Safeom.com virus removal?

eurocracy

Poster Extraordinaire
Joined
Feb 28, 2010
Messages
2,824
I've got the incredibly annoying safeom.com virus that stops many programs running and such. It's also annoying to remove. Spyware doctor apparently removes it but refuses to start up (Yes I have temporarily disabled the virus via task manager, where it will stay offline until my next boot).
When I load up spyware doctor it does the smart update thing, then pops up the prompt to smart update over and over, when I click cancel the program flashes up and then disappears. I need some help in getting Spyware Doctor working or I'm going to need a windows registry expert to help me remove the program manually.
Do not go to safeom.com, you'll probably get it.
And don't worry guys, thankfully it's on my laptop.
 
Last edited:
You try running your antivirus in Safe Mode?
This is an effective spyware, there's only 2 ways to remove it and one program. I'm currently trying a method to get spyware doctor running again. I've tried antivirus, sophos. Nothing turned up.
 
Virus removed, for those who get this virus, reboot your PC and cntrl+alt+delete to get up task manager ASAP. Then wait for the popup in the tray to eppear and open the program. On task manager right click the taks and hit go to process. Then right click the selected process and end it. Now in your browser settings it will have left a proxy behind, make sure you turn it off. Then you need spyware doctor, run a full scan and have it fix everything and do a virus scan afterwards. Reboot and hope it's gone.
Oh yeah, it took me 3 hours, I started trying at Midnight @_@
 
Last edited:
I googled this, and i found a site telling you to delete some stuff in appdata and in the registry.
I suggest you look there in case the virus is still on your computer.

Delete:
%Temp% [RANDOM]
%Temp% [random]\[RANDOM]. Exe

Delete stuff in registry:
HKCU Software [RANDOM]
HKCU Software Microsoft Internet Explorer Download “RunInvalidSignatures” = “1′
HKCU Software Microsoft Internet Explorer PhishingFilter “Activated” = “0″
HKCU Software Microsoft Windows CurrentVersion Internet Settings “proxy-server” = “http = 127.0.0.1:59274″
HKCU Software Microsoft Windows CurrentVersion Internet Settings “ProxyEnable” = “1″
HKCU Software Microsoft Windows CurrentVersion Policies Associations “LowRiskFileTypes” = “. Exe”
HKCU Software Microsoft Windows CurrentVersion Run “[RANDOM]. Exe”
HKCU Software Microsoft Internet Explorer Download “CheckExeSignatures” = “i”

You don't have to do this, but i suggest you do it so that you are on the safe side.
 

Latest posts

Back
Top