computer help: I’m no novice at computer use, I’ve had my fair share - Help.com

I’m no novice at computer use, I’ve had my fair share

of removing trojans and viruses, even the illusive Virtumonde which renames and recreates itself after system reboots, but this one i have right now, I cant even identify, it wont let me run Spybot S&D, malwarebytes, nor will it let me update any of my other programs I manage to get running like Avast Antivirus. It’s really pissing me off, computer speeds are halting, constant message boxes saying privacy has been comprimised, and constant popups of the **** trojan trying to get me to download it’s rogue antispyware program Anti Spy Knight, wikipedia doesnt have anything specificly on this particular trojan, and nothing I do will let me get a leg up on this lil f***er. I need to know what to do, ASAP. I need to sleep but I need to finish this before I do.

This open post was written 11 months, 1 week ago | V/U/S: 77, 38, 4 | Edit Post | Leave a reply | Report Post


Reciprocity (0) Reciprocation Failure -- The poster has NOT helped anyone else yet!

Since writing this post hurley7 may have helped people, but has not within the last 4 days. hurley7 is not a verified member, has been around for 11 months, 1 week and has 1 posts and 22 replies to their name.

Post Tags (3)

Replies (38)

Where were you?

Click and drag to move the map around. FAQ: How we place people on this map »
You can also watch events on Help.com as they happen
Mouse over the map for 2 seconds to see an expanded, interactive view

Joey_PR offline Verified User (1 year, 3 months) Long Term User Shouts: 4 #
An Unknown Location | 11 months, 1 week ago (7 minutes after post)

did you try via “Safe Mode”?

Quote this reply Report this reply to moderators
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (9 minutes after post)

the laptop I am on, when rebooted, does not give me a chance to press F8 to go to the menu to run safe mode, my idiot brother installed someone’s version of a “lite” windows, and apparently they took that feature out, i dont have time to put regular XP on now though

Quote this reply Report this reply to moderators
This account has been deactivated.
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (17 minutes after post)

in think i MIGHT have found it, right when the popups launch, jqs.exe launches… now i need to nuke this file

Quote this reply Report this reply to moderators
This account has been deactivated.
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (19 minutes after post)

in google there are things that jqs is java related and the title of the spyware that i have also shows up… but i dont have jqs on any other system

Quote this reply Report this reply to moderators
This account has been deactivated.
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (21 minutes after post)

which is it?

Quote this reply Report this reply to moderators
This account has been deactivated.
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (22 minutes after post)

jqs is in the java folder, but oh wait, java handle the browser helper object to launch the popups, but i need to know how to stop this from blocker all 3 of my prgorams!!! i even bought spyhunter… blocked

Quote this reply Report this reply to moderators
This account has been deactivated.
Joey_PR offline Verified User (1 year, 3 months) Long Term User Shouts: 4 #
An Unknown Location | 11 months, 1 week ago (23 minutes after post)

hmmm…
Im not sure how to…
but what type of info or crap does the popup display?

Quote this reply Report this reply to moderators
Michael Leibman offline Verified User (1 year, 10 months) Long Term User Shouts: 4 #
Littleton, CO, US | 11 months, 1 week ago (29 minutes after post)

If you download ProcessMonitor from Microsoft you can watch what’s running and figure out where its files exist.

Quote this reply Report this reply to moderators
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (37 minutes after post)

ima work on process monitor, but the thing that pisses me off th emost, is i wasnt even going to shady websites or downloading hax

Quote this reply Report this reply to moderators
This account has been deactivated.
Mayor offline Verified User (1 year) Long Term User Shouts: 166 #
An Unknown Location | 11 months, 1 week ago (38 minutes after post)

Go to microsoft.com/downloads and download the latest Windows Malicious Software Removal Tool. Run it. Then check out the hosts file and see if something is hijacking it. Then go to start > run > netsh winsock reset catalog. Reboot.

Let me know if that helps.

Quote this reply Report this reply to moderators
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (40 minutes after post)

i dont know what too look for in process monitor there is 30000+ results and i dont know what to put into the filter

Quote this reply Report this reply to moderators
This account has been deactivated.
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (42 minutes after post)

ooo hey looky i found winlogon adding the browser helper objects

Quote this reply Report this reply to moderators
This account has been deactivated.
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (46 minutes after post)

i found this file C:\WINDOWS\system32\hgGyyvww.dll what say you? virus? looks like it maybe i have virtumonde again

Quote this reply Report this reply to moderators
This account has been deactivated.
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (47 minutes after post)

virtumonde generates a random name with 8 letters with random capitals and gives you popups

Quote this reply Report this reply to moderators
This account has been deactivated.
Michael Leibman offline Verified User (1 year, 10 months) Long Term User Shouts: 4 #
Littleton, CO, US | 11 months, 1 week ago (48 minutes after post)

hurley7 wrote:
i dont know what too look for in process monitor there is 30000+ results and i dont know what to put into the filter

It’d be easier if you killed all the running programs you can first, then see uses the registry the most while nothing is supposed to be running or when just one program hosting malware is running.

Quote this reply Report this reply to moderators
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (51 minutes after post)

i did kill all the excss but right now there are 220000 events
i need to put on a filter, but i dont know what to sort out

Quote this reply Report this reply to moderators
This account has been deactivated.
Michael Leibman offline Verified User (1 year, 10 months) Long Term User Shouts: 4 #
Littleton, CO, US | 11 months, 1 week ago (53 minutes after post)

Hmm… unfortunately I don’t have a Microsoft system so I can’t easily guide you through it step-by-step… that’s just what worked fastest for me in fixing other people’s mysterious-virus problems. Perhaps following the Mayor’s advice will get you there much quicker.

Quote this reply Report this reply to moderators
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (54 minutes after post)

im working on downloading it now, i started running vundofix

Quote this reply Report this reply to moderators
This account has been deactivated.
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (59 minutes after post)

great, my trojan wont let me download it

Quote this reply Report this reply to moderators
This account has been deactivated.
Michael Leibman offline Verified User (1 year, 10 months) Long Term User Shouts: 4 #
Littleton, CO, US | 11 months, 1 week ago (1 hour, 3 minutes after post)

I found this at one of the first google results for anti spy knight:

“Antispy Knight manual removal:
Kill processes:
antispyknight.exe
HELP:
how to kill malicious processes

Delete registry values:
AntispyKnight
Microsoft\Windows\CurrentVersion\Run\antispyknight
Microsoft\Windows\CurrentVersion\Uninstall\{D3C91983-DDCC-4586-9FE2-78E856 0470CF}
HELP:
how to remove registry entries

Delete files:
antispyknight.exe
HELP:
how to remove harmful files”

Quote this reply Report this reply to moderators
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (1 hour, 15 minutes after post)

antispyknight.exe isnt running, i didnt download it from their site

Quote this reply Report this reply to moderators
This account has been deactivated.
Michael Leibman offline Verified User (1 year, 10 months) Long Term User Shouts: 4 #
Littleton, CO, US | 11 months, 1 week ago (1 hour, 16 minutes after post)

You did mention it as one of the problems though. Did you search the registry for that term?

Quote this reply Report this reply to moderators
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (1 hour, 17 minutes after post)

yes i mentioned it because it is the trojan that tells you you need to download anti spy knight

Quote this reply Report this reply to moderators
This account has been deactivated.
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (1 hour, 19 minutes after post)

im 10 minutes away from nuking this hard drive

Quote this reply Report this reply to moderators
This account has been deactivated.
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (1 hour, 20 minutes after post)

this is redicules i am done, now it apparently forwards me to more of their ****** sites when i try to go to something that could help me

time to die trojan

Quote this reply Report this reply to moderators
This account has been deactivated.
Michael Leibman offline Verified User (1 year, 10 months) Long Term User Shouts: 4 #
Littleton, CO, US | 11 months, 1 week ago (1 hour, 20 minutes after post)

hurley7 wrote:
yes i mentioned it because it is the trojan that tells you you need to download anti spy knight

Yeah, I know. That’s what those removal instructions are for. They may be totally inaccurate as to where things actually exist but the general malware-style is usually the same.

Quote this reply Report this reply to moderators
Michael Leibman offline Verified User (1 year, 10 months) Long Term User Shouts: 4 #
Littleton, CO, US | 11 months, 1 week ago (1 hour, 22 minutes after post)

just ignore me if I’m babbling. I was looking at other posts.

Quote this reply Report this reply to moderators
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (1 hour, 23 minutes after post)

lol its ok, i think i found something in process monitor,when the popups come up i hit go to process then filter everything else out in monitor and lets see…

Quote this reply Report this reply to moderators
This account has been deactivated.
Michael Leibman offline Verified User (1 year, 10 months) Long Term User Shouts: 4 #
Littleton, CO, US | 11 months, 1 week ago (1 hour, 28 minutes after post)

‘processexplorer’, part of the same sysinternals group of programs may have been the easier one to use.

Quote this reply Report this reply to moderators
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (1 hour, 36 minutes after post)

okay linked processes: normaliz.dll Linked; unknown
sxmg4.dll Known malware
coegzt.dll Linked; N/A most likely randomly named malware
umdmxfrm.dll Linked; unknown
bunches more most valid

Quote this reply Report this reply to moderators
This account has been deactivated.
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (1 hour, 37 minutes after post)

normaliz is valid i think

Quote this reply Report this reply to moderators
This account has been deactivated.
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (1 hour, 39 minutes after post)

coegzt is most likely malware no decription or certificate claiming micrsoft

Quote this reply Report this reply to moderators
This account has been deactivated.
hurley7 offline Unverified User #
An Unknown Location | 11 months, 1 week ago (1 hour, 39 minutes after post)

umdmxfrm is valid

Quote this reply Report this reply to moderators
This account has been deactivated.
Michael Leibman offline Verified User (1 year, 10 months) Long Term User Shouts: 4 #
Littleton, CO, US | 11 months, 1 week ago (2 hours, 9 minutes after post)

I think the most important thing is to not take it too personally, don’t let yourself get too frustrated by the machine. You’re running Windows, it’s buggy and insecure, that’s just how it is. Things screw up, crash, you can fix it, or wipe the hard drive or reinstall the OS. It all doesn’t have to matter too much, it’s like a game in itself.

That’s my words of wisdom, take it for whatever it’s worth.

Quote this reply Report this reply to moderators
The Clue offline Verified User (4 years) Long Term User Shouts: 19 #
Minot, ND, US | 11 months, 1 week ago (4 hours, 12 minutes after post)

I know what that bug is but I suggest that you get a legit copy of you office system and reformat the pc. That way you will get all of the options that you should have. Hope this helps :-)

Quote this reply Report this reply to moderators
DZM offline Verified User (11 months) Long Term User Shouts: 0 #
An Unknown Location | 11 months ago (1 week, 3 days after post)

My suggestion (If you plan to reinstall)
- Boot from an external device. In my case I use a portable version of linux on my flashdrive.
- Copy all the things you want to save to an external device. In my case I would use my 500gb hard drive. (costs about $100)
- My Documents, Favorites, and Desktop is all I keep, but you may need more.
- Reinstall the OS with a proper copy. For me it would be Windows XP with SP2.
- Run all the critical updates to Windows - keeping your computer up to date is the most important thing in protecting against viruses (If you have had problems with SP3 you can skip that one) I install Microsoft updates and install/update everything except the new Microsft Search tool that slows down my computer.
- Created a backup image of your computer. I own Ghost, so I would use that. But there are others that would work.
- Install your security programs - For me it would be Spybot and CCleaner. So far I haven’t had a need for anti-virus software. I do regular reinstalls of my computer, and am constantly updating my Ghost image so that re-installation is easy.
- Update your security software - Especially if you install anti-virus software.
- Create another backup image of your computer.
- Install all the internet programs you use. For me it is Flash, Shockwave, Acrobat, Java, Picasa, Chrome, Talk, Quicktime, and Silverlight.
- Update the internet programs.
- Create another backup image of your computer. (You can clean out the original one if you are sure you security software hasn’t effected the speed of your computer.)
- Install Office (I use OpenOffice.org), and all the other software that you think is most important.
- Run Updates.
- Create another image.
- Use your computer like you normally would. Surf the net, install demo software, test beta software, chat, email, …
- Continually backup your documents, pictures, music to your external device.
- Reinstall you computer with your latest image when you computer gets bogged down with to much stuff and/or installed programs.
- Run updates again.
Repeat the last four steps as much as you like, depending on how you use your computer.

Quote this reply Report this reply to moderators
The Clue offline Verified User (4 years) Long Term User Shouts: 19 #
Minot, ND, US | 11 months ago (1 week, 3 days after post)

Why would anyone so so many backups when you installing your programs after new install? It automatically makes a restore point so you don’t have to do any of those images until your finished installing all of the programs. Must have a lot of free time on you hands LMAO. Hope this helps :-)

Quote this reply Report this reply to moderators
DZM offline Verified User (11 months) Long Term User Shouts: 0 #
An Unknown Location | 10 months, 4 weeks ago (1 week, 4 days after post)

It is just how I do it. The computer does the work for me. I am usually working on other things while it is being ghosted. I have had issues with system restore so I don’t use it anymore. It used to take me hours to fix a computer problem, now I just copy my data (that isn’t backed up) and reinstall. The most time I will spend on a problem is 15 min now.

Quote this reply Report this reply to moderators

Invite Others to Help

A logged in and verified Help.com member has the ability to setup a Friends List and invite others to help with posts.