mbren
Topic Starter
I've been through 6 computers since January 2005. I had no idea I was hijacked until I bought a brand new Dell Pc. and ctfmon, explorer.EXE and IExplorer.exe came right back into all the computers.
Everytime I shut Windows down, my registry is held. The last line of the Event warning reads: This is often
caused by services running as a user account, try configuring the services to run in either the
LocalService or NetworkService account. You bet they are.
I have lost Administrator rights and use of my pc 5 times with 5 pc's in the last year. I'm on a 6th pc right now. Brand new and they got me again. I don't understand how this continues plaguing me and stopping me from enjoying my life and my pc.
Tonight, explorer.exe (normal file name) was at 38,396 and winlogon.exe at 27,296. ctfmon.exe shows up and I bounce it and it comes right back again. So, I did a Symantec Removal Tool scan for W32.Mydoom.B@mm (and variants of W32.Novarg/Mydoom) cleaning today in Safe Mode (twice as instructed). It said my pc is not infected with W32.Mydoom.B@mm, etc.
Then, I did a HJT and found ctfmon.exe, explorer.EXE and IExplorer.exe. Only ctfmon.exe shows in Task Manager and explorer.exe (normal file name) and IE (normal file name).
I also have four svchost.exe's running (one at 34,320). I just found a tagged on TrendMicro PC-cillin file that they are using (C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe.) I no longer have an anti-virus program available and my TrendProxy (tmproxy.exe) is a running process of 68,044 CPUs. And another, O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing.
I am at my wit's end. Please, someone help me. Thank you.
MBren
Here is the HJT logfile header of today: (I have complete log if needed)
Logfile of HijackThis v1.99.1
Scan saved at 9:46:08 PM, on 1/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Please, please let me know what is going on and how I can get back to using a pc BY MYSELF?
Thanks, again!