Need help removing Happili redirect virus

mos1961

New member
Local time
7:15 AM
Messages
5
Greetings,

I have contracted the evil Happili redirect virus and need assitance in eradicating it. I saw from a previous post that you had requested the attached files so I generated those. I'm lost from here.

Thanks in advance.
MOS
 

Attachments

My Computer

Computer Manufacturer/Model Number
Dell Inspiron 620 desktop
OS
Windows 7 64-bit
CPU
i5-2320 3.00 Ghz
Memory
8 GB
First, I want you to flush the dirty DNS cache and restore Microsoft's Hosts file:

Copy and paste these lines in Note pad.

@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0

Save as flush.bat to your desktop.
Double click on the flush.bat file to run it.Vista and Windows 7... right click the .bat file and choose to run as Administrator. Your computer will reboot itself.

After you have done the above,

Download Combofix from any of the links below, and save it to your desktop.<--Important
Link 1
Link 2
Link 3

Click on this link Here to see a list of programs that should be disabled.
The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
Next: Disconnect from the internet. If you are on Cable or DSL, unplug your computer from the modem.
Next: Please disable all onboard security programs (all running with back ground protection) as it may hinder the scanner from working.

This includes Antivirus, Firewall, and any Spyware scanners that run in the background.
  • Double click combofix.exe and follow the prompts.
  • When finished, it will produce a log for you.
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Please be patient while the scan runs, at times it may appear to stall.
When finished and after reboot (in case it asks to reboot), it should open a log, combofix.txt.
Post this log in your next reply
After rebooting ensure your Security applications have been re-enabled.

In your next reply post:
ComboFix.txt
***A guide and tutorial on "How to use Combofix" can be found here:
A guide and tutorial on using ComboFix

IF CF won't run:
During the download, rename Combofix.exe to sVchost.exe
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hello Jacee - Thank you very much for the assistance. I have followed the directions so far and have attached the combofix log.

Best regards,
MOS
 

Attachments

My Computer

Computer Manufacturer/Model Number
Dell Inspiron 620 desktop
OS
Windows 7 64-bit
CPU
i5-2320 3.00 Ghz
Memory
8 GB
Hello Jacee - This appears to have worked. I'm not seeing the redirects anymore. Does this complete the process? Don't want to assume anything. Please advise.

And once again, I can't thank you enough for the assistance. You and others like you provide an awesome service that help many, many people.

Thanks,
MOS
 

My Computer

Computer Manufacturer/Model Number
Dell Inspiron 620 desktop
OS
Windows 7 64-bit
CPU
i5-2320 3.00 Ghz
Memory
8 GB
I'd like you to scan your machine with ESET OnlineScan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the
    esetOnline.png
    button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on
      esetSmartInstall.png
      to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the
      esetSmartInstallDesktopIcon.png
      icon on your desktop.
  4. Check
    esetAcceptTerms.png
  5. Click the
    esetStart.png
    button.
  6. Accept any security warnings from your browser.
  7. Check
    esetScanArchives.png
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
    esetListThreats.png
  11. Push
    esetExport.png
    , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the
    esetBack.png
    button.
  13. Push
    esetFinish.png
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hello Jacee - Showed as finding 1 virus. Please see attached.

Thanks,
MOS
 

Attachments

My Computer

Computer Manufacturer/Model Number
Dell Inspiron 620 desktop
OS
Windows 7 64-bit
CPU
i5-2320 3.00 Ghz
Memory
8 GB
Okay, good. Download TFC by Old Timer TFC - Temp File Cleaner by OldTimer - Geeks to Go Forums and save it to your desktop.
Save any unsaved work. TFC will close ALL open programs including your browser!
Double-click on TFC.exe to run it. If you are using Vista/Windows 7 right-click on the file and choose Run As Administrator.
Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.

TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder. It also cleans out the %systemroot%\temp folder and checks for .tmp files in the %systemdrive% root folder, %systemroot%, and the system32 folder (both 32bit and 64bit on 64bit OSs). It shows the amount removed for each location found (in bytes) and the total removed (in MB). Before running, it will stop Explorer and all other running apps. When finished, if a reboot is required the user must reboot to finish clearing any in-use temp files.

After rebooting/restarting your computer:
Click on the Start button and then select Run from the menu. In the run box type (or copy/paste) ComboFix /Uninstall and click OK. Note the space between the X and the /, it needs to be there.

Download Secunia Personal Inspector and update all programs that are vulnerable to security exploits. Free Computer Security - Personal Software Inspector (PSI) - Secunia
Uncheck any "bundled" toolbars, search engines, etc that may be included with the setup.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hello Jacee,

This set of instructions is now complete as well. PSI found and patched 4 unsecure programs. Thanks again for all of your assistance. Life is better!

Best Regards,
MOS
 

My Computer

Computer Manufacturer/Model Number
Dell Inspiron 620 desktop
OS
Windows 7 64-bit
CPU
i5-2320 3.00 Ghz
Memory
8 GB
You're welcome :D

Now, remove Combofix ....
Click on the Start button and then select Run from the menu. This will open up the Run box.
Copy/Paste combofix /uninstall (Please note that there is a space between combofix and /uninstall), click on the OK button or Enter on your keyboard.
You can now delete the ComboFix.exe program from your computer
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hi I followed the instructions here, dns cache, combofix, TFC and dled PSI, but I'm still getting redirected to happili. I attached my combo and ESET log. I'm not sure what to do now.
 

Attachments

My Computer

OS
Windows 7 Ultimate x64
Hi if the mentioned steps above don't work, is there anything else I can do?
 

My Computer

OS
Windows 7 Ultimate x64
Still have the happili virus after following instructions of other thr

Hi I followed these instructions, http://www.sevenforums.com/system-s...ing-happili-redirect-virus-2.html#post1893255 twice, and still have the happili virus; is there anything else I can do?

I uploaded my combo log / eset scans

A couple notes: After none of it worked, I tried uninstalling firefox, but my computer wouldn't let me so I simply deleted all the files, and ran some antivirus programs that I saw here. Now, I use google chrome.

I also have this ask toolbar updater that I can't get rid of. I uninstalled the program a long time ago, but for some reason the updater remains. I attached a screenshot to show you clearly.
 

Attachments

My Computer

OS
Windows 7 Ultimate x64
Awww kelv211, you have a rootkit. I don't work in trying to remove this type of obnoxious infection. Please read this and you'll understand why I suggest a 'wipe and clean OS install'. You can't ever count on your computer to be stable again by just "cleaning". :( Rootkit - Wikipedia, the free encyclopedia
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Awww kelv211, you have a rootkit. I don't work in trying to remove this type of obnoxious infection. Please read this and you'll understand why I suggest a 'wipe and clean OS install'. You can't ever count on your computer to be stable again by just "cleaning". :( Rootkit - Wikipedia, the free encyclopedia
Aw okay, can you link me somewhere with instructions on how to do it? I"ve never wiped and cleaned my OS before
 

My Computer

OS
Windows 7 Ultimate x64

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
This should help you http://www.sevenforums.com/tutorials/1649-clean-install-windows-7-a.html?ltr=C

If not, then post your question:
"how to do it? I"ve never wiped and cleaned my OS before"
Here General Discussion - Windows 7 Forums
Thank you

I'd like to ask two things; What happens If I leave the rootkit on my computer? Can a rootkit prevent your computer's CD-R from working?

If all it does is redirect my browser, maybe I can leave it there a while longer. I am hesitant to wipe my system clean not only because I've never done it before, but my CD-R isn't working, which I'm paranoid is because of the rootkit.
 

My Computer

OS
Windows 7 Ultimate x64
Hi,

Leaving a rootkit on your PC will eventually bring it to its knees, and thats not mentioning all the keystrokes it might be sending back to the originator without your knowledge.

A clean install is most definately, without a shadow of a doubt, the best fix.

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Back
Top