Unsolved

This post is more than 5 years old

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

6465

April 15th, 2005 15:00

is About:Buster itself a "hijacker" ?

i was testing About:Buster yesterday, and every time i ran it, there was a warning (from WinPatrol) about an attempt being made to change my home page and search page to google.com  (fortunately, WinPatrol allowed me to restore both my original pages)
 
has anyone else experienced/noticed this?  is about:buster itself a "hijacker" ?
 
since about:buster is used/recommended here by several of the HJT experts, i am very concerned about this.
 
(version 4.0, just in case that makes the difference)

Message Edited by ky331 on 04-15-2005 11:27 AM

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

April 15th, 2005 16:00

Bertha2,
 
I realize that about:buster is supposed to be "a tool which aides in the removal of About Blank type" infections.  (and i'm not in a position to debate whether or not it is effective at the task).   all i know is that, every time i tried running a:b, something --- which i have to assume is a:b,  based on the repeated cause/effect correlation --- was attempting to hijack both my home and search pages... specifically, to google.com 
since it happened  every time i ran a:b (and morever, never happened when i wasn't running a:b), it can't just be a coincidence.
 
have you tried running a test yourself?    with a:b version 4.0 ?  (make sure it's a fair test, if you've enabled any passive hijacking blockers)

Message Edited by ky331 on 04-15-2005 12:51 PM

711 Posts

April 15th, 2005 16:00

Hey Ky331,

AboutBuster itslef is not a "Hijacker"

Winpatrol my be picking it up becuase it is a specific tool which targets certain areas of your system (I had a similair problem with an L2M removal tool, which was also being picked up as dangerous but I know that it is not)

Instead it is a tool which addes in the removal of About Blank type 2/4

Bertha2

711 Posts

April 15th, 2005 17:00

hey Ky331,

If theres a problem with your system just pop up a Hijackthis Log here for me and Ill take a look

I dont conside AboutBuster to cause any problems what so ever

Bertha2

4 Apprentice

 • 

8.8K Posts

April 15th, 2005 18:00

ky331,

Hold on,...don't get carried away. I never said you werent' crazy:)


Steve

you know I'm just kiddin ya

4 Apprentice

 • 

8.8K Posts

April 15th, 2005 18:00

Ky331,
I just ran About:Buster verion 4.

It did infact change my homepage on IE to Google.com. I don't think it's really a HiJack in the true sense of the word. There are many FREE applications out there. This is just one of the ways I am assuming they make some money by changing the IE homepage to Google.com.

I am sure that it can be easily reset back to the homepage of your choice, when you want, thus it isn't a HiJack in the true sense of the word. Just a small price you have to pay for using their application. They could have also changed the homepage to the About:Buster homepage but I am sure that Google paid them for this one.

I hope this helps put your mind at ease, now I have just reset my homepage and all is well.


Steve

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

April 15th, 2005 18:00

steve,
 
i was able to easily reset mine as well... so the "browser redirection" (if you want to distinguish it from  a malicious "hijacking") isn't especially serious in this case... but, now that you've confirmed my observation, i think it's something that the HJT experts should keep in mind when they advise someone to use Buster.
 
at least now i know i'm not crazy... :smileyhappy:
 
 

711 Posts

April 15th, 2005 18:00

Can i just add though that your systems are not infected with About Blank are they?

So therefore you wont have homepages similair to this - http://www.malwareremoval.com/images/ab-t2/newhomepage001.JPG

Therefore when AboutBuster is run it is removing the CWS variant that is causing such a problem and then resetting the Homepage to Google after it has removed the offendign problems (from there the vicitm can reset their homepage to whatever it was before or leave it at Google) as you both say

As a victim this would not concern me as Google is a far better homepage than the Malware caused About Blank which is what you want rid of when you have this problem

So yes AboutBuster is resetting the hompeage but this is part of the fix as it does so when fixing an About Blank infection and removing the annoying and key sign (of an About Blank infetcion) the About Blank homepage

Bertha2

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

April 15th, 2005 18:00

bertha2,

you're right --- my system was not infected with about:blank when i ran Buster.

and i hope this won't become a big 'debate' here... the "browser redirection" in this instance is certainly not dangerous nor harmful... nor hard to undo.   but it certainly came as a surprise to me.

i've been using WinPatrol for several years now, and (fortunately/luckily for me) i believe it's the first time i've ever been warned about a potential home page redirection.  my hat is off to Scotty the Windows Watchdog... if you don't know what i'm talking about, see

http://forums.us.dell.com/supportforums/board/message?board.id=si_virus&message.id=39066

have a good weekend all, time for me to call it a day

2 Intern

 • 

2.5K Posts

April 15th, 2005 23:00

Into the fray.  I have be following this thread,  sorta.  Let me see if I have it,  running AboutBuster changes you home page, for no apparent reason.  That is a big non-no as far as I am concerned.  Whether is is easy to repair or not is irrevelant.  Changing anything without the consent or requested by the user is definition of malware.  Changing anything not required by the program to perform it intended purpose unacceptable as far as I am concerned.  I thought the rule was "First do no harm"  which can be interperted as "Do nothing that does not need to be done".

711 Posts

April 16th, 2005 06:00

msgale you have not fully understood my post above here

AboutBuster is run on a system that has About Blnka (that means they have numerous problems oone of which being their homepage lookign like above, the link I gave)

Thereofre running AboutBuster removes these nasties, and stops your homepage goign to About Blnak and resets it to Google for the time being (that is its default settign after removing About Blank) From there the victim can change it to whatever they like if they wish

AboutBuster si not meant to be run on a system that does not have AboutBlank

Hopefully that is the end of the thread

Bertha2

2 Intern

 • 

860 Posts

April 16th, 2005 09:00

Calling about:buster a hijacker is usually done by users who do not know the history of about:buster
 
About:Buster was created by RubbeR DuckY a well known spyware fighter and anti spyware application developer
(ChrisRLG would know him well as hes done some software testing for him)
 
RubbeR DuckY's forum is located here
http://www.malwarebytes.biz/forums/index.php?
 
All queries in reference to can be posted here About:Buster Errors
http://www.malwarebytes.biz/forums/index.php?showforum=2
 

2 Intern

 • 

2.5K Posts

April 16th, 2005 13:00

From an earlier response by zbestwun2001

“It did infact change my homepage on IE to Google.com. I don't think it's really a HiJack in the true sense of the word. There are many FREE applications out there. This is just one of the ways I am assuming they make some money by changing the IE homepage to Google.com.”  

If this is true then without question this is a HiJack since someone is making money off others misfortune. It is no different from those that register misspellings of real web address to get click through fees.  Again, if the quote is true, why not, after cleaning the home page set it to nothing, ask the use what he/she wants it to be, or tell the user that what the program is doing and getting paid it.  One of the courses I had to take in graduate school for my Masters in Computer and Information Science was at LaSalle University, a fully accredited University In Philadelphia Pennsylvania, was the “Legal, Ethical and Social Issues and Computer Sciences”, I didn’t much like the course, but one thing I did learn was “click through fees” are unethical when the user is unaware of them.  Again assuming that the initial quote is true, the fact the ChrisRLG knows RubbeRDuckY is immaterial, what would resolve the issue is an clear statement from the program’s creator that he/she derives no financial rewards from the use of the product.  Again let me state everything I say is predicated upon zbestwun2001 statement being true. 

April 16th, 2005 21:00

Hello all,

Just to add a little bit to what Bertha2 said earlier.

About Buster is not a detection tool in the sense of Spybot S&D, or Ad-Aware. It is a diagnostic/repair tool, meant to be run as part of one of the CWS variant infections. Not to be run on a clean machine.

Since the infected machine has a hijacked
homepage, it would be very difficult if not impossible for a program to determine what the original homepage was. So About Buster is programmed to reset the hijacked page to a known "safe" page: Google.

I hope this puts the issue to rest.:smileyhappy:

George a.k.a. SpotCheckBilly

Message Edited by SpotCheckBilly on 04-16-200503:27 PM

Message Edited by SpotCheckBilly on 04-16-2005 03:27 PM

2 Intern

 • 

2.5K Posts

April 16th, 2005 22:00

No, your answer has not put absolutely nothing to rest; actually your non-answer seems to lend credence to zbestwun2001’s statement.  It is a simple question, you have three choices 1, – you know the statement is true, 2 – you know the statement is false, 3 – you do not know.  Zbestwin2001’s statement “It did infact change my homepage on IE to Google.com. I don't think it's really a HiJack in the true sense of the word. There are many FREE applications out there. This is just one of the ways I am assuming they make some money by changing the IE homepage to Google.com.”  

 

April 17th, 2005 06:00

OK, I don't know how I can make this any more clear.

1. About Buster is not and was not designed to be run on a noninfected machine. It was written to assist in the removal of a specific CWS infection ONLY!!!


Simple enough? Read on.

2. On an infected machine, the homepage has been hijacked, redirected, switched, changed to, however you would like to put it, to an unwanted page which cannot be reset.

3. The About Buster program has no way of determining the original homepage.

4. During the repair, About Buster resets the hijacked page to a "safe" (almost universally known?)  page, Google.

Now here's the part you seem to have trouble with.

5. If your machine is not infected, About Buster will reset what it considers a hijacked page to its preprogrammed "safe" page, Google.

Why does it do this? Referr back to No.1 through No.3.

Does this add any clarity? Or are we just being deliberately obtuse?

Either way, I'm done with this silliness. About Buster is a useful tool and does its job well.

George a.k.a. SpotCheckBilly

BTW nowhere, in anything I have ever read regarding About Buster has led me to believe that it is in any way whatsoever affiliated (in a monetary way) with Google.--- sorry Steve, I think you slipped on that one.:smileyhappy:
No Events found!

Top