Home Articles Spyware Research Support Scan Now Purchase F.A.Q.

P2P/BearShare

Alias: BearShare

Description: This adware may be downloaded with some music-related programs such as BearShare or NetPumper.

Threat type:

P2P - P2P is any peer-to-peer file swapping program. The following software applications are typical examples: Audiogalaxy, Bearshare, Blubster, E-Mule, Gnucleus, Grokster, Imesh, KaZaa, KaZaa Lite, Limewire, Morpheus, Shareaza, WinMX, Xolox, etc. P2P software may pose security issues because outsiders are granted access to you files. P2P can degrade network performance, consume vast amounts of storage and be bundled with adware and/or spyware programs.


Advice: Remove This is a very high risk threat and should be removed immediately as to prevent harm to your computer or your privacy.

Detection:
SpyNoMore detects P2P/BearShare: Yes

Threat risk: High Risk
SpyNoMore AntiSpyware: Remove BearShare, BearShare Remover
Very dangerous malware. Can log user's keyboard activity and take snapshots of the user's screen. Uses stealth installation and removal is very difficult. Category includes spyware programs, adware programs and trojans.

Symptoms:

P2P/BearShare Signature Details: The following information includes some of the standard signatures associated with this spyware threat. Please do not attempt to manually remove these items from your computer; Removing these items incorrectly or partially can cause your computer to experience critical errors, prevent your computer from restarting or cause loss of Internet connectivity. Should you be infected with P2P/BearShare, you can clean your computer by downloading SpyNoMore now.

Running Process Signatures:
N/A

File Signatures:
%PROGRAM_FILES%\bearsh~1\bearsh~1.exe
%COMMON_PROGRAMS%\bearshare.lnk
%DESKTOPDIRECTORY%\bearshare downloads.lnk
%DESKTOPDIRECTORY%\bearshare.lnk

Registered Dll (Dynamic Link Library) Signatures:
N/A

Folder Signatures:
%PROGRAM_FILES%\bearshare

Registry Signatures:
HKCR\clsid\{9f95f736-0f62-4214-a4b4-caa6738d4c07}
HKCU\appevents\eventlabels\bearsharechatnotifymsg
HKLM\software\bearshare
HKLM\software\classes\gnutella
HKLM\software\classes\clsid\{558ec983-bedb-9168-b2de-31dbf0ee543e}
HKLM\software\classes\gnu
HKCU\appevents\schemes\apps\bearshare
HKLM\software\classes\gnufile\shell\open\command
HKCR\clsid\{905d0df2-3a0a-4d94-853c-54a12a745905}
HKCR\typelib\{905d0df2-3a0a-4d94-853c-54a12a745905}
HKU\.default\appevents\schemes\apps\bearshare
HKLM\software\microsoft\active setup\installed components\{5f95e1af-2620-4f15-bdf9-7fdce4607e17}
HKCR\gnufile
HKLM\software\classes\ed2k
HKU\.default\appevents\eventlabels\bearsharechatnotifymsg
HKLM\software\microsoft\windows\currentversion\uninstall\bearshare


SpyNoMore Collected Residual File Signatures:
N/A


See Also:
Trojan/RAT/Downloader/Whomp.10
Backdoor/RAT/Winshell.50
Nuker/BAT.Deltree.q
Trojan/Hacker Tool/PSW.Akcom.b
Trojan/Dlder.a
RAT/EMCO Remote CmdLine
Trojan/Breakit
P2P/KaZaA
Spyware/SavingBot Shopper
Trojan/Key Logger/Spy.SCKeyLog.a

Spyware Removal Home | Support | F.A.Q. | Contact Us | Spyware Removal Database | Privacy Policy | Site Map
Copyright © 2005-2008 Illysoft LLC