I’m no novice at computer use, I’ve had my fair share
of removing trojans and viruses, even the illusive Virtumonde which renames and recreates itself after system reboots, but this one i have right now, I cant even identify, it wont let me run Spybot S&D, malwarebytes, nor will it let me update any of my other programs I manage to get running like Avast Antivirus. It’s really pissing me off, computer speeds are halting, constant message boxes saying privacy has been comprimised, and constant popups of the **** trojan trying to get me to download it’s rogue antispyware program Anti Spy Knight, wikipedia doesnt have anything specificly on this particular trojan, and nothing I do will let me get a leg up on this lil f***er. I need to know what to do, ASAP. I need to sleep but I need to finish this before I do.
This open post was written 11 months, 1 week ago | V/U/S: 77, 38, 4 | Edit Post | Leave a reply | Report Post
Reciprocity (0)
Since writing this post hurley7 may have helped people, but has not within the last 4 days. hurley7 is not a verified member, has been around for 11 months, 1 week and has 1 posts and 22 replies to their name.
Post Tags (3)
Replies (38)
Where were you?
You can also watch events on Help.com as they happen
did you try via “Safe Mode”?
the laptop I am on, when rebooted, does not give me a chance to press F8 to go to the menu to run safe mode, my idiot brother installed someone’s version of a “lite” windows, and apparently they took that feature out, i dont have time to put regular XP on now though
in think i MIGHT have found it, right when the popups launch, jqs.exe launches… now i need to nuke this file
in google there are things that jqs is java related and the title of the spyware that i have also shows up… but i dont have jqs on any other system
which is it?
jqs is in the java folder, but oh wait, java handle the browser helper object to launch the popups, but i need to know how to stop this from blocker all 3 of my prgorams!!! i even bought spyhunter… blocked
hmmm…
Im not sure how to…
but what type of info or crap does the popup display?
If you download ProcessMonitor from Microsoft you can watch what’s running and figure out where its files exist.
ima work on process monitor, but the thing that pisses me off th emost, is i wasnt even going to shady websites or downloading hax
Go to microsoft.com/downloads and download the latest Windows Malicious Software Removal Tool. Run it. Then check out the hosts file and see if something is hijacking it. Then go to start > run > netsh winsock reset catalog. Reboot.
Let me know if that helps.
i dont know what too look for in process monitor there is 30000+ results and i dont know what to put into the filter
ooo hey looky i found winlogon adding the browser helper objects
i found this file C:\WINDOWS\system32\hgGyyvww.dll what say you? virus? looks like it maybe i have virtumonde again
virtumonde generates a random name with 8 letters with random capitals and gives you popups
hurley7 wrote:
i dont know what too look for in process monitor there is 30000+ results and i dont know what to put into the filter
It’d be easier if you killed all the running programs you can first, then see uses the registry the most while nothing is supposed to be running or when just one program hosting malware is running.
i did kill all the excss but right now there are 220000 events
i need to put on a filter, but i dont know what to sort out
Hmm… unfortunately I don’t have a Microsoft system so I can’t easily guide you through it step-by-step… that’s just what worked fastest for me in fixing other people’s mysterious-virus problems. Perhaps following the Mayor’s advice will get you there much quicker.
im working on downloading it now, i started running vundofix
great, my trojan wont let me download it
I found this at one of the first google results for anti spy knight:
“Antispy Knight manual removal:
Kill processes:
antispyknight.exe
HELP:
how to kill malicious processes
Delete registry values:
AntispyKnight
Microsoft\Windows\CurrentVersion\Run\antispyknight
Microsoft\Windows\CurrentVersion\Uninstall\{D3C91983-DDCC-4586-9FE2-78E856 0470CF}
HELP:
how to remove registry entries
Delete files:
antispyknight.exe
HELP:
how to remove harmful files”
antispyknight.exe isnt running, i didnt download it from their site
You did mention it as one of the problems though. Did you search the registry for that term?
yes i mentioned it because it is the trojan that tells you you need to download anti spy knight
im 10 minutes away from nuking this hard drive
this is redicules i am done, now it apparently forwards me to more of their ****** sites when i try to go to something that could help me
time to die trojan
hurley7 wrote:
yes i mentioned it because it is the trojan that tells you you need to download anti spy knight
Yeah, I know. That’s what those removal instructions are for. They may be totally inaccurate as to where things actually exist but the general malware-style is usually the same.
just ignore me if I’m babbling. I was looking at other posts.
lol its ok, i think i found something in process monitor,when the popups come up i hit go to process then filter everything else out in monitor and lets see…
‘processexplorer’, part of the same sysinternals group of programs may have been the easier one to use.
okay linked processes: normaliz.dll Linked; unknown
sxmg4.dll Known malware
coegzt.dll Linked; N/A most likely randomly named malware
umdmxfrm.dll Linked; unknown
bunches more most valid
normaliz is valid i think
coegzt is most likely malware no decription or certificate claiming micrsoft
umdmxfrm is valid
I think the most important thing is to not take it too personally, don’t let yourself get too frustrated by the machine. You’re running Windows, it’s buggy and insecure, that’s just how it is. Things screw up, crash, you can fix it, or wipe the hard drive or reinstall the OS. It all doesn’t have to matter too much, it’s like a game in itself.
That’s my words of wisdom, take it for whatever it’s worth.
I know what that bug is but I suggest that you get a legit copy of you office system and reformat the pc. That way you will get all of the options that you should have. Hope this helps :-)
My suggestion (If you plan to reinstall)
- Boot from an external device. In my case I use a portable version of linux on my flashdrive.
- Copy all the things you want to save to an external device. In my case I would use my 500gb hard drive. (costs about $100)
- My Documents, Favorites, and Desktop is all I keep, but you may need more.
- Reinstall the OS with a proper copy. For me it would be Windows XP with SP2.
- Run all the critical updates to Windows - keeping your computer up to date is the most important thing in protecting against viruses (If you have had problems with SP3 you can skip that one) I install Microsoft updates and install/update everything except the new Microsft Search tool that slows down my computer.
- Created a backup image of your computer. I own Ghost, so I would use that. But there are others that would work.
- Install your security programs - For me it would be Spybot and CCleaner. So far I haven’t had a need for anti-virus software. I do regular reinstalls of my computer, and am constantly updating my Ghost image so that re-installation is easy.
- Update your security software - Especially if you install anti-virus software.
- Create another backup image of your computer.
- Install all the internet programs you use. For me it is Flash, Shockwave, Acrobat, Java, Picasa, Chrome, Talk, Quicktime, and Silverlight.
- Update the internet programs.
- Create another backup image of your computer. (You can clean out the original one if you are sure you security software hasn’t effected the speed of your computer.)
- Install Office (I use OpenOffice.org), and all the other software that you think is most important.
- Run Updates.
- Create another image.
- Use your computer like you normally would. Surf the net, install demo software, test beta software, chat, email, …
- Continually backup your documents, pictures, music to your external device.
- Reinstall you computer with your latest image when you computer gets bogged down with to much stuff and/or installed programs.
- Run updates again.
Repeat the last four steps as much as you like, depending on how you use your computer.
Why would anyone so so many backups when you installing your programs after new install? It automatically makes a restore point so you don’t have to do any of those images until your finished installing all of the programs. Must have a lot of free time on you hands LMAO. Hope this helps :-)
It is just how I do it. The computer does the work for me. I am usually working on other things while it is being ghosted. I have had issues with system restore so I don’t use it anymore. It used to take me hours to fix a computer problem, now I just copy my data (that isn’t backed up) and reinstall. The most time I will spend on a problem is 15 min now.
Invite Others to Help
A logged in and verified Help.com member has the ability to setup a Friends List and invite others to help with posts.
