This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] possible HEUR/HTML.Malware problem

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been having problems surfing the net and suspect a possible infection. Malware and Antivir scans run in safe mode indicate no suspicious files, but when I go to trusted web sites, Antivir stops the loading of the web page until I quarantine the file(s): C:\Users\ralph\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1FJH3SFC\flexcroll[1].js Antivir indicates this file is associated with HEUR/HTML.Malware If I deny access or quarantine then IE lets me access the trusted web page. But going to the next web page, I get the same thing (actually I get 2 Antivir warning windows every time). Is this a real problem? What can I do to fix it? I'm afraid to browse the web and of course I really can't with Antivir warnings every browsing mouse click. Thanks for any help you can provide.
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thanks CatByte! I'll take these actions and report back here. One additional piece of info is that the one main site that I've noticed getting these warnings (from Antivir about the possible HEUR/HTML.Malware) is T-mobile when I log in to that site. Most other sites when I browse the net give me no indications of problems. Thanks again for your help.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI