Pieter_Arntz
September 10th, 2003, 05:09 AM
For anyone not familiar with this hijacker: CWS Chronicles (http://www.spywareinfoforum.com/~merijn/cwschronicles.html)
The latest version included a very nasty surprise.
They mutated the DNSRelay variant (number 8 at the site above) to include a hosts file hijack, including these lines:
O1 - Hosts: 64.135.204.60 spywareinfoforum.com
O1 - Hosts: 64.135.204.60 www.spywareinfoforum.com
O1 - Hosts: 64.135.204.60 lavasoftsupport.com
O1 - Hosts: 64.135.204.60 www.lavasoftsupport.com
Effectively disabling people from downloading HijackThis and CWShredder from their normal download-links and getting support at some of the most renowned anti-spyware-forums.
If you experience problems downloading both these programs and fear you have been hit by this hijack, please got to this post (http://www.wilderssecurity.com/showthread.php?t=12516) and download the attachment.
Then unzip, double-click HijackThis.exe and hit "Scan".
When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log as a .txt file, and copy and paste its contents into your next post.
Most of what it lists will be harmless, so do not fix anything yet.
Regards,
Pieter
The latest version included a very nasty surprise.
They mutated the DNSRelay variant (number 8 at the site above) to include a hosts file hijack, including these lines:
O1 - Hosts: 64.135.204.60 spywareinfoforum.com
O1 - Hosts: 64.135.204.60 www.spywareinfoforum.com
O1 - Hosts: 64.135.204.60 lavasoftsupport.com
O1 - Hosts: 64.135.204.60 www.lavasoftsupport.com
Effectively disabling people from downloading HijackThis and CWShredder from their normal download-links and getting support at some of the most renowned anti-spyware-forums.
If you experience problems downloading both these programs and fear you have been hit by this hijack, please got to this post (http://www.wilderssecurity.com/showthread.php?t=12516) and download the attachment.
Then unzip, double-click HijackThis.exe and hit "Scan".
When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log as a .txt file, and copy and paste its contents into your next post.
Most of what it lists will be harmless, so do not fix anything yet.
Regards,
Pieter