DiskClean

DiskClean (Disk Clean) is a rogue security tool. DiskClean spreads via Trojans and once it is inside a computer system it will create a registry entry that will ensure it is executed with every system reboot. DiskClean will bombard a victim with fake security alerts and scan reports claiming that the system is infected and the only solution is to purchase the "full version" of DiskClean. DiskClean is created to swindle gullible users who believe the fake security notifications and purchase the rogueware. DiskClean should be removed upon detection.

File System Details

DiskClean may create the following file(s):
# File Name Detections
1. C:\Program Files\DiskClean\DCAutoUpdate.exe
2. C:\Program Files\DiskClean\etc\avsrvc.exe
3. C:\Program Files\DiskClean\etc\dcMon.exe
4. C:\Program Files\DiskClean\etc\DCreport.exe
5. C:\Program Files\DiskClean\DiskClean.exe
6. C:\Program Files\DiskClean\etc\avsrv.exe
7. C:\Program Files\DiskClean\etc\DCFilterDriver.SYS
8. C:\Program Files\DiskClean\etc\DCmonRemote.dll
9. C:\Program Files\DiskClean\DCEngine.dll
10. C:\Program Files\DiskClean\Uninstall.exe
11. C:\Program Files\DiskClean\etc\avSubEngine.exe
12. C:\Program Files\DiskClean\etc\dcReg.exe
13. C:\Program Files\DiskClean\SoDCUpdateServer.dat
14. C:\Program Files\DiskClean\partner.ini
15. C:\Program Files\DiskClean\DCUpdateServer.dat

Registry Details

DiskClean may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\diskcleanmain
HKEY_LOCAL_MACHINE\SOFTWARE\DiskClean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DiskCleanMain

Related Posts

Trending

Most Viewed

Loading...