Jump to content

Recommended Posts

  • Staff
What is PC Clean Plus?

The Malwarebytes research team has determined that PC Clean Plus is a fake registry cleaner. These so-called "registry cleaners" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems.
More information about this type of PUPs can be found on our Malwarebytes Unpacked blog.

How do I know if I am infected with PC Clean Plus?

This is how the main screen of the registry cleaning application looks:

main.png

You will find these icons in your taskbar and on your desktop:

icons.png

And see these warnings during install:

install.png

warning1.png

warning2.png

and these screens during "operations":

warning3.png

warning6.png

You may see this entry in your list of installed programs:

warning4.png

and these tasks in your Task Scheduler:

warning5.png


How did PC Clean Plus get on my computer?

These so-called registry cleaners use different methods of getting installed. This particular one was bundled by other software.

How do I remove PC Clean Plus?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted application.
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan Now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
Is there anything else I need to do to get rid of PC Clean Plus?
  • No, Malwarebytes' Anti-Malware removes PC Clean Plus completely.
  • This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this registry cleaner.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the PC Clean Plus installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late.

Technical details for experts

No visible signs in a HijackThis log

You may see these entries in FRST logs:

 
 C:\Users\{username}\AppData\Roaming\PC Clean Plus
 C:\Windows\System32\Tasks\PC Clean Plus_DEFAULT
 C:\Windows\System32\Tasks\PC Clean Plus
 C:\Windows\System32\Tasks\PC Clean Plus_UPDATES
 C:\Users\Public\Desktop\PC Clean Plus.lnk
 C:\Windows\Tasks\PC Clean Plus_UPDATES.job
 C:\Windows\Tasks\PC Clean Plus_DEFAULT.job
 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus
 C:\Program Files (x86)\PC Clean Plus
 (Jawego Partners LLC ) C:\Users\{username}\Desktop\pccpsetup_p9jwsite.exe

PC Clean Plus (HKLM-x32\...\PC Clean Plus_is1) (Version: 3.6 - Jawego Partners LLC)
Task: {75422E6B-B5DB-4968-BAC6-41B068781CBE} - System32\Tasks\PC Clean Plus_DEFAULT => C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe [2016-01-07] (PC Clean Plus)
Task: {7E8EF9B9-6830-4310-B932-3ACB9CCEC182} - System32\Tasks\PC Clean Plus => C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe [2016-01-07] (PC Clean Plus)
Task: {8BEDA66A-710A-4D51-930F-D39BB591CE75} - System32\Tasks\PC Clean Plus_UPDATES => C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe [2016-01-07] (PC Clean Plus)
Task: C:\Windows\Tasks\PC Clean Plus_DEFAULT.job => C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe
Task: C:\Windows\Tasks\PC Clean Plus_UPDATES.job => C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe
Alterations made by the installer:
 
File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Program Files (x86)\PC Clean Plus
       Adds the file eng_pcp.ini"="29/12/2015 12:40, 85512 bytes, A
       Adds the file eng_uninst.ini"="03/12/2015 19:18, 2830 bytes, A
       Adds the file unins000.dat"="28/01/2016 09:14, 37829 bytes, A
       Adds the file unins000.exe"="28/01/2016 09:13, 1211056 bytes, A
       Adds the file unins000.msg"="28/01/2016 09:14, 22701 bytes, A
       Adds the file xmllite.dll"="17/11/2015 14:06, 126976 bytes, A
    Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus
       Adds the file PC Clean Plus.lnk"="28/01/2016 09:14, 1075 bytes, A
       Adds the file Register PC Clean Plus.lnk"="28/01/2016 09:14, 1101 bytes, A
       Adds the file Uninstall PC Clean Plus.lnk"="28/01/2016 09:14, 1060 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\PC Clean Plus
       Adds the file backup6.bin"="28/01/2016 09:14, 583 bytes, A
       Adds the file eng_pcp.dat"="28/01/2016 09:14, 32972 bytes, A
       Adds the file log_01-28-2016.log"="28/01/2016 09:14, 0 bytes, A
       Adds the file results.pcp"="28/01/2016 09:15, 10948 bytes, A
    In the existing folder C:\Users\Public\Desktop
       Adds the file PC Clean Plus.lnk"="28/01/2016 09:14, 1057 bytes, A
    In the existing folder C:\Windows\System32\Tasks
       Adds the file PC Clean Plus"="28/01/2016 09:14, 3122 bytes, A
       Adds the file PC Clean Plus_DEFAULT"="28/01/2016 09:14, 3240 bytes, A
       Adds the file PC Clean Plus_UPDATES"="28/01/2016 09:14, 3052 bytes, A
    In the existing folder C:\Windows\Tasks
       Adds the file PC Clean Plus_DEFAULT.job"="28/01/2016 09:14, 286 bytes, A
       Adds the file PC Clean Plus_UPDATES.job"="28/01/2016 09:14, 294 bytes, A

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures]
       "PC Clean Plus_DEFAULT.job"="REG_BINARY, ................................
       "PC Clean Plus_DEFAULT.job.fp"="REG_DWORD", -1249756553
       "PC Clean Plus_UPDATES.job"="REG_BINARY, ................................
       "PC Clean Plus_UPDATES.job.fp"="REG_DWORD", -2077534197
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Jawego\Params]
       "affiliateid"="REG_SZ", ""
       "PCCP"="REG_DWORD", 1
       "utm_campaign"="REG_SZ", "p9jwdefault"
       "utm_medium"="REG_SZ", "newbuild"
       "utm_source"="REG_SZ", "p9jwsite"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PC Clean Plus_is1]
       "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe"
       "DisplayName"="REG_SZ", "PC Clean Plus"
       "DisplayVersion"="REG_SZ", "3.6"
       "EstimatedSize"="REG_DWORD", 12788
       "HelpLink"="REG_SZ", "http://www.pccleanplus.com/"
       "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\PC Clean Plus"
       "Inno Setup: Icon Group"="REG_SZ", "PC Clean Plus"
       "Inno Setup: Language"="REG_SZ", "en"
       "Inno Setup: Setup Version"="REG_SZ", "5.5.6 (u)"
       "Inno Setup: User"="REG_SZ", "{username}"
       "InstallDate"="REG_SZ", "20160128"
       "InstallLocation"="REG_SZ", "C:\Program Files (x86)\PC Clean Plus\"
       "MajorVersion"="REG_DWORD", 3
       "MinorVersion"="REG_DWORD", 6
       "NoModify"="REG_DWORD", 1
       "NoRepair"="REG_DWORD", 1
       "Publisher"="REG_SZ", "Jawego Partners LLC"
       "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\PC Clean Plus\unins000.exe" /SILENT"
       "UninstallString"="REG_SZ", ""C:\Program Files (x86)\PC Clean Plus\unins000.exe" /silent"
       "URLInfoAbout"="REG_SZ", "http://www.pccleanplus.com/"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\PC\Clean\Plus\key\6]
       "(Default)"="REG_BINARY, .......................................................................................................................o............................................................................................................................H...........
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\PC Clean Plus]
       "Expired"="REG_DWORD", 0
       "FirstTimeASPFired"="REG_DWORD", 1
       "MaxFixLimit"="REG_DWORD", 15
       "PCPURL"="REG_SZ", "http://www.pccleanplus.com/buynow/?utm_source=p9jwsite&utm_campaign=p9jwdefault&utm_medium=newbuild"
       "RENEWALURL"="REG_SZ", "http://www.pccleanplus.com/renewal/?utm_source=p9jwsite&utm_campaign=p9jwdefault&utm_medium=newbuild"
       "ShowExitPage"="REG_DWORD", 0
       "TELNO"="REG_SZ", "(844) 944-0918"
       "utm_campaign"="REG_SZ", "p9jwdefault"
       "utm_medium"="REG_SZ", "newbuild"
       "utm_source"="REG_SZ", "p9jwsite"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\PC Clean Plus\LANG]
       "LangID"="REG_DWORD", 0
    [HKEY_CURRENT_USER\Software\PC\Clean\Plus\key\6]
       "(Default)"="REG_BINARY, .......................................................................................................................o............................................................................................................................H...........
    [HKEY_CURRENT_USER\Software\PC Clean Plus]
       "1stInstalled_Time"="REG_SZ", "28/01/2016 09:14:24"
       "AutoRepair"="REG_DWORD", 0
       "ConfirmBkUps"="REG_DWORD", 1
       "CurrentScanTime"="REG_BINARY, ........
       "ErrorCount"="REG_DWORD", 30
       "FirstRun"="REG_DWORD", 1
       "GoToSystemTrayOnClose"="REG_DWORD", 0
       "ImprovementProgram"="REG_DWORD", 1
       "NumTimesPCPRunned"="REG_DWORD", 1
       "RegErrFoundTillDate"="REG_DWORD", 0
       "RegErrsFixedLast"="REG_DWORD", 0
       "RegErrsFixedTillDate"="REG_DWORD", 0
       "ScheduledTime"="REG_SZ", ""
       "SetChkDontShowRedTrayPopup"="REG_DWORD", 0
       "SetChkREmovableMedia"="REG_DWORD", 1
       "SetChkSkipEmptyKeys"="REG_DWORD", 1
       "SetEnableSound"="REG_DWORD", 1
       "StartAutoScanOnLaunch"="REG_DWORD", 0
       "StartAutoScanPMUI"="REG_DWORD", 0
       "StartAutoTutorial"="REG_DWORD", 1
       "StartMinimized"="REG_DWORD", 0
       "StartScan"="REG_DWORD", 0
       "StartWhenWinBoots"="REG_DWORD", 1
       "StrLastOptimizeTime"="REG_SZ", ""
       "StrLastScan"="REG_SZ", "Thu. January 28, 2016. 09:15 AM"
       "StrLastScanResults"="REG_SZ", "30"
       "StrLastStartupOpt"="REG_SZ", ""
       "StrLatestRegDefrag"="REG_SZ", ""
       "StrLatestRestorePoint"="REG_SZ", ""
       "TrialType"="REG_DWORD", 0
    [HKEY_CURRENT_USER\Software\PC Clean Plus\LANG]
       "LangCode"="REG_SZ", "en"
       "LangID"="REG_DWORD", 0
Malwarebytes Anti-Malware log:
 
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 28/01/2016
Scan Time: 09:35
Logfile: mbamPCCleanPlus.txt
Administrator: Yes

Version: 2.2.0.1020
Malware Database: v2016.01.28.02
Rootkit Database: v2016.01.20.01
License: Premium
Malware Protection: Disabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {username}

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 318016
Time Elapsed: 5 min, 27 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 8
PUP.Optional.PCCleanPlus, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PC Clean Plus_is1, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\PC Clean Plus, Delete-on-Reboot, [fa08003f4e4b66d02580bf82689c13ed], 
PUP.Optional.PCCleanPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\PC Clean Plus_DEFAULT, Delete-on-Reboot, [23dfa897a9f07cbaf8ad0c358084f50b], 
PUP.Optional.PCCleanPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\PC Clean Plus_UPDATES, Delete-on-Reboot, [79898cb30c8d37fff8aded5441c3bc44], 
PUP.Optional.PCCleanPlus, HKLM\SOFTWARE\WOW6432NODE\PC Clean Plus, Quarantined, [758d023d11881a1c457285bc20e4b749], 
PUP.Optional.PCCleanPlus, HKLM\SOFTWARE\WOW6432NODE\PC\CLEAN\Plus, Quarantined, [8979043baced57df0cacd8690bf9758b], 
PUP.Optional.PCCleanPlus, HKCU\SOFTWARE\PC Clean Plus, Quarantined, [24de80bfb2e78caaa60f52efdd278d73], 
PUP.Optional.PCCleanPlus, HKCU\SOFTWARE\PC\CLEAN\Plus, Quarantined, [28dad36c5643e452ab0b8bb68c7815eb], 

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 3
PUP.Optional.PCCleanPlus, C:\Users\{username}\AppData\Roaming\PC Clean Plus, Quarantined, [58aaf34c7227a78fe7b9d1708d779a66], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus, Quarantined, [b64ca59af4a5ea4c8a8e4992ec16c040], 

Files: 69
PUP.Optional.PCCleanPlus, C:\Users\{username}\Desktop\pccpsetup_p9jwsite.exe, Quarantined, [6b97102f3b5ee55117a3af2dee138d73], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe, Quarantined, [e31ff44bafea3402b83bc911758c6997], 
PUP.Optional.PCCleanPlus, C:\Users\{username}\AppData\Roaming\PC Clean Plus\ExcludeList.pcp, Quarantined, [58aaf34c7227a78fe7b9d1708d779a66], 
PUP.Optional.PCCleanPlus, C:\Users\{username}\AppData\Roaming\PC Clean Plus\backup3.bin, Quarantined, [58aaf34c7227a78fe7b9d1708d779a66], 
PUP.Optional.PCCleanPlus, C:\Users\{username}\AppData\Roaming\PC Clean Plus\backup6.bin, Quarantined, [58aaf34c7227a78fe7b9d1708d779a66], 
PUP.Optional.PCCleanPlus, C:\Users\{username}\AppData\Roaming\PC Clean Plus\eng_pcp.dat, Quarantined, [58aaf34c7227a78fe7b9d1708d779a66], 
PUP.Optional.PCCleanPlus, C:\Users\{username}\AppData\Roaming\PC Clean Plus\log_01-28-2016.log, Quarantined, [58aaf34c7227a78fe7b9d1708d779a66], 
PUP.Optional.PCCleanPlus, C:\Users\{username}\AppData\Roaming\PC Clean Plus\pcpupdate.ini, Quarantined, [58aaf34c7227a78fe7b9d1708d779a66], 
PUP.Optional.PCCleanPlus, C:\Users\{username}\AppData\Roaming\PC Clean Plus\results.pcp, Quarantined, [58aaf34c7227a78fe7b9d1708d779a66], 
PUP.Optional.PCCleanPlus, C:\Users\{username}\AppData\Roaming\PC Clean Plus\TempHLList.pcp, Quarantined, [58aaf34c7227a78fe7b9d1708d779a66], 
PUP.Optional.PCCleanPlus, C:\Users\Public\Desktop\PC Clean Plus.lnk, Quarantined, [da283b040d8c49ed3170410032d2c43c], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\unins000.dat, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Finnish_uninst_fi.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Portuguese_pcp.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Chinese_pcp.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Chinese_uninst.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Danish_pcp.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Danish_uninst.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Dutch_pcp.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Dutch_uninst.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\eng_pcp.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\eng_uninst.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\FileList.pcp, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Finnish_pcp_fi.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Japanese_pcp.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Japanese_uninst.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\korean_pcp_ko.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\korean_uninst_ko.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Norwegian_pcp.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Norwegian_uninst.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\PCCPUns.exe, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\polish_pcp_pl.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\polish_uninst_pl.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\portugese_pcp_pt.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\portugese_uninst_pt.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\French_pcp.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\French_uninst.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\German_pcp.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\German_uninst.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\greek_pcp_el.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\greek_uninst_el.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\install_left_image.bmp, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\isxdl.dll, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Italian_pcp.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Italian_uninst.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Portuguese_uninst.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\RegList.pcp, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\russian_pcp_ru.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\russian_uninst_ru.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Spanish_pcp.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\spanish_uninst.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Swedish_pcp.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\swedish_uninst.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\TPS.ico, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\TraditionalCn_pcp_zh-tw.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\traditionalcn_uninst_zh-tw.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\turkish_pcp_tr.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Turkish_uninst_tr.ini, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\unins000.exe, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\unins000.msg, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\xmllite.dll, Quarantined, [2dd569d6c1d850e6b8eaf64b58ac6d93], 
PUP.Optional.PCCleanPlus, C:\Windows\System32\Tasks\PC Clean Plus, Quarantined, [e31f1a250198df573a696dd4f0142cd4], 
PUP.Optional.PCCleanPlus, C:\Windows\System32\Tasks\PC Clean Plus_DEFAULT, Quarantined, [11f187b8afeae74ff2b11f229371d42c], 
PUP.Optional.PCCleanPlus, C:\Windows\System32\Tasks\PC Clean Plus_UPDATES, Quarantined, [e91954eb643540f64261d26f5ea69e62], 
PUP.Optional.PCCleanPlus, C:\Windows\Tasks\PC Clean Plus_DEFAULT.job, Quarantined, [4fb34df226737eb8257f62dfe0243ac6], 
PUP.Optional.PCCleanPlus, C:\Windows\Tasks\PC Clean Plus_UPDATES.job, Quarantined, [70927cc378211521a9fb51f0f014c53b], 
PUP.Optional.PCCleanPlus, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus\PC Clean Plus.lnk, Quarantined, [b64ca59af4a5ea4c8a8e4992ec16c040], 
PUP.Optional.PCCleanPlus, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus\Register PC Clean Plus.lnk, Quarantined, [b64ca59af4a5ea4c8a8e4992ec16c040], 
PUP.Optional.PCCleanPlus, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus\Uninstall PC Clean Plus.lnk, Quarantined, [b64ca59af4a5ea4c8a8e4992ec16c040], 

Physical Sectors: 0
(No malicious items detected)


(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.

 

Edited by Metallica
Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.