Reply
Contributor
armygirl44
Posts: 22
Registered: ‎05-12-2012

Re: Browser redirect issues - possible Happili infection? (help, Quads...)

Renamed combofix.exe as badfile.exe but got the same error:

 

CFScript Name Error

Were you trying to run CFScript?

The name, CFScript appears to be incorrectly spelt

Bot Obliterator
Quads
Posts: 13,254
Registered: ‎07-21-2008

Re: Browser redirect issues - possible Happili infection? (help, Quads...)

Shift Combofix to the system root directory   C:\combofix.exe,  bad..... or what ever.   and try from it located there.

 

Quads

Contributor
armygirl44
Posts: 22
Registered: ‎05-12-2012

Re: Browser redirect issues - possible Happili infection? (help, Quads...)

Just want to confirm my guess that I need to move the cfscript.txt file to same location?

Bot Obliterator
Quads
Posts: 13,254
Registered: ‎07-21-2008

Re: Browser redirect issues - possible Happili infection? (help, Quads...)

Probably easier to have them both in the same location unless you want to have the small C:\ windows open and still have the desktop showing and drag the script right across.

 

Quads

Contributor
armygirl44
Posts: 22
Registered: ‎05-12-2012

Re: Browser redirect issues - possible Happili infection? (help, Quads...)

That did it - ComboFix ran with no issues this time.  As you said would happen after CF finished, got a couple of warnings about programs trying to perform illegal operations on registry keys marked for deletion.  Rebooted as instructed, and that seems to have resolved it.  CF log is attached.

Bot Obliterator
Quads
Posts: 13,254
Registered: ‎07-21-2008

Re: Browser redirect issues - possible Happili infection? (help, Quads...)

Download a new  copy of Combofix like the main instructions in the past and so on, on to your desktop but this time run it without any script.

Have to make sure one of the files is gone.

 

You Could also have  a permissions problem with files / folders.

 

Also you do or did have Malwarebytes running with it's realtime protection running (another security product), or it could be that the infection hurt Norton.

 

Quads

Contributor
armygirl44
Posts: 22
Registered: ‎05-12-2012

Re: Browser redirect issues - possible Happili infection? (help, Quads...)

Downloaded a new copy of CF to the desktop and ran it as instructed.  (Did not delete the copy we placed in the root directory since you didn't say to do so - hope that was ok.)  Logfile is attached.

Contributor
armygirl44
Posts: 22
Registered: ‎05-12-2012

Re: Browser redirect issues - possible Happili infection? (help, Quads...)

Forgot to add - didn't have any other security product running that I am aware of.  Removed mbam several steps ago, when instructed to do so.  Norton seems to be running OK now - the error code I reported getting previously when attempting to access the security history is no longer occuring.

 

Bot Obliterator
Quads
Posts: 13,254
Registered: ‎07-21-2008

Re: Browser redirect issues - possible Happili infection? (help, Quads...)

The file detected is a False Positive  ( I went and looked it up)

 

Please read carefully and Slowly

 

 Please scan with ESET next   Using Internet Explorer


I'd like us to scan your machine with ESET OnlineScan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and DON'T (NO) check Remove found threats (reason for this is we don't want something deleted and then Windows won't load).
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • Attach the resulting log in your next reply


If you think a log should have been generated then go to C:\Program Files\ESET\ESET Online Scanner\log.txt to find it. 

 

Quads

Contributor
armygirl44
Posts: 22
Registered: ‎05-12-2012

Re: Browser redirect issues - possible Happili infection? (help, Quads...)

Wow, that one took awhile.  Came up clean, though - that's a relief.

 

Log is attached.