Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » Security Watch » CWS getting even nastier..

Security Watch - CWS getting even nastier.. posted in the Security & Safety forums; Identity Theft Ring Discovered By Spyware Researcher Get a good grip on your chair because this story might knock you right out of it. I've just finished picking myself up ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 08-09-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default CWS getting even nastier..


Identity Theft Ring Discovered By Spyware Researcher


Get a good grip on your chair because this story might knock you right out of it. I've just finished picking myself up off the floor after reading about this.

While investigating a new mutation of the CoolWebSearch trojan, a Sunbelt researcher was astounded to discover that it was being used for identity theft. All manner of personal information is being uploaded to a publicly-viewable web server, including eBay passwords, Paypal passwords and passwords for bank accounts worth hundreds of thousands of dollars. Anyone who knows this web server's IP address can view all of this information!

After initially rebuffing Sunbelt when they first made contact, the FBI now is said to be investigating the matter. Sunbelt also has tried contacting some of the victims of this identity theft.

CoolWebSearch is a particularly nasty browser hijacker with countless variations. They have hundreds, possibly thousands, of affiliated web sites who all feed traffic into coolwebsearch.com. Many of those affiliates use exploits for various flaws in Windows and Internet Explorer to install browser hijackers.

The motivation behind all of this, of course, is money. Coolwebsearch.com is nothing more than a collection of paid listings. If someone clicks the links on their web site, they are paid a small commission from the owner of the site being linked. In turn, CoolWebSearch pays their affiliates to drive traffic to their site.

They almost always have used unethical and possibly illegal methods to install this hijacking software. This is the first time, to my recollection, that they or one of their affiliates have done something so blatantly illegal. I have been practically begging the FTC to investigate CWS for well over a year. Although I am saddened that so many people have been victimized by this crime, I am glad that CoolWebSearch finally will be investigated for their activities.

From:

http://www.spywareinfo.com/newslette.../2005/aug7.php


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #2  
Old 08-09-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Re: CWS getting even nastier..


Some more info:


Financial Passwords and Credit Card Numbers Stolen From Thousands of Machines

There is more information about the identity theft operation I reported late Saturday.
================================================== ==========================================

Patrick Jordan, a researcher for Sunbelt, maker of Counterspy antispyware, made the discovery while investigating a new variant of the CoolWebSearch browser hijacker. After this variant was running on his test machine, Jordan discovered that it had downloaded and installed surveillance spyware.

This as-yet-unidentified spyware logs instant message and other chat activity, the web addresses visited by the victim, user names and passwords the victim uses to log into various web sites, as well as information filled out on web site forms. The spyware also accesses Microsoft's Internet Explorer "Protected Storage", which is where Internet Explorer stores information and passwords entered into web forms.

Once this information has been collected, it is transmitted to a remote web server over the internet. Once transmitted to the server, the information is dumped into an unencrypted file. Anyone who knows the address of this server can view this file. One bank account, whose complete access information has been stored on this remote server, is worth over $350,000.00 USD.

The personal information of thousands of victims is being written to this file on a continuing basis. Sunbelt has been monitoring the file and has discovered that the information it contains is being compressed and archived at regular intervals. The file then is reset to blank so that more information can be written to it.

It is not, as was first reported here and elsewhere, the CoolWebSearch software itself that is stealing this personal information. Rather, the spyware is downloaded and installed by this particular variant of CWS after it is running on the victim's machine. There are two known versions of this spyware. It is unknown at this time whether CoolWebSearch.com or the affiliate responsible for this variant have access to the spyware or the information that it is collecting.

The FBI as well as the US Secret Service are investigating. Neither organization will comment on the matter.

If you suspect that you have this spyware installed, you are urged to install a firewall immediately, then block all outbound access to the internet. Kerio and ZoneLabs both make excellent software firewalls. Then you should contact your bank and credit card companies. Following that, log in from an uninfected machine and change all passwords on web sites where you have an account.

If you determine for a fact that this or any other spyware is installed on your computer and that your financial accounts have been compromised, you should contact your local police department. They should put you in contact with any Federal agency investigating the crime.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 08-09-2005
merlin's Avatar
Trusted Security Analyst
My PC
 
Join Date: Jul 2005
Location: Wisconsin
Posts: 2,616
PC Experience: Computers Fear Me
merlin - See this Members User comments on their Profile page merlin - See this Members User comments on their Profile page
Send a message via Yahoo to merlin
Default Re: CWS getting even nastier..

This is why people need to read the fine print when they download stuff!! And if your using spyware apps, make sure to let them know to block known adv. sites!


__________________
QuickTime Alternative..Hijackthis..SpeedFan..ATI Tool..Whats Running..Everest..Absolute Control..All Drivers
If you feel we saved you some money please help support this site by DONATING as this site is funded by great people like you

OUT FOR LUNCH


  #4  
Old 08-09-2005
Spaceman3750's Avatar
Elite Member
My PC
 
Join Date: Jan 2004
Location: Riverton, IL, USA
Posts: 1,476
PC Experience: Very Experienced
Spaceman3750 - See this Members User comments on their Profile page
Send a message via AIM to Spaceman3750 Send a message via MSN to Spaceman3750 Send a message via Yahoo to Spaceman3750
Default Re: CWS getting even nastier..

Wow! I'm using FireFox, so I am not at much of a risk for giving our computer CW, but my mom uses IE, although she does not download anything, can she still pick it up on accident?


__________________
- Ryan
http://www.spaceman3750.info
http://www.conglomerate-game.net

Cisco Academy - CCNA student
  #5  
Old 08-09-2005
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,778
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default Re: CWS getting even nastier..

Joe,
I don't know what is scarier, the CWS or the fact that the FBI and Homeland Security won't comment on how bad it is...

Hey Space,
I am not sure about CWS, however, yes just surfing your mother could potentially be infected, that's why using the tools is sooooooo important, some of these rotten little monsters install themselves with out asking, (how rude

But it sounds as if you are all using the same PC, and you know to have the firewall up, and the Spyware and AV updated, so she should be OK .

I use IE and now that Joe and Merlin have shown me the error of my gulp, firewall free days I haven't had a problem.

So Guys, is CWS one of those scary monsters that can install without your help?? Inquiring minds want to know...

TTFN

T


  #6  
Old 08-09-2005
Spaceman3750's Avatar
Elite Member
My PC
 
Join Date: Jan 2004
Location: Riverton, IL, USA
Posts: 1,476
PC Experience: Very Experienced
Spaceman3750 - See this Members User comments on their Profile page
Send a message via AIM to Spaceman3750 Send a message via MSN to Spaceman3750 Send a message via Yahoo to Spaceman3750
Default Re: CWS getting even nastier..

Yah, I have Norton Firewall 2003 (don't tell me it is time to update, I know...) and Norton AntiVirus 2003, plus I use AdAware Personal, Spyboy Search & Destroy, and Ewido (thanks for that one Merlin ). I have the same security going on my Aunt's computer (I am responsible for her computer maintenance and security, plus I got her to get FireFox for if/when she drops AOL *gasp, AOL* off of her high-speed connection) except she has Norton Internet Security 2005 (she really should have gotten the two seperate, but I didn't realize she had gotten that, or I probably would have let her know).


__________________
- Ryan
http://www.spaceman3750.info
http://www.conglomerate-game.net

Cisco Academy - CCNA student
  #7  
Old 08-09-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Re: CWS getting even nastier..

Originally Posted by tjnbarbour


So Guys, is CWS one of those scary monsters that can install without your help?? Inquiring minds want to know...
Wow! I'm using FireFox, so I am not at much of a risk for giving our computer CW, but my mom uses IE, although she does not download anything, can she still pick it up on accident?

CoolWebSearch hijackers are invariably installed by exploitation of a wide variety of web browser security holes, the vast majority (but not all) of which target Internet Explorer and its MS Java virtual machine.
from:
http://www.doxdesk.com/parasite/CoolWebSearch.html


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes
Linear Mode Linear Mode