Segurazo Antivirüsü, genellikle bir program kurulumunun yanında gelir.
Sizlere sisteminizde zararlılar bulundu diye false positiveler gösterip yazılımın ücretli sürümünü satmaya çalışan bir program kendisi.
Segurazo'nun görünümü:
Segurazo'nun kurulum esnasında gerçekleşen işlemler ise böyle:
Kod:
Adds the folder C:\Program Files (x86)\Segurazo
Adds the file Errors.dat"="7/19/2019 9:41 AM, 621 bytes, A
Adds the file ExclusionsList.dat"="7/19/2019 9:38 AM, 2520 bytes, A
Adds the file Microsoft.Diagnostics.Tracing.TraceEvent.dll"="12/19/2018 12:23 PM, 1008944 bytes, A
Adds the file Microsoft.Win32.TaskScheduler.dll"="12/19/2018 12:23 PM, 310784 bytes, A
Adds the file ReportsList.dat"="7/19/2019 9:46 AM, 408 bytes, A
Adds the file rsEngine.config"="7/19/2019 9:38 AM, 236 bytes, A
Adds the file rsEngine.dll"="2/26/2019 12:31 PM, 5490968 bytes, A
Adds the file rsEngineHelper.exe"="2/26/2019 12:31 PM, 165656 bytes, A
Adds the file rsEngineHelper.exe.config"="12/19/2018 12:23 PM, 383 bytes, A
Adds the file rsEngineSDK.dll"="2/26/2019 12:31 PM, 198936 bytes, A
Adds the file ScanDetectionsList.dat"="7/19/2019 9:46 AM, 128 bytes, A
Adds the file SegurazoClient.exe"="3/18/2019 4:02 PM, 1896872 bytes, A
Adds the file SegurazoClient.exe.config"="2/9/2019 5:44 PM, 427 bytes, A
Adds the file SegurazoEngine.dll"="3/18/2019 4:02 PM, 3877288 bytes, A
Adds the file SegurazoService.config"="7/19/2019 9:49 AM, 4736 bytes, A
Adds the file SegurazoService.exe"="3/18/2019 4:03 PM, 179624 bytes, A
Adds the file SegurazoService.exe.config"="2/9/2019 5:44 PM, 427 bytes, A
Adds the file SegurazoShell64_v1069.dll"="3/18/2019 4:02 PM, 172456 bytes, A
Adds the file SegurazoShell86_v1069.dll"="3/18/2019 4:02 PM, 145320 bytes, A
Adds the file SegurazoTools.dll"="3/18/2019 4:03 PM, 135080 bytes, A
Adds the file SegurazoUninstaller.exe"="3/18/2019 4:02 PM, 1012136 bytes, A
Adds the file SegurazoUninstaller.exe.config"="2/9/2019 5:44 PM, 427 bytes, A
Adds the file Signatures.dat"="7/19/2019 9:40 AM, 1060120 bytes, A
Adds the file SignaturesPacks.dat"="7/19/2019 9:40 AM, 203992 bytes, A
Adds the file SubmitsList.dat"="7/19/2019 9:46 AM, 128 bytes, A
Adds the file System.Threading.dll"="12/19/2018 12:23 PM, 387408 bytes, A
Adds the file uninstaller.ico"="12/19/2018 12:23 PM, 24990 bytes, A
Adds the file WhiteList.dat"="7/19/2019 9:40 AM, 278616 bytes, A
Adds the folder C:\Program Files (x86)\Segurazo\amd64
Adds the file KernelTraceControl.dll"="12/19/2018 12:23 PM, 223008 bytes, A
Adds the file msdia140.dll"="12/19/2018 12:23 PM, 1380512 bytes, A
Adds the folder C:\Program Files (x86)\Segurazo\Cache
Adds the folder C:\Program Files (x86)\Segurazo\Logs
Adds the file err.dat"="7/19/2019 9:41 AM, 447 bytes, A
Adds the folder C:\Program Files (x86)\Segurazo\Scans
Adds the file abfc197d-3021-42b9-8ca6-5aaa7345b20b.scan"="7/19/2019 9:46 AM, 1388 bytes, A
Adds the folder C:\Program Files (x86)\Segurazo\x64
Adds the file 7z64.dll"="12/19/2018 12:23 PM, 1646592 bytes, A
Adds the file ext_x64.dll"="12/19/2018 12:23 PM, 375576 bytes, A
Adds the file lz4_x64.dll"="12/19/2018 12:23 PM, 119064 bytes, A
Adds the file rsEngineFW_x64.dll"="12/19/2018 12:23 PM, 104216 bytes, A
Adds the file rsEnginePM_x64.dll"="12/19/2018 12:23 PM, 228120 bytes, A
Adds the file rsLggrServer_x64.dll"="12/19/2018 12:23 PM, 821528 bytes, A
Adds the file System.Data.SQLite.dll"="12/19/2018 12:23 PM, 1658136 bytes, A
Adds the folder C:\Program Files (x86)\Segurazo\x86
Adds the file 7z86.dll"="12/19/2018 12:23 PM, 1113088 bytes, A
Adds the file ext_x86.dll"="12/19/2018 12:23 PM, 280344 bytes, A
Adds the file KernelTraceControl.dll"="12/19/2018 12:23 PM, 167200 bytes, A
Adds the file lz4_x86.dll"="12/19/2018 12:23 PM, 98584 bytes, A
Adds the file msdia140.dll"="12/19/2018 12:23 PM, 1081656 bytes, A
Adds the file rsEngineFW_x86.dll"="12/19/2018 12:23 PM, 88856 bytes, A
Adds the file rsEnginePM_x86.dll"="12/19/2018 12:23 PM, 190744 bytes, A
Adds the file rsLggrServer_x86.dll"="12/19/2018 12:23 PM, 569344 bytes, A
Adds the file System.Data.SQLite.dll"="12/19/2018 12:23 PM, 1209624 bytes, A
Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Segurazo
Adds the file Segurazo Antivirus.lnk"="7/19/2019 9:38 AM, 1055 bytes, A
Adds the folder C:\ProgramData\Segurazo
Adds the file SegurazoEngine.dll"="3/18/2019 4:02 PM, 3877288 bytes, A
Adds the file SegurazoIC.exe"="3/18/2019 4:03 PM, 542120 bytes, A
Adds the file SegurazoWD.config"="7/19/2019 9:49 AM, 1 bytes, A
Adds the file SegurazoWD.exe"="3/18/2019 4:03 PM, 38312 bytes, A
Adds the file SegurazoWD.exe.config"="1/30/2019 6:58 PM, 427 bytes, A
Adds the folder C:\Users\{username}\AppData\Roaming\segurazoclient
Adds the file segurazoclientConfig.xml"="7/19/2019 9:46 AM, 1178 bytes, A
Registry details [View: All details] (Selection)
------------------------------------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt]
"(Default)"="REG_SZ", "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.lnk\ShellEx\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt]
"(Default)"="REG_SZ", "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}]
"(Default)"="REG_SZ", "SegurazoShellExtension.FileContextMenuExt Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}\InprocServer32]
"(Default)"="REG_SZ", "C:\Program Files (x86)\Segurazo\SegurazoShell64_v1069.dll"
"ThreadingModel"="REG_SZ", "Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt]
"(Default)"="REG_SZ", "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt]
"(Default)"="REG_SZ", "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt]
"(Default)"="REG_SZ", "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\*\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt]
"(Default)"="REG_SZ", "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.lnk\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt]
"(Default)"="REG_SZ", "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\Directory\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt]
"(Default)"="REG_SZ", "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\Folder\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt]
"(Default)"="REG_SZ", "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\lnkfile\shellex\ContextMenuHandlers\SegurazoShellExtension.FileContextMenuExt]
"(Default)"="REG_SZ", "{BFD98515-CD74-48A4-98E2-13D209E3EE4F}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}]
"(Default)"="REG_SZ", "SegurazoShellExtension.FileContextMenuExt Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BFD98515-CD74-48A4-98E2-13D209E3EE4F}\InprocServer32]
"(Default)"="REG_SZ", "C:\Program Files (x86)\Segurazo\SegurazoShell86_v1069.dll"
"ThreadingModel"="REG_SZ", "Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\SegOption]
"fst"="REG_DWORD", 1
"gui"="REG_DWORD", 42
"guisc"="REG_DWORD", 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo]
"FirstRun"="REG_SZ", "7/19/2019 9:38:51 AM"
"FSSDT"="REG_SZ", "7/19/2019 9:46:49 AM"
"FSSID"="REG_SZ", "abfc197d-3021-42b9-8ca6-5aaa7345b20b"
"FSSTIDQuick"="REG_SZ", "abfc197d-3021-42b9-8ca6-5aaa7345b20b"
"LSTSCDQuick"="REG_SZ", "7/19/2019 9:46:49 AM"
"LSTSCQuick"="REG_SZ", "abfc197d-3021-42b9-8ca6-5aaa7345b20b"
"PMDPP"="REG_SZ", "0"
"PRSC"="REG_SZ", "0"
"PRSD"="REG_SZ", ""
"RGUSR"="REG_SZ", "636991259313647198"
"ServicePipe"="REG_SZ", "Segurazo1"
"SIGLC"="REG_SZ", "7/19/2019 9:40:01 AM"
"STATSC"="REG_SZ", "1"
"U"="REG_SZ", "4f8dd972-5ca9-45c9-8e9f-ead0fc20f9e0"
"UH"="REG_SZ", "6BFC2FFE7B88A3463B117E05B0F0F3D7"
"WLLCK"="REG_SZ", "7/19/2019 9:40:02 AM"
[HKEY_LOCAL_MACHINE\SOFTWARE\Segurazo\RescanQueue]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Segurazo]
"DisplayIcon"="REG_SZ", "C:\Program Files (x86)\Segurazo\uninstaller.ico"
"DisplayName"="REG_SZ", "Segurazo Antivirus"
"DisplayVersion"="REG_SZ", "1.0.6.9"
"EstimatedSize"="REG_DWORD", 25746
"Publisher"="REG_SZ", "Digital Communications Inc"
"UninstallString"="REG_SZ", "C:\Program Files (x86)\Segurazo\SegurazoUninstaller.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Segurazo]
"FirstRun"="REG_SZ", "7/19/2019 9:38:51 AM"
"FSSDT"="REG_SZ", "7/19/2019 9:46:49 AM"
"FSSID"="REG_SZ", "abfc197d-3021-42b9-8ca6-5aaa7345b20b"
"FSSTIDQuick"="REG_SZ", "abfc197d-3021-42b9-8ca6-5aaa7345b20b"
"LSTSCDQuick"="REG_SZ", "7/19/2019 9:46:49 AM"
"LSTSCQuick"="REG_SZ", "abfc197d-3021-42b9-8ca6-5aaa7345b20b"
"PMDPP"="REG_SZ", "0"
"PRSC"="REG_SZ", "0"
"PRSD"="REG_SZ", ""
"RGUSR"="REG_SZ", "636991259313647198"
"SIGLC"="REG_SZ", "7/19/2019 9:40:01 AM"
"STATSC"="REG_SZ", "1"
"U"="REG_SZ", "4f8dd972-5ca9-45c9-8e9f-ead0fc20f9e0"
"UH"="REG_SZ", "6BFC2FFE7B88A3463B117E05B0F0F3D7"
"WLLCK"="REG_SZ", "7/19/2019 9:40:02 AM"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\SegurazoAntivirus]
"InstallEnd"="REG_DWORD", 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application]
"AutoBackupLogFiles"="REG_DWORD", 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\SegurazoSvc]
"EventMessageFile"="REG_EXPAND_SZ, "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\EventLogMessages.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Service1]
"EventMessageFile"="REG_EXPAND_SZ, "C:\Windows\Microsoft.NET\Framework64\v2.0.50727\EventLogMessages.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoIC]
"DelayedAutostart"="REG_DWORD", 1
"Description"="REG_SZ", "This service protect your pc from viruses and spyware."
"DisplayName"="REG_SZ", "SegurazoIC"
"ErrorControl"="REG_DWORD", 1
"FailureActions"="REG_BINARY, ............d...d...d.
"ImagePath"="REG_EXPAND_SZ, "C:\ProgramData\Segurazo\SegurazoIC.exe -service"
"ObjectName"="REG_SZ", "LocalSystem"
"Start"="REG_DWORD", 2
"Type"="REG_DWORD", 16
"WOW64"="REG_DWORD", 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoIC\Security]
"Security"="REG_BINARY, ........0................p...."......................... ...................................
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoSvc]
"DelayedAutostart"="REG_DWORD", 1
"Description"="REG_SZ", "This service protect your pc from viruses and spyware."
"DisplayName"="REG_SZ", "SegurazoSvc"
"ErrorControl"="REG_DWORD", 1
"FailureActions"="REG_BINARY, ............d...d...d.
"ImagePath"="REG_EXPAND_SZ, "C:\Program Files (x86)\Segurazo\SegurazoService.exe"
"ObjectName"="REG_SZ", "LocalSystem"
"Start"="REG_DWORD", 2
"Type"="REG_DWORD", 16
"WOW64"="REG_DWORD", 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoSvc\Security]
"Security"="REG_BINARY, ........0................p...."......................... ...................................
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoWD]
"DelayedAutostart"="REG_DWORD", 1
"Description"="REG_SZ", "This service protect your pc from viruses and spyware."
"DisplayName"="REG_SZ", "SegurazoWD"
"ErrorControl"="REG_DWORD", 1
"FailureActions"="REG_BINARY, ............d...d...d.
"ImagePath"="REG_EXPAND_SZ, "C:\ProgramData\Segurazo\SegurazoWD.exe"
"ObjectName"="REG_SZ", "LocalSystem"
"Start"="REG_DWORD", 2
"Type"="REG_DWORD", 16
"WOW64"="REG_DWORD", 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SegurazoWD\Security]
"Security"="REG_BINARY, ........0................p...."......................... ...................................
Segurazo nasıl kaldırılır?
Segurazo, Malwarebytes'ın veri tabanında 'PUP.Optional.Segurazo' olarak geçiyor. Potansiyel olarak istenmeyen program. Malwarebytes'ı indirip sisteminizi taratmanız Segurazo'yu tamamen kaldıracaktır.1-)
Bağlantıları görmek için lütfen
Giriş Yap
- mb3-setup-consumer-{version}.exe dosyasını çalıştır, kurulum için adımları takip et.
- Sonrasında "Bitir"e tıkla.
- Program tamamen güncel ise, "Scan for rootkits" için, "Scan options" seçeneğinin "Protection" sekmesinin altında açık olduğundan emin ol. Eğer açık değil ise o seçeneği açın.
- Ardından dashboard sekmesinde "Scan now"a tıkla ve tarama bitene kadar bekle.
- Tarama tamamlandığında, tüm tehditlerin seçili olduğundan emin ol ve "Seçilenleri Kaldır"a tıkla.
- Sisteminizi yeniden başlatmanız istendiğinde, sisteminizi yeniden başlatın.
Son düzenleme: