Threat Database Adware Adware.eXact.BargainBuddy

Adware.eXact.BargainBuddy

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 21,228
Threat Level: 20 % (Normal)
Infected Computers: 5
First Seen: July 24, 2009
Last Seen: June 19, 2026
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Symantec Adware.Bullseye
Sunbelt eXact.Downloader
Sophos BargainBuddy
Prevx1 Cool.Web.Search.HOMESEARCH
Panda Adware/Exact.BargainBuddy
Ikarus not-a-virus:AdWare.Win32.BargainBuddy.n
CAT-QuickHeal AdWare.BargainBuddy.j (Not a Virus)
BitDefender Application.Bargainbuddy.BC
AVG Adware Generic.CRI
AntiVir ADSPY/BargainBudd.n
Symantec Adware.NaviSearch
Sophos eXactAdvertising
Prevx1 Generic.Malware
Panda Adware/Exact.SearchBar
Microsoft Adware:Win32/eXact.BargainBuddy

File System Details

Adware.eXact.BargainBuddy may create the following file(s):
# File Name MD5 Detections
1. msbe.dll c0df070ea8ee15c03552de3e25756715 1
2. nvms.dll 02d5e94c3c02c86dfc00b5ca0d905731 0

Analysis Report

General information

Family Name: Adware.BargainBuddy
Signature status: Root Not Trusted

Known Samples

MD5: fade0a28fbf5b8b2aece75a8642e8c23
SHA1: 8a708dfc009b0218259164d3c1261a3cb625adc6
SHA256: A9D8C76BAF2E7CD15D874C9C22E4636B95F8D1DF29E421D86C7879DA3F7EA2E6
File Size: 104.97 KB, 104968 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Digital Signatures

Signer Root Status
Outblaze Ltd. Thawte Premium Server CA Root Not Trusted

File Traits

  • x86

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • ReadProcessMemory
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState

Related Posts

Trending

Most Viewed

Loading...