Leupold BX-4 Rangefinding Binoculars

CWS trojan, evil stuff dont get it but if ya do..

feclnogn

New member
Joined
Dec 11, 2000
Messages
802
Location
next to the rock over by the tree on the other sid
I thought I would let you guys know about an evil trojan that is transmitted by popups and not email to your machine. I just spent the last two days trying to figure out how to get rid of it. I just got a new computer on Wednesday and two days later (friday) had it infected. Here is some info from another forum

there are now nearly 10,000 Coolwebsearch affiliates!
They do this as a "Pay-per-Click" scheme, basically getting a few cents for each user that gets hijacked to Coolwebsearch or one of it's major affiliates. Nice guys huh? Most of these affiliates are Adult related, so be careful where you surf and practice Safe Hex!
One of the newer tricks Coolwebsearch uses is to block the infected user from accessing most major anti-spyware programs and sites. Download: CWS.SmartKiller from SpyBot S&D. If you can not access Merijn.org or you get redirected, use the direct IP address instead, this bypasses the HOSTS file hijack. Download: [HijackThis] [CWShredder]

This trojan messes up your reg files in IE and sets your homepage to one of the cool web search affiliates. It also places about 50 shortcuts to websites in your favorites folder and if you delete them they come right back. This trojan also blocks you from going to websites that have the software to fix it. It opens up a window that says access denied or it just opens up a blank page.

I hooked up my old computer and went to this link

http://www.spywareinfo.com/~merijn/downloads.html

I would recomend downloading the CWS shredder app if for future use you need it. Better to have it and not need it. If you do get this trojan you will not be able to download the software.

here is some more info copy and pasted from the above line


<BLOCKQUOTE>quote:</font><HR> This is an article which details the variants of the browser hijacker known as CoolWebSearch (CWS). In the last few months, the people behind this name have succeeded in becoming (IMHO) an even bigger nuisance than the now infamous Lop.

The difficulty of removing CWS from a user's system has grown from slightly tricky in the first variant to virtually impossible for the latest few. Some of the variants even used methods of hiding and running themselves that had never been used before in any other spyware strains.

The chronological order in which the CWS variants appeared is detailed here, along with the approximate dates when they appeared online. However, since the evil programmers of CWS have released over two dozen versions of their hijacker on the advertising market in such a short time, and are crunching out new ones steadily practically every week, this document might be out of date at times.

The CWShredder tool to remove Coolwebsearch will always be up to date and is updated as fast as possible when new variants emerge.<HR></BLOCKQUOTE>

<FONT COLOR="#800080" SIZE="1">[ 01-31-2004 12:13: Message edited by: feclnogn ]</font>
 
Seems that the FCC would be very interested in this unethical method of getting attention. I think that propagators or viruses, adware, worms, and trojans are just another form of terrorism and should be dealt with as such.

I've been an advocate of Spybot Search and Distroy since in a comparison test, it (A freebie) blew the doors off a $79 program! I recommended it to a business associate who complained that her computer was acting up and slower than the hubs of Hades. Her kids frequented the music download sites, and from what she described, I knew she was chock full of adware. She called me the day after I suggested that she download SS&D to tell me that I was now her and her husband's hero for passing the info along. Saved them a trip to the computer shop.

Hey, you know me...I talk too much, but love to help people out!
elkgrin.gif


<FONT COLOR="#800080" SIZE="1">[ 01-31-2004 14:05: Message edited by: RogueWarrior1957 ]</font>
 
Thanks boys!! Three days I been trying to track the source of a program that was creating and naming a new program and causing it to execute at startup every day. Guess what; Found it!!
biggrin.gif
 
I got hit with one of those, It took awhile to find the file but find it I did.
It was named "iefeatures".
I had all kinds of wierd stuff
xxx tool bars, new home page, 10 gazillion pop ups that my pop up blocker wouldn't block, a bunch of new favorites that would magically reappear. And 8 viruses that nortons would catch each time you logged on to the net, or restarted the pc. You would delete them, and the next log on they would be back, what a pain
mad.gif

I couldn't delete or uninstall the file so I used nortons wipe to get rid of it.
After it was wiped I was able to get rid of all the rest of the crap and it didn't magically reappear
biggrin.gif


<FONT COLOR="#800080" SIZE="1">[ 01-31-2004 21:38: Message edited by: michaelr ]</font>
 
michaelr,

Down load the cwsshredder app and run it. It takes about 10 seconds to sweep your computer. I ran Norton and it took out a bunch of the problems but some persisted. When I ran CWSshredder it found 22 different file paths
eek.gif
eek.gif
You might be surprised at what you find.

Some one should shoot these idiots that sit around and figure out how to screw up some ones computer.
mad.gif
mad.gif


S.FECl
 
The sad thing is, 90% of the hackers and virus script writers are under the age of 25, and a good 75% are under the age of 20.
eek.gif
When I was that age I had far better things on my mind than screwing up poor ol' Bubba's computer (no offense meant to any Bubba's out there).

I can't remember where I read that statistic, but it shocked me at first. I mean, whatever happened to hotrods, girlfriends, and all that kind of stuff? Whatever happened to the geeks of our day whose objective was to save the world...not distroy it.

As I've said before...I guess I'm getting old!
 
No Scotty; so far the one thing the cats haven't destroyed is the puter. The neighbor did dupm a coke on the video card once! Cats were blamed until I tore it apart.
eek.gif
(I'd have killed her if she weren't so damned cute!)
wink.gif
 
Discovered the source of our CWS infection. A Black Hills Gold outfit at Golddiggers.com. Thought you guys would like to know.
smile.gif
 
Back
Top