232
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pmedint.exe File name: 2pmedint.exe
Size: 99.87 KB (99872 bytes)
MD5: 82da641e7046b289cd5bd1837f6db8f7
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES(x86)%\CouponAlert_2p\bar\1.bin\2pbarsvc.exe File name: 2pbarsvc.exe
Size: 42.5 KB (42504 bytes)
MD5: 3489caaacb6747ac2cafee3756b5a857
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES%\CouponAlert_2p\bar\setups\Coupon Alert Installer(0006e060).exe File name: Coupon Alert Installer(0006e060).exe
Size: 90.23 KB (90230 bytes)
MD5: 23a41dabcb6e1c4da1f48d451c7cefff
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\setups
Group: Malware file
Last Updated: January 2, 2020
%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pSrchMn.exe File name: 2pSrchMn.exe
Size: 42.53 KB (42536 bytes)
MD5: c76414d0e3482c7658a0b937ffc458c2
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014
%PROGRAMFILES%\CouponAlert_2p\bar\1.bin\2pbrmon.exe File name: 2pbrmon.exe
Size: 30.09 KB (30096 bytes)
MD5: a6946d14ee944b26077182788113cdd7
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\CouponAlert_2p\bar\1.bin
Group: Malware file
Last Updated: February 26, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{004EB151-885B-4A9E-A22D-CA98DD998D75}{041278C7-DF92-486D-AE85-921BDFC75A43}{0bdf6c42-132c-45f5-92de-dc13f40c6dab}{0F1794F2-900B-4C81-8146-9234E5CC5BE2}{1116A14B-F6A3-4FD9-A00E-FF8CF270EE48}{16fe2505-f2a0-4782-b035-af0e5188c02c}{1f0a2185-da7e-4614-91c0-dd5f4a76cb1b}{20BCCE5A-C687-46FF-8DD2-AD8235F5F2B4}{21D9997E-5D2A-4737-BCBA-C958C0590295}{23b38049-323f-443d-9732-f454e5b15b72}{2d205adf-c992-4eda-99c3-096e13f38ab4}{3276E8A8-A233-449B-A7EB-FCEE21246018}{3462c343-be19-4143-af70-cefb56f46fc6}{36A7148B-639E-423C-90BB-30B6E1A40BD7}{3a421c8f-e238-4aeb-8874-b8b5f2cc4772}{411b1946-3277-4a7f-9f60-745266360613}{4500a1b4-ae7b-41f0-afb6-b7139a8f950b}{457a4cb8-0391-409d-98b4-c4ccb2849670}{4d8eacbc-e293-4462-b91e-42ea5b54b743}{53CA18E7-5223-4358-9FD9-97C62C66C5BD}{58E64AEE-516A-4DFC-AC38-31C50E8AF0F1}{60e91567-ef8a-4520-bce2-83aba5256799}{60FC9013-4A5A-4306-9695-FCE0A6617F22}{61DAB0AD-AD23-4E40-84AC-7C6CE64D4EB3}{65D8E17B-312E-4E12-913B-A841A8631143}{6BDA50D2-5597-4C68-A842-9B857FCCDA49}{6CA3D0AB-F807-462C-BA7F-E27F07F91E32}{6F99D2AE-5C90-43C2-A2FE-81DBE512E2FC}{7717f4b3-397f-4ce5-9192-6effde3ac999}{7924FD2B-877C-4395-A063-A88AB887EA6D}{79583DE9-D0C2-44EF-AE0D-CBFA16C2A785}{7b9f8c21-46ec-4c0b-8683-e755ef84577a}{813AF603-8FB5-4F42-8DDA-3BBA24B473D0}{84576f6e-0660-4b4f-8918-bc6c975044d4}{860AF5D1-0735-409D-8E5F-E3E99356D7E9}{8867ac9b-4426-44a2-a693-c95850d3405c}{8997561D-CF0B-42C7-AAE6-78801B3ADC7F}{92580E8C-88F5-4551-9D9E-8147E7EE2C32}{95B3F577-D54A-4831-B2B4-8AACEEDA85CF}{A0636D37-97D0-4DC4-95A6-93AABA07437F}{A4116F8C-A634-4536-B9EF-6B9EBCC5BAE1}{A786F51D-B3C7-4F52-91EF-E1A892C2A2AE}{B27B89D7-65E1-4F23-89AA-02F8B7D0F525}{C7E7FB02-C4FD-446E-8F5B-463A049935BF}{cf9d6d4e-5496-438e-ba24-5a580a59f5a3}{D196831D-1A59-4B05-9D47-E4F488EF0499}{D244EAC5-A0F5-4859-A1F8-18ABC0AC3A00}{D7CE22AF-CCB3-423F-84D5-4D77152181F3}{DAFC4DAE-7794-4E16-9A98-F6001303DCD0}{def07acd-bcea-4269-933a-4087d20842bb}{E625B4C4-7359-4FE9-9022-5C4A2CEA0893}{EAB77009-B974-48DF-8229-E70CFAA11C69}{EBAA6283-B61F-4DDD-9659-56635433A307}{EBAF2B4F-510A-47C7-86BA-E7D94D1162F6}{ebbc4e43-292a-40df-88e3-3262b7521460}{EFB0C189-5077-4340-9838-AF7B8E792A54}{EFB4F034-3EB5-48D5-84DD-89BBCF9A182F}{F9D45087-1CF1-452E-9649-FDFDAC578E03}{FF2EBC1C-6579-41DB-91DD-945A1C8DB2D2}File name without pathhttp_couponalert.dl.tb.ask.com_0.localstoragehttp_couponalert.dl.tb.ask.com_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{3462C343-BE19-4143-AF70-CEFB56F46FC6}Software\Microsoft\Internet Explorer\Approved Extensions\{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}Software\Microsoft\Internet Explorer\Approved Extensions\{60E91567-EF8A-4520-BCE2-83ABA5256799}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16fe2505-f2a0-4782-b035-af0e5188c02c}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3a421c8f-e238-4aeb-8874-b8b5f2cc4772}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{60e91567-ef8a-4520-bce2-83aba5256799}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0bdf6c42-132c-45f5-92de-dc13f40c6dab}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{23b38049-323f-443d-9732-f454e5b15b72}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4623a8c4-150d-4983-8982-68c01e7d6541}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8867ac9b-4426-44a2-a693-c95850d3405c}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{95B3F577-D54A-4831-B2B4-8AACEEDA85CF}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{cf9d6d4e-5496-438e-ba24-5a580a59f5a3}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3462C343-BE19-4143-AF70-CEFB56F46FC6}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{60E91567-EF8A-4520-BCE2-83ABA5256799}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{23B38049-323F-443D-9732-F454E5B15B72}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3462C343-BE19-4143-AF70-CEFB56F46FC6}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4623A8C4-150D-4983-8982-68C01E7D6541}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{60E91567-EF8A-4520-BCE2-83ABA5256799}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16fe2505-f2a0-4782-b035-af0e5188c02c}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8ac668b9-43c7-4e92-8854-2f96cb0df8e2}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3a421c8f-e238-4aeb-8874-b8b5f2cc4772}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{60e91567-ef8a-4520-bce2-83aba5256799}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0bdf6c42-132c-45f5-92de-dc13f40c6dab}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{23b38049-323f-443d-9732-f454e5b15b72}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4623a8c4-150d-4983-8982-68c01e7d6541}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8867ac9b-4426-44a2-a693-c95850d3405c}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{95B3F577-D54A-4831-B2B4-8AACEEDA85CF}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{cf9d6d4e-5496-438e-ba24-5a580a59f5a3}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}CouponAlert_2pbar Uninstall Internet Explorer

Additional Information

The following URL's were detected:
Coupon Alert
Loading...