BookedSpace Removal: Remove BookedSpace Forever
Let our support team solve your problem with BookedSpace and repair BookedSpace right now!
Leave the detailed description of your BookedSpace problem in the form below. Our support team will contact you in several minutes and give a step-by-step instruction on how to fix BookedSpace problem. Please be specific. Do your best describing the problem. This will help us recommend right and complete BookedSpace problem removal solution.
Describe your problem here and we'll contact you in several minutes:
Warning:
1) We hate spam as much as you do. We will not share your email with any third party or publish it anywhere. Your email is used only to contact you and give you BookedSpace removal solution.
2) All fields of this form are obligatory.
Threat's profile
|
Name of the threat: BookedSpace |
| Command or file name: bs5-nt15v.exe |
| Threat type: Badware |
| Affected OS: Win32 (Windows 9x, Windows XP, Windows Vista) |
BookedSpace intrusion method
BookedSpace copies its file(s) to your hard disk. Its typical file name is bs5-nt15v.exe. Then it creates new startup key with name BookedSpace and value bs5-nt15v.exe. You can also find it in your processes list with name bs5-nt15v.exe or BookedSpace.
If you have further questions about BookedSpace, please fill in the form above and we'll contact you shortly.
» Download program to remove BookedSpace (BookedSpace Removal Tool)
Recommended Solution
If you are not sure what to delete, use our award winning program - BookedSpace Removal Tool.
BookedSpace Removal Tool will find and fully remove BookedSpace and all problems associated with BookedSpace virus.
Fast, easy, and handy, BookedSpace Removal Tool protects your computer against BookedSpace that does harm to your computer and breaks your privacy. BookedSpace Removal Tool scans your hard disks and registry and destroys any manifestation of BookedSpace. Standard anti-virus software can do nothing against malicious programs like BookedSpace. Remove BookedSpace straight away!
» Download BookedSpace Removal Tool now for free
How to fix BookedSpace
This problem can be solved manually by deleting all registry keys and files connected with BookedSpace, removing it from starup list and unregistering all corresponding DLLs. Additionally missing DLL's should be restored from distribution in case they are corrupted by BookedSpace.
To get rid of BookedSpace, you should:
1. Kill the following processes and delete the appropriate files:
• bs5-vwqouc.exe
• bsx5.dll
• bxsx5.dll
• bxxs5.dll
• cfgmgr51.dll
• cfgmgr??.dll
• oo4.dll
• rem00001.dll
Warning: you should delete only those files which checksums are listed as malicious. There may be valid files with the same names in your system. We recommend you to use BookedSpace Removal Tool for safe problem solution.
2. Delete the following malicious folders:
• C:\Windows\bsx32\
• C:\Windows\bsx32\
• C:\Windows\bundles\
3. Delete the following malicious registry entries and\or values:
• Key: bookedspace.extension cextension object Value: @
• Key: bookedspace.extension.5 cextension object Value: @
• Key: bookedspace.extension.5\clsid {0019c3e2-dd48-4a6d-abcd-8d32436323d9} Value: @
• Key: bookedspace.extension\curver bookedspace.extension.5 Value: @
• Key: clsid\{0019c3e2-dd48-4a6d-ab2d-8d32436313d9}
• Key: clsid\{0019c3e2-dd48-4a6d-abcd-8d32436313d9}
• Key: clsid\{2b3452c5-1b9a-440f-a203-f6ed0f64c895}
• Key: clsid\{392be62b-e7de-430a-8859-0afe677de6e1}
• Key: clsid\{a85c4a1b-bd36-44e5-a70f-8ec347d9b24f}
• Key: invisiblepop.invisible.1\clsid Value: @
• Key: invisiblepop.invisible\clsid Value: @
• Key: invisiblepop.invisible\curver Value: @
• Key: newfavorite.favoriteman\clsid Value: @
• Key: newfavorite.favoriteman\curver Value: @
• Key: software\microsoft\windows\currentversion\explorer\browser helper objects\{0019c3e2-dd48-4a6d-ab2d-8d32436313d9} Value: @
• Key: software\microsoft\windows\currentversion\explorer\browser helper objects\{0019c3e2-dd48-4a6d-abcd-8d32436313d9} Value: @
• Key: software\microsoft\windows\currentversion\explorer\browser helper objects\{0019c3e2-dd48-4a6d-abcd-8d32436323d9} Value: @
• Key: software\microsoft\windows\currentversion\explorer\browser helper objects\{2b3452c5-1b9a-440f-a203-f6ed0f64c895} Value: @
• Key: software\microsoft\windows\currentversion\explorer\browser helper objects\{392be62b-e7de-430a-8859-0afe677de6e1} Value: @
• Key: software\microsoft\windows\currentversion\explorer\browser helper objects\{a85c4a1b-bd36-44e5-a70f-8ec347d9b24f} Value: @
• Key: software\bookedspace
• Key: software\classes\appid\bookedspace.dll\appid Value: @
• Key: software\classes\clsid\{0019c3e2-dd48-4a6d-ab2d-8d32436313d9}
• Key: software\classes\clsid\{0019c3e2-dd48-4a6d-abcd-8d32436313d9}
• Key: SOFTWARE\Classes\CLSID\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} Value: AppID
• Key: software\classes\clsid\{0019c3e2-dd48-4a6d-abcd-8d32436323d9}\appid Value: @
• Key: software\classes\clsid\{2b3452c5-1b9a-440f-a203-f6ed0f64c895}
• Key: software\classes\clsid\{392be62b-e7de-430a-8859-0afe677de6e1}
• Key: SOFTWARE\Classes\CLSID\{669695BC-A811-4A9D-8CDF-BA8C795F261C}
• Key: software\classes\clsid\{a85c4a1b-bd36-44e5-a70f-8ec347d9b24f}
• Key: software\classes\clsid\{ebbd88e5-c372-469d-b4c5-1fe00352ab9b}
• Key: software\classes\interface\{05080e6b-a88a-4cfd-8c3d-9b2557670b6e}
• Key: SOFTWARE\Classes\Interface\{38493F7F-2922-4C6C-9A9A-8DA2C940D0EE}
• Key: SOFTWARE\Classes\KBBar.KBBarBand\CLSID
• Key: software\classes\typelib\{0dc5cd7c-f653-4417-aa43-d457be3a9622}
• Key: software\classes\typelib\{690bccb4-6b83-4203-ae77-038c116594ec}
• Key: software\classes\typelib\{dffe1ccf-e1e8-4470-9962-73277cc2c898}
• Key: software\classes\typelib\{eb5e961f-f519-303c-9744-0d4376b1b0b5}
• Key: software\microsoft\code store database\distribution units\{ddffa75a-e81d-4454-89fc-b9fd0631e726}\installer Value: @
• Key: software\microsoft\code store database\distribution units\{ddffa75a-e81d-4454-89fc-b9fd0631e726}\systemcomponent Value: @
• Key: software\microsoft\code store database\distribution units\{ebbd88e5-c372-469d-b4c5-1fe00352ab9b}\installer Value: @
• Key: software\microsoft\code store database\distribution units\{ebbd88e5-c372-469d-b4c5-1fe00352ab9b}\systemcomponent Value: @
• Key: software\microsoft\windows nt\currentversion\winlogon\notify\wow\asynchronous Value: @
• Key: software\microsoft\windows nt\currentversion\winlogon\notify\wow\dllname Value: @
• Key: software\microsoft\windows nt\currentversion\winlogon\notify\wow\id Value: @
• Key: software\microsoft\windows nt\currentversion\winlogon\notify\wow\idex Value: @
• Key: software\microsoft\windows nt\currentversion\winlogon\notify\wow\impersonate Value: @
• Key: software\microsoft\windows nt\currentversion\winlogon\notify\wow\logoff Value: @
• Key: software\microsoft\windows nt\currentversion\winlogon\notify\wow\logon Value: @
• Key: software\microsoft\windows nt\currentversion\winlogon\notify\wow\version Value: @
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0019c3e2-dd48-4a6d-ab2d-8d32436313d9}
• Key: software\microsoft\windows\currentversion\explorer\browser helper objects\{0019c3e2-dd48-4a6d-abcd-8d32436313d9} Value: @
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9}
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2b3452c5-1b9a-440f-a203-f6ed0f64c895}
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{392be62b-e7de-430a-8859-0afe677de6e1}
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a85c4a1b-bd36-44e5-a70f-8ec347d9b24f}
• Key: software\microsoft\windows\currentversion\internet settings\user agent\post platform\{75abd9b6-028e-4117-a1dd-b4839f1e0a1e} Value: @
• Key: software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/ax.dll\.owner Value: @
• Key: software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/ax.dll\{ddffa75a-e81d-4454-89fc-b9fd0631e726} Value: @
• Key: software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/mmview_ouch.dll\.owner Value: @
• Key: software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/mmview_ouch.dll\{ebbd88e5-c372-469d-b4c5-1fe00352ab9b} Value: @
• Key: software\microsoft\windows\currentversion\run bxxs5 Value: @
• Key: software\microsoft\windows\currentversion\run\bookedspace Value: @
• Key: software\microsoft\windows\currentversion\run\bsx3 Value: @
• Key: software\microsoft\windows\currentversion\run\bxss5 Value: @
• Key: software\microsoft\windows\currentversion\run\bxsx5 Value: @
• Key: software\microsoft\windows\currentversion\shell extensions\approved\{e8ed4fff-8bf1-4068-b378-2caff1540f76}
• Key: CLSID\{C68AE9C0-0909-4DDC-B661-C1AFB9F59898} Value: AppID
• Key: AppID\{5CD19420-B328-47D5-A55F-1C07638EFDF8}
• Key: BookedSpace.Extension.3
• Key: Interface\{05080E6B-A88A-4CFD-8C3D-982557670B6E}
• Key: Interface\{56EBFFE6-9557-46C2-A322-DB1DF5CAF199}
• Key: software/bookedspace
• Key: SOFTWARE\Classes\AppID\{0DC5CD7C-F653-4417-AA43-D457BE3A9622}
• Key: SOFTWARE\Classes\AppID\BookedSpace.DLL Value: AppID
• Key: SOFTWARE\Classes\BookedSpace.Extension
• Key: SOFTWARE\Classes\BookedSpace.Extension.5
• Key: software\classes\interface\{4534cd6b-59d6-43fd-864b-06a0d843444a}
• Key: software\classes\invisiblepop.invisible
• Key: software\classes\invisiblepop.invisible.1
• Key: software\classes\localnrddll.localnrddllobj.1
• Key: TypeLib\{5CD19420-B328-47D5-A55F-1C07638EFDF8}
• Key: CLSID\{C68AE9C0-0909-4DDC-B661-C1AFB9F59898}\InprocServer32 Value: ThreadingModel
• Key: CLSID\{C68AE9C0-0909-4DDC-B661-C1AFB9F59898}\TypeLib
• Key: TypeLib\{90A52F08-64AC-4DC6-9D7D-451667029898}\1.0
• Key: TypeLib\{90A52F08-64AC-4DC6-9D7D-451667029898}\1.0\FLAGS
• Key: TypeLib\{90A52F08-64AC-4DC6-9D7D-451667029898}\1.0\0\win32
• Key: TypeLib\{90A52F08-64AC-4DC6-9D7D-451667029898}\1.0\HELPDIR
• Key: SOFTWARE\Classes\AppID\{27A1CA0D-78CE-4e23-8A89-2C95C15954B3}
• Key: SOFTWARE\Classes\BookedSpace.Extension.5\CLSID
• Key: SOFTWARE\Classes\BookedSpace.Extension\CLSID
• Key: SOFTWARE\Classes\BookedSpace.Extension\CurVer
• Key: SOFTWARE\Classes\CLSID\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9}\ProgID
• Key: SOFTWARE\Classes\CLSID\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9}\VersionIndependentProgID
• Key: SOFTWARE\Classes\CLSID\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9}\Programmable
• Key: SOFTWARE\Classes\CLSID\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9}\InprocServer32 Value: ThreadingModel
• Key: SOFTWARE\Classes\CLSID\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9}\TypeLib
• Key: SOFTWARE\Classes\TypeLib\{0DC5CD7C-F653-4417-AA43-D457BE3A9622}\1.0
• Key: SOFTWARE\Classes\TypeLib\{0DC5CD7C-F653-4417-AA43-D457BE3A9622}\1.0\FLAGS
• Key: SOFTWARE\Classes\TypeLib\{0DC5CD7C-F653-4417-AA43-D457BE3A9622}\1.0\0
• Key: SOFTWARE\Classes\TypeLib\{0DC5CD7C-F653-4417-AA43-D457BE3A9622}\1.0\0\win32
• Key: SOFTWARE\Classes\TypeLib\{0DC5CD7C-F653-4417-AA43-D457BE3A9622}\1.0\HELPDIR
• Key: SOFTWARE\Classes\Interface\{05080E6B-A88A-4CFD-8C3D-9B2557670B6E}\ProxyStubClsid
• Key: SOFTWARE\Classes\Interface\{05080E6B-A88A-4CFD-8C3D-9B2557670B6E}\ProxyStubClsid32
• Key: SOFTWARE\Classes\Interface\{05080E6B-A88A-4CFD-8C3D-9B2557670B6E}\TypeLib Value: Version
• Key: KBBar.KBBarBand.1
• Key: SOFTWARE\Classes\KBBar.KBBarBand.1\CLSID
• Key: KBBar.KBBarBand
• Key: SOFTWARE\Classes\KBBar.KBBarBand
• Key: SOFTWARE\Classes\KBBar.KBBarBand\CurVer
• Key: SOFTWARE\Classes\CLSID\{669695BC-A811-4A9D-8CDF-BA8C795F261C}\ProgID
• Key: SOFTWARE\Classes\CLSID\{669695BC-A811-4A9D-8CDF-BA8C795F261C}\VersionIndependentProgID
• Key: SOFTWARE\Classes\CLSID\{669695BC-A811-4A9D-8CDF-BA8C795F261C}\InprocServer32 Value: ThreadingModel
• Key: SOFTWARE\Classes\CLSID\{669695BC-A811-4A9D-8CDF-BA8C795F261C}\TypeLib
• Key: SOFTWARE\Classes\TypeLib\{3277CD27-4001-4EF8-9D96-C6CA745AC2F9}\1.0
• Key: SOFTWARE\Classes\TypeLib\{3277CD27-4001-4EF8-9D96-C6CA745AC2F9}\1.0\FLAGS
• Key: SOFTWARE\Classes\TypeLib\{3277CD27-4001-4EF8-9D96-C6CA745AC2F9}\1.0\0
• Key: SOFTWARE\Classes\TypeLib\{3277CD27-4001-4EF8-9D96-C6CA745AC2F9}\1.0\0\win32
• Key: SOFTWARE\Classes\TypeLib\{3277CD27-4001-4EF8-9D96-C6CA745AC2F9}\1.0\HELPDIR
• Key: SOFTWARE\Classes\Interface\{38493F7F-2922-4C6C-9A9A-8DA2C940D0EE}\ProxyStubClsid
• Key: SOFTWARE\Classes\Interface\{38493F7F-2922-4C6C-9A9A-8DA2C940D0EE}\ProxyStubClsid32
• Key: SOFTWARE\Classes\Interface\{38493F7F-2922-4C6C-9A9A-8DA2C940D0EE}\TypeLib Value: Version
• Key: SOFTWARE\Classes\CFG32S.Search.1
• Key: SOFTWARE\Classes\CFG32S.Search.1\CLSID
• Key: SOFTWARE\Classes\CFG32S.Search
• Key: SOFTWARE\Classes\CFG32S.Search\CLSID
• Key: SOFTWARE\Classes\CFG32S.Search\CurVer
• Key: SOFTWARE\Classes\CLSID\{7564B020-44E8-4c9b-A887-C6EC41AC67DA} Value: AppID
• Key: SOFTWARE\Classes\CLSID\{7564B020-44E8-4c9b-A887-C6EC41AC67DA}\ProgID
• Key: SOFTWARE\Classes\CLSID\{7564B020-44E8-4c9b-A887-C6EC41AC67DA}\VersionIndependentProgID
• Key: SOFTWARE\Classes\CLSID\{7564B020-44E8-4c9b-A887-C6EC41AC67DA}\Programmable
• Key: SOFTWARE\Classes\CLSID\{7564B020-44E8-4c9b-A887-C6EC41AC67DA}\InprocServer32 Value: ThreadingModel
• Key: SOFTWARE\Classes\CLSID\{7564B020-44E8-4c9b-A887-C6EC41AC67DA}\TypeLib
• Key: SOFTWARE\Classes\TypeLib\{27A1CA0D-78CE-4E23-8A89-2C95C15954B3}
• Key: SOFTWARE\Classes\TypeLib\{27A1CA0D-78CE-4E23-8A89-2C95C15954B3}\1.0
• Key: SOFTWARE\Classes\TypeLib\{27A1CA0D-78CE-4E23-8A89-2C95C15954B3}\1.0\FLAGS
• Key: SOFTWARE\Classes\TypeLib\{27A1CA0D-78CE-4E23-8A89-2C95C15954B3}\1.0\0
• Key: SOFTWARE\Classes\TypeLib\{27A1CA0D-78CE-4E23-8A89-2C95C15954B3}\1.0\0\win32
• Key: SOFTWARE\Classes\TypeLib\{27A1CA0D-78CE-4E23-8A89-2C95C15954B3}\1.0\HELPDIR
• Key: SOFTWARE\Classes\Interface\{41E74C20-8BBD-4B15-8C24-95BAC7B3BAC1}
• Key: SOFTWARE\Classes\Interface\{41E74C20-8BBD-4B15-8C24-95BAC7B3BAC1}\ProxyStubClsid
• Key: SOFTWARE\Classes\Interface\{41E74C20-8BBD-4B15-8C24-95BAC7B3BAC1}\ProxyStubClsid32
• Key: SOFTWARE\Classes\Interface\{41E74C20-8BBD-4B15-8C24-95BAC7B3BAC1}\TypeLib Value: Version
• Key: SOFTWARE\Classes\AppID\CFG32S.DLL Value: AppID
• Key: Software\zAbstract Value: r
• Key: SOFTWARE\zAbstract Value: Unique
• Key: SOFTWARE\zAbstract Value: Stamp-Spawn
• Key: SOFTWARE\zAbstract Value: Stamp-Update
• Key: SOFTWARE\zAbstract Value: Count-Update
• Key: SOFTWARE\zAbstract Value: Delay-Update
• Key: SOFTWARE\zAbstract Value: Delay-SPZ5
• Key: SOFTWARE\zAbstract Value: Delay-ASI5AFF
• Key: SOFTWARE\zAbstract Value: Delay-MYGEEK3
• Key: SOFTWARE\zAbstract Value: Delay-ASI_SPEC
• Key: SOFTWARE\zAbstract Value: Campaigns
• Key: SOFTWARE\zAbstract Value: Receipt-MYGEEK3
• Key: SOFTWARE\zAbstract Value: Data-MYGEEK3
• Key: SOFTWARE\zAbstract Value: Receipt-ASI_SPEC
• Key: SOFTWARE\zAbstract Value: Data-ASI_SPEC
• Key: SOFTWARE\zAbstract Value: Receipt-UPG82
• Key: SOFTWARE\zAbstract Value: Parent
• Key: SOFTWARE\Microsoft\Internet Explorer\Toolbar Value: {669695BC-A811-4A9D-8CDF-BA8C795F261C}
• Key: SOFTWARE\zAbstract Value: r
• Key: SOFTWARE\zAbstract Value: App1
• Key: SOFTWARE\zAbstract Value: App3
• Key: SOFTWARE\zAbstract Value: App4
• Key: SOFTWARE\zAbstract Value: App5
• Key: SOFTWARE\zAbstract Value: App4
• Key: SOFTWARE\zAbstract Value: App1
• Key: SOFTWARE\zAbstract Value: App2
• Key: SOFTWARE\zAbstract Value: App3
Warning: If value is listed for some registry entries, you should only clear these values and leave keys with such values untouched. We recommend you to use BookedSpace Removal Tool for safe problem solution.
Next threat: BookmarkExpress »
Learn more about BookedSpace and bs5-nt15v.exe »
« Back to catalog
Solution: 869
|