This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Where Is Whenusave?

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi everyone! Just thought I'd drop a line on an interesting problem (?) I'm having. On SiggyX's advice I've been running the occasional online scan to keep my mule healthy and I've come up with something odd. On Panda's Activescan I get the result that I have Adware in the Windows Registry called WhenUSave. Of course, while I'm running the free version of Activescan it says it can't delete it automatically, but it could if I paid for their antivirus service. On following their instructions on how to remove this Adware manually, I can't find it on my system at all. No other antivirus/spyware removal program detects it. I don't see it in the registry, and I can't find the specified files when I search for them. Yet every time I do Activescan it comes up with the same result. Previously (about a month ago) Panda found no such result. I'm not using P2P programs, only using this computer for work (ahem, mostly). Am I going mad? Well, yes, but do I have reason to be annoyed by this? Is this just some ploy by Panda to buy their software or is it something that Activescan is detecting that looks like WhenUSave? Any enlightenment would truly be appreciated! Amanda
Could be a false positive. You may want to try a couple other online scans and see what they find… if anything.

Try the scans at TrendMicro Housecall, eTrust AntiVirus Web Scanner.

See if they find anything. Reboot between each scan. If they do find something that they can't clean, make a note of it, and post here along with a HijackThis log.

The latest version of HijackThis is 1.99.1 and can be downloaded from here. Make sure you run HijackThis from its own folder if you are going to post a log.
Thanks Kota! I have done Housecall but am unable to access the update for the new beta version 6.0, says it can't access the server for some reason. I'm behind a firewall but can't see anywhere that Activeupdate is being blocked. I'll try the other scan and let you know.
I should mention too that both Spybot and AdAware have found no incident of Whenusave, they're both fully updated. I'm pretty sure we're looking at a false positive but better safe than spied on. By the way, how's the weather in Alberta? We're almost rid of our snow here in Ontario….can't wait to see green grass again!
Weathers pretty good. +10, little bit overcast. Had a bit of a snap a couple weeks ago, snowed pretty good, got cold. Its all gone now though. Can't wait for summer!
Copy that, I have a major case of cabin fever at the moment which would probably explain my obsession with this particular bug. eTrust did find something, which I deleted then promptly forgot what it was called. I redid the scan after rebooting and it didn't find it again. I'm still unable to connect to the update server for the beta Housecall 6.0, don't really know what the deal is with that one, so I'm doing the regular version of the scan. Then I'll do another Panda scan and let you know what I get. Thanks again! Amanda
Well, I've done just about every scan I know about AND I've picked apart my own HJT log and I don't see anything. I'm still learning about HJT but mine's easy, all it shows is my access manager, Explorer and all the various antivirus/antispyware programs I've run. Panda still detects Whenusave somewhere in the registry but I don't see it. I wish they would say where they detected it, like give me some kind of path to follow. Throw me a breadcrumb, Panda, for heaven's sake! I've picked apart my registry and the only things I see that I can (probably) safely remove are Google (which I don't use) and an old program called TaxWiz. As long as I back it up I should be OK. If I can remember how to back it up, hmmm. Isn't there some way of backing it up/cleaning it with Spybot? Off to take the dog for a drag here, supposed to be +14 today and +20 tomorrow and lots of sunshine! :D Talk to you later! Amanda
Spybot does have a registry checker. May want to run it and see if it finds anything. You have to switch the view to Advanced Mode. Click the Tools button, then the System Internals button, then the Check button. I think Spybot allows you to do a backup of the registry when you first install it, after that though, I haven't found an option in the program itself. There are different ways to do a registry backup. You can do a full backup or just backup a certain key. If you are using Win98/ME, you can use the scanregw command. If it's for Win2K/XP you can use the ntbackup command. You can also use regedit to backup or export certain keys. Doing a google search should bring back a bunch of 3rd party apps you can try too. Don't think I'd worry too much about this though, if anything it's most likely an orphaned entry of some sort.
Awww, poor orphaned files, I've put most of them out of their misery. Ran Spybot and deleted everything I could recognize, most of them missing shared dlls. I don't use MS Office so I should be ok, most of the ones I deleted were related to Nero anyways and I can always reinstall that if I need to. I'm going to use RegScrubXP to back up and degunk, then I'll further degunk with Spybot. Funny Spybot doesn't give you the option to back up your registry spontaneously, but I guess if you take the option up once at install (which I didn't) then you shouldn't have to do it again. I'll have to remember to do that the next time a newer version of Spybot comes out. Ah, well. It's time for everyone's favourite game….let's see what happens when I do this. Hopefully I'm as smart as I think I am. You'll know if you don't see me in this thread for a while! ;) Have a great day! Amanda
And I'm still here, all programs still work as far as I can tell. I got rid of everything that Spybot found plus deleted everything RegScrub found, each found ten errors (same ones?). Processing speed has now increased exponentially, which is nice. I'd forgot how fast this little P3 can be! I'm going to try running Panda and then we'll know for sure if it's a false positive….back in a jiffy…..
Well, it has to be a false positive. No other scan picks anything up. I've gone through all the scans I know of and only Panda shows Whenusave. Which is good, I guess. If anything this whole experience is a lesson in not panicking/jumping to conclusions/recklessly formatting your hard drive. Don't panic, people! Things aren't always as they appear. Always get a professional's (in my case 'KotaGuy's) second opinion. Speaking of which, thanks 'Kota for helping me out with this! It was giving me grey hair, and due to the recent price of fuel I can't afford to drive to the store to get hair dye. You've saved me from looking, uh, more distinguished than I actually am. Thank you! Take care and have a wonderful (albeit short) Canadian summer! Thanks again! Amanda
One other thing you might want to try is MWAV.

Great little scanning utility. Free version doesnt clean anything, but will give you a list of anything left behind that you should be able to clean manually.

Its found some things on my system the others didnt.
Well, well, well. Guess I spoke too soon! I did do the MicroWorld scan, Siggyx and I had had some trouble a while back getting my mule to run that scan past a certain point. The same thing happened again, would only go to a certain point and then stop. So I forgot about it for a while, but while I was eating dinner I thought "I wonder if I just got MW to scan the registry?". Needless to say, dinner got put on hold. Some people are addicted to scrapbooking or needlework, I'm hooked on debugging computers. So I ran MW and it came up with this: File System Found infected by "VB and VBA Program Settings Spyware/Adware" Virus. Of course, it can't be cleaned on the free version like you said. Traces of the LovGate virus were also found but were cleaned. So, where do I find this little buggie in the registry? MW always stopped in the same place HKLM_Current\Control Set\Services. Guess I'll start there…. Glad you reminded me about that one, Kota! Thanks! Amanda
After MWAV has scanned, you should be able to view a log of what it has scanned. Look for the infected entries, note what/where they are, and squash 'em! :P
Well, I scanned with MW doing each portion seperately and it found three buggies which I happily squished. One of them was KILLAPPS.EXE which had been on there for quite a while and had gone undetected. Good thing it didn't do any damage! The only section I couldn't run with MW is the Services portion of the scan. It hangs at 82 files, the little wheel keeps running but it doesn't go anywhere. I've left it for an hour and at 82 it remains. It always hangs in the same spot: hkey_local_machine\system\current control set\services\VxD I've discovered that this is a key related to Sympatico's Access Manager, the subfolder is JAVASUP.VXD. There are no errors in it, so I have no idea why MW has decided to loiter here. I don't think I can delete it without affecting my ethernet connection, so I'm going to leave it be. I am, however, going to get rid of other strange entries in the registry. America Online, Google and PC Rescue to name a few. I suspect these are from when my Dad had this unit as his pack mule, though I don't think he ever did any real work with it. Unless you call trolling the web for animations of Leprechauns doing the Macarena work! I have had some strange browsing activity today, while I was doing the CA scan the page suddenly redirected to Microsoft and McAfee shut down. I might actually look into the log that the MW scan generated and see if I can run the individual files through Kaspersky from where it's hanging. I might be uncovering some embedded junk, who knows….I might find Jimmy Hoffa in there somewheres. Even better, I might find the pot of gold the Dancing Leprechauns left behind! Take care! Amanda

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI