SecureExpertCleaner

GoldSparrow By GoldSparrow in Rogue Anti-Spyware Program | 55 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

SecureExpertCleaner Description

 
 
Image Screenshot
[+] Click Image to Enlarge
 
 

SecureExpertCleaner or Secure Expert Cleaner, is a rogue anti-spyware program often bundled with the Trojan Zlob which is found on fake video codecs. SecureExpertCleaner can also be found on rogue websites that provide a trial for the user to download. Once Zlob is installed, it will generate an enormous amount of fake popups and system notifications stating that the user’s computer is infected with spyware. If the user is tricked into clicking on any of these messages, he/she will be redirected to secureexpertcleaner.com where he/she will be forced to purchase SecureExpertCleaner’s commercial version. SecureExpertCleaner will allege it’s able to remove the spyware found on the user’s computer system, however, this is just another mechanism to push the user into buying its full version.

SecureExpertCleaner’s trial version is also able to generate a computer system scan and display erroneous results to scare the user.

Type: Rogue AntiSpyware Programs

How Can You Detect SecureExpertCleaner?

 
 

Download SpyHunter’s Detection Scanner
to Detect SecureExpertCleaner.

 
 

SecureExpertCleaner Technical Report

As new SecureExpertCleaner details are reported by our customers and findings from our Threat Research Center, we will update this section.

The following SecureExpertCleaner files with its MD5s were created in the system:

File Name File Size MD5
CleanerInstaller[1].exe 92944 710b55fd6d22d33e60d086f4960cf6d7
Reminder.exe 480768 fc587a10a5dfcf7c8c862a9d8b85f665
SEC.exe 1548288 2989d2abff61cdeac9cc2c2f5fb3c1e8
SecureExpertCleaner_Installer_Dual_En.exe 422864 476a0ff01c7638fea7862103257bf6c2
QuickInstallPack.exe 422864 476a0ff01c7638fea7862103257bf6c2
FreeCleaner.exe 1657032 82afccbf194705e0ab54fabc023ab950
Reminder.exe 480768 267d9b214e73b1b0df8fdefc8ec44e4b
SecureExpertCleaner_Installer_Dual_En[2].exe 173505 c93a2ec828f3ae3fcf88571e9a77e1e4
SEC.exe 1671168 a0f40353097a36025a25928ad147f313
SecureExpertCleaner_Pandora_Installer_Qip_Dual_En[1].exe 422864 1a0fcc81b3b051fb4be294ec655aeb92
QuickInstallPack.exe 422864 1a0fcc81b3b051fb4be294ec655aeb92
SecureExpertCleaner_Pandora_Dual_En.exe 1661848 ace1b86722352350eb439deb716094ee
iercpt.dll 110592 a8438de7f0971479bcb6d1a450a167ba
SecureExpertCleaner_Pandora_Dual_En.exe 1717824 8bea221924647bdca0ab5dd064daa3c4
SecureExpertCleaner_Pandora_Installer_Qip_Dual_En[1].exe 723456 d6ebc1296e6e4576653370c6a61818bd
QuickInstallPack.exe 723456 d6ebc1296e6e4576653370c6a61818bd
SecureExpertCleaner_Pandora_Dual_En.exe 1726264 3b9a5d227f48c5dc6c562f73f0d062d0
Reminder.exe 481280 2658e76f60f681b78fb040a88e2bb835
SecureExpertCleaner_Pandora_Dual_En.exe 1872528 756abd2a7e125db49c805bc04953281a
SecureExpertCleaner_Pandora_Installer_Qip_Dual_En.exe 1872344 436e6a3a9ba5f2345385726739475863
SecureExpertCleaner_Dual_Rezer_En.exe 1872088 d7edd052b5363c57777addb72e8ae47c
sec_free_setup.exe 1731856 5a9087a4ef2dbf7f9e5a98226e94d8ff
sec.exe 1667072 e5b42ac7eab77ca43106946db9124a54

SecureExpertCleaner Video Demo

Click on the “How SecureExpertCleaner Infects Your Computer” video to see a SecureExpertCleaner infection in action! See through the eyes of an unsuspecting Internet user while him/her is being victimized by SecureExpertCleaner.

At the end of this video, there’s a link to download SpyHunter’s Free Spyware Scanner. SpyHunter’s Free Spyware Scanner is for detection purposes only. To remove SecureExpertCleaner, you must purchase SpyHunter’s full version.

Tip: Turn your sound ON and watch the video in Full Screen mode to fully experience how SecureExpertCleaner infects a computer. The video contains clickable buttons.

SecureExpertCleaner has typically the following processes in memory:

  • %program_files%\secureexpertcleaner\microsoft.vc80.crt\msvcr80.dll
  • %program_files%\secureexpertcleaner\reminder.exe
  • SecureExpertCleaner_Installer_Dual_En[2].exe
  • QuickInstallPack.exe
  • SecureExpertCleaner_Dual_Rezer_En.exe
  • %program_files%\secureexpertcleaner\microsoft.vc80.crt\msvcp80.dll
  • %program_files%\secureexpertcleaner\unins000.exe
  • SecureExpertCleaner_Installer_Dual_En.exe
  • SecureExpertCleaner_Pandora_Dual_En.exe
  • SecureExpertCleaner_Pandora_Installer_Qip_Dual_En.exe
  • %program_files%\secureexpertcleaner\mfc80.dll
  • %program_files%\secureexpertcleaner\sec.exe
  • CleanerInstaller[1].exe
  • SecureExpertCleaner_Pandora_Installer_Qip_Dual_En[1].exe
  • %USERPROFILE%\Local Settings\Application Data\qip\iercpt.dll
  • sec_free_setup.exe

SecureExpertCleaner created the following directories, files, paths:

  • %AppData%\SecureExpertCleaner
  • %ProgramFiles%\SecureExpertCleaner
  • %AllUsersProfile%\Start Menu\Programs\SecureExpertCleaner

SecureExpertCleaner creates the following registry entries:

  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run secureexpertcleaner
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 displayicon
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 inno setup: icon group
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 inno setup: deselected tasks
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 uninstallstring
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 urlinfoabout
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 urlupdateinfo
  • HKEY_LOCAL_MACHINE\software\sec producttid
  • HKEY_CURRENT_USER\software\sec producttid
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 quietuninstallstring
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 inno setup: app path
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 inno setup: setup version
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 helplink
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 installlocation
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 norepair
  • HKEY_LOCAL_MACHINE\software\sec frun
  • SecureExpertCleaner
  • HKEY_CURRENT_USER\software\sec
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 displayname
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 inno setup: selected tasks
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 inno setup: user
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 installdate
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\3p_usec_is1 nomodify
  • HKEY_LOCAL_MACHINE\software\sec
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet settings\5.0\user agent\post platform 3p_usec 1.0.7.1

Important Article Disclaimer

ESG Support Center

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Furl
  • StumbleUpon
  • Technorati
  • YahooMyWeb
This entry was posted on 08/4/08 and is filed under Rogue Anti-Spyware Program. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Poll

How much money have you spent trying to rid your PC of spyware?
View Results
Follow Us on Twitter

Archives

Home Sitemap RSS Feed Privacy Policy End User License Agreement Copyright 2003-2010. Enigma Software Group USA, LLC. All Rights Reserved.