Hi all, I'm new on this site, I have been looking for help against the Hifrm-5 virus, bfore posting but couldn't find anything. Don't know wht exactly is, but MIS from my company blocked the access of my NB to the network of the company because is trying to "broadcast" to the proxy server. After running an anivirus scan found Hifrm-5 on some files, I performed a clean-up according instructions on one of these threads but couldn't delete them. I really don't want to re-install Windows, so any help will be really appreciated.

Dani AI

Generated

Quick expert summary and next steps (adds context to , and builds on and ):

Trend Micro’s Hifrm label (examples: POSSIBLE_HIFRM-5 / Mal_Hifrm) is a heuristic used to flag “hifrm” — typically HTML iframe or injected web content rather than a classic self-replicating binary. Detections often show up as .htm files inside browser temp folders and can cause recurring popups or repeated outbound web requests that look like “broadcasting” to a proxy. (trendmicro.com)

Common causes and false-positive traps:

  • Drive‑by / injected iframe content and adware frequently create temp .htm files that get flagged.
  • Two resident scanners can clash (one unpacking files into its temp area while another flags them), producing locked/quarantined temp files that look like a regenerating infection. The Avast/Trend example illustrates this class of problem. (bleepingcomputer.com)

Verification workflow (no reinstall required if clean):

  • Obtain the MIS removal/quarantine report (which files were removed or quarantined).
  • Run a pre-boot/offline scan to confirm no rootkit/bootkit remains (Microsoft Defender Offline is the built‑in option). For stubborn cases, use a reputable bootable rescue disk (for example, Kaspersky Rescue Disk) and update signatures before scanning. (learn.microsoft.com)

Quick command checklist to confirm configuration and persistence (run from an admin shell / use rescue media where appropriate):

netsh winhttp show proxy
netsh winhttp reset proxy
Start-MpWDOScan
schtasks /query /fo LIST /v

Follow that by an autoruns scan (Sysinternals Autoruns) to look for hidden startup entries, scheduled tasks, BHOs or winsock/LSP changes. These tools expose persistence points that simple file scans can miss. (learn.microsoft.com)

Final note: the advice from and about collecting logs (Malwarebytes/HiJackThis when an active infection is present) is still valid. If MIS reports a clean system, the offline/rescue checks above provide a reliable confirmation without reinstalling Windows.

Recommended Answers

All 4 Replies

We really cannot advise unless we see some logs from the programs you have run.
I would like to see an MBA-M log and a HiJackThis log if possible.

Hi all, I'm new on this site, I have been looking for help against the Hifrm-5 virus, bfore posting but couldn't find anything. Don't know wht exactly is, but MIS from my company blocked the access of my NB to the network of the company because is trying to "broadcast" to the proxy server. After running an anivirus scan found Hifrm-5 on some files, I performed a clean-up according instructions on one of these threads but couldn't delete them. I really don't want to re-install Windows, so any help will be really appreciated.

We really cannot advise unless we see some logs from the programs you have run.
I would like to see an MBA-M log and a HiJackThis log if possible.

Hello and welcome to Daniweb Kenji :)

Pls do the following, i as well as jholland1964 would like to see the a Malwarebytes' Log as well as a hijackthis log.

1. - Download Malwarebytes' Anti-Malware (http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button) to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Make sure that you restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

2. - Download hijackthis and post the log.

In your reply, post the logs (in this order):
1. - Malware Bytes Log
2. - Hijackthis Log

Thanks,

Cohen

Thanks guys....
I haven't replay before cus I didn't understand clearly jholland comments.... MIS from my company cleaned the computer already, shall I run the Malware Bytes and the Hijackthis anyway? wil this be helpful for me or for any other person who is having the same trouble?
Please advice and will do it ASAP.

Thanks!!!!

Thanks guys....
I haven't replay before cus I didn't understand clearly jholland comments.... MIS from my company cleaned the computer already, shall I run the Malware Bytes and the Hijackthis anyway? wil this be helpful for me or for any other person who is having the same trouble?
Please advice and will do it ASAP.

Thanks!!!!

No if the computer is now clean you wouldn't need to run the programs. Sorry you didn't understand my comments. What I meant was we really couldn't offer any steps for you to take until you had posted the logs here from the programs you ran, like Malwarebytes' Anti-Malware and also an HiJackThis log. We need to see some logs before we can decide what steps a person should take. Sorry if I wasn't clear and I am very glad the computer is clean.
Judy

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.