Infected by " Live security platinum " malware

How is the computer behaving now ?

it’s good now, I fixed it by following guide on the link because I was in rush that evening, I didn’t tried with OTL, but still thank you very much for posting removal guide.

I didn’t noticed any serious problems anymore , I unninstalled avast before cleaning pc with tools, and then install it again and now have together avast and trial Malwarebytes Anti-Malware

The only thing I noticed is that some sites get completely blocked.

I will still keep monitoring this situation

Well! I guess you got infected with the new icon varient of live security rogue…Avast now has detections for these varients now…

the problem is that these fakeAV’s and other malware change on daily basis…I would recommend you to run Malwarebytes PRO with avast

that would prevent these attacks…MBAM is great side kick to your AV…what avast doesnt have detection for MBAM will get it…I would recommend you to buy MBAM Pro [Really cheap] and its worth the money!! ;D

I have my own clients running Avast and mbam pro and they never got infected and never turned up back again…

and how about avast pro ? maybe pro had protection. 8)

Avast free,pro and IS have same engines…they provide same high quality protection…just pro and IS have more features than free…but the additional features in pro and IS are safezone…manual sanboxing avalilability…so the additional features in pro and IS are to be manually used by he user :wink:

anyway I feel you like avast pro…go for it then :smiley: i switched 2 of my family members to them…1 to pro and 1 to IS… :slight_smile: all have MBAM pro running alongside :wink:

why do I hear twice “avast virus database has been updated” ?

Message about update is showed only on second voice. ::slight_smile:

I just had two friends of mine whom of which I recommended Avast to bring their laptops to me infected with Live Security Platinum in the past two days. Both had the newest version of Avast installed with the most recent updates. You can even run avast and do a quick scan/full scan/boot scan and it does not fix the issue.

Needless to say, they were not impressed.

Here is the issue - it is another case of people visiting websites which have been hacked. Both go the virus from online forums. They logged onto the forums and a window popup said they had a virus and click here to fix it, that of course was a rouse and it installs the actual virus/trojan. Avast for some reason never flagged it and it boots into memory before Avast and stops you from opening MSCONFIG, REGEDIT, a list of other antivirus products, and the uninstall screens.

The one thing Avast does have going for it is that it doesn’t stop updates. I have seen this before on a PC last week and it stops MCafee from even starting or updating, blocking the update websites and keeps you from downloading it in your browser. They seem to have ignored Avast as Avast runs perfectly, it just doesn’t see it as a threat.

I used the systernals process explorer (procexp.exe) to fix the issue. First you have to rename it as EXPLORER.EXE as the virus will block it as it is setup to stop it as well, but if you rename it as EXPLORER.EXE it will let it run. You can then kill the Live Platinum Process and you will find the location in your User folder, random folder and filename which you can then delete. You also after killing it can remove it from the startup using msconfig.

Ye need to get this sorted though and quick as if I have already seen three of these in a week it does not bode well for whats to come if ye leave it unchecked.

There is a nice write-up about this here from Stelian Pilici: http://malwaretips.com/blogs/live-security-platinum-virus/
Victims are advised to seek help from a qualified removal expert, like essexboy etc. to guide the removal routine,

polonus