Removing Burstabit Spyware?
Webbsurfer asks: "I recently returned home from school from winter break, and discovered a good chunk of spyware on my parent's computer. I've ran ad-aware and cleared out the obvious P2P programs, but there's one I can't seem to get rid of. It generates pop-up ads, which come from the burstabit.com domain. Any ideas who these guys are and how to get rid of their junk?"
You can just point the offending domain name to localhost so that it can't actually grab any of the banner ads. How you go about this depends on what OS you're running.
Aside from the program folder, a lot of spyware hides in the list of Browser Help Objects. Do a net search for "BHO Cop". (That utility, by PC Magazine, was withdrawn from general distribution, but can be found here and there, and there are other utilities that do the same thing.)
c:\>format c:
Microsoft have acknowledged the problem with removing certain types of crap software. Check out this knowledgebase article to solve the problem.
Assuming you're running Windows, I'd just run regedit and search for burstabit. Delete everything that comes up, unless you can find a compelling reason not to.
Funny, I can't seem to find one. Hmm.
Too bad you didn't make the offending domain a hyperlink. I'm sure they would have loved the slashdotting. Think of the irony of it. You can't use your parent's computer because of burstabit, but burstabit couldn't use their own servers because of you :)
:P
Yes, might doesn't make right.. blah blah blah, but three lefts do.
-
ping -f 255.255.255.255 # if only
Try adding the domain to the HOSTS file, do a search and you will find it. Add something like this:
127.0.0.1 burstabit.com
http://phreakinb.com
Ad-Aware hasn't updated their reference files since late September. Do yourself a favor and grab Spybot [http://security.kolla.de/].
I'd use BHO Cop as suggested in a previous post, but more than likely it's just in one of the Run keys in the registry. You can either launch regedit and browse to the run keys, or use msconfig's startup tab to delete all the unneccessary crap.
I started using a new computer at work that various people had used before me, but there didn't appear to be much spyware on it.
Atleast, until I opened IE. The first URL I type in that is a typo, I get sent to something at www.lop.com or something like that which brings up pop-ups.
Every single time I mis-type a url, bam, pop-ups. It was the single most annoying thing I ever used. After a week of this, I formatted the computer.
Is this really how your parents are making you spend your vacation? ;-)
Curiosity: Did your parents sign off on the installation of all of the spyware? If so, why, if not, how did it arrive?
Happy Hunting -- and Holidays.
Very funny. Merry Christmas to you sir!
Then they won't have that problem.
God DAMN that's nasty. I'd forgotten I'd enabled popups. That hit me with 8 or 9 copies before I could hit escape.
What do they do - put newWindow(this) in the onLoad handler? (Note: preceeding was not necessarily valid, or even, reasonable, Javascript)
What if life is just a side effect of some other process and God has no idea we exist?
It's easy on a Win box. Run regedit (or equivalent) and look for the key:
u rr entVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\C
and see what gets kicked off when the system starts. Delete the entries you don't want. Done.
Moderation Totals: +3, Obvious
I want to delete my account but Slashdot doesn't allow it.
Backup. Fdisk. Reinstall.