Author Topic: [Resolved K] Happili virus redirecting  (Read 1460 times)

0 Members and 1 Guest are viewing this topic.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
Re: [Resolved K] Happili virus redirecting
« Reply #15 on: April 30, 2012, 11:56:44 PM »
If you are not seeing any re-directs or odd behavior do the following:

Step 1

Remove Combofix now that we're done with it
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")


  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
The above procedure will delete the following:
  • ComboFix and its associated files and folders.
  • VundoFix backups, if present
  • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

It is very important that you get a successful uninstall because of the extra functions done at the same time, let me know if this does not happen.

Step 2

We need to remove ESET Online Scanner.

  • Click Start, click Run, type control appwiz.cpl in the Open box, and then press ENTER.
  • Click to select ESET Online Scanner from the application list, and then click Remove. Only re-boot if prompted
Step 3

  • Download OTC by OldTimer and save it to your desktop. Alternative mirror
  • Double click icon to start the program.
    If you are using Vista or Windows 7, please right-click and choose run as administrator
  • Then Click the big button.
  • You will get a prompt saying "Begining Cleanup Process". Please select Yes.
  • Restart your computer when prompted.
  • This will remove tools we have used and itself.


Any tools/logs remaining on the Desktop can be deleted.

Step 4

Download TFC  to your desktop, from either of the following links
 Link 1
 Link 2
  • Save any open work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program. Vista or Windows 7 users right click and select “Run as Administartor”
  • If prompted, click "Yes" to reboot.
TFC will automatically close any open programs, including your Desktop. Let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds.  TFC may re-boot your system, if not Re-boot it yourself to  complete cleaning process <---- Very Important

Keep TFC it is an excellent utility to keep your system optimized, it empties all user temp folders, Java cache etc etc.  Always remember to re-boot after a run, even if not prompted

Let me know if those steps completed OK. Also give an update on any remaining issues or concerns...

Kevin...








Offline samantha

  • Bronze Member
  • Posts: 15
Re: [Resolved K] Happili virus redirecting
« Reply #16 on: May 05, 2012, 07:44:18 PM »
Kevin,

My apologies for taking so long to respond, but life got busy as I am sure you will understand.


I have tried to unistall ComboFix, but it wants to run. I ran it once and then tried to unistall it, but it still won't let me. What am I doing wrong?

Warmly,
Laura

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
Re: [Resolved K] Happili virus redirecting
« Reply #17 on: May 06, 2012, 12:59:45 AM »
Hiya Laura,

Do the following, Delete Combofix from your Desktop, d/l a fresh copy from either of the following links:

Link 1
Link 2

Ensure that Combofix is saved directly to the Desktop <--- Very important

Next,

Select the Windows key and R key together, that should open the "Run" box for you. Copy and paste the following command into the "Run" box exactly as shown, including quotes..

"%userprofile%\Desktop\combofix" /uninstall

Then select OK, or tap the "Enter" key.....   Does that work? if so continue with the other steps given previously..

Kevin...





Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
Re: [Resolved K] Happili virus redirecting
« Reply #18 on: May 09, 2012, 04:00:48 PM »
Are you still with us Laura?

Offline samantha

  • Bronze Member
  • Posts: 15
Re: [Resolved K] Happili virus redirecting
« Reply #19 on: May 10, 2012, 12:49:50 PM »
I am, Kevin. My apologies, two sick kids have slowed me down.

I will try your last advice and reply back.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
Re: [Resolved K] Happili virus redirecting
« Reply #20 on: May 10, 2012, 01:28:27 PM »
I know exactly what you mean Laura, real life can be hectic at times. Just reply when you`re ready, i`ll be around...

Thanks,

Kevin  :t

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
Re: [Resolved K] Happili virus redirecting
« Reply #21 on: May 15, 2012, 02:04:25 AM »
Anything happening Laura?

Offline samantha

  • Bronze Member
  • Posts: 15
Re: [Resolved K] Happili virus redirecting
« Reply #22 on: May 17, 2012, 10:54:16 PM »
Kevin,

The other fix just runs Combofix too. What am I doing wrong? Also, what happens if I can't unistall it?

Thank you for your patience. The kids are better, so I hope to be more responsive.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
Re: [Resolved K] Happili virus redirecting
« Reply #23 on: May 18, 2012, 12:13:44 AM »
Don`t worry Laura you`re doing nothing wrong, OK do the following:

Download this download.bleepingcomputer.com/sUBs/CF_UNINST.EXE and save to Desktop.

Double click the file to run it, that should reove CF....

When that completes continue with the other steps, just post back when you`re done or if you have any problems..

Good to hear the kids are better,

Kevin  :t



Offline samantha

  • Bronze Member
  • Posts: 15
Re: [Resolved K] Happili virus redirecting
« Reply #24 on: May 19, 2012, 06:31:39 PM »
Thank you , Kevin. I am too.

Unfortunately, the CF Unistall doesn't seem to be working either. I installed it (twice) double clicked it, I get the cursor with the arrow and hourglass, then a tiny little window saying Finished. Done. with nothing else. Combo Fix is still there and still tries to run.  Clearly I installed it very well.

What next?

Hope you are well.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
Re: [Resolved K] Happili virus redirecting
« Reply #25 on: May 20, 2012, 02:30:03 AM »
OK, drag CF from your Desktop and drop in the recycle bin, then continue with the rest of the steps. When you run OTC it will remove all files/folders associated to Combofix.

When you complete the rest of the steps there will be one more to add as follows:

Reset your system restore points and create a new clean one. To do this "Turn off" System restore > Left click start > Right click My Computer > Left click Properties > Select System restore tab > put tick in Turn off System Restore box > apply > ok. To reverse as previous but remove the tick from Turn off System Restore > apply ok.

Create the new restore point > Start > all programs > accessories > system tools > system restore > create a restore point > In the Restore point description box give it a name for reference eg. Clean 1. The time and date are added automatically > then select create and follow the wizard out.

Let me know if all goes OK....

Kevin :t



Offline samantha

  • Bronze Member
  • Posts: 15
Re: [Resolved K] Happili virus redirecting
« Reply #26 on: May 23, 2012, 08:13:48 AM »
Kevin,

We have some progress, but we are not entirely out of the woods.

I was able to do everything until I got to "create a restore point". I just get a window telling me that system restore is turned off and would I like to turn it back on. There is no wizard in sight.

Hope all is well with you,
Samantha

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
Re: [Resolved K] Happili virus redirecting
« Reply #27 on: May 23, 2012, 01:12:29 PM »
Hiya Samantha,

The instructions in my last reply tell you to turn System Restore OFF, then back ON. That flushes the Restore point cache, did you complete that? Then you create a new clean restore point....

Kevin

Offline samantha

  • Bronze Member
  • Posts: 15
Re: [Resolved K] Happili virus redirecting
« Reply #28 on: May 24, 2012, 07:40:07 AM »
And this is why you are such a godsend and I should keep my hands off electronics!

All done. Is there anything else I should do?

Samantha

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
Re: [Resolved K] Happili virus redirecting
« Reply #29 on: May 24, 2012, 01:09:24 PM »
Hiya Samantha,

Now you`ve completed flushing the system restore cache and creating a new clean restore point you`re good to go....

If no more issues here are some tips to reduce the potential for malware infection in the future:

Make proper use of your antivirus and firewall

Antivirus and Firewall programs are integral to your computer security. However, just having them installed isn't enough. The definitions of these programs are frequently updated to detect the latest malware, if you don't keep up with these updates then you'll be vulnerable to infection. Many antivirus and firewall programs have automatic update features, make use of those if you can. If your program doesn't, then get in the habit of routinely performing manual updates, because it's important.

You should keep your antivirus and firewall guard enabled at all times, NEVER turn them off unless there's a specific reason to do so. Also, regularly performing a full system scan with your antivirus program is a good idea to make sure you're system remains clean. Once a week should be adequate. You can set the scan to run during a time when you don't plan to use the computer and just leave it to complete on its own.

Install and use WinPatrol  This will inform you of any attempted unauthorized changes to your system.

WinPatrol features explained Here

Use a safer web browser

Internet Explorer is not the most secure tool for browsing the web. It has been known to be very susceptible to infection, and there are a few good free alternatives:
 
Firefox,

Opera, and

Chrome.
 
All of these are excellent faster, safer, more powerful and functional free alternatives to Internet Explorer. It's definitely worth the short period of adjustment to start using one of these. If you wish to continue using Internet Explorer, it would be a good idea to follow the tutorial HERE which will help you to make IE MUCH safer.

These browser add-ons will help to make your browser safer:

Web of Trust warns you about risky websites that try to scam visitors, deliver malware or send spam. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous ones:

Available for Firefox and Internet Explorer.

Green to go,
Yellow for caution, and
Red to stop.


Available for Firefox only. NoScript helps to block malicious scripts and in general gives you much better control over what types of things webpages can do to your computer while you're browsing.

These are just a couple of the most popular add-ons, if you're interested in more, take a look at THIS article.

Here a couple of links by two security experts that will give some excellent tips and advice.

So how did I get infected in the first place by Tony Klein

How to prevent Malware by Miekiemoes

Finally this link HERE will give a comprehensive upto date list of free Security programs. To include - Antivirus, Antispyware, Firewall, Antimalware, Online scanners and rescue CD`s.

Don`t forget, the best form of defense is common sense. If you don`t recognize it, don`t open it. If something looks to good to be true, then it aint.

Let me know when its OK to close out your thread,

Take care,

Kevin