PDA

View Full Version : Binkiland: not supported yet?



maxxyme
2015-02-10, 00:42
Hello,

My wife unfortunately installed so crapware attached to i-dont-know-which install program she executed, and I noticed alongside OptimizerPro, and ClockHand, there was this browser-hijacker "Binkiland".
The most visually impacting problem is, once Windows' started, you can't see the desktop, but a black screen. And there's this small OptimizerPro registrer popup in the right-low corner, and even if you click No, the black screen stays.
Hopefully for you, if you know enough in Windows, you can go back to the desktop by starting the task manager (Ctrl+Shift+Esc) and killing the explorer.exe process, then re-start it.
Under the Programs and Features you can execute some uninstalls these crapwares put there, but they still left traces (files, folders) and active threats (startup scripts).

Apparently you can "get" it by installing Daemon Tools Lite from clubic.com, as said in this French help forum: http://www.commentcamarche.net/forum/affich-31517048-ecran-noir-binkiland-adware
But I can't recall what did my wife download. So, can't help you with that.

I think this malware is quite new, as I just installed/updated Spybot S&D 2, did a full scan, and it did find nothing. But after that, I had to manually check some registry keys, especially RunOnce startup entries that still tried to launch some scripts hidden in this folder: C:\Users\Admin\AppData\Roaming\Binkiland

tashi
2015-02-10, 04:21
Hello maxxyme, :welcome:

In case you missed it please see the FAQ which also includes guidelines for this Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) and instructions in post #2 on how to provide the logs from Farbar Recovery Scan Tool and aswMBR, which are the logs used in the preliminary analysis.

http://forums.spybot.info/showthread.php?t=288

If you'd like someone to take a look at the system please start a new topic providing the logs as shown in that sticky with a link back to this thread and a volunteer analyst will advise. :)


Hello,

My wife unfortunately installed so crapware attached to i-dont-know-which install program she executed, and I noticed alongside OptimizerPro, and ClockHand, there was this browser-hijacker "Binkiland".


In the event a software is installed with user permission it is unlikely to be flagged, please see: Optional Installs (http://forums.spybot.info/showthread.php?279-So-how-did-I-get-infected-in-the-first-place&p=286306&viewfull=1#post286306)

Best regards.