1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

CoolWebSearch browser hijacker

Discussion in 'Security and Privacy' started by albatros, 2004/06/26.

Thread Status:
Not open for further replies.
  1. 2004/06/26
    albatros

    albatros Inactive Thread Starter

    Joined:
    2004/04/17
    Messages:
    58
    Likes Received:
    0
  2. 2004/06/26
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0

  3. to hide this advert.

  4. 2004/06/26
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    Albatros, you need to understand the creators of CoolWebSearch are constantly changing their tactics of infecting, mostly due to Merijin, the creator of the CWShredder.
    The creators of CoolWebSearch are in it for the money, how they get it it, I do not know. They do not seem to care what their product does to the perfomance of your system.
    Merijin, the creator of CWShredder, is not in it for the money, although he does welcome donations. He does care about the performance of your system, and does not want to put something out that may damage your system while fixing it.
    You do have to applaud him for the work he has done, as it is not easy reverse engineering a compiled program, you do not get the original source code doing this. In short, he is looking for cause and effect.
     
  5. 2004/06/28
    albatros

    albatros Inactive Thread Starter

    Joined:
    2004/04/17
    Messages:
    58
    Likes Received:
    0
    markp62, I completely agree; and I also approve the Merijin work, of course. But a little bit closer to mine question- does someone know how the CWS is distributed?
     
  6. 2004/06/28
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    My first guess would be through drive-by DPF's. Second would be scripted web pages and third would be questionable downloads. :)
     
  7. 2004/06/28
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
  8. 2004/06/28
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    There is no specific answer to your question, there are several ways to accomplish this.
    Read post #6 in the link.
    http://www.windowsbbs.com/showthread.php?t=31535
    About the link that Welshjim provided, do you have a specific question?
     
  9. 2004/06/29
    albatros

    albatros Inactive Thread Starter

    Joined:
    2004/04/17
    Messages:
    58
    Likes Received:
    0
    Yes, the link Welshjim provide is much closer.
    Just not clear still where do located this hijackers web pages the CWS installs from. Some peoples say CWS installs from such advertisers as www.approvedlinks.com
     
  10. 2004/06/29
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    That seems to be one of them, that site is Restricted in my browser.
    So you are looking for the sites that do this? The best I could do is suggest the IEspyads.Zip file, it contains a few thousand of them. The link is below.
     
  11. 2004/06/30
    albatros

    albatros Inactive Thread Starter

    Joined:
    2004/04/17
    Messages:
    58
    Likes Received:
    0
    It seems, the CWS installs not from that site directly, but from some affiliated sites. Which? How to add site to Restricted in IE browser?
     
  12. 2004/06/30
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    If you install IESpyads you won't need to add it to the resticted sites.
     
  13. 2004/07/01
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    If you install the IEspyads.Reg [double click on it] file included in the download, it doesn't matter if you are directly on the webpage, as I stated in my previous post, or an affiliated site is included on a website you are at.
    In the first case, when I was directly at the site, in the lower right corner where it normally says Internet, it said Restricted instead.
    In a case where one of the websites in the Restricted Zone appears in a webpage as an affiliated site, it will say Unknown [Mixed] instead.
    Just do a Custom configuration of the Restricted Zone. Set everything to Disable, if Disable is not available as an option choose High, set password to Prompt, and these sites will not be able to put so much as a cookie on you.
    When you install the file correctly, you will be prompted if you want to merge this information into the registry, yes you do, then a confirmation message will appear.
     
  14. 2004/07/01
    albatros

    albatros Inactive Thread Starter

    Joined:
    2004/04/17
    Messages:
    58
    Likes Received:
    0
    I mean for standard IE configuration, I have no IESpyads installed.
     
  15. 2004/07/01
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    albatros--
    Well, you can set up your own customized Restricted Sites list (see below), but why bother when IESpyAds will do the work for you? (I think there are over 2000 websites in IESpyAds.) You get IESpyAds here
    https://netfiles.uiuc.edu/ehowes/www/resource.htm
    The only downside is that you may want to use ActiveX, scripting, etc. on some of those sites. When that happens you can always remove the site from Restricted Sites.
    Here is how to set up Restricted Sites manually
    http://www.infinisource.com/techfiles/surf-safe.html
    Note the Power Tweak Web Accessory offered. Could help simplify the job.

    P.S. to Markp62--Your link to IESpyAds is old. It will redirect, but the new one is above.
     
  16. 2004/07/02
    albatros

    albatros Inactive Thread Starter

    Joined:
    2004/04/17
    Messages:
    58
    Likes Received:
    0
    Probably someone who has infected by CWS recently, can look at IE history and define from what page exactly he has got infection?
     
  17. 2004/07/02
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    albatros - this might go a little quicker if we had a better idea of what you are after.
     
  18. 2004/07/03
    albatros

    albatros Inactive Thread Starter

    Joined:
    2004/04/17
    Messages:
    58
    Likes Received:
    0
    I mean if we shall define the exact address, we could investigate a method which it uses, and it would enable to struggle not with CWS versions(which constantly changes, therefore it's inefficient), but we can block the reason. As a variant, probably we could to attack and destroy some of this sites.
     
  19. 2004/07/03
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    albatros--You have a good idea. From History you can see where you have surfed and when. But I unless you can pinpoint the exact time you got the CWS malware, how can you use the History info? Maybe a right click|Properties on a CWS malware file (like a .exe or .dll) can provide that info??
     
  20. 2004/07/06
    albatros

    albatros Inactive Thread Starter

    Joined:
    2004/04/17
    Messages:
    58
    Likes Received:
    0
    Of course, it will be better if know exact time as well. Most probably, it installs from **** sites.
     
  21. 2004/07/06
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Here's a way you can check for CWS domains. Create a shortcut on the desktop to CWShredder, right click the shortcut and choose properties. In the 'target' box, add a space then /debug and apply. Now open CWS from the shortcut. From the history, right click and properties of a site, copy the URL then paste it in the CWS box. Remove the http://

    You can also check this site.

    http://www.spywareinfo.com/~merijn/junk/cws_domains.txt
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.