Hello and thank you in advance for your time and help,
I have been infected for a week or so by a virus called Mal Hifrm and the infected file is: C:\Users\Ed\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\different file name each time\i[1].htm
My anti-virus program (TREND) detects it near daily but says it cannot quarantine or remove it. Malwarebytes was recommended as the tool to remove it, so I've downloaded, updated and ran MalWarebytes many times but the virus is still there. The results show my computer is clean, but I know that is not the case, as Trend Micro warns me multiples times per day that I am infected. I use ATF-Cleaner to empty the temp files, but still the warnings recur. I have been manually erasing the specified temp files in the Content.IE5 folder, but still the warning recur. I tried to erase the entire Content.IE5 folder but can't seem to do so. I am using Windows Vista.
Any suggestions on how to get rid of Mal Hifrm?
Here is a copy of the HijackThis log I just ran.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:47:46 AM, on 8/19/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)
It's normal after running ATF cleaner that the PC will be slower to boot the first time.
Next:
Download ComboFix from one of these locations:
Link 1 Link 2
* IMPORTANT !!! Save ComboFix.exe to your Desktop
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs
Double click on ComboFix.exe & follow the prompts.
Note: Combofix will run without the Recovery Console installed.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.
Notes:
1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it atleast 20-30 minutes to finish if needed.
Also please describe how your computer behaves at the moment.
It always says it's found in:
C:\Users\Ed\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3V91VN6I\
Of course the temp file in the Content.IE5 folder, in this case 3V91VN6I, is different each time.
I have to close out AOL and Explorer processes through the task manager, then I delete the contents of the specified file. I tried to delete the Content.IE5 folder entirely, but am not allowed that function by the pc.
Please help, this has been going on for weeks now, and I see others on this forum have been suffering the same problem.
Thanks!
Ed
I will set the Explorer options as you recommend.
However, I am not visiting any new sites. And I think this is a worm, judging from other posts on this site. Your colleagues seem to think it's a lot more serious than just a temp. int. file.
Are you sure it's not a worm?
You didn't answer my question about what sites you're visiting to get those infected temp files.
You do understand where the Temporary Internet Files\Content.IE5 files are coming from, right?
http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Note: You will need to use Internet explorer for this scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Click Start
Make sure that the option Remove found threats is unticked, and the option Scan unwanted applications is checked
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.
Thanks for your continues help.
I certainly do understand that temp int. files go in the Content.IE5 folder.
I visit too many sites to know which one triggered the Trend Micro Mal Hifrm warning.
I ran ESET scan as you instructed and there were no infected files found.
The log is:
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
Did I do something wrong? Should I rerun it?
Thanks once again!
I certainly do understand that temp int. files go in the Content.IE5 folder.
I visit too many sites to know which one triggered the Trend Micro Mal Hifrm warning.
I ran ESET scan as you instructed and there were no infected files found.
The log is:
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
Did I do something wrong? Should I rerun it?
Thanks once again!
If it didn't find any infections then I'd say your pc is clean.
You'll always get temp files and cookies when you visit websites.
You can run this one if you want.
Please click here to download AVP Tool by Kaspersky.
Save it to your desktop.
Reboot your computer into SafeMode.
You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
Use your up arrow key to highlight SafeMode then hit enter.
Double click the setup file to run it.
Click Next to continue.
It will by default install it to your desktop folder.Click Next.
Hit ok at the prompt for scanning in Safe Mode.
It will then open a box There will be a tab that says Automatic scan.
Under Automatic scan make sure these are checked.
System Memory
Startup Objects
Disk Boot Sectors.
My Computer.
Also any other drives (Removable that you may have)
After that click on Security level then choose Customize then click on the tab that says Heuristic Analyzer then choose Enable Deep rootkit search then choose ok.
Then choose OK again then you are back to the main screen.
Then click on Scan at the to right hand Corner.
It will automatically Neutralize any objects found.
If some objects are left un-neutralized then click the button that says Neutralize all
If it says it cannot be Neutralized then chooose The delete option when prompted.
After that is done click on the reports button at the bottom and save it to file name it Kas.
Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.
Note: This tool will self uninstall when you close it so please save the log before closing it.
Hi,
Thanks for recommending Kaspersky Scan.
I just finished it and it did find a worm (virus), please see below.
Detected
——–
Status Object
—— ——
deleted: virus Worm.Win32.AutoRun.ek File: C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\1408.tmp//CryptFF.b
I deleted this file. Would you recommend I take any other actions?
Thanks again,
Ed
The following will implement some cleanup procedures as well as reset System Restore points:
Click START then RUN
Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
[external image: Posted Image]
To be on the safe side, I would also change all my passwords.
Here's my usual all clean post
Log looks good
Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
This will ensure your computer has always the latest security updates available installed on your computer.
If there are new updates to install, install them immediately, reboot your computer, and revisit the site
until there are no more critical updates.
Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI