Clean32.com

Malware logo.png
Clean32.com has been flagged by the community as a distributor of malware. Below are some community projects watching Malware that may have pages listed about Clean32.com.

Title

registry

Description

Additional Information

See Talk:Clean32.com

Discussion

Warning www.clean32.com is a known source of malware. Don't use this site nor any of the services it provides.

I've just fixed a malware infection. The computer had started randomly communucating with:

registrycleanerxp.com

regupdate.net

clean32.com

fix64.com


(Don't open those sites!!!)


errorlc9.th.png


YOU CAN FIX THIS BY FOLLOWING THESE INSTRUCTION ON THIS PAGE BY MICROSOFT - http://www.microsoft.com/windowsxp/using/security/learnmore/stopspam.mspx


It's a hoax and not something you need to worry about. Get a copy of [url=http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022_4-10672044.html?tag=lst-0-1]Ad-Aware[/img] and SpyBot Search and Destroy and scan your Windows installation to eliminate the spyware. While not a real problem, it can be ugly and unpleasant to have to deal with.

Remember that ANY Windows installation NEEDS an antivirus program. AVG free edition is a good choice. And keep both Ad-Aware and SpyBot handy. Finally, safe surfing is REALLY important, particularly when running Windows.

OR

Stop Messenger Service on system and run HijackThis and search the log file for BHO process and fix these processes

Logfile of HijackThis v1.99.1 Scan saved at 03:21:48 p.m., on 16/05/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Archivos de programa\Analog Devices\Core\smax4pnp.exe C:\Archivos de programa\Analog Devices\SoundMAX\Smax4.exe C:\WINDOWS\System32\RUNDLL32.EXE C:\Archivos de programa\Eset\nod32kui.exe C:\WINDOWS\System32\ctfmon.exe C:\Archivos de programa\Eset\nod32krn.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\wuauclt.exe C:\Documents and Settings\Cesar\Escritorio\Spybot, Ad-Aware y AntiSpyware\HijackThis3.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos R3 - URLSearchHook: Barra Yahoo! con bloqueador de ventanas emergentes - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Archivos de programa\Spybot - Search & Destroy\SDHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Barra Yahoo! con bloqueador de ventanas emergentes - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe O4 - HKLM\..\Run: [SoundMAXPnP] C:\Archivos de programa\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [SoundMAX] "C:\Archivos de programa\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Archivos de programa\Yahoo!\Common\yinsthelper.dll O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

and strop Messenger Service on system.

Related Domains

External Links