Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice

CWS hijack pulls a nasty stunt

1004 Views 4 Replies 5 Participants Last post by  panzer999
For anyone not familiar with this hijacker: CWS Chronicles

The latest version included a very nasty surprise.
They mutated the DNSRelay variant (number 8 at the site above) to include a hosts file hijack, including these lines:
O1 - Hosts: 64.135.204.60 spywareinfo.com
O1 - Hosts: 64.135.204.60 www.spywareinfo.com
O1 - Hosts: 64.135.204.60 lavasoftsupport.com
O1 - Hosts: 64.135.204.60 www.lavasoftsupport.com

Effectively disabling people from downloading HijackThis and CWShredder from their normal download-links and getting support at some of the most renowned anti-spyware-forums.

If you experience problems downloading both these programs and fear you have been hit by this hijack, please use this link:
http://216.180.252.218/~spywareinfo.com/downloads/tools/hijackthis.zip

Then unzip, double-click HijackThis.exe and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log as a .txt file, and copy and paste its contents into your next post.

Most of what it lists will be harmless, so do not fix anything yet.

Regards,

Pieter
Status
Not open for further replies.
1 - 5 of 5 Posts
thanx for the heads up pieter.
:up:
That is tantamount to sabotage, and is highly illegal,

Thanks for the heads up :D
bump
This isn't a sticky yet???????
1 - 5 of 5 Posts
Status
Not open for further replies.
Top