Help with my HJT log please

By AnFboy1892 ยท 5 replies
Mar 11, 2006
  1. I have several problems: Whenever I CTRL+ALT+DELETE there are no tabs on my window. Also, It says my computer is no longer registered to me. Also, because of something on my computer I cannot run ad-aware or other anti-spyware/adware programs, even online free virus scans. My last hope is HTJ will help out, maybe some /regedit help? /shrug.

    Attached Files:

  2. BeetleTX330

    BeetleTX330 TS Rookie

    Hi. You definitely have some bad things in the HJT log. You also have a few things that I always disable, even if they're not BAD (it's just that they don't server ENOUGH of a needed purpose, IMHO).

    I've hit TAB and put an XX in front of what I know to be bad. I've hit TAB and put two asterisks (**) in front of the ones I'd disable because they're not necessary.

    Lastly, I use Sysinternals "AutoRuns" app to disable stuff -- it does a really good job and is easy to use (a side note, when you first run AutoRuns, hit the ESCape button and go to Options and checkmark "Hide Microsoft Entries", then refresh the list). Once the list is up, you can selectively uncheckmark the entries you don't want to start up.
  3. AnFboy1892

    AnFboy1892 TS Rookie Topic Starter


    Thank you Beetle,

    I removed the suggested items. I'm going to reboot in safemode and make a fresh HJT log then try the sysinternals.
  4. AnFboy1892

    AnFboy1892 TS Rookie Topic Starter


    Here's the updated HJT log.
  5. BeetleTX330

    BeetleTX330 TS Rookie

    I see that the following line is still present and shouldn't be:
    O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun

    I also see:
    O4 - HKLM\..\RunServices: [windrv] C:\WINDOWS\System32\windrv32.exe
    ...which I must have missed the first time around. It's bad too, see:

    I don't see a problem with the rest of the list BUT that's not a guarantee that one of those has been compromised. Also, these remaining bad listings may be powerful enough to combat your removal techniques and re-install themselves (which may explain why "cfgmgr52" is back).

    If you haven't yet, go to and run their online anti-virus/malware scanner in case YOUR anti-virus software has been compromised (which is the first thing viruses do nowadaze).
  6. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    Your system is infected with quite a collection of nasties.

    Go and have your computer scanned HERE.

    Then go HERE and follow the instructions.

    Then, go and read both these threads by RBS. Follow all the instructions exactly.

    How to remove Trojans and its ilk! and How to remove Begin2search / coolwebsearch and other nasties.

    Post a fresh HJT log, only after doing the above.

    Regards Howard :wave: :wave:
Topic Status:
Not open for further replies.

Similar Topics

Add your comment to this article

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...