RE: BargainBuddy
From: Malke (malke_at_nospoonnotreally.com)
Date: 03/04/05
- Next message: Bob: "Re: Winhlpp32.exe/ W32.HLLW.Gaobot"
- Previous message: mickeyd: "RE: BargainBuddy"
- In reply to: mickeyd: "RE: BargainBuddy"
- Next in thread: mickeyd: "RE: BargainBuddy"
- Reply: mickeyd: "RE: BargainBuddy"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 03 Mar 2005 18:49:48 -0800
mickeyd wrote:
> Adaware se latest version catches it and says it deleted it, but on
> reboot it's baaack, Spybot detects it and say it cannot delete it, and
> asks to run on startup, I let it and it still says it cannot delete
> the registry keys, if I let the system stay online for a while it will
> then also infect the machine
> with flashenhancer.BHO also. I assume the longer it is on and the
> more
> surfing done it will continue to try to install more crap. MS
> antispyware routinely catches things on bootup and says it stops the
> registry changes but I cannot get rid of the urlcatcher entries in the
> registry.
>
BargainBuddy is a tricky one to remove. Use HijackThis and post your log
in one of the forums below (not here, please). I highly recommend the
forum at AumHa - the regulars are expert and friendly. Please read the
posting FAQ first.
http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Jim
Eshelman
http://aumha.net - forums
http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
forum
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/
Malke
-- MS MVP - Windows Shell/User Elephant Boy Computers www.elephantboycomputers.com "Don't Panic!"
- Next message: Bob: "Re: Winhlpp32.exe/ W32.HLLW.Gaobot"
- Previous message: mickeyd: "RE: BargainBuddy"
- In reply to: mickeyd: "RE: BargainBuddy"
- Next in thread: mickeyd: "RE: BargainBuddy"
- Reply: mickeyd: "RE: BargainBuddy"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|