Solved Unable to remove virus/malware

little Dom 12

New member
Local time
3:28 PM
Messages
15
After running a spybot scan it comes up with 2 infections but is unable to remove them, it shows they are in the registry, the ones it can't remove/ keep coming back are called:

SafeSaver.BHO
W3i.IQ5.fraud

Malware bites cannot detect them yet spybot is showing them as a severe threat can anyone help me remove them or link me to something that can
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home premium 64 bit
CPU
I3 2120 3.3ghz
Graphics Card(s)
Nvidia Geforce GT 620
Antivirus
Microsoft ecurity essentials
Browser
Firefox

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
The ESET online scan is a good program. However, it is a rather lengthy process, and can be used after we zero-in on the location of the malware in question.

Please use the tool that follows to get to the target issues...

Zoek:
Download > Download zoek.exe version 5.0.0.0
Click: Download Zoek.exe version 5.0.0.0 (Do not click .zip or .rar)

When the download shows, and you get the option to save, please do so to the Desktop.
Right-click zoek.exe and select: Run as Administrator (Give it a few seconds to appear.)

If your AntiVirus warns you about the program, either allow Zoek to run, or temporarily disable your AV program.
Info on how to disable your security applications > How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs - Security Mini-Guides

Next, copy and then paste the entire script inside the code box below to the input field of Zoek:

Code:
createsrpoint; 
process; 
filesrcm; 
startupall; 
installedprogs;
installer-list; 
uninstall-list;
hijackthis; 
firefoxlook; 
chromelook;  
srinfo; 
DIR /S /A:L "%systemdrive%\*">>"%temp%\log.txt";b

Now...

Close any open windows.

Click the Run script button and wait. It takes a few minutes to run all the script.

When finished, the zoek-results.log is opened in Notepad.
If a reboot is needed the log is opened after the reboot.

The log is also found on the systemdrive, normally C:\

:ar: Please post the zoek-results.log in your reply.

Thanks.


.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home premium 64 bit
CPU
I3 2120 3.3ghz
Graphics Card(s)
Nvidia Geforce GT 620
Antivirus
Microsoft ecurity essentials
Browser
Firefox

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
No signs of SafeSaver.BHO or W3i.IQ5.fraud.

Everything looked for came up blank.

What version of Spybot do you have installed?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
its version 2.1 (atleast thats what it says when i open it) guessing its a problem with spyware then if nothing else can find that particular virus
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home premium 64 bit
CPU
I3 2120 3.3ghz
Graphics Card(s)
Nvidia Geforce GT 620
Antivirus
Microsoft ecurity essentials
Browser
Firefox
There is a later version of Spybot Search and Destroy.

Please update your program.

Start the Update through the Spybot tray icon (on the lower right of your Desktop by the clock).

Right-click the Spybot 2 tray icon and select: Update

Next, run a scan, and see if you still get these goodies:
SafeSaver.BHO
W3i.IQ5.fraud


When done, please obtain a Spybot report.

After the System Scan, select: Save scan log
Its on the navigation bar on the left.
Save to the Desktop, and provide in your reply.


Thanks!


.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home premium 64 bit
CPU
I3 2120 3.3ghz
Graphics Card(s)
Nvidia Geforce GT 620
Antivirus
Microsoft ecurity essentials
Browser
Firefox
Aha! Good job.

There is nothing better than knowing what, exactly, is causing the problem. It beats looking at a crystal ball!!

:info: Please right-click Zoek.exe again, and select: Run as Administrator
Give the program a few seconds to appear.

Next, copy/paste the entire script inside the code box below to the input field of Zoek:
Do not copy the word 'code'.

Code:
W3i;u
SafeSaver;u
[-HKEY_LOCAL_MACHINE\SOFTWARE\Freeze.com];r
[-HKEY_LOCAL_MACHINE\SOFTWARE\SProtector];r
emptyalltemp;
emptyclsid;

Note: This script is written only for use on this computer. Please do not use it on another computer even if the problems are similar!

Now...

Close any open windows.

Click the Run script button and wait. It takes a few minutes to run the script.

When finished, the zoek-results.log is opened in Notepad.
If a reboot is needed the log is opened after the reboot.

:ar: Please post the new zoek-results.log in your reply.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home premium 64 bit
CPU
I3 2120 3.3ghz
Graphics Card(s)
Nvidia Geforce GT 620
Antivirus
Microsoft ecurity essentials
Browser
Firefox
Please run Spybot again, and post its results.

This may all be a false detection.

Thanks!
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Excellent!!

While we are at it, please download Security Check:
http://screen317.spywareinfoforum.org/
Save to your Desktop.
Double-click: SecurityCheck.exe
Follow the onscreen instructions inside the black box.

When done, a Notepad report opens automatically, it is called: checkup.txt

:ar: Please post the checkup.txt in your reply.
(Please do not take any corrective actions!)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home premium 64 bit
CPU
I3 2120 3.3ghz
Graphics Card(s)
Nvidia Geforce GT 620
Antivirus
Microsoft ecurity essentials
Browser
Firefox
This is a vulnerability you cannot afford to have:

:warn: Adobe Reader out of date!

Please download the latest version of Adobe Reader from:
here.

Once installed, launch it, select Help > Check for Updates, and install any updates.
Then, uninstall earlier versions of Adobe Reader:
Go to Start > Control Panel > Add/Remove Programs, and remove all older versions of Adobe Reader.


One the above is done, if you no longer have malware questions or problems, you are good to go!

Let's wrap up and remove the tools used and their reports. Since these tools are updated frequently, it is best to have their latest version.

Tools and Reports:
Zoek, and its zoek-results.log
Security check, and its checkuo.txt

Also, make sure your security software is ALL enabled and running!

Thanks for following all the instructions and providing the reports!!

Have a great year 2014, little Dom 12 !!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Thanks for the help ive ipdated Adobe and at the moment have no more uninvited guests on my pc
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home premium 64 bit
CPU
I3 2120 3.3ghz
Graphics Card(s)
Nvidia Geforce GT 620
Antivirus
Microsoft ecurity essentials
Browser
Firefox
Glad to help! :)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
scan result of Zoek

My all browsers are redirecting to "https://huasvsaier.ru", please help me in this regards.
Thanks
Vipul
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 Enterprise 32bit
Hard Drives
500gb
Antivirus
kaspersky
Browser
IE 11, Mozila, Chrome
Back
Top