spyware removal instructions

BargainBuddy removal

Spyware BargainBuddy Information
Name: BargainBuddy
Category: Adware
Date: 2005-04-23
Dangerous: Yes
BargainBuddy belongs to Adware spyware category.
BargainBuddy is a Explorer Helper Object that monitores the pages your explorer requests & the terms you enter into a search engine web form. If a term matches a preset list of sites or keywords, BargainBuddy will display an ad. A process that is invoked at machine startup will check a remote server for updates to the software & ads that will be displayed.Bargain Buddy is made of an IE Explorer Helper Object, & a process define to run at startup. The BHO records web pages requested & terms inputed into forms. If theres a match with a preset list of sites & keywords, an advertisement may be shown. The process can contact its maker´s server to download updates to the list of adverts & to the software itself. It's presense means that your computer is infected with malicious software and is insecure.
BargainBuddy description by publisher:
"The eXact Advertising Network has been in existence since 2000 as the advertising sales division of Net2Phone Inc. In May 2002, the management team that ran the Net2Phone Ad Network completed a buyout of the division. What was born was a new company with yeahrs of experience & success as its foundation." [ source]´Bargain Buddy is installed on your computer & supplies relevant contextual data to you in the form of advertisements based on URLs and/or search terms you enter when navigating the Internet.´ --- From the End User License Agreement.
This Adware is also known as:
ap.exe (after the installer inclue with some versions) - named by e.
Adware/ExactSearch - named by Panda.
Bargain Buddy - named by a.
Brgins (process nme).
Bullseye Network.
Ikena (the server it connects to).
Spyware/BargainBuddy - named by Panda.

>> Delete BargainBuddy automatically - Download Spyware Doctor

BargainBuddy Removal Instructions
Kill the following processes
bargain3.exe, bargain4.exe, bbi8032.exe, buddy.exe, bargains.exe, igudyn.exe, manager.exe, newupdate.exe, bbchk.exe, bbi8015.exe, bbi8018.exe, bbi8024.exe, bargains.exe, cb.exe, bargains.exe, cb.exe, uninst.exe, bargainbuddy.exe, adp8035.exe, adv.exe, adx.exe, bargains.exe, uninstall.exe, euni_bbi8015.exe, msbb.exe, isinstalldonecrazy.exe, kahlisetup_demo.exe, keenpostback.exe, msbb.exe, nlnp49.exe, oskasetup_demo.exe, tahnisetup_demo.exe, nnstp_bbi6009.exe, sprite.exe, ahadp.exe, angelex.exe, bbchk.exe, exclean.exe, exdl.exe, exdl0.exe, exdl1.exe, exul.exe, exul1.exe, msexreg.exe, q17i9a4j.exe, zeta.exe, update.exe
Unregister the following DLLs and reboot
5de1097bc22d2117da82ee85603c38b1.dll, nvms.dll, webabout.dll, zmscb.dll.
apuc.dll in Program Files\bargain buddy\bin2\
apuc.dll in Program Files\bargain buddy\bin\
apuc.dll in Program Files\bargai~1\bin\
msbbhook.dll in Program Files\crazymates\
apuc.dll, msbb.dll, msbb1.dll, mset_bbi8010.dll, mset_bbi80101.dll, mset_bbi80102.dll, mset_bbi80103.dll, qh4mkbv9.dll in Windows\system32\
apuc.dll in Windows\system\
backup-20040105-225929-414.dll in Windows\temp\
Delete these registry entries
HKEY_CLASSES_ROOT\adp.urlcatcher
HKEY_CLASSES_ROOT\adp.urlcatcher.1\adp urlcatcher class
HKEY_CLASSES_ROOT\adp.urlcatcher.1\clsid\{f4e04583-354e-4076-be7d-ed6a80fd66da}
HKEY_CLASSES_ROOT\adp.urlcatcher\adp urlcatcher class
HKEY_CLASSES_ROOT\adp.urlcatcher\clsid\{f4e04583-354e-4076-be7d-ed6a80fd66da}
HKEY_CLASSES_ROOT\apuc.urlcatcher
HKEY_CLASSES_ROOT\apuc.urlcatcher\clsid
HKEY_CLASSES_ROOT\clsid\{ce31a1f7-3d90-4874-8fbe-a5d97f8bc8f1}
HKEY_CLASSES_ROOT\clsid\{014da6c4-189f-421a-88cd-07cfe51cff10}
HKEY_CLASSES_ROOT\clsid\{4eb7bbe8-2e15-424b-9ddb-2cdb9516a2a3}
HKEY_CLASSES_ROOT\clsid\{60f8fb2a-9915-4202-967d-1fa694a8bcf5}
HKEY_CLASSES_ROOT\clsid\{676058db-89bd-11d6-8a8c-0050ba8452c0}
HKEY_CLASSES_ROOT\clsid\{676058e3-89bd-11d6-8a8c-0050ba8452c0}
HKEY_CLASSES_ROOT\clsid\{6e1c7285-263b-431d-8b83-c3cbce301704}
HKEY_CLASSES_ROOT\clsid\{72f81209-6c73-4de7-a3dc-408a8bd472fb}
HKEY_CLASSES_ROOT\clsid\{79849612-a98f-45b8-95e9-4d13c7b6b35c}\control
HKEY_CLASSES_ROOT\clsid\{974cc25e-d62c-4278-84e6-a806726e37bc}
HKEY_CLASSES_ROOT\clsid\{9d1b86c7-1b93-4586-9009-ea3bd0ad63a5}
HKEY_CLASSES_ROOT\clsid\{9dbafccf-592f-ffff-ffff-00608cec297b}
HKEY_CLASSES_ROOT\clsid\{b8afa251-4efb-4703-87d4-da7d2435ba5e}
HKEY_CLASSES_ROOT\clsid\{be35582c-9796-4cf1-aed9-556ada120b38}
HKEY_CLASSES_ROOT\clsid\{c6906a23-4717-4e1f-b6fd-f06ebed14177}
HKEY_CLASSES_ROOT\clsid\{ce31a1f7-3d90-4874-8fbe-a5d97f8bc8f1}
HKEY_CLASSES_ROOT\clsid\{df7d760c-b7e2-4735-bb77-f5a1a9745e16}
HKEY_CLASSES_ROOT\clsid\{f94c0089-9394-4e44-b4ea-58dba1f7b84e}
HKEY_CLASSES_ROOT\interface\{8eee58d5-130e-4cbd-9c83-35a0564e5678}\ixyz
HKEY_CLASSES_ROOT\interface\{8eee58d5-130e-4cbd-9c83-35a0564e5678}\proxystubclsid\{00020424-0000-0000-c000-000000000046}
HKEY_CLASSES_ROOT\interface\{8eee58d5-130e-4cbd-9c83-35a0564e5678}\proxystubclsid32\{00020424-0000-0000-c000-000000000046}
HKEY_CLASSES_ROOT\interface\{8eee58d5-130e-4cbd-9c83-35a0564e5678}\typelib\{4eb7bbe8-2e15-424b-9ddb-2cdb9516b2c3}
HKEY_CLASSES_ROOT\interface\{8eee58d5-130e-4cbd-9c83-35a0564ea119}
HKEY_CLASSES_ROOT\interface\{c6906a23-4717-4e1f-b6fd-f06ebed14177}
HKEY_CLASSES_ROOT\interface\{c6906a23-4717-4e1f-b6fd-f06ebed15678}\iurlcatcher
HKEY_CLASSES_ROOT\interface\{c6906a23-4717-4e1f-b6fd-f06ebed15678}\proxystubclsid\{00020424-0000-0000-c000-000000000046}
HKEY_CLASSES_ROOT\interface\{c6906a23-4717-4e1f-b6fd-f06ebed15678}\proxystubclsid32\{00020424-0000-0000-c000-000000000046}
HKEY_CLASSES_ROOT\interface\{c6906a23-4717-4e1f-b6fd-f06ebed15678}\typelib\{4eb7bbe8-2e15-424b-9ddb-2cdb9516b2c3}
HKEY_CLASSES_ROOT\rsp.bizlgk\clsid
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{ce31a1f7-3d90-4874-8fbe-a5d97f8bc8f1}
HKEY_CLASSES_ROOT\typelib\{4eb7bbe8-2e15-424b-9ddb-2cdb9516a2a3}
HKEY_CLASSES_ROOT\typelib\{4eb7bbe8-2e15-424b-9ddb-2cdb9516b2c3}\1.0\0\win32\c:\windows\system32\msbe.dll
HKEY_CLASSES_ROOT\typelib\{4eb7bbe8-2e15-424b-9ddb-2cdb9516b2c3}\1.0\adp 1.0 type library
HKEY_CLASSES_ROOT\typelib\{4eb7bbe8-2e15-424b-9ddb-2cdb9516b2c3}\1.0\flags\0
HKEY_CLASSES_ROOT\typelib\{4eb7bbe8-2e15-424b-9ddb-2cdb9516b2c3}\1.0\helpdir\c:\windows\system32\
HKEY_LOCAL_MACHINE\software\bargains
HKEY_LOCAL_MACHINE\software\classes\f1.organizer
HKEY_LOCAL_MACHINE\software\classes\f1.organizer\clsid
HKEY_LOCAL_MACHINE\software\classes\f1.organizer\curver
HKEY_LOCAL_MACHINE\software\classes\interface\{226a045e-fd4e-4632-b51d-a112bd8254e5}
HKEY_LOCAL_MACHINE\software\classes\interface\{297afc77-2039-4d3c-bef9-598819eb2c8a}
HKEY_LOCAL_MACHINE\software\classes\interface\{676058e3-89bd-11d6-8a8c-0050ba8452c0}
HKEY_LOCAL_MACHINE\software\classes\interface\{8eee58d5-130e-4cbd-9c83-35a0564ea119}
HKEY_LOCAL_MACHINE\software\classes\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}
HKEY_LOCAL_MACHINE\software\classes\interface\{f6fbfe07-ca76-438e-b34e-4f4dc41f0123}
HKEY_LOCAL_MACHINE\software\classes\interface\{f94c0089-9394-4e44-b4ea-58dba1f7b84e}
HKEY_LOCAL_MACHINE\software\classes\ipinsigt.ipinsigtobj.1
HKEY_LOCAL_MACHINE\software\classes\typelib\{4eb7bbe8-2e15-424b-9ddb-2cdb9516a2a3}
HKEY_LOCAL_MACHINE\software\classes\typelib\{676058db-89bd-11d6-8a8c-0050ba8452c0}
HKEY_LOCAL_MACHINE\software\classes\typelib\{8c752c5e-3c10-4076-af0a-ffc69fa20d1b}
HKEY_LOCAL_MACHINE\software\classes\typelib\{974cc25e-d62c-4278-84e6-a806726e37bc}
HKEY_LOCAL_MACHINE\software\classes\typelib\{be35582c-9796-4cf1-aed9-556ada120b38}
HKEY_LOCAL_MACHINE\software\classes\typelib\{ef100607-f409-426a-9e7c-cb211f2a9030}
HKEY_LOCAL_MACHINE\software\classesc\wusn_id
HKEY_LOCAL_MACHINE\software\crazymates\install_dir
HKEY_LOCAL_MACHINE\software\euniverse\install_guid
HKEY_LOCAL_MACHINE\software\euniverse\vbarry\1.0\email
HKEY_LOCAL_MACHINE\software\euniverse\vbarry\1.0\lastname
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{6e1c7285-263b-431d-8b83-c3cbce301704}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\bargain buddy
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{ce31a1f7-3d90-4874-8fbe-a5d97f8bc8f1}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{f4e04583-354e-4076-be7d-ed6a80fd66da}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browserhelperobjects\{ce31a1f7-3d90-4874-8fbe-a5d97f8bc8f1}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\apd
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\bargains
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\bullseye network
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\epakucmzh\c:\winnt\epakucmzh.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{21c555b1-43b9-45e3-929f-258e64772372}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\bargain buddy
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\bargain buddy\displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\bargain buddy\uninstallstring
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\bargainbuddy
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\cashback
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\whenusaveuniv\displayicon
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\whenusaveuniv\displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\whenusaveuniv\displayversion
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\whenusaveuniv\helplink
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\whenusaveuniv\publisher
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\whenusaveuniv\uninstallstring
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\whenusaveuniv\urlinfoabout
HKEY_LOCAL_MACHINE\software\navisearch
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\zesoft
Remove the following files
5de1097bc22d2117da82ee85603c38b1.dll, ad.dat, bargain3.exe, bargain4.exe, bargainbuddy.txt, bbi8032.exe, data.mnu, fiz1, igudyn.exe, keenvaluelog.txt, kv002.dat, listing.txt, manager.exe, msbb.log, newupdate.exe, nvms.dll, oska deskmate.lnk, sprite.exe, tahni deskmate.lnk, ub.dat, uninstall oska.lnk, uninstall tahni.lnk, update.exe, webabout.dll, zmscb.dll.
buddy.exe in c:\
bargains.exe, bb_auto_wider.swf, bb_click_wider.swf, bb_welcome.html, bb_welcome1.swf, blank.gif, extmp0.html, icon.gif, logo.gif in c:\temp\
bbchk.exe, bbi8015.exe, bbi8018.exe, bbi8024.exe, uninst.exe in Program Files\bargain buddy\
apuc.dll, bargains.exe, cb.exe in Program Files\bargain buddy\bin2\
apuc.dll, bargains.exe, cb.exe in Program Files\bargain buddy\bin\
apuc.dll in Program Files\bargai~1\bin\
bargainbuddy.exe in Program Files\blue haven media\kazoom\
adp8035.exe, uninstall.exe in Program Files\bullseye network\
adv.exe, adx.exe, bargains.exe in Program Files\bullseye network\bin\
euni_bbi8015.exe, isinstalldonecrazy.exe, kahlisetup_demo.exe, keenpostback.exe, msbb.exe, msbbhook.dll, nlnp49.exe, oskasetup_demo.exe, tahnisetup_demo.exe in Program Files\crazymates\
msbb.exe in Program Files\crazymates\fleok\
b.class, ba.class, bb.class, bc.class, bd.class, be.class, bf.class, bg.class, bh.class in Program Files\ebatesmoemoneymaker\system\code\
nnstp_bbi6009.exe in Program Files\neoaudio\
ahadp.exe, zeta.exe in Windows\
angelex.exe, apuc.dll, bbchk.exe, exclean.exe, exdl.exe, exdl0.exe, exdl1.exe, exul.exe, exul1.exe, javexulm.vxd, msbb.dll, msbb1.dll, mset_bbi8010.dll, mset_bbi80101.dll, mset_bbi80102.dll, mset_bbi80103.dll, msexreg.exe, netut80ex.vxd, q17i9a4j.exe, q17i9a4j.ini, qh4mkbv9.dll in Windows\system32\
apuc.dll in Windows\system\
backup-20040105-225929-414.dll in Windows\temp\
Remove the following directories
Program Files\bargain buddy
Program Files\bullseye network
Program Files\cashback
Program Files\crazymates
Program Files\iemenuextension

Bookmark BargainBuddy page

 Previous Spyware: Remove Barely19 Next Spyware: Remove Barisot