Home Malware Programs Adware B-Information

B-Information

Posted: April 14, 2014

Threat Metric

Ranking: 6,216
Threat Level: 2/10
Infected PCs: 42,889
First Seen: April 14, 2014
Last Seen: March 2, 2025
OS(es) Affected: Windows


B-Information is adware that may insert an unwanted add-on, plug-in or browser extension on the Web browsers such as Internet Explorer, Mozilla Firefox, and Google Chrome. Once installed on the computer system, Help Save may display pop-up advertisements, messages and banners carrying various online saving coupons, discount deals, sales, and other offers. B-Information may seem to be a useful tool to online shoppers. However, in fact, B-Information may be considered to be a potentially unwanted program (PUP) if it installs itself on the PC without the computer user's approval. B-Information may spread and access the PC as an extra program through bundled freeware that computer users can download from unreliable download websites. B-Information may keep track of the PC user's surfing habits and gather browsing details that may later be used with the purpose to deliver targeted advertisements. B-Information may be created with the goal to generate advertising income from clicks on ads and messages.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



E:\Partition C\Programme\InstallShield Installation Information\{E28B1E6F-E0AA-4228-AB89-DB4A0C89D426}\setup.exe File name: setup.exe
Size: 294.91 KB (294912 bytes)
MD5: 9a48b208b1dbb07a23604566eb8db9d1
Detection count: 10,057
File type: Executable File
Mime Type: unknown/exe
Path: E:\Partition C\Programme\InstallShield Installation Information\{E28B1E6F-E0AA-4228-AB89-DB4A0C89D426}\setup.exe
Group: Malware file
Last Updated: January 18, 2025
%PROGRAMFILES(x86)%\Information\50368.xpi File name: 50368.xpi
Size: 308.7 KB (308703 bytes)
MD5: fedc6e4409160a78138ef40576c64609
Detection count: 74
Mime Type: unknown/xpi
Path: %PROGRAMFILES(x86)%\Information
Group: Malware file
Last Updated: April 16, 2014
%PROGRAMFILES(x86)%\Information\Uninstall.exe File name: Uninstall.exe
Size: 78.84 KB (78848 bytes)
MD5: 08229e6e0a178632405a85d99ba3ed9f
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Information
Group: Malware file
Last Updated: March 3, 2020

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{11111111-1111-1111-1111-110511031168}{22222222-2222-2222-2222-220522032268}{44444444-4444-4444-4444-440544034468}{55555555-5555-5555-5555-550555035568}{66666666-6666-6666-6666-660566036668}Regexp file mask%WinDir%\System32\Tasks\Information-chromeinstaller%WinDir%\System32\Tasks\Information-codedownloader%WinDir%\System32\Tasks\Information-firefoxinstaller%WinDir%\System32\Tasks\Information-updater%WinDir%\Tasks\Information-chromeinstaller.job%WinDir%\Tasks\Information-codedownloader.job%WinDir%\Tasks\Information-firefoxinstaller.job%WinDir%\Tasks\Information-updater.jobHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Crossrider\onBeforeNavigate\50368Software\AppDataLow\Software\Crossrider\onRequest\50368Software\AppDataLow\Software\InformationSOFTWARE\Classes\CrossriderApp0050368.BHOSOFTWARE\Classes\CrossriderApp0050368.BHO.1SOFTWARE\Classes\CrossriderApp0050368.SandboxSOFTWARE\Classes\CrossriderApp0050368.Sandbox.1SOFTWARE\InformationSoftware\InstalledBrowserExtensions\21409\50368Software\InstalledBrowserExtensions\VisualBee\50368Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110511031168}SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Information-bg.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Information-chromeinstallerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Information-codedownloaderSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Information-firefoxinstallerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Information-updaterSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511031168}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110511031168}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110511031168}SOFTWARE\Wow6432Node\InformationSOFTWARE\Wow6432Node\InstalledBrowserExtensions\21409\50368SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Information-bg.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511031168}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Information

Additional Information

The following directories were created:
%PROGRAMFILES%\Information%PROGRAMFILES(x86)%\Information
Loading...