Solved how to remove invisible program Spy Cobra

redcherry

New member
Hi,

my boyfriend has installed a program called Spy Cobra on my pc and i would like to know how to remove it as it doesnt show up in task manager. from what ive read its supposed to be undetected and isnt supposed to show up there..please help as it is invading my privacy and recording all my passwords and taking screen shots. i know this because i saw them on his pc. thank you!
 

My Computer

OS
windows 7
Hello Redcherry,

It may be best to just do a clean reinstall of Windows 7 since there's no telling what else he may have done or installed on your PC. Afterwards, change all your passwords. I would also recommend to not let him back on your PC, and you might consider kicking him to the curb since that's a violation of your trust in him. :(
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
i was thinking of doing a format to be sure its gone! thanks for reply! i am also worried about my phone is there a possibility its being monitored to?if so how would i know?
 

My Computer

OS
windows 7

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
i was thinking of doing a format to be sure its gone! thanks for reply! i am also worried about my phone is there a possibility its being monitored to?if so how would i know?

Are you in danger of physical abuse at your "boyfriend's" hands? I think that installing a keylogger like this is already a criminal offense. I hope that's the worst he's capable of.
 

My Computer

Computer Manufacturer/Model Number
homegrown
OS
Windows 7 Pro X64 SP1
CPU
Intel Core I7-3930k
Motherboard
Asus P9X79 Pro
Memory
16 GB Gskill DDR3-2133
Graphics Card(s)
eVGA GTX680
Sound Card
Creative X-Fi Titanium
Monitor(s) Displays
As PA246Q
Screen Resolution
1920 X 1200
Hard Drives
Corsair Force GT, 120 GB
WDC 1.5TB Caviar Black
PSU
PCP&C Silencer 750 Crossfire
Case
Silverstone FT02
Cooling
Noctua NH-D14
Keyboard
cheap Logitech USB
Mouse
Microsoft Intellimouse Explorer (old optical) USB
Internet Speed
6Mb cable
Other Info
Pioneer BDR-205
Samsung SH-203B
Monsoon 5.1 speakers
Gmer is an application that detects and removes rootkits.


On gmer's website click on Download EXE button. Randomly named EXE version of this tool will be generated and downloaded (to prevent detection by file name).

In GMER's window click on Scan button.
Item red highlighted items are suspicious items.
 

My Computer

Computer type
PC/Desktop
OS
Windows 8.1 ; Windows 7 x86 (Dec2008-Jan2013)
Other Info
"The scale icon at the top right of a post or tutorial is how you can give rep to the member."
Thank you for your replies! I also believe it is a criminal offence too and am a bit worried what else he capable of..but were finished after this I can't trust him!

Neutron I will run gmer later this afternoon a nd can I post log file here as im not sure wat is safe to remove..I have been running lots of spy ware removal programs so for all I know I may have already removed it but I still notice my laptop is real slow and getting very hot even when I'm not doing anything the fan is constantly blowing nearly..
 

My Computer

OS
windows 7
Sure you can upload the log file here if you like. If it's to large, then place in it a ZIP file instead.

Personally, I'd recommend a clean install to be safe though.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
i did scan but it didnt seem to find much..does that mean that maybe its already been removed by other scans ive done? anyway heres the log file..thanks :)
 

Attachments

My Computer

OS
windows 7
I would also recommend a clean install. Make sure you backup all your documents and pictures then wipe the HDD and start again.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Professional 64bit
CPU
Intel i7-5960X
Motherboard
EVGA X99 Classified
Memory
64GB Corsair Dominator 2400MHz
Graphics Card(s)
3 EVGA GTX980's
Sound Card
on board
Monitor(s) Displays
3 Dell E2715H 27"
Screen Resolution
1920x1080 (5760x1080)
Hard Drives
Samsung 950 Pro 1TB M.2 SSD,
Western Digital Black 2TB HDD's x5
Western Digital Black 1TB HDD's x3
PSU
Corsair AX1200i
Case
Corsair 750D
Cooling
Corsair H110i GT
Keyboard
Corsair K70
Mouse
Corsair M45
Internet Speed
250 down/10 up
Antivirus
Microsoft Security Essentials
Browser
IE 11, Google Chrome

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP pavilion DV6
OS
win7 home premium-64bit-SP1-IE10
CPU
T6600 2.2Ghz
Motherboard
HP Model 3628
Memory
4 Gb
Graphics Card(s)
ATI Mobility Radeon HD 4530
Sound Card
IDT High Definition
Screen Resolution
1366x768 @ 60Hz
Hard Drives
500Gb Western Digital
Antivirus
MSE
Other Info
Malwarebytes Antimalware + Spybot-Search&Destroy

My Computer

Computer Manufacturer/Model Number
Dell XPS 15 L502x
OS
Windows 7 Home Premium 64bit (O.E.M)
CPU
Intel Core i7 2630QM @2.00GHz
Memory
6GB DDR3
Graphics Card(s)
Intel Intergrated Graphics 3000, nVidia GT525M (1GB)
Screen Resolution
1366x768
Hard Drives
750GB Seagate 7200rpm
Keyboard
Backlit Dell XPS 15 L502x Keyboard
Mouse
Microsoft Wireless Mobile Mouse 4000
Internet Speed
2.5 Mb/s down, 0.36 up
Be aware that certain rootkit viruses can even survive reformatting a hard drive. In these cases the only 100% safe option is to replace the hard drive and reinstall Windows
 

My Computer

Computer type
PC/Desktop
OS
XP home premium, Vista home premium, Windows 7 Professional, Windows 8 home premium
The solution is use Process Explorer from Microsoft and look for Winlogon. Remove any entry after "," (comma).
This will prevent from auto starting...

Normally they are hidden from the user so go to c:\ click on View > Options > View > Show Hidden Files, Folders and drives and press OK

To remove the files use an anti virus or navigate to c:\program files\ and look for suspicious folder.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Toshiba
OS
Windows 8 32 bits
Antivirus
Kaspersky Internet Security
Browser
Chrome
Hello Redcherry,

It may be best to just do a clean reinstall of Windows 7 since there's no telling what else he may have done or installed on your PC. Afterwards, change all your passwords. I would also recommend to not let him back on your PC, and you might consider kicking him to the curb since that's a violation of your trust in him. :(

"Kicking" is the correct idea..."Curb" is the wrong place.

People and what they do never ceases to amaze me.:(
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
1. HP p6733w Desktop 2. HP Envy 700-515xt Desktop
OS
1. Windows 7 Home Premium sp1 - 64bit 2. Windows 7 Pro sp1 - 64bit
CPU
1. AMD Phenom II x2 511 3.4GHz 2. Intel i7-4790 Quad 4.0GHz
Motherboard
1. N-Alvorix-RS880-uATX 2. Kaili2
Memory
1. 5 GB - DDR3 2. 8GB DDR3-1600MHz
Graphics Card(s)
Integrated 1. ATI Radeon 4200 2. Intel HD Graphics 4600
Sound Card
1. Realtek High Definition Audio 2. Realtek (Neutered Beats)
Monitor(s) Displays
1. Acer V193L 2. HP 2311 Series Wide LCD
Screen Resolution
1. 1280 x 1024 2. 1920 x 1080
Hard Drives
1. 750 GB - 7200 RPM SATA 2. 1TB 7200 RPM SATA
PSU
1. 250w 2. 300w
Cooling
Stock
Keyboard
Logitech USB keyboard
Mouse
Logitech USB optical mouse
Internet Speed
1.0 - 2.0 mbps
Antivirus
Eset Smart Security v9.0.349.0
Browser
Pale Moon
Back
Top