The fake Microsoft Security Essentials Alert: what it is and how to remove it

The fake Microsoft Security Essentials Alert is a Trojan virus that impersonates the legitimate Microsoft Security Essentials antivirus program and states that your computer is infected with Unknown Win32/Trojan. This is a rogue program that spreads via fake scanners, malicious emails, and similar unsolicited methods.

Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

An automatic scan can look at taskmgr.exe and the other programs installed around the same time.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove The fake Microsoft Security Essentials Alert yourself 5 steps, about 15 minutes, no software needed.

Start the steps
The fake Microsoft Security Essentials Alert: microsoft security essentials fake alert
The fake Microsoft Security Essentials Alert as our 2021 report showed it.

The fake Microsoft Security Essentials Alert: summary

DistributionAlready installed Trojans, fake scanners,
NameThe fake Microsoft Security Essentials Alert
TypeRogue antispyware, malware
SymptomsProvides fake scan results in order to make users purchase its full version; promotes other rogue programs
Detection namesNo Microsoft detection name is known
DamageNot recorded in the old report
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 4 more facts
Files and processestaskmgr.exe
EvidenceOne write-up by a security site; details still limited
First seen30 April 2021
Facts checked7 October 2026

Is The fake Microsoft Security Essentials Alert a real security program?

  • File: taskmgr.exe

From our report of Apr 2021 · not reviewed since

More from our earlier report on The fake Microsoft Security Essentials Alert

  • You can uninstall unwanted programs via the Control Panel but to make sure that all the malicious components are eliminated, use or another reputable antivirus software
  • If your computer starts to malfunction after malware is eliminated, scan it with
  • The application taskmgr.exe was launched successfully but it was forced to shut down due to security reasons.
  • This happened because the application was infected by a malicious program which might pose a threat for the OS.
  • It is highly recommended to install the necessary heuristic module and perform a full scan of your computer to exterminate malicious programs from it.
  • Outdated viruses database are not effective can't guarantee adequate protection and security for your PC!

How to remove The fake Microsoft Security Essentials Alert

Nothing it reports is real.

These steps remove it and undo a payment if you made one.

  1. Step 1: Do not pay, and undo a payment if you made one

    The fake Microsoft Security Essentials Alert reports problems to sell a licence: the "threats" or "errors" it lists are invented or harmless leftovers.

    If you already paid, ask your card issuer to dispute the charge and cancel the subscription both in the seller's account and through your bank.

    If you called a phone number it showed and let someone connect, treat the PC as remotely accessed and remove the remote tool. Uninstalling it from Windows 11 or Windows 10 does not cancel a subscription by itself.

    Full procedure with screenshots: What to do after paying a scammer

  2. Step 2: Uninstall programs you did not mean to install

    Open Settings > Apps > Installed apps in Windows 11, or Settings > Apps > Apps & features in Windows 10, and sort the list by install date. Look at what appeared around the day the problem started and uninstall every program you do not recognise or did not choose.

    Free converters, PDF and video tools, "system optimizers" and unknown browsers are the usual carriers of The fake Microsoft Security Essentials Alert. If a name is unclear, search for it before you remove it, so you do not uninstall a driver or a Windows component.

    Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix

  3. Step 3: Remove it from startup

    Whatever The fake Microsoft Security Essentials Alert installed usually starts with Windows.

    Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  4. Step 4: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  5. Step 5: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

Instructions for each browser and system

The detailed steps for every browser and system this guide covers. Open the one you use.

Uninstall from Windows

Uninstall from Windows 10/8:

  1. Type Control Panel into the Windows search box and open the result.
  2. Under Programs, select Uninstall a program.Uninstall from Windows 10/8

Uninstall from Windows 7/XP:

  1. Click on Windows Start > Control Panel (Windows XP users should click on Add/Remove Programs).
  2. In Control Panel, select Programs > Uninstall a program.Uninstall from Windows 7/XP

Remove the unwanted program:

  1. In the Programs and Features window, look for any recently installed suspicious entries, select them, and click Uninstall.
  2. If User Account Control appears, click Yes to confirm, then complete the removal.Uninstall the unwanted program from Windows
Remove from Google Chrome

Delete malicious extensions from Google Chrome:

  1. Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
  2. In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.Remove extensions from Chrome

Clear cache and web data from Chrome:

  1. Click on Menu and pick Settings.
  2. Under Privacy and security, select Clear browsing data.
  3. Select Browsing history, Cookies and other site data, as well as Cached images and files.
  4. Click Clear data.Clear cache and web data from Chrome

Change your homepage:

  1. Click menu and choose Settings.
  2. Look for a suspicious site in the On startup section.
  3. Click on Open a specific or set of pages and click on three dots to find the Remove option.

Reset Google Chrome:

If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:

  1. Click on Menu and select Settings.
  2. In the Settings, scroll down and click Advanced.
  3. Scroll down and locate Reset and clean up section.
  4. Now click Restore settings to their original defaults.
  5. Confirm with Reset settings.Reset Chrome 2
Remove from Microsoft Edge

Delete unwanted extensions from MS Edge:

  1. Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
  2. From the list, pick the extension and click on the Gear icon.
  3. Click Remove.Remove extensions from Edge

Clear cookies and other browser data:

  1. Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
  2. Under Clear browsing data, pick Choose what to clear.
  3. Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.Clear Edge browsing data

Restore new tab and homepage settings:

  1. Click the menu icon and choose Settings.
  2. Then find On startup section.
  3. Click Remove next to any suspicious startup page.

Reset MS Edge if the above steps did not work:

  1. Press on Ctrl + Shift + Esc to open Task Manager.
  2. Click on More details arrow at the bottom of the window.
  3. Select Details tab.
  4. Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.Reset MS Edge
Instructions for Chromium-based Edge

Delete extensions from MS Edge (Chromium):

  1. Open Edge and click select Settings > Extensions.
  2. Delete unwanted extensions by clicking Remove.Remove extensions from Chromium Edge

Clear cache and site data:

  1. Click on Menu and go to Settings.
  2. Select Privacy, search and services.
  3. Under Clear browsing data, pick Choose what to clear.
  4. Under Time range, pick All time.
  5. Select Clear now.Clear browser data from Chroum Edge

Reset Chromium-based MS Edge:

  1. Click on Menu and select Settings.
  2. On the left side, pick Reset settings.
  3. Select Restore settings to their default values.
  4. Confirm with Reset.
  5. This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.Reset Chromium Edge
Remove from Mozilla Firefox (FF)

Remove dangerous extensions:

  1. Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
  2. Select Add-ons.
  3. In here, select the unwanted extension and click Remove.Remove extensions from Firefox

Reset the homepage:

  1. Click three horizontal lines at the top right corner to open the menu.
  2. Choose Settings.
  3. Under Home, set your preferred homepage and new tab settings.

Clear cookies and site data:

  1. Click Menu and pick Settings.
  2. Go to Privacy & Security section.
  3. Scroll down to locate Cookies and Site Data.
  4. Click on Clear Data...
  5. Select Cookies and Site Data and Temporary cached files and pages, then click Clear.Clear cookies and site data from Firefox

Reset Mozilla Firefox

If clearing the browser as explained above did not help, reset Mozilla Firefox:

  1. Open Mozilla Firefox browser and click the Menu.
  2. Go to Help and then choose Troubleshooting Information.Reset Firefox 1
  3. Under Give Firefox a tune up section, click on Refresh Firefox...
  4. Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.Reset Firefox 2
Delete from Safari

Remove dangerous extensions:

  1. Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
  2. Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.Remove extensions from Safari

Clear history and website data:

  1. Click Safari in the menu and pick Clear History.
  2. Set Clear to all history and confirm with Clear History.Clear history from Safari

Reset Safari:

  1. Click Safari in the menu and select Preferences > Advanced.
  2. Enable Show Develop menu in menu bar.
  3. From the menu bar, click Develop and select Empty Caches.Reset Safari

Protect your privacy - employ a VPN

There are several ways how to make your online time more private - you can access an incognito tab.

However, there is no secret that even in this mode, you are tracked for advertising purposes. There is a way to add an extra layer of protection and create a completely anonymous web browsing practice with the help of VPN. This software reroutes traffic through different servers, thus leaving your IP address and geolocation in disguise.

Besides, it is based on a strict no-log policy, meaning that no data will be recorded, leaked, and available for both first and third parties. The combination of a secure web browser and VPN will let you browse the Internet without a feeling of being spied or targeted by criminals.

No backups? No problem. Use a data recovery tool

If you wonder how data loss can occur, you should not look any further for answers - human errors, malware attacks, hardware failures, power cuts, natural disasters, or even simple negligence.

In some cases, lost files are extremely important, and many straight out panic when such an unfortunate course of events happen. Due to this, you should always ensure that you prepare proper data backups on a regular basis.

If you were caught by surprise and did not have any backups to restore your files from, not everything is lost. is one of the leading file recovery solutions you can find on the market - it is likely to restore even lost emails or data located on an external device.

From our report of Apr 2021 · not reviewed since

The fake Microsoft Security Essentials Alert is a malicious program you should remove

The fake Microsoft Security Essentials Alert is a Trojan virus that impersonates the legitimate Microsoft Security Essentials antivirus program and states that your computer is infected with Unknown Win32/Trojan.

This is a rogue program that spreads via fake scanners, malicious emails, and similar unsolicited methods.

This malicious software promotes five different fake anti-virus programs, including:

The fake Microsoft Security Essentials Alert will state that it could not remove Unknown Win32/Trojan threat and will prompt you to install one of those five rogue programs to remove the infection, which actually doesn't even exist on your computer. Actually, it will display a list with 35 different antivirus programs, 30 of which are legitimate, but it let you install only the rogue ones.

Once the rogue program is installed, it will prompt you to reboot your computer.

That's the main goal of this malware - to trick you into purchasing the rogue program. The scan results are false, and you can safely ignore them. And, of course, don't purchase any of those rogue programs.

The fake Microsoft Security Essentials Alert and related rogue programs should be removed from the computer as soon as possible. However, if you already purchased it, then you should contact your credit card company and dispute the charges.

There are two other every annoying things about this malware: it blocks task manager, registry editor, and other legitimate programs, and it also displays fake security alerts to scare you into thinking that your computer is infected with spyware, adware, Trojans, and other malware. Some of the fake security alerts read:

  • Red Cross Antivirus,
  • Peak Protection 2010,
  • Pest Detector 4.1,
  • Major Defense Kit
  • AntiSpySafeguard.
The fake Microsoft Security Essentials Alert: microsoft security essentials fake alert
The fake Microsoft Security Essentials Alert in our 2021 report.

From our report of Apr 2021 · not reviewed since

Malware removal steps

The fake Microsoft Security Essentials Alert and all those five rogues Red Cross Antivirus, Peak Protection 2010, Pest Detector 4.1, Major Defense Kit, and AntiSpySafeguard should be removed from the system upon detection. It is evident that this is a scam.

None of those programs will actually protect your computer against malicious software. Related files:

  • tmp.exe
  • kjkkklklj.bat
  • hotfix.exe

Questions about The fake Microsoft Security Essentials Alert

Is taskmgr.exe a virus?

The name taskmgr.exe is not enough to say. Malware often uses technical-sounding names, and harmless updaters often use odd ones. Check three things:

  • the folder the file runs from
  • the Digital Signatures tab in its properties
  • the program that starts it (Startup apps, Task Scheduler or services)

A signed file from a company whose product you use is almost certainly fine. An unsigned file in a user folder that no installed program explains should be removed, and the PC scanned with Microsoft Defender in offline mode.

Can I end taskmgr.exe in Task Manager?

Ending an unknown process is safe in the sense that Windows will warn you before you close anything critical, and a restart brings back whatever Windows needs. Ending taskmgr.exe will not remove it, though: if a task or startup entry launches it, it returns at the next sign-in.

Use ending the process as a test. If something important stops working, it belonged to a program you use. If nothing changes and it comes back by itself, find and disable its starter, delete the file and scan the PC.

How do I know The fake Microsoft Security Essentials Alert is fake?

Three things give it away. It appears as an unfamiliar process called taskmgr.exe in Task Manager, a window from a program rather than from Windows Security. It pushes you to act quickly by calling, paying or downloading.

And the threats it reports never show up when you run a scan in the real Windows Security app. Microsoft does not put phone numbers in warnings or charge for removing threats through pop-ups. Close the window, do not call, and follow the steps to find and uninstall the program behind it.

Do I need to buy antivirus after removing The fake Microsoft Security Essentials Alert?

No. Windows 11 and Windows 10 include Microsoft Defender in Windows Security, which provides real-time protection, scheduled scans, the offline scan and protection against unwanted apps at no cost. Keep it switched on and updated, and turn on Reputation-based protection under App & browser control.

If you prefer a third-party product, buy it from the vendor's own site after reading independent test results, never from a pop-up or a phone call. The lesson of The fake Microsoft Security Essentials Alert is that security offers which arrive unasked are the ones to avoid.

I let a technician connect to my PC because of The fake Microsoft Security Essentials Alert. Is it safe now?

Not until you check. While connected, the caller could install other programs, create a user account or look at saved passwords. Disconnect from the internet, uninstall the remote access program and anything else installed during the call, and run a full scan and the Microsoft Defender offline scan.

From another device, change your e-mail and banking passwords and turn on two-step verification. If the caller opened your online banking, call the bank today. A reset of Windows is the safest option if you cannot tell what was done.

Did The fake Microsoft Security Essentials Alert steal my information?

Not by itself, as far as reports show. Programs that display an unfamiliar process called taskmgr.exe in Task Manager are built to scare people into paying or calling; they rarely take data on their own.

The risk comes from what you did in response: typing card details into the program, or letting a caller connect to your PC. If you did neither, uninstalling the program is enough. If you did either, treat that information as exposed:

  • block the card
  • change passwords from another device
  • remove any remote-access tool that was installed

Should I reset my PC because of The fake Microsoft Security Essentials Alert?

Only if the signs point to deeper access. Reset when you see an unfamiliar process called taskmgr.exe in Task Manager again after removal, when Windows Security cannot start or update, when remote access tools you did not install keep appearing, or when you simply cannot trust the PC any more.

Otherwise, the plan in this guide plus an offline scan is enough. If you do reset, choose Remove everything and Cloud download for a fresh copy of Windows, restore only documents and photos, and reinstall programs from their official sites. Change important passwords from the clean system afterwards.

What should I do if I already clicked or replied to The fake Microsoft Security Essentials Alert?

Stop all contact, do not click anything else and secure your accounts right away. If you typed a password, change it at once from a clean device, then turn on two-factor authentication.

If you gave card or bank details, call the bank on the number printed on your card and ask to block or replace it. If you installed something or allowed remote access, disconnect from the internet and follow the removal plan. Keep screenshots and the message, because they help when you report it.

Will Fortect remove The fake Microsoft Security Essentials Alert?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For The fake Microsoft Security Essentials Alert, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove "Unauthorized Access Detected" virus

“Unauthorised Access Detected” scam strikes again “Unauthorised Access Detected” virus operates as a tech support scam which scares users with fake claims that their computers might have been disabledRogue Anti-SpywareHigh riskJulie Splinters ·

Remove Systemcare-antivirus.org

Systemcare-antivirus.org is a fraudulent website that should always be avoided. You may run into it with and even without your knowledge because it has been promoted with a help ofRogue Anti-SpywareHigh riskUgnius Kiguolis ·

Remove Windows Antivirus 2008

Windows Antivirus 2008 – a fake security tool showing false-positive scan results Windows Antivirus 2008 is a corrupt security tool that is promoted as useful anti-spyware software. It manipulates the nameRogue Anti-SpywareMedium riskLucia Danes ·

Remove Personal Security

Personal Security - a fake anti-malware tool that will scam you out of your money Personal Security is a misleading anti-spyware application that displays fake security alerts/pop-ups and reports falseRogue Anti-SpywareMedium riskUgnius Kiguolis ·

Questions and experiences: The fake Microsoft Security Essentials Alert

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year