Solved

"www.1861.sh" popup

Posted on 2006-11-04
9
191 Views
Last Modified: 2013-12-04
Anyone know how to get rid of "www.1861.sh" site from popping up? It appears to be a Chinese ringtone sales site. I can't get rid of it, none of my spyware utilities sees it (Counterspy, Spyware Doctor, Hijackthis, Spybot, Ad Aware).

I have added it to Restricted Sites in IE but it still pops up every 1/2 hour or so.

I have since set IE to block all popups and have reset all IE security levels to their default position. We'll see how that works.

Anyone else been annoyed by this 1861.sh site??

Thanks
0
Comment
Question by:countryfreshness
  • 3
9 Comments
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 17874628
Let's look at your hiackthis log, don't fix anything though, I'd like to see what entries are there.

Upload the log at EE-Stuff.com or at any hosting sites, or if you have trouble uploading it just paste it here.
0
 

Author Comment

by:countryfreshness
ID: 17874847
*** Hijack This log removed by humeniuk PE ***
0
 

Author Comment

by:countryfreshness
ID: 17875281
It's all good. I uploaded and it checked out OK. The site seems harless enough. It seems to come from a large telecom company in China.
0
 

Author Comment

by:countryfreshness
ID: 17895211
I figured it out.

In the Windows\System32 folder I found and deleted the following files:

STHU1.EXE, STHU2.EXE, STHU3.EXE, D3802E40.DLL, D3802E40.EXE and D3802E40T.EXE

The DLL file I used Killbox to remove on reboot.

No popup of 'www.1861.sh' since then.

0
 
LVL 1

Accepted Solution

by:
Computer101 earned 0 total points
ID: 19561237
PAQed with points refunded (125)

Computer101
EE Admin
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
What is S-1-5-90-2? 16 311
Updating clients Trend Micro (OfficeScan) Console 5 78
Bombarded with 45000+ event ID from the same computer ? 10 69
deny local logon 12 78
Many people tend to confuse the function of a virus with the one of adware, this misunderstanding of the basic of what each software is and how it operates causes users and organizations to take the wrong security measures that would protect them ag…
No security measures warrant 100% as a "silver bullet". The truth is we also cannot assume anything but a defensive and vigilance posture. Adopt no trust by default and reveal in assumption. Only assume anonymity or invisibility in the reverse. Safe…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now