![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Too lazy to set a custom title
Join Date: Jan 2003
Location: Los Angeles
Posts: 10,548
|
![]() Anyone here have any luck getting rid of Happili malware? Suggestions for approaches?
__________________
![]() ![]() ![]() ![]() ![]() Blue Blood's SpookyCash.com Babe photography portfolio |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
there's no $$$ in porn
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
|
format, reinstall.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Junior Achiever
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
|
Can you restore to a previous day?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
Start off with rkill.
http://www.bleepingcomputer.com/down...ti-virus/rkill Then use tdsskiller. http://support.kaspersky.com/faq/?qid=208283363 If it won't run, rename the exe. Then run malwarebytes and restart.
__________________
I like pie. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
there's no $$$ in porn
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
|
Once a system has been compromised, the only way to be sure you get rid of everything is to wipe it clean and reinstall. Annoying? yep, but it's the only way.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
That's not true at all.
__________________
I like pie. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
there's no $$$ in porn
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
|
kernel modules anyone?
When a system has been compromised you know 1 thing: That the system has been compromised.
Based on the output of the system or programs running within that system, you can't know what the attacker has done. You can't know what the attacker has installed. You can no longer trust any info the system provides. Why? Because the system has been compromised. That's security 101. Ken Thompson already made that point back in 1984 (or 1985) with his "reflections on trusting trust" (or "reflecting on trusting trust") presentation. (Remember his famous c compiler trojan?). |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
xxx
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
|
http://www.malwarebytes.org/products/malwarebytes_free
its free download then scan. if it does not work (some Malware stops this softwar running), go into safemode. to go into safe mode shut your pc down then when you restart press f8. if you go info safe mode with net access you can then update the softear or download it if you did not already download it.
__________________
The Affiliate Program |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 | |
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
Quote:
![]() ![]() ![]() Relax. It's a little Windows trojan, not stuxnet. If you want to reformat after your computer catches a cold, have at it but it's almost never necessary.
__________________
I like pie. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
xxx
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
|
__________________
The Affiliate Program |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Industry Role:
Join Date: Mar 2012
Posts: 374
|
Malware Bytes.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
xxx
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
|
Just to note:
You can have as many anti-Malware softwear progs on your pc as you wish. Scan your pc every week at least. But its recomended only one ati-virus softwear as they often run 24/7. Its not uncommon to have two running and find they have problems together. So only have one.
__________________
The Affiliate Program |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
there's no $$$ in porn
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
|
You're making a lot of assumptions here.
What do we know? We know her pc got infected. We know the happili malware was identified on her pc. So we know this little Windows trojan somehow made it onto her pc. The question now becomes: How? Browser exploit? other exploit? email? an already existing infection (a bot herder selling installs)? If its a browser exploit, how do we know this infection is the first and/or only one to occur based on this attack vector? We could go on and on, but ultimately the only way to be sure is to wipe an reinstall. Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
xxx
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
|
Quote:
these days many pc's do not have the windows file on disc. plus as long as she has all her data backed up, what is the worst that would happen? i do not think its the same as a virus, but some anoying bit of softwear that just anoys you. i do not think we are at the stage just yet were your pc is being infected by a supercomputer that is planning on ruling earth. that said mabe i have been sent back in time to tell her not to clear her pc as i am making sure my computer mater does rule earth.
__________________
The Affiliate Program |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |||
there's no $$$ in porn
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
|
Quote:
Quote:
Quote:
|
|||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Confirmed User
Join Date: Jun 2002
Posts: 9,506
|
Nothing 100%, reformat!
__________________
Vacares - Web Hosting, Domains, O365, Security & More Unparked domains burning a hole in your pocket? 5 Simple Ways to Make Easy $$$ from Unused Domains |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 | |
xxx
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
|
Quote:
but as i say as longf as all data is backed up, i would not be too worried. personaly if you have the room, i would have one pc for pic and vid editing that is not conected to the net (except for mabe updates) and one for going online. but i still think its an overkill to do what you sugested. i have had lots of nasty stuff on my pc. i have an old pc with vista. and so far not needed to clear it. with xp i was having to re-do it from scratch every few months. softwear today seems much more secure. i also suspect that they may target tablet and phones more as i bet they are more vunrabel and i bet do not have much protection. Or to put it this way, why invade the usa when you can invade canada.
__________________
The Affiliate Program |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Confirmed User
Join Date: Aug 2006
Posts: 1,756
|
Restore to factory settings.
__________________
![]() ![]() ![]() ![]() Load your OKPay account directly with Moneybookers, Liqpay, Bitcoin, Cashu, RBK Money,... No need for a 3rd party exchanger. Payment gateway modules for OSCommerce, Zen-Cart, VirtueMart, cubecart, 3dcart,... available. Find out more. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
I am making a lot of assumptions? I'm not the one suggesting reformatting for a silly little trojan. You're assuming that the world is out to get you with next level worms that are hell-bent on your destruction. This is the real world. This is just garbage malware.
Serious question: Do you gut the interior of your home and remodel every time you find a spider?
__________________
I like pie. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Porn Meister
Industry Role:
Join Date: Feb 2005
Posts: 16,443
|
I think for MOST people, the idea of reformatting is just so daunting that they never consider it except if their system is absolutely trashed. However if you have a great recent backup. it's never a bad way to go since you can be very sure it's all clear. I wouldn't knock it, but I also wouldn't do it as a first attempt. I'd probably go for a system restore point and all the standard scans as have been suggested then consider it.
__________________
43-922-863 Shut up and play your guitar. ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Too lazy to set a custom title
Join Date: Jan 2003
Location: Los Angeles
Posts: 10,548
|
Unfortunately MalwareBytes can't clean this particular annoyance. I actually thought I'd gotten rid of it with a system restore and some suggestions from BleepingComputer, but it had only been reduced, not eradicated. And now I don't have an older system restore.
I'm going to try that Panda thing next.
__________________
![]() ![]() ![]() ![]() ![]() Blue Blood's SpookyCash.com Babe photography portfolio |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 | |
xxx
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
|
Quote:
__________________
The Affiliate Program |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
xxx
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
|
__________________
The Affiliate Program |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Confirmed User
Industry Role:
Join Date: Oct 2001
Location: Toronto
Posts: 7,103
|
Happili? WTF? Is that an Apple thing?
I didn't even watch this: |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 | |
Confirmed User
Industry Role:
Join Date: Oct 2001
Location: Toronto
Posts: 7,103
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Arthur Flegenheimer
Industry Role:
Join Date: Jul 2006
Location: New York City
Posts: 11,056
|
malwarebytes is usually the best
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 | |
Confirmed User
Industry Role:
Join Date: Aug 2007
Posts: 6,697
|
Quote:
Try all of them Panda, Security Essentials, Malwarebytes, AVG. Try in both normal and safe mode (it can make a difference and it can help to do both as strange as it sounds) and when it looks like you got them all run another pass to be sure. It also appears that this malware often tries to infect the disk controller to digitself in really deep. http://www.techsupportforum.com/foru...ck-641028.html http://spywarehammer.com/simplemachi...topic=12815.45 Looks like they had some success here so you might try that approach http://forums.techguy.org/virus-othe...ont-leave.html Basically you need to wipe out all places where the malware is hiding. Often these things infect a system in many different ways. If you don't get every last piece it will come right back. Check for bogus DNS and proxy entires too as described. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 | |
Confirmed User
Industry Role:
Join Date: Aug 2007
Posts: 6,697
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 | |
Confirmed User
Industry Role:
Join Date: Sep 2007
Posts: 631
|
Quote:
Acronis True Image Home http://www.acronis.com/homecomputing...cts/trueimage/ Also at the same time get the Add on Plus Pack Add-On - http://www.acronis.com/homecomputing...age/#plus-pack Ability to Restore to Dissimilar Hardware - Whatever the make, model or installed components of your new computer, Plus Pack restores everything back to its proper form. .
__________________
Things that make ya go hmmmm.... |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 | |
Icq: 14420613
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
|
there are tons of computer stores that will do the work for you.
Quote:
__________________
Need WebHosting ? Email me for some great deals [email protected] |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
Confirmed User
Industry Role:
Join Date: Sep 2006
Posts: 2,921
|
Or restore a backup image of the drive. I always use sandboxie, I've never seen any virus get around it. Even if one did I keep backups and it only takes about 15 to 20 minutes to restore. Although none of that probably helps Amelia's current situation now that the virus is on her PC and she probably doesn't have backups. signupdamnit has the best advice here for her problem, although there's a lot of good antiviruses out there.
|
![]() |
![]() ![]() ![]() ![]() ![]() |