{"id":72723,"date":"2010-11-16T06:14:23","date_gmt":"2010-11-16T06:14:23","guid":{"rendered":"https:\/\/localhost\/wordpress\/?p=72723"},"modified":"2010-11-16T06:14:23","modified_gmt":"2010-11-16T06:14:23","slug":"fake-microsoft-security-essentials","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/fake-microsoft-security-essentials\/","title":{"rendered":"Fake Microsoft Security Essentials"},"content":{"rendered":"<p>We have analyzed few rogue security programs which displays fake Microsoft Security Essentials threat alerts.<\/p>\n<p>When certain programs are launched then this FakeAV program displays a fake Security Essentials alert dialog.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/1_mse.jpg\" alt=\"\" width=\"576\" height=\"571\" \/><\/p>\n<p>If users closes this dialog box then it also terminates the program that it reports as a threat.<br \/>\nIt claims as threat to the genuine programs including Internet Explorer and other common web browsers.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/2_mse.jpg\" alt=\"\" width=\"577\" height=\"244\" \/><\/p>\n<p>In order to clean these fake threat it claims that you need to install AV software.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/3_mse.jpg\" alt=\"\" width=\"577\" height=\"244\" \/><\/p>\n<p>It then installs fakeav &#8220;ThinkPoint&#8221; whcih comes after reboot the machine. After reboot user see the rogue&#8217;s &#8220;ThinkPoint&#8221;<br \/>\nGUI instead of your desktop. This Fakeav run its own scan and reports multiple threats messages and claims that you<br \/>\nneed to buy the full version of the scanner to remove the threats.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/4_mse.jpg\" alt=\"\" width=\"705\" height=\"450\" \/><\/p>\n<p>Quick Heal Antivirus detects and removes this Fakeav programs successfully.<\/p>\n<p>If your computer has been infected by this FakeAV then to terminate it&#8217;s process follow below instructions:<\/p>\n<p>1&gt; Click Settings on the ThinkPoint menu tab.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/6_mse.jpg\" alt=\"\" width=\"541\" height=\"318\" \/><\/p>\n<p>2&gt; Check Allow unprotected startup.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/7_mse.jpg\" alt=\"\" width=\"407\" height=\"406\" \/><\/p>\n<p>3&gt; Click Save settings.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/8_mse.jpg\" alt=\"\" width=\"408\" height=\"409\" \/><\/p>\n<p>You should now be able to close the rogue\u2019s window and Windows Explorer will run.<\/p>\n<p>4&gt; Open a command prompt and type &#8220;taskkill \/IM hotfix.exe&#8221; to kill Fakeav&#8217;s processes.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have analyzed few rogue security programs which displays fake Microsoft Security Essentials threat alerts. When certain programs are launched then this FakeAV program displays a fake Security Essentials alert dialog. If users closes this dialog box then it also terminates the program that it reports as a threat. It claims as threat to the [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-72723","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/72723"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=72723"}],"version-history":[{"count":0,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/72723\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=72723"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=72723"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=72723"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}