Name: CoolWebSearch
Category: Browser Hijacker
Advice: Remove
Risk: Elevated Risk Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge.
Description: CoolWebSearch is a name given to a wide range of different browser hijackers. Though the code is very different between variants, they are all used to redirect users to and other sites affiliated with its operators.

CoolWebSearch is part of a strain of trojans that have recently been identified that all have one thing in common: they install through the ByteVerify exploit in the MS Java VM and change the IE homepage, search page, search bar, etc.

CoolWebSearch Symptoms:
- Hijacks to various search engines. Different variants of CoolWebSearch will redirect you to different sites.
- When a URL is mistyped in the browser, CoolWebSearch will redirect the page to affiliate websites as well as
- Installs bookmarks to adult websites in the favorites menu.
- Installs toolbars into the browser.
- Slows down PC.
- Can cause reboots.
- Targets anti-spyware websites, usually vendors of spyware removal tools. Once infected with CoolWebSearch, you may be unable to visit these websites to download their products.
- Will open porn popups if it thinks the website being viewed is pornographic in nature.
- Can cause significant slowdowns when attempting to type into a browser.
- Will add to the trusted sites list.

CoolWebSearch has a number of variants:

IE pages changed to and (, hijack returning on system restart. This variant does everything in its powers to redirect you to a domain owned by IE is hijacked to it, the hosts file is replaced to redirect about 100 porn and CWS domains to, and a randomly named stylesheet is dropped that redirects to when certain keywords appear in webpages.

IE hijacked to and, redirections to and when typing incomplete URLs into address bar.

There only were several threads of users experiencing enormous slowdowns in IE when typin messages into text boxes. Delays of over a minute before the typed text appeared were reported. Also some redirections to were reported. The hijack installed a stylesheet that used a flaw in Internet Explorer and allowed a .css stylesheet file to execute Javascript code. The code in the file was encrypted, and spawned a popup off-screen that did the redirecting. However, this file was called on almost every action taken in IE, slowing it down - this was the most obvious when typing text.

IE hijacked to

A browser helper object that changes your Home Page and open pop-up windows based on the currently visited url.

also known as TROJ_ESEPOR.A, TROJ_ESEPOR.B or TROJ_ESEPOR.C, operations seems to vary from opening pop-up windows, to changing search results from popular search engines.

Type: Browser Hijacker - Browser hijackers are malicious programs that change a user's web browser settings, usually altering designated default start and search pages. In addition a browser hijacker can modify nearly every aspect of a web browser including adding bookmarks, and redirecting search traffic to alternative sites.

