Reply
Bot Obliterator
Quads
Posts: 13,246
Registered: ‎07-21-2008

Re: happili redirect

[ Edited ]

vmbray wrote:

Thanks, I looked at the other thread and ran the combofix with the script (yes the one that was only for the other user- but it only does java cache, didn't see that hurting anything) and it seems to have fixed it.  Reported userinit.exe was infected and repaired it.  I'll keep an eye on it.  I'm a big proponent of reloading once every year or so to get back the spunk but just now I am really tired of loading software due to work stuff so if it works I'll leave it and reload later.

 

Thanks to you and the other forum members who posted, saved me loads of time!!!



Notice Combofix did more than the java cache people??   

 

Think about this Combofix is told to do the Java Cache but incorrectly does something to a file or registry entry, like delete or attempted curing so that objects get corrupt or are missing.

The user then states  "I can't load or get into windows now after running combofix,  I used another users script"

 

Then they expect the malware removal crew to fix the problem without knowing what was taken or done, because people don't take notice of the warnings.

 

In the case above you are lucky as combofix did more than you intended and if something went wrong with the file stated, you would not be able to logon to your Windows User Account.

 

More like bamital variants

 

Quads

Bot Obliterator
Quads
Posts: 13,246
Registered: ‎07-21-2008

Re: happili redirect

Norton's  Sonar has definitions for files as follows

 

Packed.Generic.344 FakeAV, zeroaccess
Packed.Generic.350 Trojan.zbot, zeroaccess / Pihar
Packed.Generic.360 Trojanzbot, Pihar, Zeroaccess added April 5, 2012

 

Hopefully that will stop a lot of droppers / installers for now, before more damage is done 

 

Example https://www.virustotal.com/file/fc2f91bfdd3be029db22423e39d460d2583b721fd801cedb8fb5d93220bcc37e/ana...

 

Quads

Newbie
SunnyB
Posts: 1
Registered: ‎04-10-2012

Re: My computer is infected with Happili redirect problem.

I have just self-diagnosed that I too have Happili redirect problem.  I have not made any steps other than Norton scan.  Please help.

Super Trojan Terminator
Krusty13
Posts: 3,301
Registered: ‎05-31-2011

Re: My computer is infected with Happili redirect problem.

Welcome SunnyB,

 

Your best chance at getting help with this would be to start your own thread.  Please include your version of Windows,  Service Packs installed and whether 32-bit or 64-bit.

 

Please DO NOT run any other scans.

 

And PLEASE BE PATIENT.

 

Cheers,  Dave.

Windows 7 x64 SP1     N360v20.3.1.22     NU16     SSR 2013     Secunia PSI     SpywareBlaster     NoScript     MBAM free     SAS free

Visitor
jackm
Posts: 2
Registered: ‎04-13-2012

Re: happili redirect

[ Edited ]

 Happili virus

 

Kids don’t try this at home, NOT for beginners

 ---------------------

I had this, along with a world of malware hurt on my two antique desktop xp machines, I decided I had p*ssed someone off, happili was just one more and only one of what turned out to be about five redirects, or more, some would hijack me for one interruption, a few went for three before letting me get back to work

 ---------------------------

I had a very long exchange with malwarebytes.com and Microsoft security, in the end they provided no help, I have become quite expert in the huge domain of malware removal, and learned a lot about cr*p; on my machine

 -------------------------

I am self-taught geek enough to know that there were probably multiple separate attacks, and multiple separate locations in my machine where these malware (plural noun) lay lurking

 ------------------------------

After a while I started to read the Redirect websites, not just curse and saw that they came with urls, happili is the most obnoxious, placing its name prominently atop the hijack page

 ------------------------------

I captured (copied) the urls for at least five, and saved them to notepad, and studied them, ‘study’ means stare at, and hope for creativity and inspiration

 ------------------------------

The light bulb half went off, I decided/ speculated that these malware urls were hard-coded into the invasions, only b/c I was flailing

 -----------------------

I then did a string search, or substring, a ‘string’ is geek talk – ‘www.happli.com ‘ is a string, ‘happili’ is a string, all find and replace commands operate on ‘strings’

 ----------------------

I used agent ransack, which I inherited sort of by accident, after another malware defeated my Search command,

 

--

 

- -------------------------------

 

and !   f**k   y**r   m*th*r,   ! happili was polluting my machine, so what to do now

 ----------------------------

to mass delete would probably delete my operating system I have done that in the past, land-fill time

 -----------------------------

many of the happili pollutants were *. Sqlite file, where * is a place holder for a file name

 -------------------

SQLite is, I think Structured Query Language, lite, Oracle and DB2 database programmers will recognize the acronym

 ----------------------------------

So I deleted these, and also _cache_ several copies, b/c the malware writes itself into cache, not explained here, I also ran ccleaner before and after each internet session, which erases all my passwords etc, and erased all my histories etc, with browser tools options, IE and Mozilla, which exist in so many places that you really have no privacy, and inside various {system restore} locations, kids don’t try this at home, and be sure to backup your data and bookmarks etc, removable usb disk, is A Good Idea

 -------------------------------

And then I was faced with a dilemma, happily had written itself into my google profile, deleting a profile sounded BAD (it is)

 ---------------------------------

The malware infestation abated, only to recur, but I now knew where and how to look, and what to delete, this is a holding action, but works

 ---------------------------

These files infested with the happili string, can be examined in agent ransack, where I saw the entire url, and the other urls which Redirected me – note these are NOT text files, but have text embedded, the redirect pests will mature after reading this

 --------------------

Aha, M*Fr, gotcha!

 ---------------------------------

These files also have Properties, they are windows objects, and these properties have creation dates, so I now knew when they had started, and saw that hey were new and post-dated my cleanup efforts, so I was being reinfected, which I had thought

 -----------------------------

I also found, after a while a *.sc file, which is a java script, I think, which had not only the happily string and also the name of a wiki file where I had just been, from which I decided that the wiki file had been infected by the happily virus when I opened the wiki file the virus came down and created the sqlite and sc files, the timing was all consistent,

 ----------------------------

So I clobbered (deleted) them (Marvel comix fans may remember Hulk and ‘clobbering time’)

 

Which worked pretty good, but I still had the Mozilla profile problem, this was some Trojan horse, to let the virii back in I was afraid, the profile name is random characters, and virii infiltrate with random character name generators, to defeat name-specific anti-malware searching, so I decided the profile was a Trojan horse and deleted it

 -------------------------

At which point Mozilla stopped working, but I still had IE, so I uninstalled and reinstalled Mozilla, and it started worked

 -------------------------

The error message was bizarre, when I tried to commence a session it said the previous session was running and had to be manually stopped, but task manager did not have any information, of a concurrent or stalled session, and a hard reboot (power down) did not help either, uninstall/ reinstall helped, the first time, turns out I had two profiles in Mozilla

 ----------------------------------

So I am now happily working away and whap! happili is back, so I delete all the happily infested files, and also the profile, just in case, and now Mozilla won’t work even with uninstall reinstall

 ----------------------------------

So now I have to think

  ----------------------------------

At an IE session, searching on my error message, I see that my error message means that I have a Mozilla profile problem, indeed I do I have no Mozilla profile, so I search on ‘fix this error’ and find that there is a one line command to create a Mozilla profile, using 'default', and I am back in biz, happily not happili, the profile-name is a random character set (or string) so now I know that the random string is mozilla’s not happili’s and I am happy

  ----------------------------------

So I do not know about prevention, that is for Norton etc, but I know about removal, manually, I have gotten pretty fast at it, and the bad guys now know how to defeat the good guys, on this,

 

 

[edit: Please do not link to malicious websites per the Participation Guidelines and Terms of Service.]

Visitor
Ajones3745
Posts: 2
Registered: ‎04-25-2012

Re: My computer is infected with Happili redirect problem.

Quad, my computer is infected with the Happili redirect.  I have followed your directions on creating logs from aswMBR and OTL.exe.  I am attaching the logs.  I only ran the scans and saved the logs.  I am attaching the logs an "extras" log was created and I'm including that as well. if there is anything you can do to help, I'd appreciate it.  Thanks

Newbie
naythor
Posts: 1
Registered: ‎04-28-2012

I also have the happili redirect problem

[ Edited ]

Hi Quads, I too have the happili redirect problem. Would appreciate any help you can give me.

Bot Obliterator
Quads
Posts: 13,246
Registered: ‎07-21-2008

Re: I also have the happili redirect problem

[ Edited ]

What is it about people using more advanced tools??   

One log is not complete, One log was run with extras selected as well. though I do see the symptoms.

 

Quads