Slashdot Mirror


Removing Burstabit Spyware?

Webbsurfer asks: "I recently returned home from school from winter break, and discovered a good chunk of spyware on my parent's computer. I've ran ad-aware and cleared out the obvious P2P programs, but there's one I can't seem to get rid of. It generates pop-up ads, which come from the burstabit.com domain. Any ideas who these guys are and how to get rid of their junk?"

7 of 40 comments (clear)

  1. Browser Help Object by TheSHAD0W · · Score: 5, Informative

    Aside from the program folder, a lot of spyware hides in the list of Browser Help Objects. Do a net search for "BHO Cop". (That utility, by PC Magazine, was withdrawn from general distribution, but can be found here and there, and there are other utilities that do the same thing.)

    1. Re:Browser Help Object by TheSHAD0W · · Score: 4, Informative

      Here's a page at spywareinfo.com with a number of utilities for cleaning up Browser Help Objects and other forms of spyware. I recommend it.

  2. Re:What OS? by GimmeFuel · · Score: 5, Informative
    Given that the question talks about parents who don't sound very computer literate and P2P programs, I'd assume it's some flavor of Windows. Try to find a "hosts" file (no extension) in C:\WINDOWS\ or a subdirectory (I also found it in C:\WINDOWS\SYSTEM32\DRIVERS\etc). Open it with notepad and add on a new line:

    127.0.0.1 burstabit.com

    This means that whenever the system tries to connect to burstabit.com, it'll skip the DNS lookup and connect to 127.0.0.1, which is your computer. This'll hopefully stop the spyware.

  3. Get Spybot by Anonymous Coward · · Score: 2, Informative

    Ad-Aware hasn't updated their reference files since late September. Do yourself a favor and grab Spybot [http://security.kolla.de/].

  4. Check the registry by Ziktar · · Score: 3, Informative

    I'd use BHO Cop as suggested in a previous post, but more than likely it's just in one of the Run keys in the registry. You can either launch regedit and browse to the run keys, or use msconfig's startup tab to delete all the unneccessary crap.

  5. Re:The one that annoyed me by einTier · · Score: 3, Informative
    I've used a computer 'infected' with lop.com. One of the worst things I've ever seen. I couldn't figure out how to get rid of it either, I had to eventually just format the thing and just start over.


    Tons of pop-ups, a lot of mis-redirection back to lop.com (like trying to go to google.com), and all kinds of "helper" lop.com applications. I'd love to know how to get rid of it if I ever run across it again.

    --
    -------------------------------------------------- $665.95 -- retail price of the beast.
  6. Re:The one that annoyed me by babbage · · Score: 3, Informative
    Unfortunately, considering the ways these spyware programs are written, their "official" uninstall instructions are unlikely to be enough. What to do? Google to the rescue! Their new webquotes beta service -- which shows you [a] the URL it thinks you're looking for, and [b] *what other pages say about that URL* -- is exactly what you need here. Follow that link and you'll find several explanations of how Lop works & how to remove it, and you don't have to take their "official" word for it.

    Google rules. Well, usually -- they're not turning up any hits for Burstabit yet, though I'm sure this article will itself become part of their index before too long. Not that that Google reference helps the person who submitted this story in the first place...