Popular Categories

software (9409)
internet (9249)
business (8210)
online (6824)
health (6764)
free (5978)
home (5803)
news (5665)
tools (5066)
web (4912)
web2.0 (4201)
game (4149)
& (3840)
shopping (3790)
social (3616)
games (3516)
golf (3448)
default (3376)
blog (3205)
search (3120)
design (3102)
arizona (3094)
music (2910)
lasvegas (2880)
mortgage (2856)
myrtlebeach (2855)
golfswing (2852)
golfclubs (2851)
desktop (2843)
credit (2819)
windows (2726)
download (2700)
mp3 (2606)
file (2502)
management (2450)
screen (2440)
bookmarks (2394)
video (2374)
security (2321)
money (2251)
loans (2243)
loan (2223)
screensaver (2159)
utilities (2150)
email (2118)
education (2104)
image (1968)
debt (1942)
finance (1915)
to (1907)

How to Get Rid of ThinkSmart Antivirus hotfix.exe defender.exe? Eliminate & Remove ThinkSmart Installed via Fake Microsoft Alert

by Tom Parks

posted in Computers and Technology : Security

Syndicate This Article
Code: BZCL3. 3$ Dto si pedidos encima de 30$

How to Get Rid of ThinkSmart Antivirus? Eliminate & Remove ThinkSmart Fake Antivirus Completely. How to remove ThinkSmart

ThinkSmart Antivirus is not a legitimate and Real Antispyware Program but itself a spyware, more precisely a new kind of rogue antispyware program from the same family of ThinkPoint installed through a Trojan Fake Alert that mimics Microsoft Security Essentials Alert.

This program is distributed with the help of trojan Fake Microsoft Security Essentials Alert.

The fake "Microsoft Security Essentials Alert" is actually a Trojan that looks very similar to real alert from legitimate Microsoft Security Essentials. 

This trojan will try to trick you into thinking that your computer is infected. It will show the warning below

"Microsoft Security Essentials Alert Potential threat details

Microsoft Security Essentials detected potential threats that might compromise your privacy or damage your computer. Your access to these items may be suspended until you take an action. Click ‘Show details' to learn more

Unknown Win32/Trojan Severe"

When you click ‘Show details' It will then prompt you to clean your computer using the program in order to remove it. When you click on the ‘Clean Computer' or ‘Apply actions' button, it will state that it was unable to remove it and then prompt you to scan online.

"Unable to remove threat. Click "Scan online" to remove this threat"

If you click on the Scan Online button it will list 35 different anti-virus programs, 30 of which are legitimate anti-virus programs and 5 that are rogues that the Trojan is distributing.

These five rogue programs are:

•Red Cross Antivirus
•Red Cross Antivirus
•Pest Detector 4.1
•Major Defense Kit
•AntiSpySafeguard or AntiSpy Safeguard Plus

Think Point and now the new ThinkSmart

This fake alert was endorsing only five applications as above but recently it included Think Point and ThinkSmart as an addition to the family 

So that you will then ‘Free Install' and purchase this rogue anti-virus program that this Fake Microsoft Security Essentials Alert Trojan is distributing.

During this fake online scan only the 5 fake anti-virus programs plus ThinkSmart listed above will state that this supposed Microsoft Security Essentials Alert Trojan as an infection like ‘Unknown Trojan, Trojan Horse or Rootkit'.

It does this to scare you into clicking the Free Install button next to them that will install the rogue program onto your computer and then reboot your computer. It should be noted that ThinkSmart, ThinkPoint, Red Cross Antivirus, Peak protection 2010, Pest Detector 4.1, Major Defense Kit, AntiSpySafeguard or AntiSpy Safeguard theTrojan is distributing are exactly the same. They just have different names and different (GUI) graphical user interfaces.

When the trojan Fake Microsoft Security Essentials Alert is started, it will automatically download and install ThinkSmart Virus tool onto your computer without your consent and knowledge and configure it to run when you start Windows

When ThinkSmart Antivirus is started, it will imitate a system scan and detect a lot of various infections that will not be fixed unless you first purchase the program. Important to know, all of these reported infections are fake and don't actually exist on your computer! So you can safely ignore the scan results.

While ThinkSmart is running, it will block the ability to run any programs as a method to scare you into thinking that your computer is infected with malware 

The following warnings will be shown

"The application iexplore.exe was launched successfully but it was forced to shut down due to security reasons.

This happened because the application was infected by a malicious program which might pose a threat for the OS.

It is highly recommended to install the necessary heuristic module and perform a full scan of your computer to exterminate malicious programs from it."

Furthermore, these rogues will also fake messages such as:

Think Smart:

9191 – files checked

10 – files infected

5 – files restored

5 – files can't be restored (heuristic module missing)

Install the full version with the required modules

Continue unprotected

Warning! Database updated failed!
Database update failed!
Outdated viruses database are not effective can't guarantee adequate protection and security for your PC! Click here to get the full version of the product and update the database!

Warning! Running trial version!
The security of your computer has been compromised! Now running trial version of the software! Click here to purchase the full version of the software and get full protection for your PC!


Of course, all of above warnings and alerts nothing more but a scam and like false scan results should be ignored!

As you can see ThinkSmart Antivirus, is a scam that is designed with one purpose to trick you into purchasing the so-called full version. Do not fall for these virus creators bait into buying the Rogueware and if you already have, you should contact your credit card company and dispute the charges.

And now coming back on How to Get Rid of ThinkSmart Antivirus, you need a solid program to fix the damages, the rogue has caused. It alters files, folders,permissions and registry keys.

So you need something as good as Reimage, to fix all the damages that was left behind, to delete all the traces revive your PC from malicious trojans that may still reside and make your PC slow and to stop from getting re-infected.

When you try to fix this rogue, by running legitimate antivirus you encounter that app cannot be executed warning, task manager disabled, registry editing disabled etc..

So, in order to get rid of ThinkSmart Antivirus completely, start your PC in safe mode with networking, If you can`t run the IE, then you should as below.

If you can't open the task manager by pressing CTRL+ALT+DEL, you can run these commands and stop the fake AV processes first using these commands.

Try this before you fix proxy settings.

Go to C:Documents and SettingsUserProfileApplication Data.

It will open the contents of Application Data folder (for Windows XP) or the contents of Roaming folder (for Windows Vista, Windows 7).

By default, this is C:Documents and Settings\Application Data for Windows 2000/XP. For Windows Vista and Windows 7 it is C:Users\AppDataRoaming or C:Users\AppDataLocal. Conversely you can also Click on Start > Run and type shell:Local AppData

%UserProfile%\Application Data\hotfix.exe %UserProfile%\Application Data\thinksmart.exe %UserProfile%\Application Data\defender.exe

Now rename as below

-if you find ‘hotfix' rename it to hotfix1,

-if you find ‘defender' rename it to ‘defender1′.

-if you find ‘thinksmart' rename it to ‘thinksmart1′

It is normal if some files listed above does not exist.

Next, reboot your computer. Now you should now be able to connect to internet .

If you have problems renaming hotfix.exe, then do this.

Kill the process from Task Manager using instructions below.

Go to ‘Start'

Click ‘Run'


taskkill /f /im hotfix.exe


taskkill /f /im defender.exe


taskkill /f /im thinksmart.exe

If you can`t run the IE, then you should repair the proxy settings of Internet Explorer. Run Internet Explorer, Click Tools -> Internet Options. Select Connections Tab and click to Lan Settings button. Uncheck "Use a proxy server" box. Click OK. Click Apply.

Now Go to and run scan to get rid of ThinkSmart Antivirus.

Reimage works by comparing each and every OS system files with the correct files from a web repository of 25 million Windows components. (since Reimage works by comparing with correct file, it can easily find the hiding rootkit, infact this is what a rootkit remover do......dumps a list of files from your hard disk drive and compares it with the list from the recovery console in order to find a hiding virus) This is the sole reason you can get a PC as good as new once you run Reimage, all other antivirus and antimalware programs just delete the virus....but they don't correct the damage...which results in re-infection and slow performing PC.

Reimage first scans your computer thoroughly; all the files, folders, registry keys and values, drivers, softwares, stacks and then either repair or remove those stuffs that should be there. But it's not just that it does. They have an enormous web repository of application, drivers, system objects, etc. from where they compare your PC's files and if corrupted replace it with the healthy ones.

Visit Reimage For a Complete Scan Now to Get Rid of ThinkSmart Antivirus Fake Antivirus Completely

About the Author:

Tom Parks works for Microsoft. He is currently researching on PC optimization and system security. He is also an avid gamer and owns xbox, PS3, Nintendo Wii, Dsi and PSP. Visit my blog

Code: SAVEND18. Men's cloth on sale,huge save,extra $18 off $158 for any order
960P HD 360 Grad Wireless Wifi VR IP Kamera nur 21,49 €

Newest Articles in Security

Other articles by Tom Parks