Home Malware Programs Potentially Unwanted Programs (PUPs) Bizzybolt

Bizzybolt

Posted: December 4, 2013

Threat Metric

Ranking: 10,405
Threat Level: 2/10
Infected PCs: 3,822
First Seen: December 4, 2013
Last Seen: October 13, 2023
OS(es) Affected: Windows

Although online advertisements are one of the easiest ways to make money with little effort, browser add-on developers are constantly coming up with new brand names to distribute their old adware. Bizzybolt is one of the newest of these adware products that provide no serious features, at least, unless you consider being forced to sit through forced advertisements a 'feature.' Deleting adware like Bizzybolt is something that malware researchers can recommend without hesitation, both due to the nature of Bizzybolt's browser changes and the potential for its advertisements to include hostile content. However, good anti-malware or anti-adware products always should be considered your top shelf solutions for uninstalling Bizzybolt and similar PUPs.

The Add-on that Leaves You Dizzy with Advertisements

Bizzybolt, most likely one of the newer entrants into the SuperWeb LLC family of adware, has no meaningful presence on the Web in terms of marketing, and most likely is installed through software-bundling utilities. This means of distributing add-ons seen by malware experts in other kinds of adware too common to count, usually requires you to install an unrelated program from free sources (such as torrent networks or freeware sites), but also presents an option for installing Bizzybolt. If you pay close attention to the options during the installation routine, you may be able to opt out of Bizzybolt's 'offer,' although this is far from guaranteed.

Bizzybolt usually may be identified immediately after its installation by watching for its advertisements in various formats, most of which are outlined here:

  • Pop-up windows for Bizzybolt advertisements that load automatically.
  • Injected banners displaying advertisements by Bizzybolt in Web pages that shouldn't show these advertisements.
  • Injected links to Bizzybolt advertisements, usually based on the text keywords included in articles, blog posts, etc.

Getting Busy Doing Something About Bizzybolt

There's no need to panic over Bizzybolt as though Bizzybolt was a rootkit, banking Trojan or any other type of high-level PC threat, particularly if you use basic precautions about interacting with advertisements delivered via Bizzybolt. Nevertheless, PUPs like Bizzybolt almost always should be removed to keep your browser safe and to optimize its performance as much as possible. Most competent brands of anti-malware programs should be more than able to remove Bizzybolt easily, although updating their databases may be needed to guarantee accuracy.

New brands of adware add-ons are very common, and Bizzybolt is only one of many similar PUPs. Unless given a compelling reason for doing otherwise, you usually should be treating any adware similar to Bizzybolt with the same suspicion. Other adware also hailing from Bizzybolt's developers include BrowseSmart, Storimbo, WonderBrowse, Illoxum and Bizzybolt. Windows browsers are at the greatest risk of being modified by Bizzybolt and related adware programs, although malware researchers also must emphasize that adware has been seen affecting other OSes in smaller numbers.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{13070af0-bc6c-4185-8baa-40a4cf05b323}{4BEF58BF-540C-4353-AC56-466B1D97000B}{8CC59D63-7206-4488-8980-742C1F52E86E}HKEY..\..\..\..{RegistryKeys}Software\BizzyboltSoftware\Microsoft\Internet Explorer\Approved Extensions\{13070af0-bc6c-4185-8baa-40a4cf05b323}SOFTWARE\Microsoft\Tracing\updateBizzybolt_RASAPI32SOFTWARE\Microsoft\Tracing\updateBizzybolt_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{13070af0-bc6c-4185-8baa-40a4cf05b323}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{13070AF0-BC6C-4185-8BAA-40A4CF05B323}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{13070AF0-BC6C-4185-8BAA-40A4CF05B323}SOFTWARE\Wow6432Node\BizzyboltSOFTWARE\Wow6432Node\Microsoft\Tracing\updateBizzybolt_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateBizzybolt_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{13070af0-bc6c-4185-8baa-40a4cf05b323}SYSTEM\ControlSet001\services\eventlog\Application\Update BizzyboltSYSTEM\ControlSet001\services\Update BizzyboltSYSTEM\ControlSet001\Services\Util BizzyboltSYSTEM\ControlSet002\Services\Util BizzyboltSYSTEM\CurrentControlSet\services\eventlog\Application\Update BizzyboltSYSTEM\CurrentControlSet\services\Update BizzyboltSYSTEM\CurrentControlSet\Services\Util BizzyboltHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Bizzybolt

Additional Information

The following directories were created:
%ProgramFiles%\Bizzybolt%ProgramFiles(x86)%\Bizzybolt
The following URL's were detected:
Bizzybolt
Loading...