[21 Jan] Database update, now detecting CoolWebSearch.loadnew.
Overview
CoolWebSearch.loadnew is a suite of software components installed without user notice when visiting (Warning, do not visit this site!) 213.159.117.133. Several files will be dropped on your system, such as in %WinDir%, %SystemDir% but also on the current user's desktop. The files contains functionality shut down your computer, change browser settings to
[Only Registered and Activated Users Can See Links. Click Here To Register...], add sites to the Trusted Zones, some hook into explorer.exe and show strong indications to be spam related, others have backdoor capabilities.