IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice
CWS hijack pulls a nasty stunt
1004
Views
4
Replies
5
Participants
Last post by
panzer999,
For anyone not familiar with this hijacker: CWS Chronicles
The latest version included a very nasty surprise.
They mutated the DNSRelay variant (number 8 at the site above) to include a hosts file hijack, including these lines:
O1 - Hosts: 64.135.204.60 spywareinfo.com
O1 - Hosts: 64.135.204.60 www.spywareinfo.com
O1 - Hosts: 64.135.204.60 lavasoftsupport.com
O1 - Hosts: 64.135.204.60 www.lavasoftsupport.com
Effectively disabling people from downloading HijackThis and CWShredder from their normal download-links and getting support at some of the most renowned anti-spyware-forums.
Then unzip, double-click HijackThis.exe and hit "Scan".
When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log as a .txt file, and copy and paste its contents into your next post.
Most of what it lists will be harmless, so do not fix anything yet.
A forum community dedicated to tech experts and enthusiasts. Come join the discussion about articles, computer security, Mac, Microsoft, Linux, hardware, networking, gaming, reviews, accessories, and more!