WbSvCouponApp

WbSvCouponApp

Known Toolbar

by InstalleRex-WebPick

What is WbSvCouponApp?

WbSvCouponApp is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 67.53% of installations running this operating system. WbSvCouponApp's installer is typically 836.00 KB in size and installs around 69 files. The most common release is 2.2.0.1281 with 20.78% of all installations currently using this version.

WbSvCouponApp is most popular in the United States with 58.14% of installations residing in this country.

About WbSvCouponApp?

Coupon App is a web browser extension developed by JustPlug.It and distributed through the WebPick InstalleRex download and install manager. It is often bundled with adware offers and includes various components such as a Windows service, auto-starting component, and browser toolbar/plugin. The purpose of the extension is to inject advertisements in the form of banner ads, hyper-text links, popups, and affiliate codes in links as coupon offers. Additionally, it may hijack existing advertising on websites. During installation, the program will install itself in a folder with a random name in Program Files or ProgramData, and each included file will also have a shared randomly generated name. The Windows Service runs with full administrator rights under the Services control app and connects to remote servers for updates. It also creates a server that listens for TCP network requests locally.

Multiple virus scanners have detected malware in WbSvCouponApp.

VG.exe (MD5: eb4ce60ecd7f5821196fa0e2996ea50b) has been flagged by 36 scanners:
Scanner Software Result
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:Dropper-gen [Drp]
AVG Generic5.AVUU
Avira SPR/Tool.689664.1
AVware Trojan.Win32.Generic!BT
ByteHero BDV Trojan.Exception.gen.101
Comodo Security ApplicUnwnt
Cyren W32/Application.SEEW-0376
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
McAfee Artemis!EB4CE60ECD7F
McAfee-GW-Edition BehavesLike.Win32.PUP.jh
NANO AntiVirus Riskware.Win32.MultiPlug.dfmntw
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA OA
SUPERAntiSpyware Adware.Multiplug/Variant
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.3
VIPRE Antivirus Trojan.Win32.Generic!BT
Lavasoft Ad-Aware Application.Generic.654852
Baidu-International Adware.Win32.MultiPlug.bY
Bitdefender Application.Generic.654852
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.654852
G Data Application.Generic.654852
Malwarebytes PUP.Optional.MultiPlug.A
MicroWorld-eScan Application.Generic.654852
Qihoo-360 Win32/Trojan.Dropper.c9f
TrendMicro-HouseCall Suspicious_GEN.F47V0620
IKARUS anti.virus Win32.Downloader.UZJ
K7 AntiVirus Adware ( 00495ec11 )
K7GW Adware ( 00495ec11 )
Avira AntiVir Adware/MultiPlug.Y.4
Antiy-AVL Trojan/Win32.TSGeneric
Dr.Web Trojan.Crossrider.1760
ViRobot Adware.Agent.695808
1U.exe (MD5: 18c75d6e6235019d9d92dd51ff43cc3b) has been flagged by 16 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:Dropper-gen [Drp]
ByteHero BDV Trojan.Exception.gen.101
Dr.Web Trojan.Crossrider.5139
McAfee Artemis!18C75D6E6235
McAfee-GW-Edition Artemis!18C75D6E6235
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.F47V0317
VIPRE Antivirus JustPlugIt (fs)
AVG Generic5.AWDQ
Baidu-International Adware.Win32.BHO.77
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
Malwarebytes PUP.Optional.MultiPlug.A
Comodo Security Application.Win32.MultiPlug.SJ
Qihoo-360 HEUR/Malware.QVM10.Gen
ViRobot Adware.Agent.695808
2RApv.exe (MD5: 028c1a42ac6ff8fc1798d94718ed480f) has been flagged by 23 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.621135
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:MultiPlug-AD [PUP]
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.45
Bitdefender Application.Generic.621135
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.T
G Data Application.Generic.621135
K7GW Adware ( 004976341 )
Malwarebytes PUP.Optional.MultiPlug.A
MicroWorld-eScan Application.Generic.621135
TrendMicro-HouseCall TROJ_GEN.F47V0416
VIPRE Antivirus Trojan.Win32.Generic!BT
Dr.Web Trojan.Crossrider.1760
IKARUS anti.virus Virus.Win32.Dropper
K7 AntiVirus Adware ( 00495ec11 )
McAfee Artemis!29EE858C3050
McAfee-GW-Edition Artemis!29EE858C3050
Qihoo-360 HEUR/Malware.QVM10.Gen
Symantec WS.Reputation.1
ByteHero BDV Trojan.Exception.gen.101
ViRobot Adware.Agent.695808
FTjBX6Vo6.exe (MD5: dc0ac7dbdcbbb8b2561ba9b8ccab3d37) has been flagged by 9 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
Malwarebytes PUP.Optional.Multiplug
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
Symantec WS.Reputation.1
ViRobot Adware.Agent.695808
Baidu-International Adware.Win32.AdBlock.81
TrendMicro-HouseCall TROJ_GEN.F47V0519
AVG Generic5.AVLQ
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
Fp8F3EOou.exe (MD5: d0d484be64658687aec68689c2480693) has been flagged by 12 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:MultiPlug-AD [PUP]
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.T
Comodo Security Application.Win32.MultiPlug.SJ
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.T
Malwarebytes PUP.Optional.MultiPlug.A
Qihoo-360 HEUR/Malware.QVM10.Gen
TrendMicro-HouseCall TROJ_GEN.F47V0214
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
Symantec WS.Reputation.1
ViRobot Adware.Agent.695808

Software Details

URL:
https://optonthing.info
Support:
–
Installation path:
C:\ProgramData\wbsvcouponapp
Uninstaller:
"C:\ProgramData\WbSvCouponApp\hikS.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
836.00 KB
Language:
English

WbSvCouponApp Executable Details

Primary executable:
hikS.exe
Name:
WbSvCouponApp
Path:
C:\ProgramData\wbsvcouponapp\hikS.exe
MD5:
ef38514253e4dafb6823f236bc47bb5f
SHA-1:
–
SHA-256:
–
Files installed by WbSvCouponApp
File Type Filename MD5
EXE
ef38514253e4dafb6823f236bc47bb5f
EXE
bcea600f3a66eb8a64c96c385e4e0371
EXE
VG.exe
Adware
eb4ce60ecd7f5821196fa0e2996ea50b
EXE
0920b67a31662468e9eafdb6d9bc0f72
EXE
18c75d6e6235019d9d92dd51ff43cc3b
EXE
1U.exe
Adware
18c75d6e6235019d9d92dd51ff43cc3b
EXE
028c1a42ac6ff8fc1798d94718ed480f
EXE
d0d484be64658687aec68689c2480693
EXE
dc0ac7dbdcbbb8b2561ba9b8ccab3d37
EXE
d0d484be64658687aec68689c2480693