Hijacker . CWS.Cassandra (Summary)
Software Name: CWS.Cassandra
Company Name:
Product Name: CWS.Cassandra
Classification: Hijacker
Website:
Brief:
Hijacks browser homepage and search settings. Downloads other malware files in the background. Changes internet zonemap domain settings.
IMPORTANT!
Some of the Hijacker.CWS.Cassandra components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of CWS.Cassandra
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
CWS.Cassandra might create following folders (and inject its files inside
the folders):
n/a
CWS.Cassandra might create following files (some of the files might be
loaded in memory while the software is running):
- %FAVORITES%\all crazy sex.url
- %FAVORITES%\chat112.com - free dating fervice.url
- %FAVORITES%\free xxx pics & movies.url
- %FAVORITES%\go to sex.url
- %FAVORITES%\online casino.url
- %FAVORITES%\online dating.url
- %FAVORITES%\spyware remove.url
- %FAVORITES%\tgp with pics prewiev.url
- %FAVORITES%\web anal sex.url
CWS.Cassandra is often accompanied by the following tracking cookies:
- here4search.com
- win-eto.com
- kita-search.com
- myexexex.com
- super-spider.com
CWS.Cassandra might create following registry keys (and inject subkeys
and values):
- HKEY_CLASSES_ROOT\CLSID\{467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E}
- HKEY_CLASSES_ROOT\Interface\{0D721150-AEF3-457B-B03A-5097B623CE45}
- HKEY_CLASSES_ROOT\Plugin6.DNSErrObj
- HKEY_CLASSES_ROOT\Plugin6.DNSErrObj.1
- HKEY_CLASSES_ROOT\redalert.here
- HKEY_CLASSES_ROOT\redalert.here.1
- HKEY_CLASSES_ROOT\TypeLib\{444A5674-FF85-45D4-9AE2-4199D8D70C85}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Cassandra
CWS.Cassandra might create following registry values:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Control handler
- HKEY_USERS\*\Software\Microsoft\Internet Explorer|*|http://win-eto.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|Control Date
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|ControlID
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|TODO_Count
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|TODO_Item_Data1_1
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|TODO_Item_Data2_1
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|TODO_Item_Data3_1
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|TODO_Item_Data1_2
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|TODO_Item_Data2_2
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|TODO_Item_Data3_2
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|GUID
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|URL_Count
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|URL_Index
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|URL_Item_1
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|URL_Item_Id_1
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|URL_Item_Date_1
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|URL_Item_2
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|URL_Item_Id_2
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|URL_Item_Date_2
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|URL_Item_3
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|URL_Item_Id_3
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|URL_Item_Date_3
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|UpdateDate
CWS.Cassandra might create registry values with following data:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|http://win-eto.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|http://win-eto.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Settings|*|http://super-spider.com*
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\greg-search.com|*|2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1|:Range|195.225.177.13
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range10|:Range|66.79.169.45
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range11|:Range|66.98.198.202
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range12|:Range|69.31.79.102
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range13|:Range|69.50.170.212
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range14|:Range|81.211.105.37
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range15|:Range|81.222.131.56
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range16|:Range|82.196.67.62
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range17|:Range|82.196.73.10
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range2|:Range|206.161.207.105
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range3|:Range|209.8.161.52
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range4|:Range|213.159.117.131
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range5|:Range|213.159.117.235
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range6|:Range|38.113.193.2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range7|:Range|65.110.38.219
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range8|:Range|65.125.230.94
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range9|:Range|66.230.145.49
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|http://kita-search.com*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|http://myexexex.com*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|http://here4search.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|http://kita-search.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|http://myexexex.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|http://here4search.com*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|http://super-spider.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|http://super-spider.com*
CWS.Cassandra might insert following entries in the HOSTS file:
n/a
Click
here to scan your computer for CWS.Cassandra free of charge
|