
By Jim
Updated on Wednesday, May 12th, 2010
People trust Microsoft. After all, they make the operating system they work on everyday, Windows. A Russian team of hackers are using this trust and turning it around by hijacking Microsoft’s own trademarked name, Microsoft Security Essentials, and using it for their own rogue software.
Sure, you wouldn’t really know if it’s fake by the name but if it asks for registration via SMS better ignore it and remove this malware right away. The original Microsoft Security Essentials is free but this version will constantly prompt you to upgrade, so that is another red flag for you. While masquerading as a security app, it will be able to steal information from your computer that can open it up to illegal and illicit activity from hackers. They can pick up your credit card information, passwords and even your address book and spread the infection to your relatives and friends.
Make sure to remove this badware immediately and replace it with the completely free and original version from Microsoft’s own site. It costs nothing and works pretty well. It also does not need any SMS registration and will work with any genuine Microsoft product. Here are the instructions on how to clean your computer from the fake Microsoft Security Essentials.
Symptoms Of Infection
- Your computer is acting slow. Microsoft Security Essentials Fake slows down your system significantly. This includes starting up, shutting down, playing games, and surfing the web.
- You are getting pestered with pop ups. Microsoft Security Essentials Fake infects your registry and uses it to launch annoying pop up ads out of nowhere.
- Searches are redirected or your homepage and desktop are settings are changed. This is a symptom of a very serious Microsoft Security Essentials Fake infection.
Dangers Of Infection
Viruses like Microsoft Security Essentials Fake will infect your registry and other important system files. If the infection is not treated it can cause a complete collapse of your system.
![]()
Some Microsoft Security Essentials Fake infections contain spyware and keyloggers which can be used to record sensitive data like passwords, credit card, bank account, and social security numbers. The longer you allow the infection to fester, the greater the chance of identity fraud.
How To Remove Infection Manually
Uninstall Microsoft Security Essentials Fake Processes
41.exe
smss32.exe
winlogon32.exe
Delete Microsoft Security Essentials Fake Files
Remove Microsoft Security Essentials Fake Registry Files
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-soft-package.com
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-software-package.com
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\get-key-se10.com
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\is-software-download.com
HKEY_CURRENT_USER\Software\SE2010
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\buy-security-essentials.com
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\get-key-se10.com
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallpaper” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer “NoActiveDesktopChanges” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer “NoSetActiveDesktop” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Security essentials 2010″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “smss32.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop “NoChangingWallpaper” = “1″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer “NoActiveDesktopChanges” = “1″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer “NoSetActiveDesktop” = “1″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “smss32.exe”
Popular Search Terms
Remove Microsoft Security Essentials Fake
Delete Microsoft Security Essentials Fake
Uninstall Microsoft Security Essentials Fake
How to get rid of Microsoft Security Essentials Fake
How to remove Microsoft Security Essentials Fake
Microsoft Security Essentials Fake removal
Remove MicrosoftSecurityEssentialsFake
MicrosoftSecurityEssentialsFake removal
Microsoft-Security-Essentials-Fake
Warning! If Spyware Doctor is blocked by the virus then run your system in safe mode and try again. To do this reboot your system and tap F8 repeatedly as your computer starts up. Then run Spyware Doctor as normal. If this doesn’t work try renaming the Spyware Doctor EXE file.
Posted under Fake Antispyware | No Comments
