Shopica redirect I can't get rid of!!

Thread Solved

Join Date: Nov 2009
Posts: 26
Reputation: jw22 is an unknown quantity at this point 
Solved Threads: 0
jw22 jw22 is offline Offline
Light Poster
 
0
  #11
31 Days Ago
I did as instructed, still being redirected. When I rebooted, windows defender came up and said that "Trojan:win/32/Alureon.ct" was detected. I removed it.

The reason it ran twice was because a few days ago I ran it in an amateurish attempt at fixing this myself.
Reply With Quote Quick reply to this message  
Join Date: Nov 2009
Posts: 26
Reputation: jw22 is an unknown quantity at this point 
Solved Threads: 0
jw22 jw22 is offline Offline
Light Poster
 
0
  #12
31 Days Ago
I also tried to run anti-spyware and nothing came up
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 959
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 46
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Posting Shark
 
0
  #13
31 Days Ago
Originally Posted by jw22 View Post
I also tried to run anti-spyware and nothing came up
I'm curious about this one:

Please navigate to the file in bold below and upload it here for analysis and let us know what you find ---> http://virusscan.jotti.org/
c:\windows\system32\windrv.sys

I'd also suggest a GMER run, if crunchie concurs...

PP


EDIT: You can get deldomains here without registering:
http://www.mvps.org/winhelp2002/restricted.htm
Last edited by PhilliePhan; 31 Days Ago at 8:57 pm. Reason: Added info
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,046
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 761
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer
 
0
  #14
31 Days Ago
Please Run the ESET Online Scanner and post the ScanLog with your post for assistance.
  • You will need to use Internet Explorer to complete this scan.
  • You will need to temporarily Disable your current Anti-virus program.
  • Be sure the option to Remove found threats is Un-checked at this time (we may have it clean what it finds at a later time), and the option to Scan unwanted applications is Checked.
  • When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please post that log for us as directed below.
NOTE: If you are unable to complete the ESET scan, please try another from the list below:
Kaspersky Online Scanner
Panda Active Scan
Trend Micro HouseCall
F-Secure Online Virus Scanner
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 959
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 46
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Posting Shark
 
0
  #15
31 Days Ago
Originally Posted by jw22 View Post
"Trojan:win/32/Alureon.ct" was detected.
This is a DNS changer / cache poisoner in the TDSS family. You guys might want to have a look in that direction....

Cheers
PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,046
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 761
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer
 
0
  #16
31 Days Ago
I didn't see your 1st post PP. I am not sure thar deletedomains works with Vista. Thats why I deleted my post.
MBA-M could also be updated and run to see if it picks anything up.

Gmer can be run too .
Reply With Quote Quick reply to this message  
Join Date: Nov 2009
Posts: 26
Reputation: jw22 is an unknown quantity at this point 
Solved Threads: 0
jw22 jw22 is offline Offline
Light Poster
 
0
  #17
31 Days Ago
ESET found nothing. The log:
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
Reply With Quote Quick reply to this message  
Join Date: Nov 2009
Posts: 26
Reputation: jw22 is an unknown quantity at this point 
Solved Threads: 0
jw22 jw22 is offline Offline
Light Poster
 
0
  #18
31 Days Ago
Also, I dont know if this is of any consequence, but running IE starts an internet security warning to appear saying a website wants to open web content using this program on your computer. Then has a button for "allow" and "Don't allow" There are two publishers that alternated: either AOL LLC or Adobe Flash player...these continually pop up even after saying "don't allow"....might not be relevant, but I thought i'd mention it...don't know how long this has been happening, since I rarely use IE.
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,046
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 761
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer
 
0
  #19
31 Days Ago
Not the full ESET log, but if nothing found, it doesn't matter.
Have you run Gmer as PP suggested?

Not sure about those warnings. Programs appear to be legit.
Reply With Quote Quick reply to this message  
Join Date: Nov 2009
Posts: 26
Reputation: jw22 is an unknown quantity at this point 
Solved Threads: 0
jw22 jw22 is offline Offline
Light Poster
 
0
  #20
31 Days Ago
Running it now...that was all that was in the log file for ESET...is there a log I need to post, or might this just clear up the redirect?
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC