CleanUp Antivirus
CleanUp Antivirus Description
CleanUp Antivirus or Clean Up Antivirus is a fake anti-virus application created by the authors of rogueware such as Security Antivirus. Trojans help in the distribution of CleanUp Antivirus by surreptitiously placing it into users’ systems. These Trojans will also create harmless files which will be detected as dangerous malware when CleanUp Antivirus runs a fake online system scan on a compromised PC. The said scan will produce a fabricated report indicating that the system is badly infected with numerous computer threats that can only be removed with the “full” version of CleanUp Antivirus. Purchasing CleanUp Antivirus is the last thing you should do; instead use a recognized security tool to completely remove CleanUp Antivirus.
Type: Rogue Anti-Virus Program
How Can You Detect CleanUp Antivirus?
CleanUp Antivirus Technical Report
As new CleanUp Antivirus details are reported by our customers and findings from our Threat Research Center, we will update this section.
The following CleanUp Antivirus files with its MD5s were created in the system:
| File Name | File Size | MD5 |
|---|
| CUdccb.exe | 2697216 | 74b98cf1fcb66e93641a9d2748318639 |
| xp_c47b6[1].exe | 2697216 | 74b98cf1fcb66e93641a9d2748318639 |
| CUc42a.exe | 2696704 | 1c27851b94a980d2eecca3b366e17104 |
| CU6e0b.exe | 2038272 | 77c5ca0b088c02ec12fb829d5ebf9bab |
| CUfa07.exe | 2693120 | f5324ebe5c89238c957e6dbd0f9a7dc0 |
| CUe222.exe | 2704384 | 1f0a43a571c3a349a993d7ae017f7a03 |
| CUa36c.exe | 2037760 | ea1986dad67f5eaeaa5ec8c040a3130d |
| CUa42e.exe | 2696192 | 2d2b0eb9df0f9d78df7ae6f765cdb553 |
CleanUp Antivirus has typically the following processes in memory:
- %UserProfile%\Recent\grid.exe
- %UserProfile%\Recent\DBOLE.sys
- c:\Documents and Settings\All Users\Application Data\345d567\sqlite3.dll
- %UserProfile%\Recent\FS.dll
- %UserProfile%\Recent\DBOLE.dll
- c:\Documents and Settings\All Users\Application Data\345d567\mozcrt19.dll
- %UserProfile%\Recent\PE.exe
- %UserProfile%\Recent\tjd.sys
- c:\Documents and Settings\All Users\Application Data\345d567\CU345d.exe
CleanUp Antivirus created the following directories, files, paths:
- %AppData%\CleanUp Antivirus
CleanUp Antivirus creates the following registry entries:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “App/7.00195″
- HKEY_CLASSES_ROOT\CU345d.DocHostUIHandler
- HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes “URL” = “http://findgala.com/?&uid=195&q={searchTerms}”
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer “PRS” = “http://127.0.0.1:27777/?inj=%ORIGINAL%”
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List “C:\Documents and Settings\All Users\Application Data\345d567\CU345d.exe”
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1″
- HKEY_CURRENT_USER\Software\3
- HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes “URL” = “http://findgala.com/?&uid=195&q={searchTerms}”
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = “no”
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List “C:\Documents and Settings\All Users\Application Data\345d567\CU345d.exe”
- HKEY_CURRENT_USER\Software\CleanUp Antivirus
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “CleanUp Antivirus”
- HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
- HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes “URL” = “http://findgala.com/?&uid=195&q={searchTerms}”
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “Library1.00195″
Important Article Disclaimer

CleanUp Antivirus 
(16 votes, average: 4.38 out of 5)










March 29th, 2010 at 12:18 am
how to delete cleanup antivirus?
pls help me….
[Reply]
April 4th, 2010 at 8:32 am
how to delete this fake antivirus??? help……………….
[Reply]
April 5th, 2010 at 12:07 am
Please help to remove CLEANUP ANTIVIRUS MALWARE
[Reply]
April 8th, 2010 at 10:11 pm
I’d really like to contact the folks who wrote this “cleanup antivirus.” Anyone know how to contact them? Like to give a peice of my mind, just before I take em to court.
Thank you
[Reply]
April 23rd, 2010 at 12:55 pm
that cleanup anti virus is the worst!!!! it duznt clean up its just annoys u
[Reply]
May 13th, 2010 at 2:22 am
I was misled and purchased cleanup antivirus which started malfunctioning.Now I camre to know that it is a rougue antivirus software Kindly help me to remove it from the system
[Reply]
May 27th, 2010 at 8:22 am
my advice to those who have problems with the software named CleanUp Antivirus is to keep in touch with the support center. I purchased it by the internet and received a downloadable software on my pc however it didn’t work from the beginning. I tried to reinstall it numerous times but all kind of errors kept flashing up on my screen, so I called them and asked about why I had those problems…it turned out that I accidentely changed my windows system settings while trying to start the program, so the support representative provided me the information how to set up this software on my computer…finally it was installed and began working.
Try to contact phone support: +1 888 3180062
Good luck!
[Reply]
May 28th, 2010 at 2:43 pm
Hi Kate Simps,
CleanUp Antivirus is NOT a legitimate program and you may be in danger of damaging your system. It is highly advisable that you avoid use of CleanUp Antivirus and DO NOT contact the support number that you provided under any circumstances. The creators of CleanUp Antivirus are cybercrooks and out to steal your money. Your credit card may be in jeopardy of being charged for unapproved purchases.
[Reply]
August 4th, 2010 at 6:32 am
Thank you so much, GoldSparrow! Next time I’ll be more carefull.
By the way I checked my CC, but didn’t find any strange or unknown charges. I have clarified this situation with their representatives
[Reply]