Home Malware Programs Potentially Unwanted Programs (PUPs) S5mark

S5mark

Posted: February 23, 2015

Threat Metric

Ranking: 7,185
Threat Level: 2/10
Infected PCs: 35,851
First Seen: February 23, 2015
Last Seen: October 14, 2023
OS(es) Affected: Windows

S5mark is classified a Potentially Unwanted Program (PUP) with adware symptoms that pretend to optimize your online experience. Distribution methods of adware-laced products like S5mark are various - bundling techniques, spam campaigns, malicious websites, etc. Once it has infected your PC, S5mark would instantly start displaying additional online advertisements. 'Ads by S5mark', 'Powered by S5mark' or 'Brought to you by S5mark' may be noticed in the bottom of the advertisements. S5mark adware application is known to affect all well-known browsers and the computer as well. Performance of your PC may significantly drop because of S5mark, and your online experience might become rather unpleasant.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\n7048\s5Mark_0302-daa74853.exe File name: s5Mark_0302-daa74853.exe
Size: 974.84 KB (974848 bytes)
MD5: 4d818b4785504db3791f24cfa6ea93d6
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\n7048
Group: Malware file
Last Updated: March 17, 2015
dz.exe File name: dz.exe
Size: 1.34 MB (1341440 bytes)
MD5: 55810b4d79abbcd3d42f0aff6b3f67f9
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 10, 2020

Registry Modifications

The following newly produced Registry Values are:

File name without pathS5mark.lnkRegexp file mask%userprofile%\Desktop\s5.lnkHKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Network\FileServiceSOFTWARE\Microsoft\Windows\CurrentVersion\Run\s5markrunSOFTWARE\Wow6432Node\Microsoft\Network\FileServiceSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\s5markrunSOFTWARE\Wow6432Node\xsHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}s5ms5mark

Additional Information

The following directories were created:
%PROGRAMFILES%\S5
Loading...