Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

HIJACK! (No, not THAT kind!)
various | Today | Me

Posted on 06/05/2004 8:06:55 PM PDT by Long Cut

You may have heard of this lately, or perhaps have had it happen to you. That's right...your internet browser gets hijacked. Taken from your control, as it were.

It takes you to sites you would never have visited in a million years; your computer slows down and maybe crashes; your homepage is mysteriously changed; you now have about a dozen "favorites" that you never selected and don't want.

You've been HIJACKED!

What happened? How? You ask, as you pull your hair out in disgust.

Well, it happened to me,, and some FReepers I know, and a LOT of my friends, lately. I've been hearing scuttlebutt around the Web, and around the water cooler. People's computers are being taken over by insidious, rotten spyware and malware that effectively seizes control and can have serious reperussions for the user.

These things download some particularly nasty porn, even child porn, to a computer. People have been fired, investigated, and disgraced for something they never did.

I discovered mine one day whil, of all things, trying to access FR. I mistyped the URL, and found myself redirected to some porn search engine. Massive popups overwhelmed my Pop-up Stopper, and froze my computer.

After the reboot, I ran my McAffie antivirus, which quickly crashed the system and failed to ever work again. Ad-Aware removed some registry keys and values, and I thought all was well.

Wrong. It happened again.

Now, I got serious. I obtained Symantec Pro version, and ran it. It caught several more bugs, but some couldn't be quarantined OR removed.

I was in a fix. I was using a computer that FReeper thumperusn had graciously loaned me, and I didn't want to give it back to him all jacked up. Thus began my battle with the Internet demon known as "CoolWebSearch".

I went to sites like Spywareguide.com, Spywareinfo.com,, and Symantec's excellent site, and educated myself about CWS. It's a mean one.

With over 25 versions to date, and about 30 affiliated sites, CWS has infected millions of computers to date. It uses a "hole" in JavaScript Virtual Machine to invade your machine and make changes to IE and your registry. It also copies itself to your "restore" files, which the antivirus and anti-spyware programs DO NOT search or modify.

After educating myself, and wading through literally hundreds of pages of "geek-speak", I formed a plan of attack.

PROTECTION

First, I would fix the holes in my system. The borrowed laptop used Windows Me, from 2000. It needed updating, and MS's website had a whole bunch of them. Since I'm on a dialup, it took hours to download and install all the patches.

Next, some firewalls. At Major Geeks.com, I found and downloaded Zone Alarm and Browser Hijack Blaster, both for free. Thus protected from further invasion, I set about curing the disease.

MEDICINE FOR A SICK COMPUTER

I first updated the Symantec to the latest standards. I then did the same with Ad-Aware, and downloaded Spybot Search&Destroy from Majorgeeks. It was about then I discovered that I was not alone.

I found Merjin.org, a website set up by a computer student with the sole purpose of combatting CWS. From there, I obtained the invaluable CWShredder, a program that can remove ANY CWS bugs, and which is updated frequently. I also got HiJackTHIS!, a program which can find and display anything that is downloaded to your computer, and remove it with a command.

So effective are these programs, CWS has recently conducted Denial Of Service attacks on Merjin.org. Thankfully, it has survived...it also contains detailed information about all the CWS variants, and manual removal procedures.

I was able to sweep my system clean of many more bugs. Unfortunately, I still wasn't done.

HEALING THE PATIENT

I was still getting some spyware from CWS, and some Browser Helper Objects (BHO's) were still turning up. Fortunately, due to Zone Alarm and Hijack Blaster, I was warned well in advance. However, I was suspicious as to how it was happening on a daily basis. Thus, I went even deeper.

I went to Symantec's website and downloaded detailed instructions for THOUROUGHLY cleaning your system. I had missed something important.

CWS also writes itself to your "restore" files. These are immune from the cleaning software. The cure for that was quite new for me, a relative computer novice. However, one learns by doing, so I plowed ahead.

I disabled the "restore" function (instructions from Symantec), and rebooted into "safe" mode(also on Symantec's instructions). I then ran all my cleaning and anti-virus/anti-spyware programs, deleting everything found.

Then, I went to the C://System/Restore files and deleted them all. If it affects the "restore" function adversly, I have not seen evidence of it yet.

I rebooted, performed a scandisk and a defrag, and rebooted again. Then I enabled the "restore" function once more.

That was yesterday, and so far, so good. I'd like to think I got it all, but with these bugs, you never know. Fortunately, I'm now forewarned and forearmed.


TOPICS: Crime/Corruption; Culture/Society; Miscellaneous; News/Current Events; Your Opinion/Questions
KEYWORDS: computers; coolwebsearch; hijack; hijackers; spyware; trojanhorses; virus; viruses; worm
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 181-192 next last
To: Long Cut

That is what my scripts look out for. My system isn't your typical soft target.


21 posted on 06/05/2004 8:22:48 PM PDT by inflation (Cuba = BAD, China = Good? Why, should not both be treated the way Cuba is?)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Long Cut

One of my kids managed to get some coolweb stuff on a laptop that I hadn't updated. Among other things, it took over Windows media player and turned it into a monster.

In addition to the programs you mention, you also might want to look into CWShredder, a small program that removes Coolweb malware.

And I recommend the combination of SpybotSearch&Destroy and Spyware Blaster to immunize yourself from bad sites.


22 posted on 06/05/2004 8:23:46 PM PDT by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma; mylife
Is it difficult to replace IE with Mozilla? I've ben thinking about doing that.

Do you have any pointers? I'm still pretty computer-illiterate, just way more familiar with hijackers now.

23 posted on 06/05/2004 8:24:19 PM PDT by Long Cut (Certainty of Death, small chance of Success...What are we waiting for?...Gimli the Dwarf)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Long Cut
The best software for taking control of your computer back from hijackers is PestPatrol.
Virus checkers do not detect or remove these kinds of infestations. PestPatrol does.
24 posted on 06/05/2004 8:24:19 PM PDT by counterpunch (<-CLICK HERE for my CARTOONS)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Long Cut

You are not alone.

I am an IT professional and have been so for 20+ years.

I now am cleaning spyware/adware/trojans from computers several times a week.

Most of these machines have become unusable because of it.

The latest genuine threat is Peper. This nasty piece can't be killed until you go into safe mode, delete a pile of hidden files and clean out the registry of BHOs.

I will say this...unless you run a popup stopper and/or an ad remover, you're going to get this garbage.

You need to get and run:

Spywareblaster
spybot search and destroy
Adaware
hijackthis

Further stop using Internet Explorer. Switch over to Mozilla Firefox. At least until this garbage is kept at bay.

Firefox is also VERY extensable. Imagezoomer is a great add-in to firefox. Allows you to zoom in or out any image in any post. There are over 100 add-ins to Firefox that add all sort of nifty things. Firefox displays pages just as fast or faster than IE(if someone tells you otherwise, they have an OS problem, I've installed it on over 50 machines) and Firefox blocks popups and much of the adware issues we've got right now.

-Mal


25 posted on 06/05/2004 8:24:20 PM PDT by Malsua
[ Post Reply | Private Reply | To 1 | View Replies]

To: Long Cut

Exact same thing happened to my Mom's PC. One day, out of nowhere, she opened an IE window, and BAM...some disgusting porn garbage.

This is my MOM we're talking about here. Words could not express my fury and embarrassment over this hijack!

I tried everything I could think of to get rid of the offending bug, but it seemed that every time I thought I made some headway, I'd re-boot and the bugger would re-appear.

Eventually, I just downloaded and installed NetScape. She's been using that ever since with no problems.


26 posted on 06/05/2004 8:25:09 PM PDT by ItsOurTimeNow ("A sword day! A red day, 'ere the sun rises!")
[ Post Reply | Private Reply | To 1 | View Replies]

To: jern

ping for later


27 posted on 06/05/2004 8:25:59 PM PDT by jern
[ Post Reply | Private Reply | To 1 | View Replies]

To: Long Cut
CWShredder removes all known CoolWebSearch variants automatically.
28 posted on 06/05/2004 8:26:01 PM PDT by South40 (Amnesty for ILLEGALS is a slap in the face to the USBP!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Long Cut

Man is this a timely thread. I just spent a couple hours getting rid of this crap on my computer. But here's something I can't solve. For some reason my "Favorites" will only except 4 addresses. If I try to add more, it shows up until I close my browser, and then doesn't reappear. Any ideas?


29 posted on 06/05/2004 8:28:46 PM PDT by Rokke
[ Post Reply | Private Reply | To 1 | View Replies]

To: counterpunch

Thanks. I'm downloading it as we speak.


30 posted on 06/05/2004 8:28:53 PM PDT by Long Cut (Certainty of Death, small chance of Success...What are we waiting for?...Gimli the Dwarf)
[ Post Reply | Private Reply | To 24 | View Replies]

To: Long Cut
It a piece of cake. Click on download in the upper left corner

Then run the file

31 posted on 06/05/2004 8:29:02 PM PDT by mylife (The roar of the masses could be farts)
[ Post Reply | Private Reply | To 23 | View Replies]

To: Long Cut
Thanks for your post. I have been hijacked, and right now I am trying desperately to fix the problem. A nightmare indeed.
32 posted on 06/05/2004 8:30:14 PM PDT by Fraulein
[ Post Reply | Private Reply | To 1 | View Replies]

To: Malsua

I've got all the programs you listed except Mozilla. Is it difficult to replace IE with it? How exactly is this done?


33 posted on 06/05/2004 8:31:43 PM PDT by Long Cut (Certainty of Death, small chance of Success...What are we waiting for?...Gimli the Dwarf)
[ Post Reply | Private Reply | To 25 | View Replies]

To: Long Cut

Thanks for posting this. I would sure like to spend an afternoon with the Democrats (you know that what they are) that create this malware.


34 posted on 06/05/2004 8:34:34 PM PDT by Living Stone (The following statement is true: The preceeding statement is false.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Long Cut

see #31


35 posted on 06/05/2004 8:34:36 PM PDT by mylife (The roar of the masses could be farts)
[ Post Reply | Private Reply | To 33 | View Replies]

To: Rokke; Malsua

That's a new one on me. Mal, any ideas??


36 posted on 06/05/2004 8:34:54 PM PDT by Long Cut (Certainty of Death, small chance of Success...What are we waiting for?...Gimli the Dwarf)
[ Post Reply | Private Reply | To 29 | View Replies]

To: Long Cut

HijackThis is great. I rank it up there with Lavasoft's ad-aware.


37 posted on 06/05/2004 8:35:51 PM PDT by freebilly (Vote Kerry-- 1 Billion Muslims Can't Be Wrong....)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Long Cut

I'm doing exactly the same thing right now...been fighting it for two weeks now.

Thanks for the tip on cleaning in Safe Mode.


38 posted on 06/05/2004 8:36:08 PM PDT by Luis Gonzalez (Sin Pátria, pero sin amo.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Long Cut

It has gotten to the point that I rarely venture off of FR. I find myself waiting for commentary on an article rather than clicking on the source for the full story. I use spybot and adaware. The web can be a realy dangerous place.


39 posted on 06/05/2004 8:36:28 PM PDT by eastforker (The color of justice is green,just ask Johny Cochran!)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Long Cut

There are a few Linux viruses in circulation. More will surely come as more start using it.

Same with Mac's. Just this past week there was a thread on a Mac 'vunerability.'

If every one stopped using Windows tomorrow and changed to Mac or Linux, the virus makers would increase their attacks on those.


40 posted on 06/05/2004 8:36:54 PM PDT by TomGuy (Clintonites have such good hind-sight because they had their heads up their hind-ends 8 years.)
[ Post Reply | Private Reply | To 20 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 181-192 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson