This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need HijackThis help, Please

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been through 6 computers since January 2005. I had no idea I was hijacked until I bought a brand new Dell Pc. and ctfmon, explorer.EXE and IExplorer.exe came right back into all the computers. Everytime I shut Windows down, my registry is held. The last line of the Event warning reads: This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account. You bet they are. I have lost Administrator rights and use of my pc 5 times with 5 pc's in the last year. I'm on a 6th pc right now. Brand new and they got me again. I don't understand how this continues plaguing me and stopping me from enjoying my life and my pc. Tonight, explorer.exe (normal file name) was at 38,396 and winlogon.exe at 27,296. ctfmon.exe shows up and I bounce it and it comes right back again. So, I did a Symantec Removal Tool scan for W32.Mydoom.B@mm (and variants of W32.Novarg/Mydoom) cleaning today in Safe Mode (twice as instructed). It said my pc is not infected with W32.Mydoom.B@mm, etc. Then, I did a HJT and found ctfmon.exe, explorer.EXE and IExplorer.exe. Only ctfmon.exe shows in Task Manager and explorer.exe (normal file name) and IE (normal file name). I also have four svchost.exe's running (one at 34,320). I just found a tagged on TrendMicro PC-cillin file that they are using (C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe.) I no longer have an anti-virus program available and my TrendProxy (tmproxy.exe) is a running process of 68,044 CPUs. And another, O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing. I am at my wit's end. Please, someone help me. Thank you. MBren Here is the HJT logfile header of today: (I have complete log if needed) Logfile of HijackThis v1.99.1 Scan saved at 9:46:08 PM, on 1/28/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Please, please let me know what is going on and how I can get back to using a pc BY MYSELF? Thanks, again!
Hi mbren,
Can you post a full HJT log you have only posted the header of the log

Here is the HJT logfile header of today: (I have complete log if needed)
Logfile of HijackThis v1.99.1
Scan saved at 9:46:08 PM, on 1/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Thanks dan
Hi, Dan: Thanks for your reply. I lost all my documents (including the HJT log) since I could no longer access my Admin account. I spoke with Dell On Call techs who debugged and formatted my pc (again). Then, they suggested I download Kaspersky anti-virus and firewall and Sygate Personal firewall (both free). I do not have any bad stuff on my pc as of this cleansing. The techs did a Dell Connect and searched for the RootKit Hd4 (NewDotNet) and did not find it. Now, I will do an HJT on this pc and will post it. Thanks, Dan. Will get back to you soon. Mbren

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI