So I double clicked the "Copy of MBAM" and it loaded, I then again ran the quick scan and it said it found no infections. I just figured it worked since all the problems that I was having went away after running it. Malwarebytes' Anti-Malware 1.38 Database version: 2297 Windows 5.1.2600 Service Pack 3 27/06/2009 18:51:32 mbam-log-2009-06-27 (18-51-32).txt Scan type: Quick Scan Objects scanned: 137717 Time elapsed: 12 minute(s), 44 second(s) Memory Processes Infected: Close/disable all anti virus and anti malware programs including TeaTimer if you have it so they do not interfere with the running of ComboFix.

Trojan.injector Malwarebytes

What I would like you to do is a temporary uninstall of the program and the reinstall it after completing the script below. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.

Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data:, -> Quarantined and deleted successfully. Then double-click on SASDEFINITIONS.EXE to install the definitions.)In the Main Menu, click the Preferences... SmitFraudFix v2.423 Scan done at 21:14:26.40, 27/06/2009 Run from C:\Documents and Settings\Hassaan\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode ╗╗╗╗╗╗╗╗╗╗╗╗╗╗╗╗╗╗╗╗╗╗╗╗ Run the scan, enable your A/V and reconnect to the internet.

Run the scan, enable your A/V and reconnect to the internet. I am not convinced it is gone and it is all removed. Here is the DDS.txt I was supposed to post along with the details of my problem: DDS (Ver_09-05-14.01) - NTFSx86 Run by Alann Cabang at 20:25:27.63 on Sun 06/14/2009 Internet Explorer: navigate to this website Unfortunately, during the few times I've scanned with it it would freeze up and I've been forced to shut it down through ctrl+alt+del.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{408b4471-79bd-4528-9867-a1fae527d106}\NameServer (Trojan.DNSChanger) -> Data:, -> Quarantined and deleted successfully.

I double clicked on "Copy of MBAM" and it opened, I then went to the update tab and tried to update it but it failed so I downloaded "MBAM-Rules.exe" and ran it. is it a back door for the computer for hackers?

It was designed to exploit security vulnerabilities and perform malicious actions on the system. scanning hidden files ...

Just that I've got such a busy week. I then ran a quick scan and it found some infections, I'll post the log below. I am about to do the second scan now. http://mseedsoft.com/trojan-horse/trojan-horse-injector-el.html Turn on any router or hub that your computer may be plugged into. 8.

It's easy! Malware did give me a pop-up warning but it tookall of my above steps and 3 full scans to get rid of it.I am by no means a computer techie. Turn on the cable/dsl modem. 6.

If I have helped you then please consider donating so I can continue the fight against malware

I have uninstalled Ashampoo Firewall and reloaded. Close HijackThis window (do not fix anything unless you receive instruction from the HJT analysts) Flag Permalink This was helpful (0) Back to Spyware, Viruses, & Security forum 2 total posts If you click on this in the drop-down menu you can choose Track this topic. Updating your antivirus software is a one-click process.

Anyway here is the log:GMER - http://www.gmer.netRootkit scan 2009-06-28 22:24:02Windows 5.1.2600 Service Pack 3---- System - GMER 1.0.15 ----SSDT spkp.sys ZwCreateKey [0xF770B0E0]SSDT spkp.sys ZwEnumerateKey [0xF7728CA2]SSDT spkp.sys ZwEnumerateValueKey [0xF7729030]SSDT spkp.sys ZwOpenKey Previously had AVG 7.5 free with no trouble to update automatically regularly. For a free anti-virus please follow these instructions:Click on this link: AVGUnderneath AVG Anti-Virus Free click on DownloadClick on AVG 8.5 Free for WindowsClick on DownloadA window will open. http://mseedsoft.com/trojan-horse/trojan-horse-injector-hf.html HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\Interfaces\{408b4471-79bd-4528-9867-a1fae527d106}\NameServer (Trojan.DNSChanger) -> Data:, -> Quarantined and deleted successfully.

Close any open browsers.2. Once updating is finished, run a full system scan. With these rigid changes, the best solution is to return Windows to previous working state is through System Restore.To verify if System Restore is active on your computer, please follow the Select "Enable Safe Mode with Networking" or number 5.h) Windows will now boot on Safe Mode with Networking.

I managed to download it through cnet but when I attempted to use it after installing it wouldn't run, I had to rename it to have it load up. This method ensures that your antivirus program can detect even newer variants of Trojan Horse Injector.

Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. Preview post Submit post Cancel post You are reporting the following post: Help with Trojan Horse Injector Virus This post has been flagged and will be reviewed by our staff. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff

It does not only scan files but also monitors your Internet traffic and is extremely active on blocking malicious communication. Implement full caution with links that you may receive from emails, social networking sites, and instant messaging programs. Click here to Register a free account now! scanning hidden autostart entries ...

Since I have the Malwarebytes Pro installed, initially came here for information. Track this discussion and email me when there are updates If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other pertinent details. I then copied and pasted the "MBAM.exe" file in the same folder and windows renamed it "Copy of MBAM".