Virus Serwab

Last update on June 18, 2009 10:38 AM by jak58
Published by aakai1056

Virus Serwab






Intro


The virus Serwab is a rogue virus that installed on your computer and forces to buy the anti-virus Winsecure. When browsing on Internet Explorer, if you received a message informing you that your computer get infected by a virus Serwab and forces to buy the antivirus Winsecure. This means that this virus has already installed on your PC.

You may also receive a message under the title Microsoft Customer Support displaying below documentation:


Hello Dear.
In programm maintenance of corporation Microsoft critical
vulnerabilyty has been found in processing wmf files. Programmers
Microsoft have let out critical updating for Windows 98/2000/XP. We
urgently recommend you and to estabilish updating. One copy of
updating packet in attach for this letter.
Detalis: http://support.microsoft.com
With best regards,
Microsoft Customer Support.



The virus is in fact attached to a file named timesrv.exe (53 Ko). Be Careful, do not run this file as this will be copied in your system directory under timesrv.exe. This will modify the registry and will be run at every windows start. This will automatically be sent to windows address book through its SMTP engine.

The virus will then open the port TCP 9999 waiting for instructions.

How to uninstall Serwab


1. Go to Menu Start and select Run¯.

Type services.msc

Scroll to the below lines in the Services and disable them.
  • Command Service
  • Network Monitor

To disable, right-click >Properties and in the Start up type, select Disable.

2.Go to menu Start¯ and open My Computer In the address bar, type
"C:\", "Program Files", then scroll to the below mentioned file and delete one by one
  • Deskbar
  • ToolBar888
  • TheSearchAccelerator
  • Network Monitor


Then click on menu Start and select Search > All files and folders¯, then cut and paste the following file names in the search bar. If the file appears, delete one by one
  • GIDCAI32.dll
  • winlog.exe
  • dfndrff_12.exe
  • kybrdff_12.exe
  • ALCXMNTR.EXE


3. Go to Menu Start > My computer > "C:\", "<gras>Documents and settings" User namer" "My documents" and delete the file
  • WinAntiVirusPro2006FreeInstall_fr.exe

Download Smitfraudix


Download Smitfraudix by following below link:
  • Restart your PC press F8 to enter Safe Mode


http://www.softpedia.com/get/Antivirus/SmitfraudFix.shtml

Delete from Safe Mode


If a file persists to get uninstall:

Restart your computer and Press F8 to enter Safe Mode

This process might a few minutes to download all files. Then select the specific files and delete it and empty your recycle bin.

Download HighjackThis


Then download HijackThis and make a complete scan of your computer system.

You can download this software on below link:

http://www.filehippo.com/download_hijackthis/
Best answers for « Virus Serwab » in :
Viruses - Introduction to viruses Show Virus A virus is a small computer program found within the body of another program which, when run, loads itself into the memory and carries out the instructions programmed by its author. The definition of a virus may be: « Any computer...
The LovSan/Blaster virus Show Introduction to the LovSan virus Appearing in the summer of 2003, LovSan (also known as W32/Lovsan.worm, W32/Lovsan.worm.b, W32.Blaster.Worm, W32/Blaster-B, WORM_MSBLAST.A, MSBLASTER, Win32.Poza, Win32.Posa.Worm, and Win32.Poza.B) is the first...
The Nimda virus Show Introduction to the Nimda virus Le Nimda virus (code name W32/Nimda) is a worm which spreads by email. It also has four other ways to spread: The web Shared folders Microsoft IIS security holes File transfer At particular risk are users of...
[Virus] System Volume Information Show[Virus] System Volume Information The System Volume Information folder is used by Windows XP for storing data on system configuration and is also used by the System Restore tool to store information and restore points. Restore points...
How to remove the virus CONFICKER / DOWNADUP / KIDO? ShowHow to remove the virus CONFICKER / DOWNADUP / KIDO What is the Conficker? How to avoid being infected by Conficker? Disinfect a computer affected by Conficker Preliminary Remove infection What is the Conficker? Conficker (also...
The First Steps to Virus/Spyware/Adware Removal ShowThe First Steps to Virus/Spyware/Adware Removal Step 1: Delete Temporary Files How to delete Temporary Files? How to delete Temporary Internet Files? Step 2: Get a good all in one Antivirus/Anti Spyware/ Anti Adware...
Download Clean Virus MSN ShowViruses meet hereafter a bit on the net by all thinkable means everywhere. After mails , supporting they attack instantaneous freight forwarding. Clean Virus MSN is a tool which discerns automatically the viruses which circulate on MSN Messenger....
Download McAfee Virusscan ShowWould you like to have a robust protect against viruses? McAfee Virusscan can protect your computer from virus. McAfee Virusscan is a powerful antivirus allowing to protect your PC from malware and viruses. Since it scans your downloads from...
The Bad Trans virus ShowIntroduction to the BadTrans virus The BadTrans virus (code name W32.BadTrans.B or W32/Badtrans-B) is a worm which spreads by e-mail. It also uses another method to spread: Microsoft Internet Explorer security flaws The BadTrans.B virus...