Browser hijacking

  • Thread starter Thread starter Alan
  • Start date Start date
A

Alan

Having done a recent reinstall of 98/IE5 (and probably forgetting to
baton down something or other) I find that I'm being hijacked by
(non-existent?) search engines like hi-search, bb-search... It appears
these all emanate from a parasitic site called coolwebsite or something.
None of the checkers I have picked up this activity. Can anyone
recommend something that will?

I have just d/l a freeware app called Hijack This
http://tomcoyote.org/hjt/ to try to hunt this down. It may be of
interest to others. Anyone had any experience with it?
 
Having done a recent reinstall of 98/IE5 (and probably forgetting to
baton down something or other) I find that I'm being hijacked by
(non-existent?) search engines like hi-search, bb-search... It appears
these all emanate from a parasitic site called coolwebsite or something.
None of the checkers I have picked up this activity. Can anyone
recommend something that will?

I have just d/l a freeware app called Hijack This
http://tomcoyote.org/hjt/ to try to hunt this down. It may be of
interest to others. Anyone had any experience with it?

It works well, I was hit with a particularly nasty browser hijack. The
pornmeisters somehow hijacked my browser via the hosts file and Hijack This
was the only app. that tracked down and eliminated the problem.
 
Alan said:
Having done a recent reinstall of 98/IE5 (and probably forgetting to
baton down something or other) I find that I'm being hijacked by
(non-existent?) search engines like hi-search, bb-search... It appears
these all emanate from a parasitic site called coolwebsite or
something. None of the checkers I have picked up this activity. Can
anyone recommend something that will?

I have just d/l a freeware app called Hijack This
http://tomcoyote.org/hjt/ to try to hunt this down. It may be of
interest to others. Anyone had any experience with it?

Get and unpack the following and run the CWShredder.exe.
http://www.spywareinfo.com/~merijn/files/cwshredder.zip

Read about it.
http://www.spywareinfo.com/~merijn/cwschronicles.html

NOTE: if you can not get to these sites then your HOSTS file has been
hijacked as well. See the following about HOSTS file.

Get and update SpyBot Search and Destroy through its online update function.
http://tomcoyote.org/SPYBOT/

Ad-Aware is also a good "adware" remover.
http://www.lavasoftusa.com/support/download/

Get a good HOSTS file to stop theses nasties.
http://www.mvps.org/winhelp2002/hosts.htm

SpywareBlaster also stops these nasties.
http://www.javacoolsoftware.com/spywareblaster.html

Keep these things up to date as new nasties come along just like
viruses/worms.

This stuff is discussed in alt.privacy.spyware.
 
Hi Alan - This has been showing up a lot lately and seems to be caused by
some malware called CoolWebSearch. Do the following:

Download and run: http://www.spywareinfo.com/~merijn/files/cwshredder.zip
to remove the parasite
Then download and run:
http://www.kellys-korner-xp.com/regs_edits/iegentabs.reg to restore your
tabs and remove any restrictions that the parasite has put in place.

However, this also indicates that you may have acquired some other malware
along the way. If you go to this page at Jim Eshelman's site, here:
http://aumha.org/a/noads.htm and wait a little bit (be patient), an
analysis of a number of possible parasites on your machine will be made to
help you identify and remove them. NOTE: You will need to disable Ad
Blocking in Zone Alarm 3.x, if present or any other Ad Blocking software
which interferes with Java Scripting for this scan to work. You should get a
message between the two lines of **** giving the results of the scan.

Get Ad-Aware 6.0, Build 181 or later, here:
http://www.lavasoftusa.com/support/download/. Update and run this regularly
to get rid of most "spyware/hijackware" on your machine. If it has to fix
things, be sure to re-boot and rerun AdAware again and repeat this cycle
until you get a clean scan. The reason is that it may have to remove
things which are currently "in use" before it can then clean up others.

Another excellent program for this purpose is SpyBot Search and Destroy
available here: http://security.kolla.de/ SpyBot Support Forum here:
http://www.net-integration.net/cgi-bin/forums/ikonboard.cgi. I recommend
using both normally. After fixing things with SpyBot S&D, be sure to
re-boot and rerun SpyBot again and repeat this cycle until you get a clean
"no red" scan. The reason is that SpyBot sometimes has to remove things
which are currently "in use" before it can then clean up others.

Note that sometimes you need to make a judgement call about what these
programs report as spyware. See here, for example:
http://www.imilly.com/alexa.htm


Try these steps first, then if you still have difficulties, please post
back.

--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
 
I found the cwshredder by doing a google search for coolwebsearch. It
seems to have done the trick. Many props to the guys out there working
to protect us from evil scumbags.
 
Having done a recent reinstall of 98/IE5 (and probably forgetting to
baton down something or other) I find that I'm being hijacked by
(non-existent?) search engines like hi-search, bb-search... It appears
these all emanate from a parasitic site called coolwebsite or something.
None of the checkers I have picked up this activity. Can anyone
recommend something that will?

Your biggest problem is that you are running a hopelessly outdated,
many times compromised version of IE.

If you must continue to run IE, at least upgrade to IE6 SP1.

Or do yourself a real favor, and ditch it for Mozilla Firebird.
 
-----BEGIN PGP SIGNED MESSAGE-----
Having done a recent reinstall of 98/IE5 (and probably forgetting to
baton down something or other) I find that I'm being hijacked by
(non-existent?) search engines like hi-search, bb-search... It appears
these all emanate from a parasitic site called coolwebsite or something.

Visit windowsupdate.microsoft.com and download all updates available,
including Internet Explorer 6.0 with all updates for it. That will do
wonders, stops almost all spyware and other parasites attacking your
computer.

-----BEGIN PGP SIGNATURE-----
Version: PGP for Business Security 6.0

iQEVAwUBP2h5G9qdjtC5IgZHAQEJnwf/R8tv4l5RJdHhjLq2y1aPZ4xHpGu/L9aj
XFv0k8fAjs3QUHsJCHPPaC2pNjMJeBM0UgEe1VosmJ0+CDuFAtP5VpYHLbA6h4/P
AYeBLxKijzYPZAdW1Han4/BkzAF43gZZDlPvb1Hch713zaN1+3XczAYu1exz7+Km
M+2ROwnQRDNB5wPVvANOXB7bi8aUkmHI6mS2gx9hbo5tt3MM1RQQ7A2Qe8gqpcPY
Jzgrn9OZI15ecIsQcox2GiCndlo+dvUHUHD+lTCoETJ+Z7h3fBa8I3ig+UTWPkAb
rorhwgozpqy+R3IXpZY1iAJ4pVF0qfWP47WhhzfC1teYW6GA2yRMEw==
=xo7D
-----END PGP SIGNATURE-----
 
Alan said:
Having done a recent reinstall of 98/IE5 (and probably forgetting to
baton down something or other) I find that I'm being hijacked by
(non-existent?) search engines like hi-search, bb-search... It appears
these all emanate from a parasitic site called coolwebsite or
something. None of the checkers I have picked up this activity. Can
anyone recommend something that will?

I have just d/l a freeware app called Hijack This
http://tomcoyote.org/hjt/ to try to hunt this down. It may be of
interest to others. Anyone had any experience with it?

Thanks to all who replied with useful suggestions. Turns out it was all
in the hosts file, which is now nuked, so all is well. I've taken
onboard some of the other useful utils mentioned too. The Hijack This
util does its job very well, although I discover (after the event) that
Spybot S&D will show the hosts content, but not alert to anything
untoward AFAIK.
 
donut said:
Your biggest problem is that you are running a hopelessly outdated,
many times compromised version of IE.

If you must continue to run IE, at least upgrade to IE6 SP1.

Or do yourself a real favor, and ditch it for Mozilla Firebird.

Thanks, but I don't really relish service packs etc. as a desirable way
to go. It was my own laxity/haste that allowed me to become hit, diving
onto the net before I'd set security appropriately. Since then I've done
my custom tweaks and deleted the (whopping 20K) hosts file... talk about
slowing things down... and I'm back to secured status now. Complacency
got the better of me I'm afraid, but it served as a good indicator of
just how much crap there is out there nowadays.
 
Thanks, but I don't really relish service packs etc. as a desirable way
to go. It was my own laxity/haste that allowed me to become hit, diving
onto the net before I'd set security appropriately. Since then I've done
my custom tweaks and deleted the (whopping 20K) hosts file... talk about
slowing things down... and I'm back to secured status now. Complacency
got the better of me I'm afraid, but it served as a good indicator of
just how much crap there is out there nowadays.

I mention this so often, I've lost track if I have mentioned
it to you. CoolWebSearch is spyware.

Get and unpack the following and run the CWShredder.exe.
http://www.spywareinfo.com/~merijn/files/cwshredder.zip
Read about it.
http://www.spywareinfo.com/~merijn/cwschronicles.html

Also your hosts may have been hijacked. I run a 580k hosts
and have no slowdown.

I'll second Firebird. I only use IE 6.0 for MS updates for
my wife's computer. I don't update my IE 6.0, for comparison
purposes and since I use Firebird instead.

IE 6.0 by itself doesn't stop squat unless dumbed down correctly.
SpywareBlaster doesn't scan and clean for spyware - it prevents
it from ever being installed. Adaware and other cleaners never
find a thing.
http://www.wilderssecurity.net/spywareblaster.html

MS has protection suggestions:
http://www.microsoft.com/security/protect/

Another goody:
http://www.spywareinfo.com/~merijn/files/hijackthis.zip

HTH,

BoB
 
I mention this so often, I've lost track if I have mentioned
it to you. CoolWebSearch is spyware.

Get and unpack the following and run the CWShredder.exe.
http://www.spywareinfo.com/~merijn/files/cwshredder.zip
Read about it.
http://www.spywareinfo.com/~merijn/cwschronicles.html

Also your hosts may have been hijacked. I run a 580k hosts
and have no slowdown.

I'll second Firebird. I only use IE 6.0 for MS updates for
my wife's computer. I don't update my IE 6.0, for comparison
purposes and since I use Firebird instead.

IE 6.0 by itself doesn't stop squat unless dumbed down correctly.
SpywareBlaster doesn't scan and clean for spyware - it prevents
it from ever being installed. Adaware and other cleaners never
find a thing.
http://www.wilderssecurity.net/spywareblaster.html

MS has protection suggestions:
http://www.microsoft.com/security/protect/

Another goody:
http://www.spywareinfo.com/~merijn/files/hijackthis.zip

HTH,

BoB
I run a 27MB (yes MegaByte) HOSTS file. No slow down yet that I can
see. (obviously there is some kind of slowdown versus NO hosts file
but not appreciable.
 
Get and unpack the following and run the CWShredder.exe.
http://www.spywareinfo.com/~merijn/files/cwshredder.zip
Read about it.
http://www.spywareinfo.com/~merijn/cwschronicles.html

Also your hosts may have been hijacked. I run a 580k hosts
and have no slowdown.

According to the latest SpywareInfo newsletter, Spywareinfo.com has
been added to the list of sites that CoolWebSearch blocks via the host
file. If you are not able to get to those links, try these which will
not be affected by hosts file hijacking..

http://216.180.252.218/~spywareinfo.com/downloads/tools/hijackthis.zip
http://216.180.252.218/~spywareinfo.com/downloads/tools/cwshredder.zip



_________
Suzanne
 
Hi Ozzy - Normally I pretty much just monitor these threads after I've
posted what I think might contribute unless I see something factually wrong
or dangerous posted, but in this case I just can't resist. What on earth do
you manage to find to put into a HOSTS file that bulks 25 MB?!!! :) With
all of my 2600+ Favorites and a pretty major list of malware/adware
parasites (from http://www.mvps.org/winhelp2002/hosts.htm), mine's only 210
KB when I have it turned on. I'm really curious if you wouldn't mind
explaining. Thanks.

--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
 
BoB said:
I mention this so often, I've lost track if I have mentioned
it to you. CoolWebSearch is spyware.

I don't recall seeing it before this happened, either specifically "for
me" or in ACF generally. I'm sure it must have been mentioned, as you
say, but having been previously well protected (before reinstall) I
usually just skim over posts about spyware - save only to take a mental
note of potential offenders.

Thanks. Done that, among other things, and it seems to have cleaned
things up.
Also your hosts may have been hijacked. I run a 580k hosts
and have no slowdown.

The perceived "slowdown" may depend very much upon your system. A
colleague and I did some fairly extensive test runs on hosts "blocking"
vs. that of another method and obtained some results that really turned
me off using hosts for this purpose.
I'll second Firebird. I only use IE 6.0 for MS updates for
my wife's computer. I don't update my IE 6.0, for comparison
purposes and since I use Firebird instead.

IE 6.0 by itself doesn't stop squat unless dumbed down correctly.
SpywareBlaster doesn't scan and clean for spyware - it prevents
it from ever being installed. Adaware and other cleaners never
find a thing.
http://www.wilderssecurity.net/spywareblaster.html

MS has protection suggestions:
http://www.microsoft.com/security/protect/

Haven't seen this one... mosying over thar now.

Yep, that's the one I started off the thread with. :) Nice little
purpose-built app.

Thanks for the info.
 
Hi Ozzy - Normally I pretty much just monitor these threads after I've
posted what I think might contribute unless I see something factually wrong
or dangerous posted, but in this case I just can't resist. What on earth do
you manage to find to put into a HOSTS file that bulks 25 MB?!!! :) With
all of my 2600+ Favorites and a pretty major list of malware/adware
parasites (from http://www.mvps.org/winhelp2002/hosts.htm), mine's only 210
KB when I have it turned on. I'm really curious if you wouldn't mind
explaining. Thanks.

Sorry about the late reply. Been busy coding & patching openSSH fixes.

Well, Jim, my list has grown somewhat over the last 27+ years :)

Days where PDP-11, Z80's, 6502's(KIM), 6809's, etc were all the rave &
are now probably meaningless & unknown to many on these forums :)

I started a list back in my early days (50-300 baud) of everyone I had
any dealings with. Mostly Fido, university addresses, bbs numbers, etc
and kept it documented for my later perusal (& memory jogging) &
reference when someone else needed a contact number or address of the
best location of 'core wars' or some such abstract util.

As years passed, the file grew, for different reasons & not what the
list was originally intended for. Around the 80's I found the
proliferation of spammers & sites with embedded porn rising at an
alarming exponential rate. So did my list. It was only around ~2 MB at
that time, if memory serves me correctly. At that time, it wasn't too
hard to go back & re-verify some sites & see if they had cleaned up.
Invariably, I only found a new owner but the same garbage. I was
positive that something was going to 'give' on my computer. Surely
something would blow up or crash.... But it never did, much to my
amazement at that time.

I have been using SPEWS & other such lists for quite some time now.
Long before the general public even knew about *spam*. Some people
have been in the SPEWS list for many years & it's not easy to get
unlisted. Some say that they will have to wait till our sun goes dim
before they get unlisted :) People in my list aren't that lucky. In
100 trillion years I should be up to v2.01 of my list but they will
still be listed. My list is co-shared with others & I do use the list
from http://www.mvps.org in mine.

Yes, my list has grown & gotten out of hand... a bit. I've been
meaning to weed out the old contacts & addresses for a while now. Been
planning to re-visit each site & test for updates. Been saying that
now for 8 years :( I have just too many projects, etc on the go & no
time. Some day...maybe. I average about 60-130 valid emails a day! All
referring to projects or coding that I am involved with. If I could
find a way to cram 96 hours into each day, I might be caught up by
2028.

Many have asked why I don't code a routine to do all this for me while
I sleep? (yes, I make time for that) Sounds simple but in fact it is
not. I have to physically check each website to 'see' what is on each
page & examine their TOS, AUP & privacy policies. I have several other
trusted people & sources that do a lot of this for me & their results
get added to my list. You have to remember now, Osama & Sadamm have a
better chance of becoming President of the USA than someone getting
off my list.

Others have told me that their hosts file is ~2 MB. Others tell me
they know some having GB lists. Now IMO, GB lists are truly huge. I
hope mine will never reach that size.

Hope this may shed some insight.
 
Thanks Ozzy for the insight. You're likely already familiar with it, but if
not, you might find CIP, free, here which will check your HOSTS file and/or
check and then save Favorites to your HOSTS file (for high speed local DNS
checks):
http://www.webattack.com/php/download.php?id=100774&app=cipfree&r=l useful
in trying to clean up your list. It allows you to "clean up" unfound
entries, for example. (Be careful with this one )

--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
 
Thanks Ozzy for the insight. You're likely already familiar with it, but if
not, you might find CIP, free, here which will check your HOSTS file and/or
check and then save Favorites to your HOSTS file (for high speed local DNS
checks):
http://www.webattack.com/php/download.php?id=100774&app=cipfree&r=l useful
in trying to clean up your list. It allows you to "clean up" unfound
entries, for example. (Be careful with this one )

Jim, thanks but CIP has been pointed out before & in my case it is
very dangerous to use.

I DON'T want ANY contact with the IP's listed in my hosts file. It is
a blocking list, not an accept list. I DO NOT want my IP address
showing up anywhere near these sites :) CIP has to go out & physically
poll the site... something I will not allow. They're in the list for a
reason.

I must not have made that clear in my previous ramble. Sorry, my
fault.
 
Get and unpack the following and run the CWShredder.exe.
http://www.spywareinfo.com/~merijn/files/cwshredder.zip

Read about it.
http://www.spywareinfo.com/~merijn/cwschronicles.html

NOTE: if you can not get to these sites then your HOSTS file has been
hijacked as well. See the following about HOSTS file.
Not necessarily. My HOSTS file listed them under 208.251.150.135, where
they were at some point, but not anymore. A fresh bookmarks/favourites-
address-resolve (or whatever it is called) should cure this.

btw, "127.0.0.1 sitefinder.verisign.com" DEFINATELY belongs in every HOSTS
file.
 
Back
Top