PUA

Should I remove “PUP.Optional.SimilarPhotoCleaner”?

Malware Removal

The PUP.Optional.SimilarPhotoCleaner is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.SimilarPhotoCleaner virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to create or modify system certificates
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
crt.usertrust.com

How to determine PUP.Optional.SimilarPhotoCleaner?


File Info:

crc32: 2A8B944F
md5: 3aa657af2da37669c551dc394423635a
name: spcspcw6.exe
sha1: bb5277516106b7fdd380791284d72ec6070210ab
sha256: 5670060a3c37be12952fb0608bd89619d994df92984f50d74a7b6a65f2769e92
sha512: 533ba08a79db7386bb39f68ec07c39ea4385d59b9a1eb33e8610cec90f6ccc901057563b7a0bf26ac5e96d6321b4e3fad417fcf249d6f3f9922466d372b4052d
ssdeep: 49152:a9jHjAoRM2YElv9hSdNYju3HUVWy379Fj0lBTxkv/C5js9WlJ8h2UX5:UjlRB1v9hSsq3UIy35FyqOjrL8h7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: Similar Photo Cleane
CompanyName: similarphotocleaner.com
Comments: This installation was built with Inno Setup.
ProductName: Similar Photo Cleaner
ProductVersion: 1.0.0.35166
FileDescription: Similar Photo Cleaner
Translation: 0x0000 0x04b0

PUP.Optional.SimilarPhotoCleaner also known as:

MicroWorld-eScanTrojan.GenericKD.32672070
FireEyeTrojan.GenericKD.32672070
McAfeeArtemis!3AA657AF2DA3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 005205e51 )
BitDefenderTrojan.GenericKD.32672070
K7GWAdware ( 005205e51 )
SymantecML.Attribute.HighConfidence
GDataTrojan.GenericKD.32672070
KasperskyHoax.Win32.DeceptPCClean.kms
AlibabaRiskWare:Win32/PCFixer.7ae31d9a
AegisLabHacktool.Win32.DeceptPCClean.3!c
Ad-AwareTrojan.GenericKD.32672070
SophosGeneric PUA LL (PUA)
ComodoMalware@#18t2s0g1bp8yi
DrWebProgram.Unwanted.4626
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.32672070 (B)
JiangminHoax.DeceptPCClean.apg
MaxSecureTrojan.Malware.74161428.susgen
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F28946
ZoneAlarmHoax.Win32.DeceptPCClean.kms
AhnLab-V3Malware/Gen.Generic.C3544067
ALYacTrojan.GenericKD.32672070
MAXmalware (ai score=80)
MalwarebytesPUP.Optional.SimilarPhotoCleaner
PandaTrj/CI.A
ESET-NOD32a variant of Win32/GT32SupportGeeks.M.gen potentially unwanted
TencentWin32.Trojan-psw.Deceptpcclean.Lmla
FortinetRiskware/DeceptPCClean
AVGFileRepMalware

How to remove PUP.Optional.SimilarPhotoCleaner?

PUP.Optional.SimilarPhotoCleaner removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment