If you are reading this article than you’re most likely trying to find out, what Live Security Platinum is and how you can get rid of this virus.
As you’ve probably realized by now,Live Security Platinum is a malicious software (rogue security software) that is displaying bogus antivirus alerts in an attempt to scare you into buying this fake security product.
Live Security Platinum is also blocking you from running programs and is causing browser redirects and slowing down your PC.
Live Security Platinum Images
Below you can see some images of Live Security Platinum.
![Live Security Platinum virus [Image: Live Security Platinum virus]](http://malwaretips.com/blogs/wp-content/uploads/2012/06/Live-Security-Platinum-2.png)
![Live Security Platinum fake alert [Image: Live Security Platinum Alert]](http://malwaretips.com/blogs/wp-content/uploads/2012/06/Live-Security-Platinum-4.png)
![Live Security Platinum activation [Image: Live Security Platinum Activation request]](http://malwaretips.com/blogs/wp-content/uploads/2012/06/Live-Security-Platinum-3.png)
![Live Security Platinum fake warning [Image: Live Security Platinum Warning]](http://malwaretips.com/blogs/wp-content/uploads/2012/06/Live-Security-Platinum-1.png)
Registration codes for Live Security Platinum
As an optional step,you can use the following license key to register Live Security Platinum and stop the fake alerts.
AA39754E-715219CE
Please keep in mind that entering the above registration code will NOT remove Live Security Platinum from your computer , instead it will just stop the fake alerts so that you’ll be able to complete our removal guide more easily.
Live Security Platinum Removal Instructions
STEP 1 : Start your computer in Safe Mode with Networking
- Remove all floppy disks, CDs, and DVDs from your computer, and then restart your computer.
- Press and hold the F8 key as your computer restarts.Please keep in mind that you need to press the F8 key before the Windows start-up logo appears.
Note: With some computers, if you press and hold a key as the computer is booting you will get a stuck key message. If this occurs, instead of pressing and holding the “F8 key”, tap the “F8 key” continuously until you get the Advanced Boot Options screen. - On the Advanced Boot Options screen, use the arrow keys to highlight Safe Mode with Networking , and then press ENTER.
![Safe Mode with Networking screen [Image: Safemode.jpg]](//malwaretips.com/images/removalguide/safemode.jpg)
STEP 2: Remove Live Security Platinum malicious proxy server
Live Security Platinum may add a proxy server which prevents the user from accessing the internet,follow the below instructions to remove the proxy.
- Start the Internet Explorer browser and if you are using Internet Explorer 9 ,click on the gear icon
(Tools for Internet Explorer 8 users) ,then select Internet Options.
![Internet Options in IE [Image: Internet-options-IE.png]](//malwaretips.com/images/removalguide/ie1.png)
- Go to the tab Connections.At the bottom, click on LAN settings.
![Connections tab in Internet Explorer [Image: Remove-proxy-server2.png]](//malwaretips.com/images/removalguide/ie2.png)
- Uncheck the option Use a proxy server for your LAN. This should remove the malicious proxy server and allow you to use the internet again.
![Uncheck the option Use a proxy server for your LAN [Image: Remove-proxy-server3.png]](//malwaretips.com/images/removalguide/ie3.png)
If you are a Firefox users, go to Firefox(upper left corner) → Options → Advanced tab → Network → Settings → Select No Proxy
STEP 3: Repair your Windows Registry from Live Security Platinum malicious changes.
Smart Fortress 2012 has changed your Windows registry settings so that when you try to run a executable file (ending with .exe ) , it will instead launch the infection rather than the desired program.
- Download the registryfix.reg file to fix the malicious registry changes from Live Security Platinum.
REGISTRYFIX.REG DOWNLOAD LINK (This link will automatically download the registry fix called registryfix.reg) - Double-click on registryfix.reg file to run it. Click “Yes” for Registry Editor prompt window,then click OK.
![Remove Live Security Platinum (TUTORIAL) 1 [Image: fix registry]](//malwaretips.com/blogs/wp-content/uploads/2011/12/registry.png)
STEP 4: Run RKill to terminate known malicious processes associated with Live Security Platinum.
RKill is a program that will attempt to terminate all malicious processes associated with Live Security Platinum,so that we will be able to perform the next step without being interrupted by this malicious software.
Because this utility will only stop Live Security Platinum running process, and does not delete any files, after running it you should not reboot your computer as any malware processes that are configured to start automatically will just be started again.
- While your computer is in Safe Mode with Networking ,please download the latest official version of RKill.Please note that we will use a renamed version of RKILL so that Live Security Platinum won’t block this utility from running.
RKILL DOWNLOAD LINK (This link will automatically download RKILL renamed as iExplore.exe) - Double-click on the iExplore.exe icon in order to automatically attempt to stop any processes associated with Live Security Platinum.
![RKILL ICON [Image: run-rkill-1.png]](//malwaretips.com/images/removalguide/rkill1.png)
- RKill will now start working in the background, please be patient while the program looks for various malware programs and tries to terminate them.
![RKILL Command prompt [Image: run-rkill-2.png]](//malwaretips.com/images/removalguide/rkill2.png)
IF you are having problems starting or running RKill, you can download any other renamed versions of RKill from here. - When Rkill has completed its task, it will generate a log. You can then proceed with the rest of the guide.
![RKILL LOG [Image: Live Security Platinum rkill3.jpg]](//malwaretips.com/images/removalguide/rkill3.png)
WARNING: Do not reboot your computer after running RKill as the malware process will start again , preventing you from properly performing the next step.
STEP 5: Remove Live Security Platinum malicious files with Malwarebytes Anti-Malware FREE
- Download the latest official version of Malwarebytes Anti-Malware FREE.
MALWAREBYTES ANTI-MALWARE DOWNLOAD LINK (This link will open a download page in a new window from where you can download Malwarebytes Anti-Malware Free) - Start the Malwarebytes’ Anti-Malware installation process by double clicking on mbam-setup file.
![Malwarebytes Anti-Malware Installer [Image: Malwarebytes Installer]](//malwaretips.com/images/removalguide/malwarebytes-setup.png)
- When the installation begins, keep following the prompts in order to continue with the setup process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware checked. Then click on the Finish button. If Malwarebytes’ prompts you to reboot, please do not do so.
![Malwarebytes last setup screen [Image: Finishing Malwarebytes installation]](//malwaretips.com/images/removalguide/update-malwarebytes.png)
- Malwarebytes Anti-Malware will now start and you’ll be prompted to start a trial period , please select ‘Decline‘ as we just want to use the on-demand scanner.
- On the Scanner tab,select Perform full scan and then click on the Scanbutton to start scanning your computer.
![Perform a Full System Scan with Malwarebytes Anti-Malware [Image: Starting a full system sca]](//malwaretips.com/images/removalguide/start-scan-malwarebytes.png)
- Malwarebytes’ Anti-Malware will now start scanning your computer for Live Security Platinum malicious files as shown below.
![Malwarebytes Anti-Malware scanning for Live Security Platinum [Image: Malwarebytes scanning for malicious files]](//malwaretips.com/images/removalguide/scan-malwarebytes.png)
- When the scan is finished a message box will appear, click OK to continue.
![Malwarebytes when the system scan has finished [Image: Malwarebytes scan results]](//malwaretips.com/images/removalguide/results-malwarebytes.png)
- You will now be presented with a screen showing you the malware infections that Malwarebytes’ Anti-Malware has detected.Please note that the infections found may be different than what is shown in the image.Make sure that everything is Checked (ticked) and click on the Remove Selectedbutton.
![Removing the infections found by Malwarebytes [Image: Infections found by Malwarebytes]](//malwaretips.com/images/removalguide/detection-malwarebytes.png)
- Malwarebytes’ Anti-Malware will now start removing the malicious files.After completing this task it will display a message stating that it needs to reboot,please allow this request and then let your PC boot in Normal mode.
STEP 6: Double check your system for any left over infections with HitmanPro
- This step can be performed in Normal Mode ,so please download the latest official version of HitmanPro.
HITMANPRO DOWNLOAD LINK(This link will open a download page in a new window from where you can download HitmanPro) - Double click on the previously downloaded fileto start the HitmanPro installation.
![HitmanPro Installer [Image: hitmanpro-icon.png]](//malwaretips.com/images/removalguide/hpro1.png)
IF you are experiencing problems while trying to starting HitmanPro, you can use the “Force Breach” mode.To start this program in Force Breach mode, hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including the malware process. (How to start HitmanPro in Force Breach mode – Video) - Click on Next to install HitmanPro on your system.
![HitmanPro installation process [Image: installing-hitmanpro.png]](//malwaretips.com/images/removalguide/hpro2.png)
- The setup screen is displayed, from which you can decide whether you wish to install HitmanPro on your machine or just perform a one-time scan, select a option then click on Next to start a system scan.
![HitmanPro setup options [Image: hitmanpro-setup-options.png]](//malwaretips.com/images/removalguide/hpro3.png)
- HitmanPro will start scanning your system for malicious files. Depending on the size of your hard drive, and the performance of your computer, this step will take several minutes.
![HitmanPro scanning for Live Security Platinum [Image: hitmanpro-scanning.png]](//malwaretips.com/images/removalguide/hpro4.png)
- Once the scan is complete,a screen displaying all the malicious files that the program found will be shown as seen in the image below.After reviewing each malicious object click Next.
![HitmanPro Live Security Platinum scan results [Image: hitmanpro-scan-results.png]](//malwaretips.com/images/removalguide/hpro5.png)
- Click Activate free license to start the free 30 days trial and remove the malicious files.
![Activate HitmanPro free license to remove detected infections [Image: hitmanpro-activation.png]](//malwaretips.com/images/removalguide/hpro6.png)
- HitmanPro will now start removing the infected objects, and in some instances, may suggest a reboot in order to completely remove the malware from your system. In this scenario, always confirm the reboot action to be on the safe side.
![Safe Mode with Networking screen [Image: Safemode.jpg]](http://malwaretips.com/images/removalguide/safemode.jpg)
![Internet Options in IE [Image: Internet-options-IE.png]](http://malwaretips.com/images/removalguide/ie1.png)
![Connections tab in Internet Explorer [Image: Remove-proxy-server2.png]](http://malwaretips.com/images/removalguide/ie2.png)
![Uncheck the option Use a proxy server for your LAN [Image: Remove-proxy-server3.png]](http://malwaretips.com/images/removalguide/ie3.png)
![Remove Live Security Platinum (TUTORIAL) 1 [Image: fix registry]](http://malwaretips.com/blogs/wp-content/uploads/2011/12/registry.png)
![RKILL ICON [Image: run-rkill-1.png]](http://malwaretips.com/images/removalguide/rkill1.png)
![RKILL Command prompt [Image: run-rkill-2.png]](http://malwaretips.com/images/removalguide/rkill2.png)
![RKILL LOG [Image: Live Security Platinum rkill3.jpg]](http://malwaretips.com/images/removalguide/rkill3.png)
![Malwarebytes Anti-Malware Installer [Image: Malwarebytes Installer]](http://malwaretips.com/images/removalguide/malwarebytes-setup.png)
![Malwarebytes last setup screen [Image: Finishing Malwarebytes installation]](http://malwaretips.com/images/removalguide/update-malwarebytes.png)
![Perform a Full System Scan with Malwarebytes Anti-Malware [Image: Starting a full system sca]](http://malwaretips.com/images/removalguide/start-scan-malwarebytes.png)
![Malwarebytes Anti-Malware scanning for Live Security Platinum [Image: Malwarebytes scanning for malicious files]](http://malwaretips.com/images/removalguide/scan-malwarebytes.png)
![Malwarebytes when the system scan has finished [Image: Malwarebytes scan results]](http://malwaretips.com/images/removalguide/results-malwarebytes.png)
![Removing the infections found by Malwarebytes [Image: Infections found by Malwarebytes]](http://malwaretips.com/images/removalguide/detection-malwarebytes.png)
![HitmanPro Installer [Image: hitmanpro-icon.png]](http://malwaretips.com/images/removalguide/hpro1.png)
![HitmanPro installation process [Image: installing-hitmanpro.png]](http://malwaretips.com/images/removalguide/hpro2.png)
![HitmanPro setup options [Image: hitmanpro-setup-options.png]](http://malwaretips.com/images/removalguide/hpro3.png)
![HitmanPro scanning for Live Security Platinum [Image: hitmanpro-scanning.png]](http://malwaretips.com/images/removalguide/hpro4.png)
![HitmanPro Live Security Platinum scan results [Image: hitmanpro-scan-results.png]](http://malwaretips.com/images/removalguide/hpro5.png)
![Activate HitmanPro free license to remove detected infections [Image: hitmanpro-activation.png]](http://malwaretips.com/images/removalguide/hpro6.png)
Thanks Stelian!Got this virus from an email attachment, your guide saved my PC.
Thank you! It worked perfectly for me!
My Dell has been infected with Live Security Platinum, bringing in its train (apparently) Symantec Proxy Email Virus. I followed all the steps above without problems, and threats or traces were removed at each point. After the Emsisoft scan finished, I rebooted, but now am unable to get past the Welcome page. When I click my user icon, the Windows XP just closes down. I have tried opening in Safe Mode, with the same result. Can you advise? I have not yet been able to check whether the viruses have gone or not – and maybe I have a new one, now!
Hello,
You most likely had a Zero Access rootkit on your system,which infected one of your Windows drivers……
Do you have the Windows XP CD?If yes, then perform a System Repair a seen on this video : http://www.youtube.com/watch?v=KNOQ0sCYY8s
Thanks for that, it all worked except at the very end it didnt come up with the activate free licsense option on hit man pro.
I’ll comment to the HitmanPro developers for analysis… In the mean time , you can perform a scan with Emsisoft Anti-Malware…
Perform a system scan with Emsisoft Anti-Malware:
Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
If during the removal process Emsisoft will display a message stating that it needs to reboot, please allow this request.
PLEASE HELP!!!! I am a technologically challenged teacher and have attempted to do all the things you have suggested but nothing will download and it refuses to allow me on the internet in “safe mode with netoworking”. It keeps telling me my current security settings won’t allow me to download the programmes you’ve suggested! I am at my wits end! I desperately need to do work and can not get rid of this malware!!!! :( :(
Please follow the below instructions:
STEP 1 : While in NORMAL MODE,download HitmanPro and then start this program in ForceBreach Mode
1.Here are the direct download links for HitmanPro,
– http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
– http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including this rogue malicious process
Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
3. Let HitmanPro scan and remove all the detected threats.
STEP 2: Download/Run Rkill and then run a scan with Malwarebytes.
1.Download any re-named version of Rkill (direct download links bellow):
http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
http://download.bleepingcomputer.com/grinler/rkill.scr
2.Next,please perform a scan with Malwarebytes as seen on the guide.
STEP3 : Perform a system scan with Emsisoft Anti-Malware:
Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
If during the removal process Emsisoft will display a message stating that it needs to reboot, please allow this request.
Thank you, but it still comes up with “your current security settings will not allow you to perform this function” every time I try download HitManPro. It will not let me watch the tutorial on YouTube at all. :( What else can I do?!?!?!?!
1.Run the below registry fix!
A.Copy all the text in bold below and paste to Notepad/Text Document
B.THIS IS VERY IMPORTANT! Save file as fix.reg to your Desktop. NOTE: (Save as type: All files)
C. Double-click on fix.reg file to run it. Click “Yes” for Registry Editor prompt window. Then click OK.
NEXT,
1.Download any re-named version of Rkill (direct download links bellow):
http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
http://download.bleepingcomputer.com/grinler/rkill.scr
2.Next,please perform a scan with Malwarebytes as seen on the guide.
3. : Perform a system scan with Emsisoft Anti-Malware as seen on my previous reply!
I have attempted to follow your instructions but the virus keeps blocking all attempts to open any of the downloads to fix the problem
Is there something else I can try?
OPTION 1 : While in NORMAL MODE,download HitmanPro and then start this program in ForceBreach Mode
1.Here are the direct download links for HitmanPro,
– http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
– http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including this rogue malicious process
Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
3. Let HitmanPro scan and remove all the detected threats.
VERY IMPORTANT!: When HitmanPro will detect the infections, make sure that they aren’t false possitive or compromised critical system files before removing them!I’m saying this because usually when you can’t connect to the internet while in Safe Mode with Networking could mean that you have other infections besides this Smart HDD Rogue.
4.Run Rkill and then a scan with Malwarebytes.
OPTION 2: While in NORMAL MODE,download/Run Rkill and then run a scan with Malwarebytes.
1.Download any re-named version of Rkill (direct download links bellow):
http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
http://download.bleepingcomputer.com/grinler/rkill.scr
2.Next,please perform a scan with Malwarebytes as seen on the guide and then a scan with HitmanPro.
Let me know , how everything goes!
Thank you so much! That dumb virus was really annoying me, and this helped alot!
i can not connect to the internet while in network safe mode…. plz help me
OPTION 1 : While in NORMAL MODE,download HitmanPro and then start this program in ForceBreach Mode
1.Here are the direct download links for HitmanPro,
– http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
– http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including this rogue malicious process
Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
3. Let HitmanPro scan and remove all the detected threats.
VERY IMPORTANT!: When HitmanPro will detect the infections, make sure that they aren’t false possitive or compromised critical system files before removing them!I’m saying this because usually when you can’t connect to the internet while in Safe Mode with Networking could mean that you have other infections besides this Smart HDD Rogue.
4.Run Rkill and then a scan with Malwarebytes.
OPTION 2: While in NORMAL MODE,download/Run Rkill and then run a scan with Malwarebytes.
1.Download any re-named version of Rkill (direct download links bellow):
http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
http://download.bleepingcomputer.com/grinler/rkill.scr
2.Next,please perform a scan with Malwarebytes as seen on the guide and then a scan with HitmanPro.
Let me know , how everything goes!
thank you so much it’s worked
Stay safe!:D
much easier. Trash your computer with windows and buy a new one with linux, mac osx or something better. You would do a favor to the rest of the world.
so far seems to have worked perfectly – thanks so much for making this fix publicly available and best of all free
It worked for me thank you..
Worked a treat!
Thanks.
Hi i followed as shown above and when i run the renamed verion of rkill it says “C:/Users/xxxx/AppData/Local/Temp/RarSFX0 folder is not accessible Please Help.
Hello,
Try this :
Option 1 : Try to download a different named Rkill (direct download links bellow):
http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
http://download.bleepingcomputer.com/grinler/rkill.scr
And then follow the guide starting with the Malwarebytes scan.
If that doesn’t work please try to do this:
Option 2: Download HitmanPro and then start this program in ForceBreach Mode
1.Here are the direct download links for HitmanPro,
– http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
– http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including this rogue malicious process
Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
3. If it start ,let it scan and remove all the detected threats , then perform a scan with Malwarebytes.
If you are still experiencing problems , start a thread in our Malware Removal Support forum : http://malwaretips.com/Forum-Help-my-PC-is-infected
Thank you!Worked perfectly :party:
im having slight problems doing the remove live security platinum. its seemed to have stopped on 14,22s and crashed or frozen. its not responding and the mouse seems to manover very slowley?
thanks
Jase
Hello,
Did you run RKILL before starting the scan?
Give the Malwarebytes scan some time to complete (around 1-2 hours) if the problem persist , stop this scan and then start a HitmanPro scan.
After you’ve removed all the detected threats by HitmanPro , please re-scan with Malwarebytes.
I’ll wait for your reply , and help you if need it.
Good luck:)
Hi, Thanks for the easy to follow guide, really useful.
Is it best practice to do the Emsisoft scan following the normal procedure anyway?
G
It doesn’t hurt to do it…. Malwarebytes and HitmanPro should have completely remove this rogue antivirus, however if you want to do another check , then you can go ahead and go a scan with Emsisoft.
Stay safe!
YOU THE MAN!
Great tutorial!! Just followed the directions and that crap is gone from my comp. Screw you geek squad (150 bucks my ass)!!! Thanks!
+1 :D
Stay safe!
I followed the above instructions to remove Live Security Platinum from my wife’s home PC last night, and it appeared to have worked…both Malwarebytes and HitmanPro detected and deleted items. This morning my wife was using using Firefox and logged into her Google account and whenever she would perform a search and click on a link it would redirect her to a different site, but when she logged out of Google it wouldn’t do that. She just called to inform me that Live Security Platinum appeared again on the PC. The only two sites she was on was Facebook and Google. I am at a loss and I don’t understand how Live Security Platinum can still be on the system after following all of the instructions above. I would greatly appreciate any suggestions or advice you may have as to what I can do to repair this problem.
Hello Joel,
Please re-scan your computer with Malwarebytes and HitmanPro.
Next , perform a system scan with Emsisoft Anti-Malware:
Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
If during the removal process Emsisoft will display a message stating that it needs to reboot, please allow this request.
If you are still experiencing problems , start a thread in our Malware Removal Support forum : http://malwaretips.com/Forum-Malware-Removal-Assistance
I feel a bit of a muppet about how I let this get onto my system. Thanks for your help.