Author Topic: Segurazo "Antivirus" - how to remove  (Read 28476 times)

0 Members and 1 Guest are viewing this topic.

Offline Cryptochik

  • Newbie
  • *
  • Posts: 4
Segurazo "Antivirus" - how to remove
« on: July 13, 2019, 07:19:40 PM »
I obviously downloaded something that included Segurazo fake antivirus.  I can't remove or uninstall this piece of garbage.  I first tried uninstall from control panel, but the malware opens itself when you try to uninstall, so Windows won't touch it.  I then tried Malwarebytes, Avast, Revo Uninstall and have even got to command prompt and tried to manually delete the folder.   I'm faced with repeated lines saying I don't have permission to uninstall.  I am in the admin mode, so this shouldn't be an issue. I even right clicked on the Segurazo folder in Program Files (x86) and ran Avast on the actual file and it found nothing.

Has anyone accidentally installed this trash and not been able to remove it?  Ideas? Thanks.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37528
  • Not a avast user
Re: Segurazo "Antivirus" - how to remove
« Reply #1 on: July 13, 2019, 07:29:15 PM »
Instructions  https://forum.avast.com/index.php?topic=194892.0

attach FRST diagnostic logs from step #2


« Last Edit: July 13, 2019, 07:48:07 PM by Pondus »

Offline Cryptochik

  • Newbie
  • *
  • Posts: 4
Re: Segurazo "Antivirus" - how to remove
« Reply #2 on: July 13, 2019, 08:52:57 PM »
Mbam file attached, going to step 2 but can't download Farbar because my computer keeps removing it as malware

« Last Edit: July 13, 2019, 09:13:43 PM by Cryptochik »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33899
  • malware fighter
Re: Segurazo "Antivirus" - how to remove
« Reply #3 on: July 13, 2019, 09:30:44 PM »
While you are waiting for a qualified remover to go through your logs and help you out with the cleansing of it.
read this: https://www.carbonite.com/blog/article/2016/04/when-antivirus-is-a-virus

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37528
  • Not a avast user
Re: Segurazo "Antivirus" - how to remove
« Reply #4 on: July 13, 2019, 10:16:58 PM »
Mbam file attached, going to step 2 but can't download Farbar because my computer keeps removing it as malware
what program is detecting FRST ? .... can you disable it?

Did you let malwarebytes remove quarantine all the crap it found?  your log say "no action by user"


« Last Edit: July 13, 2019, 11:21:27 PM by Pondus »

Offline Cryptochik

  • Newbie
  • *
  • Posts: 4
Re: Segurazo "Antivirus" - how to remove
« Reply #5 on: July 13, 2019, 11:14:16 PM »
I ran Malwarebyes and generated the file again, then I deleted the 500+ files from the Quarantine folder in Malwarebytes.  It still doesn't see or remove the Segurazo files, which are located (at least some are visible) in: C:\Program Files (x86)\Segurazo.  Additionally, I reran Revo Uninstaller.  It no longer was able to see the Segurazo folder, so I had to use the Hunter directly on the icon in the bottom right tray.  It found all the Segurazo files, said it was deleting them, then said the files would be removed when I restarted.  Sounds good, but when I restarted the files were still there.  This is the second try.  Avast and Malwarebytes are both blocking FRST.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37528
  • Not a avast user
Re: Segurazo "Antivirus" - how to remove
« Reply #6 on: July 13, 2019, 11:20:03 PM »
Quote
Avast and Malwarebytes are both blocking FRST.
Turn off malwarebytes realtime protection
right click avast tray icon and pause all shields



Offline Cryptochik

  • Newbie
  • *
  • Posts: 4
Re: Segurazo "Antivirus" - how to remove
« Reply #7 on: July 18, 2019, 11:49:49 PM »
The best I was able to do was to go into Safe Mode offline and manually delete any file with Segurazo in the title.  I assume I missed some, but I got back online and ran Avast and Malwarebyes and they caught a few more when I used the name as a keyword? I believe it is gone but keep running the antivirus and malware software to be sure.  I believe I got this while downloading a supposed file recovery software named Reclaimation.