PDA

View Full Version : BHO Trojans - Vista



paulatharris
2009-02-24, 22:39
Just run Spybot for first time on a new Vista Machine brought one week ago and it pulled up BHO Trojans. Should I be concerned and should I try to remove them with Spybot?

Results Below. Thanks

--- Search result list ---
PartnerBHO: [SBI $2FE4A5BE] Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{28A88B70-D874-4f73-BBBA-9B2B222FB7D6}

PartnerBHO: [SBI $BE743C00] Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\kt_bho_dll.dll

PartnerBHO: [SBI $F3EE08ED] Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}

PartnerBHO: [SBI $14904C60] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\kt_bho.KettleBho

PartnerBHO: [SBI $14904C60] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\kt_bho.KettleBho.1

PartnerBHO: [SBI $14904C60] Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}

PartnerBHO: [SBI $14904C60] Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}

PartnerBHO: [SBI $14904C60] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\kt_bho.KettleBho.1

PartnerBHO: [SBI $14904C60] Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}

PartnerBHO: [SBI $14904C60] Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}

PartnerBHO: [SBI $14904C60] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\kt_bho.KettleBho

PartnerBHO: [SBI $6B47FF4E] Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{86676E13-D6D8-4652-9FCF-F2047F1FB000}

drragostea
2009-02-25, 05:11
A quick search brings up "PartnerBHO" as a malicious library file. Remove what Spybot-Search&Destroy finds (flagged PartnerBHO entries).