»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 01-31-2004, 12:35 PM   #1 (permalink)
Registered User
 
CubKid's Avatar
 
Join Date: Dec 2001
Posts: 984
CubKid is on a distinguished road
Malware/Spyware problem

Ok, since installing then later removing Freewire, I've had some problems with some sort of malware and/or spyware. Here lately I've been recieving popups, redirects, and its been doing some pretty wierd stuff to webpages. I've run adaware back to back, and spybot on occasion (adaware seems to pick up the objects, spybot dosent), but now Im stumped. It seems like once I close adaware and start browsing again, its fine for a bit, then it comes back just like I'd never removed it. Heres some info on what it finds. What the heck is it and how can I permanently get rid of it? I dont want to reformat, but if it comes down to it, I will.

Quote:

These are taken from adawares search results. They're Registry keys:

Vendor:RemanentBHO
Category:Malware
Object Type:RegKey
Size:-
Location:AppID\BookedSpace.DLL\
Last Activity:1-31-2004
Risk LevelLow
Comment:
Description:No Information Available.

Vendor:RemanentBHO
Category:Malware
Object Type:RegKey
Size:-
Location:BookedSpace.Extension\
Last Activity:1-31-2004
Risk LevelLow
Comment:
Description:No Information Available.

Vendor:RemanentBHO
Category:Malware
Object Type:RegKey
Size:-
Location:SOFTWARE\BookedSpace\
Last Activity:1-31-2004
Risk LevelLow
Comment:
Description:No Information Available.

CubKid is offline   Reply With Quote
Old 01-31-2004, 01:04 PM   #2 (permalink)
Registered User
 
crystaldragon's Avatar
 
Join Date: Oct 2001
Location: Springfield,Mo
Posts: 564
crystaldragon is on a distinguished road
Send a message via Yahoo to crystaldragon
From what I just read it's a type of dialer exploit and seems to be pretty well known for stealth type installs. The latest updates from AdAware and Spybot should take care of it.

If not you'll probably have to manually remove it from the registry.
__________________
Those who cannot remember the past are condemned to repeat it
crystaldragon is offline   Reply With Quote
Old 01-31-2004, 01:12 PM   #3 (permalink)
Registered User
 
CubKid's Avatar
 
Join Date: Dec 2001
Posts: 984
CubKid is on a distinguished road
I've let adaware remove the components, and I've went to the registry and removed them manually. They come back almost as soon as I close the regedit. I'll try the adaware update and see what happens.
CubKid is offline   Reply With Quote
Old 01-31-2004, 01:33 PM   #4 (permalink)
Registered User
 
Jarhed7276's Avatar
 
Join Date: Apr 2003
Location: Texas
Posts: 249
Jarhed7276 is on a distinguished road
If your running XP you need to turn off system restore before running adaware and/or spybot.
Jarhed7276 is offline   Reply With Quote
Old 01-31-2004, 01:48 PM   #5 (permalink)
Registered User
 
CubKid's Avatar
 
Join Date: Dec 2001
Posts: 984
CubKid is on a distinguished road
System restore has been off since I installed (cant stand something taking up space for no reason).

On another note, after I posted the last reply I went and updated adaware. To my suprise instead of the 4or5 objects it found before, it found about 45. One of the files needs to be removed after reboot, but I can handle that. Hopefully this solves my troubles so I dont have to go reformat this thing.
CubKid is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 01:31 PM.