By George Norman
Added on 18 Feb 2010(4889 Views)



classification: Rogue AntiSpyware Programs
The people with malicious intent that put out the Internet Security 2010 rogue have rolled out another fake security software application, mainly Security Essentials 2010. Just like its sibling, this rogue is usually distributed by Trojans. The Trojan sneaks onto the user’s computer by pretending to be a Flash update needed to view online videos. Once it compromises the user’s computer, the Trojan will install Security Essentials 2010 without the user’s consent.
Here is what the Security Essentials 2010 rogue will do once it has been installed on the user’s computer:
  • It will automatically run at startup and will keep running in the background. This causes the computer to act sluggish as the rogue eats up system resources.
  • It performs fake system scans that detect a whole bunch of infected files.
  • It bombards the user with popups and fake security alerts. Here are some examples:
Security Warning!
Worm.Win32.NetSky detected on your machine.
This virus is distributed via the Internet through e-mail and Active-x objects.
The worm has its own SMTP engine which means it gathers e-mails from your local computer and re-distributes itself.
In worst cases this worm can allow attachers to access your computer, stealing passwords and personal data.
Viruses can damage your confidential data and work on your computer.
Continue working in unprotected mode is very dangerous.

System warning!
Continue working in unprotected mode is very dangerous. Viruses can damage your confidential data and work on your computer. Click here to protect your computer.

Critical Warning!
Critical System Warning! Your system is probably infected with a version of Trojan-Spy.HTML.Visafraud.a. This may result in website access passwords being stolen from Interner Explorer, Mozilla Firefox, Outlook etc. Click Yes to scan and remove threats. (recommended)
  • It hijacks the browser.
  • It doesn’t let the user launch applications. When the user attempts to run an executable, the rogue displaysthe following message:
Application cannot be executed. The file is infected. Please activate your antivirus software.
  • Last but not least, it tries to scam the user out of some money. That’s the reason why the rogue has been using all the scare tactics above. To trick him into thinking his computer is infected so it could ask the user to purchase a Security Essentials 2010 license to remove the infection.

You are well advised not to pay. You would only be lining the pockets of the people with malicious intent that came up with Security Essentials 2010. What you should do is remove the rogue from your system as soon as possible.

Automatic removal guide
Step 1. If you have a printer, make sure to print out this tutorial. If you do not have a printer, save this tutorial, go out to a copy center and print it out there. If you do not have a printer and do not want to go out, then use the pen and paper method: grab a pen and a piece of paper and write down the instruction presented in the steps below. In the process of eliminating Security Essentials 2010 from your machine you will need to shut down the browser. And since this will also shut down the tutorial, you need to know what you should do next.

Step 2. You will have to install Malwarebytes’ Anti-Malware. In this regard you need to download the software’s setup executable. Just click this link and save the .exe file on your computer (preferably on your desktop).

Step 3. Double click the Malwarebytes’ Anti-Malware setup executable. It should be on the desktop under the name mbam-setup. This will launch the installation process. If you already know how to install a piece of software, proceed to step 4. If you do not know how to do this, we’ll walk you though it all:



- The Select Setup Language window should have popped up. By default, the language in which the software will be installed is set to English, but you can change this. The software provides support for 30+ languages. After selecting the language of your choice, click OK. It would be best to just leave it set to English though.



- The Malwarebytes’ Anti-Malware Setup Wizard will now popup. Just click Next.



- You will be presented with the License Agreement. Click I accept the agreement and then click Next. If you do not accept the agreement you will not be able to continue.



- Keep clicking Next until you get to the Ready to install window. Now click Install. After the installation process completes click Finish. Do not uncheck the boxes next to Update Malwarebytes’ Anti-Malware or Launch Malwarebytes’ Anti-Malware.















Step 4. The Malwarebytes’ Anti-Malware application will launch automatically. The Perform quick scan option should be checked by default – if it isn’t then check it and then click Scan. You are well advised to close all running apps before clicking scan. This will ensure the scan for Security Essentials 2010 will complete swiftly.



Malwarebytes’ Anti-Malware will start scanning your files for signs of Security Essentials 2010. This may take a while, so be patient. It all depends on how powerful your computer is and how many files Malwarebytes’ Anti-Malware has to scan.



When the scan for Security Essentials 2010 is complete you will be presented with a notification box. Click OK to close the notification box and go to the main Scanner screen. Click Show Results and you will be presented with a list of all the infected files Malwarebytes’ Anti-Malware has detected.





Step 5. Click Remove Selected and Malwarebytes’ Anti-Malware will remove all the infected files it has detected. It may be necessary to restart your computer in order to remove some of these files. After Malwarebytes’ Anti-Malware is done removing all the infected files, it will open Notepad and present the scan log to you. You can review the log at your leisure – save it If you want.



Step 6. Close Malwarebytes’ Anti-Malware and you’re done. No traces of Security Essentials 2010 should be left on your computer.

Manual removal guide

Stop and remove the processes:

winlogon32.exe
smss32.exe
41.exe
250904.exe
SE2010.exe


Access the Windows Registry Editor and delete the following registry keys:


HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ZoneMap/Domains/buy-security-essentials.com
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ZoneMap/Domains/download-soft-package.com
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ZoneMap/Domains/download-software-package.com
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ZoneMap/Domains/get-key-se10.com
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ZoneMap/Domains/is-software-download.com
HKEY_CURRENT_USER/Software/SE2010
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Internet Settings/ZoneMap/Domains/buy-security-essentials.com
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Internet Settings/ZoneMap/Domains/get-key-se10.com
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Policies/ActiveDesktop "NoChangingWallpaper" = "1"
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Policies/Explorer "NoActiveDesktopChanges" = "1"
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Policies/Explorer "NoSetActiveDesktop" = "1"
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Policies/System "DisableTaskMgr" = "1"
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Run "Security essentials 2010"
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Run "smss32.exe"
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/policies/ActiveDesktop "NoChangingWallpaper" = "1"
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/policies/Explorer "NoActiveDesktopChanges" = "1"
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/policies/Explorer "NoSetActiveDesktop" = "1"
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run "smss32.exe"


Locate and delete the following files:

c:/s
c:/Program Files/Securityessentials2010/
c:/Program Files/Securityessentials2010/SE2010.exe
%UserProfile%/Application Data/Microsoft/Internet Explorer/Quick Launch/Security essentials 2010.lnk
%UserProfile%/Desktop/Security essentials 2010.lnk
%UserProfile%/Start Menu/Security essentials 2010.lnk
c:/WINDOWS/system32/41.exe
c:/WINDOWS/system32/helpers32.dll
c:/WINDOWS/system32/smss32.exe
c:/WINDOWS/system32/warnings.html
c:/WINDOWS/system32/winlogon32.exe


Unregister the following DLL libraries:


helpers32.dll


Block access to the domain(s):

securityessentials2010.com
buy-security-essentials.com
mega-scan-pc-new13.org




Don't forget to:

Tags:

Link to this article:


Comments

Jenny - 28 Aug 2010 00:33
I just scanned my computer with SuperAntiSpyware and it found 9000 Security Essentials 2010 files, registry items, and memory items but when I scanned with Microsoft Security Essentials and Malwarebytes the searches just come out clean. I tried searching for the SE2010 file manually and I can't find a thing. Needless to say, I'm confused...
Harmony - 03 Jun 2010 16:57
Cannot say anything bad about that company.I am using Security Essentials 2010 and completely happy with it. Besides all they have a support center for customers who have some problems. Why didn't you used the support service?
Penelope - 19 Feb 2010 23:44
George, I can not thank you enough. I got the virus about 10 pm last night and was up til 6 am freaking out and trying to figure out what to do. This was the best site I found and everything worked perfectly and my computer is finally functioning normally. You are my hero, George.

Add comment:
Name(Required)
Email(Required - Never shown)
Website(Optional)
Comment(Required):

Insert the following code:
Removal Guide Articles
How To Remove XP Micro Antivirus
If you did not manually install XP Micro Antivirus and ...
19 Feb 2010
How To Remove Software Antivirus
Software Antivirus, unlike what the name may suggest, is not ...
19 Feb 2010
How To Remove WiniFighter
The irony here is that the name WiniFighter would lead ...
19 Feb 2010
How To Remove PC Security 2009
PC Security 2009, a rogue antispyware program, is usually distributed ...
19 Feb 2010
How To Remove Security Essentials 2010
The people with malicious intent that put out the ...
18 Feb 2010
How To Remove Personal Anti Malware
Personal Anti Malware, a rogue security software application, is usually ...
18 Feb 2010
Recommended Tools

Top Downloads