×
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
websterslair
Former Member
Message 1 of 5

FAKE MICROSOFT SECURITY ESSENTIALS ALERT TROJAN

Jump to solution

I am running Windows 7 Ultimate with McAfee Internet Security 2010 with all updates current.  I had what appeared to be a Java Update load, then a "Microsoft Security Essentials Alert" pop-up came onto the screen.  I can see from various web postings this is a fake AV Trojan, but cannot find anything worthwhile on removing it.  I have tried running GetSusp 3.0.0.81 but when I attempt to view the report the pop up comes up again, preventing IE8 from launching.  It appears there is a file called hotfix.exe that is suspicious as well as mmfinfo.dll

1 Solution

Accepted Solutions
vinoo
Former Member
Message 4 of 5

Re: FAKE MICROSOFT SECURITY ESSENTIALS ALERT TROJAN

Jump to solution

C:\Users\Lee\AppData\Roaming\hotfix.exe is confirmed malicious.

md5: 5a230eb885af102f611cf882129ab640

Please reboot in safe mode and delete this file.

View solution in original post

4 Replies
CopyRon
Former Member
Message 2 of 5

Re: FAKE MICROSOFT SECURITY ESSENTIALS ALERT TROJAN

Jump to solution

Download and install mawarebytes, update and run quick scan.

http://http://www.malwarebytes.org/

This shoud remove the trojan.

Hayton
Reliable Contributor
Reliable Contributor
Message 3 of 5

Re: FAKE MICROSOFT SECURITY ESSENTIALS ALERT TROJAN

Jump to solution

With apologies to CopyRon, it may take slightly more than Malwarebytes to get rid of this rogue program (much as I admire Malwarebytes).

The removal issue is being discussed all over the place, but I've picked out two threads from other forums that websterslair should read through carefully. One is from VirusRemovalGuru - http://www.virusremovalguru.com/?p=5687

The other is from the Microsoft Security Essentials Forum -

http://social.answers.microsoft.com/Forums/en-US/msescan/thread/e6a8f912-270a-46ba-b3a1-dda329fbeed2

Between the two of them, it should be possible to find a method to remove this menace from an infected system. Perhaps websterslair would like to give some feedback to help anyone else who gets infected (and they probably will).

vinoo
Former Member
Message 4 of 5

Re: FAKE MICROSOFT SECURITY ESSENTIALS ALERT TROJAN

Jump to solution

C:\Users\Lee\AppData\Roaming\hotfix.exe is confirmed malicious.

md5: 5a230eb885af102f611cf882129ab640

Please reboot in safe mode and delete this file.

websterslair
Former Member
Message 5 of 5

Re: FAKE MICROSOFT SECURITY ESSENTIALS ALERT TROJAN

Jump to solution

Thanks for the help.  A quick note that this did come in looking like Java Update.  I have since went to my firewall settings and adjusted the permissions for both Adobe and Java Updates, as it seems that both the Action Antivirus and Fake Microsoft Secrity Essentials Alert Trojan are slipping by using this method.

How Many Badges Can You Collect?
Ready for a little competition? Members like you are earning badges and unlocking perks for their helpful answers. Are you? Click here to find out.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community