How to uninstall and remove Segurazo virus and/or SAntivirus virus.
Solved/Closed
Coco
-
Malekal_morte- -
Malekal_morte- -
Hi, I recently installed a software that gave me the Sergurazo antivirus. It's not very useful since I already have one, so I've decided to uninstall it, but it's not present in my control panel. However, in the local disk > programs (x86), there is still a folder < Sergurazo > that cannot be deleted < You need permission from DESKTOP-46FSK54/Coco to modify this folder. (Coco is the name of my PC) Sergurazo also appears in the task manager under 2 names: Sergurazo Engine and Sergurazo Service, and I can't uninstall them either, just end the task, which is useless. It's also present in my registry editor, where when I try to delete it, it says: Unable to delete Segurazo: error deleting the key.
I have tried numerous methods but to no avail. Thank you for your help.
I have tried numerous methods but to no avail. Thank you for your help.
46 answers
- 1
- 2
- 3
Next
-
Hello,
First:
- If Segurazo has returned to the installed programs, uninstall it via program uninstallation, it will ask you to restart your PC, you restart, upon restarting a Segurazo window will appear, you accept and check the two boxes (to the left of the Segurazo window) and it will finish uninstalling.
- If Segurazo is still not present in the installed programs, go to the Segurazo folder (located in C:\Program Files (x86) or C:\Programs), you should find a file Uninstaller.exe or segurazouninstall.exe, right-click on it, choose Run as administrator, the uninstallation begins, Segurazo will ask you to restart your computer, once your computer has restarted a Segurazo window appears, check the two boxes on the left of the window and confirm, the uninstallation continues, normally Segurazo should no longer be there, CHECK AND TELL ME IF SEGURAZO IS REMOVED.
If it doesn't work:
Download FRST, once downloaded save it on the desktop, then open it you will have this:
Click on Analyze at the end of the analysis you will have two text files on the desktop FRST and Addition send these reports to https://pjjoint.malekal.com/ see this tutorial paragraph Send the analysis reports to pjjoint then provide the two links generated by Pjoint in your next message.
bazfile
Moderator/Contributor security.
click here -
Hi
try uninstalling it with "Revo Uninstaller"
the Sergurazo antivirus is a scam!!! -
Hi, here I am also infected with segurazo and chromium. I followed the standard procedure but with no results, so I followed the tutorial and here are the bazfile links if you can do anything.
https://pjjoint.malekal.com/files.php?id=20191027_y10g15s8u14w10
https://pjjoint.malekal.com/files.php?id=FRST_20191027_i10b915j8z6
Thanks-
Good evening,
You caught Segurazo while installing Nox Player, which is an Android emulator. The setup was "repacked" and contained Segurazo in addition to Nox Player. Be careful where you download your software, and also be cautious during the installation of free software. There are pre-checked boxes, and if you don't uncheck them, unwanted software like Segurazo will be installed along with the application you wish to install.
Uninstall the software Wondershare Helper Compact as it is adware.
Segurazo is no longer very active on your PC, but there are still some remnants. Start your PC in safe mode with networking. To boot into safe mode, just carefully read this page and do what is indicated in the paragraph Boot into Safe Mode from Windows. You can print the pages or take notes because from the paragraph Recovery Options, you will no longer be in Windows and will only return once in safe mode.
Once in safe mode, do the following:
Procedure to follow in the order indicated:
1- Open FRST
- Copy the entire script in the box below:Start::
CloseProcesses:
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare software CO., LIMITED -> Wondershare)
HKU\S-1-5-21-2495059071-2474607549-1102390807-1000\...\Run: [Chromium] => c:\users\jean\appdata\local\chromium\application\chrome.exe [4195328 2017-10-07] (The Chromium Authors) [Unsigned file]
Task: {908079B9-0DE9-44A3-B399-BAD43BD49754} - \Microsoft\Windows\UNP\RunCampaignManager -> No file
2019-10-27 17:00 - 2019-10-27 17:06 - 000000000 ____D C:\WINDOWS\system32\Tasks\{1AF47C8C-BEC5-AD91-3E49-6B90E7513F5D}
S2 SegurazoIC; C:\Program Files (x86)\Segurazo\SegurazoIC.exe -service [X]
S2 SegurazoSvc; C:\Program Files (x86)\Segurazo\SegurazoService.exe [X]
C:\Program Files (x86)\Segurazo
C:\Users\Jean\AppData\Local\chromium
EmptyTemp:
End::
2- Once the script is copied, return to FRST, click on Fix.
FRST will automatically take the script from the clipboard and execute it.
Let the fix run, and once completed, restart your computer.
Then, once your computer has restarted:
4- You will have a Fixlog file on your desktop, send it via https://pjjoint.malekal.com/ and then put the link generated by Pjoint in your next message.
5- CHECK AND TELL ME IF YOUR PROBLEM IS STILL PRESENT.- Thank you!
After checking, Segurazo and Chromium have indeed disappeared.
I have uninstalled Wondershare Helper Compact.
That'll teach me; I'll be more careful next time. Here is the fixlog file, thanks again.
https://pjjoint.malekal.com/files.php?id=20191027_q14w12v9s6o9
-
-
-
Hello gentlemen.
I also have a problem with this malware/virus.
I started by uninstalling it (along with Chromium) using Iobit Uninstaller, but every day Avira and Malwarebytes still find traces of it...
I have launched the FRST procedure and here are the documents:
FRST: https://pjjoint.malekal.com/files.php?id=FRST_20191121_n14x11q13h14r9
Addition: https://pjjoint.malekal.com/files.php?id=20191121_j12o8o8o11i11
Thank you in advance.-
Hello,
Attention this script is for IV_Cuatro_IV many requests do not get it wrong.
Procedure to be followed in the order indicated:
Segurazo is no longer active on your PC but there are still traces, Chromium is still active.
1- Open FRST
- Copy the entire script that is in the box below:Start::
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-1206733066-2615911468-1976337299-1001\...\Run: [] => [X]
HKU\S-1-5-21-1206733066-2615911468-1976337299-1001\...\Run: [GalaxyClient] => [X]
HKU\S-1-5-21-1206733066-2615911468-1976337299-1001\...\Run: [Chromium] => "c:\users\lehel\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
C:\users\lehel\appdata\local\chromium
HKU\S-1-5-21-1206733066-2615911468-1976337299-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11142019100228960\...\Run: [] => [X]
HKU\S-1-5-21-1206733066-2615911468-1976337299-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11142019100228960\...\Run: [GalaxyClient] => [X]
HKU\S-1-5-18\...\Run: [] => [X]
HKU\S-1-5-21-1206733066-2615911468-1976337299-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11142019100228960\...\Run: [Chromium] => "c:\users\lehel\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
S2 SegurazoIC; C:\Program Files (x86)\Segurazo\SegurazoIC.exe -service [X]
U2 SegurazoSvc; C:\Program Files (x86)\Segurazo\SegurazoService.exe [X]
R1 SEGURAZOKD; \??\C:\Program Files (x86)\Segurazo\SegurazoKD.sys [X]
C:\Users\Kael\AppData\Roaming\segurazoclient
C:\Program Files (x86)\Segurazo
C:\ProgramData\Segurazo
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Segurazo
EmptyTemp:
End::
2- Once the script is copied, return to FRST and click on Fix.
FRST will automatically take the script from the clipboard and execute it.
Let the fix complete and once it is done, restart your computer.
Then once your computer has restarted:
4- You will have a Fixlog file on your desktop, send it via https://pjjoint.malekal.com/ and then put the link generated by Pjoint in your next message.
5- Reset your internet browsers https://forums.commentcamarche.net/forum/affich-37585758-reinitialiser-son-navigateur
6- CHECK AND TELL ME IF YOUR PROBLEM IS STILL PRESENT. -
Fixlog :
https://pjjoint.malekal.com/files.php?id=20191121_u12b8y10r6h6
so far, everything is impeccable! -
-
-
Good evening, I also have the same problem with Segurazo and Chromium it seems.
Could you help me remove these harmful software that are using a lot of RAM.
Here are the two links I got from my analysis:
https://pjjoint.malekal.com/files.php?id=FRST_20191128_b11o7p116x8
and
https://pjjoint.malekal.com/files.php?id=20191128_c13f13l7j12j15
Thank you and have a good day ^^-
Hello,
You caught Segurazo while installing the Android emulator Nox APP Player.
Procedure to follow in the order indicated:
WARNING to ensure disinfection works, you need to start your PC in safe mode with networking support.
To start in safe mode just read carefully this page and do as indicated in the Start in safe mode from Windows paragraph.
You can print the pages or take notes because from the Recovery options paragraph you will no longer be in Windows and will only return once in safe mode.
1- Open FRST
2- Copy the entire script that is in the box below:Start::
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-1329852130-1186937447-350906376-1001\...\Run: [Chromium] => "c:\users\antoc\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
HKU\S-1-5-21-1329852130-1186937447-350906376-1001\...\Run: [SegurazoRun] => C:\Program Files (x86)\Segurazo\SegurazoUninstaller.exe [1296080 2019-11-07] (Digital Communications Inc -> Digital Communications Inc)
R2 SegurazoIC; C:\Program Files (x86)\Segurazo\SegurazoIC.exe [4561616 2019-11-07] (Digital Communications Inc -> Digital Communications Inc)
R2 SegurazoSvc; C:\Program Files (x86)\Segurazo\SegurazoService.exe [185040 2019-11-07] (Digital Communications Inc -> Digital Communications Inc)
R1 SEGURAZOKD; C:\Program Files (x86)\Segurazo\SegurazoKD.sys [84472 2019-11-07] (Digital Communications Inc. -> Digital Communications Inc)
2019-11-18 12:34 - 2019-11-18 15:18 - 000000000 ____D C:\Program Files (x86)\Chromium
2019-11-18 12:33 - 2019-11-28 10:42 - 000000000 ____D C:\Program Files (x86)\Segurazo
2019-11-18 12:33 - 2019-11-18 12:35 - 000000000 ____D C:\Users\antoc\AppData\Local\{FFFAC9A6-DB52-A51E-B6CA-80F692A27C6E}
2019-11-18 12:33 - 2019-11-18 12:35 - 000000000 ____D C:\ProgramData\mzdzq
2019-11-18 12:33 - 2019-11-18 12:33 - 000000000 ____D C:\Users\antoc\AppData\Roaming\segurazoclient
2019-11-18 12:33 - 2019-11-18 12:33 - 000000000 ____D C:\ProgramData\Segurazo
2019-11-18 12:33 - 2019-11-18 12:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Segurazo
EmptyTemp:
End::
3- Once the script is copied, return to FRST and click on Fix.
FRST will automatically take the script from the clipboard and execute it.
Let the correction finish, and once it is done, restart your computer.
Then once your computer has restarted:
4- You will have a Fixlog file on your desktop, send it via https://pjjoint.malekal.com/ and put the link generated by Pjoint in your next message.
5- Reset your internet browsers https://forums.commentcamarche.net/forum/affich-37585758-reinitialiser-son-navigateur
6- CHECK AND LET ME KNOW IF YOUR PROBLEM IS STILL PRESENT. -
-
-
Thank you very much for your help, indeed I don't always pay attention to it, which is a mistake...
The link to the fix: https://pjjoint.malekal.com/files.php?id=20200204_u13r14b9s6o5
It looks clean to me -
Hello,
I struggled a bit to uninstall this stubborn malware on Windows 10.
The version I fell victim to didn’t allow for a standard uninstallation (file/process/service locking).
Rather than installing third-party software that we know nothing about, it’s better to use Windows Safe Mode.
To start in Safe Mode on Windows 10:
Click on Start / Power and then hold down Shift while clicking on Restart.
Upon reboot, a special menu (bluish, if I remember correctly) will appear. Navigate through the options available (I don’t recall the details, but it’s intuitive) until you select Safe Mode from a list. There are surely videos or tutorials on this if you're a bit lost.
Then you can uninstall the software normally (right-click on Start / Apps and Features / Segurazo -> Uninstall). It will uninstall cleanly (removal of files, registry entries…).
After rebooting your PC in normal mode, you will see that it is no longer present in the processes (Shift + Ctrl + Esc to display the running processes).
The whole process takes 2 minutes. -
Hello,
I tried your method but when I restart the computer, no window opens and segurazo is still there. Do you know what I can do?
Thank you again.-
https://forums.commentcamarche.net/forum/affich-36167920-comment-desinstaller-et-supprimer-virus-segurazo-et-ou-virus-santivirus#2
I remind you:
Download FRST once downloaded save it on the desktop then open it, you will have this:
Click on Scan at the end of the scan you will have two text files on the desktop FRST and Addition send these reports to https://pjjoint.malekal.com/ see this tutorial paragraph Send analysis reports to pjjoint then give the two links generated by Pjoint in your next message. -
You say you're not good at computers, but you still managed to brilliantly complete the first step. ;)
Let's continue, read carefully what follows before starting:
Start your PC in safe mode with network support, you might ask me what that is? Well, it's very simple, just read this page and do what is indicated in the paragraph Booting in Safe Mode from Windows. You can print the pages or take notes because from the paragraph Recovery Options, you will no longer be in Windows; you will only return once in safe mode.
Once in safe mode, do the following:
Procedure to be done in the order indicated:
1- Open FRST
- Copy the entire script that is in the box below:Start::
CloseProcesses:
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction
HKU\S-1-5-21-3544211576-441248113-2308167528-1001\...\Run: [Chromium] => c:\users\user\appdata\local\chromium\application\chrome.exe [4195328 2017-10-07] (The Chromium Authors) [Unsigned file]
c:\users\user\appdata\local\chromium
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction
R2 SegurazoIC; C:\Program Files (x86)\Segurazo\SegurazoIC.exe [4471400 2019-10-03] (Digital Communications Inc. -> Digital Communications Inc)
R2 SegurazoSvc; C:\Program Files (x86)\Segurazo\SegurazoService.exe [249960 2019-10-03] (Digital Communications Inc. -> Digital Communications Inc)
R1 SEGURAZOKD; C:\Program Files (x86)\Segurazo\SegurazoKD.sys [84256 2019-10-02] (Digital Communications Inc. -> Digital Communications Inc)
C:\Program Files (x86)\Segurazo
2019-10-14 12:15 - 2019-10-14 12:20 - 000000000 ____D C:\Users\User\AppData\Roaming\segurazoclient
2019-10-14 12:11 - 2019-10-15 18:25 - 000000000 ____D C:\Program Files\WinZip Driver Updater
2019-10-14 12:10 - 2019-10-14 12:29 - 000000000 ____D C:\Program Files (x86)\Hotspot Shield
2019-10-14 12:08 - 2019-10-14 21:25 - 000000000 ____D C:\Users\User\AppData\Local\chromium
2019-10-14 12:06 - 2019-10-14 21:28 - 000000000 ____D C:\Program Files (x86)\Chromium
2019-10-14 12:06 - 2019-10-14 12:29 - 000000000 ____D C:\ProgramData\Hotspot Shield
2019-10-14 12:06 - 2019-10-14 12:06 - 000000000 ____D C:\ProgramData\{56C46AF8-7EEC-1280-26B4-3AA8CE5CE270}
2019-10-14 12:05 - 2019-10-14 12:17 - 000000000 ____D C:\Users\User\AppData\Local\{50E466B8-744C-0A00-19D4-2FE83DBCD370}
2019-10-14 12:05 - 2019-10-14 12:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Segurazo
2019-10-14 12:04 - 2019-10-16 15:18 - 000000000 ____D C:\Program Files (x86)\Segurazo
2019-10-14 12:04 - 2019-10-14 12:05 - 000000000 ____D C:\ProgramData\Segurazo
S2 hshld; "C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe" [X]
EmptyTemp:
End::
2- Once the script is copied, return to FRST and click on Fix.
FRST will automatically take the script from the clipboard and execute it.
Let the correction take place and once it's finished, restart your computer.
Then, once your computer has restarted:
4- You will have a Fixlog file on your desktop, send it via https://pjjoint.malekal.com/ and put the link generated by Pjoint in your next message.
5- Reset your web browsers https://forums.commentcamarche.net/forum/affich-37585758-reinitialiser-son-navigateur
6- CHECK AND TELL ME IF YOUR PROBLEM IS STILL PRESENT. -
-
-
-
-
Is it this way? I'm really not good with computers but thank you very much for your feedback!!! -
-
Hello, I didn't understand everything, but I have the same issue with segurazo
here are my links after running the frst software
https://pjjoint.malekal.com/files.php?id=FRST_20191018_r13q5m7g11t8
https://pjjoint.malekal.com/files.php?id=20191018_v14h10p7o10w7
If someone could help me, I would be grateful.
Respectfully :)-
Segurazo is no longer active on your PC.
Procedure to follow in the order indicated:
1- Open FRST
- Copy the entire script that is in the box below:Start::
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-750121026-360057664-4069803116-1001\...\Run: [Chromium] => "c:\users\utilisateur\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction
2019-10-15 21:50 - 2019-10-15 22:13 - 000000000 ____D C:\Users\Utilisateur\AppData\Local\chromium
2019-10-15 21:48 - 2019-10-18 21:31 - 000000000 ____D C:\Program Files (x86)\Segurazo
2019-10-15 21:48 - 2019-10-15 22:44 - 000000000 ____D C:\Program Files (x86)\Chromium
2019-10-15 21:48 - 2019-10-15 21:51 - 000000000 ____D C:\Users\Utilisateur\AppData\Local\{EAA6DCFA-CE0E-B042-A396-95AA87FE6932}
2019-10-15 21:48 - 2019-10-15 21:48 - 000000000 ____D C:\ProgramData\Segurazo
EmptyTemp:
End::
2- Once the script is copied, go back to FRST and click on Fix.
FRST will automatically take the script from the clipboard and execute it.
Let the fix complete and once it is done, restart your computer.
Then once your computer has restarted:
4- You will have a Fixlog file on your desktop, send it via https://pjjoint.malekal.com/ and put the link generated by Pjoint in your next message.
5- Reset your internet browsers https://forums.commentcamarche.net/forum/affich-37585758-reinitialiser-son-navigateur
6- CHECK AND TELL ME IF YOUR PROBLEM STILL EXISTS. -
-
-
-
-
Hello,
The FRST report is not complete, you are too impatient, you did not wait for it to finish, you need to wait for the message saying that the FRST analysis is complete to appear on the screen, I will try to work with what I have.
FIRST uninstall Wondershare Helper Compact it is an adware.
THEN:
Procedure to be done in the order indicated:
Start your PC in safe mode with networking.
To boot in safe mode just carefully read this page and do as indicated in the paragraph Boot in safe mode from Windows.
You can print the pages or take notes because from the paragraph Recovery options you will no longer be in Windows, you will only return to it once in safe mode.
1- Open FRST
- Copy the entire script that is in the box below:Start::
CloseProcesses:
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133728 2017-09-12] (Wondershare Technology Co.,Ltd -> Wondershare)
HKLM-x32\...\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction
HKU\S-1-5-21-3446404936-4264823063-2574871056-1001\...\Run: [] => [X]
HKU\S-1-5-21-3446404936-4264823063-2574871056-1001\...\Run: [Chromium] => "c:\users\megaport\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
c:\users\megaport\appdata\local\chromium
Task: {6F8B78F0-15C2-49C3-886B-614B98DC85E8} - System32\Tasks\Nipepegak\{03F94F09-D1DE-A550-78B1-60DA43B799DB} => C:\Users\Megaport\AppData\Roaming\LUREHE~1\NIPEPE~1.EXE
C:\Users\Megaport\AppData\Roaming\LUREHE~1
R2 SegurazoIC; C:\Program Files (x86)\Segurazo\SegurazoIC.exe [4471400 2019-10-29] (Digital Communications Inc. -> Digital Communications Inc)
R2 SegurazoSvc; C:\Program Files (x86)\Segurazo\SegurazoService.exe [248936 2019-08-28] (Digital Communications Inc. -> Digital Communications Inc)
R1 SEGURAZOKD; C:\Program Files (x86)\Segurazo\SegurazoKD.sys [84768 2019-09-23] (Digital Communications Inc. -> Digital Communications Inc)
C:\Program Files (x86)\Segurazo
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Segurazo
C:\Users\User\AppData\Roaming\segurazoclient
EmptyTemp:
End::
2- Once the script is copied, return to FRST click on Fix.
FRST will automatically take the script from the clipboard and execute it.
Let the fix complete and once it is done, restart your computer.
Then once your computer has restarted:
4- You will have a Fixlog file on your desktop, send it via https://pjjoint.malekal.com/ then put the link generated by Pjoint in your next message.
5- CHECK AND LET ME KNOW IF YOUR PROBLEM IS STILL PRESENT.
6- DO ANOTHER ANALYSIS WITH FRST AND GIVE ME THE LINKS OF THE TWO REPORTS BUT COMPLETE THIS TIME.
. -
-
Segurazo and the other infections have been removed, can you confirm that for me?
Just a leftover of Segurazo that is not important, to remove it here is the script to run as before, but it's unnecessary to start Windows in safe mode; normal mode will be sufficient since Segurazo is no longer active on your PC:Start::
CloseProcesses:
C:\Users\Megaport\AppData\Roaming\segurazoclient
EmptyTemp:
End:: -
-
-
-
https://pjjoint.malekal.com/files.php?id=20191102_y7g15m7b14h6
https://pjjoint.malekal.com/files.php?id=FRST_20191102_r5r6y13w9y13
hello here is the same problem I have my two links and I don't understand where I should send them-
Hello,
To do in the order indicated.
First uninstall the software Avast Cleanup Premium it does nothing but slow down your PC https://www.malekal.com/avast-cleanup-premium/#Avast_CleanUp_Premium_est-il_vraiment_utile
Also uninstall Booking.
To uninstall these two programs, use RevoUninstaller.
Then:
Start your PC in safe mode with networking.
For starting in safe mode just carefully read this page and do what is indicated in the paragraph Starting in safe mode from Windows.
You can print the pages or take notes because from the paragraph The recovery options you will no longer be in Windows and you will only return once in safe mode.
1- Open FRST
- Copy the entire script that is in the box that follows:Start::
CloseProcesses:
HKU\S-1-5-21-3773553060-2300421546-2427899487-1001\...\Run: [Chromium] => c:\users\shone\appdata\local\chromium\application\chrome.exe [4195328 2017-10-07] (The Chromium Authors) [Unsigned file]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avast Cleanup Premium.lnk [2019-11-02]
ShortcutTarget: Avast Cleanup Premium.lnk -> C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe (AVAST Software s.r.o. -> AVAST Software)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction
Task: {45F9AC70-7B88-42D5-A212-7EF36D8593E0} - System32\Tasks\Avast Cleanup Update => C:\Program Files (x86)\AVAST Software\Avast Cleanup\TUNEUpdate.exe [1659000 2019-11-02] (AVAST Software s.r.o. -> AVAST Software)
Task: {477789C2-D0AE-49C2-AC31-180B603175CF} - \Microsoft\Windows\UNP\RunCampaignManager -> No file
C:\Users\shone\AppData\Roaming\segurazoclient
C:\Users\shone\AppData\Local\chromium
2019-10-24 19:34 - 2019-11-02 17:17 - 000000000 ____D C:\ProgramData\{5F6B6357-7743-1B2F-2F1B-3307C7F3EBDF}
C:\Program Files (x86)\Chromium
2019-10-24 19:34 - 2019-10-24 19:36 - 000000000 ____D C:\Users\shone\AppData\Local\{594B6F17-7DE3-03AF-107B-26473413DADF}
C:\Program Files (x86)\Segurazo
C:\ProgramData\Segurazo
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Segurazo
EmptyTemp:
End::
2- Once the script is copied, return to FRST and click on Fix.
FRST will automatically take the script from the clipboard and execute it.
Let the fix run and once it's done, restart your computer.
Then, once your computer has restarted:
4- You will have a Fixlog file on your desktop, send it via https://pjjoint.malekal.com/ then put the link generated by Pjoint in your next message.
5- Reset your internet browsers https://forums.commentcamarche.net/forum/affich-37585758-reinitialiser-son-navigateur
6- VERIFY AND LET ME KNOW IF YOUR PROBLEM IS STILL PRESENT. -
-
-
-
-
-
https://pjjoint.malekal.com/files.php?id=20191103_n15r12i10o7k10
there, I did it -
Thank you very much, Segurazo has disappeared. I reset Chrome, should I do the same with Explorer even though I don't use it?
-
Hello, I am currently desperate, this segurazo virus is a real nightmare, impossible to remove! So I'm going to try your procedure with FRST, here are the links I obtained:
https://pjjoint.malekal.com/files.php?id=20191107_t12f6h7u15b13
https://pjjoint.malekal.com/files.php?id=FRST_20191107_8l11c11q11b13
If you could help me, I would be very grateful. Thank you! :)-
Segurazo is still present on your PC but not really active anymore, you may have also been infected by Reimage Repair, there are still some remnants, and you also have Chromium that came along with Segurazo.
Out of caution, since with Segurazo it's best to be wary, Boot your PC in safe mode with network support.
To boot in safe mode, just carefully read this page and do what is indicated in the paragraph Starting in Safe Mode from Windows.
You can print the pages or take notes because starting from the paragraph Recovery Options you will no longer be in Windows; you will return only once in Safe Mode.
Procedure to follow in the indicated order:
1- Open FRST
- Copy the entire script that is in the box below:Start::
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-1646369961-3103968007-833443096-1001\...\Run: [Chromium] => "c:\users\hugo martin\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
C:\users\hugo martin\appdata\local\chromium
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction
S2 SegurazoIC; C:\Program Files (x86)\Segurazo\SegurazoIC.exe -service [X]
S2 SegurazoSvc; C:\Program Files (x86)\Segurazo\SegurazoService.exe [X]
R1 SEGURAZOKD; \??\C:\Program Files (x86)\Segurazo\SegurazoKD.sys [X]
C:\Program Files (x86)\Segurazo
C:\ProgramData\Segurazo
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Segurazo
2019-11-02 13:58 - 2019-11-02 14:03 - 000000140 _____ C:\WINDOWS\Reimage.ini
2019-11-02 13:56 - 2019-11-02 13:56 - 000590136 _____ (Reimage) C:\Users\Hugo Martin\Downloads\ReimageRepair.exe
EmptyTemp:
End::
2- Once the script is copied, go back to FRST and click on Fix.
FRST will automatically take the script from the clipboard and execute it.
Let the fix run, and once it is finished, restart your computer.
Then once your computer has restarted:
4- You will have a Fixlog file on your desktop, send it via https://pjjoint.malekal.com/ then put the link generated by Pjoint in your next message.
5- CHECK AND LET ME KNOW IF YOUR PROBLEM IS STILL PRESENT. -
-
-
-
Hello,
same problem, I tried to uninstall it via the uninstaller but nothing works.
here are the two reports, I hope to be able to delete it!!
https://pjjoint.malekal.com/files.php?id=20191113_n9f14b11t11i13
https://pjjoint.malekal.com/files.php?id=FRST_20191113_j10v7h5b10t10
Thank you in advance
have a good evening -
Hello bazfile,
Here are the 2 links following the sending of the txt files on pjjoint…
https://pjjoint.malekal.com/files.php?id=FRST_20191121_o5p9l12p5r11
https://pjjoint.malekal.com/files.php?id=20191121_j11y10g12z13h8
You're the one who will delete SEGURAZO and CHROMIUM, right?
Thanks in advance,... I hope it works!-
Hello,
Warning this script is for Didier563 many requests do not be mistaken.
Uninstall Avast Cleanup Premium it is useless except for slowing down your PC see this page.
Procedure to be done in the order indicated:
WARNING for the disinfection to work you must start your PC in safe mode with networking.
For starting in safe mode just carefully read this page and do what is indicated in the paragraph Start in safe mode from Windows.
You can print the pages or take notes because from the paragraph The recovery options you will no longer be in Windows you will only return once in safe mode.
1- Open FRST
- Copy the entire script that is in the box below:Start::
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-4279214589-224401948-3185324137-1001\...\Run: [Chromium] => c:\users\didier\appdata\local\chromium\application\chrome.exe [828416 2017-01-21] (The Chromium Authors) [Unsigned file]
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe
GroupPolicy: Restriction ?
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction
Task: {B4612EA4-1717-4FD4-904B-CB8F4C73A260} - \Microsoft\Windows\UNP\RunCampaignManager -> No file
Task: C:\WINDOWS\Tasks\Yahoo! Powered losel.job => Wscript.exe C:\ProgramData\{FD8A38E9-77C8-B22F-F10E-2C6D6B4CA7A3}\doco.txt
R2 SegurazoIC; C:\Program Files (x86)\Segurazo\SegurazoIC.exe [4471400 2019-11-19] (Digital Communications Inc. -> Digital Communications Inc)
R2 SegurazoSvc; C:\Program Files (x86)\Segurazo\SegurazoService.exe [250472 2019-10-20] (Digital Communications Inc. -> Digital Communications Inc)
R1 SEGURAZOKD; C:\Program Files (x86)\Segurazo\SegurazoKD.sys [84768 2019-10-19] (Digital Communications Inc. -> Digital Communications Inc)
C:\Program Files (x86)\Chromium
C:\users\didier\appdata\local\chromium
2019-11-19 07:32 - 2019-11-19 07:32 - 000002982 _____ C:\Users\Didier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search Powered by Yahoo!.lnk
C:\Users\Didier\AppData\Local\{94C8A294-B060-CE2C-DDF8-EBC4F990175C}
C:\Users\Didier\AppData\Roaming\segurazoclient
C:\Program Files (x86)\Segurazo
C:\ProgramData\Segurazo
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Segurazo
EmptyTemp:
End::
2- Once the script is copied go back to FRST click on Fix.
FRST will automatically take the script from the clipboard and execute it.
Let the fix complete once it is finished restart your computer.
Then once your computer has restarted:
4- You will have a file Fixlog on your desktop send it via https://pjjoint.malekal.com/ then put the link generated by Pjoint in your next message.
5- Reset your internet browsers https://forums.commentcamarche.net/forum/affich-37585758-reinitialiser-son-navigateur
6- CHECK AND TELL ME IF YOUR PROBLEM IS STILL PRESENT.
. -
Hello,
I'm having a bit of trouble starting "safe mode from Windows".
Apparently, I have no other choice but to download the WINDOWS 10 REPAIR TOOL
Which I did, but I had to agree to download Advance System Repair Pro, which scanned my PC.
And I don't see any command regarding "start in safe mode with networking"
I'm a bit lost, sorry to ask you for help again.
Best regards. -
Here it is, I succeeded in safe mode! :D
1st Problem
- a screen mask indicating that I am not connected,
- click the troubleshooting button
- troubleshooting is impossible in safe mode…
2nd Problem
FRST = 4 folders (Bin - Hives - Logs - Quarantine) where should I copy the script above?
Thank you in advance for your patience, I think it's going to be tough... sorry... -
You didn't do what was indicated; you should have started in safe mode with networking to have internet access. You just need to read and do what is specified. If you can't manage that, forget it. I don't see why you downloaded Advance System Repair Pro, which is a scam; you should uninstall it. Just do what I told you.
-
-
Hello, I have the same issue with this adware from ***** after installing Nox (never again).
It is not listed in my programs, and AdwCleaner cannot remove it.
Can someone please help me? Here are my reports
https://pjjoint.malekal.com/files.php?id=FRST_20191123_x13g5x7b15j15
https://pjjoint.malekal.com/files.php?id=20191123_j14t9p15u11i11
Thank you so much!-
-
-
I only have my smartphone, please be patient, we are volunteers, we have a life outside of CCM, I am currently on the move, I will look into it tonight. At first glance, your PC is infected, but not just by Segurazo and Chromium. If you are really in a hurry, you can go to a repair shop, but it will be paid and on a Sunday, I doubt you will find one, so wait until tonight.
-
-
I'm on my PC, I hadn't seen that you had put two FRST reports, my smartphone doesn't have a very large screen, so I only looked at the latest FRST report, Segurazo is no longer present but there are still some things remaining.
Procedure to follow in the indicated order:
1- Open FRST
- Copy the entire script that is in the box below:Start::
CreateRestorePoint:
CloseProcesses:
HKLM\Software\...\AppCompatFlags\Custom\chrome.exe: [{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb] ->
HKLM\Software\...\AppCompatFlags\Custom\explorer.zza: [{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb] ->
HKLM\Software\...\AppCompatFlags\Custom\iexplore.exe: [{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb] ->
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => No file
Task: {8FB5F71D-DA3B-42C2-A790-9A9E7F1BCFCE} - \Microsoft\Windows\UNP\RunCampaignManager -> No file
Task: {EA23836D-D4D8-4BBB-9FE3-58CB04E7E576} - System32\Tasks\bvyvdvyxc => C:\Users\david\AppData\Local\bvyvdvyxc\bvyvdvyxc.exe
C:\Users\david\AppData\Local\bvyvdvyxc
C:\Users\david\AppData\Local\chromium
C:\Program Files (x86)\Chromium
C:\Users\Didier\AppData\Roaming\segurazoclient
C:\Program Files (x86)\Segurazo
C:\ProgramData\Segurazo
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Segurazo
EmptyTemp:
End::
2- Once the script is copied, go back to FRST and click on Fix.
FRST will automatically take the script from the clipboard and execute it.
Let the fix complete, once it's done restart your computer.
Then once your computer has restarted:
4- You will have a Fixlog file on your desktop, send it via https://pjjoint.malekal.com/ and then put the link generated by Pjoint in your next message.
5- Reset your web browsers https://forums.commentcamarche.net/forum/affich-37585758-reinitialiser-son-navigateur
6- CHECK AND LET ME KNOW IF YOUR PROBLEM IS STILL PRESENT.
-
-
Hello, I have the same problem with segurazo, could I get some help?
https://pjjoint.malekal.com/files.php?id=20191124_f6c1214k11v5https%3A%2F%2Fpjjoint.malekal.com%2Ffiles.php%3Fid%3D20191124_f6c1214k11v5-
I would like to insist because the software seems to still be active, and my PC has been very slow since the installation of Nox player; I have run a scan again, and if there is anything, I would be happy to remove it, and if there really is nothing, do I need to reformat my PC to factory settings?
https://pjjoint.malekal.com/files.php?id=20191124_p15m13l8v5h8
https://pjjoint.malekal.com/files.php?id=20191124_e5z13f11w5u10 -
-
-
You caught this infection by installing the Android emulator Nox.
Procedure to follow in the given order:
WARNING for the disinfection to work, you must start your PC in safe mode with network support.
To start in safe mode just carefully read this page and do what is indicated in the paragraph Start in safe mode from Windows.
You can print the pages or take notes because from the paragraph The recovery options you will no longer be in Windows and will only return once in safe mode.
1- Open FRST
2- Copy the entire script that is in the box below:Start::
CloseProcesses:
Task: {219DC7DE-505C-4994-98BE-E3E0232700C8} - System32\Tasks\ChromiumUpdateTaskMachineCore => C:\Program Files (x86)\Chromium\Update\ChromiumUpdate.exe [102400 2019-10-29] (Chromium.) [Unsigned file]
Task: {FCEE00A4-36C6-470A-89AA-4FE5F8CC4BA5} - System32\Tasks\ChromiumUpdateTaskMachineUA => C:\Program Files (x86)\Chromium\Update\ChromiumUpdate.exe [102400 2019-10-29] (Chromium.) [Unsigned file]
S2 chromium; C:\Program Files (x86)\Chromium\Update\ChromiumUpdate.exe [102400 2019-10-29] (Chromium.) [Unsigned file]
S3 chromiumm; C:\Program Files (x86)\Chromium\Update\ChromiumUpdate.exe [102400 2019-10-29] (Chromium.) [Unsigned file]
R1 SEGURAZOKD; C:\Program Files (x86)\Segurazo\SegurazoKD.sys [84768 2019-09-23] (Digital Communications Inc. -> Digital Communications Inc)
R2 SegurazoIC; C:\Program Files (x86)\Segurazo\SegurazoIC.exe [4471400 2019-10-29] (Digital Communications Inc. -> Digital Communications Inc)
R2 SegurazoSvc; C:\Program Files (x86)\Segurazo\SegurazoService.exe [248936 2019-11-20] (Digital Communications Inc. -> Digital Communications Inc)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction
C:\Users\jamin\AppData\Roaming\segurazoclient
C:\Users\jamin\AppData\Local\chromium
C:\Program Files (x86)\Segurazo
C:\Users\jamin\AppData\Local\{FF76C92A-DBDE-A592-B646-807A922E7CE2}
C:\WINDOWS\system32\Tasks\ChromiumUpdateTaskMachineUA
C:\ProgramData\Segurazo
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Segurazo
C:\ProgramData\{F956C56A-D17E-BD12-8926-953A61CE4DE2}
EmptyTemp:
End::
3- Once the script is copied, return to FRST and click on Fix.
FRST will automatically take the script from the clipboard and execute it.
Let the correction complete and once it is done, restart your computer.
Then once your computer has restarted:
4- You will have a Fixlog file on your desktop, send it via https://pjjoint.malekal.com/ then put the link generated by Pjoint in your next message.
5- CHECK AND LET ME KNOW IF YOUR PROBLEM IS STILL PRESENT. -
-
- 1
- 2
- 3
Next