That entry should go, especially without the file being present. This is what we suggest you do.
Uninstall these programs because you tried to disable them and it didn't work, maybe you did not disable them correctly. You can uninstall Prevx and AVG Anti Spyware they are just trials anyway. You can always download and reinstall AVG Free , dont know about Tau monitor. Completely uninstall them all then reboot and try fixing that 020 entry with HJT. O20 - Winlogon Notify: cryptimg - cryptimg.dll (file missing)
cryptimg is still in registry and now won't delete.
the files within look like this
default REG_SZ (VALUE NOT SET)
asynchronous REG_DWORD 0X00000001(1)
dllname REG_EXPAND_SZ cryptimg.dll
impersonate REG_DWORD 0X00000000(0)
startshell REG_SZ cryptimgshellnotify
uninstalled those programs but still no luck
is a xp reformat my only option now?
Save this as fix.reg Choose to save as *all files and place it on your desktop.
Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.
You should delete the other fixreg if its still on your desktop that we did earlier.
Delete these files:
C:\WINDOWS\iexpl0ra.exe
C:\Documents and Settings\All Users.WINDOWS\Application Data\date flap shim dvd\htm internet.exe
C:\docments and settings\pete\LOCAL Settings\Temp\\sysonling.exe
C:\docments and settings\pete\\APPLIC~1\\LOUDCU~1\\inside deaf.exe
Go to Start> Run and type in regedit
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptimg
With the offending registry key highlighted, select 'Security > Permissions'
from the menu and set the permissions back to 'Everyone - Full Control', then
you will be allowed to delete it. Be aware that you may need to tick the box for
'replace on all sub-keys' as well, if the key you are trying to delete has
subkeys underneath it - a locked key further down the branch you are trying to
kill will cause the same 'refused' symptoms you described.
Now open HJT and try to delete that entry again. Post a new HJT log either way.
found and deleted iexpl0ra.exe
found sham flim dvd folder and deleted whole thing
couldnt find the other two
did as instructed in regedit
020 stil there
Logfile of HijackThis v1.99.1
Scan saved at 15:38:49, on 11/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
1. Please downloadThe Avengerby Swandog46 to your Desktop.
Click on Avenger.zip to open the file
Extract avenger.exe to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
Files to delete:
C:\Program Files\loud curb bows
C:\WINDOWS\iexpl0ra.exe
C:\WINDOWS\system32\drivers\ttp.exe
C:\Documents and Settings\All Users\Application Data\date flap shim dvd
C:\Documents and Settings\pete\Local Settings\Temp\sysonling.exe
C:\Documents and Settings\pete\Application Data\loud curb bows
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
3. Now, start The Avenger program by clicking on its icon on your desktop.
Under "Script file to execute" choose "Input Script Manually".
Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
Paste the text copied to clipboard into this window by pressing (Ctrl+V).
Click Done
Now click on the Green Light to begin execution of the script
Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
On reboot, it will briefly open a black command window on your desktop, this is normal.
After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply
Go to Start > Run > copy and paste this in > will produce a file called output.txt in "C"
avenger
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\vqjgvimb
*******************
Script file located at: \??\C:\Program Files\jsampysc.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\Program Files\loud curb bows not found!
Deletion of file C:\Program Files\loud curb bows failed!
Could not process line:
C:\Program Files\loud curb bows
Status: 0xc0000034
File C:\WINDOWS\iexpl0ra.exe not found!
Deletion of file C:\WINDOWS\iexpl0ra.exe failed!
Could not process line:
C:\WINDOWS\iexpl0ra.exe
Status: 0xc0000034
File C:\WINDOWS\system32\drivers\ttp.exe not found!
Deletion of file C:\WINDOWS\system32\drivers\ttp.exe failed!
Could not process line:
C:\WINDOWS\system32\drivers\ttp.exe
Status: 0xc0000034
Could not open file C:\Documents and Settings\All Users\Application Data\date flap shim dvd for deletion
Deletion of file C:\Documents and Settings\All Users\Application Data\date flap shim dvd failed!
Could not process line:
C:\Documents and Settings\All Users\Application Data\date flap shim dvd
Status: 0xc000003a
File C:\Documents and Settings\pete\Local Settings\Temp\sysonling.exe not found!
Deletion of file C:\Documents and Settings\pete\Local Settings\Temp\sysonling.exe failed!
Could not process line:
C:\Documents and Settings\pete\Local Settings\Temp\sysonling.exe
Status: 0xc0000034
File C:\Documents and Settings\pete\Application Data\loud curb bows not found!
Deletion of file C:\Documents and Settings\pete\Application Data\loud curb bows failed!
Could not process line:
C:\Documents and Settings\pete\Application Data\loud curb bows
Status: 0xc0000034
Completed script processing.
*******************
Finished! Terminate.
Logfile of HijackThis v1.99.1
Scan saved at 17:03:56, on 11/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
I need to see this.
Go to Start > Run > copy and paste this in
regedit /e c:\output.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify"
It will produce a file called output.txt in "C"
We are calling in an expert on these infections to take a look and offer advice.
Run both these reg fixes, before you do delete the ones on your desktop that we created already.
Launch Notepad (Start>All Programs>Accessories), and copy/paste all the BOLD REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save
ran avg av and found 2 psw trojans in docs+setts/allusers/WINDOWS/App data/sectaskman/IExplore.q_1963766C_q
and 2 worm/delfs in docs+setts\kate\localsettings\temp\internat.com
don't know if this helps any
Logfile of HijackThis v1.99.1
Scan saved at 19:43:27, on 12/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)