republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
1234
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies


justhijacked

@tm.net.my

help advise on Live Security Platinum

Live Security Platinum is a new rogue antivirus program that belongs to the same family of rogues as Security Shield and Security Tool, which are known for their nasty activities for a long time now.

One of my Laptop recently got infected with Live Security Platinum . I managed to clean up the rouge software with

Malwarebytes Anti-Malware and doubled checked with HitmanPro malware scanner to determine the laptop is free from malware. Results seems to prove that it got rid of the thread but I am still very worried as another Laptop of mine which are not infected got the infection .

I need help in advise how this rouge software is spreads?

I have read online that it can be spread by changing usb drives from one infected pc to a non infected. But in my case I do not think changing usb drives is the cause.

I have also read from online that it can spreads from :-
A computer hijack occurs when an attacker takes control of a computer system and exploits it. There are a number of ways computer hijacks can occur; most involve a network connection

Can this Live security Platinum really spreads through network connection as I can find changing usb drives is not the caused as all my usb drives are free from malware.

Please any help in regards to how it spreads is appreciated,

I am worried to open my third Laptop as one Laptop got infected with no apparent obvious reason.

Pls advise how the hijackers able to get to my other good Laptop? as this questions is still a mystery to me.

I am able to clean both Laptops of the rouge software, but what I am concern is hijack through network connection.

Are the hackers still able to trace my pc and hijack it again even after I clean up the rouge security software?

Pls help advise what should I do know as I am afraid to open my other pcs and laptops as one of my laptop just got the infection for no apparent reason. Also I am afraid of my online passwords and paypal passwords will get stolen.

Please help advise as I am fully concern how the hell this damn thing spreads . Any help will be appreciated from a computer expert.

Thanks


NormanS
Premium,MVM
join:2001-02-14
San Jose, CA
kudos:9
Reviews:
·SONIC.NET
·Pacific Bell - SBC

Microsoft's own site has some good advice:

quote:
Prevention
Take the following steps to help prevent infection on your computer:
Enable a firewall on your computer.
Get the latest computer updates for all your installed software.
Use up-to-date antivirus software.
Limit user privileges on the computer.
Use caution when opening attachments and accepting file transfers.
Use caution when clicking on links to webpages.
Avoid downloading pirated software.
Protect yourself against social engineering attacks.
Use strong passwords.

From:

»www.microsoft.com/security/porta···Platinum

I expect that using Limited User Accounts in a multi-user environment should mitigate the rogue; if the users are not allowed Admin privilege. Especially given that a visit to a compromised web site might throw a "Scan your computer now!" pop-up, which could suck a naive user into installation of the rogue.
--
Norman
~Oh Lord, why have you come
~To Konnyu, with the Lion and the Drum


Cudni
La Merma - Vigilado
Premium,MVM
join:2003-12-20
Someshire
kudos:13

said by NormanS:

I expect that using Limited User Accounts in a multi-user environment should mitigate the rogue;

Absolutely and it makes removal easer

Cudni
--
"what we know we know the same, what we don't know, we don't know it differently."
Help yourself so God can help you.
Microsoft MVP, 2006 - 2012/13

redwolfe_98
Premium
join:2001-06-11
kudos:1

3 edits

reply to justhijacked
justhijacked, it would help if you used a secure browser.. with "internet explorer," that would mean using high security-settings for the "internet zone" and the "intranet zone".. with "firefox" it would mean using "firefox" with the "noscript" addon..

using "firefox" with the "noscript" addon is what i would recommend rather than using "internet explorer" with high security-settings.. it is a lot easier to allow "scripting", when needed, when using "firefox" with the "noscript" addon than it is to add websites to IE's "trusted sites" zone, but that is an option..

i used IE, with high security-settings, for years, but i switched to using "firefox" a couple of years ago (after microsoft took too long to patch a vulnerability in IE, though it was finally patched, about a week after i switched to using "firefox" ).. still, like i said, using "firefox" with the "noscript" addon is a lot easier than using IE, with high security-settings..

also, i would recommend not having "java" installed.. most malware-infections, for the past couple of years, have been caused by java-exploits.. that is likely how your computers were infected with malware, by java-exploits ie by "blackhole exploit kits"..

another thing that might help would be to use the "foxit" PDF reader instead of using the "adobe" PDF reader.. if you are going to use the "adobe" PDF reader, i suppose that you should use the "X" version.. according to adobe, the "X" version of the "adobe" PDF reader has not been compromised, as far as they know..

like "java", the "adobe" PDF reader is another thing that is targetted by exploit kits, like the "blackhole exploit kit".. "foxit" says that their "foxit" PDF reader is not vulnerable to the same vulnerabilities that adobe has had to deal with, with their "adobe" PDF reader.. of course, the "foxit" PDF reader has to be patched, as needed, like every other program..

something else that you could consider would by using a program that can control the execution of files.. "faronics" "antiexecutable" is one such program but, from what i have heard, a lot of people have problems with using that program.. "EXE Radar", from "novirusthanks", is another program that can be used to control the execution of files, and it is not very expensive..

another option is..some firewall's apparently can control the execution of files.. "privatefirewall" is one.. i think that the "comodo" firewall also controls the execution of files.. there might be others, too, like maybe agnitum's "outpost" firewall.. from some posts that i saw in the "wilderssecurity forum", many people there tried using "EXE radar" and, apparently, it worked OK for them, but, from what they said, "privatefirewall" does the same thing so they just relied on "privatefirewall" to control the execution of files rather than using "EXE radar" along with it..

in my opinion, the internet is wrecked, with all of the bad stuff that is going on, with thousands of new "websites" (including hacked websites) popping up every day, distributing malware.. if anything, you need to use a browser that is secure, like "firefox" with the "noscript" addon..

p.s. i don't fool with google's "chrome" browser but, if you use it, from what i have heard, it has some security-settings buried somewhere deep within its settings-options.. so, if you use "chrome", my advice is to dig and dig and dig and dig until you find the security-settings and to adjust them for high-security, if possible..

p.p.s. "sandboxie" is another security-program that you could consider using..


Tuesday, 21-May 07:16:30 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 13.5 years online © 1999-2013 dslreports.com.
Most commented news this week
Hot Topics