Sunday, January 6, 2013

btsearch.name Take over Browser! (Steps to Stop btsearch Virus)

btsearch.name is such a tricky hijacker that borrow avg’s name in its URL address appearing as avg.name. However its weird and typical hijacker behavior notify people that it is a pesky hijacker and it is lame without any icon, logo or something like that.
Here’s the screenshot of btsearch.name:



 Tee Support agents 24/7 online have been informed that btsearch.name is also able to install toolbar imperceptibly and search.openmediasoft.com seems to be a collaborator.

 Hard Time to Remove btsearch.name! Doomed?



Of course not. There’s always a solution even though you’ve attempted to change back homepage by going to ‘options’ -> ‘General tab’ on firefox browser; cleaned out all junk/temp files; reset/repaired Network connection; removed any suspect problems and left just basic applications and etc..

Be noted that a virus can get into your system with antivirus program protection is not that easy to be found. Some components are hidden and some are titled with names similar to systematic ones, which is the usual way to bypass security utilities. To find out those crafty ones, manual way based on security programs help is needed to achieve a complete removal. 

Follow the steps below and be careful, any slight mistake would lead to windows break down. If you have any concern during the removal process, you are welcome to start a live chat here for professional help.



Summery on Damages


  1. Injects keyloggers to gather information stored in system and blabbed out to your contacts.
  2. Computer seizes when try to operate several programs simultaneously.
  3. Firewall becomes unable to run against threats when it stays turn-off.
  4. System Restore point is missing but doesn’t invite attention since many things have been installed into folders and C drive.

No Idea to Remove btsearch.name? Feasible Steps to Follow up

1. Disable any suspicious startup items.
For Windows XP:

step: Click Start menu -> click Run -> type: msconfig in the search bar -> open System Configuration Utility -> Disable all possible startup items.



2. Remove add-ons:

Internet Explorer:
1) Go to Tools -> ‘Manage Add-ons’;
2) Choose ‘Search Providers’ -> choose ‘Bing’ search engine or ‘Google’ search engine and make it default;
3) Select ‘Search Results’ and click ‘Remove’ to remove it;
4) Go to ‘Tools’ -> ‘Internet Options’; select ‘General tab’ and click website, e.g. Google.com. Click OK to save changes.

Google Chrome
1) Click on ‘Customize and control’ Google Chrome icon, select ‘Settings’;
2) Choose ‘Basic Options’;
3) Change Google Chrome’s homepage to google.com or any other and click the ‘Manage Search Engines…’ button;
4) Select ‘Google’ from the list and make it your default search engine;
5) Select ‘Search Result’ from the list to remove it by clicking the ‘X’ mark.    

Mozilla Firefox
1) Click on the magnifier’s icon and select ‘Manage Search Engine…’;
2) Choose ‘Search Results’ from the list and click ‘Remove’ and OK to save changes;
3) Go to ‘Tools’ -> “Options”. Reset the startup homepage or change it to google.com under ‘General tab;  


3. Disable proxy

  1. Click on Tools on the menu bar
  2. select Internet options
  3. go to Connections tab
  4. select LAN settings at the bottom of the dialog
  5. under the Proxy sever, untick 'use a proxy server for your LAN (These settings will not apply to dial-up or VPN connections).'
  6. Click OK 

4. Show hidden files  
step: a) open Control Panel from Start menu and search for Folder Options;

 

b) under View tab to tick Show hidden files and folders and non-tick Hide protected operating system files (Recommended) and then click OK;

 


5. Open Windows Task Manager and close all running processes.
step: Use CTRL+ALT+DEL combination to open Task Manager  

Please stop all the following processes.
random.exe

6. Delete all related files and registry values in your local hard disk C.
step: Hold down the Windows key on your keyboard and press the "R" button. Type in "regedit" and hit "Enter" to gain access to the Registry Editor.


                         

Registry:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegedit” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegistryTools” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “ConsentPromptBehaviorAdmin” = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “ConsentPromptBehaviorUser” = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “EnableLUA” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Inspector”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “net” = “2012-4-27_2″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “UID” = “tovvhgxtud”
HKEY_CURRENT_USER\Software\ASProtect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
step: Click on the “Start” menu and then click on the “Search programs and files” box, Search for and delete these files:

%AllUsersProfile%\Application Data\.dll
%AllUsersProfile%\Application Data\.exe
C:\WINDOWS\system32\drivers\serial.sys
C:\Users\Vishruth\AppData\Local\Temp\random.xml
C:\windows\system32\drivers\mrxsmb.sys(random)
C:\WINDOWS\system32\drivers\redbook.sys(random

Video Sample Guide to Cue You in btsearch.name Removal

 

Kind Reminder: manual removal of btsearch.name is a process of high complexity and should be performed with extreme caution, or mal-operation often results in loss of precious data even system crash. Therefore, if you're not familiar with that, you are welcome to get help from an Online Computer Expert here. Then your issue can be fixed directly and effectively.

No comments:

Post a Comment