[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-Disclosure] Windows hosts file changing.
- To: "Kevin Gerry" <poof1@cox.net>
- Subject: Re: [Full-Disclosure] Windows hosts file changing.
- From: Joe Stewart <jstewart@lurhq.com>
- Date: Wed, 22 Oct 2003 10:11:00 -0400
On Wednesday 22 October 2003 4:01 am, Kevin Gerry wrote:
> Does -ANYBODY- know how it occurs?
This isn't Qhosts. It's a variant of the CoolWebSearch browser hijacker.
Browsing the contact.htm page on the IP address given quickly reveals
this site and CoolWebSearch are running the same scam under different
names. The site's webmaster even has a link to the CWS removal tool and
a "Don't blame me for trojaning you, blame Microsoft" message.
More info on CoolWebSearch:
http://www.spywareinfo.com/~merijn/cwschronicles.html
-Joe
--
Joe Stewart, GCIH
Senior Security Researcher
LURHQ http://www.lurhq.com/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html