Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 04-18-2012, 03:07 AM   #1
AmeliaG
Too lazy to set a custom title
 
AmeliaG's Avatar
 
Join Date: Jan 2003
Location: Los Angeles
Posts: 10,548
Getting Rid of Happili Malware

Anyone here have any luck getting rid of Happili malware? Suggestions for approaches?
__________________
GFY Hall of Famer

AltStar Hall of Famer




Blue Blood's SpookyCash.com

Babe photography portfolio
AmeliaG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 05:37 AM   #2
u-Bob
there's no $$$ in porn
 
u-Bob's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
format, reinstall.
u-Bob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 05:38 AM   #3
BIGTYMER
Junior Achiever
 
BIGTYMER's Avatar
 
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
Can you restore to a previous day?
BIGTYMER is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 05:47 AM   #4
Babaganoosh
♥♥♥ Likes Hugs ♥♥♥
 
Babaganoosh's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
Start off with rkill.
http://www.bleepingcomputer.com/down...ti-virus/rkill

Then use tdsskiller.
http://support.kaspersky.com/faq/?qid=208283363
If it won't run, rename the exe.

Then run malwarebytes and restart.
__________________
I like pie.
Babaganoosh is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 05:52 AM   #5
u-Bob
there's no $$$ in porn
 
u-Bob's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
Once a system has been compromised, the only way to be sure you get rid of everything is to wipe it clean and reinstall. Annoying? yep, but it's the only way.
u-Bob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 05:53 AM   #6
Babaganoosh
♥♥♥ Likes Hugs ♥♥♥
 
Babaganoosh's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
Quote:
Originally Posted by u-Bob View Post
Once a system has been compromised, the only way to be sure you get rid of everything is to wipe it clean and reinstall. Annoying? yep, but it's the only way.
That's not true at all.
__________________
I like pie.
Babaganoosh is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 05:59 AM   #7
seeandsee
Check SIG!
 
seeandsee's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Europe (Skype: gojkoas)
Posts: 50,945
How did you got that malware?
__________________
BUY MY SIG - 50$/Year

Contact here
seeandsee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 06:06 AM   #8
u-Bob
there's no $$$ in porn
 
u-Bob's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
kernel modules anyone?

Quote:
Originally Posted by Babaganoosh View Post
That's not true at all.
When a system has been compromised you know 1 thing: That the system has been compromised.

Based on the output of the system or programs running within that system, you can't know what the attacker has done. You can't know what the attacker has installed. You can no longer trust any info the system provides. Why? Because the system has been compromised. That's security 101.

Ken Thompson already made that point back in 1984 (or 1985) with his "reflections on trusting trust" (or "reflecting on trusting trust") presentation. (Remember his famous c compiler trojan?).
u-Bob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 06:06 AM   #9
DVTimes
xxx
 
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
http://www.malwarebytes.org/products/malwarebytes_free

its free

download then scan.

if it does not work (some Malware stops this softwar running), go into safemode.

to go into safe mode shut your pc down then when you restart press f8.

if you go info safe mode with net access you can then update the softear or download it if you did not already download it.
__________________
The Affiliate Program
DVTimes is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 06:13 AM   #10
Babaganoosh
♥♥♥ Likes Hugs ♥♥♥
 
Babaganoosh's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
Quote:
Originally Posted by u-Bob View Post
When a system has been compromised you know 1 thing: That the system has been compromised.

Based on the output of the system or programs running within that system, you can't know what the attacker has done. You can't know what the attacker has installed. You can no longer trust any info the system provides. Why? Because the system has been compromised. That's security 101.

Ken Thompson already made that point back in 1984 (or 1985) with his "reflections on trusting trust" (or "reflecting on trusting trust") presentation. (Remember his famous c compiler trojan?).


Relax. It's a little Windows trojan, not stuxnet. If you want to reformat after your computer catches a cold, have at it but it's almost never necessary.
__________________
I like pie.
Babaganoosh is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 06:22 AM   #11
DVTimes
xxx
 
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
I posted this if its any help:

http://www.dvtimes.com/2012/04/18/ma...-malware-free/
__________________
The Affiliate Program
DVTimes is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 06:24 AM   #12
Mrwww
Confirmed User
 
Industry Role:
Join Date: Mar 2012
Posts: 374
Malware Bytes.
__________________


DattonMedia
Affordable design and media.
Daniel Datton
// ICQ: 9 0 5 9 2 8
support
@dattonmedia.com
Mrwww is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 06:25 AM   #13
DVTimes
xxx
 
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
Just to note:

You can have as many anti-Malware softwear progs on your pc as you wish. Scan your pc every week at least.

But its recomended only one ati-virus softwear as they often run 24/7. Its not uncommon to have two running and find they have problems together. So only have one.
__________________
The Affiliate Program
DVTimes is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 06:31 AM   #14
u-Bob
there's no $$$ in porn
 
u-Bob's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
Quote:
Originally Posted by Babaganoosh View Post


Relax. It's a little Windows trojan, not stuxnet.
You're making a lot of assumptions here.

What do we know?
We know her pc got infected.
We know the happili malware was identified on her pc.
So we know this little Windows trojan somehow made it onto her pc.

The question now becomes: How?
Browser exploit? other exploit? email? an already existing infection (a bot herder selling installs)?

If its a browser exploit, how do we know this infection is the first and/or only one to occur based on this attack vector?

We could go on and on, but ultimately the only way to be sure is to wipe an reinstall.


Quote:
If you want to reformat after your computer catches a cold, have at it but it's almost never necessary.
Having an image of a clean system at hand will save you a lot of time and will even be quicker than downloading, installing and messing with all kinds of antimalware tools.
u-Bob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 06:40 AM   #15
DVTimes
xxx
 
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
Quote:
Originally Posted by u-Bob View Post
You're making a lot of assumptions here.

What do we know?
We know her pc got infected.
We know the happili malware was identified on her pc.
So we know this little Windows trojan somehow made it onto her pc.

The question now becomes: How?
Browser exploit? other exploit? email? an already existing infection (a bot herder selling installs)?

If its a browser exploit, how do we know this infection is the first and/or only one to occur based on this attack vector?

We could go on and on, but ultimately the only way to be sure is to wipe an reinstall.



Having an image of a clean system at hand will save you a lot of time and will even be quicker than downloading, installing and messing with all kinds of antimalware tools.
seems a bit of an overkill.

these days many pc's do not have the windows file on disc.

plus as long as she has all her data backed up, what is the worst that would happen?

i do not think its the same as a virus, but some anoying bit of softwear that just anoys you.

i do not think we are at the stage just yet were your pc is being infected by a supercomputer that is planning on ruling earth.

that said mabe i have been sent back in time to tell her not to clear her pc as i am making sure my computer mater does rule earth.
__________________
The Affiliate Program
DVTimes is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 06:46 AM   #16
u-Bob
there's no $$$ in porn
 
u-Bob's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
Quote:
Originally Posted by DVTimes View Post
seems a bit of an overkill.

these days many pc's do not have the windows file on disc.
hence my advice of making an image of a clean system.

Quote:
plus as long as she has all her data backed up, what is the worst that would happen?
Other malware programs could remain behind.


Quote:
i do not think its the same as a virus, but some anoying bit of softwear that just anoys you.
The question of the attack vector remains. How did it get in? Browser exploit? Bundled with something she installed? Installed by a bot herder? ...
u-Bob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 06:52 AM   #17
Best-In-BC
Confirmed User
 
Best-In-BC's Avatar
 
Join Date: Jun 2002
Posts: 9,506
Nothing 100%, reformat!
__________________
Vacares - Web Hosting, Domains, O365, Security & More
Unparked domains burning a hole in your pocket? 5 Simple Ways to Make Easy $$$ from Unused Domains
Best-In-BC is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 06:57 AM   #18
DVTimes
xxx
 
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
Quote:
Originally Posted by u-Bob View Post
hence my advice of making an image of a clean system.


Other malware programs could remain behind.




The question of the attack vector remains. How did it get in? Browser exploit? Bundled with something she installed? Installed by a bot herder? ...
i see your point.

but as i say as longf as all data is backed up, i would not be too worried.

personaly if you have the room, i would have one pc for pic and vid editing that is not conected to the net (except for mabe updates) and one for going online.

but i still think its an overkill to do what you sugested.

i have had lots of nasty stuff on my pc. i have an old pc with vista. and so far not needed to clear it.

with xp i was having to re-do it from scratch every few months.

softwear today seems much more secure.

i also suspect that they may target tablet and phones more as i bet they are more vunrabel and i bet do not have much protection.

Or to put it this way, why invade the usa when you can invade canada.
__________________
The Affiliate Program

Last edited by DVTimes; 04-18-2012 at 06:58 AM..
DVTimes is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 07:41 AM   #19
KingNigel
Confirmed User
 
Join Date: Aug 2006
Posts: 1,756
Restore to factory settings.
__________________
OKPay Sponsors
Load your OKPay account directly with Moneybookers, Liqpay, Bitcoin, Cashu, RBK Money,... No need for a 3rd party exchanger.
Payment gateway modules for OSCommerce, Zen-Cart, VirtueMart, cubecart, 3dcart,... available. Find out more.
KingNigel is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 07:47 AM   #20
Babaganoosh
♥♥♥ Likes Hugs ♥♥♥
 
Babaganoosh's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
Quote:
Originally Posted by u-Bob View Post
You're making a lot of assumptions here.
I am making a lot of assumptions? I'm not the one suggesting reformatting for a silly little trojan. You're assuming that the world is out to get you with next level worms that are hell-bent on your destruction. This is the real world. This is just garbage malware.

Serious question: Do you gut the interior of your home and remodel every time you find a spider?
__________________
I like pie.
Babaganoosh is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 07:55 AM   #21
Tom_PM
Porn Meister
 
Industry Role:
Join Date: Feb 2005
Posts: 16,443
I think for MOST people, the idea of reformatting is just so daunting that they never consider it except if their system is absolutely trashed. However if you have a great recent backup. it's never a bad way to go since you can be very sure it's all clear. I wouldn't knock it, but I also wouldn't do it as a first attempt. I'd probably go for a system restore point and all the standard scans as have been suggested then consider it.
__________________
43-922-863 Shut up and play your guitar.
Tom_PM is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 02:52 PM   #22
AmeliaG
Too lazy to set a custom title
 
AmeliaG's Avatar
 
Join Date: Jan 2003
Location: Los Angeles
Posts: 10,548
Unfortunately MalwareBytes can't clean this particular annoyance. I actually thought I'd gotten rid of it with a system restore and some suggestions from BleepingComputer, but it had only been reduced, not eradicated. And now I don't have an older system restore.

I'm going to try that Panda thing next.
__________________
GFY Hall of Famer

AltStar Hall of Famer




Blue Blood's SpookyCash.com

Babe photography portfolio
AmeliaG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 03:04 PM   #23
DVTimes
xxx
 
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
Quote:
Originally Posted by AmeliaG View Post
Unfortunately MalwareBytes can't clean this particular annoyance. I actually thought I'd gotten rid of it with a system restore and some suggestions from BleepingComputer, but it had only been reduced, not eradicated. And now I don't have an older system restore.

I'm going to try that Panda thing next.
did you try in safe mode?
__________________
The Affiliate Program
DVTimes is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 03:06 PM   #24
DVTimes
xxx
 
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
I found this:

http://www.myantispyware.com/2012/04...edirect-virus/
__________________
The Affiliate Program
DVTimes is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 03:29 PM   #25
garce
Confirmed User
 
garce's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Toronto
Posts: 7,103
Happili? WTF? Is that an Apple thing?

I didn't even watch this:

garce is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 03:32 PM   #26
garce
Confirmed User
 
garce's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Toronto
Posts: 7,103
Quote:
Originally Posted by DVTimes View Post
I have an Aunty Spyware. She lives in my mind and tells me secrets about people who open email attachements, and click links to websites that they've never heard about.
garce is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 03:32 PM   #27
Supz
Arthur Flegenheimer
 
Supz's Avatar
 
Industry Role:
Join Date: Jul 2006
Location: New York City
Posts: 11,056
malwarebytes is usually the best
Supz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 03:53 PM   #28
signupdamnit
Confirmed User
 
signupdamnit's Avatar
 
Industry Role:
Join Date: Aug 2007
Posts: 6,697
Quote:
Originally Posted by AmeliaG View Post
Unfortunately MalwareBytes can't clean this particular annoyance. I actually thought I'd gotten rid of it with a system restore and some suggestions from BleepingComputer, but it had only been reduced, not eradicated. And now I don't have an older system restore.

I'm going to try that Panda thing next.
U-bob's advice is safest but if you can't do that then it is what it is.

Try all of them Panda, Security Essentials, Malwarebytes, AVG. Try in both normal and safe mode (it can make a difference and it can help to do both as strange as it sounds) and when it looks like you got them all run another pass to be sure.

It also appears that this malware often tries to infect the disk controller to digitself in really deep. http://www.techsupportforum.com/foru...ck-641028.html http://spywarehammer.com/simplemachi...topic=12815.45

Looks like they had some success here so you might try that approach http://forums.techguy.org/virus-othe...ont-leave.html Basically you need to wipe out all places where the malware is hiding. Often these things infect a system in many different ways. If you don't get every last piece it will come right back. Check for bogus DNS and proxy entires too as described.

Last edited by signupdamnit; 04-18-2012 at 03:54 PM..
signupdamnit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 04:05 PM   #29
signupdamnit
Confirmed User
 
signupdamnit's Avatar
 
Industry Role:
Join Date: Aug 2007
Posts: 6,697
Quote:
Originally Posted by DVTimes View Post
Just to note:

You can have as many anti-Malware softwear progs on your pc as you wish. Scan your pc every week at least.

But its recomended only one ati-virus softwear as they often run 24/7. Its not uncommon to have two running and find they have problems together. So only have one.
You can have more than one anti-virus program. You just can't have two which have an automatic on-access (real time) scanner enabled at once. The reason is that usually unless you really know what you are doing they will constantly eat resources and interact with one another in a way which could seriously hinder performance. For many people it's too hard for them to figure out how to disable the real time scanner on the others but if you can figure it out then it's not a bad idea at all to keep a couple on your computer to use as backups. That way when you suspect something and the main one isn't doing the trick you can manually update the others if need be and run manual scans.
signupdamnit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 08:01 PM   #30
Aka_Bluey
Confirmed User
 
Aka_Bluey's Avatar
 
Industry Role:
Join Date: Sep 2007
Posts: 631
Quote:
Originally Posted by AmeliaG View Post
Anyone here have any luck getting rid of Happili malware? Suggestions for approaches?
When you get it sorted out look at getting Acronis, it can make a image of your hole c drive, for me it works out about a gig a minute to backup to an ex drive.

Acronis True Image Home
http://www.acronis.com/homecomputing...cts/trueimage/

Also at the same time get the Add on Plus Pack
Add-On - http://www.acronis.com/homecomputing...age/#plus-pack
Ability to Restore to Dissimilar Hardware - Whatever the make, model or installed components of your new computer, Plus Pack restores everything back to its proper form.



.
__________________
Things that make ya go hmmmm....
Aka_Bluey is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 08:21 PM   #31
sandman!
Icq: 14420613
 
sandman!'s Avatar
 
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
there are tons of computer stores that will do the work for you.



Quote:
Originally Posted by PR_Tom View Post
I think for MOST people, the idea of reformatting is just so daunting that they never consider it except if their system is absolutely trashed. However if you have a great recent backup. it's never a bad way to go since you can be very sure it's all clear. I wouldn't knock it, but I also wouldn't do it as a first attempt. I'd probably go for a system restore point and all the standard scans as have been suggested then consider it.
__________________
Need WebHosting ? Email me for some great deals [email protected]
sandman! is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2012, 10:22 PM   #32
cess
Confirmed User
 
Industry Role:
Join Date: Sep 2006
Posts: 2,921
Quote:
Originally Posted by u-Bob View Post
format, reinstall.
Or restore a backup image of the drive. I always use sandboxie, I've never seen any virus get around it. Even if one did I keep backups and it only takes about 15 to 20 minutes to restore. Although none of that probably helps Amelia's current situation now that the virus is on her PC and she probably doesn't have backups. signupdamnit has the best advice here for her problem, although there's a lot of good antiviruses out there.
__________________
cess is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.