?
Solved

"www.1861.sh" popup

Posted on 2006-11-04
9
Medium Priority
?
198 Views
Last Modified: 2013-12-04
Anyone know how to get rid of "www.1861.sh" site from popping up? It appears to be a Chinese ringtone sales site. I can't get rid of it, none of my spyware utilities sees it (Counterspy, Spyware Doctor, Hijackthis, Spybot, Ad Aware).

I have added it to Restricted Sites in IE but it still pops up every 1/2 hour or so.

I have since set IE to block all popups and have reset all IE security levels to their default position. We'll see how that works.

Anyone else been annoyed by this 1861.sh site??

Thanks
0
Comment
Question by:countryfreshness
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
9 Comments
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 17874628
Let's look at your hiackthis log, don't fix anything though, I'd like to see what entries are there.

Upload the log at EE-Stuff.com or at any hosting sites, or if you have trouble uploading it just paste it here.
0
 

Author Comment

by:countryfreshness
ID: 17874847
*** Hijack This log removed by humeniuk PE ***
0
 

Author Comment

by:countryfreshness
ID: 17875281
It's all good. I uploaded and it checked out OK. The site seems harless enough. It seems to come from a large telecom company in China.
0
 

Author Comment

by:countryfreshness
ID: 17895211
I figured it out.

In the Windows\System32 folder I found and deleted the following files:

STHU1.EXE, STHU2.EXE, STHU3.EXE, D3802E40.DLL, D3802E40.EXE and D3802E40T.EXE

The DLL file I used Killbox to remove on reboot.

No popup of 'www.1861.sh' since then.

0
 
LVL 1

Accepted Solution

by:
Computer101 earned 0 total points
ID: 19561237
PAQed with points refunded (125)

Computer101
EE Admin
0

Featured Post

Four New Appliances. Same Industry-leading Speeds.

But don't take it from us.  The Firebox M370 is Miercom tested and Miercom approved, outperforming its competitors for stateless and stateful traffic throughput scenarios.  Learn more about the M370, M470, M570 and M670 and find the right solution for your organization today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
Add bar graphs to Access queries using Unicode block characters. Graphs appear on every record in the color you want. Give life to numbers. Hopes this gives you ideas on visualizing your data in new ways ~ Create a calculated field in a query: …
In this video, Percona Solution Engineer Rick Golba discuss how (and why) you implement high availability in a database environment. To discuss how Percona Consulting can help with your design and architecture needs for your database and infrastr…
Suggested Courses
Course of the Month12 days, 21 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question