Category:Adware,BHO
BargainBuddy (CashBack) Detection :
Files:
[%PROGRAM_FILES%]\BullsEye Network\bin\bargains.exe
[%PROGRAM_FILES%]\BullsEye Network\Uninstall.exe
[%PROGRAM_FILES%]\CashBack\bb_auto_wider.swf
[%PROGRAM_FILES%]\CashBack\bb_click_wider.swf
[%PROGRAM_FILES%]\CashBack\bb_welcome.html
[%PROGRAM_FILES%]\CashBack\bb_welcome1.swf
[%PROGRAM_FILES%]\CashBack\bin\cb.exe
[%PROGRAM_FILES%]\CashBack\bin\flash.exe
[%PROGRAM_FILES%]\CashBack\blank.gif
[%PROGRAM_FILES%]\CashBack\icon.gif
[%PROGRAM_FILES%]\CashBack\logo.gif
[%PROGRAM_FILES%]\CashBack\template.html
[%PROGRAM_FILES%]\CashBack\template2.html
[%PROGRAM_FILES%]\CashBack\template_signin.html
[%PROGRAM_FILES%]\CashBack\ub.dat
[%PROGRAM_FILES%]\CashBack\Uninstall.exe
[%SYSTEM%]\msbe.dll
[%WINDOWS%]\Temp\blank.gif
[%PROGRAM_FILES%]\BullsEye Network\bin\bargains.exe
[%PROGRAM_FILES%]\BullsEye Network\Uninstall.exe
[%PROGRAM_FILES%]\CashBack\bb_auto_wider.swf
[%PROGRAM_FILES%]\CashBack\bb_click_wider.swf
[%PROGRAM_FILES%]\CashBack\bb_welcome.html
[%PROGRAM_FILES%]\CashBack\bb_welcome1.swf
[%PROGRAM_FILES%]\CashBack\bin\cb.exe
[%PROGRAM_FILES%]\CashBack\bin\flash.exe
[%PROGRAM_FILES%]\CashBack\blank.gif
[%PROGRAM_FILES%]\CashBack\icon.gif
[%PROGRAM_FILES%]\CashBack\logo.gif
[%PROGRAM_FILES%]\CashBack\template.html
[%PROGRAM_FILES%]\CashBack\template2.html
[%PROGRAM_FILES%]\CashBack\template_signin.html
[%PROGRAM_FILES%]\CashBack\ub.dat
[%PROGRAM_FILES%]\CashBack\Uninstall.exe
[%SYSTEM%]\msbe.dll
[%WINDOWS%]\Temp\blank.gif
Registry Keys:
HKEY_CLASSES_ROOT\adp.urlcatcher
HKEY_CLASSES_ROOT\adp.urlcatcher.1
HKEY_CLASSES_ROOT\cb.urlcatcher
HKEY_CLASSES_ROOT\cb.urlcatcher.1
HKEY_CLASSES_ROOT\CLSID\{CE188402-6EE7-4022-8868-AB25173A3E14}
HKEY_CLASSES_ROOT\CLSID\{F4E04583-354E-4076-BE7D-ED6A80FD66DA}
HKEY_CLASSES_ROOT\interface\{8eee58d5-130e-4cbd-9c83-35a0564e2468}
HKEY_CLASSES_ROOT\interface\{8eee58d5-130e-4cbd-9c83-35a0564e5678}
HKEY_CLASSES_ROOT\interface\{c6906a23-4717-4e1f-b6fd-f06ebed12468}
HKEY_CLASSES_ROOT\interface\{c6906a23-4717-4e1f-b6fd-f06ebed15678}
HKEY_CLASSES_ROOT\typelib\{4eb7bbe8-2e15-424b-9ddb-2cdb9516b2c3}
HKEY_CLASSES_ROOT\typelib\{4eb7bbe8-2e15-424b-9ddb-2cdb9516e2a3}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE188402-6EE7-4022-8868-AB25173A3E14}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4E04583-354E-4076-BE7D-ED6A80FD66DA}
HKEY_LOCAL_MACHINE\SOFTWARE\Bargains
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADP.UrlCatcher
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADP.UrlCatcher.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CB.UrlCatcher
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CB.UrlCatcher.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CE188402-6EE7-4022-8868-AB25173A3E14}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F4E04583-354E-4076-BE7D-ED6A80FD66DA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E2468}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E5678}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED12468}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED15678}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4EB7BBE8-2E15-424B-9DDB-2CDB9516B2C3}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4EB7BBE8-2E15-424B-9DDB-2CDB9516E2A3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CE188402-6EE7-4022-8868-AB25173A3E14}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4E04583-354E-4076-BE7D-ED6A80FD66DA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BargainBuddy
Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Removing BargainBuddy (CashBack):
you can run trial version of ExterminateIt, or remove BargainBuddy (CashBack) manually..ExterminateIt effectively and automatically removes Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware) from you computer.
Download ExterminateIt! to instantly get rid of BargainBuddy (CashBack)!
Also Be Aware of the Following Threats:
Desktop.Marketer Adware Information
Warftpd DoS Removal
Assassin.Pub RAT Removal
skymasters.biz Adware Removal instruction
Backdoor.Spigot Backdoor Removal