BearShare Removal: Remove BearShare Easily


* What is BearShare

* Download BearShare Removal Tool

* Remove BearShare manually

* Get Professional Support

* Read Comments


Threat indicator: MEDIUM

Threat's profile

Name of the threat:

Command or file name:

Threat type:

Affected OS:

BearShare

Passe-partout.exe

Badware

Win32 (Windows XP, Vista, Seven, 8)


Bearshare is a file-sharing program that lets you find, download, share, and publish audio and video files. But it can be also classified as "badware", "problemware" or "adware". Its uninstall program doesn't remove all instances of the program, leaving such unwanted items like IE main page, toolbar, default search engine etc. Besides as every P2P software there is a danger people will share viruses under the name of songs or films.

Other known issues are:

Bearshare doesn't allow to download anything from the web. when you try to download something Bearshare pops up and download won't start. Uninstaller says Bearshare is being used and cannot be uninstalled. Removal Tool is developed to remove all instances of Bearshare from your PC. All you need to do after is possibly change some browser settings.


BearShare

BearShare intrusion method

BearShare copies its file(s) to your hard disk. Its typical file name is Passe-partout.exe. Then it creates new startup key with name BearShare and value Passe-partout.exe. You can also find it in your processes list with name Passe-partout.exe or BearShare. Also, it can create folder with name BearShare under C:\Program Files\ or C:\ProgramData.

If you have further questions about BearShare, please call us on the phone below. It is toll free. Or you can use programs to remove BearShare automatically below.


Recommended Remover - Download SpyHunter by Enigma Software Group LLC

Download this advanced removal tool and solve problems with BearShare and Passe-partout.exe (download of fix will start immediately):

Download Spyhunter to remove BearShare and Passe-partout.exe now!

EnigmaSoftware LLC A+ on BBB

* SpyHunter was developed by US-based company EnigmaSoftware and is able to remove BearShare-related issues in automatic mode. Program was tested on Windows XP, Windows Vista, Windows 7 and Windows 8.

Share if this helped!

Features of SpyHunter 4

* Removes all files created by BearShare.

* Removes all registry entries created by BearShare.

* You can activate System and Network Guards and forget about malware.

* Can fix browser problems and protect browser settings.

* Removal is guaranteed - if SpyHunter fails ask for FREE support.

* 24/7 Spyware Helpdesk Support included into the package.


Alternative Solution - Download Stronghold AntiMalware by Security Stronghold LLC

Download antimalware designed specifically to remove threats like BearShare and Passe-partout.exe (download of fix will start immediately):

Download Stronghold AntiMalware for BearShare and Passe-partout.exe now!

Features of Stronghold Antimalware

* Removes all files created by BearShare.

* Removes all registry entries created by BearShare.

* Fixes browser redirection and hijack if needed.

* "Toolbar Remover" tool will help you get rid of unwanted browser extensions.

* Removal is guaranteed - if Stronghold AntiMalware fails ask for FREE support.

* 24/7 Helpdesk Support and 5 hours of Remote Support via GoToAssist included into the package.

Let our support team solve your problem with BearShare and repair BearShare right now!

Call us using the number below and describe your problem with BearShare. Support team will offer you solution in several minutes and give a step-by-step instruction on how to remove BearShare. Trouble-free tech support with over 10 years experience removing malware.

phone banner
Software Industry Professionals Member
Threat's description and solution are developed by Security Stronghold security team.

Here you can also learn:

* Technical details of BearShare threat.

* Manual BearShare removal.

* Download BearShare Removal Tool.


How to remove BearShare manually?

This problem can be solved manually by deleting all registry keys and files connected with BearShare, removing it from starup list and unregistering all corresponding DLLs. Additionally missing DLL's should be restored from distribution in case they are corrupted by BearShare.

To get rid of BearShare, you should:

file logo

1. Kill the following processes and delete the appropriate files:

• bearshare.dat
• bearshare.exe-2a0c795d.pf
• bsinstallit.exe
• bsproinstall.exe-09623c04.pf
• connect.dat
• connect.txt
• console.txt
• glb4.tmp-2f6bfa1a.pf
• gnucache.dat
• hbcache.dat
• hostiles.txt
• library.dat
• memory.txt
• ordinal.txt
• bearshare downloads.lnk
• bearshare.lnk
• bearshare.dll
• bearshare.exe
• bsidle.dll
• freepeers.ini
• webstats.bat
• webstats.ini
• config.bin
• bsproinstall.exe
• bearsh~1.exe

Warning: you should delete only those files which checksums are listed as malicious. There may be valid files with the same names in your system. We recommend you to use BearShare Removal Tool for safe problem solution.

windows folder logo

2. Delete the following malicious folders:

• %programfiles%\bearshare\db\
• %programfiles%\bearshare\installer\
• %programfiles%\bearsh~1\

windows registry logo

3. Delete the following malicious registry entries and\or values:

  • Key: clsid\{9f95f736-0f62-4214-a4b4-caa6738d4c07}
    Value: @
  • Key: gnufile
    Value: @
  • Key: typelib\{905d0df2-3a0a-4d94-853c-54a12a745905}
    Value: @
  • Key: appevents\eventlabels\bearsharechatnotifymsg
    Value: @
  • Key: appevents\schemes\apps\bearshare
    Value: @
  • Key: software\bearshare
    Value: @
  • Key: software\bearshare\installdir
    Value: @
  • Key: software\classes\clsid\{558ec983-bedb-9168-b2de-31dbf0ee543e}
    Value: @
  • Key: software\classes\ed2k
    Value: @
  • Key: software\classes\ed2k\defaulticon
    Value: @
  • Key: software\classes\ed2k\shell\open\command
    Value: @
  • Key: software\classes\ed2k\shell\open\ddeexec
    Value: @
  • Key: software\classes\ed2k\url protocol
    Value: @
  • Key: software\classes\gnu
    Value: @
  • Key: software\classes\gnu\defaulticon
    Value: @
  • Key: software\classes\gnu\shell\open\command
    Value: @
  • Key: software\classes\gnu\url protocol
    Value: @
  • Key: software\classes\gnufile\browserflags
    Value: @
  • Key: software\classes\gnufile\editflags
    Value: @
  • Key: software\classes\gnufile\shell\open\command
    Value: @
  • Key: software\classes\gnutella
    Value: @
  • Key: software\classes\gnutella\defaulticon
    Value: @
  • Key: software\classes\gnutella\shell\open\command
    Value: @
  • Key: software\classes\gnutella\shell\open\ddeexec
    Value: @
  • Key: software\classes\gnutella\url protocol
    Value: @
  • Key: software\licenses\{056b3cf0d9ab991e1}
    Value: @
  • Key: software\licenses\{i56b3cf0d9ab991e1}
    Value: @
  • Key: software\magnet\handlers\bearshare
    Value: @
  • Key: software\magnet\handlers\bearshare\ddeapplication
    Value: @
  • Key: software\magnet\handlers\bearshare\ddetopic
    Value: @
  • Key: software\magnet\handlers\bearshare\defaulticon
    Value: @
  • Key: software\magnet\handlers\bearshare\description
    Value: @
  • Key: software\magnet\handlers\bearshare\shellexecute
    Value: @
  • Key: software\magnet\handlers\bearshare\type\urn:bitprint
    Value: @
  • Key: software\magnet\handlers\bearshare\type\urn:sha1
    Value: @
  • Key: software\microsoft\active setup\installed components\{5f95e1af-2620-4f15-bdf9-7fdce4607e17}
    Value: @
  • Key: software\microsoft\active setup\installed components\{5f95e1af-2620-4f15-bdf9-7fdce4607e17}\componentid
    Value: @
  • Key: software\microsoft\active setup\installed components\{5f95e1af-2620-4f15-bdf9-7fdce4607e17}\isinstalled
    Value: @
  • Key: software\microsoft\active setup\installed components\{5f95e1af-2620-4f15-bdf9-7fdce4607e17}\locale
    Value: @
  • Key: software\microsoft\active setup\installed components\{5f95e1af-2620-4f15-bdf9-7fdce4607e17}\version
    Value: @
  • Key: software\microsoft\windows\currentversion\run\bearshare
    Value: @
  • Key: software\microsoft\windows\currentversion\uninstall\bearshare
    Value: @
  • Key: software\microsoft\windows\currentversion\uninstall\bearshare\displayicon
    Value: @
  • Key: software\microsoft\windows\currentversion\uninstall\bearshare\displayname
    Value: @
  • Key: software\microsoft\windows\currentversion\uninstall\bearshare\displayversion
    Value: @
  • Key: software\microsoft\windows\currentversion\uninstall\bearshare\helplink
    Value: @
  • Key: software\microsoft\windows\currentversion\uninstall\bearshare\publisher
    Value: @
  • Key: software\microsoft\windows\currentversion\uninstall\bearshare\uninstallstring
    Value: @
  • Key: software\microsoft\windows\currentversion\uninstall\bearshare\urlinfoabout
    Value: @
  • Key: .default\appevents\eventlabels\bearsharechatnotifymsg
    Value: @
  • Key: .default\appevents\schemes\apps\bearshare
    Value: @

Warning: if value is listed for some registry entries, you should only clear these values and leave keys with such values untouched. We recommend you to use BearShare Removal Tool for safe problem solution.


4. Manually fix browser problems

BearShare can affect your browsers which results in browser redirection or search hijack. We recommend you to use free option "Reset Browsers" under "Tools" in Stronghold AntiMalware to reset all the browsers at once. Mention that you need to remove all files and kill all processes belonging to BearShare before doing this. To reset your browsers manually and restore your homepage perform the following steps:

internet explorer logo

Internet Explorer

  • If you use Windows XP, click Start, and then click Run. Type the following in the Open box without quotes, and press Enter: "inetcpl.cpl"

  • If you use Windows 7 or Windows Vista, click Start. Type the following in the Search box without quotes, and press Enter: "inetcpl.cpl"

  • Click the Advanced tab

  • In Reset Internet Explorer settings, click Reset. Click Reset in opened window again.

  • Select Delete personal settings checkbox to remove browsing history, search providers, homepage

  • After Internet Explorer finishes resetting, click Close in the Reset Internet Explorer Settings dialog box

Warning: In case this option will not work use free option Reset Browsers under Tools in Stronghold AntiMalware.

google chrome logo

Google Chrome

  • Go to the installation folder of Google Chrome: C:\Users\"your username"\AppData\Local\Google\Chrome\Application\User Data.

  • In the User Data folder, look for a file named as Default and rename it to DefaultBackup.

  • Launch Google Chrome and a new clean Default file will be created.

Warning: This option might not work if in Google Chrome you use online synchronization between PCs. In this case use free option Reset Browsers under Tools in Stronghold AntiMalware.

mozilla firefox logo

Mozilla Firefox

  • Open Firefox

  • Go to Help > Troubleshooting Information in menu.

  • Click the Reset Firefox button.

  • After Firefox is done, it will show a window and create folder on the desktop. Click Finish.

Warning: This option will also clean all your account passwords for all websites. If you don't want it use free option Reset Browsers under Tools in Stronghold AntiMalware.

phone banner pre download

Information provided by: Aleksei Abalmasov

Here are the descriptions of problems connected with BearShare and Passe-partout.exe we received earlier:

Problem Summary: Search.bearshare.com is keeping me from logging onto internet explorer

Internet explorer can not connect to Internet because this search.bearshare.com keeps popping up

Problem was successfully solved. Ticket was closed.

Problem Summary: Unable to transfer photos from camera to computer via usb cable

Since downloading bearshare this morning, I am now unable to transfer files from my camera to my computer. It makes the right noise but does not bring up the programme to import pictures or view pictures etc

Problem was successfully solved. Ticket was closed.

Problem Summary: Will or remove bearshare

I have tried to go into my computer and uninstall bear share but it will not uninstall at all.

Problem was successfully solved. Ticket was closed.

Problem Summary: stop my bareshare

i want to stop this and stop it from comming out of my account4104403722 or 4436003483

Problem was successfully solved. Ticket was closed.

Problem Summary: used bearshare removal tool twice-still on my computer

I paid $19.95 and ran Bearshare removal tool 2 times but it is still there when I attempt to use Firefox as browser.

Problem was successfully solved. Ticket was closed.

Problem Summary: BearShare installation is different language

I can't get the installation page for BearShare in English,mine seems to be Spanish!

Problem was successfully solved. Ticket was closed.

Problem Summary: won't connect

bearshare keeps saying unable to connect with internet, I need to sign in but I've already signed in last week.

Problem was successfully solved. Ticket was closed.

Problem Summary: I can't get rid of search.bearshare.net

Every time I get on google chrome,search.bearshare.net shows up. I've tried uninstalling it from my computer, setting google as my default browser, going to google chromes tools, and then go to the extenstions and disabling the quick access. What should I do?

Problem was successfully solved. Ticket was closed.

Problem Summary: Bearshare charges

Every month I am having withdraws of $10.00 from my bank account to BearShare. I have never agreed to pay $10.00 a month for this site, and I cant seem to find anywhere on the site to cancel this money from coming out. I don't even use BearShare anymore.

Problem was successfully solved. Ticket was closed.

Problem Summary: want to get rid of bareshare

keeps pooping up as search engine on google

Problem was successfully solved. Ticket was closed.

Show more

Today's special: rontokbro

Next threat: Beast »

Learn more about BearShare and Passe-partout.exe »

« Back to catalog

Home | Partners | Shop | Support | Terms of use | Contact Us | Privacy Policy | Sitemap

Copyright © 2014 Security Stronghold. All Rights Reserved.