personal security - antivirus program

Posted on 2010-01-01
Last Modified: 2013-11-22
I have a computer that keeps having a security program called "Personal Security" keep popping up.  It says the computer has 42 threats.  The owner says they never downloaded this.  It appears by the net that it may be a hoax of a program.  Is anyone familiar with this program and if so, how do you sucessfully remove it?  Thanks.
Question by:lpetrowicz
    LVL 57

    Expert Comment

    by:Pete Long
    Hello lpetrowicz,

    Download and install/run malware bytes


    LVL 25

    Expert Comment


    Avira AntiVir Rescue System is a Linux-based application that allows accessing computers that cannot be booted anymore. Thus it is possible to:
     repair a damaged system, rescue data and scan the system for virus infections.
    try the above avira boot system , and run
    LVL 13

    Expert Comment

    Run a temporary file remover...CCleaner is a good one and it's free.

    Download Combofix by sUBs.

    Before running Combofix, temporary disable any firewall(s) shield(s) prevent any conflicts with Combofix. After Combofix is done scanning, it will create a log, for futher instructions, save and paste the results by Attach File, or by Code Snippet so other experts can take a look at it. Once after the log looks clean, you may enable your firewall(s) shield(s) ect. Combofix will disconnect your machine from the Internet. Your Internet connection will be automatically restored just before Combofix completes its scan. If Combofix runs into problems, your Internet connection can be manually restored by restarting your machine.

    You'll might need to rename the file before saving to your desktop so it will not be blocked.

    Please note: Don't run Combofix in Safe Mode.
    LVL 22

    Expert Comment

    You may have to run Process Explorer if malware is preventing anti-malware programs from running.
    If so, look in process explorer for any entry regarding personal security or a random named process like 24456377.exe.
    Right click and suspend the "bad" process and run scanners.

    Post Malwarebytes logfile here after
    LVL 25

    Expert Comment

    LVL 12

    Expert Comment

    This bug has any number of names, madunix, including Cyber-Security, AntiVirus 2008 or 2009 (probably 2010 coming soon), Internet Security 2008 or 9, Personal Security 2008 or 9, and many others.  As far as I can tell, they all have a battle shield in either the upper right or left of the window that pops up.

    It is evolving, too.  It gets nastier and nastier as time goes on.
    LVL 5

    Expert Comment

    my advice ... download and run combofix under safemode

    download trial version of Kaspersky internet security 2010
    update it
    scan ( better under safe mode)

    Use the following instructions to remove Personal Security (Uninstall instructions)

    Step 1.

    Download Avenger from here and unzip to your desktop.

    Run Avenger, copy, then paste the following text in Input script Box:

    Drivers to delete:

    Registry keys to delete:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}

    Folders to delete:
    %ProgramFiles%\Common Files\PSecurityUninstall

    Files to delete:

    You will be asked Are you sure you want to execute the current script?. Click Yes. You will now be asked First step completed  The Avenger has been successfully set up to run on next boot. Reboot now?. Click Yes.

    Your PC will now be rebooted.

    Step 2.

    Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

    Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.

    If an update is found, it will download and install the latest version.

    Once the program has loaded you will see window similar to the one below.
    Malwarebytes Anti-Malware Window

    Select Perform Quick Scan, then click Scan, it will start scanning your computer for Personal Security infection. This procedure can take some time, so please be patient.

    When the scan is complete, click OK, then Show Results to view the results. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.
    Malwarebytes Anti-malware, list of infected items

    Make sure that everything is checked, and click Remove Selected for start Personal Security removal process. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

    Note: if you need help with the instructions, then post your questions in our Spyware Removal forum.
    Personal Security creates the following files and folders

    C:\Program Files\Common Files\PSecurityUninstall
    C:\Program Files\PSecurity
    Personal Security creates the following registry keys and values

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}

    LVL 47

    Expert Comment

    If the tools won't run, use TDSS killer first, it may be present.
    Or use Process Explorer to find the random number name and kill that process as already mentioned, or if MalwareBytes is already installed try renaming it to svchost.exe.

    Or check this article below.
    If you can't run .exes in an infected system:

    If MalwareBytes is not installed yet, sometimes it needs to be renamed twice as it says in the article.
     Rename before saving and after installation.

    Accepted Solution

    None of the above tools worked on this bad puppy.  I had to stop a number of services to be able to get a few minute window to delete the files from Program Files.  Deleting it in Add/Remove Programs brought up its activation screen.  Once I had the files deleted, I was then able to remove the rest of the program from Add/Remove Programs.  

    This was difficult but we won the battle.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    UPDATE - 6/15/2011 Added support for Release Update 6 Maintenance Patch 2 Point Patch 1 (RU6 MP2 PP1). Fixed a defect in the username field that was hard-coded to look for a specific domain (left over code from testing). This release will be the …
    The purpose of this Article is to provide information for a newly released variant of malware – with the assumption that many EE Members will have need of the information. According to “Computerworld”, well over one million web sites have been co…
    It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
    Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…

    758 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    12 Experts available now in Live!

    Get 1:1 Help Now