How to remove Mssecsvc.exe

There are more and more details about WannaCry (WanaCry, WanaCrypt, Wanna Decrypt0r) ransomware every day, and Mssecsvc.exe is one of them. It is a process that can be found in the Process Manager when WannaCry ransomware operates in the system. If you see Mssecsvc.exe running – you should immediately switch off the PC, boot it in safe mode and start removing the virus. This will help you to save some of your files (not all of them, because the encryption process has already begun). There is no guarantee that there will be the process with exactly this name, because hackers are trying to diversify the risks and made few versions of a virus with different names of important processes and different ways of work. These days you should be especially careful, because of the outbreak of ransomware and other viruses, so if you think that something is wrong with a computer – immediately take some actions to figure it out. Any information about Mssecsvc.exe process and WannaCry ransomware will be appreciated, so post in comments about your experience.

Step 1. Download security update MS17-010 for Windows

You can follow nex link: https://technet.microsoft.com/en-us/library/security/ms17-010.aspx

Step 2. Fix vulnerability of the system

Start -> Cmd ->Right click o cmd.exe -> Choose Start as Administrator

Write next command and press Enter Netsh advfirewall firewall add rule dir=in action=block protocol=tcp localport=445 name="Block_TCP-445"

Step 3. Boot system in the Safe mode

Safe mode

Start -> Msconfig.exe

Safe mode. Step 1

On the tab Boot select Safe boot

Safe mode. Step 2

Step 4. Scan the system with antiviral scanner

Step 5. Disable Safe mode

Start -> Msconfig.exe ->Disable Safe boot in the Boot tab

Deactivate Safe mode

Step 6. Update Windows

Launch security patch MS17-010 that you downloaded earlier.

Add comment

Security code
Refresh

This website uses cookies to improve your experience. If you continue using the site, we will assume that you accept our cookies policy.