Happili Virus

novice22

New member
Local time
6:45 AM
Messages
12
Hello,

I seem to have also contracted the Happili Virus on my PC. I know there are multiple posts on this but they all seem to be following different steps on a case-specific basis so I figured to start my own. Please let me know how I can remove thise as it's become a substantial nuisance.

Thank You,
Novice22
 

My Computer

Computer Manufacturer/Model Number
HP
OS
Windows 7 Professional 64 Bit
CPU
Intel core i7-2600
Memory
12 GB
Download DDS from one of these links:
Mirror 1 Mirror 2 Mirror 3
  • Disable any script blocking protection
  • Double click the dds icon to run the tool.
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt <--- will be minimized in the task tray
  • Save both reports to your desktop.
Include the contents of both logs in your next post.
The scan will instruct you to post Attach.txt as an attachment.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Two Log Files

Please find both of my log files that you requested attached here, let me know how to proceed. Thanks a lot!
 

Attachments

My Computer

Computer Manufacturer/Model Number
HP
OS
Windows 7 Professional 64 Bit
CPU
Intel core i7-2600
Memory
12 GB
I see you've run Combofix .... was it run with help on a security forum?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Yes

I did try to run combofix to get this off the computer about a month ago with no luck. I had thought it was removed prior to a few days ago when it began redirecting my searches again.
 

My Computer

Computer Manufacturer/Model Number
HP
OS
Windows 7 Professional 64 Bit
CPU
Intel core i7-2600
Memory
12 GB
We need to get a current copy of CF....

Click on the Start button and then select Run from the menu. This will open up the Run box.
Copy/Paste combofix /uninstall (Please note that there is a space between combofix and /uninstall), click on the OK button or Enter on your keyboard.
You can now delete the ComboFix.exe program from your computer

Next,

Download Combofix from any of the links below, and save it to your desktop.<--Important
Link 1
Link 2
Link 3

Click on this link Here to see a list of programs that should be disabled.
The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
Next: Disconnect from the internet. If you are on Cable or DSL, unplug your computer from the modem.
Next: Please disable all onboard security programs (all running with back ground protection) as it may hinder the scanner from working.

This includes Antivirus, Firewall, and any Spyware scanners that run in the background.
  • Double click combofix.exe and follow the prompts.
  • When finished, it will produce a log for you.
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Please be patient while the scan runs, at times it may appear to stall.
When finished and after reboot (in case it asks to reboot), it should open a log, combofix.txt.
Post this log in your next reply
After rebooting ensure your Security applications have been re-enabled.

In your next reply post:
ComboFix.txt
***A guide and tutorial on "How to use Combofix" can be found here:
A guide and tutorial on using ComboFix

IF CF won't run:
During the download, rename Combofix.exe to sVchost.exe
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
combofix

Please see attached.
 

Attachments

My Computer

Computer Manufacturer/Model Number
HP
OS
Windows 7 Professional 64 Bit
CPU
Intel core i7-2600
Memory
12 GB
Why didn't you finish the malware topic here? :confused: Happili Redirect Virus

Please flush the DNS cache and restore MS's hosts file. Copy and paste these lines in Note pad.

@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0


Save as flush.bat to your desktop.
Double click on the flush.bat file to run it.Vista and Windows 7... right click the .bat file and choose to run as Administrator. Your computer will reboot itself.

Next, download TFC by Old Timer TFC - Temp File Cleaner by OldTimer - Geeks to Go Forums and save it to your desktop.
Save any unsaved work. TFC will close ALL open programs including your browser!
Double-click on TFC.exe to run it. If you are using Vista/Windows 7 right-click on the file and choose Run As Administrator.
Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.

After doing the above, I'd like you to scan your machine with ESET OnlineScan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the
    esetOnline.png
    button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on
      esetSmartInstall.png
      to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the
      esetSmartInstallDesktopIcon.png
      icon on your desktop.
  4. Check
    esetAcceptTerms.png
  5. Click the
    esetStart.png
    button.
  6. Accept any security warnings from your browser.
  7. Check
    esetScanArchives.png
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
    esetListThreats.png
  11. Push
    esetExport.png
    , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the
    esetBack.png
    button.
  13. Push
    esetFinish.png
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
ESETScan

Thanks again for the help, please see attached.
 

Attachments

My Computer

Computer Manufacturer/Model Number
HP
OS
Windows 7 Professional 64 Bit
CPU
Intel core i7-2600
Memory
12 GB
Do you use a proxy?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
I also have the happili virus. Please help.

Jaycee,

I also got the happili virus and after following what you mentioned as far as combo fix now I no longer have internet access on my laptop.

Update: 12:38AM- I simply had to reboot and I have the internet back. I am now running the ESET Online Scanner you suggested next. After clearing the cache as you instructed. Nothing was detected.

Update: 1:59AM- I followed all the instructions you gave on the various posts and it seems to have worked. Thank you so much for all of your help indirectly.

Saved my new laptop from certain death and/or me having to take it to a shop.
 
Last edited:

My Computer

OS
Windows Home Premium 32 bit
Proxy

No I don't believe so.
 

My Computer

Computer Manufacturer/Model Number
HP
OS
Windows 7 Professional 64 Bit
CPU
Intel core i7-2600
Memory
12 GB
novice22,

Download HijackThis!
HijackThis - Trend Micro USA
Right click on HJT to run it as Administrator, then click 'Do a System Scan and Save logfile'.
The HJT log will open in notepad.
Copy and paste the HJT log from notepad
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
hijackthis

Please see attached
 

Attachments

My Computer

Computer Manufacturer/Model Number
HP
OS
Windows 7 Professional 64 Bit
CPU
Intel core i7-2600
Memory
12 GB
You aren't running any Antivirus software! Please download Microsoft Security Essentials Microsoft Security Essentials - Free Antivirus for Windows And make sure Windows Firewall is set to "automatic" in services.

Next, uninstall Chrome and its folders. Reinstall a new copy.

Now let me know if you're still getting re-directed searches.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hi Jacee. I figured I would just post in here instead of making a new topic as not to clutter the forums. I have had the happili virus for a while now. A few weeks ago, I realized that I had it; I was getting redirected and getting FPS lag in games that I play. I spent a lot of time trying to figure out how to get rid of it and ended up doing a system restore to before I thought I got it, and it was gone for about a week and a half (I thought it was gone for good). Now it is back, and although it is not the same, as in I am getting no FPS drop, just redirects from time to time, it is equally concerning.
I have run TDSS killer multiple times, malware bytez, and I have avast installed and have run that as well. I used the solution that you suggested with the flush.bat file and the temp cleaner, and after doing that, I checked and was redirected not to happili, but to some random tumblr or twitter page about cooking... and just now I tried again and got the same old Happili page.

I am using firefox and have windows 7 64 bit. I am currently running ESET and it has been scanning at 99% for about half an hour now so I figured I would go ahead and post. If you do not see this and respond by the time the scan finishes, I'll post the results here.
Thanks!
 

My Computer

Computer Manufacturer/Model Number
sager
OS
windows 7 home 64bit
Memory
4 gb ram
Graphics Card(s)
Nvidea
Please don't tag on to this topic. :cry:

I am but one person (here) trying to help, but you could start your own topic so you can each be helped individually in the forums listed. You can get help Here:
Malware Removal - HijackThis Logs - Malwarebytes Forum
Virus, Trojan, Spyware, and Malware Removal Logs - BleepingComputer.com
Virus, Spyware & Malware Removal - What the Tech

We ("trained" malware analyzers/experts) are all working to find the 'direct cause' of this obnoxious re-direct, and we're ready to help in the above Anti-Malware forums listed.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Sorry about that, thank you for your response; I am in the process of making a post for bleepingcomputer.com
 

My Computer

Computer Manufacturer/Model Number
sager
OS
windows 7 home 64bit
Memory
4 gb ram
Graphics Card(s)
Nvidea
I totally understand and I wish you the best of 'clean' computer :)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Completed

Jaycee,

I've followed all of your instructions, however, I don't know yet if the problem is resolved because the issue was pretty sporatic initially anyway. However, when I start my computer I now have the following RunDll errors pop up where it's missing these files:

...Missing...

AppData\Local\Temp\eteang.dll

AppData\Local\Temp\taprc.dll

AppData\Local\Temp\nspsl.dll

AppData\Local\Temp\widmf.dll

AppData\Local\Temp\wiplet.dll
 

My Computer

Computer Manufacturer/Model Number
HP
OS
Windows 7 Professional 64 Bit
CPU
Intel core i7-2600
Memory
12 GB
Back
Top