Gtpbstnws.com is a browser hijacker and potentially unwanted program (PUP) that redirects your web searches and homepage without permission. This intrusive software typically arrives bundled with free downloads and immediately alters your browser settings to force traffic through its advertising network. While not a virus in the traditional sense, gtpbstnws.com creates security vulnerabilities, degrades system performance, and exposes you to questionable advertisements and potentially malicious sites.

Gtpbstnws.com — cybersecurity illustration
Photo by Ann H on Pexels

Most users discover this infection when their browser suddenly opens to an unfamiliar search page, or when every search query redirects through gtpbstnws.com before landing on actual results. The hijacker generates revenue for its operators by capturing your search traffic and displaying sponsored ads, but it also creates a pathway for more serious threats to enter your system.

If you're seeing gtpbstnws.com right now: Close your browser immediately. Do not enter passwords, credit card information, or other sensitive data while this hijacker is active. The infection can monitor your browsing activity and may expose credentials to third parties. Disconnect from the internet if you've recently entered financial information, then follow the removal steps below or call us at (770) 695-6000 for immediate assistance.

Threat Profile

Attribute Details
Threat Type Browser Hijacker / Potentially Unwanted Program (PUP)
Family Search redirect hijacker (related to generic adware bundling operations)
Affected Platforms Windows 7/8/10/11; may affect Chrome, Firefox, Edge, and Internet Explorer
Distribution Method Software bundling, fake installers, misleading browser extensions
Primary Symptoms Homepage/search engine changes, search redirects, excessive pop-up ads, browser slowdown
Persistence Mechanism Browser extension installation, modified shortcuts, registry entries, scheduled tasks (varies by variant)
Data at Risk Browsing history, search queries, potentially login credentials if entered while active
Network Behavior Redirects traffic through gtpbstnws.com domain; connects to third-party ad networks; may download additional PUPs
Associated Files Browser extension folders with randomized names; helper executables in %LOCALAPPDATA% or %APPDATA% directories
Removal Difficulty Moderate — often reinstalls itself if browser extensions and system persistence mechanisms aren't fully removed
Revenue Model Pay-per-click advertising, search traffic monetization, affiliate commissions from additional software installations
Legitimate Removal Manual browser cleanup + anti-malware scan; professional removal recommended if persistent

How It Spreads

Gtpbstnws.com primarily distributes through software bundling, where it piggybacks on legitimate-looking free software installers. When you download a media player, PDF converter, or system utility from third-party download sites, the installer may include gtpbstnws.com as an "optional offer" that's pre-checked or hidden in the "Custom Installation" settings. Many users click through these installers quickly, inadvertently agreeing to install the hijacker along with their intended program.

The hijacker also spreads through deceptive browser extension prompts. You might encounter a popup claiming you need to install an extension to watch a video, access content, or verify you're human. These prompts appear legitimate but actually install the gtpbstnws.com hijacker. Malicious advertising networks sometimes serve these prompts on otherwise legitimate websites, making it difficult to distinguish safe from unsafe pages.

Common distribution methods include:

  • Bundled software packages from download portals like Softonic, Download.com, or CNET when using their download managers
  • Fake software updates claiming to be Flash Player, Java, or codec updates
  • Torrent downloads where the hijacker is packaged with cracked software or media files
  • Malicious browser extensions promoted through social engineering on YouTube, forums, or social media
  • Email attachments disguised as invoices, shipping notifications, or document viewers
  • Compromised websites that automatically trigger download prompts through exploit kits (less common for this threat)

What It Does On Your Machine

Once installed, gtpbstnws.com immediately modifies your browser configuration to redirect your web activity through its servers. It changes your default search engine, homepage, and new tab page to gtpbstnws.com or related domains. When you perform a search, your query first passes through the hijacker's servers, which log your search terms and browsing habits before redirecting you to a legitimate search engine like Google or Bing—but with the results page modified to include sponsored advertisements.

The hijacker installs persistence mechanisms that make it difficult to remove through normal means. It may create browser extensions with administrative privileges, modify browser shortcut files to launch with the hijacker's URL as the homepage, and establish registry keys that restore its settings even after you manually change them back. Some variants install scheduled tasks that periodically check whether the hijacker is still active and reinstall it if you've removed the browser component.

Beyond the obvious annoyance of unwanted redirects, gtpbstnws.com creates security vulnerabilities. The hijacker tracks your browsing activity, building a profile of your interests, shopping habits, and frequently visited sites. This data is valuable to advertisers, but it also creates privacy risks—especially if the operators sell this information to third parties without adequate security measures. More concerning is that the hijacker may redirect you to websites hosting more dangerous malware, including ransomware, trojans, or cryptocurrency miners.

Typical Gtpbstnws.com Artifacts (examples for this hijacker family)
Registry Keys: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\[RandomName] HKCU\Software\Microsoft\Internet Explorer\Main\Start Page = "http://gtpbstnws.com" HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist File Locations: %LOCALAPPDATA%\[RandomGUID]\agent.exe %APPDATA%\[BrowserName]\Extensions\[extension_id]\ %USERPROFILE%\Desktop\[Browser].lnk (modified shortcut) Browser Extension IDs: ; Varies by installation, typically randomized 32-character string Chrome: chrome://extensions/ (look for unknown extensions with "Read browsing history" permission) Firefox: about:addons (check for unfamiliar extensions installed on the date infection occurred) Scheduled Tasks: Task Scheduler Library\[RandomName] → triggers %LOCALAPPDATA%\[GUID]\*.exe

Performance degradation is another immediate effect. The constant redirects, ad injections, and background communications with advertising servers slow down your browsing considerably. Pages take longer to load, your browser may freeze or crash more frequently, and you'll notice increased CPU usage even when you're not actively browsing. If the hijacker downloads additional unwanted programs—a common behavior for this threat family—your entire system performance suffers.

Manual Removal — Step by Step

01

Disconnect and Prepare

Disconnect your computer from the internet by unplugging your ethernet cable or disabling Wi-Fi. This prevents the hijacker from downloading additional components or communicating with its command servers during removal. If you're reading these instructions on the infected computer, print them or view them on your phone.

02

Boot Into Safe Mode with Networking

Restart your computer and enter Safe Mode. On Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot → Advanced Options → Startup Settings → Restart, and press F5 for Safe Mode with Networking. Safe Mode prevents most hijacker components from loading automatically, giving you a cleaner environment for removal.

03

Uninstall Suspicious Programs

Open Control Panel → Programs and Features (or Settings → Apps on Windows 10/11). Sort by Install Date and look for programs installed around the time the redirects started. Remove anything unfamiliar, especially programs with generic names, random characters, or developers you don't recognize. Common culprits include names like "Web Companion," "SearchProtect," or names that sound like legitimate utilities but aren't.

04

Remove Browser Extensions

Open each browser you use and remove suspicious extensions. In Chrome: menu → Extensions → Manage Extensions, then remove anything you didn't intentionally install. In Firefox: menu → Add-ons and Themes → Extensions. In Edge: menu → Extensions. Pay special attention to extensions with vague names or those requesting permissions to "read and change all your data on websites."

05

Reset Browser Settings

After removing extensions, reset each browser to defaults. Chrome: Settings → Reset settings → Restore settings to their original defaults. Firefox: Help → More Troubleshooting Information → Refresh Firefox. Edge: Settings → Reset settings → Restore settings to their default values. This removes homepage hijacks, search engine changes, and other modified settings the hijacker may have altered.

06

Check and Fix Browser Shortcuts

Right-click each browser shortcut (on desktop, taskbar, and Start menu), select Properties, and examine the Target field. It should end with the browser executable name (chrome.exe, firefox.exe, etc.) with nothing after it. If you see a URL after the .exe, delete everything after the closing quote mark, click Apply, then OK. The hijacker commonly adds its URL to shortcuts to force it as your homepage.

07

Remove Scheduled Tasks and Startup Entries

Open Task Scheduler (search for it in the Start menu), expand Task Scheduler Library, and look for tasks you didn't create—especially those with random names or pointing to executables in %LOCALAPPDATA% folders. Delete suspicious tasks. Then run Task Manager (Ctrl+Shift+Esc), go to the Startup tab, and disable any unfamiliar entries, particularly those with random names or unknown publishers.

08

Delete Hijacker Files

Navigate to %LOCALAPPDATA% and %APPDATA% (type these into File Explorer's address bar) and look for folders with random names or GUIDs created on the infection date. Delete any folders containing executables you don't recognize. Also check %TEMP% and delete all temporary files. Be cautious—don't delete folders from legitimate programs. When in doubt, research the folder name online before deleting.

09

Scan with Reputable Anti-Malware Tools

Reconnect to the internet and download Malwarebytes (free version is sufficient) from malwarebytes.com. Run a full scan to catch any remnants or additional PUPs the hijacker may have installed. Let it quarantine everything it finds. Follow up with a scan using your regular antivirus if you have one. Windows Defender is adequate for a second opinion if you don't have paid security software.

10

Change Passwords and Monitor Accounts

If you entered passwords while the hijacker was active, change them immediately—especially for banking, email, and shopping accounts. Start with your email password first, as that's the key to resetting other accounts. Use a different device if possible, or at minimum wait until you've completed all previous removal steps and verified no redirects occur.

11

Reboot and Verify Clean System

Restart your computer normally (not in Safe Mode) and test your browsers. Verify your homepage is correct, searches go directly to your chosen search engine, and no unexpected ads appear. Open a few websites and watch for redirects. If everything appears normal after 10-15 minutes of browsing, you've likely removed the infection successfully. If redirects return, the hijacker has a persistence mechanism you missed—see the callout below.

Prevention

  1. Download software only from official sources. Get programs directly from the developer's website, not from third-party download portals. When you must use a download site, choose the "direct download" option and avoid their download manager utilities.
  2. Always choose Custom Installation. When installing any free software, select "Custom" or "Advanced" installation and read each screen carefully. Uncheck any pre-selected offers for additional software, toolbars, or browser changes before proceeding.
  3. Keep your system and browsers updated. Enable automatic updates for Windows and your browsers. Security patches close vulnerabilities that hijackers and malware exploit. An outdated browser is significantly more vulnerable to drive-by installations.
  4. Use a reputable ad blocker. Extensions like uBlock Origin (not uBlock) reduce your exposure to malicious advertisements and deceptive download buttons. This won't prevent bundled installations, but it blocks many of the web-based distribution methods.
  5. Maintain real-time antivirus protection. Windows Defender is adequate for most users, but consider Malwarebytes Premium for real-time PUP blocking. Ensure real-time protection is enabled—scheduled scans alone won't stop installations as they happen.
  6. Ignore update prompts on websites. Legitimate software updates come through the software itself or official update mechanisms, not through browser popups. If a website claims you need to update Flash, Java, or a codec, it's almost certainly malicious. Flash is dead anyway—there's never a legitimate reason to install it in 2024.
  7. Review browser extensions regularly. Once a month, open your extensions page and remove anything you don't actively use. Many users accumulate extensions over time and forget they're there. Each extension is a potential security risk.
  8. Be skeptical of free offers. If software seems too good to be free—professional-grade video editors, expensive utilities, premium features with no catch—there's usually a catch. That catch is often bundled PUPs or worse.
Our 90-Day Warranty: When Computer Repair Roswell removes gtpbstnws.com or any other malware from your computer, we guarantee the infection won't return due to remnants we missed. If you experience the same hijacker within 90 days after our service, we'll remove it again at no additional charge. This warranty covers the specific threat we treated—not new infections from subsequent risky behavior like downloading cracked software.

Bring It In

If the manual removal steps above feel overwhelming, or if you've followed them and the redirects keep coming back, it's time to bring your computer to professionals who handle these infections daily. Browser hijackers like gtpbstnws.com are designed to be persistent, and they often install multiple components that must all be removed completely or the infection reinstalls itself. Our technicians have specialized tools and experience to eliminate every trace, verify your system is clean, and ensure no additional malware came in alongside the hijacker.

Computer Repair Roswell is located at 60 Kingston Rd Roswell, GA 30075, and we're open Monday through Friday 10 AM to 6 PM, Saturday 10 AM to 4 PM. Call us at (770) 695-6000 to describe your symptoms—we can often tell you over the phone whether this is a simple hijacker or part of a more serious infection. Most browser hijacker removals are completed same-day, and we'll optimize your system's startup and security settings while we have it so you're better protected going forward. Don't let a persistent redirect infection waste your time and risk your personal information—we'll get you back to normal browsing within hours, not days.