Hijacker Web Sites
The following web sites have been found in log files of people infected with this trojan.
To our best knowledge, they are all affiliated with coolwebsearch.com
193.125.201.50, 1stpagehere.com, 66.250.130.194, adulthyperlinks.com, allhyperlinks.com, approvedlinks.com, bannedhost.net, bestcrawler.com, cantfind.com, carsands.com, cool-web-search.com, coolfreepage.com, coolwebsearch., coolwwwsearch., couldnotfind.com, defaultsearch.net, dev.ntcor.com, drvvv.com, ewebsearch.net, findloss.com, findwhat.com, firstbookmark.net, freebookmark.net, freebookmarks.net, global-finder.com, globesearch.com, gratis-porn-movie.com, hardloved.com, itseasy.us, jethomepage.com, jetseeker.com, kazaa-lite.ws, martfinder.com, mature50.com, mommykiss.com, mywebsearch.net, noblindlinks.com, nocensor.com, ok-search.com, pedo.ws, runsearch.com, search-2003.com, search.xrenoder.com, searchdesire.com, searchnow.ws, searchv.com, searchxp.com, sharempeg.com, sixroads.com, slawsearch.com, slotch.com, stopxxxpics.com, super-spider.com, super-websearch.com, the-exit.com, the-huns-yellow-pages.com, topsearcher.com, unipages.cc, web-search.tk, white-pages.ws, youfindall.com, youfindall.net, yourbookmarks.info, and yourbookmarks.ws
http://www.spywareinfo.com/articles/cws/
a good anti-spyware blog site:
http://www.netrn.net/spywareblog/
spybot S&D rippoff websites:
enigmasoftwaregroup.com
XP Anti-Spy Rip-off dialer sites:
xp-antispy.de
xpantispy.de
hey does this IP look dodgy to you ? :
www11.mycomputer.com - 10.0.10.11
NS1.OMNITURE.COM 216.52.17.51
NS2.OMNITURE.COM 209.213.215.52
Registrant:
Omniture, Inc. (MYCOMPUTER6-DOM)
756 East Technology Ave
Building F
Orem, UT 84097
US
Domain Name: MYCOMPUTER.COM
Administrative Contact, Technical Contact:
MyComputer.com (DN435-ORG) dnsadmin@MYCOMPUTER.COM
1358 W BUSINESS PARK DR
OREM, UT 84058-2203
US
Counters-Trackers:
NEDSTAT:212.72.38.0-212.72.38.255
never finished ®