Wallpaper hijacked!

przero

Platinum Member
Dec 30, 2000
2,060
0
0
One of our machines at work has had the wallpaper hijacked. It's a blank tan page. When you right click in the page, the drop box shows it as a web page. The machine has Bargain Buddy and a URL.Catcher, that no spyware removal tools can fix. I all can find is that explorer.exe was modified, but I can't fix it. Any ideas?
 

amdskip

Lifer
Jan 6, 2001
22,530
13
81
Display properties in control panel -> Desktop -> Customize Desktop -> Web tab

That should get you started. Try installing and running Microsoft AntiSpyware too
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Also, what antivirus software are you guys using? Brand and version, that would be interesting to know.

Big picture: if the machine has BargainBuddy on it, someone's overdue to be shorn of their Administrator/Power-User status. Make 'em a Restricted User.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Nuke the box and reinstall Windows, it'll save you time in the long run. Make sure whoever it was, they never have a Power-User or Administrator-class account again. What antivirus products are you using?

edit: oh, Norton. What version? Can I suggest something different or do you have like a site license for it or something?
 

przero

Platinum Member
Dec 30, 2000
2,060
0
0
Ran adaware, spybot, hijack this, etc. in safe mode. Bargain Buddy won't leave.
 

WiseOldDude

Senior member
Feb 13, 2005
702
0
0
Google remove bargain buddy and you will find many sources spelling out step by step procedures to remove this adware from your system.
 

przero

Platinum Member
Dec 30, 2000
2,060
0
0
I did. No success yet. They all use the premise of deleting the reg keys and they re-appear. And the URL.Catcher reg keys CANNOT be deleted. There are NO processes running other than normal MS processes.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Like I said, blow away the compromised Windows installation. You'd be done by now

If you want to keep fighting, look in your Windows Services for services with Started status that are related to the malware. Also, I suggest uninstalling Norton for now, and install a 30-day trial version of Kaspersky: http://www.kaspersky.com/trials Based on my de-spywaring episode with my little sister's system, it's better than Norton and even McAfee.

Also, take the drive out of the affected system, put it in a different system as a slave, install Kaspersky and Microsoft AntiSpyware, and scan in the other system where the bugs can't fight back. Use Maximum on the on-access and on-demand scanners in Kaspersky, and click "Configure Updater" and set it to use Extended Databases.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |