PUP.Optional.Binkiland

Binkiland is a software usually installed without your knowledge with the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
Identified : 07/08/2015.

Features

– It belongs to a family of PUP (Potentially Unwanted Program).
– A polluteware is a software that pollutes storage and/or the Base of registers.
– An Adware is a program that adds other programs without the knowledge of the user.
– Vendor : PUP.Optional

Main Actions

– It installs a plugin of the browser Google Chrome (G2),
– It installs a program of extension for browser Mozilla Firefox (M2),
– It installs a plugin of the browser Mozilla Firefox (P2),
– It changes the start page of the browser Mozilla Firefox (M0),
– It changes the start page of the browser Internet Explorer (R0),
– It changes the IP addresses of the file Hosts (O1),
– It is installed as a BHO (Browser Helper Object) of internet browser (O2),
– It installs as a process launched at startup of the system (RP),
– It Place multiple shortcuts application, Desktop, QuickLaunch, Taskbar (O4GS),
– It settled in the Base of registers to be launched each time with the system (O4),
– It installs as a program (O42),
– It creates to many registry keys ‘Software’,
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45),
– It creates multiple files users (O61),
– It changes the Internet research provider (O69),

– (…) — C:UsersCoolmanAppDataLocalBinkilandApplicationbinkiland.exe
M0 – MFSP: prefs.js http://binkiland.com
P2 – MFPP: Plugins – — C:UsersCoolmanAppDataRoamingMozillaFirefoxProfilesm9fgc5v2.defaultsearchpluginsBinkiland.xml
R0 – HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://binkiland.com
O4 – GSQuickLaunch : Binkiland.lnk . (…) — C:UsersCoolmanAppDataLocalBinkilandApplicationbinkiland.exe
O4 – GSTaskBar : Binkiland.lnk . (…) — C:UsersCoolmanAppDataLocalBinkilandApplicationbinkiland.exe
O4 – GSDesktop : Binkiland.lnk . (…) — C:UsersCoolmanAppDataLocalBinkilandApplicationbinkiland.exe
O4 – HKLM..Wow6432NodeRunOnce: . (.Microsoft Corporation – Microsoft ® Windows Based Script Host.) — C:WindowsSysWOW64wscript.exe
O4 – HKUSS-1-5-21-14936340-1953058750-3854532654-1001..RunOnce: . (.Microsoft Corporation – Microsoft ® Windows Based Script Host.) — C:WindowsSysWOW64wscript.exe
O4 – HKCU..Run: . (…) — C:UsersCoolmanAppDataLocalBinkilandApplicationbinkiland.exe =>PUP.Binkiland
O4 – HKCU..RunOnce: . (…) — C:UsersCoolmanAppDataRoamingWse_binkilandUpdateProcbkup.dat =>PUP.Binkiland
O4 – HKLM..Wow6432NodeRunOnce: . (…) — C:UsersCoolmanAppDataRoamingWse_binkilandUpdateProcbkup.dat =>PUP.Binkiland
O4 – HKUSS-1-5-21-1809328612-682360070-3977180644-1001..Run: . (…) — C:UsersCoolmanAppDataLocalBinkilandApplicationbinkiland.exe =>PUP.Binkiland
O4 – HKUSS-1-5-21-1809328612-682360070-3977180644-1001..RunOnce: . (…) — C:UsersCoolmanAppDataRoamingWse_binkilandUpdateProcbkup.dat
(…) — C:UsersCoolmanAppDataRoamingWSE_BI~1UPDATE~1UPDATE~1.exe
O39 – APT: – (..) — C:WindowsTasksBinkiland.job
O39 – APT: – (..) — C:WindowsSystem32TasksBinkiland
O39 – APT: Wse_binkiland – (…) — C:WindowsTasksWse_binkiland.job
O39 – APT: Wse_binkiland – (…) — C:WindowsSystem32TasksWse_binkiland
O42 – Logiciel: WSE_Binkiland – (.WSE_Binkiland.) — WSE_Binkiland
O42 – Logiciel: Binkiland – (.Binkiland.) — Binkiland
HKCUSoftwareBinkiland Browser
HKCUSoftwarewse_binkiland
O43 – CFD: 06/02/2015 – 08:18:32 – [] —-D C:UsersCoolmanAppDataRoamingBinkiland
O43 – CFD: 06/02/2015 – 08:20:59 – [] —-D C:UsersCoolmanAppDataLocalBinkiland
O42 – Logiciel: WSE_Binkiland – (.WSE_Binkiland.) — WSE_Binkiland
O43 – CFD: 05/02/2015 – 15:05:49 – [] —-D C:Program Files (x86)WSE_Binkiland
O43 – CFD: 05/02/2015 – 15:05:52 – [] —-D C:UsersCoolmanAppDataRoamingBinkiland
O43 – CFD: 05/02/2015 – 15:10:57 – [] —-D C:UsersCoolmanAppDataLocalBinkiland
O43 – CFD: 19/03/2015 – 19:13:47 – [] —-D C:UsersCoolmanAppDataRoamingMicrosoftWindowsStart MenuProgramsBinkiland
O45 – LFCP: – 20/03/2015 – 07:51:17 —A- – C:WindowsPrefetchBINKILAND.EXE-C1EE046A.pf
O45 – LFCP: – 19/03/2015 – 19:13:03 —A- – C:WindowsPrefetchBINKILANDUPDATE.EXE-8DBA158F.pf
O61 – LFC: 05/02/2015 – 12:50:58 —A- . (…) — C:UsersCoolmanAppDataRoamingBinkilandUpdateProcUpdateTask.exe
O61 – LFC: 19/03/2015 – 07:56:40 —A- . (…) — C:UsersCoolmanAppDataLocalBinkilandApplication31.0.1650.23Installersetup.exe
O61 – LFC: 19/03/2015 – 07:56:41 —A- . (…) — C:UsersCoolmanAppDataLocalBinkilandApplication31.0.1650.23Installeruninstall.exe
O61 – LFC: 19/03/2015 – 07:56:44 —A- . (…) — C:UsersCoolmanAppDataLocalMicrosoftWindowsINetCacheLowIEZ0I47XZ3.binkiland.com
O61 – LFC: 19/03/2015 – 07:56:48 —A- . (…) — C:UsersCoolmanAppDataRoamingWse_binkilandUpdateProcUpdateTask.exe
O69 – SBI: SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} – (Binkiland) – http://binkiland.com

:GoogleChromeAutoLaunch_A08799EAF8C1D4F0D8A3C934A7CEFFE6
:Wse_binkiland
:Wse_binkiland
C:Program Files (x86)WSE_Binkiland
C:UsersCoolmanAppDataRoamingWse_binkiland
C:UsersCoolmanAppDataLocalBinkiland
C:UsersCoolmanAppDataRoamingMicrosoftWindowsStart MenuProgramsBinkiland
C:UsersCoolmanAppDataLocalBinkilandApplicationbinkiland.exe
C:UsersCoolmanAppDataRoamingWSE_BI~1UPDATE~1UPDATE~1.exe
C:WindowsTasksWse_binkiland.job
C:WindowsSystem32TasksWse_binkiland

Alias

PUP.Optional.Binkiland.A
Win32:GenMaliciousA-IEU
Adware.Graftor

Remove Software

– Remove software in Windows Configuration Panel,

Remove with ZHPcleaner

Diagnose with ZHPDiag

1 Vote2 Votes3 Votes4 Votes5 Votes (1 votes, average: 5.00 out of 5)
SOSVirusLoading...

Leave a Comment