Jump to content

Welcome to Geeks to Go
Geeks to Go Welcome
Create Account Login to Account
Photo

Removal instructions for Secure PC Cleaner

- - - - -

  • Please log in to reply
No replies to this topic

#1
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 32,369 posts
Content is republished with permission from Malwarebytes.

What is Secure PC Cleaner?

The Malwarebytes research team has determined that Secure PC Cleaner is a fake registry cleaner. These so-called "registry cleaners" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems.
More information can be found on our Malwarebytes Unpacked blog.

How do I know if I am infected with Secure PC Cleaner?

This is how the main screen of the registry cleaning application looks:

warning7.png

You will find these icons in your taskbar and on your desktop:

icons.png

And see these warnings during install:

main.png

warning1.png

and these screens during "operations":

warning5.png

warning6.png

You may see this entry in your list of installed programs:

warning4.png

and these tasks in your Task Scheduler:

warning3.png


How did Secure PC Cleaner get on my computer?

These so-called registry cleaners use different methods of getting installed. This particular one was bundled by other software.

How do I remove Secure PC Cleaner?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted application.
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan Now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
Is there anything else I need to do to get rid of Secure PC Cleaner?
  • No, Malwarebytes' Anti-Malware removes Secure PC Cleaner completely.
  • This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this registry cleaner.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the Secure PC Cleaner installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late.

protection1.png


Technical details for experts

You may see these entries in FRST logs:

 (Secure PC Cleaner) C:\Program Files (x86)\Secure PC Cleaner\SecurePCCleaner.exe
 () C:\Users\{username}\AppData\Roaming\Event Monitor\em.exe
 C:\Windows\System32\Tasks\Secure PC Cleaner_DEFAULT
 C:\Windows\System32\Tasks\Secure PC Cleaner
 C:\Windows\System32\Tasks\Secure PC Cleaner_UPDATES
 C:\Windows\System32\Tasks\RunAtStartup
 C:\Users\Public\Desktop\Secure PC Cleaner.lnk
 C:\Windows\Tasks\Secure PC Cleaner_UPDATES.job
 C:\Windows\Tasks\Secure PC Cleaner_DEFAULT.job
 C:\Users\{username}\AppData\Roaming\Secure PC Cleaner
 C:\Users\{username}\AppData\Roaming\Event Monitor
 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure PC Cleaner
 C:\Program Files (x86)\Secure PC Cleaner

Secure PC Cleaner (HKLM-x32\...\Secure PC Cleaner_is1) (Version: 4.5 - www.securepccleaner.com/)
Task: {413B15D1-9506-417D-83C9-786658C9E90F} - System32\Tasks\Secure PC Cleaner => C:\Program Files (x86)\Secure PC Cleaner\SecurePCCleaner.exe [2016-04-15] (Secure PC Cleaner)
Task: {422696BC-ECBF-4B29-B042-75BE24861809} - System32\Tasks\RunAtStartup => C:\Users\{username}\AppData\Roaming\Event Monitor\em.exe [2016-04-27] ()
Task: {5F42ADDE-3F69-406E-8659-7E78FA906FC6} - System32\Tasks\Secure PC Cleaner_UPDATES => C:\Program Files (x86)\Secure PC Cleaner\SecurePCCleaner.exe [2016-04-15] (Secure PC Cleaner)
Task: {CC98E0FB-6BDE-4ED1-8611-B6B6FB2A653B} - System32\Tasks\Secure PC Cleaner_DEFAULT => C:\Program Files (x86)\Secure PC Cleaner\SecurePCCleaner.exe [2016-04-15] (Secure PC Cleaner)
Task: C:\Windows\Tasks\Secure PC Cleaner_DEFAULT.job => C:\Program Files (x86)\Secure PC Cleaner\SecurePCCleaner.exe
Task: C:\Windows\Tasks\Secure PC Cleaner_UPDATES.job => C:\Program Files (x86)\Secure PC Cleaner\SecurePCCleaner.exe
Alterations made by the installer:

File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Program Files (x86)\Secure PC Cleaner
       Adds the file Chinese_pcp.ini"="3/11/2016 12:17 PM, 38356 bytes, A
       Adds the file Chinese_uninst.ini"="1/20/2016 2:42 PM, 2646 bytes, A
       Adds the file Danish_pcp.ini"="3/11/2016 12:17 PM, 81680 bytes, A
       Adds the file Danish_uninst.ini"="1/20/2016 2:42 PM, 2948 bytes, A
       Adds the file Dutch_pcp.ini"="3/11/2016 12:17 PM, 85940 bytes, A
       Adds the file Dutch_uninst.ini"="1/20/2016 2:42 PM, 2944 bytes, A
       Adds the file emsetup.exe"="4/27/2016 4:39 PM, 1307104 bytes, A
       Adds the file eng_pcp.ini"="3/11/2016 12:17 PM, 75146 bytes, A
       Adds the file eng_uninst.ini"="1/20/2016 2:42 PM, 2830 bytes, A
       Adds the file FileList.pcp"="1/20/2016 2:42 PM, 13612 bytes, A
       Adds the file Finnish_pcp_fi.ini"="3/11/2016 12:17 PM, 79138 bytes, A
       Adds the file Finnish_uninst_fi.ini"="1/20/2016 2:42 PM, 3024 bytes, A
       Adds the file French_pcp.ini"="3/11/2016 12:17 PM, 91972 bytes, A
       Adds the file French_uninst.ini"="1/20/2016 2:42 PM, 3040 bytes, A
       Adds the file German_pcp.ini"="3/11/2016 12:17 PM, 91418 bytes, A
       Adds the file German_uninst.ini"="4/15/2016 1:39 PM, 3382 bytes, A
       Adds the file greek_pcp_el.ini"="3/11/2016 12:17 PM, 90622 bytes, A
       Adds the file greek_uninst_el.ini"="1/20/2016 2:42 PM, 3206 bytes, A
       Adds the file install_left_image.bmp"="1/22/2016 1:00 PM, 156296 bytes, A
       Adds the file isxdl.dll"="4/15/2016 1:39 PM, 157616 bytes, A
       Adds the file Italian_pcp.ini"="3/11/2016 12:17 PM, 88312 bytes, A
       Adds the file Italian_uninst.ini"="1/20/2016 2:42 PM, 2948 bytes, A
       Adds the file Japanese_pcp.ini"="3/11/2016 12:17 PM, 51168 bytes, A
       Adds the file Japanese_uninst.ini"="1/20/2016 2:42 PM, 2734 bytes, A
       Adds the file korean_pcp_ko.ini"="3/11/2016 12:17 PM, 59774 bytes, A
       Adds the file korean_uninst_ko.ini"="1/20/2016 2:42 PM, 2712 bytes, A
       Adds the file Norwegian_pcp.ini"="3/11/2016 12:17 PM, 78072 bytes, A
       Adds the file Norwegian_uninst.ini"="1/20/2016 2:42 PM, 2888 bytes, A
       Adds the file polish_pcp_pl.ini"="3/11/2016 12:17 PM, 81628 bytes, A
       Adds the file polish_uninst_pl.ini"="1/20/2016 2:42 PM, 3066 bytes, A
       Adds the file portugese_pcp_pt.ini"="3/11/2016 12:17 PM, 84934 bytes, A
       Adds the file portugese_uninst_pt.ini"="1/20/2016 2:42 PM, 2950 bytes, A
       Adds the file Portuguese_pcp.ini"="3/11/2016 12:17 PM, 82554 bytes, A
       Adds the file Portuguese_uninst.ini"="1/20/2016 2:42 PM, 2950 bytes, A
       Adds the file RegList.pcp"="1/20/2016 2:42 PM, 92210 bytes, A
       Adds the file russian_pcp_ru.ini"="3/11/2016 12:17 PM, 84912 bytes, A
       Adds the file russian_uninst_ru.ini"="1/20/2016 2:42 PM, 3214 bytes, A
       Adds the file SecurePCCleaner.exe"="4/15/2016 1:39 PM, 9004464 bytes, A
       Adds the file Spanish_pcp.ini"="3/11/2016 12:17 PM, 86544 bytes, A
       Adds the file spanish_uninst.ini"="1/20/2016 2:42 PM, 3086 bytes, A
       Adds the file SPCCUns.exe"="4/15/2016 1:39 PM, 572336 bytes, A
       Adds the file Swedish_pcp.ini"="3/11/2016 12:17 PM, 76830 bytes, A
       Adds the file swedish_uninst.ini"="1/20/2016 2:42 PM, 2962 bytes, A
       Adds the file TPS.ico"="1/20/2016 2:42 PM, 34494 bytes, A
       Adds the file TraditionalCn_pcp_zh-tw.ini"="3/11/2016 12:17 PM, 38426 bytes, A
       Adds the file traditionalcn_uninst_zh-tw.ini"="1/20/2016 2:42 PM, 2654 bytes, A
       Adds the file turkish_pcp_tr.ini"="3/11/2016 12:17 PM, 82408 bytes, A
       Adds the file Turkish_uninst_tr.ini"="1/20/2016 2:42 PM, 3060 bytes, A
       Adds the file unins000.dat"="5/31/2016 12:08 PM, 39885 bytes, A
       Adds the file unins000.exe"="5/31/2016 12:07 PM, 1210800 bytes, A
       Adds the file unins000.msg"="5/31/2016 12:08 PM, 22701 bytes, A
       Adds the file xmllite.dll"="1/20/2016 2:42 PM, 126976 bytes, A
    Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure PC Cleaner
       Adds the file Register Secure PC Cleaner.lnk"="5/31/2016 12:08 PM, 1149 bytes, A
       Adds the file Secure PC Cleaner.lnk"="5/31/2016 12:08 PM, 1123 bytes, A
       Adds the file Uninstall Secure PC Cleaner.lnk"="5/31/2016 12:08 PM, 1088 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Event Monitor
       Adds the file em.exe"="4/27/2016 4:39 PM, 3297728 bytes, A
       Adds the file eng_em.ini"="4/18/2016 4:38 PM, 634 bytes, A
       Adds the file French_em.ini"="4/18/2016 4:38 PM, 662 bytes, A
       Adds the file German_em.ini"="4/22/2016 6:35 PM, 708 bytes, A
       Adds the file ininotfound0.ini"="5/31/2016 12:08 PM, 172 bytes, A
       Adds the file isxdl.dll"="4/27/2016 4:39 PM, 156608 bytes, A
       Adds the file log_05-31-2016.log"="5/31/2016 12:08 PM, 0 bytes, A
       Adds the file update.ini"="5/31/2016 12:08 PM, 338 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Secure PC Cleaner
       Adds the file backup6.bin"="5/31/2016 12:08 PM, 622 bytes, A
       Adds the file eng_pcp.dat"="5/31/2016 12:08 PM, 29190 bytes, A
       Adds the file log_05-31-2016.log"="5/31/2016 12:08 PM, 0 bytes, A
       Adds the file results.pcp"="5/31/2016 12:08 PM, 6828 bytes, A
    In the existing folder C:\Users\Public\Desktop
       Adds the file Secure PC Cleaner.lnk"="5/31/2016 12:08 PM, 1105 bytes, A
    In the existing folder C:\Windows\System32\Tasks
       Adds the file RunAtStartup"="5/31/2016 12:08 PM, 3012 bytes, A
       Adds the file Secure PC Cleaner"="5/31/2016 12:08 PM, 3154 bytes, A
       Adds the file Secure PC Cleaner_DEFAULT"="5/31/2016 12:08 PM, 3256 bytes, A
       Adds the file Secure PC Cleaner_UPDATES"="5/31/2016 12:08 PM, 3068 bytes, A
    In the existing folder C:\Windows\Tasks
       Adds the file Secure PC Cleaner_DEFAULT.job"="5/31/2016 12:08 PM, 302 bytes, A
       Adds the file Secure PC Cleaner_UPDATES.job"="5/31/2016 12:08 PM, 310 bytes, A

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures]
       "Secure PC Cleaner_DEFAULT.job"="REG_BINARY, ............................z...
       "Secure PC Cleaner_DEFAULT.job.fp"="REG_DWORD", -1577655805
       "Secure PC Cleaner_UPDATES.job"="REG_BINARY, ................................
       "Secure PC Cleaner_UPDATES.job.fp"="REG_DWORD", 808472808
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Event Monitor]
       "bShowCongratsAfterUpdateRestart"="REG_DWORD", 0
       "Expired"="REG_DWORD", 0
       "TELNO"="REG_SZ", "(844) 763-5838"
       "TELNODE"="REG_SZ", "(800) 180-6512"
       "TELNOFR"="REG_SZ", "01.76.54.05.61"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Event Monitor\LANG]
       "LangCode"="REG_SZ", "en"
       "LangID"="REG_DWORD", 0
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Jawego\Params]
       "affiliateid"="REG_SZ", ""
       "SPCC"="REG_DWORD", 1
       "utm_campaign"="REG_SZ", "1029dl"
       "utm_medium"="REG_SZ", "newbuild"
       "utm_source"="REG_SZ", "1029dl"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Secure PC Cleaner_is1]
       "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\Secure PC Cleaner\SecurePCCleaner.exe"
       "DisplayName"="REG_SZ", "Secure PC Cleaner"
       "DisplayVersion"="REG_SZ", "4.5"
       "EstimatedSize"="REG_DWORD", 13930
       "HelpLink"="REG_SZ", "http://www.securepccleaner.com/"
       "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\Secure PC Cleaner"
       "Inno Setup: Icon Group"="REG_SZ", "Secure PC Cleaner"
       "Inno Setup: Language"="REG_SZ", "en"
       "Inno Setup: Setup Version"="REG_SZ", "5.5.6 (u)"
       "Inno Setup: User"="REG_SZ", "{username}"
       "InstallDate"="REG_SZ", "20160531"
       "InstallLocation"="REG_SZ", "C:\Program Files (x86)\Secure PC Cleaner\"
       "MajorVersion"="REG_DWORD", 4
       "MinorVersion"="REG_DWORD", 5
       "NoModify"="REG_DWORD", 1
       "NoRepair"="REG_DWORD", 1
       "Publisher"="REG_SZ", "www.securepccleaner.com/"
       "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\Secure PC Cleaner\unins000.exe" /SILENT"
       "UninstallString"="REG_SZ", ""C:\Program Files (x86)\Secure PC Cleaner\unins000.exe" /silent"
       "URLInfoAbout"="REG_SZ", "http://www.securepccleaner.com/"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Secure\PC\Cleaner\key\6]
       "(Default)"="REG_BINARY, .......................................................................................................................o............................................................................................................................H...........
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Secure PC Cleaner]
       "Expired"="REG_DWORD", 0
       "FirstTimeASPFired"="REG_DWORD", 1
       "MaxFixLimit"="REG_DWORD", 15
       "PCPURL"="REG_SZ", "http://www.securepccleaner.com/buynow/?utm_source=1029dl&utm_campaign=1029dl&utm_medium=newbuild"
       "RENEWALURL"="REG_SZ", "http://www.securepccleaner.com/renewal/?utm_source=1029dl&utm_campaign=1029dl&utm_medium=newbuild"
       "ShowExitPage"="REG_DWORD", 0
       "TELNO"="REG_SZ", "(844) 763-5836"
       "TELNODE"="REG_SZ", "(800) 180-6512"
       "TELNOFR"="REG_SZ", "01.76.54.27.59"
       "utm_campaign"="REG_SZ", "1029dl"
       "utm_medium"="REG_SZ", "newbuild"
       "utm_source"="REG_SZ", "1029dl"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Secure PC Cleaner\LANG]
       "LangID"="REG_DWORD", 0
    [HKEY_CURRENT_USER\Software\Event Monitor\LANG]
       "LangCode"="REG_SZ", "en"
       "LangID"="REG_DWORD", 0
    [HKEY_CURRENT_USER\Software\Secure\PC\Cleaner\key\6]
       "(Default)"="REG_BINARY, .......................................................................................................................o............................................................................................................................H...........
    [HKEY_CURRENT_USER\Software\Secure PC Cleaner]
       "1stInstalled_Time"="REG_SZ", "5/31/2016 12:08:01 PM"
       "AutoRepair"="REG_DWORD", 0
       "ConfirmBkUps"="REG_DWORD", 1
       "CurrentScanTime"="REG_BINARY, ......9.
       "ErrorCount"="REG_DWORD", 18
       "FirstRun"="REG_DWORD", 1
       "GoToSystemTrayOnClose"="REG_DWORD", 0
       "ImprovementProgram"="REG_DWORD", 1
       "NumTimesPCPRunned"="REG_DWORD", 1
       "RegErrFoundTillDate"="REG_DWORD", 0
       "RegErrsFixedLast"="REG_DWORD", 0
       "RegErrsFixedTillDate"="REG_DWORD", 0
       "ScheduledTime"="REG_SZ", ""
       "SetChkDontShowRedTrayPopup"="REG_DWORD", 0
       "SetChkREmovableMedia"="REG_DWORD", 1
       "SetChkSkipEmptyKeys"="REG_DWORD", 1
       "SetEnableSound"="REG_DWORD", 1
       "StartAutoScanOnLaunch"="REG_DWORD", 0
       "StartAutoScanPMUI"="REG_DWORD", 0
       "StartAutoTutorial"="REG_DWORD", 1
       "StartMinimized"="REG_DWORD", 0
       "StartScan"="REG_DWORD", 0
       "StartWhenWinBoots"="REG_DWORD", 1
       "StrLastOptimizeTime"="REG_SZ", ""
       "StrLastScan"="REG_SZ", "Tue. May 31, 2016. 12:08 PM"
       "StrLastScanResults"="REG_SZ", "18"
       "StrLastStartupOpt"="REG_SZ", ""
       "StrLatestRegDefrag"="REG_SZ", ""
       "StrLatestRestorePoint"="REG_SZ", ""
       "TrialType"="REG_DWORD", 0
    [HKEY_CURRENT_USER\Software\Secure PC Cleaner\LANG]
       "LangCode"="REG_SZ", "en"
       "LangID"="REG_DWORD", 0

Malwarebytes Anti-Malware log:

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 5/31/2016
Scan Time: 12:19 PM
Logfile: mbamSecurePCCleaner.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.05.31.02
Rootkit Database: v2016.05.27.01
License: Premium
Malware Protection: Disabled
Malicious Website Protection: Enabled
Self-protection: Enabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {username}

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 312388
Time Elapsed: 8 min, 23 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 2
PUP.Optional.EventMonitor, C:\Users\{username}\AppData\Roaming\Event Monitor\em.exe, 4056, Delete-on-Reboot, [d29ce4f8dbbe3501000c883e34cd7b85]
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\SecurePCCleaner.exe, 2768, Delete-on-Reboot, [caa47f5d3267c670ba0c2a8744bed32d]

Modules: 3
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\isxdl.dll, Delete-on-Reboot, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\xmllite.dll, Delete-on-Reboot, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.EventMonitor, C:\Users\{username}\AppData\Roaming\Event Monitor\isxdl.dll, Delete-on-Reboot, [a7c78b51c4d5b97d7c67106b42c2f10f], 

Registry Keys: 12
PUP.Optional.SecurePCCleaner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Secure PC Cleaner, Delete-on-Reboot, [81edc7157d1c1323abb8dc085aa905fb], 
PUP.Optional.SecurePCCleaner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Secure PC Cleaner_DEFAULT, Delete-on-Reboot, [cba38f4d4653f640a6bde9fb2bd857a9], 
PUP.Optional.SecurePCCleaner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Secure PC Cleaner_UPDATES, Delete-on-Reboot, [74fa4894f1a8db5b451ee5ffde25f20e], 
PUP.Optional.PCCleanPlus, HKLM\SOFTWARE\WOW6432NODE\Jawego, Quarantined, [aac4ce0ed6c3c47292f8edf7b35042be], 
PUP.Optional.SecurePCCleaner, HKLM\SOFTWARE\WOW6432NODE\Secure PC Cleaner, Quarantined, [2a4429b364357eb883e254902dd6ce32], 
PUP.Optional.SecurePCCleaner, HKLM\SOFTWARE\WOW6432NODE\EVENT MONITOR, Quarantined, [dd914993425747ef028abf250df61ee2], 
PUP.Optional.SecurePCCleaner, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Secure PC Cleaner_is1, Quarantined, [74fa0fcda4f52e08481c07ddc241966a], 
PUP.Optional.SecurePCCleaner, HKLM\SOFTWARE\WOW6432NODE\SECURE\PC\Cleaner, Quarantined, [5e10ecf0485114220363f3f10ef5916f], 
PUP.Optional.SecurePCCleaner, HKCU\SOFTWARE\Event Monitor, Quarantined, [630b6676693041f5404bbb29eb18b34d], 
PUP.Optional.SecurePCCleaner, HKCU\SOFTWARE\Secure PC Cleaner, Quarantined, [a9c5b6264b4ead89570ad60e3fc4ce32], 
PUP.Optional.SecurePCCleaner, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\DDAAD53_0, Quarantined, [d599f0ec0099eb4b2f31e004cc37d729], 
PUP.Optional.SecurePCCleaner, HKCU\SOFTWARE\SECURE\PC\Cleaner, Quarantined, [1e50e8f49bfeec4afc66d60e11f28e72], 

Registry Values: 2
PUP.Optional.SecurePCCleaner, HKLM\SOFTWARE\WOW6432NODE\EVENT MONITOR|TELNO, (844) 763-5838, Quarantined, [dd914993425747ef028abf250df61ee2]
PUP.Optional.SecurePCCleaner, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\ddaad53_0, {0.0.0.00000000}.{6256f43c-1fdb-48f9-92d4-02b7de615556}|\Device\HarddiskVolume2\Program Files (x86)\Secure PC Cleaner\SecurePCCleaner.exe%b{00000000-0000-0000-0000-000000000000}, Quarantined, [d599f0ec0099eb4b2f31e004cc37d729]

Registry Data: 0
(No malicious items detected)

Folders: 4
PUP.Optional.SecurePCCleaner, C:\Users\{username}\AppData\Roaming\Secure PC Cleaner, Delete-on-Reboot, [35395884bcddb28454711f9218eaa759], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner, Delete-on-Reboot, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure PC Cleaner, Quarantined, [620ca834dfbad66026a19d1489799c64], 
PUP.Optional.EventMonitor, C:\Users\{username}\AppData\Roaming\Event Monitor, Delete-on-Reboot, [a7c78b51c4d5b97d7c67106b42c2f10f], 

Files: 74
PUP.Optional.EventMonitor, C:\Users\{username}\AppData\Roaming\Event Monitor\em.exe, Delete-on-Reboot, [d29ce4f8dbbe3501000c883e34cd7b85], 
PUP.Optional.SecurePCCleaner, C:\Users\{username}\Desktop\spccsetup.exe, Quarantined, [f77718c43f5af0467504a5cf37cde917], 
PUP.Optional.SecurePCCleaner, C:\Users\Public\Desktop\Secure PC Cleaner.lnk, Quarantined, [d6986d6ff7a2bd791b425d87a95a1be5], 
PUP.Optional.SecurePCCleaner, C:\Windows\System32\Tasks\Secure PC Cleaner, Quarantined, [046a63792871c076e17da53fc53e7987], 
PUP.Optional.SecurePCCleaner, C:\Windows\System32\Tasks\Secure PC Cleaner_DEFAULT, Quarantined, [5816c7150099fd39c19d4f950ff425db], 
PUP.Optional.SecurePCCleaner, C:\Windows\System32\Tasks\Secure PC Cleaner_UPDATES, Quarantined, [2b433ca01089bf77e579a2421de6629e], 
PUP.Optional.SecurePCCleaner, C:\Windows\Tasks\Secure PC Cleaner_DEFAULT.job, Quarantined, [a1cdc913029771c5fd620fd5b3507888], 
PUP.Optional.SecurePCCleaner, C:\Windows\Tasks\Secure PC Cleaner_UPDATES.job, Quarantined, [3a3418c4d0c91d19f66954909a6953ad], 
PUP.Optional.SecurePCCleaner, C:\Users\{username}\AppData\Roaming\Secure PC Cleaner\backup6.bin, Quarantined, [35395884bcddb28454711f9218eaa759], 
PUP.Optional.SecurePCCleaner, C:\Users\{username}\AppData\Roaming\Secure PC Cleaner\eng_pcp.dat, Quarantined, [35395884bcddb28454711f9218eaa759], 
PUP.Optional.SecurePCCleaner, C:\Users\{username}\AppData\Roaming\Secure PC Cleaner\log_05-31-2016.log, Delete-on-Reboot, [35395884bcddb28454711f9218eaa759], 
PUP.Optional.SecurePCCleaner, C:\Users\{username}\AppData\Roaming\Secure PC Cleaner\results.pcp, Quarantined, [35395884bcddb28454711f9218eaa759], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Finnish_pcp_fi.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Italian_pcp.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\RegList.pcp, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Chinese_pcp.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Chinese_uninst.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Danish_pcp.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Danish_uninst.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Dutch_pcp.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Dutch_uninst.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\emsetup.exe, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\eng_pcp.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\eng_uninst.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\FileList.pcp, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Italian_uninst.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Japanese_pcp.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Japanese_uninst.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\korean_pcp_ko.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\korean_uninst_ko.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Norwegian_pcp.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Norwegian_uninst.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\polish_pcp_pl.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\polish_uninst_pl.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\portugese_pcp_pt.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\portugese_uninst_pt.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Portuguese_pcp.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Portuguese_uninst.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Finnish_uninst_fi.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\French_pcp.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\French_uninst.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\German_pcp.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\German_uninst.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\greek_pcp_el.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\greek_uninst_el.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\install_left_image.bmp, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\isxdl.dll, Delete-on-Reboot, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\russian_pcp_ru.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\russian_uninst_ru.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\SecurePCCleaner.exe, Delete-on-Reboot, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Spanish_pcp.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\spanish_uninst.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\SPCCUns.exe, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Swedish_pcp.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\swedish_uninst.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\TPS.ico, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\TraditionalCn_pcp_zh-tw.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\traditionalcn_uninst_zh-tw.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\turkish_pcp_tr.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\Turkish_uninst_tr.ini, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\unins000.dat, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\unins000.exe, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\unins000.msg, Quarantined, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\Program Files (x86)\Secure PC Cleaner\xmllite.dll, Delete-on-Reboot, [caa47f5d3267c670ba0c2a8744bed32d], 
PUP.Optional.SecurePCCleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure PC Cleaner\Register Secure PC Cleaner.lnk, Quarantined, [620ca834dfbad66026a19d1489799c64], 
PUP.Optional.SecurePCCleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure PC Cleaner\Secure PC Cleaner.lnk, Quarantined, [620ca834dfbad66026a19d1489799c64], 
PUP.Optional.SecurePCCleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure PC Cleaner\Uninstall Secure PC Cleaner.lnk, Quarantined, [620ca834dfbad66026a19d1489799c64], 
PUP.Optional.EventMonitor, C:\Users\{username}\AppData\Roaming\Event Monitor\update.ini, Quarantined, [a7c78b51c4d5b97d7c67106b42c2f10f], 
PUP.Optional.EventMonitor, C:\Users\{username}\AppData\Roaming\Event Monitor\eng_em.ini, Quarantined, [a7c78b51c4d5b97d7c67106b42c2f10f], 
PUP.Optional.EventMonitor, C:\Users\{username}\AppData\Roaming\Event Monitor\French_em.ini, Quarantined, [a7c78b51c4d5b97d7c67106b42c2f10f], 
PUP.Optional.EventMonitor, C:\Users\{username}\AppData\Roaming\Event Monitor\German_em.ini, Quarantined, [a7c78b51c4d5b97d7c67106b42c2f10f], 
PUP.Optional.EventMonitor, C:\Users\{username}\AppData\Roaming\Event Monitor\ininotfound0.ini, Quarantined, [a7c78b51c4d5b97d7c67106b42c2f10f], 
PUP.Optional.EventMonitor, C:\Users\{username}\AppData\Roaming\Event Monitor\isxdl.dll, Delete-on-Reboot, [a7c78b51c4d5b97d7c67106b42c2f10f], 
PUP.Optional.EventMonitor, C:\Users\{username}\AppData\Roaming\Event Monitor\log_05-31-2016.log, Delete-on-Reboot, [a7c78b51c4d5b97d7c67106b42c2f10f], 

Physical Sectors: 0
(No malicious items detected)


(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
  • 0

Advertisements





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

featured
Malware Removal How to Guides Windows 7 System Building Download Files Register welcome

Never used a forum? Learn how.