Home Malware Programs Rogue Anti-Spyware Programs Live Security Suite

Live Security Suite

Posted: May 14, 2010

Live Security Suite is a copy of older rogue anti-virus programs, only distinguished by a few minor graphical differences and a new name. Rogue programs in the Live Security Suite family will block various applications from being used to prevent you from deleting them, all the while simultaneously pretending to warn you about infections on your PC. However, Live Security Suite will actually create suspicious files to use as fake infection suspects and has no anti-virus capabilities. You should remove Live Security Suite and Live Security Suite's relatives with a real anti-malware program.

Live Security Suite – A Suite of Fake PC Security

The Live Security Suite group of rogue anti-virus programs also includes such members as Internet Antivirus, Internet Antivirus Pro, Personal Antivirus and General Antivirus. Each of these rogue security programs uses similar attacks although some variations may be more aggressive than others. Live Security Suite is infects new computers predominately through the use of fake online scanners that falsely warn you about an infection on your computer before offering you Live Security Suite or another rogue security program as a quick-fix download.

Live Security Suite will create a variety of inaccurate error messages to mislead you into believing that countless infections are on your PC. Some of Live Security Suite's false positive warnings include:

Live Security Suite has detected harmful software in your system. We strongly recommended you to register Live Security Suite to remove these threats immediately.

Your PC is still infected with dangerous viruses. It is strongly recommended to activate anti-virus protection to prevent data loss and to avoid the theft of your credit card details. Click here to activate protection.

Tracking cookies that steal your passwords, accounts and credit card information have been detected in your system. Click here to remove them immediately with Live Security Suite.

System files modification alert!
Some critical system files of your computer were modified by malicious program. It may cause system instability and data loss. Click here to block unauthorized modification by removing threats (Recommended).

Privacy Violation alert!
Live Security Suite detected a Privacy Violation. A program is secretly sending your private data to an untrusted Internet host. Click here to block this activity by removing the threat (Recommended).

Spyware activity alert!
Spyware.BrowserDeath activity detected. This kind of spyware is attempts to steal passwords from Internet Explorer, Mozilla Firefox, Opera and other programs, including logins and passwords from online banking sessions, eBay, PayPal, etc.

Intercepting programs that may compromise your privacy and harm your system have been detected on your PC. Click here to remove it immediately with Live Security Suite.

Just like most other rogue security programs, Live Security Suite only fakes security features without really having them – if you see junk files on your PC that look like Trojan s or viruses, it's because Live Security Suite created them explicitly for that purpose. Likewise, you shouldn't be worried about any of the infections that Live Security Suite tells you that your PC has.

What Live Security Suite Really Does to Your Computer

In addition to making up infections to force you to spend money on fake security software, Live Security Suite is also likely to:

  • Hijack your web browser to send you to dangerous websites or stop you from browsing safe websites.
  • Block the use of various applications. Anti-virus scanners and even basic Windows utilities like MSConfig and Task Manager may be unavailable.
  • Launch itself without your permission whenever Windows starts, thus putting Live Security Suite into an unpleasantly convenient position to perform the two attacks listed above.

You should try Safe Mode, boot an operating system from a removable device, or switch to a pre-installed non-Windows operating system to stop Live Security Suite from launching itself. Once this is done, all that remains is to give your PC a complete scan with your preferred anti-malware software. Make sure that you have all necessary updates before you scan, and try to verify that Live Security Suite isn't active.

Keeping these things in mind will help you get rid of Live Security Suite without any complications.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\Live Security Suite
    2 %UserProfile%\Application Data\Live Security Suite\db
    3 %UserProfile%\Application Data\Live Security Suite\db\config.cfg
    4 %UserProfile%\Application Data\Live Security Suite\db\Timeout.inf
    5 %UserProfile%\Application Data\Live Security Suite\db\Urls.inf
    6 %UserProfile%\Application Data\Live Security Suite\settings.ini
    7 %UserProfile%\Application Data\Live Security Suite\uill.ini
    8 %UserProfile%\Application Data\Live Security Suite\unins000.exe
    9 %UserProfile%\Application Data\Live Security Suite\Uninstall Live Security Suite.lnk
    10 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Live Security Suite.lnk
    11 %UserProfile%\Desktop\Live Security Suite.lnk
    12 %UserProfile%\Desktop\LiveSS.exe.txt
    13 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iGSh.png
    14 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iMSh.png
    15 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iPSh.png
    16 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
    17 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe
    18 c:\Documents and Settings\All Users\Desktop\Live Security Suite.lnk
    19 c:\Documents and Settings\All Users\Start Menu\Programs\Live Security Suite
    20 c:\Documents and Settings\All Users\Start Menu\Programs\Live Security Suite\Live Security Suite Home Page.lnk
    21 c:\Documents and Settings\All Users\Start Menu\Programs\Live Security Suite\Live Security Suite.lnk
    22 c:\Documents and Settings\All Users\Start Menu\Programs\Live Security Suite\Purchase Licence.lnk
    23 c:\Documents and Settings\All Users\Start Menu\Programs\Live Security Suite\Purchase License.lnk
    24 c:\Program Files\Live Security Suite
    25 c:\Program Files\Live Security Suite\activate.ico
    26 c:\Program Files\Live Security Suite\db
    27 c:\Program Files\Live Security Suite\db\DBInfo.ver
    28 c:\Program Files\Live Security Suite\db\ia080614.db
    29 c:\Program Files\Live Security Suite\db\lists.ini
    30 c:\Program Files\Live Security Suite\db\WMILib.dll
    31 c:\Program Files\Live Security Suite\Explorer.ico
    32 c:\Program Files\Live Security Suite\Languages
    33 c:\Program Files\Live Security Suite\LiveSS.exe
    34 c:\Program Files\Live Security Suite\unins000.dat
    35 c:\Program Files\Live Security Suite\uninstall.ico
    36 c:\Program Files\Live Security Suite\working.log

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Live Security SuiteHKEY_CURRENT_USER\Software\Microsoft\FTP "SearchDir" = "C:\Program Files\Live Security Suite\"HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PrS" = "http://gen-avpay.com/choose/?productid=GENAV3&uid=0&machineid=c3f92274b4b15694ae2311bd2316c727"HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "uniname" = "Live Security Suite_is1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Live Security Suite"HKEY_LOCAL_MACHINE\SOFTWARE\Live Security SuiteHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AVPath" = "\\.\root\SecurityCenter:AntiVirusProduct.instanceGuid="{653E64F8-62B6-4F96-B22D-4FFC6E44130E}"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallDisableNotify" = "0"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirstRunDisabled" = "0"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "UpdatesDisableNotify" = "0"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent "URLSS[2.0.3.0]"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Live Security Suite_is1

Additional Information on Live Security Suite

  • The following messages's were detected:
    # Message
    1 Internet Explorer has closed this webpage to help protect your computer.
    A malfunctioning or malicious add-on has caused Internet Explorer to close this webpage.
    2 Live Security Suite has detected harmful software in your system. We strongly recommended you to register Live Security Suite to remove these threats immediately.
    3 Privacy Violation alert!
    Live Security Suite detected a Privacy Violation. A program is secretly sending your private data to an untrusted internet host. Click here to block this activity by removing the threat (Recommended).
    4 Spyware activity alert!
    Spyware.BrowserDeath activity detected. This kind of spyware is attempts to steal passwords from Internet Explorer, Mozilla Firefox, Opera and other programs, including logins and passwords from online banking sessions, eBay, PayPal, etc.
    5 System files modification alert!
    Some critical system files of your computer were modified by malicious program. It may cause system instability and data loss. Click here to block unauthorized modification by removing threats (Recommended).
    6 Live Security Suite has found %Found% viruses on your computer. It is recommended to disinfect files as soon as possible.
    7 Your PC is still infected with dangerous viruses. It is strongly recommended to activate antivirus protection to prevent data loss and to avoid the theft of your credit card details. Click here to activate protection.
    8 Tracking cookies that steal your passwords, accounts and credit card information have been detected in your system. Click here to remove them immediately with Live Security Suite.
    9 Intercepting programs that may compromise your privacy and harm your system have been detected on your PC. Click here to remove it immediately with Live Security Suite.
    10 Self restoring Trojan virus that can lead to total system crash has been detected on your PC. Click here to remove this harmful virus immediately with Live Security Suite.
    11 Malicious spyware that can harm your system has been detected on your PC. Click here to remove this riskware immediately with Live Security Suite.

Related Posts

3 Comments

  • pashajoje@cs.com says:

    I got this virus on my laptop last night. When I tried to go on line on my laptop this morning, this popup will not allow me to do anything. I can access My Computer, but not sure how far I can go with oponing folders. How can I remove this virus since I cannot get on line to download the spyware?

  • Mafiadogg says:

    The virus will usually prohibit you from accessing the internet or downloading anything from the internet. To go around this, boot your computer and press f8. you will prompted with various bootup options. choose 'safemode with networking'. thren continue starting up ur computer normally. log on to the file you recieved the virus. open internet explorer. go to tools>internet options>connections>LAN settings> a nd uncheck the box that says 'use a proxy server...'. then log onto the internet while still in safemode. it should allow you to access the internet and download files. if it still does not let you, then you need to download the file from a different computer to a cd or some sort of drive
    hope this helps 🙂

  • Tom Eldershaw says:

    I am trying to repair a friends computer that has this crap on it. Live Security Suite will not allow me to install any malware removal programs, use task manager, or the command prompt. Is there a program that I can install at bootup and run before all the other stuff loads? Thanks in advance.

Loading...