REstoring Address Bar search after Bs3.dll/Bsx5.dll "infection/deletion"

Z

Zonky

As documented here:

http://www.allexperts.com/previousqv.asp?QuestionID=3246967

(specifically)

Both bs3.dll and bsx5.dll are part of parasite spyware

What it does to your computer:
It allows installation of a file(s) that tracks your web browsing. bs stands for
BookedSpace.
BookedSpace is an Internet Explorer Browser Helper Object used to show advertising.

bs3.dll and bsx5.dll are both variants of spyware orginal BookedSpace/Remanent, an early
variant (around July 2003) with filename rem00001.dll, controlling server 66.225.192.199.
These are both newer revisions with filename bs2.dll or bs3.dll, or bsx5.dll controlling
server www.bookedspace.com.
It is silently installed by MThree MP3 to WAV converter. Origin currently unknown.

bs3.dll or bsx5.dll = BookedSpace can contact its controlling server when a new page is
visited, which may direct it to open pop-up ads.
When the controlling server is contacted, the URL of the current page is passed along with a
user ID for tracking purposes.
It can download and install third-party software as directed by its controlling server.
BookedSpace/BS2 has been seen to install the BargainBuddy, nCase and eBates parasites.

Stability problem = Seems to stop IE address bar searches from working.

<end quote>

These dll's have been removed from my system (windows XP Home). Is there any way to restore
the Address bar searching (i.e, the settings in
HKEY_USERS\Software\Microsoft\Internet Explorer\SearchUrl\ are present as is before, but
when for e.g i type g searchterm, the page does not load it loads http:///g searchterm and
cannot find the page....
 
M

Mike Burgess

Zonky,
http:/// = CWS.Svcinit (coolwebsearch trojan)

How to remove Coolwebsearch and affiliates
http://mvps.org/winhelp2002/unwanted.htm#Coolwebsearch

Note: this type hijack indicates an unpatched machine, that is lacking
in "Defense". Please visit Windows Update to avoid these exploits.
____________________________________________________________
Mike Burgess [MVP Windows Shell\User] http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 12-15-03]
Please post replies to this Newsgroup, email address is invalid
--

Zonky said:
As documented here:

http://www.allexperts.com/previousqv.asp?QuestionID=3246967

(specifically)

Both bs3.dll and bsx5.dll are part of parasite spyware

What it does to your computer:
It allows installation of a file(s) that tracks your web browsing. bs stands for
BookedSpace.
BookedSpace is an Internet Explorer Browser Helper Object used to show advertising.

bs3.dll and bsx5.dll are both variants of spyware orginal BookedSpace/Remanent, an early
variant (around July 2003) with filename rem00001.dll, controlling server 66.225.192.199.
These are both newer revisions with filename bs2.dll or bs3.dll, or bsx5.dll controlling
server www.bookedspace.com.
It is silently installed by MThree MP3 to WAV converter. Origin currently unknown.

bs3.dll or bsx5.dll = BookedSpace can contact its controlling server when a new page is
visited, which may direct it to open pop-up ads.
When the controlling server is contacted, the URL of the current page is passed along with a
user ID for tracking purposes.
It can download and install third-party software as directed by its controlling server.
BookedSpace/BS2 has been seen to install the BargainBuddy, nCase and eBates parasites.

Stability problem = Seems to stop IE address bar searches from working.

<end quote>

These dll's have been removed from my system (windows XP Home). Is there any way to restore
the Address bar searching (i.e, the settings in
HKEY_USERS\Software\Microsoft\Internet Explorer\SearchUrl\ are present as is before, but
when for e.g i type g searchterm, the page does not load it loads
http:///g searchterm and
 
Z

Zonky

Zonky,
http:/// = CWS.Svcinit (coolwebsearch trojan)

How to remove Coolwebsearch and affiliates
http://mvps.org/winhelp2002/unwanted.htm#Coolwebsearch

Note: this type hijack indicates an unpatched machine, that is lacking
in "Defense". Please visit Windows Update to avoid these exploits.
____________________________________________________________
Mike Burgess [MVP Windows Shell\User]
http://www.mvps.org/winhelp2002/ Blocking Spyware, Adware, Parasites,
Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 12-15-03] Please
post replies to this Newsgroup, email address is invalid --

Thanks- tried this and coolwebsearch was not present, however, i'm sorry
but i gave the slightly wrong url. When the searchurl g searchterm is used,
the web browser ends up with:

http:///? g searchterm

I'm pretty sure it's probably tied in to bookedspace- that was the only
thing adaware has found.

Z.
 
M

Mike Burgess

Zonky,
This is an indication of a broken "URLSearchHook"

See: "Repair the corrupted or altered (spyware) HTTP prefixes"
http://mvps.org/winhelp2002/unwanted.htm
____________________________________________________________
Mike Burgess [MVP Windows Shell\User] http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 12-15-03]
Please post replies to this Newsgroup, email address is invalid
--

Zonky said:
Zonky,
http:/// = CWS.Svcinit (coolwebsearch trojan)

How to remove Coolwebsearch and affiliates
http://mvps.org/winhelp2002/unwanted.htm#Coolwebsearch

Note: this type hijack indicates an unpatched machine, that is lacking
in "Defense". Please visit Windows Update to avoid these exploits.
____________________________________________________________
Mike Burgess [MVP Windows Shell\User]
http://www.mvps.org/winhelp2002/ Blocking Spyware, Adware, Parasites,
Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 12-15-03] Please
post replies to this Newsgroup, email address is invalid --

Thanks- tried this and coolwebsearch was not present, however, i'm sorry
but i gave the slightly wrong url. When the searchurl g searchterm is used,
the web browser ends up with:

http:///? g searchterm

I'm pretty sure it's probably tied in to bookedspace- that was the only
thing adaware has found.

Z.
 
Z

Zonky

Zonky,
This is an indication of a broken "URLSearchHook"

See: "Repair the corrupted or altered (spyware) HTTP prefixes"
http://mvps.org/winhelp2002/unwanted.htm
____________________________________________________________
Mike Burgess [MVP Windows Shell\User]
http://www.mvps.org/winhelp2002/ Blocking Spyware, Adware, Parasites,
Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 12-15-03] Please
post replies to this Newsgroup, email address is invalid --

Thanks, this worked.

Z.
 
Top