Struck by Live Security platinum

masplin

New member
Member
VIP
Local time
5:35 AM
Messages
246
My wife was browsing and got struck by this thing. hopefully I can remove it with Superantispyware free version that seems to have detected it.

my question is to understand how it got on givne I think I'm reasonably security conscious. This is the 2nd time as one of my daughters had simialr a few months ago. Both were runnig MSE and spybot teatimer. Both are set up as non-adminstrative users to stop things installing themselves. so 2 questions:

1. do any anti-virus or anti-spyware programs prevent these types of programs infecting you?
2. how has it managed to install when you need an administrators password to change anything else critical on the system?

thanks for some education

Mike
 

My Computer

Computer Manufacturer/Model Number
Dell XPS 430
OS
Windows 7 64 bit
CPU
intel quad Q6600 2.4GHz
Motherboard
Intel X48
Memory
4GB
Graphics Card(s)
ATI Radeon HD 4850 512Mb
Sound Card
ATI High Def
Monitor(s) Displays
Dell 1707FPV
Hard Drives
640GB RAID 0
320GB
PSU
425W
Keyboard
Logitech MX3000
Mouse
Logitech M-RAG97
Internet Speed
7Mb

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Inspiron 530
OS
Windows 7 Professional SP1 64-bit
CPU
Intel Core 2 Duo Processor E8300 @ 2.83GHz
Motherboard
Dell Inc. 0RY007 (Socket 775)
Memory
4.00 GB Dual-Channel DDR2 @ 332MHz (5-5-5-15)
Graphics Card(s)
Intel(R) G33/G31 Express Chipset Family
Sound Card
Integrated 7.1 Channel Audio
Monitor(s) Displays
Acer G245HQL 23.6" LED(1920x1080@60Hz)
Screen Resolution
1920 x 1080
Hard Drives
Disk 0 HITACHI 1TB OS Installed - Disk 1 HITACHI 1TB For Backups
Keyboard
Dell USB Keyboard
Mouse
Dell Optical USB Mouse
Internet Speed
DSL 10 meg
Antivirus
Symantec(SEP)
Browser
Pale Moon
Platinum rogue usually comes with Zero access.This instruction may not be sufficient to eradicate malware.
 

My Computer

OS
32 bit
Well Superantispyware seems to have done the job and don't seem to have any issues

i was more interested in why it happens and how to prevent it as it quite irritating?
 

My Computer

Computer Manufacturer/Model Number
Dell XPS 430
OS
Windows 7 64 bit
CPU
intel quad Q6600 2.4GHz
Motherboard
Intel X48
Memory
4GB
Graphics Card(s)
ATI Radeon HD 4850 512Mb
Sound Card
ATI High Def
Monitor(s) Displays
Dell 1707FPV
Hard Drives
640GB RAID 0
320GB
PSU
425W
Keyboard
Logitech MX3000
Mouse
Logitech M-RAG97
Internet Speed
7Mb
Viruses generally have a bad habit of introducing more viruses to your system. In addition to keeping a close watch on your PC's behavior, you should also run the following scanners to make sure it is indeed "all clean."

http://www.sevenforums.com/tutorials/166445-windows-defender-offline.html?filter

Malwarebytes : Malwarebytes Anti-Malware PRO removes malware including viruses, spyware, worms and trojans, plus it protects your computer

Anti-rootkit utility TDSSKiller.

No AV gets every virus, so when a new variant comes out, it slips under the radar. One of the more common ways a virus is caught is called "drive-by", you visit a web page that has malicious code embedded, it silently loads into your PC and installs itself without your knowledge. Some viruses will circumvent the safety systems and install, regardless of what your setup is.

If you are using Firefox, there is a plug in called NoScript, this stops most malicious code from running in the background of a compromised web page.

https://addons.mozilla.org/en-US/firefox/addon/noscript/?src=search
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
perfect thanks for the advice.
 

My Computer

Computer Manufacturer/Model Number
Dell XPS 430
OS
Windows 7 64 bit
CPU
intel quad Q6600 2.4GHz
Motherboard
Intel X48
Memory
4GB
Graphics Card(s)
ATI Radeon HD 4850 512Mb
Sound Card
ATI High Def
Monitor(s) Displays
Dell 1707FPV
Hard Drives
640GB RAID 0
320GB
PSU
425W
Keyboard
Logitech MX3000
Mouse
Logitech M-RAG97
Internet Speed
7Mb

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
That's the whole point of viruses and malware. They go around all security measures or attemp to anyways. The only thing we can do is be ready.
Obviously the likehood of getting a virus is reduced substantially with the aid of anti virus and anti malware protectiong to help defend against malicious coding.

Spybot in my opinion has slowed down and is not as reliable as it once was a long time ago. I would recommend Malwarebytes.
User Account Control enabled with IE8 or 9 works well too, this enables IE protected mode.
All you can do is have a real time anti virus, firewall, and spyware protection and hope for the best. The sites you visit also increase/decrease the likelyhood of getting an infection. Now that you mention it it's been almost 3 years since i gotten a single infection.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Gateway / Slight Modifications
OS
Windows 8 64 bit PRO
CPU
AMD Phenom X4 9100e
Motherboard
Gateway RS780
Memory
2GB X2 DDR2
Graphics Card(s)
Sapphire HD 6850
Sound Card
Integrated
Monitor(s) Displays
Gateway 19" + Dell 19"
Screen Resolution
1440X900 sometimes 2880 by 900
Hard Drives
WD 80GB
WD 640GB
WD 1,000GB
PSU
Antec BP 550watts
Case
Antec 300
Cooling
Stock Cooling
Keyboard
Saitek Eclipse II
Mouse
Gigabyte GM-M6800
Internet Speed
D: 30Mbps U:4Mbps
Antivirus
Avast version 8
Browser
Internet Explorer ver 10 64 bit
Other Info
This is my work computer.
I have another laptop running Windows 7 64 bit.
Another PC running Windows 8 64 bit pro.
Total of 3
I do have a system image and take them every month and daily overnight backups so should be prepared ofr the worst!!!
 

My Computer

Computer Manufacturer/Model Number
Dell XPS 430
OS
Windows 7 64 bit
CPU
intel quad Q6600 2.4GHz
Motherboard
Intel X48
Memory
4GB
Graphics Card(s)
ATI Radeon HD 4850 512Mb
Sound Card
ATI High Def
Monitor(s) Displays
Dell 1707FPV
Hard Drives
640GB RAID 0
320GB
PSU
425W
Keyboard
Logitech MX3000
Mouse
Logitech M-RAG97
Internet Speed
7Mb
So maybe not so good. I can access the internet but can no longer access any other pc on the network. Error is diagnostic Policy Server not running. If I go to services it is set to automatic but stopped. If I try start it it tries to and then stops again saying "some servcies stop if not in use by other services or programs"

I have run Malware, Rootkiller, Windows Defender offline (which found some things to remove). I have also run sfc /scannow and checked msconfig set to normal as saw that on another post about Diagnostic server. I have rebooted.

I went to system restore and oddly the last restore point is the night after I got infected. Previous to that there is one in Feb. Not sure if that lack of restore points is related. I have a system image of my C drive (all user profiles are on a partitioned U drive) from 9th July.

Before doing something as drastic as an image restore are there any other steps I can take as seems a bit odd I can access the internet but not my network as same adapter.

Thanks Mike
 

My Computer

Computer Manufacturer/Model Number
Dell XPS 430
OS
Windows 7 64 bit
CPU
intel quad Q6600 2.4GHz
Motherboard
Intel X48
Memory
4GB
Graphics Card(s)
ATI Radeon HD 4850 512Mb
Sound Card
ATI High Def
Monitor(s) Displays
Dell 1707FPV
Hard Drives
640GB RAID 0
320GB
PSU
425W
Keyboard
Logitech MX3000
Mouse
Logitech M-RAG97
Internet Speed
7Mb
I have run Malware, Rootkiller, Windows Defender offline (which found some things to remove).

Do you remember the name of these items it found? The name of these viruses will be a deciding factor in what actions you should take.

Some viruses do remove restore points or deny access to them. And they also like to embed themselves in restore points, usually the first one. If you can access a restore point after an infection, it's best to go back 2 or 3 points. Unfortunately, some viruses corrupt the entirety of restore points.

You could try the restore point in Feb, but that does seem odd there are no others, since you've no doubt had updates from MS and they, by default, make a restore point before installing.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Personally I would not use any restore point because they can be infected. I also would not use any back ups that where made any where the time of the found infection. Infection can be installed with a time delay or a action related start. Example: When and if you hit the Windows Flag Key you could activate the infection. It could be anything along that line.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Good point Layback. This is why when I make system images, I keep the last 4 of them on file so that if I do inadvertently make a backup with a virus, I can go back even farther.

When was this system image made? Was it made before or after the infection?

Being that the only restore point you have is Feb, it's a good chance your restore points are infected.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Unfortunately I didnt write down the files Windows Defender found. Would they be logged somewhere if I restart it?

The image is July 9th so fairly recent in that there wont be many changes, but before the infection which was 2 days ago. However I only take a system image of my C drive that is on an SSD and contains just OS and programs. I moved the user files to a seperate HD in a "U" partition partly becuase of space and partly I was advised by this forum it was good practice. The "U" drive gets backed up daily with windows backup to another HD. I saw some of the virus files had paths on this U drive so wondering if just restoring my C drive with the image is going to be sufficient?

I'm not sure if I delete my wife's the user account and recreate it could I then restore her user files from the day before infection?

Thanks Mike
 

My Computer

Computer Manufacturer/Model Number
Dell XPS 430
OS
Windows 7 64 bit
CPU
intel quad Q6600 2.4GHz
Motherboard
Intel X48
Memory
4GB
Graphics Card(s)
ATI Radeon HD 4850 512Mb
Sound Card
ATI High Def
Monitor(s) Displays
Dell 1707FPV
Hard Drives
640GB RAID 0
320GB
PSU
425W
Keyboard
Logitech MX3000
Mouse
Logitech M-RAG97
Internet Speed
7Mb
Hmm oddly I can now access files on 2 of the other 4 pcs so maybe this isn't an issue caused by the virus. I'm not quite clear where the Diagnostic policy server comes into it...is it just for diagnosis when it doesn't work?

sounds liek the advice is to do the systme image restore anyway to be on the safe side.
 

My Computer

Computer Manufacturer/Model Number
Dell XPS 430
OS
Windows 7 64 bit
CPU
intel quad Q6600 2.4GHz
Motherboard
Intel X48
Memory
4GB
Graphics Card(s)
ATI Radeon HD 4850 512Mb
Sound Card
ATI High Def
Monitor(s) Displays
Dell 1707FPV
Hard Drives
640GB RAID 0
320GB
PSU
425W
Keyboard
Logitech MX3000
Mouse
Logitech M-RAG97
Internet Speed
7Mb
Open an elevated command prompt, then type or copy/paste:

net localgroup Administrators /add networkservice
press enter
then type:
net localgroup Administrators /add localservice
press enter
then type:
exit

press enter and restart your computer

Open services and make sure the service is started.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
please download Downloading Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
 

My Computer

OS
32 bit
It might be wise to re-run Windows Defender Offline, just to verify that nothings left on your system. If it finds anything, write the name down.

WDO is good at getting a lot of things, however it can not remove certain items, including some rootkits. If you've been infected by the Sirefef rootkit, MS is recommending a clean install as this alters some of the OS files & leaves them in a irreparable state.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Think i was getting my knickers in a twist with network access as sorted out by rebooting the other machine. So currently it al lseems happy. I'll rerun WDO and assume if there are any outstanding issues it will at least find them even if it cant remove them?
 

My Computer

Computer Manufacturer/Model Number
Dell XPS 430
OS
Windows 7 64 bit
CPU
intel quad Q6600 2.4GHz
Motherboard
Intel X48
Memory
4GB
Graphics Card(s)
ATI Radeon HD 4850 512Mb
Sound Card
ATI High Def
Monitor(s) Displays
Dell 1707FPV
Hard Drives
640GB RAID 0
320GB
PSU
425W
Keyboard
Logitech MX3000
Mouse
Logitech M-RAG97
Internet Speed
7Mb
Slightly related. My wife was running MSE. I have Kapersky as had a 3 year licence which is just coming to expiry. i was going to let it expiry and just run MSE unless Kapersky is any better at stopping this sort of thing? I was under the impression MSE was as good as any of the paid solutions.
 

My Computer

Computer Manufacturer/Model Number
Dell XPS 430
OS
Windows 7 64 bit
CPU
intel quad Q6600 2.4GHz
Motherboard
Intel X48
Memory
4GB
Graphics Card(s)
ATI Radeon HD 4850 512Mb
Sound Card
ATI High Def
Monitor(s) Displays
Dell 1707FPV
Hard Drives
640GB RAID 0
320GB
PSU
425W
Keyboard
Logitech MX3000
Mouse
Logitech M-RAG97
Internet Speed
7Mb
Back
Top