Threat type: Trojan -
Threat risk: Severe Risk
Severe risk threats are typically installed without user interaction through security exploits, and may allow an attacker to remotely control the infected machine. Such threats may allow the attacker to install additional malware and use the compromised machine to participate in denial of service attacks, spamming, and bot nets, or to transmit sensitive data to a remote server. The malware may be cloaked and not visible to the user. These threats severely compromise the system by lowering security settings, installing “backdoors,” infecting system files, or spreading to other networked machines.
Description: eXact.ISEXEng is a Trojan Windows service installed by BargainBuddy and CashBack.
Author: eUniverse.com Inc/eXact Advertising, LLChttp://research.sunbelt-software.com/threa...&threatid=15030
This is an undesirable program.
This file has been identified as a program that is undesirable to have running on your computer. This consists of programs that are misleading, harmful, or undesirable.
If the description states that it is a piece of malware, you should immediately run an antivirus and antispyware program. If that does not help, feel free to ask us for assistance in the forums.
Command: Unknown at this time.
Description: This file is associated with adware. It is known to download and install other spware and adware on to your computer. This service should definitely be stopped and disabled.
File Location: %System%
Startup Type: This startup entry is installed as a Windows NT, 2000, 2003, or XP service.
Service Name: ISEXEng
Service Display Name: ISEXEng
HijackThis Category: O23 Entry
Your computer seems to be infected with known malware.
The best thing to do is download, install, update and run the following two applications (which you need to have on your computer anyway)
Ad-Aware SE Personal - freeware http://www.lavasoft.com/
Click on Adaware SE Personal in “Products” on the left side of the page
Or it may be easier to find it here:http://fileforum.betanews.com/detail/Adawa...nal/965718306/1
Spybot S&D: http://www.safer-networking.org/en/index.html
Be sure to enable “Teatimer” which gives you realtime protection against malware invasion. (absolutely necessary)
Run them using safe mode and let them fix what they find.
Following that that I suggest you post a “HijackThis” log for expert assistance with your problem.
Read the pinned post in our “HijackThis” forum, herehttp://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/ Carefully read and follow all directions explicitly.
Following instructions run a log, and post it in following HJT forum, at this link
. Include a brief description of your computer (ie, processor, amount of RAM, brand or motherboard, etc, and the problem you are experiencing.)http://www.bleepingcomputer.com/forums/posthjtlog.htmlUnless you are expert at editing the registry, Do not as yet attempt to fix anything by yourself using Hijack This as even what may seem to be a small mistake can render your op system inoperable.
Some files when in one folder may be fine while in another may be malware.
A member of our HJT Team will analyze your log, make recommendations and offer assistance.
It may take a period of time to get a response to the log you posted because the members of our HJT Team are kept very busy. Please
be patient as this team is manned by volunteers. They will help you in order received as soon as possible.NOTE
Once you have posted your HJT log, please DO NOT make any additional posts in the HJT forum thread you created until you get a response from a member of our HJT expert team, and do not make any changes to your system (changes, including any attempted repairs, will make it different than displayed in the log you posted and therefore make your log inaccurate).
The first criteria they have when looking for logs that need replies are posts showing 0 replies
. If you make an additional post, it will show as having 1 reply
A team member, looking for a new log to work on might well assume another HJT Team member is already assisting you and might not open the thread to respond.
So, make your post and wait for a response from a team member.