PUP.Optional.Bang5mai

Logo_Malware
Bang5mai is an application usually installs without your knowledge vith the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
Identified : 07/08/2015.

Features

– It belongs to a family of PUP (Potentially Unwanted Program).
– A polluteware is a software that pollutes storage and/or the Base of registers.
– Vendor : PUP.Optional

Main Actions

– It installs a plugin of the browser Google Chrome (G2)
– It installs a program of extension for browser Mozilla Firefox (M2)
– It installs a plugin of the browser Mozilla Firefox (P2)
– It is installed as a BHO (Browser Helper Object) of internet browser (O2),
– It installs as a process launched at startup of the system (RP),
– It installs as a service to be launched each time the system (O23),(SS/SR).
– It creates to many registry keys ‘Software’
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45).
– It creates multiple files users (O61),

– (…) — C:UsersCoolmanAppDataLocalB5TShareB5TService.exe
G2 – GCE: Preference __MSG_extTitle__
P2 – EXT FILE: (…) — C:UsersCoolmanAppDataRoamingMozillaFirefoxProfilesj78hke7b.defaultextensionsextension@b5m.com.xpi
P2 – FPN: – (.B5MSoft.) — C:UsersCoolmanAppDataLocalB5TPluginnpB5TPlugin.dll
O2 – BHO: B5T Shopping Assistant – {260669B1-FC2C-41C0-BAA2-6EF3BB188660} . (.B5MSoft – Bang5Tao BHO.) — C:UsersCoolmanAppDataLocalB5TPluginB5TShoppingAssistant.dll
O23 – Service: B5TService (B5TService) . (…) – C:UsersCoolmanAppDataLocalB5TShareB5TService.exe
HKLMSOFTWAREB5TService
HKCUSOFTWAREB5MSoft
O43 – CFD: 2015/10/16 16:10:20 – D — C:ProgramDataB5TTmp
O43 – CFD: 2015/10/01 15:23:03 – [] D — C:UsersCoolmanAppDataLocalB5T
SR – Auto B5TService (B5TService) . (…) – C:UsersCoolmanAppDataLocalB5TShareB5TService.exe

Alias

PUP.Optional.Bang5mai.A
PUA.Win32.Bang5mai.B 20151012
W32.HfsAdware.E5B3 20151012
a variant of Win32/Bang5mai.B potentially unwanted 20151013
Riskware/Bang5mai 20151013
PUA.Bang5mai 20151013
PE:PUF.Hijacker-B5T!1.A1C0

Remove Software

– Remove software in Windows Configuration Panel,

Remove with ZHPcleaner

Diagnose with ZHPDiag

1 Vote2 Votes3 Votes4 Votes5 Votes (No Ratings Yet)
SOSVirusLoading...

Leave a Comment