Sign in to follow this  
Metallica

Removal instructions for RegClean Pro

Recommended Posts

What is RegClean Pro?

The Malwarebytes research team has determined that RegClean Pro is a fake registry cleaner. These so-called "registry cleaners" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems.
More information can be found on our Malwarebytes Unpacked blog.

How do I know if I am infected with RegClean Pro?

This is how the main screen of the registry cleaning application looks:

main1.png

You will find these icons in your taskbar and on your desktop:

icons.png

And see these warnings during install:

main.png

warning1.png
There were more extra offers, but I declined all of them.

warning5.png

warning6.png

and this screen when you try to fix the found "errors":

warning7.png

You may see this entry in your list of installed programs:

warning4.png

and these tasks in your Task Scheduler:

warning8.png


How did RegClean Pro get on my computer?

These so-called registry cleaners use different methods of getting installed. This particular one was bundled by other software.

How do I remove RegClean Pro?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted application.
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan Now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
Is there anything else I need to do to get rid of RegClean Pro?
  • No, Malwarebytes' Anti-Malware removes RegClean Pro completely.
  • This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this registry cleaner.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the RegClean Pro installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late.
 

protection1.png


Technical details for experts

You may see these entries in FRST logs:
 
 (Systweak Inc) C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe
 C:\Windows\System32\Tasks\RegClean Pro
 C:\Windows\System32\Tasks\RegClean Pro_UPDATES
 C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
 C:\Users\Public\Desktop\RegClean Pro.lnk
 C:\Windows\Tasks\RegClean Pro_UPDATES.job
 C:\Windows\Tasks\RegClean Pro_DEFAULT.job
 C:\Users\{username}\AppData\Roaming\Systweak
 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
 C:\Program Files (x86)\RegClean Pro
 (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe

RegClean Pro (HKLM-x32\...\RegClean Pro_is1) (Version: 6.21 - Systweak Inc) <==== ATTENTION
Task: {852C1A39-3748-41B1-A686-504B28FA2F5A} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe [2013-08-22] (Systweak Inc) <==== ATTENTION
Task: {C9D987BF-531D-4747-914D-49A1A8EE52F7} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe [2013-08-22] (Systweak Inc) <==== ATTENTION
Task: {E69628BC-C674-4CB2-9471-9250F413AFB4} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe [2013-08-22] (Systweak Inc) <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION
Alterations made by the installer:
 
File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Program Files (x86)\RegClean Pro
       Adds the file Chinese_rcp.ini"="8/22/2013 3:48 PM, 49366 bytes, A
       Adds the file CleanSchedule.exe"="8/22/2013 6:36 PM, 94040 bytes, A
       Adds the file Cloud_Backup_Setup.exe"="8/22/2013 11:20 AM, 73824 bytes, A
       Adds the file Cloud_Backup_Setup_Intl.exe"="8/22/2013 11:20 AM, 73840 bytes, A
       Adds the file Danish_rcp.ini"="8/22/2013 3:48 PM, 92654 bytes, A
       Adds the file Dutch_rcp.ini"="8/22/2013 3:48 PM, 96908 bytes, A
       Adds the file eng_rcp.ini"="8/22/2013 3:49 PM, 86620 bytes, A
       Adds the file Finnish_rcp_fi.ini"="8/22/2013 3:48 PM, 90116 bytes, A
       Adds the file French_rcp.ini"="8/22/2013 3:48 PM, 102938 bytes, A
       Adds the file German_rcp.ini"="8/22/2013 3:48 PM, 102394 bytes, A
       Adds the file greek_rcp_el.ini"="8/22/2013 3:47 PM, 101584 bytes, A
       Adds the file install_left_image.bmp"="8/22/2013 11:20 AM, 156296 bytes, A
       Adds the file isxdl.dll"="8/22/2013 6:36 PM, 157016 bytes, A
       Adds the file Italian_rcp.ini"="8/22/2013 3:47 PM, 99264 bytes, A
       Adds the file Japanese_rcp.ini"="8/22/2013 3:47 PM, 62204 bytes, A
       Adds the file korean_rcp_ko.ini"="8/22/2013 3:47 PM, 70750 bytes, A
       Adds the file Norwegian_rcp.ini"="8/22/2013 3:47 PM, 89050 bytes, A
       Adds the file polish_rcp_pl.ini"="8/22/2013 3:47 PM, 92604 bytes, A
       Adds the file portugese_rcp_pt.ini"="8/22/2013 3:47 PM, 95906 bytes, A
       Adds the file Portuguese_rcp.ini"="8/22/2013 3:47 PM, 93526 bytes, A
       Adds the file RCPUninstall.exe"="8/22/2013 6:36 PM, 2491736 bytes, A
       Adds the file RegCleanPro.dll"="8/22/2013 6:36 PM, 2469888 bytes, A
       Adds the file RegCleanPro.exe"="8/22/2013 6:36 PM, 9125720 bytes, A
       Adds the file russian_rcp_ru.ini"="8/22/2013 3:47 PM, 95864 bytes, A
       Adds the file Spanish_rcp.ini"="8/22/2013 3:47 PM, 97502 bytes, A
       Adds the file Swedish_rcp.ini"="8/22/2013 3:47 PM, 87798 bytes, A
       Adds the file systweakasp.exe"="8/22/2013 6:52 PM, 591720 bytes, A
       Adds the file TraditionalCn_rcp_zh-tw.ini"="8/22/2013 3:47 PM, 49428 bytes, A
       Adds the file turkish_rcp_tr.ini"="8/22/2013 3:47 PM, 93374 bytes, A
       Adds the file unins000.dat"="6/28/2016 9:30 AM, 76355 bytes, A
       Adds the file unins000.exe"="6/28/2016 9:28 AM, 1189208 bytes, A
       Adds the file unins000.msg"="6/28/2016 9:30 AM, 22357 bytes, A
       Adds the file xmllite.dll"="8/22/2013 11:16 AM, 126976 bytes, A
    Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
       Adds the file RegClean Pro.lnk"="6/28/2016 9:30 AM, 1068 bytes, A
       Adds the file Register RegClean Pro.lnk"="6/28/2016 9:30 AM, 1094 bytes, A
       Adds the file Uninstall RegClean Pro.lnk"="6/28/2016 9:30 AM, 1053 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Systweak\RegClean Pro\Version 6.1
       Adds the file eng_rcp.dat"="6/28/2016 9:30 AM, 32724 bytes, A
       Adds the file log_06-28-2016.log"="6/28/2016 9:30 AM, 0 bytes, A
       Adds the file results.rcp"="6/28/2016 9:31 AM, 6812 bytes, A
    In the existing folder C:\Users\Public\Desktop
       Adds the file RegClean Pro.lnk"="6/28/2016 9:30 AM, 1050 bytes, A
    In the existing folder C:\Windows\System32
       Adds the file roboot64.exe"="8/22/2013 6:36 PM, 20312 bytes, A
    In the existing folder C:\Windows\System32\Tasks
       Adds the file RegClean Pro"="6/28/2016 9:30 AM, 3108 bytes, A
       Adds the file RegClean Pro_DEFAULT"="6/28/2016 9:30 AM, 2894 bytes, A
       Adds the file RegClean Pro_UPDATES"="6/28/2016 9:30 AM, 3050 bytes, A
    In the existing folder C:\Windows\Tasks
       Adds the file RegClean Pro_DEFAULT.job"="6/28/2016 9:30 AM, 284 bytes, A
       Adds the file RegClean Pro_UPDATES.job"="6/28/2016 9:30 AM, 292 bytes, A

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures]
       "RegClean Pro_DEFAULT.job"="REG_BINARY, ................................
       "RegClean Pro_DEFAULT.job.fp"="REG_DWORD", -1698287326
       "RegClean Pro_UPDATES.job"="REG_BINARY, ................................
       "RegClean Pro_UPDATES.job.fp"="REG_DWORD", 948359014
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RegClean Pro_is1]
       "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\RegClean Pro\Regcleanpro.exe"
       "DisplayName"="REG_SZ", "RegClean Pro"
       "DisplayVersion"="REG_SZ", "6.21"
       "EstimatedSize"="REG_DWORD", 17871
       "HelpLink"="REG_SZ", "http://www.systweak.com/RegCleanPro/"
       "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\RegClean Pro"
       "Inno Setup: Icon Group"="REG_SZ", "RegClean Pro"
       "Inno Setup: Language"="REG_SZ", "en"
       "Inno Setup: Setup Version"="REG_SZ", "5.5.1 (u)"
       "Inno Setup: User"="REG_SZ", "{username}"
       "InstallDate"="REG_SZ", "20160628"
       "InstallLocation"="REG_SZ", "C:\Program Files (x86)\RegClean Pro\"
       "MajorVersion"="REG_DWORD", 6
       "MinorVersion"="REG_DWORD", 21
       "NoModify"="REG_DWORD", 1
       "NoRepair"="REG_DWORD", 1
       "Publisher"="REG_SZ", "Systweak Inc"
       "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\RegClean Pro\unins000.exe" /SILENT"
       "UninstallString"="REG_SZ", ""C:\Program Files (x86)\RegClean Pro\unins000.exe" /silent"
       "URLInfoAbout"="REG_SZ", "http://www.systweak.com/RegCleanPro/"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Systweak]
       "MachineID"="REG_BINARY, (zero length data)
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Systweak\Params]
       "affiliateid"="REG_SZ", ""
       "utm_campaign"="REG_SZ", "sd_new_esusa"
       "utm_medium"="REG_SZ", "newbuild"
       "utm_source"="REG_SZ", "softonic_new"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Systweak\RegClean Pro\Version 6.1]
       "amazonparams"="REG_SZ", " /ACTION=install /COMPONENTS=toolbar,startpage,defaultsearch"
       "Expired"="REG_DWORD", 0
       "FireAmazonOffered"="REG_DWORD", 1
       "FirstTimeASPFired"="REG_DWORD", 1
       "InstallAmazon"="REG_DWORD", 1
       "InstallASP"="REG_DWORD", 0
       "LaunchASP"="REG_DWORD", 1
       "MaxFixLimit"="REG_DWORD", 15
       "RCPURL"="REG_SZ", "http://www.systweak.com/registryCleaner/price/en?utm_source=softonic_new&utm_campaign=sd_new_esusa&utm_medium=newbuild"
       "RENEWALURL"="REG_SZ", "http://www.systweak.com/registrycleaner/renewal.asp?utm_source=softonic_new&utm_campaign=sd_new_esusa&utm_medium=newbuild"
       "TELNO"="REG_SZ", "(800) 871-7918"
       "TELNOSPAIN"="REG_SZ", "(801) 432-6563"
       "utm_campaign"="REG_SZ", "sd_new_esusa"
       "utm_medium"="REG_SZ", "newbuild"
       "utm_source"="REG_SZ", "softonic_new"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Systweak\RegClean Pro\Version 6.1\LANG]
       "LangID"="REG_DWORD", 0
    [HKEY_CURRENT_USER\Software\Licenses]
       "{0DE49903F6A7893C6}"="REG_BINARY, ...........................................................................................
       "{IDE49903F6A7893C6}"="REG_BINARY, ..
       "{K7C0DB872A3F777C0}"="REG_BINARY, ..................................................................................................................................
       "{R7C0DB872A3F777C0}"="REG_BINARY, ..
    [HKEY_CURRENT_USER\Software\Systweak]
       "MachineID"="REG_BINARY, (zero length data)
    [HKEY_CURRENT_USER\Software\Systweak\RegClean Pro]
       "ErrorCount"="REG_DWORD", 18
    [HKEY_CURRENT_USER\Software\Systweak\RegClean Pro\Version 6.1]
       "AutoRepair"="REG_DWORD", 0
       "ConfirmBkUps"="REG_DWORD", 1
       "CurrentScanTime"="REG_BINARY, ........
       "FirstRun"="REG_DWORD", 1
       "GoToSystemTrayOnClose"="REG_DWORD", 0
       "ImprovementProgram"="REG_DWORD", 1
       "NumTimesRCPRunned"="REG_DWORD", 1
       "RegErrFoundTillDate"="REG_DWORD", 0
       "RegErrsFixedLast"="REG_DWORD", 0
       "RegErrsFixedTillDate"="REG_DWORD", 0
       "ScheduledTime"="REG_SZ", ""
       "SetChkDontShowRedTrayPopup"="REG_DWORD", 0
       "SetChkREmovableMedia"="REG_DWORD", 1
       "SetChkSkipEmptyKeys"="REG_DWORD", 1
       "SetEnableSound"="REG_DWORD", 1
       "StartAutoScanOnLaunch"="REG_DWORD", 0
       "StartAutoScanPMUI"="REG_DWORD", 0
       "StartAutoTutorial"="REG_DWORD", 1
       "StartMinimized"="REG_DWORD", 0
       "StartScan"="REG_DWORD", 0
       "StartWhenWinBoots"="REG_DWORD", 1
       "StrLastOptimizeTime"="REG_SZ", ""
       "StrLastScan"="REG_SZ", "Tue. June 28, 2016. 09:31 AM"
       "StrLastScanResults"="REG_SZ", "18"
       "StrLastStartupOpt"="REG_SZ", ""
       "StrLatestRegDefrag"="REG_SZ", ""
       "StrLatestRestorePoint"="REG_SZ", ""
       "TrialType"="REG_DWORD", 0
    [HKEY_CURRENT_USER\Software\Systweak\RegClean Pro\Version 6.1\LANG]
       "LangCode"="REG_SZ", "en"
       "LangID"="REG_DWORD", 0
Malwarebytes Anti-Malware log:
 
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 6/28/2016
Scan Time: 9:42 AM
Logfile: mbamRegCleanPro.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.06.28.01
Rootkit Database: v2016.05.27.01
License: Premium
Malware Protection: Disabled
Malicious Website Protection: Enabled
Self-protection: Enabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {username}

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 314138
Time Elapsed: 7 min, 52 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 1
PUP.Optional.SysTweak, C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe, 2776, Delete-on-Reboot, [9cb53cc66634181e4fe1704d19e8d42c]

Modules: 3
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\isxdl.dll, Delete-on-Reboot, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\RegCleanPro.dll, Delete-on-Reboot, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\xmllite.dll, Delete-on-Reboot, [55fc82804a5085b167b7ddd4d42f0ef2], 

Registry Keys: 8
PUP.Optional.SysTweak, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\RegClean Pro_is1, Quarantined, [ada43fc35545b87e8e5a477a11f045bb], 
PUP.Optional.RegCleanPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{852C1A39-3748-41B1-A686-504B28FA2F5A}, Delete-on-Reboot, [85cc18ea5e3c42f4a586646aba486a96], 
PUP.Optional.RegCleanerPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{C9D987BF-531D-4747-914D-49A1A8EE52F7}, Delete-on-Reboot, [3918c63c643655e14e056a8f07fc53ad], 
PUP.Optional.RegCleanPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{E69628BC-C674-4CB2-9471-9250F413AFB4}, Delete-on-Reboot, [f65b758d7426b48249e2fdd1cd35f40c], 
PUP.Optional.RegCleanerPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\RegClean Pro, Delete-on-Reboot, [ed6428da63371f177fc2e8f0748eed13], 
PUP.Optional.RegCleanPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\RegClean Pro_DEFAULT, Delete-on-Reboot, [064b12f076242c0a3ee4e9c88f74718f], 
PUP.Optional.RegCleanPro, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\RegClean Pro, Quarantined, [0a470ef42e6c152110138b2624df1be5], 
PUP.Optional.RegCleanerPro, HKCU\SOFTWARE\SYSTWEAK\RegClean Pro, Quarantined, [4011d42eddbd75c13edef2bfca39e11f], 

Registry Values: 3
PUP.Optional.RegCleanPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{852C1A39-3748-41B1-A686-504B28FA2F5A}|Path, \RegClean Pro_UPDATES, Delete-on-Reboot, [85cc18ea5e3c42f4a586646aba486a96]
PUP.Optional.RegCleanerPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{C9D987BF-531D-4747-914D-49A1A8EE52F7}|Path, \RegClean Pro, Delete-on-Reboot, [3918c63c643655e14e056a8f07fc53ad]
PUP.Optional.RegCleanPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{E69628BC-C674-4CB2-9471-9250F413AFB4}|Path, \RegClean Pro_DEFAULT, Delete-on-Reboot, [f65b758d7426b48249e2fdd1cd35f40c]

Registry Data: 0
(No malicious items detected)

Folders: 4
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro, Delete-on-Reboot, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro, Quarantined, [8dc4b84a4357da5c78a7624fa85b5ea2], 
PUP.Optional.RegCleanerPro, C:\Users\{username}\AppData\Roaming\Systweak\RegClean Pro, Delete-on-Reboot, [341d7d856c2e1026c40654662bd78d73], 
PUP.Optional.RegCleanerPro, C:\Users\{username}\AppData\Roaming\Systweak\RegClean Pro\Version 6.1, Delete-on-Reboot, [341d7d856c2e1026c40654662bd78d73], 

Files: 47
PUP.Optional.SysTweak, C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe, Delete-on-Reboot, [9cb53cc66634181e4fe1704d19e8d42c], 
PUP.Optional.RegCleanerPro, C:\Users\{username}\Desktop\new_esusa.exe, Quarantined, [1b36679b3c5e6bcbab63881c60a0d927], 
PUP.Optional.MyPCBackup, C:\Program Files (x86)\RegClean Pro\Cloud_Backup_Setup.exe, Quarantined, [ce83cf331a800e28ee34cfc7867ef10f], 
PUP.Optional.MyPCBackup, C:\Program Files (x86)\RegClean Pro\Cloud_Backup_Setup_Intl.exe, Quarantined, [0150b84ad3c710266cb68d098b7915eb], 
PUP.Optional.SysTweak, C:\Program Files (x86)\RegClean Pro\unins000.exe, Quarantined, [ada43fc35545b87e8e5a477a11f045bb], 
PUP.Optional.RegCleanPro, C:\Windows\System32\roboot64.exe, Quarantined, [aea3cd35e6b454e28cd54847f50f9c64], 
PUP.Optional.RegCleanerPro, C:\Users\Public\Desktop\RegClean Pro.lnk, Quarantined, [2c25dd257b1f83b3f56d74714eb4a15f], 
PUP.Optional.RegCleanerPro, C:\Windows\System32\Tasks\RegClean Pro, Quarantined, [88c9ab57f2a8251167fda63f82800000], 
PUP.Optional.RegCleanerPro.J, C:\Windows\Tasks\RegClean Pro_UPDATES.job, Quarantined, [4f02db27277384b25f61ef0379892ed2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\TraditionalCn_rcp_zh-tw.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\install_left_image.bmp, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\Chinese_rcp.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\CleanSchedule.exe, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\Danish_rcp.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\Dutch_rcp.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\eng_rcp.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\Finnish_rcp_fi.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\French_rcp.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\German_rcp.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\greek_rcp_el.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\isxdl.dll, Delete-on-Reboot, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\Italian_rcp.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\Japanese_rcp.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\korean_rcp_ko.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\Norwegian_rcp.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\polish_rcp_pl.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\portugese_rcp_pt.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\Portuguese_rcp.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\RCPUninstall.exe, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\RegCleanPro.dll, Delete-on-Reboot, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\russian_rcp_ru.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\Spanish_rcp.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\Swedish_rcp.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\systweakasp.exe, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\turkish_rcp_tr.ini, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\unins000.dat, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\unins000.msg, Quarantined, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\Program Files (x86)\RegClean Pro\xmllite.dll, Delete-on-Reboot, [55fc82804a5085b167b7ddd4d42f0ef2], 
PUP.Optional.RegCleanPro, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro\Register RegClean Pro.lnk, Quarantined, [8dc4b84a4357da5c78a7624fa85b5ea2], 
PUP.Optional.RegCleanPro, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro\RegClean Pro.lnk, Quarantined, [8dc4b84a4357da5c78a7624fa85b5ea2], 
PUP.Optional.RegCleanPro, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro\Uninstall RegClean Pro.lnk, Quarantined, [8dc4b84a4357da5c78a7624fa85b5ea2], 
PUP.Optional.RegCleanPro, C:\Windows\System32\Tasks\RegClean Pro_DEFAULT, Quarantined, [61f038cab6e41026aa76edc490739d63], 
PUP.Optional.RegCleanPro, C:\Windows\Tasks\RegClean Pro_DEFAULT.job, Quarantined, [c38ed42ecccebb7ba77a476a709337c9], 
PUP.Optional.RegCleanerPro, C:\Windows\System32\Tasks\RegClean Pro_UPDATES, Quarantined, [a3ae8c76faa0dc5a0d7f409e22e136ca], 
PUP.Optional.RegCleanerPro, C:\Users\{username}\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\eng_rcp.dat, Quarantined, [341d7d856c2e1026c40654662bd78d73], 
PUP.Optional.RegCleanerPro, C:\Users\{username}\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\log_06-28-2016.log, Delete-on-Reboot, [341d7d856c2e1026c40654662bd78d73], 
PUP.Optional.RegCleanerPro, C:\Users\{username}\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\results.rcp, Quarantined, [341d7d856c2e1026c40654662bd78d73], 

Physical Sectors: 0
(No malicious items detected)


(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.

Share this post


Link to post
Share on other sites
Sign in to follow this  

  • Recently Browsing   0 members

    No registered users viewing this page.