Results 1 to 3 of 3

Thread: DesktopHijack - SmitFraud - CWS.Cassandra

  1. #1
    Triple Platinum Member Curio's Avatar
    Join Date
    Nov 2004
    Location
    London
    Posts
    899

    DesktopHijack - SmitFraud - CWS.Cassandra

    The latest variants of the CoolWebSearch trojan are a little bit nasty and like all CWS variants are apparently mutating on a regular basis. It seems like they spend a real lot of time trying to find every nasty trick that can be pulled and then bundling it all together for our web-browsing pleasure.

    Anyway it is typified by some large warning banner or other overtaking the desktop (hence 'DesktopHijack') and installation of various dubious Spyware/Virus removal programs. There are now some tools about to help automate it's removal. Although from experience I can tell you they may not completely solve your issues they should at least recover your PC to a usable state, you may need to delete the HOSTS file to further the process but it depends on what other crap you have accumulated.



    There is a detailed listing of the earlier SmitFraud variants and what it does at Symantec
    http://securityresponse.symantec.com...tophijack.html
    http://securityresponse.symantec.com...phijack.b.html
    I'm using Windows 7 - you got a problem with that?

  2. #2
    Old and Cranky Super Moderator rik's Avatar
    Join Date
    Aug 2003
    Location
    Watching Your every move...
    Posts
    4,638
    Great info. Thanks for sharing and trying to keep us safe.

  3. #3
    Triple Platinum Member Curio's Avatar
    Join Date
    Nov 2004
    Location
    London
    Posts
    899
    The original banner was along the lines of

    'an error was caused by Trojan-Spy.Smitfraud.c'

    And a load of other gunk, that should attract some hits once google has done it's job.
    trojan-spy.smitfraud.c remove removal fix repair spyware virus
    oops - started writing a keywords list
    I'm using Windows 7 - you got a problem with that?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •