spyware removal instructions

BookedSpace removal

Spyware BookedSpace Information
Name: BookedSpace
Category: Browser Helper Object
Date: 2004-12-28
Dangerous: Yes
BookedSpace is one of Browser Helper Object spywares.
Finding it on your computer means that your computer is infected with Browser Helper Object and crucial data could be endangered or even lost.
This Browser Helper Object is also known as:
Adware/BookedSpace - named by Panda.
BookedSpace - Remanent - named by a.

>> Delete BookedSpace automatically - Download Spyware Doctor

BookedSpace Removal Instructions
Unregister the following DLLs and reboot
eabh.dll.
bs2.dll, bs3.dll, bsx5.dll, bxxs5.dll, oo4.dll in Windows\
acd.dll, anaamon.dll, bs2.dll, bs3.dll, bsx5.dll, bxsx5.dll, bxxs5.dll, oo4.dll, rem00001.dll in Windows\system32\
bs2.dll, bs3.dll, bsx5.dll, bxsx5.dll, bxxs5.dll, oo4.dll, rem00001.dll in Windows\system\
bxxs5.dll in Windows\windows\
Delete these registry entries
HKEY_CLASSES_ROOT\appid\bookedspace.dll appid {0dc5cd7c-f653-4417-aa43-d457be3a9622}
HKEY_CLASSES_ROOT\bookedspace.extension
HKEY_CLASSES_ROOT\bookedspace.extension cextension object
HKEY_CLASSES_ROOT\bookedspace.extension.5
HKEY_CLASSES_ROOT\bookedspace.extension.5 cextension object
HKEY_CLASSES_ROOT\bookedspace.extension.5\clsid {0019c3e2-dd48-4a6d-abcd-8d32436323d9}
HKEY_CLASSES_ROOT\bookedspace.extension\clsid
HKEY_CLASSES_ROOT\bookedspace.extension\curver
HKEY_CLASSES_ROOT\bookedspace.extension\curver bookedspace.extension.5
HKEY_CLASSES_ROOT\clsid\{0019c3e2-dd48-4a6d-ab2d-8d32436313d9}
HKEY_CLASSES_ROOT\clsid\{0019c3e2-dd48-4a6d-abcd-8d32436313d9}
HKEY_CLASSES_ROOT\clsid\{2b3452c5-1b9a-440f-a203-f6ed0f64c895}
HKEY_CLASSES_ROOT\clsid\{392be62b-e7de-430a-8859-0afe677de6e1}
HKEY_CLASSES_ROOT\clsid\{a85c4a1b-bd36-44e5-a70f-8ec347d9b24f}
HKEY_CLASSES_ROOT\invisiblepop.invisible.1\clsid
HKEY_CLASSES_ROOT\invisiblepop.invisible\clsid
HKEY_CLASSES_ROOT\invisiblepop.invisible\curver
HKEY_CLASSES_ROOT\localnrddll.localnrddllobj.1
HKEY_CLASSES_ROOT\newfavorite.favoriteman
HKEY_CLASSES_ROOT\newfavorite.favoriteman\clsid
HKEY_CLASSES_ROOT\newfavorite.favoriteman\curver
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{0019c3e2-dd48-4a6d-ab2d-8d32436313d9}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{0019c3e2-dd48-4a6d-abcd-8d32436313d9}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{0019c3e2-dd48-4a6d-abcd-8d32436323d9}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{2b3452c5-1b9a-440f-a203-f6ed0f64c895}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{392be62b-e7de-430a-8859-0afe677de6e1}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{a85c4a1b-bd36-44e5-a70f-8ec347d9b24f}
HKEY_LOCAL_MACHINE\software\bookedspace
HKEY_LOCAL_MACHINE\software\bookedspace\adware
HKEY_LOCAL_MACHINE\software\classes\appid\bookedspace.dll\appid
HKEY_LOCAL_MACHINE\software\classes\clsid\{0019c3e2-dd48-4a6d-ab2d-8d32436313d9}
HKEY_LOCAL_MACHINE\software\classes\clsid\{0019c3e2-dd48-4a6d-abcd-8d32436313d9}
HKEY_LOCAL_MACHINE\software\classes\clsid\{0019c3e2-dd48-4a6d-abcd-8d32436323d9}
HKEY_LOCAL_MACHINE\software\classes\clsid\{0019c3e2-dd48-4a6d-abcd-8d32436323d9}\appid
HKEY_LOCAL_MACHINE\software\classes\clsid\{00320615-b6c2-40a6-8f99-f1c52d674fad}
HKEY_LOCAL_MACHINE\software\classes\clsid\{2b3452c5-1b9a-440f-a203-f6ed0f64c895}
HKEY_LOCAL_MACHINE\software\classes\clsid\{392be62b-e7de-430a-8859-0afe677de6e1}
HKEY_LOCAL_MACHINE\software\classes\clsid\{a85c4a1b-bd36-44e5-a70f-8ec347d9b24f}
HKEY_LOCAL_MACHINE\software\classes\clsid\{ebbd88e5-c372-469d-b4c5-1fe00352ab9b}
HKEY_LOCAL_MACHINE\software\classes\interface\{05080e6b-a88a-4cfd-8c3d-9b2557670b6e}
HKEY_LOCAL_MACHINE\software\classes\typelib\{0dc5cd7c-f653-4417-aa43-d457be3a9622}
HKEY_LOCAL_MACHINE\software\classes\typelib\{690bccb4-6b83-4203-ae77-038c116594ec}
HKEY_LOCAL_MACHINE\software\classes\typelib\{dffe1ccf-e1e8-4470-9962-73277cc2c898}
HKEY_LOCAL_MACHINE\software\classes\typelib\{eb5e961f-f519-303c-9744-0d4376b1b0b5}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{ddffa75a-e81d-4454-89fc-b9fd0631e726}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{ddffa75a-e81d-4454-89fc-b9fd0631e726}\installer
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{ddffa75a-e81d-4454-89fc-b9fd0631e726}\systemcomponent
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{ebbd88e5-c372-469d-b4c5-1fe00352ab9b}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{ebbd88e5-c372-469d-b4c5-1fe00352ab9b}\installer
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{ebbd88e5-c372-469d-b4c5-1fe00352ab9b}\systemcomponent
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wow\asynchronous
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wow\dllname
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wow\id
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wow\idex
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wow\impersonate
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wow\logoff
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wow\logon
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wow\version
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0019c3e2-dd48-4a6d-ab2d-8d32436313d9}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0019c3e2-dd48-4a6d-abcd-8d32436313d9}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0019c3e2-dd48-4a6d-abcd-8d32436323d9}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2b3452c5-1b9a-440f-a203-f6ed0f64c895}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{392be62b-e7de-430a-8859-0afe677de6e1}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{a85c4a1b-bd36-44e5-a70f-8ec347d9b24f}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet settings\user agent\post platform\{75abd9b6-028e-4117-a1dd-b4839f1e0a1e}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/ax.dll\.owner
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/ax.dll\{ddffa75a-e81d-4454-89fc-b9fd0631e726}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/mmview_ouch.dll\.owner
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/mmview_ouch.dll\{ebbd88e5-c372-469d-b4c5-1fe00352ab9b}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run bxxs5
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\bookedspace
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\bsx3
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\bxss5
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\bxsx5
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shell extensions\approved\{e8ed4fff-8bf1-4068-b378-2caff1540f76}
HKEY_LOCAL_MACHINE\software\remanent
Remove the following files
basis.dst, basis.kwd, eabh.dll, saisau.dat.
remove spyware.url in Desktop\
bs2.dll, bs3.dll, bsx5.dll, bxxs5.dll, oo4.dll in Windows\
acd.dll, anaamon.dll, bs2.dll, bs3.dll, bsx5.dll, bxsx5.dll, bxxs5.dll, oo4.dll, rem00001.dll in Windows\system32\
bs2.dll, bs3.dll, bsx5.dll, bxsx5.dll, bxxs5.dll, oo4.dll, rem00001.dll in Windows\system\
bsx32.ini, bxxs5.dll in Windows\windows\
Remove the following directories
Favorites\games and prizes
Windows\bsx32

Bookmark BookedSpace page

 Previous Spyware: Remove Boojum.334.A Next Spyware: Remove BookedSpace.BS2