RegClean

Translate To:

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 37
First Seen: July 24, 2009
Last Seen: June 10, 2026
OS(es) Affected: Windows

RegClean Image

RegClean is a rogue registry cleaner application that is usually downloaded and installed onto your computer by a Trojan finding its way through browser security holes. As soon as it is installed it will display notifications of non-existent and overemphasized system errors in order to trick you into purchasing the full version. RegClean is a clone of ErrorSweeper.

Aliases

1 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Prevx1 Heuristic: Suspicious File Which Interferes With V

SpyHunter Detects & Remove RegClean

File System Details

RegClean may create the following file(s):
# File Name MD5 Detections
1. setupxv[1].exe 56ac83029cd09e0a81f7e36e5ba55a12 7
2. RegClean.exe d9259183228a683379bc14dfaa0e5209 3
3. setup[1].exe ad8b53274e8539f10f8cd880982ea40f 0
4. Launcher.exe 27be4cfed338e7c31e1cafbbcc92c49f 0

Analysis Report

General information

Family Name: RegClean
Packers: UPX
Signature status: Self Signed

Known Samples

MD5: 92c1c3f4670a789e63a9f0af567294ab
SHA1: dd96d65e231862f7dee15422ad1edf1d4c06f8d5
SHA256: 17063C9A2B44C1BEDD0FD640B190A490E3953A013C5261CC11BC7BCC6C3B5135
File Size: 4.48 MB, 4477576 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Igor Pavlov
File Description 7z Setup SFX
File Version 4.42
Internal Name 7zS.sfx
Legal Copyright Copyright (c) 1999-2006 Igor Pavlov
Original Filename 7zS.sfx.exe
Product Name 7-Zip
Product Version 4.42

Digital Signatures

Signer Root Status
2Squared Software VeriSign Class 3 Code Signing 2004 CA Self Signed

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7zs1ef3.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot.msi Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot.msi Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot64.msi Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot64.msi Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\antispywarebot.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\antispywarebot.exe Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\antispywarebot.srv.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\antispywarebot.srv.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\antispywarebot.url Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\antispywarebot.url Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\database.ref Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\database.ref Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\difxapi.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\difxapi.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\filterdrv Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\filterdrv\antispywarebot.amd64.sys Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\filterdrv\antispywarebot.amd64.sys Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\filterdrv\antispywarebot.cat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\filterdrv\antispywarebot.cat Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\filterdrv\antispywarebot.inf Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\filterdrv\antispywarebot.inf Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\filterdrv\antispywarebot.x86.sys Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\filterdrv\antispywarebot.x86.sys Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\spycleaner.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\spycleaner.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\tcl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\tcl.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\vistacptasks.xml Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\vistacptasks.xml Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\zlib.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\antispywarebot\zlib.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\msistart.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs1ef3.tmp\msistart.exe Synchronize,Write Attributes
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\3c3948be6e525b8a8cee9fac91c9e392_2a7101c933464c162b9f6d6837ce2079 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\60e31627fda0a46932b0e5948949f2a5 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\3c3948be6e525b8a8cee9fac91c9e392_2a7101c933464c162b9f6d6837ce2079 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\60e31627fda0a46932b0e5948949f2a5 Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\ctf\msutb::left RegNtPreCreateKey
HKCU\software\microsoft\ctf\msutb::top RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

.\MSIStart.exe AntiSpywareBot
msiexec /i AntiSpywareBot64.msi

Related Posts

Trending

Most Viewed

Loading...