We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide
remove System Security 2009 virus
DaveG247
Posts: 401 Forumite
in Techie Stuff
Hi All,
My dads seems to have installed System Security 2009 on his pc which I'm guessing a some sort of virus/malware and I need some advice on how to get rid of it.
I have malwarebytes installed which was recommended here last time I had a problem and normally does the trick, however not sure if it is the System Security 2009 programme but it will not run malwarebytes on the PC I've also tried add and remove programmes but this wont run either?
Any help would be much appreciated.
Dave
My dads seems to have installed System Security 2009 on his pc which I'm guessing a some sort of virus/malware and I need some advice on how to get rid of it.
I have malwarebytes installed which was recommended here last time I had a problem and normally does the trick, however not sure if it is the System Security 2009 programme but it will not run malwarebytes on the PC I've also tried add and remove programmes but this wont run either?
Any help would be much appreciated.
Dave
0
Comments
-
Cheers espresso,
Right forget what I just posted I've managed to get Malwarebytes updated and running on my dads pc had to change the name of the shortcut to lauch the programme, doing a scan now hopfully this should get rid of the problem.0 -
post the log file when its doneEx forum ambassador
Long term forum member0 -
post the log file when its done
Sorry Browntoa didn't see your post in time I did not make a copy of the log. However the problems now sorted there seems to be no sign of the problems I had before, malwarebytes cleared it no probs (once I got it running).
Cheers again for the help espresso0 -
Sorry Browntoa didn't see your post in time I did not make a copy of the log
Open Malwarebytes, select the 'Log' tab, select the appropriate date/time.Move along, nothing to see.0 -
Here's a copy of the log
Malwarebytes' Anti-Malware 1.37
Database version: 2229
Windows 5.1.2600 Service Pack 3
04/06/2009 18:52:08
mbam-log-2009-06-04 (18-52-08).txt
Scan type: Full Scan (C:\|)
Objects scanned: 139536
Time elapsed: 50 minute(s), 26 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 7
Memory Processes Infected:
C:\Documents and Settings\All Users\Application Data\10515374\10515374.exe (Rogue.Multiple.H) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SystemSecurity2009 (Rogue.Systemsecurity) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\10515374 (Rogue.Multiple.H) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\All Users\Application Data\10515374 (Rogue.Multiple.H) -> Quarantined and deleted successfully.
c:\documents and settings\D Goodhand\Start Menu\Programs\System Security (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
Files Infected:
c:\documents and settings\all users\application data\10515374\10515374.exe (Rogue.Multiple.H) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\10515374\10515374.glu (Rogue.Multiple.H) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\10515374\pc10515374cnf (Rogue.Multiple.H) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\10515374\pc10515374ins (Rogue.Multiple.H) -> Quarantined and deleted successfully.
c:\system volume information\_restore{35ec702a-3e28-47c7-ab8f-4a1b162adf44}\rp13\A0002142.sys (Rootkit.Agent.Z) -> Quarantined and deleted successfully.
c:\documents and settings\d goodhand\start menu\Programs\system security\System Security (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
c:\documents and settings\d goodhand\Desktop\System Security 2009.lnk (Rogue.SystemSecurity) -> Quarantined and deleted successfully.0 -
for belt and braces I would run this
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
looking at the type of infection you had
then post that log file as wellEx forum ambassador
Long term forum member0
This discussion has been closed.
Confirm your email address to Create Threads and Reply
Categories
- All Categories
- 353.5K Banking & Borrowing
- 254.1K Reduce Debt & Boost Income
- 455K Spending & Discounts
- 246.6K Work, Benefits & Business
- 602.9K Mortgages, Homes & Bills
- 178K Life & Family
- 260.5K Travel & Transport
- 1.5M Hobbies & Leisure
- 16K Discuss & Feedback
- 37.7K Read-Only Boards
