Hardclean

Hardclean is a rogue anti-virus program that is mainly distributed and infecting computers in Korea. This fake program will set user’s mind that computer is infected with different types of malware and viruses through its fake alert messages. Hardclean also performs a fabricated scan of local hard drives and report numerous threats found even if computer is free from viruses. This misleading technique repeatedly used by rogue programs to deceive computer users and convince them that purchasing a registered version is necessary.

If infected, it will modify system settings and make changes on Windows registry to ensure that it will be loaded when Windows starts. Hardclean will generate a Taskbar Icon so that it may look like a legitimate program.

Screen Shot Image:

Hardclean

Technical Details and Additional Information:

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista

Characteristics (Analysis)

  • This particular program must be downloaded from their website. You must have been infected by a browser hijacker that points browser to their website and automatically downloaded the program onto your computer.
  • It can be installed on your computer by embedding itself on another executable file that can be obtain from file-sharing networks.

Malware Behavior
Just as any fake security software, Hardclean will attempt to deceive computer users by flashing excessive alerts that does not complement the real security status of the PC. This method is dubbed as scare tactics.

Same deceptive process is also projected in its virus scan that will commence after logging-in to Windows. Hardclean will detect non-existent threat to persuade victims into purchasing the paid version of the software.

Added Registry Entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hardclean
HKEY_LOCAL_MACHINE\SOFTWARE\hardclean
Associated Files and Folders:
%\Program Files\HardClean\hardclean.exe
%\Program Files\HardClean\hardcleanBK.exe
%\Program Files\HardClean\hardcleandm.exe
%\Program Files\HardClean\hardcleanU.exe
%\Program Files\HardClean\bottomAd.swf
%\Program Files\HardClean\mdata.dat
%\Program Files\HardClean\trackingsitedata
%\Program Files\HardClean\ubdata
%\WINDOWS\system32\uninst_hardclean.exe

How to Remove Hardclean

Manual Removal Procedure

1. Kill any running process that belongs to Hardclean.
- Press Ctrl+Alt+Del on your keyboard.
- When Windows Task Manager appears, look for the following files and click End Task.
hardclean.exe, hardcleandm.exe

2. Delete all registry entries that belong to this malware.
- Press [Windows Key]+R on your keyboard.
- In the 'Open' dialog box, type regedit. This will open registry editor.
- Find and delete the following:
HKEY_LOCAL_MACHINE\SOFTWARE\hardclean
- Close registry editor. Changes made will be save automatically.

3. Scan the computer with antivirus program.
- Connect to Internet and open your antivirus software. Please Update to obtain the latest database and necessary files.
- Restart the computer in Safe Mode.
- Just before Windows logo begins to load press F8 on your keyboard.
- On Windows Advanced Boot Options, select Safe Mode and press Enter.

4. Delete all files dropped by Hardclean.
- While still in Safe Mode, search and delete malicious files. Please refer to 'Associated Files and Folders.'

Automatic Removal of Hardclean

In order to completely remove the threat, click here to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.

What to do next...