944,189 Members | Top Members by Rank

Ad:
You are currently viewing page 2 of this multi-page discussion thread; Jump to the first page
Nov 4th, 2009
0
Re: Shopica redirect I can't get rid of!!
I did as instructed, still being redirected. When I rebooted, windows defender came up and said that "Trojan:win/32/Alureon.ct" was detected. I removed it.

The reason it ran twice was because a few days ago I ran it in an amateurish attempt at fixing this myself.
Reputation Points: 10
Solved Threads: 0
Light Poster
jw22 is offline Offline
26 posts
since Nov 2009
Nov 4th, 2009
0
Re: Shopica redirect I can't get rid of!!
I also tried to run anti-spyware and nothing came up
Reputation Points: 10
Solved Threads: 0
Light Poster
jw22 is offline Offline
26 posts
since Nov 2009
Nov 4th, 2009
0
Re: Shopica redirect I can't get rid of!!
Click to Expand / Collapse  Quote originally posted by jw22 ...
I also tried to run anti-spyware and nothing came up
I'm curious about this one:

Please navigate to the file in bold below and upload it here for analysis and let us know what you find ---> http://virusscan.jotti.org/
c:\windows\system32\windrv.sys

I'd also suggest a GMER run, if crunchie concurs...

PP


EDIT: You can get deldomains here without registering:
http://www.mvps.org/winhelp2002/restricted.htm
Last edited by PhilliePhan; Nov 4th, 2009 at 8:57 pm. Reason: Added info
Moderator
Reputation Points: 169
Solved Threads: 106
Central Scrutinizer
PhilliePhan is offline Offline
1,576 posts
since Dec 2006
Nov 4th, 2009
0
Re: Shopica redirect I can't get rid of!!
Please Run the ESET Online Scanner and post the ScanLog with your post for assistance.
  • You will need to use Internet Explorer to complete this scan.
  • You will need to temporarily Disable your current Anti-virus program.
  • Be sure the option to Remove found threats is Un-checked at this time (we may have it clean what it finds at a later time), and the option to Scan unwanted applications is Checked.
  • When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please post that log for us as directed below.
NOTE: If you are unable to complete the ESET scan, please try another from the list below:
Kaspersky Online Scanner
Panda Active Scan
Trend Micro HouseCall
F-Secure Online Virus Scanner
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,165 posts
since Feb 2004
Nov 4th, 2009
0
Re: Shopica redirect I can't get rid of!!
Click to Expand / Collapse  Quote originally posted by jw22 ...
"Trojan:win/32/Alureon.ct" was detected.
This is a DNS changer / cache poisoner in the TDSS family. You guys might want to have a look in that direction....

Cheers
PP
Moderator
Reputation Points: 169
Solved Threads: 106
Central Scrutinizer
PhilliePhan is offline Offline
1,576 posts
since Dec 2006
Nov 4th, 2009
0
Re: Shopica redirect I can't get rid of!!
I didn't see your 1st post PP. I am not sure thar deletedomains works with Vista. Thats why I deleted my post.
MBA-M could also be updated and run to see if it picks anything up.

Gmer can be run too .
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,165 posts
since Feb 2004
Nov 4th, 2009
0
Re: Shopica redirect I can't get rid of!!
ESET found nothing. The log:
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
Reputation Points: 10
Solved Threads: 0
Light Poster
jw22 is offline Offline
26 posts
since Nov 2009
Nov 4th, 2009
0
Re: Shopica redirect I can't get rid of!!
Also, I dont know if this is of any consequence, but running IE starts an internet security warning to appear saying a website wants to open web content using this program on your computer. Then has a button for "allow" and "Don't allow" There are two publishers that alternated: either AOL LLC or Adobe Flash player...these continually pop up even after saying "don't allow"....might not be relevant, but I thought i'd mention it...don't know how long this has been happening, since I rarely use IE.
Reputation Points: 10
Solved Threads: 0
Light Poster
jw22 is offline Offline
26 posts
since Nov 2009
Nov 4th, 2009
0
Re: Shopica redirect I can't get rid of!!
Not the full ESET log, but if nothing found, it doesn't matter.
Have you run Gmer as PP suggested?

Not sure about those warnings. Programs appear to be legit.
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,165 posts
since Feb 2004
Nov 4th, 2009
0
Re: Shopica redirect I can't get rid of!!
Running it now...that was all that was in the log file for ESET...is there a log I need to post, or might this just clear up the redirect?
Reputation Points: 10
Solved Threads: 0
Light Poster
jw22 is offline Offline
26 posts
since Nov 2009

This thread is solved

Either the thread starter or a moderator has marked this thread as solved. You can most likely trust the responses and answers given. There is most likely no reason for any further responses to be posted here. If you have a related question, please start a new thread in this forum instead.

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: Problems with my comp
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: DDoS for sale





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC