Instructions to remove Safesoft Trojan (WIN32.Zafi.B virus)
Symptoms of a computer infected with WIN32.Zafi.B is that Windows Firewall will automatically appear with messages like ' Security Center Alert ', ' To help protect your computer, Windows Firewall có hoạt động đã xác định của máy phục vụ harmful . '. Then there is a line with the _____ mark, followed by the message:
' Do bạn muốn thiết bị khối này'.
Name: Sinowal.Trojan
Risk Level: High
Description: Sinowal.Trojan is a Trojan program that records and takes screen shots of the computer. Stealing personal financial Information . '
There will be 3 options for users: Keep Blocking, Unblock (these 2 buttons are gray and you cannot click), Enable Protection - the only button you can interact with and it will automatically point to a website called Safe Soft Reviews, there are 'selling' a lot of security security programs with extremely attractive information.
Just below the button, you will see the warning information given by the program as follows:
' Windows Firewall đã tìm thấy không cho phép hoạt động, nhưng nó không thể thực hiện bạn gỡ bỏ các người dùng. Gặp khoá loggers và đối tượng khác khác và gỡ bỏ bạn thông tin thông tin từ bạn computer . '
And below that link is the comment line: ' Click to download and activate protection ':
When you open this link in IE, you will see the security center warning you of the sign of sinowal.trojan on it
Solution 01
Navigate to the path: C: documents and settingsusernameapplication dataGoogle , you will see a file named xxxxxx.exe ( pfysw721318.exe .) with the symbol of a certain security program. Please delete the file:
For some computers, there will be an error when deleting the file:
When encountering this case, use KillBox program and select the file to delete, the program will execute this command after the user restarts the computer.
Solution 02
You only need to use the following free Combofix program, run the file, the program will automatically scan the entire system and detect harmful virus patterns in the computer.
You should read it
- Kaspersky's free support security utilities
- Steps to root Win32 virus: Expiro
- Learn about the Trojan.Win32.FraudPack.bkhe template
- Description of template Trojan-PSW.Win32.Qbot.mk
- Kill viruses, Windows 7 trojans without downloading software
- Top 3 best IPL hair removal machines today
- 'Great technique' Autorun virus removal by hand
- What is a Trojan? How to avoid trojan attack?
May be interested
- Scan for viruses - spyware does not need to install softwaredo you suspect that your computer is infected with the virus, but the anti-virus program on your computer is inefficient or your computer has not had any program to fight the virus?
- Overview of sample Net-Worm.Win32.Kido.ihclassified as extremely toxic net-worms, they have strong spread properties through computer networks, their most distinguishing feature is self-replication and spread without the need for human interaction. use.
- Description of the P2P-Worm.Win32.BlackControl.g templatewith the name p2p worm - they are mainly spread through peer-to-peer sharing models like kazaa, grokster, edonkey, fasttrack, gnutella ...
- Learn about Backdoor.Win32.Bredolab.eua malwarethe concept of backdoor is used to refer to malware, created to install and distribute malicious code to users' computers ...
- Find out about Virus.Win32.Sality.ag templateviruses like these often have a mechanism to replicate the resources on the infected computer, unlike worms, unused viruses and exploit network services to replicate and spread themselves to other computers ..
- Dangerous virus attacks the chat programkaspersky lab has discovered a worm called im-worm.win32.zeroll with 4 variants that can spread in all chat programs such as yahoo messenger, skype ...