Bargain Buddy

By CagedTech in Browser Helper Object

Threat Scorecard

Popularity Rank: 17,965
Threat Level: 30 % (Normal)
Infected Computers: 3,872
First Seen: July 24, 2009
Last Seen: April 12, 2026
OS(es) Affected: Windows

File System Details

Bargain Buddy may create the following file(s):
# File Name MD5 Detections
1. ACSTRAY.EXE 9f3d7c8d8d8f794c1115b3170926a0e0 2,862
2. adx.exe 812def7df63838ed0be0a2b6a3fbcdb0 0
3. adv.exe 56979b69b9ff449b792e53f7e956cecc 0
4. exdXX.exe 9b571f4eb622096d7989dff203b0bbe1 0
More files

Registry Details

Bargain Buddy may create the following registry entry or registry entries:
CLSID
{F4E04583-354E-4076-BE7D-ED6A80FD66DA}
File name without path
adp.exe
adv.exe
adx.exe
bargains.exe
bb.exe
bbchk.exe
cc_versn.dll
exul.exe
Run keys
Bargains

Analysis Report

General information

Family Name: Adware.BargainBuddy
Signature status: Root Not Trusted

Known Samples

MD5: fade0a28fbf5b8b2aece75a8642e8c23
SHA1: 8a708dfc009b0218259164d3c1261a3cb625adc6
SHA256: A9D8C76BAF2E7CD15D874C9C22E4636B95F8D1DF29E421D86C7879DA3F7EA2E6
File Size: 104.97 KB, 104968 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Digital Signatures

Signer Root Status
Outblaze Ltd. Thawte Premium Server CA Root Not Trusted

File Traits

  • x86

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • ReadProcessMemory
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState

Related Posts

Trending

Most Viewed

Loading...