Content

Adware-BB

Type
Program
SubType
Adware
Discovery Date
10/27/2003
Length
varies
Minimum DAT
4300 (10/29/2003)
Updated DAT
5586 (04/16/2009)
Minimum Engine
5.1.00
Description Added
12/11/2003
Description Modified
12/11/2003 6:18 AM (PT)
Risk Assessment
Corporate User
N/A
Home User
N/A

Tab Navigation

Characteristics

This is not a virus or trojan. It is a direct-marketing adware application. This application generates extra pop-up ads while using Internet Explorer.

This kind of application generally comes bundled with another program, which usually discloses the fact that it is ad-supported.  Users agree to have the Adware installed in the license agreement, although they may not realise at first that this file was packaged with the product they installed.

This adware uses 2 main components which are:

  • Bargains.exe (356,428 bytes) which downloads advertisements and displays them.
  • Apuc.dll  (114,762 bytes) which keeps track of the sites visited using a Browser Helper Object and enables the adware to display better targeted ads.

Upon execution, the application installs itself as bargains.exe into a newly created folder called Bargain Buddy in C:\

The following Registry keys are added:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
"Bargains"

HKEY_LOCAL_MACHINE\Software\Bargains  

Users who would like to check for the presence of potentially unwanted programs on their system should run the command line scanner with the /PROGRAM switch.
Please note that VirusScan 7, and higher, has an option that enables users to detect this kind of program automatically (see below).

Symptoms

Presence of the files and registry keys listed above, and constant pop-up windows while using the Internet.

Method of Infection

N/A This is not a virus or trojan

Variants

Variants

    N/A

All Information

Overview -

This is a Potentially Unwanted Program (PUP) detection. It is not a virus or trojan. PUPs are any piece of software which a reasonably security-or privacy-minded computer user may want to be informed of.

Characteristics

Characteristics -

This is not a virus or trojan. It is a direct-marketing adware application. This application generates extra pop-up ads while using Internet Explorer.

This kind of application generally comes bundled with another program, which usually discloses the fact that it is ad-supported.  Users agree to have the Adware installed in the license agreement, although they may not realise at first that this file was packaged with the product they installed.

This adware uses 2 main components which are:

  • Bargains.exe (356,428 bytes) which downloads advertisements and displays them.
  • Apuc.dll  (114,762 bytes) which keeps track of the sites visited using a Browser Helper Object and enables the adware to display better targeted ads.

Upon execution, the application installs itself as bargains.exe into a newly created folder called Bargain Buddy in C:\

The following Registry keys are added:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
"Bargains"

HKEY_LOCAL_MACHINE\Software\Bargains  

Users who would like to check for the presence of potentially unwanted programs on their system should run the command line scanner with the /PROGRAM switch.
Please note that VirusScan 7, and higher, has an option that enables users to detect this kind of program automatically (see below).

Symptoms

Symptoms -

Presence of the files and registry keys listed above, and constant pop-up windows while using the Internet.

Method of Infection

Method of Infection -

N/A This is not a virus or trojan

Removal -

Removal -

Instructions on Enabling/Disabling Detection and Removal of Potentially Unwanted Programs

Variants

Variants -

    N/A