Live Essential Platinum

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 25
First Seen: June 23, 2012
Last Seen: October 8, 2022
OS(es) Affected: Windows

Live Essential Platinum is a new addition to the WinWebSec family of malware. Malware like Live Essential Platinum is designed to enter a computer system using social engineering tactics. For example, Live Essential Platinum itself will usually infiltrate a computer after another malware infection or a malicious component on a website displays an alarming error message urging the victim to download this fake security program. Once installed, Live Essential Platinum makes changes to the Windows Registry and settings that allow Live Essential Platinum to interfere with real security software, the web browser and the file explorer. Live Essential Platinum will also start up automatically whenever the victim logs on to Windows.

How Criminals Use Live Essential Platinum to Try to Steal Your Money

Live Essential Platinum can be recognized as a variant in the WinWebSec family of malware because of its characteristic light pink interface that is also used in malware such as System Security, Antivirus Security, Total Security 2009, Security Tool, Trojan.RogueAV.a.gen, System Adware Scanner 2010, FakeAlert-KW.e, Advanced Security Tool 2010, System Tool 2011, Security Shield, MS Removal Tool, Total Security, System Security 2011, Essential Cleaner, Security Shield Pro 2011, Personal Shield Pro, Security Shield 2011, Security Sphere 2012, Advanced PC Shield 2012, Futurro Antivirus. These are all bogus security programs designed to steal their victim's money by carrying out a well-known scam. Basically, Live Essential Platinum will try to convince its victims that they need to pay for a useless and expensive upgrade for Live Essential Platinum in order to remove a nonexistent infection. Although most reliable anti-malware programs can deal easily with Live Essential Platinum and other infections in the WinWebSec family of malware, these can still be tricky to remove due to the fact that they have components designed to thwart many legitimate security programs.

The main way in which Live Essential Platinum steals its victims' money is by convincing them that their computer is severely infected with malware. To do this, Live Essential Platinum will use a variety of alarming error messages, fake virus scans and intrusive tactics such as browser redirects. However, if the victim tries to use Live Essential Platinum to fix these supposed malware problems, Live Essential Platinum will claim that a 'full version' will need to be purchased. Of course, this supposed 'upgrade' is quite expensive and will also let the criminals behind Live Essential Platinum gain access to the victim's credit card information and other personal data.

Dealing with a Live Essential Platinum Infection

Due to the harmful changes that Live Essential Platinum makes to your computer system's settings, it is recommended to remove this infection with a trustworthy anti-malware application rather than attempting manual removal. Live Essential Platinum can protect itself from many legitimate security programs. To avoid this, ESG security analysts advise starting up Windows in Safe Mode or using an independent memory accessory (such as a network-shared drive or a CD) to start up Windows.

File System Details

Live Essential Platinum may create the following file(s):
# File Name Detections
1. %AppData%\[RANDOM]\[RANDOM].exe
2. C:\Documents and Settings\\Start Menu\Programs\Live Security Platinum
3. %Programs%\Live Essential Platinum\Live Essential Platinum.lnk
4. %Desktopdir%\Live Essential Platinum.lnk
5. C:\Documents and Settings\\Application Data\529C50F6007459265E197DE0D151FC4E

Registry Details

Live Essential Platinum may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Live Essential Platinum "DisplayIcon" = "'%AppData%\[RANDOM]\[RANDOM].exe,0'"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Live Security Platinum "UninstallString" = "'C:\Documents and Settings\All Users\Application Data\529C50F6007459265E197DE0D151FC4E\529C50F6007459265E197DE0D151FC4E.exe" -u'"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Live Security Platinum "DisplayName" = "'Live Security Platinum'"
HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\5AA458FE087C612E662185E8D95A0456 "(Default)"="1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Live Essential Platinum "UninstallString" = "'%AppData%\[RANDOM]\[RANDOM].exe" -u
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Live Security Platinum "ShortcutPath" = "'C:\Documents and Settings\All Users\Application Data\529C50F6007459265E197DE0D151FC4E\529C50F6007459265E197DE0D151FC4E.exe" -u'"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "529C50F6007459265E197DE0D151FC4E" = "'C:\Documents and Settings\All Users\Application Data\529C50F6007459265E197DE0D151FC4E\529C50F6007459265E197DE0D151FC4E.exe'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Live Essential Platinum
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Live Security Platinum "DisplayIcon" = "'C:\Documents and Settings\All Users\Application Data\529C50F6007459265E197DE0D151FC4E\529C50F6007459265E197DE0D151FC4E.exe,0'"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Live Essential Platinum "ShortcutPath" = "'%AppData%\[RANDOM]\[RANDOM].exe" -u
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "[random]" = "%AppData%\[RANDOM]\[RANDOM].exe"

Trending

Most Viewed

Loading...