# Who writes spyware?

**URL:** <https://boards.straightdope.com/t/who-writes-spyware/247942>\
**Category:** Factual Questions\
**Created:** [May 31, 2004, 6:37pm UTC](https://boards.straightdope.com/t/who-writes-spyware/247942 "2004-05-31T18:37:15Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![GorillaMan](https://avatars.discourse-cdn.com/v4/letter/g/50afbb/32.png) [@GorillaMan](https://boards.straightdope.com/u/GorillaMan)\
**Post date:** [May 31, 2004, 6:37pm UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/1 "2004-05-31T18:37:15Z")

</div>

I’m _hoping_ this has an answer, and so is a GQ…

I’m not talking about Gator and stuff, which while unpleasant is the creation of a legitimate company…I’m thinking along the lines of CoolWebSearch. I can’t find anything online except for how to remove it - I’m wondering where it originates from, and who is (presumably) making a lot of money from it.

Any ideas? Or is it all shrouded in Russian-mafia secrecy?

---

<div class="post-metadata">

**Author:** ![The\_world\_s\_most\_deadliest](https://avatars.discourse-cdn.com/v4/letter/t/bc79bd/32.png) [@The\_world\_s\_most\_deadliest](https://boards.straightdope.com/u/The_world_s_most_deadliest)\
**Post date:** [May 31, 2004, 10:27pm UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/2 "2004-05-31T22:27:28Z")

</div>

IIRC, Spybot can show you details on (some of) the spyware it finds in a scan. Sometimes those details has a website address for the company it comes from.

---

<div class="post-metadata">

**Author:** ![Starguard](https://avatars.discourse-cdn.com/v4/letter/s/8dc957/32.png) [@Starguard](https://boards.straightdope.com/u/Starguard)\
**Post date:** [May 31, 2004, 10:31pm UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/3 "2004-05-31T22:31:36Z")

</div>

> [@GorillaMan](#):
>
> I’m _hoping_ this has an answer, and so is a GQ…
> 
> I’m not talking about Gator and stuff, which while unpleasant is the creation of a legitimate company…I’m thinking along the lines of CoolWebSearch. I can’t find anything online except for how to remove it - I’m wondering where it originates from, and who is (presumably) making a lot of money from it.
> 
> Any ideas? Or is it all shrouded in Russian-mafia secrecy?

Who makes sypyware? Thats easy…Hackers

Just like thieves make the best locks.

---

<div class="post-metadata">

**Author:** ![PecanSandy](https://avatars.discourse-cdn.com/v4/letter/p/fbc32d/32.png) [@PecanSandy](https://boards.straightdope.com/u/PecanSandy)\
**Post date:** [May 31, 2004, 11:00pm UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/4 "2004-05-31T23:00:53Z")

</div>

\>\>\>\>\>  
Who makes sypyware? Thats easy…Hackers  
\>\>\>\>\>

Hardly. Hacker’s hate spyware too.  
If you’re talking of adware…it’s programmers working for companies who write it. While people may not like it, adware is currently legal and extremely profitable.

---

<div class="post-metadata">

**Author:** ![GorillaMan](https://avatars.discourse-cdn.com/v4/letter/g/50afbb/32.png) [@GorillaMan](https://boards.straightdope.com/u/GorillaMan)\
**Post date:** [May 31, 2004, 11:23pm UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/5 "2004-05-31T23:23:06Z")

</div>

> [@PecanSandy](#):
>
> If you’re talking of adware…it’s programmers working for companies who write it. While people may not like it, adware is currently legal and extremely profitable.

But who are the companies? Since the OP, I realised that Google was filtering out all the ‘positive’ references to CoolWebSearch - but you can get to them via www. coolwebsearch .com (don’t try it with IE). But who are they? Where are they based - Florida, Caymans, Uzbekistan? Is anything known at all?

---

<div class="post-metadata">

**Author:** ![Kal](https://avatars.discourse-cdn.com/v4/letter/k/9de053/32.png) [@Kal](https://boards.straightdope.com/u/Kal)\
**Post date:** [May 31, 2004, 11:51pm UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/6 "2004-05-31T23:51:20Z")

</div>

> [@GorillaMan](#):
>
> Is anything known at all?

Yep. Whois reports the coolwebsearch site as being registered to InterWeb Solutions Inc. PO Box 326, Road Town, Tortola, IO, 65113.

Tortola is one of the Virgin Islands, btw.

---

<div class="post-metadata">

**Author:** ![Cillasi](https://avatars.discourse-cdn.com/v4/letter/c/71e660/32.png) [@Cillasi](https://boards.straightdope.com/u/Cillasi)\
**Post date:** [May 31, 2004, 11:54pm UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/7 "2004-05-31T23:54:27Z")

</div>

Many of these companies keep themselves hidden behind multiple shell companies. The best way to find out who actually writes/distributes a particular one is to seach anti-spyware/malware sites. Many of them have ferreted out this information and make it available to you.

I look forward to the day when this stuff is outlawed.

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [May 31, 2004, 11:58pm UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/8 "2004-05-31T23:58:47Z")

</div>

CoolWebSearch claims they are not responsisble for any browser hijackers that may be placed by their affiliates. From their security page:

[http://coolwebsearch.com/security/?country=US](http://coolwebsearch.com/security/?country=US)

> [@](#):
>
> Browser security is a very important issue. More and more people, nowdays, neglect the security of their browser, and as a result, end up being victims of so called “browser hijacks”.
> 
> If you are a victim of such a hijack, please read the following before sending a complaint. We are not responsible for these kinds of activities, we are buying surfers’ searches from webmasters all over the world. Maybe some webmasters, who are sending visitor traffic to us, are challenging your system’s security. We are not aware of this, nor are responsible for this. If you do, however, experience this situation, please, submit his affiliate ID when reporting to us.
> 
> We do not condone this sort of activities, and we investigate every complaint we get. Also, please include all the relevant information, like what exactly happened to your computer, where you surfed, to get the hijack (quite often it comes from porn pages), etc.
> 
> As a cure, we can recommend you to run CWShredder, a special third party program that can help clean your system. This program was written by Merijn from [spywareinfo.com](http://spywareinfo.com) You can download it from [coolwebsearch.com](http://coolwebsearch.com) site, clicking on those links: CWShredder.exe \<— this is the unpacked version cwshredder\_u.zip \<— this is the packed version.
> 
> Instructions:  
> Save this file on your hard drive, then close all IE windows and run an unpacked file. When finished (after reboot), run the file again, just in order to verify if everything was fixed. NOTE, this software is NOT written by us, it was written by merijn from [www.spywareinfo.com](http://www.spywareinfo.com), so we do not offer any warranties of any kind regarding this program.
> 
> Additionally, you should use the following program to look for any installed spyware on your system. This program is called “Spybot Search and Destroy”. It’s a free program that works quite well. NOTE, you have to UPDATE it first (click update in the program), since the default version doesn’t have all the latest spyware definitions.
> 
> Here is the link: [http://www.safer-networking.org](http://www.safer-networking.org).
> 
> After doing this, we strongly recommend you to update your system, clicking on the link [http://windowsupdate.microsoft.com](http://windowsupdate.microsoft.com) There is a security scanner there, you can easily scan and fix all your system’s vulnerabilities. You should visit this url and scan your system very often, in order to keep your browser free from hijacks and other even worst things.
> 
> Legal Notice: we are not affiliated with any of the programs provided above, these are simply links to help you, provided to your as is, with no warranties of any kind.

I’m not saying I believe them, but this is their policy. Judging by how rapidly CWS mutates, I suppose it is reasonable to conclude it may be the work of many affiliates working independently rather than one company.

---

<div class="post-metadata">

**Author:** ![Cillasi](https://avatars.discourse-cdn.com/v4/letter/c/71e660/32.png) [@Cillasi](https://boards.straightdope.com/u/Cillasi)\
**Post date:** [June 1, 2004, 12:52am UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/9 "2004-06-01T00:52:29Z")

</div>

> [@](#):
>
> …we are buying surfers’ searches from webmasters all over the world. Maybe some webmasters, who are sending visitor traffic to us, are challenging your system’s security. We are not aware of this, nor are responsible for this.

That’s like a company saying they manufacture guns but not ammunition. They manufacture a product that can specifically tag itself to a certain webmaster and the webmaster gets paid for every search hit to CWS. What further temptation is needed to make the ammunition (browser hijack) to fire the gun (CWS)?

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [June 1, 2004, 1:56am UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/10 "2004-06-01T01:56:01Z")

</div>

The disclaimer is, of course, bullshit. CoolWebSearch is most certainly behind the hijacking (it happens if you visit their own pages – they don’t know about that?).

---

<div class="post-metadata">

**Author:** ![wolf\_meister](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wolf_meister/32/15202_2.png) [@wolf\_meister](https://boards.straightdope.com/u/wolf_meister)\
**Post date:** [June 1, 2004, 2:55am UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/11 "2004-06-01T02:55:52Z")

</div>

The CWS quote:  
_Maybe some webmasters, who are sending visitor traffic to us, are challenging your system’s security. We are not aware of this, nor are responsible for this._

What incredible bullshit. If some webmasters are challenging your system’s security, \*“We are not aware of this.” \*  
If they are NOT aware of it, then why do they mention it?  
Sheesh. Incidentally, if my SDMB name is wolf\_meister, I am not aware of it. :rolleyes:

---

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [June 1, 2004, 4:42am UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/12 "2004-06-01T04:42:32Z")

</div>

ARE there any movements to enact laws against spyware? If you ask me, this stuff is worse than spam and telemarketing put together!

---

<div class="post-metadata">

**Author:** ![wolf\_meister](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wolf_meister/32/15202_2.png) [@wolf\_meister](https://boards.straightdope.com/u/wolf_meister)\
**Post date:** [June 1, 2004, 4:58am UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/13 "2004-06-01T04:58:32Z")

</div>

**Guinastasia**  
Yes spyware is really getting malevolent - it has almost destroyed my neighbor’s computer: [http://boards.straightdope.com/sdmb/showthread.php?t=259005](http://boards.straightdope.com/sdmb/showthread.php?t=259005)  
And that link connects to _another_ link about that problem.

This is worse than telemarketing. At least when you are through talking with a telemarketer, your phone doesn’t blow up !!!

---

<div class="post-metadata">

**Author:** ![Grrr](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/grrr/32/146_2.png) [@Grrr](https://boards.straightdope.com/u/Grrr)\
**Post date:** [June 1, 2004, 7:37am UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/14 "2004-06-01T07:37:30Z")

</div>

My computer is so jacked up from this bs right now that I’m gonna have to spend 60 bucks for some somputer tech to fix my computer back. :mad: not to mention the hassle of un-hooking my computer and taking it down to the shop.

---

<div class="post-metadata">

**Author:** ![KellyM](https://avatars.discourse-cdn.com/v4/letter/k/57b2e6/32.png) [@KellyM](https://boards.straightdope.com/u/KellyM)\
**Post date:** [June 1, 2004, 1:02pm UTC](https://boards.straightdope.com/t/who-writes-spyware/247942/15 "2004-06-01T13:02:04Z")

</div>

The vast majority of spyware is written by questionably ethical private companies seeking to gather marketing information so they can sell it to questionably ethical private companies seeking to spam you with advertising.

However, a small portion of spyware is apparently written by or for the government; the FBI reportedly has a small arsenal of keystroke loggers and other such nasties that it has reportedly unleashed from time to time to gather evidence against child pornographers and against suspected terrorists. As far as I know, none of the evidence collected in this way has ever been used in court.
