Malware

About “Hoax.Win32.DeceptPCClean.kiw” infection

Malware Removal

The Hoax.Win32.DeceptPCClean.kiw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Hoax.Win32.DeceptPCClean.kiw virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to create or modify system certificates
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
crt.usertrust.com
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com
crl.sectigo.com

How to determine Hoax.Win32.DeceptPCClean.kiw?


File Info:

crc32: 2FC00442
md5: a2f788d096a7634adb96e7e334332ad9
name: spcspcw2.exe
sha1: 512ed52f81eef90439fd2629800ac356a6f010c3
sha256: 51cceb68097631487c7f3e778420379ba6d40fefea001772baba0ad3866c4960
sha512: b3dafd35c2ccac33a5fa93421dd60a4e253d3aef342d4b63654bde178e1e539d0941555d6cd0a3c79f11c39eddfe92da6bf90472bab2c52c60619fc936c6bdc7
ssdeep: 49152:99jign98hw+fC2WhYfj0Ddu12UkX7X5c8D5OY2y5qEEaZFb/NFkDrOS:rjig6wO0xucxy8D5Ory5ttbLS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: Similar Photo Cleane
CompanyName: similarphotocleaner.com
Comments: This installation was built with Inno Setup.
ProductName: Similar Photo Cleaner
ProductVersion: 1.0.0.35166
FileDescription: Similar Photo Cleaner
Translation: 0x0000 0x04b0

Hoax.Win32.DeceptPCClean.kiw also known as:

MicroWorld-eScanTrojan.GenericKD.32622138
McAfeeArtemis!A2F788D096A7
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabHacktool.Win32.DeceptPCClean.3!c
SangforMalware
BitDefenderTrojan.GenericKD.32622138
K7GWAdware ( 0052b4081 )
K7AntiVirusAdware ( 0052b4081 )
ArcabitTrojan.Generic.D1F1C63A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GT32SupportGeeks.M.gen potentially unwanted
GDataTrojan.GenericKD.32622138
KasperskyHoax.Win32.DeceptPCClean.kiw
AlibabaRiskWare:Win32/PCFixer.8d743892
TencentWin32.Trojan-psw.Deceptpcclean.Lnxv
EmsisoftApplication.PCFixer (A)
ComodoMalware@#3vjaj9dvy3dz3
DrWebProgram.Unwanted.4558
McAfee-GW-EditionArtemis
FireEyeTrojan.GenericKD.32622138
SophosGeneric PUA FB (PUA)
CyrenW32/Trojan.KWEA-3516
JiangminHoax.DeceptPCClean.aqo
MAXmalware (ai score=81)
MicrosoftPUA:Win32/Puamson.A!ml
ViRobotAdware.Pcfixer.3006304
ZoneAlarmHoax.Win32.DeceptPCClean.kiw
ALYacTrojan.GenericKD.32622138
MalwarebytesPUP.Optional.SimilarPhotoCleaner
PandaTrj/CI.A
FortinetRiskware/DeceptPCClean
Ad-AwareTrojan.GenericKD.32622138
AVGFileRepMalware
AvastFileRepMalware
MaxSecureTrojan.Malware.74648761.susgen

How to remove Hoax.Win32.DeceptPCClean.kiw?

Hoax.Win32.DeceptPCClean.kiw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment