PUP.PC Cleaner Pro

Threat Scorecard

Popularity Rank: 6,335
Threat Level: 10 % (Normal)
Infected Computers: 331,708
First Seen: November 28, 2011
Last Seen: January 28, 2026
OS(es) Affected: Windows

Aliases

8 security vendors flagged this file as malicious.

Antivirus Vendor Detection
AVG Smartpcso.504
McAfee-GW-Edition FakeAlert-FTM!29342D6E11BE
Symantec WS.Reputation.1
McAfee Artemis!E841A3F506F9
Ikarus Trojan.SuspectCRC
McAfee-GW-Edition Artemis
Symantec PCCleaner
McAfee Artemis!BD268F75BFCE

SpyHunter Detects & Remove PUP.PC Cleaner Pro

File System Details

PUP.PC Cleaner Pro may create the following file(s):
# File Name MD5 Detections
1. BrowserCleaner (1).exe 65127738b0069eebaa8fd0aecad3f498 11,233
2. PC_Cleaner_Pro_Installer_a3(1).exe 1a7f85b1a7568f5275475ee4fe7f38eb 3,618
3. app3_Install_eng.exe 15b158e544fe6528082a4a2f25beda26 3,194
4. PCCLauncher.exe b9625263a6dc6601b8723226df295020 2,875
5. app2_eng_exe 0e86c4697275cde2b02c29c98fbcc90c 1,280
6. PC-Installer-Pro-application.exe 2fd80f6984b1f45dcc01afbe25333e9b 1,186
7. PCCSmartScan.exe 2de388250125b66c3ab38961c00d8147 954
8. PCCleanerAV.exe 9e76d65891a935bef9f055eb7afb3a2e 834
9. pcavmon.exe 94a443e4257a9f86717077f6033ca404 754
10. A0332266.exe e1c7b52a6a4c49cb9d01b5604fcad67f 385
11. ~extncp18467.exe 6d4f4c58cb8bc800dcf73dc8d6b47a5b 381
12. PCCleaner.exe f32a5119378d0d0478daf1678fb456b6 252
13. app2_eng.exe 8e184690be9d28bb4a66512528150f0a 110
14. poptunst.exe 657791f9698748e56d16b165dfe13bdf 98
15. pclunst.exe ddb1997ab9c4fe1ff6f6956c93798a88 30
16. pcpro-app1.exe 7dbb6e9935e1cbbc1744d1ed643f8c6f 26
17. .exe 029e6768ff151b23c406c0a872f7260b 24
18. PCPro-Elite-English.exe 5ebd5c91953fab42aa60adacb6e428aa 16
19. PCPro-Installer.exe 04353a2e548db34a6bf9a1b194625128 8
20. PCBrowserCleaner.exe 2c30520bbf98887dfaf1d7baa3065bf8 4
21. appclunst.exe c27ba24cdaaa38c323339021810480e2 2
22. setup.exe 94ada7d39eed532e99f2d066d2300f38 2
23. PCCleaners.exe cacce37441a61451dcebf185ad35956a 1
24. file.exe 6933dcecf7fbe32c3106265a9abea5f5 1
25. 637D04F2EC2855F5070BB64F2F61B6CC 637d04f2ec2855f5070bb64f2f61b6cc 1
26. pccleanpro.exe 162ad52ad455f5aa96bec0ba26470e0f 0
27. PCPro-Elite-Swedish.exe 864ec447841a03f113cb213f412b8cea 0
More files

Registry Details

PUP.PC Cleaner Pro may create the following registry entry or registry entries:
CLSID
{0542D788-C4FC-4ED8-2222-D654E27AF7F8}
{2064E8AE-A939-441b-BBD5-BA0F30A336FE}
{A3011E88-B997-11CF-2222-0080C7B2D6BB}
{A39F8F88-F91E-4E49-2222-BD21AB39D1BB}
{A3D87888-DEAA-4971-2222-5D5046F2B3BB}
{AF843388-EFC2-49C9-2222-FC0C403B0EBB}
File name without path
http_pccleanerpro.net_0.localstorage
PC Antivirus Pro.lnk
PC Browser Cleaner.lnk
PC Cleaner Lite.lnk
PC Cleaner Pro.lnk
Regexp file mask
%WINDIR%\System32\Tasks\PC Cleaner Pro Optimization
%WINDIR%\System32\Tasks\PC Cleaner Pro Update Job
%WINDIR%\System32\Tasks\pc-dis-upd
%WINDIR%\System32\Tasks\PCCleaner-Maintenance-Autorun
Software\Classes\apcrdsdef01
SOFTWARE\Classes\AppID\pcavmon.exe
SOFTWARE\Classes\pcavmon.Gate
SOFTWARE\Classes\pcavmon.Gate.1
SOFTWARE\Classes\Wow6432Node\AppID\pcavmon.exe
Software\Classes\{3564E8AE-A939-441b-BBD5-BA0F30A336FE}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC Cleaner Pro Optimization
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC Cleaner Pro Update Job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC Cleaner Updater
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pc-dis-upd
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PCCleaner-Maintenance-Autorun
Software\PCAntivirus
Software\PCBrowserCleaner
Software\PCCleanerProLanguage
Software\PCCleaners
SOFTWARE\PCCleanerSettings
SOFTWARE\Wow6432Node\PCCleaners
SOFTWARE\Wow6432Node\PCCleanerSettings
SYSTEM\ControlSet001\services\pcavmon
SYSTEM\CurrentControlSet\services\pcavmon

Directories

PUP.PC Cleaner Pro may create the following directory or directories:

%ALLUSERSPROFILE%\AVC1Data
%ALLUSERSPROFILE%\Application Data\LocalStoragePC1
%ALLUSERSPROFILE%\Application Data\PC Cleaner Pro
%ALLUSERSPROFILE%\Application Data\PC Cleaners
%ALLUSERSPROFILE%\Application Data\PC1Data
%ALLUSERSPROFILE%\Application Data\PCCleaner Pro
%ALLUSERSPROFILE%\Application Data\PCProSettingsLocal
%ALLUSERSPROFILE%\LocalStoragePC1
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\PC Cleaners
%ALLUSERSPROFILE%\PC Browser Cleaner
%ALLUSERSPROFILE%\PC Cleaner Pro
%ALLUSERSPROFILE%\PC Cleaners
%ALLUSERSPROFILE%\PC1BcData
%ALLUSERSPROFILE%\PC1Data
%ALLUSERSPROFILE%\PCCleaner Pro
%ALLUSERSPROFILE%\PCProSettingsLocal
%ALLUSERSPROFILE%\Start Menu\Programs\PC Cleaners
%APPDATA%\AVPro
%APPDATA%\Microsoft\Windows\Start Menu\Programs\PC Cleaner Pro
%APPDATA%\Microsoft\Windows\Start Menu\Programs\PC Cleaners
%APPDATA%\PC Cleaner Pro
%LOCALAPPDATA%\PCCleanerPro
%PROGRAMFILES%\PC Antivirus
%PROGRAMFILES(X86)%\PC Antivirus
%PROGRAMFILES(x86)%\PC Cleaner Pro
%USERPROFILE%\Microsoft\Windows\Start Menu\Programs\PC Cleaners
%userprofile%\documents\PCCleanerPro

Analysis Report

General information

Family Name: PUP.PC Cleaner Pro
Packers: UPX
Signature status: Self Signed

Known Samples

MD5: f033fafc5d08b4b7539b38b523bf2179
SHA1: 67a7fe680cce90ae2a295938bff193bbf9434219
SHA256: D7A971A529541A05C7E9437725557F857A0376840CECC7DE909D78DBAD59D221
File Size: 5.25 MB, 5247896 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name (c) PC Cleaners Inc
File Description PC Cleaner Pro
File Version 21.0.0.0
Internal Name PCInstaller.exe
Legal Copyright (c)2015 PC Cleaners Inc. All rights reserved.
Original Filename PCInstaller.exe
Product Name PC Cleaner Pro
Product Version 21.0.0.0

Digital Signatures

Signer Root Status
PC Cleaner Inc. Symantec Class 3 SHA256 Code Signing CA Self Signed

Block Information

Total Blocks: 2,085
Potentially Malicious Blocks: 7
Whitelisted Blocks: 1,966
Unknown Blocks: 112

Visual Map

0 ? ? 0 ? ? 0 ? 0 ? ? ? ? x 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? x ? 0 0 ? 0 0 ? ? 0 0 0 0 ? ? 0 ? x 0 0 ? ? ? 0 ? ? 0 0 0 0 0 ? 0 ? ? ? ? ? 0 0 ? ? ? 0 ? 0 0 ? ? 0 ? 0 ? 0 ? ? 0 ? 0 0 0 ? 0 ? ? 0 0 0 ? ? ? ? 0 0 0 ? ? ? ? 0 ? ? 0 0 0 ? ? ? 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 2 0 0 0 0 0 1 0 0 0 0 0 0 1 1 1 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 1 1 0 3 1 1 0 0 0 1 1 0 0 0 2 3 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 2 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 1 0 1 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 1 0 0 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 2 1 1 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 2 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\programdata\pc1data\settings.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\pc1data\settings.txt Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows nt\currentversion\appcompatflags\compatibility assistant\persisted::c:\users\user\downloads\67a7fe680cce90ae2a295938bff193bbf9434219_0005247896  RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
  • SetWindowsHookEx

Related Posts

Trending

Most Viewed

Loading...