Think Point is a rogue anti-spyware application which was created to lie to computer user about the security status of his machine. In reality, this scam is not capable to detect any computer trouble because it is a masked virus which will use security or other exploits to reach the targeted Operating System. As soon as Trojan infiltrates computer through misleading alert of fake Microsoft Security Essentials, it will start appearing on the desktop and then will continuously interrupt into a normal your PCs functionality. This alert presents Think Point as a “world’s leading security solution” which after checking PC for malware has detected some viruses, like Unknown Win32/Trojan. Additionally, rogue starts claiming that some of the viruses detected can’t be restored because of the heuristic module which is missing. However, Think Point offers to install these required modules but then asks paying ninety or more dollars.
9191 – files checked
10 – files infected
5 – files restored
5 – files can’t be restored (heuristic module missing)
Install the full version with the required modules
Remember – if you are unlucky enough to purchase and install Think Point rogue, you will soon encounter more serious PC problems like system degrading or slow down, Internet connection loss and general computer vulnerability (Think Point may let more viruses inside). Besides, this scam is promoted by Microsoft Security Essentials Alert which also promotes Red Cross Antivirus , AntiSpySafeguard, Peak Protection 2010, Pest Detector 4.1, Major Defense Kit, so it obviously should be removed immediately upon detection. Get a reputable anti-spyware and remove ThinkPoint!
UPDATE: A new version of Think Point has been released and published recently. Be careful with this infection and make sure you remove it as soon as possible.
Note! Because ThinkPoint may disable you from the Internet, try these special notes when removing it:
1. Restart your computer and before it launches Windows, start tapping “F8” key. Highlight “Safe Mode with Networking” with arrow keys and press ENTER.
2. Press CTRL+SHIFT+ESC to start Task Manager. Check for the processes of ThinkPoint and stop them.
2a. If the screen goes black, try launching explorer.exe from task manager.
2b. If you can’t kill Thinkpoints process, Try rebooting into safe mode, repeat 1 & 2 and search/delete for files you have stopped. Then Reboot into safe mode with networking and continue.
3. Open Internet Explorer, choose Tools menu and select Internet Options.
4. Click on the Connections tab and then on the LAN Settings button. Uncheck the checkbox labeled Use a proxy server for your LAN under the Proxy Server section and press OK.
5. Download spyhunter and run a full system scan. Delete files identified as infected.
For users that CAN NOT DO ANYTHING in safe mode and Normal mode
Some users claim, that they can not boot or do something in safe mode or safe mode with networking, as thinpoint blocks everything.
1. Reboot, press F8, Choose SAFE MODE WITH Command promt.
2. Enter these commands: regedit
3. Update the the key with the following value [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] “Shell”=”Explorer.exe”
3. CD to EACH USERS Application Data subfolders and delete hotfix.exe
4. Shutdown /r /t 1
5. Press F8, choose safe mode with networking
6. Download spyhunter ( https://www.2-viruses.com/spdoc.exe ), update, do a full system scan and delete what in detects.
7. Reboot, scan last time with spyhunter, Malwarebytes Anti-Malware and your antivirus. If you haven’t done in a while, update these tools
We recommend upgrading to full versions of either spyhunter or Malwarebytes Anti-Malware to stay protected from this malware in the future. A decent internet security suite would protect you as well.
As of 2011.03, thinkPoint was replaced by CleanThis malware that is very similar to its predecessor.
Automatic Malware removal tools