Unsolved
This post is more than 5 years old
5 Journeyman
•
15.6K Posts
•
45K Points
0
6465
April 15th, 2005 15:00
is About:Buster itself a "hijacker" ?
i was testing About:Buster yesterday, and every time i ran it, there was a warning (from WinPatrol) about an attempt being made to change my home page and search page to google.com (fortunately, WinPatrol allowed me to restore both my original pages)
has anyone else experienced/noticed this? is about:buster itself a "hijacker" ?
since about:buster is used/recommended here by several of the HJT experts, i am very concerned about this.
(version 4.0, just in case that makes the difference)
Message Edited by ky331 on 04-15-2005 11:27 AM
No Events found!


ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
April 15th, 2005 16:00
Message Edited by ky331 on 04-15-2005 12:51 PM
Bertha2
711 Posts
0
April 15th, 2005 16:00
Hey Ky331,
AboutBuster itslef is not a "Hijacker"
Winpatrol my be picking it up becuase it is a specific tool which targets certain areas of your system (I had a similair problem with an L2M removal tool, which was also being picked up as dangerous but I know that it is not)
Instead it is a tool which addes in the removal of About Blank type 2/4
Bertha2
Bertha2
711 Posts
0
April 15th, 2005 17:00
hey Ky331,
If theres a problem with your system just pop up a Hijackthis Log here for me and Ill take a look
I dont conside AboutBuster to cause any problems what so ever
Bertha2
zbestwun2001
4 Apprentice
•
8.8K Posts
0
April 15th, 2005 18:00
Hold on,...don't get carried away. I never said you werent' crazy:)
Steve
you know I'm just kiddin ya
zbestwun2001
4 Apprentice
•
8.8K Posts
0
April 15th, 2005 18:00
I just ran About:Buster verion 4.
It did infact change my homepage on IE to Google.com. I don't think it's really a HiJack in the true sense of the word. There are many FREE applications out there. This is just one of the ways I am assuming they make some money by changing the IE homepage to Google.com.
I am sure that it can be easily reset back to the homepage of your choice, when you want, thus it isn't a HiJack in the true sense of the word. Just a small price you have to pay for using their application. They could have also changed the homepage to the About:Buster homepage but I am sure that Google paid them for this one.
I hope this helps put your mind at ease, now I have just reset my homepage and all is well.
Steve
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
April 15th, 2005 18:00
Bertha2
711 Posts
0
April 15th, 2005 18:00
Can i just add though that your systems are not infected with About Blank are they?
So therefore you wont have homepages similair to this - http://www.malwareremoval.com/images/ab-t2/newhomepage001.JPG
Therefore when AboutBuster is run it is removing the CWS variant that is causing such a problem and then resetting the Homepage to Google after it has removed the offendign problems (from there the vicitm can reset their homepage to whatever it was before or leave it at Google) as you both say
As a victim this would not concern me as Google is a far better homepage than the Malware caused About Blank which is what you want rid of when you have this problem
So yes AboutBuster is resetting the hompeage but this is part of the fix as it does so when fixing an About Blank infection and removing the annoying and key sign (of an About Blank infetcion) the About Blank homepage
Bertha2
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
April 15th, 2005 18:00
bertha2,
you're right --- my system was not infected with about:blank when i ran Buster.
and i hope this won't become a big 'debate' here... the "browser redirection" in this instance is certainly not dangerous nor harmful... nor hard to undo. but it certainly came as a surprise to me.
i've been using WinPatrol for several years now, and (fortunately/luckily for me) i believe it's the first time i've ever been warned about a potential home page redirection. my hat is off to Scotty the Windows Watchdog... if you don't know what i'm talking about, see
http://forums.us.dell.com/supportforums/board/message?board.id=si_virus&message.id=39066
have a good weekend all, time for me to call it a day
msgale
2 Intern
•
2.5K Posts
0
April 15th, 2005 23:00
Bertha2
711 Posts
0
April 16th, 2005 06:00
msgale you have not fully understood my post above here
AboutBuster is run on a system that has About Blnka (that means they have numerous problems oone of which being their homepage lookign like above, the link I gave)
Thereofre running AboutBuster removes these nasties, and stops your homepage goign to About Blnak and resets it to Google for the time being (that is its default settign after removing About Blank) From there the victim can change it to whatever they like if they wish
AboutBuster si not meant to be run on a system that does not have AboutBlank
Hopefully that is the end of the thread
Bertha2
jamez kann
2 Intern
•
860 Posts
0
April 16th, 2005 09:00
(ChrisRLG would know him well as hes done some software testing for him)
http://www.malwarebytes.biz/forums/index.php?
http://www.malwarebytes.biz/forums/index.php?showforum=2
msgale
2 Intern
•
2.5K Posts
0
April 16th, 2005 13:00
From an earlier response by zbestwun2001
“It did infact change my homepage on IE to Google.com. I don't think it's really a HiJack in the true sense of the word. There are many FREE applications out there. This is just one of the ways I am assuming they make some money by changing the IE homepage to Google.com.”
If this is true then without question this is a HiJack since someone is making money off others misfortune. It is no different from those that register misspellings of real web address to get click through fees. Again, if the quote is true, why not, after cleaning the home page set it to nothing, ask the use what he/she wants it to be, or tell the user that what the program is doing and getting paid it. One of the courses I had to take in graduate school for my Masters in Computer and Information Science was at LaSalle University, a fully accredited University In Philadelphia Pennsylvania, was the “Legal, Ethical and Social Issues and Computer Sciences”, I didn’t much like the course, but one thing I did learn was “click through fees” are unethical when the user is unaware of them. Again assuming that the initial quote is true, the fact the ChrisRLG knows RubbeRDuckY is immaterial, what would resolve the issue is an clear statement from the program’s creator that he/she derives no financial rewards from the use of the product. Again let me state everything I say is predicated upon zbestwun2001 statement being true.
SpotCheckBilly
932 Posts
0
April 16th, 2005 21:00
Just to add a little bit to what Bertha2 said earlier.
About Buster is not a detection tool in the sense of Spybot S&D, or Ad-Aware. It is a diagnostic/repair tool, meant to be run as part of one of the CWS variant infections. Not to be run on a clean machine.
Since the infected machine has a hijacked homepage, it would be very difficult if not impossible for a program to determine what the original homepage was. So About Buster is programmed to reset the hijacked page to a known "safe" page: Google.
I hope this puts the issue to rest.:smileyhappy:
George a.k.a. SpotCheckBilly
Message Edited by SpotCheckBilly on 04-16-200503:27 PM
Message Edited by SpotCheckBilly on 04-16-2005 03:27 PM
msgale
2 Intern
•
2.5K Posts
0
April 16th, 2005 22:00
No, your answer has not put absolutely nothing to rest; actually your non-answer seems to lend credence to zbestwun2001’s statement. It is a simple question, you have three choices 1, – you know the statement is true, 2 – you know the statement is false, 3 – you do not know. Zbestwin2001’s statement “It did infact change my homepage on IE to Google.com. I don't think it's really a HiJack in the true sense of the word. There are many FREE applications out there. This is just one of the ways I am assuming they make some money by changing the IE homepage to Google.com.”
SpotCheckBilly
932 Posts
0
April 17th, 2005 06:00
1. About Buster is not and was not designed to be run on a noninfected machine. It was written to assist in the removal of a specific CWS infection ONLY!!!
Simple enough? Read on.
2. On an infected machine, the homepage has been hijacked, redirected, switched, changed to, however you would like to put it, to an unwanted page which cannot be reset.
3. The About Buster program has no way of determining the original homepage.
4. During the repair, About Buster resets the hijacked page to a "safe" (almost universally known?) page, Google.
Now here's the part you seem to have trouble with.
5. If your machine is not infected, About Buster will reset what it considers a hijacked page to its preprogrammed "safe" page, Google.
Why does it do this? Referr back to No.1 through No.3.
Does this add any clarity? Or are we just being deliberately obtuse?
Either way, I'm done with this silliness. About Buster is a useful tool and does its job well.
George a.k.a. SpotCheckBilly
BTW nowhere, in anything I have ever read regarding About Buster has led me to believe that it is in any way whatsoever affiliated (in a monetary way) with Google.--- sorry Steve, I think you slipped on that one.:smileyhappy: