happili.co m virus help
03-29-2012 03:02 PM
I have the happili.com virus on my computer. I would appreciate any help in getting this removed. I cant Use my Keyboard. Downloaded TDSSKiller. did not detect anything. I downloaded and ran the ComboFix.exe. The script ComboFix 12-03-29.02 - Dan and Yulichka 03/29/2012 17:18:16.1.2 - x86 .. . .. .Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3316.1777 [GMT -4:00] Running from: c:\users\Dan and Yulichka\Desktop\ComboFix.exe AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\Downloaded Program Files\IDropPTB.dll . . ((((((((((((((((((((((((( Files Created from 2012-02-28 to 2012-03-29 ))))))))))))))))))))))))))))))) . . 2012-03-29 21:08 . 2012-03-29 21:08 56200 ----a-w- c:\programdata\Microsoft\Wind
Re: happili.co m virus help
03-30-2012 05:09 AM
I have to try and figure out which driver has gone missing or is corrupt / infected
1. Download OTL hxxp://oldtimer.geekstogo.com/OTL.exe (change the hxxp to http) save it to your Desktop.
Double click on OTL.exe to run it. Right click OTL.exe and select run as administator for Vista and Win 7.
Click the Scan All Users checkbox.
Change file age to 60 days
Click on Run Scan at the top left hand corner.
Post back the log OTL.txt (attach)
Download hxxp://download.bleepingcomputer.com/farbar/FSS.exe (change the hxxp to http) and run it on the computer with the issue. On the desktop.
Make sure the following options are checked:
Internet Services
Windows Firewall
System Restore
Security Center/Action Center
Windows Update
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.
Quads
Re: happili.co m virus help
03-30-2012 05:27 AM
Quads,
Thanks for jumping onto this thread. I am on my work computer now (with a keyboard that works) but even this one is giving me a hard time because my work's computer security loads the Norton webpages painfully slow. I had to copy and paste individual letters to make the first few sentences of my last post.
A better summary of what happened:
I think I got the virus from watching a TV show online, started getting redirects to "Happili.com" and my computer was running very slow.
I did a Norton Scan (Norton 360), which detected nothing.
I did the Windows Malware Scan, which detected and removed 3 different malwares (Harnig.B and two others, can't remember but I have it written down at home)
I then did malwarebytes, which detected some more malware which I think it removed. I don't know if I still have that log.
I then used Norton Power Eraser, that detected some trojans.
At this point, the computer was working faster but google wouldn't search at all.
I then used the Norton Reboot program (for the infections that are so bad your computer wont start). It found 1 trojan.
That is when my keyboard stopped working.
I then ran TDSSKiller, which found nothing and then ComboFix. Combofix found 1 malware as shown in my post.
I checked my keyboard hardware in the Windows Control Panel, it looks like the driver has been erased because windows doesn't detect any plugged in keyboard. Not sure how to fix that one.
Quads, Again thanks for jumping onto the thread. I see you are very thorough in solving all the problems, and I will attach logs from now on. If you can provide some help it would be greatly appreciated.
On a side note, is it safe to back up files from my computer (pictures and music) onto my removable hard disk? Or will it just infect the hard disk? I figure as a worst case scenario I could just wipe my hard drive but I don't think that is necessary.
Re: happili.co m virus help
03-30-2012 05:37 AM
Why are people determined to do this when they don't know what they are doing, Geez
I did the Windows Malware Scan, which detected and removed 3 different malwares (Harnig.B and two others, can't remember but I have it written down at home)
I then did malwarebytes, which detected some more malware which I think it removed. I don't know if I still have that log.
I then used Norton Power Eraser, that detected some trojans.
At this point, the computer was working faster but google wouldn't search at all.
I then used the Norton Reboot program (for the infections that are so bad your computer wont start). It found 1 trojan.
That is when my keyboard stopped working.
I then ran TDSSKiller, which found nothing and then ComboFix. Combofix found 1 malware Combofix does not detect Malware as such
Quads
Re: happili.co m virus help
03-30-2012 06:15 AM
"Why are people determined to do this when they don't know what they are doing, Geez"
Quads,
I admit stupidity on my part with the shoot-from-the-hips action of installing some of the tools developed by masters of the computer engineering and programming world. In my frustration, I did something stupid that could have caused a lot of damage and I admit fault. I also admit I don't understand the full use of combofix. I will follow only your instruction and those instructions to a tee.
Anything on how I can at least use my keyboard? The copy and paste of individual letters is quite frustrating.
Re: happili.co m virus help
03-30-2012 03:08 PM
Try a USB keyboard, or turn on the Vista on screen keyboard for now.
I will need the Malware bytes log to.
It may be easier to have NBRT and Malwarebytes restore / undo the objects, including the driver back even though it's infected, and then have the infection removed correctly.
Quads
