Home Malware Programs Potentially Unwanted Programs (PUPs) NCupons

NCupons

Posted: March 24, 2015

Threat Metric

Ranking: 3,228
Threat Level: 2/10
Infected PCs: 70,279
First Seen: March 24, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows

NCupons is yet another misleading web browser extension or add-on that is discovered to exhibit adware symptoms. Typically, unwanted products with adware nature are distributed using questionable methods such as bundling. If you are thinking of installing NCupons, think twice as this application is not as useful as advertised. At first glance, NCupons might try to convince you that NCupons will enhance your online shopping experience. NCupons might also promise to deliver best coupons, discounts and deals in order to save money and time for you. However, once installed on your computer, adware-supported programs like NCupons starts keeping a record of your frequently visited websites, search queries, etc. With the collected information, NCupons generates user-orientated ads and coupons that are intended to redirect them to third-party websites and build up their online traffic.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Ezequiel 08.03.18\Program Files (x86)\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2218256 bytes)
MD5: 8e6daecd7ff082c0c9d24ccd9d009d61
Detection count: 2,373
File type: Executable File
Mime Type: unknown/exe
Path: C:\Ezequiel 08.03.18\Program Files (x86)\RBM\NCupons\ncupons.exe
Group: Malware file
Last Updated: December 22, 2021
c:\program files\rbm\ncupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2217744 bytes)
MD5: 2c07f39f40ce513a19c3448942c27407
Detection count: 1,342
File type: Executable File
Mime Type: unknown/exe
Path: c:\program files\rbm\ncupons\ncupons.exe
Group: Malware file
Last Updated: August 26, 2022
C:\Program Files (x86)\Viva\viva.exe File name: viva.exe
Size: 356.64 KB (356640 bytes)
MD5: 9c364b17993fdb5e1b39ea21f336fcde
Detection count: 550
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\Viva\viva.exe
Group: Malware file
Last Updated: May 13, 2022
%PROGRAMFILES(x86)%\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2217744 bytes)
MD5: d189621e2fec97af3ba7f9e38fd79403
Detection count: 321
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\RBM\NCupons
Group: Malware file
Last Updated: April 24, 2015
C:\AdwCleaner\Quarantine\v1\20200810.114405\116\RBM\NCupons\ncupons.exe#C641E7461FDE6F7E File name: ncupons.exe#C641E7461FDE6F7E
Size: 2.21 MB (2216720 bytes)
MD5: 972f19123fe20d1b1cf97e93fa9d207a
Detection count: 201
Mime Type: unknown/exe#C641E7461FDE6F7E
Path: C:\AdwCleaner\Quarantine\v1\20200810.114405\116\RBM\NCupons\ncupons.exe#C641E7461FDE6F7E
Group: Malware file
Last Updated: November 11, 2021
%PROGRAMFILES%\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2218256 bytes)
MD5: c0e05437181be13521aef45c4fd863a8
Detection count: 178
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RBM\NCupons
Group: Malware file
Last Updated: April 24, 2015
%PROGRAMFILES%\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2218256 bytes)
MD5: 137e11d45b8dcfd9a1f8ff30f42b85f4
Detection count: 112
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RBM\NCupons
Group: Malware file
Last Updated: April 24, 2015
%PROGRAMFILES(x86)%\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2218256 bytes)
MD5: afcc05807e6d95dd4675edd81fb18ff0
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\RBM\NCupons
Group: Malware file
Last Updated: June 16, 2017
%PROGRAMFILES%\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2218256 bytes)
MD5: 03c08a91b7eb1a3b106f49281ccbf4e7
Detection count: 87
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RBM\NCupons
Group: Malware file
Last Updated: April 24, 2015
%PROGRAMFILES%\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2216720 bytes)
MD5: 68603bb3b9bbb6e56177ecb0ffc441f6
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RBM\NCupons
Group: Malware file
Last Updated: June 16, 2017
%PROGRAMFILES(x86)%\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2217744 bytes)
MD5: 00ce38be9b01115425bf36c12f2bfd3f
Detection count: 49
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\RBM\NCupons
Group: Malware file
Last Updated: April 24, 2015
%PROGRAMFILES%\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2216720 bytes)
MD5: 5dfdeaf755ca9b1a43e83bde7800b613
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RBM\NCupons
Group: Malware file
Last Updated: June 16, 2017
%PROGRAMFILES%\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2216720 bytes)
MD5: 69c821165f2acfd063cae093ad9d4d11
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RBM\NCupons
Group: Malware file
Last Updated: June 16, 2017
%PROGRAMFILES(x86)%\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2216720 bytes)
MD5: 5120d2f9aeff77b39a750d86ced45bbb
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\RBM\NCupons
Group: Malware file
Last Updated: June 16, 2017
%PROGRAMFILES%\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2216720 bytes)
MD5: d52448018954194ddc2ac351117eb324
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RBM\NCupons
Group: Malware file
Last Updated: June 13, 2020
%PROGRAMFILES%\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.01 MB (2017552 bytes)
MD5: 08b0c7518528ebd3adf4175149e8ca6a
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RBM\NCupons
Group: Malware file
Last Updated: April 29, 2020
%PROGRAMFILES(x86)%\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2216720 bytes)
MD5: 02b0db958a172caf955942229f9d990c
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\RBM\NCupons
Group: Malware file
Last Updated: February 19, 2020
%PROGRAMFILES(x86)%\RBM\NCupons\ncupons.exe File name: ncupons.exe
Size: 2.21 MB (2216720 bytes)
MD5: eaf1e1172d79ff77b6c05490e6aaaf49
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\RBM\NCupons
Group: Malware file
Last Updated: June 16, 2017

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%WINDIR%\System32\drivers\cashnbackdrv.sys%WINDIR%\System32\drivers\lmservicedrv.sys%WINDIR%\System32\drivers\ncuponsdrv.sys%WINDIR%\System32\drivers\vivadrv.sysHKEY..\..\..\..{RegistryKeys}SOFTWARE\NCuponsSOFTWARE\Wow6432Node\NCuponsSYSTEM\ControlSet001\Enum\Root\LEGACY_NCUPONSDRVSYSTEM\ControlSet001\Enum\Root\LEGACY_VIVADRVSYSTEM\ControlSet001\Services\COMLiveServiceSYSTEM\ControlSet001\Services\NCupons ApplicationSYSTEM\ControlSet001\Services\ncuponsdrvSYSTEM\ControlSet001\services\NSCP ServiceSYSTEM\ControlSet001\services\nscp_cnbSYSTEM\ControlSet001\Services\vivadrvSYSTEM\ControlSet002\Enum\Root\LEGACY_NCUPONSDRVSYSTEM\ControlSet002\Enum\Root\LEGACY_VIVADRVSYSTEM\ControlSet002\Services\COMLiveServiceSYSTEM\ControlSet002\Services\NCupons ApplicationSYSTEM\ControlSet002\Services\ncuponsdrvSYSTEM\ControlSet002\services\NSCP ServiceSYSTEM\ControlSet002\services\nscp_cnbSYSTEM\ControlSet002\Services\vivadrvSYSTEM\CurrentControlSet\Enum\Root\LEGACY_NCUPONSDRVSYSTEM\CurrentControlSet\Enum\Root\LEGACY_VIVADRVSYSTEM\CurrentControlSet\Services\COMLiveServiceSYSTEM\CurrentControlSet\Services\NCupons ApplicationSYSTEM\CurrentControlSet\Services\ncuponsdrvSYSTEM\CurrentControlSet\services\NSCP ServiceSYSTEM\CurrentControlSet\services\nscp_cnbSYSTEM\CurrentControlSet\Services\vivadrvHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}NCuponsnscp_cnb{15436961-4543-4CA2-ACBF-0B5C73D9E737}_is1

Additional Information

The following directories were created:
%PROGRAMFILES%\RBM\CashNBack%PROGRAMFILES%\RBM\NCupons%PROGRAMFILES%\nscp%PROGRAMFILES(x86)%\RBM\CashNBack%PROGRAMFILES(x86)%\RBM\NCupons%PROGRAMFILES(x86)%\nscp
Loading...