Clean This

Clean This or also known as CleanThis virus is believed to be another variant of widely-spread rogue software called Think Point. Clean This is introduced as real anti-virus program on web sites created for promotional purposes. Authors of this malware also spread a Trojan in advance to infect web sites and modify each to run instant virus scan on visitor’s computer. The said online scan will show fake detection intended to influence victim to download and install a copy of Clean This. At first glance, innocent user may not know it as a threat. Some may consider the rogue program is useful because it clearly simulate to protect the system. Additionally, Clean This was developed using a nice graphical user interface. Most of all, it may turn out that the fake antivirus was part of the Windows operating system.

Victims may suffer from severe obstruction while using the PC when Clean This virus starts to display a lot of alerts and taskbar warning messages. It also blocks any programs from running and declares that relevant file is infected. This moment is the perfect time to advise the acquisition for full version of Clean This. Several pop-up is displayed suggesting immediate removal of identified Trojans and viruses.

Do not get deceived by this rogue product, start scanning the computer with genuine and effective security software as described below. The removal guide and free tool will help you remove Clean This virus without going through a long process.

Screen Shot Images:

"Clean This" Virus

Technical Details and Additional Information:

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

Characteristics (Analysis)
Clean This virus is set to start up automatically by producing registry entry that contains this value:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “cleanthis”

Malware Behavior

An attempt to run any installed program is blocked by this malware. Instead, it will state that the file is infected through this alert warning:

CleanThis
The application taskmgr.exe was launched successfully but was forced to shut down due to security reasons. This happened because the application was infected by a malicious program which might post a threat for the OS. It is highly recommended to install the necessary heuristic module and perform a full scan of your computer to exterminate malicious programs from it.

Added Registry Entries:
HKEY_CURRENT_USER\Software\PAV
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “cleanthis”
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon “Shell” = “%Documents and Settings%\[UserName]\Application Data\gog.exe”
Associated Files and Folders:
%UserProfile%\Application Data\gog.exe
%UserProfile%\Application Data\cleanthis.exe
%UserProfile%\Application Data\install

How to Remove Clean This

Manual Removal Procedure

1. Kill any running process that belongs to Clean This.
- Press Ctrl+Alt+Del on your keyboard.
- When Windows Task Manager appears, look for the following files and click End Task.
hotfix.exe, gog.exe

2. Delete all registry entries that belong to this malware.
- Press [Windows Key]+R on your keyboard.
- In the 'Open' dialog box, type regedit. This will open registry editor.
- Find and delete the following:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon “Shell” = “%Documents and Settings%\[UserName]\Application Data\gog.exe”
- Close registry editor. Changes made will be save automatically.

3. Scan the computer with antivirus program.
- Connect to Internet and open your antivirus software. Please Update to obtain the latest database and necessary files.
- Restart the computer in Safe Mode.
- Just before Windows logo begins to load press F8 on your keyboard.
- On Windows Advanced Boot Options, select Safe Mode and press Enter.

4. Delete all files dropped by Clean This.
- While still in Safe Mode, search and delete malicious files. Please refer to 'Associated Files and Folders.'

Automatic Removal of Clean This

In order to completely remove the threat, click here to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.
Notes

During Clean This infection, it will drop several files under some areas of your system. It also alters some settings under Windows registry. To revert the changes made by the virus, try doing a System Restore first before proceeding with other removal guides. Running system restore replaces malicious files and registry entries with clean ones preserved under a restore point. Click here for procedures.

Warning!

You should not make changes to Windows Registry except it is crucial. Faulty registry entries may result to severe system malfunction. Please backup Windows registry before performing any changes so that you can restore it once an error is committed.Follow the procedures from this link.

Helpful Tip

Majority of malware acts to disable victim’s access to Task Manager. The main reason for this is to avoid ending process that is essential to operation. Most computer users know that ending the process will stop the affected program whether it is legitimate of rogue. So, to complete Clean This removal, you must be able to gain an access to Task Manager. Read full instructions here.

What to do next...