BSEARCHSVC.EXE is Adware Kraddare

August 20, 2012 by NightWatcher
Filed under: Adware 
: Solved!

Fix it immediately:

We received the file BSEARCHSVC.EXE and detected that BSEARCHSVC.EXE is not good.
BSEARCHSVC.EXE is Adware. You should remove the file BSEARCHSVC.EXE.
Kill the process BSEARCHSVC.EXE and remove BSEARCHSVC.EXE from Windows.

Malware Analysis of BSEARCHSVC.EXE
Full path on a computer: %Program Files%\barosearch\bsearchsvc.exe

Detected by UnHackMe:

BSEARCHSVC.EXE
Default location: %Program Files%\barosearch\bsearchsvc.exe

Removal Results: Success
Number of reboot: 1

BSEARCHSVC.EXE is known as:

Adware.Kraddare

BSEARCHSVC.EXE hash:

  • MD5: b10eae0f1196bbaa49cd01040ac077e8
The file tries to download information from some web sites.
How to quickly detect BSEARCHSVC.EXE presence?

Registry:
  • HKLM\System\CurrentControlSet\Services\BCSvc\ImagePath: “%Program Files%\barosearch\bsearchsvc.exe”
  • HKLM\System\CurrentControlSet\Services\BCSvc\DisplayName: “BSearch Service”
  • HKLM\System\CurrentControlSet\Services\BCSvc\Description: “The Service in Windows.”
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run\BSearch: “%Program Files%\barosearch\bsearch.exe”
Folders:
  • %Program Files%\barosearch
Files:
  • %Favorites%\CJmall.url
  • %Favorites%\GS SHOP.url
  • %Favorites%\Hmall.url
  • %Local Appdata%\barosearchinstall.exe
  • %Program Files%\barosearch\11st.ico
  • %Program Files%\barosearch\auction.ico
  • %Program Files%\barosearch\bsearch.exe
  • %Program Files%\barosearch\bsearchsvc.exe
  • %Program Files%\barosearch\cjmall.ico
  • %Program Files%\barosearch\cybermall.ico
  • %Program Files%\barosearch\dnshop.ico
  • %Program Files%\barosearch\emart.ico
  • %Program Files%\barosearch\faple.ico
  • %Program Files%\barosearch\gmarket.ico
  • %Program Files%\barosearch\gseshop.ico
  • %Program Files%\barosearch\halfclub.ico
  • %Program Files%\barosearch\hmall.ico
  • %Program Files%\barosearch\istore1.ico
  • %Program Files%\barosearch\lotteimall.ico
  • %Program Files%\barosearch\mutnam01.ico
  • %Program Files%\barosearch\nseshop.ico
  • %Program Files%\barosearch\player.ico
  • %Program Files%\barosearch\samsungmall.ico


Recommended: UnHackMe anti-rootkit and anti-malware

Premium software: RegRun Security Suite (Good choice for removal and protection)

Written by

Malware Hunter.

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!

You must be logged in to post a comment.