Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

HIJACK! (No, not THAT kind!)
various | Today | Me

Posted on 06/05/2004 8:06:55 PM PDT by Long Cut

You may have heard of this lately, or perhaps have had it happen to you. That's right...your internet browser gets hijacked. Taken from your control, as it were.

It takes you to sites you would never have visited in a million years; your computer slows down and maybe crashes; your homepage is mysteriously changed; you now have about a dozen "favorites" that you never selected and don't want.

You've been HIJACKED!

What happened? How? You ask, as you pull your hair out in disgust.

Well, it happened to me,, and some FReepers I know, and a LOT of my friends, lately. I've been hearing scuttlebutt around the Web, and around the water cooler. People's computers are being taken over by insidious, rotten spyware and malware that effectively seizes control and can have serious reperussions for the user.

These things download some particularly nasty porn, even child porn, to a computer. People have been fired, investigated, and disgraced for something they never did.

I discovered mine one day whil, of all things, trying to access FR. I mistyped the URL, and found myself redirected to some porn search engine. Massive popups overwhelmed my Pop-up Stopper, and froze my computer.

After the reboot, I ran my McAffie antivirus, which quickly crashed the system and failed to ever work again. Ad-Aware removed some registry keys and values, and I thought all was well.

Wrong. It happened again.

Now, I got serious. I obtained Symantec Pro version, and ran it. It caught several more bugs, but some couldn't be quarantined OR removed.

I was in a fix. I was using a computer that FReeper thumperusn had graciously loaned me, and I didn't want to give it back to him all jacked up. Thus began my battle with the Internet demon known as "CoolWebSearch".

I went to sites like Spywareguide.com, Spywareinfo.com,, and Symantec's excellent site, and educated myself about CWS. It's a mean one.

With over 25 versions to date, and about 30 affiliated sites, CWS has infected millions of computers to date. It uses a "hole" in JavaScript Virtual Machine to invade your machine and make changes to IE and your registry. It also copies itself to your "restore" files, which the antivirus and anti-spyware programs DO NOT search or modify.

After educating myself, and wading through literally hundreds of pages of "geek-speak", I formed a plan of attack.

PROTECTION

First, I would fix the holes in my system. The borrowed laptop used Windows Me, from 2000. It needed updating, and MS's website had a whole bunch of them. Since I'm on a dialup, it took hours to download and install all the patches.

Next, some firewalls. At Major Geeks.com, I found and downloaded Zone Alarm and Browser Hijack Blaster, both for free. Thus protected from further invasion, I set about curing the disease.

MEDICINE FOR A SICK COMPUTER

I first updated the Symantec to the latest standards. I then did the same with Ad-Aware, and downloaded Spybot Search&Destroy from Majorgeeks. It was about then I discovered that I was not alone.

I found Merjin.org, a website set up by a computer student with the sole purpose of combatting CWS. From there, I obtained the invaluable CWShredder, a program that can remove ANY CWS bugs, and which is updated frequently. I also got HiJackTHIS!, a program which can find and display anything that is downloaded to your computer, and remove it with a command.

So effective are these programs, CWS has recently conducted Denial Of Service attacks on Merjin.org. Thankfully, it has survived...it also contains detailed information about all the CWS variants, and manual removal procedures.

I was able to sweep my system clean of many more bugs. Unfortunately, I still wasn't done.

HEALING THE PATIENT

I was still getting some spyware from CWS, and some Browser Helper Objects (BHO's) were still turning up. Fortunately, due to Zone Alarm and Hijack Blaster, I was warned well in advance. However, I was suspicious as to how it was happening on a daily basis. Thus, I went even deeper.

I went to Symantec's website and downloaded detailed instructions for THOUROUGHLY cleaning your system. I had missed something important.

CWS also writes itself to your "restore" files. These are immune from the cleaning software. The cure for that was quite new for me, a relative computer novice. However, one learns by doing, so I plowed ahead.

I disabled the "restore" function (instructions from Symantec), and rebooted into "safe" mode(also on Symantec's instructions). I then ran all my cleaning and anti-virus/anti-spyware programs, deleting everything found.

Then, I went to the C://System/Restore files and deleted them all. If it affects the "restore" function adversly, I have not seen evidence of it yet.

I rebooted, performed a scandisk and a defrag, and rebooted again. Then I enabled the "restore" function once more.

That was yesterday, and so far, so good. I'd like to think I got it all, but with these bugs, you never know. Fortunately, I'm now forewarned and forearmed.


TOPICS: Crime/Corruption; Culture/Society; Miscellaneous; News/Current Events; Your Opinion/Questions
KEYWORDS: computers; coolwebsearch; hijack; hijackers; spyware; trojanhorses; virus; viruses; worm
Navigation: use the links below to view more comments.
first previous 1-20 ... 121-140141-160161-180181-192 last
To: Long Cut

by brother-in-laws computer was so completely overwhelmed by
spyware and adware -- CWS was the last and most difficult
to slay -- that it would take LITERALLY 10 minutes to come
up, run out of virtual memory (there were so many IE
instances in the task bar that it wasn't worth counting them) and crash.

I made two trips; made it somewhat better one day, and then
came back later in the week with several other adware tools,
and finally eradicated what turned out to be over 450 bugs.

I defragged him (35%+ fragmented. just mangled), installed
mozille firefox and told him to never run IE EVER AGAIN.


181 posted on 06/11/2004 5:58:57 PM PDT by smonk
[ Post Reply | Private Reply | To 1 | View Replies]

To: counterpunch

Oh man, PestPatrol has saved me several times from infestation.

I've been hit like this before, with pornographic pop-ups, porn sites added to my favorites list, a strange toolbar beneath my standard internet buttons, etc.

Pest Patrol killed it, thank goodness.


182 posted on 06/11/2004 6:11:21 PM PDT by baseballfanjm
[ Post Reply | Private Reply | To 24 | View Replies]

To: Long Cut
excellent news. Glad things are working so well for you. I think you'll find that actually deleting IE will be fairly difficult, as MS has gone out of their way to make not using IE almost impossible on MS windows systems.

I find it interesting that IE still managed to pick up stuff when you weren't actually using it. THat would point to one of two things, either you have been hijacked and none of your scanners have spotted it, or some other program on your computer is using IE to do something. The most likely culpret in the latter case is if you are using Outlook for your email.

Outlook makes etensive use of IE, and I'm not sure that there is any way to stop it.

183 posted on 06/13/2004 12:50:23 PM PDT by zeugma (The Great Experiment is over.)
[ Post Reply | Private Reply | To 178 | View Replies]

To: Long Cut

Very, very cool. Sounds like you've got a good handle on things. Do check out The Proxomitron though. I think I posted that advice on this thread. With that proxy running on port 8080 and setting IE and Firefox to use port 8080 you'll be looked down tighter than a medieval virgin in a chastity. belt.


184 posted on 06/13/2004 7:44:16 PM PDT by Bloody Sam Roberts (ø¤º°`°º¤ø,¸¸,ø¤º°`°º¤ø,¸¸,Election '04...It's going to be a bumpy ride,¸¸,ø¤º°`°º¤ø,¸¸,ø¤º°`°º¤ø)
[ Post Reply | Private Reply | To 178 | View Replies]

To: Long Cut

Google for a program called Clean My PC, Download it.

In trial mode it will only remove 2 things per category. Uncheck all clean categories to speed up the iteration of the test.

I did this after getting “Rid” of CWS and everything else everything active, and found several registry entries and other stuff I wanted to clean up too. If the registry entries are gone, and the files are gone, revert to “Keep The H!@# out of my machine mode” and enjoy your surfing (Safe surfing anyway)

Speaking of “Active things” I regularly compare my Task list to a File I have made of things I want running ;-D anything new, I look up on the internet Google for swchost.exe for Example. If it is benign, and I like what it does, ok, add to good list, if not, I add it to the “BAD” list and go into kill mode. If it is benign, but I don't want it I keep clutter from slowing down my machine.

Been doing this since Windows 3.1 and I always seem to have fewer problems than those who do not. (Yep, I'm a NERD, no two ways about it, but If'n I didn't want to know how my computer was runnin' Id buy me a MAC.)


185 posted on 06/13/2004 8:42:00 PM PDT by DelphiUser
[ Post Reply | Private Reply | To 77 | View Replies]

To: Long Cut

BTTT


186 posted on 06/13/2004 8:48:34 PM PDT by Fiddlstix (This Tagline for sale. (Presented by TagLines R US))
[ Post Reply | Private Reply | To 1 | View Replies]

To: DelphiUser

Thanks, I'll have to check that one out.


187 posted on 06/13/2004 9:01:22 PM PDT by Long Cut (Certainty of Death, small chance of Success...What are we waiting for?...Gimli the Dwarf)
[ Post Reply | Private Reply | To 185 | View Replies]

To: Bloody Sam Roberts
It looks like the Zone Alarm is doing its job, and keeping IE in its place, for now. If the problem returns I'll sure check that one out, though.

Trouble is, I'm not knowlegeable enough to do that "proxy" and "port" stuff yet. Hey, I freely admit to what I have no clues about, and stuff like that is some of it.

188 posted on 06/13/2004 9:03:35 PM PDT by Long Cut (Certainty of Death, small chance of Success...What are we waiting for?...Gimli the Dwarf)
[ Post Reply | Private Reply | To 184 | View Replies]

To: Long Cut
Awww...c'mon. It's eeeeeeeasy. G'head, g,head...try it...you'll like it.

The download of the program has complete point-and-click instructions. It's actually isn't a bunch of computerese mumbo-jumbo...it IS just point and click on 2 or 3 items.

Since The Proxomitron is so mind bogglingly useful and won't be available forever...I suggest just downloading it and saving it for a rainy day.

189 posted on 06/14/2004 5:42:27 AM PDT by Bloody Sam Roberts (ø¤º°`°º¤ø,¸¸,ø¤º°`°º¤ø,¸¸,Election '04...It's going to be a bumpy ride,¸¸,ø¤º°`°º¤ø,¸¸,ø¤º°`°º¤ø)
[ Post Reply | Private Reply | To 188 | View Replies]

To: Long Cut
Thank you so much for posting this. I recently went into a Tanzania Christian Site looking for Tanzania Christian music and boom I got bombarded. I had Norton & Adware6 but not Zone Alarm, Spyblaster or Spybot. I added all those things but still was having problems. Finally I found a folder that said Internet Keywords in my program files. I noticed that they were files that had been trying to get out on Zone, but that Spybot or Adware had not picked up. I had to go into safe mode to delete them and not had a problem since.

I have also learned with this not only to update Windows, Norton, and my spyware stuff - but also MS Office and Front Page and all those. I had my Access and Front Page hacked before I was done, but have it all restored now.

Hope this helps any of the rest of you.

190 posted on 07/17/2004 10:35:23 AM PDT by GrandmaC (http://home.earthlink.net/~grandmac2 or http://home.earthlink.net/~tanzaniateam)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Long Cut
Bump for your old thread. I did a keyword search for "hijack" and found this because that's what happened to my wife's computer today-CWS. Japanese XP so it's hard for me to troubleshoot. It appears I've gotten rid of of it between Spybot and restoring to an earlier date, but I'm going to keep this thread handy in case it comes back again.
191 posted on 09/07/2004 5:01:49 AM PDT by GATOR NAVY
[ Post Reply | Private Reply | To 188 | View Replies]

To: Long Cut

I'm as dumb as stump when it comes to computers and I was able to download it with no problem. I went with the foxfire edition and went with all the upgrades there is another download for that.


192 posted on 09/07/2004 5:18:31 AM PDT by bad company ( You can live on your knees or die on your feet.)
[ Post Reply | Private Reply | To 23 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 121-140141-160161-180181-192 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson