Plattform:

Windows

 Risikobewertung (gesamt):
 reportedInfection:
 Beeinträchtigung der Systemleistung ::
 Trend Micro Lösungen:
Niedrig
Mittel
Hoch
Kritisch

  • Malware-Typ:
    Potentially Unwanted Application

  • Zerstrerisch?:
    Nein

  • Verschlsselt?:
     

  • In the wild::
    Ja

  Überblick

It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  Technische Details

Dateigröße: 22,882,888 bytes
Dateityp: EXE
Speicherresiden: Ja
Erste Muster erhalten am: 04 Februar 2020

Übertragungsdetails

It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

Fügt die folgenden Prozesse hinzu:

  • %System%\regsvr32.exe /s "%Program Files%\Segurazo\SegurazoShell86_v102025.dll"
  • %System%\regsvr32.exe /s "%Program Files%\Segurazo\SegurazoShell64_v102025.dll"
  • %Program Files%\Segurazo\SegurazoService.exe
  • %Program Files%\Segurazo\SegurazoIC.exe -service
  • %System%\svchost.exe -k WerSvcGroup
  • %System%\svchost.exe -k DcomLaunch
  • %System%\svchost.exe -k netsvcs
  • %Windows%\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
  • sc config winmgmt start=disabled
  • cmd /d /c net stop winmgmt /y
  • net stop winmgmt /y
  • %System%\net1 stop winmgmt /y

(Hinweis: %Program Files%ist der Standardordner 'Programme', normalerweise C:\Programme.. %Windows% ist der Windows Ordner, normalerweise C:\Windows oder C:\WINNT.)

Erstellt die folgenden Ordner:

  • %All Users Profile%\Microsoft\Windows
  • %All Users Profile%\Segurazo
  • %System Root%\Users
  • %All Users Profile%\Segurazo\b
  • %All Users Profile%\Segurazo\b\amd64
  • %All Users Profile%\Microsoft\Windows\Start Menu
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs
  • %All Users Profile%\Microsoft
  • %User Profile%\AppData
  • %Program Files%\Segurazo\x86
  • %All Users Profile%\Segurazo\b\x86
  • %All Users Profile%\Segurazo\b\x64
  • %Program Files%\Segurazo\x64
  • %Program Files%\Segurazo\amd64
  • %Program Files%\Segurazo
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Segurazo

(Hinweis: %System Root% ist der Stammordner, normalerweise C:\. Dort befindet sich auch das Betriebssystem.. %User Profile% ist der Ordner für Benutzerprofile des aktuellen Benutzers, normalerweise C:\Windows\Profile\{Benutzername} unter Windows 98 und ME, C:\WINNT\Profile\{Benutzername} unter Windows NT, C:\Dokumente und Einstellungen\{Benutzername} unter Windows 2000(32-bit), XP und Server 2003(32-bit) und C:\Users\{user name} unter Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) und 10(64-bit).. %Program Files%ist der Standardordner 'Programme', normalerweise C:\Programme.)

Autostart-Technik

Registriert sich als Systemdienst, damit sie bei jedem Systemstart automatisch ausgeführt wird, indem sie die folgenden Registrierungseinträge hinzufügt:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoSvc
ImagePath = "%Program Files%\Segurazo\SegurazoService.exe"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoIC
ImagePath = "%Program Files%\Segurazo\SegurazoIC.exe -service"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SEGURAZOKD
ImagePath = "\??\%Program Files%\Segurazo\SegurazoKD.sys"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SegurazoSvc
ImagePath = "%Program Files%\Segurazo\SegurazoService.exe"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SegurazoIC
ImagePath = "%Program Files%\Segurazo\SegurazoIC.exe -service"

Andere Systemänderungen

Löscht die folgenden Ordner:

  • %User Temp%\nsk9A2D.tmp

(Hinweis: %User Temp% ist der Ordner 'Temp' des aktuellen Benutzers, normalerweise C:\Dokumente und Einstellungen\{Benutzername}\Lokale Einstellungen\Temp unter Windows 2000(32-bit), XP und Server 2003(32-bit) und C:\Users\{Benutzername}\AppData\Local\Temp unter Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) und 10(64-bit).)

Fügt die folgenden Registrierungseinträge hinzu:

HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo
pixel = ""

HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo
campid = ""

HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo
channel = ""

HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo
iuid = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo
tg = ""

HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo
InstallerStart = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Segurazo
InstallDir = "%Program Files%\Segurazo"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Segurazo
IMode = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\Segurazo
EstimatedSize = "30697"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\Segurazo
DisplayName = "S e g u r a z o A n t i v i r u s"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\Segurazo
Publisher = "Digital Communications Inc"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\Segurazo
DisplayIcon = "%Program Files%\Segurazo\uninstaller.ico"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\Segurazo
UninstallString = "%Program Files%\Segurazo\SegurazoUninstaller.exe /mod=0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\Segurazo
DisplayVersion = "1.0.20.25"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
SegurazoAntivirus
InstallEnd = "1"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoSvc
Type = "16"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoSvc
Start = "2"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoSvc
ErrorControl = "1"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoSvc
DisplayName = "SegurazoSvc"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoSvc
WOW64 = "1"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoSvc
ObjectName = "LocalSystem"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoSvc
Description = "This service protect your pc from viruses and spyware."

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoSvc
FailureActions = "{random characters}"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoSvc\Security
Security = "{random characters}"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoIC
Type = "16"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoIC
Start = "2"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoIC
ErrorControl = "1"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoIC
DisplayName = "SegurazoIC"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoIC
WOW64 = "1"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoIC
ObjectName = "LocalSystem"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoIC
Description = "This service protect your pc from viruses and spyware."

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoIC
FailureActions = "{random characters}"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\SegurazoIC\Security
Security = "{random characters}"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\eventlog\Application
AutoBackupLogFiles = "0"

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
services\eventlog\Application\
SegurazoSvc
EventMessageFile = "%Windows%\Microsoft.NET\Framework64\v4.0.30319\EventLogMessages.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
fst = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
guisc = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "2"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "5"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "6"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "7"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "8"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "9"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "11"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "12"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "16"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "17"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "18"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "13"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "14"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "15"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "19"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "20"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "21"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "22"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "23"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "24"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "25"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "26"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "27"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "28"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "29"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "30"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "31"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "32"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "33"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "34"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "35"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "36"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "37"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "38"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "39"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "40"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "41"

HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
gui = "42"

HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo
ite = "1570370325"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}
(Default) = "SegurazoShellExtension.FileContextMenuExt Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}\
InprocServer32
(Default) = "%Program Files%\Segurazo\SegurazoShell86_v102025.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}\
InprocServer32
ThreadingModel = "Apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
*\shellex\ContextMenuHandlers\
SegurazoShellExtension.FileContextMenuExt
(Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
SystemFileAssociations\*\shellex\
ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
(Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
.lnk\ShellEx\ContextMenuHandlers\
SegurazoShellExtension.FileContextMenuExt
(Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
SystemFileAssociations\.lnk\shellex\
ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
(Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Directory\shellex\ContextMenuHandlers\
SegurazoShellExtension.FileContextMenuExt
(Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
SystemFileAssociations\Directory\shellex\
ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
(Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Folder\ShellEx\ContextMenuHandlers\
SegurazoShellExtension.FileContextMenuExt
(Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
SystemFileAssociations\Folder\shellex\
ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
(Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
lnkfile\shellex\ContextMenuHandlers\
SegurazoShellExtension.FileContextMenuExt
(Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
SystemFileAssociations\lnkfile\shellex\
ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
(Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}
(Default) = "SegurazoShellExtension.FileContextMenuExt Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}\InprocServer32
(Default) = "%Program Files%\Segurazo\SegurazoShell64_v102025.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}\InprocServer32
ThreadingModel = "Apartment"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SEGURAZOKD
DisplayName = "Segurazo Kernel Driver"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SEGURAZOKD
Start = "SERVICE_SYSTEM_START"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SegurazoSvc
DisplayName = "SegurazoSvc"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SegurazoSvc
Start = "SERVICE_AUTO_START"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SegurazoIC
DisplayName = "SegurazoIC"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SegurazoIC
Start = "SERVICE_AUTO_START"

Einschleusungsroutine

Schleust die folgenden Dateien ein:

  • %All Users Profile%\Segurazo\b\amd64\msdia140.dll
  • %Program Files%\Segurazo\x86\lz4_x86.dll
  • %All Users Profile%\Segurazo\b\SegurazoService.exe.config
  • %All Users Profile%\Segurazo\b\amd64\KernelTraceControl.dll
  • %Program Files%\Segurazo\SegurazoIC.config
  • %Program Files%\Segurazo\7a38ad565
  • %Program Files%\Segurazo\SegurazoUninstaller.exe.config
  • %Program Files%\Segurazo\SegurazoService.exe.config
  • %All Users Profile%\Segurazo\b\SegurazoUninstaller.exe
  • %Program Files%\Segurazo\SegurazoShell64_v102025.dll
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Segurazo\S e g u r a z o A n t i v i r u s.lnk
  • %All Users Profile%\Segurazo\b\x86\7z86.dll
  • %Program Files%\Segurazo\uninstaller.ico
  • %Program Files%\Segurazo\SegurazoIC.exe
  • %Program Files%\Segurazo\amd64\KernelTraceControl.dll
  • %All Users Profile%\Segurazo\b\SegurazoShell86_v102025.dll
  • %All Users Profile%\Segurazo\b\SegurazoShell64_v102025.dll
  • %All Users Profile%\Segurazo\b\SegurazoClient.exe.config
  • %Program Files%\Segurazo\x86\rsLggrServer_x86.dll
  • %Program Files%\Segurazo\SegurazoUninstaller.exe
  • %All Users Profile%\Segurazo\b\SegurazoUninstaller.exe.config
  • %All Users Profile%\Segurazo\b\x64\System.Data.SQLite.dll
  • %All Users Profile%\Segurazo\b\x64\lz4_x64.dll
  • %All Users Profile%\Segurazo\b\x64\ext_x64.dll
  • %Program Files%\Segurazo\x64\7z64.dll
  • %All Users Profile%\Segurazo\b\SegurazoEngine.dll
  • %All Users Profile%\Segurazo\b.dat
  • %All Users Profile%\Segurazo\b\x64\rsLggrServer_x64.dll
  • %Program Files%\Segurazo\rsEngine.dll
  • %Program Files%\Segurazo\x64\ext_x64.dll
  • %All Users Profile%\Segurazo\b\x86\KernelTraceControl.dll
  • %All Users Profile%\Segurazo\b\Microsoft.Win32.TaskScheduler.dll
  • %Program Files%\Segurazo\x86\System.Data.SQLite.dll
  • %All Users Profile%\Segurazo\b\rsEngineHelper.exe.config
  • %Program Files%\Segurazo\rsEngineHelper.exe.config
  • %Program Files%\Segurazo\SegurazoShell86_v102025.dll
  • %All Users Profile%\Segurazo\b\x86\rsEnginePM_x86.dll
  • %All Users Profile%\Segurazo\b\rsEngineSDK.dll
  • %Program Files%\Segurazo\x86\rsEngineFW_x86.dll
  • %All Users Profile%\Segurazo\b\x64\7z64.dll
  • %Program Files%\Segurazo\SegurazoTools.dll
  • %All Users Profile%\Segurazo\b\x64\rsEngineFW_x64.dll
  • %Program Files%\Segurazo\x86\msdia140.dll
  • %All Users Profile%\Segurazo\b\x86\rsLggrServer_x86.dll
  • %All Users Profile%\Segurazo\b\rsEngine.dll
  • %Program Files%\Segurazo\SegurazoClient.exe.config
  • %All Users Profile%\Segurazo\b\SegurazoTools.dll
  • %Program Files%\Segurazo\x86\ext_x86.dll
  • %All Users Profile%\Segurazo\b\rsEngineHelper.exe
  • %All Users Profile%\Segurazo\b\Microsoft.Diagnostics.Tracing.TraceEvent.dll
  • %All Users Profile%\Segurazo\b\x86\lz4_x86.dll
  • %All Users Profile%\Segurazo\b\SegurazoClient.exe
  • %Program Files%\Segurazo\x86\KernelTraceControl.dll
  • %All Users Profile%\Segurazo\b\x86\System.Data.SQLite.dll
  • %Program Files%\Segurazo\x64\rsEngineFW_x64.dll
  • %Program Files%\Segurazo\SegurazoClient.exe
  • %Program Files%\Segurazo\x64\System.Data.SQLite.dll
  • %All Users Profile%\Segurazo\b\SegurazoService.exe
  • %All Users Profile%\Segurazo\b\System.Threading.dll
  • %Program Files%\Segurazo\x64\lz4_x64.dll
  • %Program Files%\Segurazo\amd64\msdia140.dll
  • %Program Files%\Segurazo\rsEngineSDK.dll
  • %Program Files%\Segurazo\rsEngineHelper.exe
  • %Program Files%\Segurazo\Microsoft.Diagnostics.Tracing.TraceEvent.dll
  • %Program Files%\Segurazo\System.Threading.dll
  • %All Users Profile%\Segurazo\b\x86\msdia140.dll
  • %All Users Profile%\Segurazo\b\x86\rsEngineFW_x86.dll
  • %Program Files%\Segurazo\Microsoft.Win32.TaskScheduler.dll
  • %All Users Profile%\Segurazo\b\7a38ad565
  • %Program Files%\Segurazo\x86\rsEnginePM_x86.dll
  • %Program Files%\Segurazo\x64\rsEnginePM_x64.dll
  • %All Users Profile%\Segurazo\b\x64\rsEnginePM_x64.dll
  • %Program Files%\Segurazo\x64\rsLggrServer_x64.dll
  • %Program Files%\Segurazo\SegurazoService.exe
  • %Program Files%\Segurazo\x86\7z86.dll
  • %All Users Profile%\Segurazo\b\x86\ext_x86.dll
  • %Program Files%\Segurazo\SegurazoKD.sys
  • %Program Files%\Segurazo\SegurazoEngine.dll

(Hinweis: %Program Files%ist der Standardordner 'Programme', normalerweise C:\Programme.)

Andere Details

It connects to the following possibly malicious URL:

  • http://secure.{BLOCKED}zo.com
  • http://ssl.{BLOCKED}zo.com

  Lösungen

Mindestversion der Scan Engine: 9.850

Step 1

Für Windows ME und XP Benutzer: Stellen Sie vor einer Suche sicher, dass die Systemwiederherstellung deaktiviert ist, damit der gesamte Computer durchsucht werden kann.

Step 2

Dateien erkennen und deaktivieren, die als PUA.Win32.Segurazo.K entdeckt wurden

[ learnMore ]
  1. Für Windows 98 und ME Benutzer: Der Windows Task-Manager zeigt möglicherweise nicht alle aktiven Prozesse an. Verwenden Sie in diesem Fall einen Prozess-Viewer eines Drittanbieters, vorzugsweise Process Explorer, um die Malware-/Grayware-/Spyware-Datei zu beenden. Dieses Tool können Sie hier.
  2. herunterladen.
  3. Wenn die entdeckte Datei im Windows Task-Manager oder Process Explorer angezeigt wird, aber nicht gelöscht werden kann, starten Sie Ihren Computer im abgesicherten Modus neu. Klicken Sie auf diesen Link, um alle erforderlichen Schritte anzuzeigen.
  4. Wenn die entdeckte Datei nicht im Windows Task-Manager oder im Process Explorer angezeigt wird, fahren Sie mit den nächsten Schritten fort.

Step 3

Diesen Registrierungswert löschen

[ learnMore ]

Wichtig: Eine nicht ordnungsgemäße Bearbeitung der Windows Registrierung kann zu einer dauerhaften Fehlfunktion des Systems führen. Führen Sie diesen Schritt nur durch, wenn Sie mit der Vorgehensweise vertraut sind oder wenn Sie Ihren Systemadministrator um Unterstützung bitten können. Lesen Sie ansonsten zuerst diesen Microsoft Artikel, bevor Sie die Registrierung Ihres Computers ändern.

  • In HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo
    • pixel = ""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo
    • campid = ""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo
    • channel = ""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo
    • iuid = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo
    • tg = ""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo
    • InstallerStart = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Segurazo
    • InstallDir = "%Program Files%\Segurazo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Segurazo
    • IMode = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Segurazo
    • EstimatedSize = "30697"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Segurazo
    • DisplayName = "S e g u r a z o A n t i v i r u s"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Segurazo
    • Publisher = "Digital Communications Inc"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Segurazo
    • DisplayIcon = "%Program Files%\Segurazo\uninstaller.ico"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Segurazo
    • UninstallString = "%Program Files%\Segurazo\SegurazoUninstaller.exe /mod=0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Segurazo
    • DisplayVersion = "1.0.20.25"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\SegurazoAntivirus
    • InstallEnd = "1"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoSvc
    • Type = "16"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoSvc
    • Start = "2"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoSvc
    • ErrorControl = "1"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoSvc
    • DisplayName = "SegurazoSvc"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoSvc
    • WOW64 = "1"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoSvc
    • ObjectName = "LocalSystem"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoSvc
    • Description = "This service protect your pc from viruses and spyware."
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoSvc
    • FailureActions = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoSvc\Security
    • Security = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoIC
    • Type = "16"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoIC
    • Start = "2"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoIC
    • ErrorControl = "1"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoIC
    • DisplayName = "SegurazoIC"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoIC
    • WOW64 = "1"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoIC
    • ObjectName = "LocalSystem"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoIC
    • Description = "This service protect your pc from viruses and spyware."
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoIC
    • FailureActions = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoIC\Security
    • Security = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application
    • AutoBackupLogFiles = "0"
  • In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\SegurazoSvc
    • EventMessageFile = "%Windows%\Microsoft.NET\Framework64\v4.0.30319\EventLogMessages.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • fst = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • guisc = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "2"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "5"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "6"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "7"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "8"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "9"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "11"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "12"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "16"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "17"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "18"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "13"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "14"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "15"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "19"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "20"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "21"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "22"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "23"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "24"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "25"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "26"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "27"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "28"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "29"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "30"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "31"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "32"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "33"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "34"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "35"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "36"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "37"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "38"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "39"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "40"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "41"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SegOption
    • gui = "42"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo
    • ite = "1570370325"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}
    • (Default) = "SegurazoShellExtension.FileContextMenuExt Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}\InprocServer32
    • (Default) = "%Program Files%\Segurazo\SegurazoShell86_v102025.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}\InprocServer32
    • ThreadingModel = "Apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
    • (Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\*\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
    • (Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.lnk\ShellEx\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
    • (Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.lnk\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
    • (Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
    • (Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\Directory\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
    • (Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
    • (Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\Folder\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
    • (Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
    • (Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\lnkfile\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt
    • (Default) = "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}
    • (Default) = "SegurazoShellExtension.FileContextMenuExt Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}\InprocServer32
    • (Default) = "%Program Files%\Segurazo\SegurazoShell64_v102025.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}\InprocServer32
    • ThreadingModel = "Apartment"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SEGURAZOKD
    • DisplayName = "Segurazo Kernel Driver"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SEGURAZOKD
    • Start = "SERVICE_SYSTEM_START"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SegurazoSvc
    • DisplayName = "SegurazoSvc"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SegurazoSvc
    • Start = "SERVICE_AUTO_START"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SegurazoIC
    • DisplayName = "SegurazoIC"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SegurazoIC
    • Start = "SERVICE_AUTO_START"

Step 4

Diese Dateien suchen und löschen

[ learnMore ]
Möglicherweise sind einige Komponentendateien verborgen. Aktivieren Sie unbedingt das Kontrollkästchen Versteckte Elemente durchsuchen unter "Weitere erweiterte Optionen", um alle verborgenen Dateien und Ordner in den Suchergebnissen zu berücksichtigen.
  • %All Users Profile%\Segurazo\b\amd64\msdia140.dll
  • %Program Files%\Segurazo\x86\lz4_x86.dll
  • %All Users Profile%\Segurazo\b\SegurazoService.exe.config
  • %All Users Profile%\Segurazo\b\amd64\KernelTraceControl.dll
  • %Program Files%\Segurazo\SegurazoIC.config
  • %Program Files%\Segurazo\7a38ad565
  • %Program Files%\Segurazo\SegurazoUninstaller.exe.config
  • %Program Files%\Segurazo\SegurazoService.exe.config
  • %All Users Profile%\Segurazo\b\SegurazoUninstaller.exe
  • %Program Files%\Segurazo\SegurazoShell64_v102025.dll
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Segurazo\S e g u r a z o A n t i v i r u s.lnk
  • %All Users Profile%\Segurazo\b\x86\7z86.dll
  • %Program Files%\Segurazo\uninstaller.ico
  • %Program Files%\Segurazo\SegurazoIC.exe
  • %Program Files%\Segurazo\amd64\KernelTraceControl.dll
  • %All Users Profile%\Segurazo\b\SegurazoShell86_v102025.dll
  • %All Users Profile%\Segurazo\b\SegurazoShell64_v102025.dll
  • %All Users Profile%\Segurazo\b\SegurazoClient.exe.config
  • %Program Files%\Segurazo\x86\rsLggrServer_x86.dll
  • %Program Files%\Segurazo\SegurazoUninstaller.exe
  • %All Users Profile%\Segurazo\b\SegurazoUninstaller.exe.config
  • %All Users Profile%\Segurazo\b\x64\System.Data.SQLite.dll
  • %All Users Profile%\Segurazo\b\x64\lz4_x64.dll
  • %All Users Profile%\Segurazo\b\x64\ext_x64.dll
  • %Program Files%\Segurazo\x64\7z64.dll
  • %All Users Profile%\Segurazo\b\SegurazoEngine.dll
  • %All Users Profile%\Segurazo\b.dat
  • %All Users Profile%\Segurazo\b\x64\rsLggrServer_x64.dll
  • %Program Files%\Segurazo\rsEngine.dll
  • %Program Files%\Segurazo\x64\ext_x64.dll
  • %All Users Profile%\Segurazo\b\x86\KernelTraceControl.dll
  • %All Users Profile%\Segurazo\b\Microsoft.Win32.TaskScheduler.dll
  • %Program Files%\Segurazo\x86\System.Data.SQLite.dll
  • %All Users Profile%\Segurazo\b\rsEngineHelper.exe.config
  • %Program Files%\Segurazo\rsEngineHelper.exe.config
  • %Program Files%\Segurazo\SegurazoShell86_v102025.dll
  • %All Users Profile%\Segurazo\b\x86\rsEnginePM_x86.dll
  • %All Users Profile%\Segurazo\b\rsEngineSDK.dll
  • %Program Files%\Segurazo\x86\rsEngineFW_x86.dll
  • %All Users Profile%\Segurazo\b\x64\7z64.dll
  • %Program Files%\Segurazo\SegurazoTools.dll
  • %All Users Profile%\Segurazo\b\x64\rsEngineFW_x64.dll
  • %Program Files%\Segurazo\x86\msdia140.dll
  • %All Users Profile%\Segurazo\b\x86\rsLggrServer_x86.dll
  • %All Users Profile%\Segurazo\b\rsEngine.dll
  • %Program Files%\Segurazo\SegurazoClient.exe.config
  • %All Users Profile%\Segurazo\b\SegurazoTools.dll
  • %Program Files%\Segurazo\x86\ext_x86.dll
  • %All Users Profile%\Segurazo\b\rsEngineHelper.exe
  • %All Users Profile%\Segurazo\b\Microsoft.Diagnostics.Tracing.TraceEvent.dll
  • %All Users Profile%\Segurazo\b\x86\lz4_x86.dll
  • %All Users Profile%\Segurazo\b\SegurazoClient.exe
  • %Program Files%\Segurazo\x86\KernelTraceControl.dll
  • %All Users Profile%\Segurazo\b\x86\System.Data.SQLite.dll
  • %Program Files%\Segurazo\x64\rsEngineFW_x64.dll
  • %Program Files%\Segurazo\SegurazoClient.exe
  • %Program Files%\Segurazo\x64\System.Data.SQLite.dll
  • %All Users Profile%\Segurazo\b\SegurazoService.exe
  • %All Users Profile%\Segurazo\b\System.Threading.dll
  • %Program Files%\Segurazo\x64\lz4_x64.dll
  • %Program Files%\Segurazo\amd64\msdia140.dll
  • %Program Files%\Segurazo\rsEngineSDK.dll
  • %Program Files%\Segurazo\rsEngineHelper.exe
  • %Program Files%\Segurazo\Microsoft.Diagnostics.Tracing.TraceEvent.dll
  • %Program Files%\Segurazo\System.Threading.dll
  • %All Users Profile%\Segurazo\b\x86\msdia140.dll
  • %All Users Profile%\Segurazo\b\x86\rsEngineFW_x86.dll
  • %Program Files%\Segurazo\Microsoft.Win32.TaskScheduler.dll
  • %All Users Profile%\Segurazo\b\7a38ad565
  • %Program Files%\Segurazo\x86\rsEnginePM_x86.dll
  • %Program Files%\Segurazo\x64\rsEnginePM_x64.dll
  • %All Users Profile%\Segurazo\b\x64\rsEnginePM_x64.dll
  • %Program Files%\Segurazo\x64\rsLggrServer_x64.dll
  • %Program Files%\Segurazo\SegurazoService.exe
  • %Program Files%\Segurazo\x86\7z86.dll
  • %All Users Profile%\Segurazo\b\x86\ext_x86.dll
  • %Program Files%\Segurazo\SegurazoKD.sys
  • %Program Files%\Segurazo\SegurazoEngine.dll

Step 5

Diese Ordner suchen und löschen

[ learnMore ]
Aktivieren Sie unbedingt das Kontrollkästchen Versteckte Elemente durchsuchen unter Weitere erweiterte Optionen, um alle verborgenen Ordner in den Suchergebnissen zu berücksichtigen.
  • %All Users Profile%\Microsoft\Windows
  • %All Users Profile%\Segurazo
  • %System Root%\Users
  • %All Users Profile%\Segurazo\b
  • %All Users Profile%\Segurazo\b\amd64
  • %All Users Profile%\Microsoft\Windows\Start Menu
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs
  • %All Users Profile%\Microsoft
  • %User Profile%\AppData
  • %Program Files%\Segurazo\x86
  • %All Users Profile%\Segurazo\b\x86
  • %All Users Profile%\Segurazo\b\x64
  • %Program Files%\Segurazo\x64
  • %Program Files%\Segurazo\amd64
  • %Program Files%\Segurazo
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Segurazo

Step 6

Durchsuchen Sie Ihren Computer mit Ihrem Trend Micro Produkt, und löschen Sie Dateien, die als PUA.Win32.Segurazo.K entdeckt werden. Falls die entdeckten Dateien bereits von Ihrem Trend Micro Produkt gesäubert, gelöscht oder in Quarantäne verschoben wurden, sind keine weiteren Schritte erforderlich. Dateien in Quarantäne können einfach gelöscht werden. Auf dieser Knowledge-Base-Seite finden Sie weitere Informationen.


Nehmen Sie an unserer Umfrage teil