We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

remove System Security 2009 virus

Hi All,

My dads seems to have installed System Security 2009 on his pc which I'm guessing a some sort of virus/malware and I need some advice on how to get rid of it.

I have malwarebytes installed which was recommended here last time I had a problem and normally does the trick, however not sure if it is the System Security 2009 programme but it will not run malwarebytes on the PC I've also tried add and remove programmes but this wont run either?

Any help would be much appreciated.

Dave

Comments

  • espresso
    espresso Posts: 16,448 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker
    Download malwarebytes again from here and change the file name before you try to run the program e.g. change to daveg247.exe

    You need the latest version anyway.
    :doh: Blue text on this forum usually signifies hyperlinks, so click on them!..:wall:
  • DaveG247
    DaveG247 Posts: 401 Forumite
    Part of the Furniture 100 Posts Combo Breaker
    edited 4 June 2009 at 5:07PM
    Cheers espresso,

    Right forget what I just posted I've managed to get Malwarebytes updated and running on my dads pc had to change the name of the shortcut to lauch the programme, doing a scan now hopfully this should get rid of the problem.
  • Browntoa
    Browntoa Posts: 49,619 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    post the log file when its done
    Ex forum ambassador

    Long term forum member
  • DaveG247
    DaveG247 Posts: 401 Forumite
    Part of the Furniture 100 Posts Combo Breaker
    Browntoa wrote: »
    post the log file when its done

    Sorry Browntoa didn't see your post in time I did not make a copy of the log. However the problems now sorted there seems to be no sign of the problems I had before, malwarebytes cleared it no probs (once I got it running).

    Cheers again for the help espresso
  • spud17
    spud17 Posts: 4,451 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Sorry Browntoa didn't see your post in time I did not make a copy of the log

    Open Malwarebytes, select the 'Log' tab, select the appropriate date/time.
    Move along, nothing to see.
  • DaveG247
    DaveG247 Posts: 401 Forumite
    Part of the Furniture 100 Posts Combo Breaker
    Here's a copy of the log

    Malwarebytes' Anti-Malware 1.37
    Database version: 2229
    Windows 5.1.2600 Service Pack 3
    04/06/2009 18:52:08
    mbam-log-2009-06-04 (18-52-08).txt
    Scan type: Full Scan (C:\|)
    Objects scanned: 139536
    Time elapsed: 50 minute(s), 26 second(s)
    Memory Processes Infected: 1
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 2
    Files Infected: 7
    Memory Processes Infected:
    C:\Documents and Settings\All Users\Application Data\10515374\10515374.exe (Rogue.Multiple.H) -> Unloaded process successfully.
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SystemSecurity2009 (Rogue.Systemsecurity) -> Quarantined and deleted successfully.
    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\10515374 (Rogue.Multiple.H) -> Quarantined and deleted successfully.
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    C:\Documents and Settings\All Users\Application Data\10515374 (Rogue.Multiple.H) -> Quarantined and deleted successfully.
    c:\documents and settings\D Goodhand\Start Menu\Programs\System Security (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
    Files Infected:
    c:\documents and settings\all users\application data\10515374\10515374.exe (Rogue.Multiple.H) -> Quarantined and deleted successfully.
    c:\documents and settings\all users\application data\10515374\10515374.glu (Rogue.Multiple.H) -> Quarantined and deleted successfully.
    c:\documents and settings\all users\application data\10515374\pc10515374cnf (Rogue.Multiple.H) -> Quarantined and deleted successfully.
    c:\documents and settings\all users\application data\10515374\pc10515374ins (Rogue.Multiple.H) -> Quarantined and deleted successfully.
    c:\system volume information\_restore{35ec702a-3e28-47c7-ab8f-4a1b162adf44}\rp13\A0002142.sys (Rootkit.Agent.Z) -> Quarantined and deleted successfully.
    c:\documents and settings\d goodhand\start menu\Programs\system security\System Security (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
    c:\documents and settings\d goodhand\Desktop\System Security 2009.lnk (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
  • Browntoa
    Browntoa Posts: 49,619 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    for belt and braces I would run this

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    looking at the type of infection you had

    then post that log file as well
    Ex forum ambassador

    Long term forum member
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.1K Reduce Debt & Boost Income
  • 455K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 602.9K Mortgages, Homes & Bills
  • 178K Life & Family
  • 260.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.