ThinkSmart

ThinkSmart is a rogue anti-spyware program and discovered to be a newer variant of the dangerous ThinkPoint rogue application. ThinkSmart (Think Smart) uses an almost identical user interface and methods of infection as the ThinkPoint rogue application. ThinkSmart has been also identified to uses a 'drive-by download' method to install a Trojan file without notice to the computer user. The Trojan is associated with a fake Microsoft Security Essentials Alert notification coming from the hotfix.exe or mstsc.exe files. These files may lock computer users out of successfullying running the task manager to end their processes. This is an essential step in manual removal of ThinkSmart just like it was with ThinkPoint.

ThinkSmart is designed to trick computer users into downloading and installing a suggested rogue anti-spyware program which may allow remote attackers access to the affected PC. ThinkSmart is known to conduct system scans that return several falsified parasites results. These bogus results are only part of ThinkSmart's scheme for enticing computer users to purchase a full version of the ThinkSmart program in hopes that the 'full-version' will remove the detected threats. ThinkSmart does not have the capability to remove any type of parasites threat.

One of the alert messages that come from ThinkSmart claims to be a Microsoft Security Essentials Alert stating that your computer is infected with a parasite called 'Unknown Win32/Trojan'. ThinkSmart even goes as far as to state that the particular parasite was detected by 30 or so other well-known security applications. These messages are all bogus and cannot be trusted. The best way to avoid this from happening to you is by installing a good trustworthy anti-spyware application.

Can't access legitimate anti-malware software like SpyHunter to detect ThinkSmart? If ThinkSmart is blocking access to SpyHunter and security websites, do the following:

- Restart your computer and if you see the ThinkSmart interface, keep hitting Ctrl+Alt+Del to open your Task Manager.

- Once Task Manager opens, hit the 'Processes' tab, locate the main ThinkSmart process called 'hotfix.exe' and choose 'End Process'. If your Task Manager is disabled, search for the name 'hotfix' on your computer using your Windows File Search Tool, rename it to hotfix0, and then open your Task Manager to delete the process.

- After this is completed, continue using your Task Manager to go to 'File' menu, select 'New Task (Run)' and type in 'explorer.exe'

- Click the 'OK' button and wait for your Desktop to get back to normal.

- Then, go ahead and open SpyHunter to automatically detect other malicious files related to ThinkSmart and the fake 'Microsoft Security Essentials Alert' message.

If you have already purchased the rogue software ThinkSmart, you should contact your credit card company and ask for a chargeback on your purchase.

Ultimately, it is advised you use a reliable, automatic detection tool to detect ThinkSmart from your computer or delete its malicious files manually.

File System Details

ThinkSmart may create the following file(s):
# File Name Detections
1. %TempDir%\kjkkklklj.bat
2. %LocAppData%\defender.exe
3. %UserProfile%\Application Data\hotfix.exe
4. %UserProfile%\Application Data\install
5. %UserProfile%\Application Data\completescan

Registry Details

ThinkSmart may create the following registry entry or registry entries:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "%LocAppData%\antispy.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnPostRedirect" = "0"
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = "0"
HKCU\Software\PAV
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce "SelfdelNT"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run "tmp"
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "%Documents and Settings%\[UserName]\Application Data\hotfix.exe"
HKEY_CURRENT_USER\Software\PAV
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "thinksmart"

Trending

Most Viewed

Loading...