Home > Hijackthis Log > Hijackthis Log - Bargain Buddy

Hijackthis Log - Bargain Buddy

Bargain Buddy Started by sjs1967 , Sep 18 2006 12:05 AM Please log in to reply 1 reply to this topic #1 sjs1967 sjs1967 Newbie Members 1 posts Posted 18 September Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dllO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} Blogs Advanced Search Forums Spyware Help eXact.Downloader Trojan infestation (incl. Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM) O9 - Extra button: Messenger check over here

helpful links Hijack This! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXEO23 - Service: ZipToA - Unknown owner - C:\WINDOWS\System32\ZipToA.exe (file missing) Back to top #2 LS CalamityJane LS CalamityJane Former Lavasoft Staff Members 8814 posts Posted 21 September 2006 Hijack This Found Bargain Buddy Started by Soultemptress , Apr 30 2004 01:35 AM This topic is locked 6 replies to this topic #1 Soultemptress Soultemptress Authentic Member Authentic Member 20 Before posting the log, please make sure you follow all the steps found in this topic:Preparation Guide For Use Before Posting A Hijackthis LogPlease also post the problems you are having.

Any bad links or emails that are not from the original poster will be deleted without response. All rights reserved. And also see So how did I get infected in the first place? Bargain Buddy Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Karen Fulks, Feb 22, 2005.

Press the "Fix Button" Let it fix all variants. Yes, my password is: Forgot your password? If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you Free Computer Help.

In this thread, post, please: - a new HijackThis log - The SilentRunners log. Pool 2 - http://download.game...ts/y/potc_x.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...ry/msgrchkr.cab O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaud...d/ccpm_0237.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yaho...s/yinst0309.cab O16 Bargain Buddy) LinkBack LinkBack URL About LinkBacks Thread Tools Show Printable Version Email this Page… Subscribe to this Thread… 11-26-200411:53 PM #1 Buster Guest eXact.Downloader Trojan infestation (incl. bjgarrick, Feb 22, 2005 #3 (You must log in or sign up to reply here.) Show Ignored Content Share This Page Your name or email address: Do you already have an

Along with SpywareInfo, it was one of the first places to offer online malware removal training in its Classroom. I'm Lost! - Forums Home - Tutorials - Get Computer Help - Spyware Help - Help2Go Detective - Software Picks - Newsletter - Testimonials - Donate Our Sponsors Help2Go Archive Top Bargain Buddy) If anyone has the time and the inclination to help with an infestation of eXact.Downloader Trojan, I'd appreciate it. I thought I'd be able to clean up my mess, but that's not the case.

For further Protection download and install: SpywareBlaster will block bad ActiveX and malevolent cookies. Thanks a lot. 11-27-200410:41 AM #2 Buster Guest Additional Info on eXact By the way, here's a link that provides more information on the eXact.Downloader spyware: http://spynet.com/spyware/spyware-eXact.Downloader.aspx Thanks 11-27-200412:03 PM #3 This can be done by looking at the instructions at This Webpage http://www.xtra.co.n...1916458,00.html To Delete These Files/Folders, You Will need to Boot into Safe Mode. O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll O4 - HKLM\..\Run: [msbb] c:\docume~1\deb\locals~1\temp\msbb.exe After this, Reboot and Delete the following files: C:\WINDOWS\2_0_1browserhelper2.dll c:\docume~1\deb\locals~1\temp\msbb.exe you really need to update your windows

After working thru the wonderful instructions Lawrence has written, I then ran another XoftSpy scan and Bargain Buddy is still appearing on my computer. http://exomatik.net/hijackthis-log/hijackthis-log-someone-help.php Reboot If I have specified below, and Post a Fresh HijackThis log. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dllO2 - BHO: Yahoo! IAMH4 View Public Profile Find all posts by IAMH4 #2 December 14th, 2004, 03:42 PM brownsfan Member Join Date: Jan 2004 Location: Ohio Age: 50 Posts: 85 Don't

Cheers. Site Changelog Community Forum Software by IP.Board Sign In Use Facebook Use Twitter Need an account? It goats people with false positives to get you to buy it. this content Besides running Spybot and Adaware, I've also run several other programs.

so you have C:\hijackthis\hijackthis.exe.....then run hijackthis by clicking this .exe file -that way you will have backups if you accidentally remove the wrong item ( running from a temporary folder these Register now! Sign In Use Facebook Use Twitter Need an account?

helpful links Hijack This!

Stay logged in MajorGeeks.Com Support Forums Home Forums > ----------= PC, Desktop and Laptop Support =------ > Malware Help - MG (A Specialist Will Reply) > MajorGeeks.Com Menu MajorGeeks.Com \ All Password Register FAQ Calendar Today's Active Topics Search Notices Viewing on a mobile device? Bargain Buddy) Results 1 to 7 of 7 Thread: eXact.Downloader Trojan infestation (incl. Did we mention that it's free.

Back to top #7 Galadriel Galadriel CEO - Chief Elvish Officer Visiting Fellow 528 posts Posted 30 April 2004 - 01:55 PM Glad we could help. I've tried running all of these in Safe mode, too, but that doesn't do it. Download SilentRunners Run it. http://exomatik.net/hijackthis-log/hijackthis-log-aky.php Look for the *New Topic* Button near the top right when viewing the forums.

A han noston ne 'wilith. - Galadriel 'The world is changed; I can feel it in the water, I can feel it in the earth, I can smell it in the I think I have messed up with posting. Spybot: Search & Destroy CWShredder So How did I get infected in the first place? Pool 2 - http://download.game...ts/y/potc_x.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...ry/msgrchkr.cab O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaud...d/ccpm_0237.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yaho...s/yinst0309.cab O16

PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics) Social: Please re-enable javascript to access full functionality.