Unsolved
This post is more than 5 years old
2 Intern
•
3.9K Posts
0
7500
January 15th, 2004 19:00
New CWS infection - Please read
Email just received from tomcoyotes/spywareinfo
----------------------------------------------
This is to inform that there is a version of CWS going around that will block your access to anti-spyware sites
This the email I posted about a few moments ago to all members of this board so that you know what to do in order to regain control over this problem
Pass this information on to your friends as they may not be able to get here without your help
------------
Written By Galadriel:
Are you having difficulty accessing security-related websites ?
You could have been hit by one of the latest hosts file scam by the Not-Coolwebsearch people...
Easy enough to fix this.
Get this program called Hosts File Reader. It will show the hosts file wherever it is located.
http://members.shaw.ca/techcd/VB_Projects/HostsFileReader.exe
Run the program and look at the bottom part of the window, if an entry is there, double click it.
You should see the contents of that file appear in the top part of the window. You can then change, delete, append, do what you want to the file using that utility.
If you do not consciously use a hosts file, you can choose to delete it. If you do use a hosts file, then you probably know how to deal with the entries listed.
If you aren't sure, there is the "Enable/Disable" function you can use. Disabling, will backup the current hosts and create a new default one. By doing this, you should be able to access those sites again.
Thanks
Tom Coyote Wilson
http://TomCoyote.org
May your day be blessed by those you love, and those you love be blessed by
HIM :-)
The current (partial) list of sites blocked by this latest malicious hosts file is:
forums.spywareinfo.com
www.spywareinfo.com
www.merijn.org
merijn.org
spywareinfo.com
www.computercops.biz
computercops.biz
dslreports.com
www.dslreports.com
www.lavasoftsupport.com
lavasoftsupport.com
forums.net-integration.net
www.tomcoyote.org
tomcoyote.org
www.wilderssecurity.com
wilderssecurity.com
www.lavasoftusa.com
lavasoftusa.com
security.kolla.de
www.security.kolla.de
www.lavasoft.de
lavasoft.de
Message Edited by ChrisRLG on 01-15-2004 09:42 PM


ChrisRLG
2 Intern
•
3.9K Posts
0
January 15th, 2004 20:00
From this Link http://forums.spywareinfo.com/index.php?showtopic=11139
Mike (Of spwareinfo)
The people who distribute the coolwebsearch.com trojan have added SpywareInfo and Lavasoft's support site to victims' HOSTS files in a vain attempt to prevent their victims from receiving assistance in removing the trojan.
Specifically, spywareinfo.com, www.spywareinfo.com, lavasoftsupport.com, and www.lavasoftsupport.com are redirected to a porn site on infected machines.
The official addresses for HijackThis and CWShredder are
http://www.merijn.org/files/cwshredder.zip and
http://www.merijn.org/files/HijackThis.exe
If you or someone you are helping elsewhere are blocked from this site, you can use these alternate addresses to download the file. These addresses are immune to HOSTS file hijacks.
http://216.180.233.153/~merijn/files/hijackthis.zip
http://216.180.233.153/~merijn/files/cwshredder.zip
http://216.180.233.153/~merijn/
YoKenny
363 Posts
0
January 21st, 2004 15:00
http://www.safer-networking.org/index.php?page=news
CoolWWWSearch.SmartKiller (v1 and v2) is a new, real ugly variant of CoolWWWSearch. When running, it will close every browser window you use to visit a large list of anti-spyware-sites, and even will close Spybot-S&D and some other anti-spyware applications as well.
So if your copy of Spybot-S&D (or the anti-spyware application of your choice) closes a few seconds after starting, or your browser closes whenever you try to visit an anti-spyware site, check our CWS.SmartKiller removal utility on this page.
amurauna
1 Message
0
February 24th, 2004 17:00
actually, I am trying to help someone who has these issues on her computer she had a list of 8 viruses trojans and vbs, which all seemed to be intertwined within each other as some of them were hidden and after deleting the files not hidden, they would regenerate ... she had cd drives opening and closing and popups further than the eye could see ..
if it helps what I found were as followed ..
troj esepor.b c:\windows\systems\tksrv98.exe
troj esepor.b c:\windows\systems\tmksrvu.exe
troj esepor.b c:\windows\systems\xplugin.dll
vbs zerolin.a
vbs zerolin.a c:\windows\explore.exe
troj winpup.b c:\program files\over.exe
troj femad.l c:\cscsfrphswc.exe
troj winpup.b C:\do.exe
I deleted the files that were shown however, I'm sure her registry is a mess..
I tried the links that you listed:
http://216.180.233.153/~merijn/files/hijackthis.zip
http://216.180.233.153/~merijn/files/cwshredder.zip
http://216.180.233.153/~merijn/
and from her computer wasn't able to gain access to those either. I had cwshredder.exe on her computer previously and apparently it had been removed. Every site that I tried came back with no result and every search ended the same as well.
When I knew it was really bad was when I tried to get to the microsoft site and couldn't reach that either.
I was able to run hijackthis.exe, spybot s&d, and adaware 6.0 however these all came back "clean".
I went in an manually deleted each of those files and did searches for files with the vbs extension however there are still a couple that are in the temperary internet folder under the content ie folder which I can't delete. I get that access is denied.
Apparently a friend sent her a link to a video on a message board and when she clicked the link is when she was first attacked by the popups.
I'm hoping that I will be able to burn all these programs on a disc and use them over there, but I'm thinking I may have to go old school on this and put everything on a floppy and go in under safe mode.
Thank you so much for this at least have given me hope that it's not just me going insane. I'll keep you updated if infact this works.
Temerc
63 Posts
0
February 24th, 2004 18:00
FYI, those sites you listed are srill down due to a DDoS attack. They hope to be up soon, but theres no time frame so far for theire return. Follow this link to read more about it.
http://forums.net-integration.net/index.php?showtopic=10803&st=165&hl=
ChrisRLG
2 Intern
•
3.9K Posts
0
February 24th, 2004 18:00
Links to a mirror, download section of this website
www.zerosrealm.com
Message Edited by ChrisRLG on 02-24-2004 08:51 PM