Jump to content

Removal instructions for Dev360 Cleaner


Recommended Posts

  • Staff
What is Dev360 Cleaner?

The Malwarebytes research team has determined that Dev360 Cleaner is a fake registry cleaner and system optimizer. These programs use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems.
More information can be found on our Malwarebytes Unpacked blog.

How do I know if I am infected with Dev360 Cleaner?

This is how the main screen of the registry cleaning application looks:

warning1.png

You will find these icons in your taskbar and on your desktop:

icons.png

And see this warning during install:

main.png

and these screens during "operations":

warning2.png

warning3.png

warning5.png

You may see this entry in your list of installed programs:

warning4.png

and this task in your Task Scheduler:

warning6.png


How did Dev360 Cleaner get on my computer?

These so-called registry cleaners use different methods of getting installed. This particular one was offered as a system optimizer.

How do I remove Dev360 Cleaner?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted application.
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan Now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
Is there anything else I need to do to get rid of Dev360 Cleaner?
  • No, Malwarebytes' Anti-Malware removes Dev360 Cleaner completely.
  • This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this registry cleaner.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the Dev360 Cleaner installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late.

 

protection1.png


Technical details for experts

You may see these entries in FRST logs:

 
 (Dev360Labs Limited) C:\Program Files (x86)\Dev360 Cleaner\D360Schedule.exe
 (Dev360Labs Limited) C:\Program Files (x86)\Dev360 Cleaner\Dev360Cleaner.exe
 C:\Windows\System32\Tasks\Dev360 Cleaner Schedule
 C:\Users\{username}\Desktop\Dev360 Cleaner.lnk
 C:\Users\{username}\Documents\Dev360 Cleaner
 C:\Users\{username}\AppData\Roaming\Dev360 Cleaner
 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dev360 Cleaner
 C:\Program Files (x86)\Dev360 Cleaner

Dev360 Cleaner v5.0 (HKLM-x32\...\Dev360 Cleaner_is1) (Version: 5.0 - Dev360Labs Limited)
Task: {C4C8A5CE-3234-4372-AD5C-F8D1DE15AABB} - System32\Tasks\Dev360 Cleaner Schedule => C:\Program Files (x86)\Dev360 Cleaner\D360Schedule.exe [2016-04-29] (Dev360Labs Limited)
Alterations made by the installer:
 
File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Program Files (x86)\Dev360 Cleaner
       Adds the file Animation.gif"="1/27/2014 9:19 PM, 16555 bytes, A
       Adds the file D360Schedule.exe"="4/29/2016 12:29 PM, 970912 bytes, A
       Adds the file Dev360Cleaner.chm"="4/29/2016 11:45 AM, 33100 bytes, A
       Adds the file Dev360Cleaner.exe"="5/2/2016 6:56 PM, 8569504 bytes, A
       Adds the file English.ini"="4/28/2016 9:37 PM, 42483 bytes, A
       Adds the file file_id.diz"="9/18/2015 9:27 PM, 914 bytes, A
       Adds the file HomePage.url"="9/18/2015 9:28 PM, 49 bytes, A
       Adds the file RList.txt"="1/14/2016 12:30 PM, 1505 bytes, A
       Adds the file SList.db"="4/28/2016 7:52 PM, 1093632 bytes, A
       Adds the file SList.txt"="4/21/2016 9:45 PM, 78828 bytes, A
       Adds the file sqlite3.dll"="4/12/2015 7:25 PM, 673521 bytes, A
       Adds the file unins000.dat"="5/26/2016 8:31 AM, 9335 bytes, A
       Adds the file unins000.exe"="5/26/2016 8:30 AM, 715038 bytes, A
    Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dev360 Cleaner
       Adds the file Check updates.lnk"="5/26/2016 8:31 AM, 1120 bytes, A
       Adds the file Dev360 Cleaner on the Web.lnk"="5/26/2016 8:31 AM, 1067 bytes, A
       Adds the file Dev360 Cleaner.lnk"="5/26/2016 8:31 AM, 1092 bytes, A
       Adds the file Help.lnk"="5/26/2016 8:31 AM, 1092 bytes, A
       Adds the file Uninstall Dev360 Cleaner.lnk"="5/26/2016 8:31 AM, 1067 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Dev360 Cleaner\Backup
    Adds the folder C:\Users\{username}\AppData\Roaming\Dev360 Cleaner\Log
    Adds the folder C:\Users\{username}\AppData\Roaming\Dev360 Cleaner\Undo
    In the existing folder C:\Users\{username}\Desktop
       Adds the file Dev360 Cleaner.lnk"="5/26/2016 8:31 AM, 1074 bytes, A
    In the existing folder C:\Windows\System32\Tasks
       Adds the file Dev360 Cleaner Schedule"="5/26/2016 8:31 AM, 3266 bytes, A

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Dev360 Cleaner_is1]
       "DisplayName"="REG_SZ", "Dev360 Cleaner v5.0"
       "DisplayVersion"="REG_SZ", "5.0"
       "EstimatedSize"="REG_DWORD", 11899
       "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\Dev360 Cleaner"
       "Inno Setup: Deselected Tasks"="REG_SZ", ""
       "Inno Setup: Icon Group"="REG_SZ", "Dev360 Cleaner"
       "Inno Setup: Language"="REG_SZ", "en"
       "Inno Setup: Selected Tasks"="REG_SZ", "desktopicon"
       "Inno Setup: Setup Version"="REG_SZ", "5.4.2 (a)"
       "Inno Setup: User"="REG_SZ", "{username}"
       "InstallDate"="REG_SZ", "20160526"
       "InstallLocation"="REG_SZ", "C:\Program Files (x86)\Dev360 Cleaner\"
       "MajorVersion"="REG_DWORD", 5
       "MinorVersion"="REG_DWORD", 0
       "NoModify"="REG_DWORD", 1
       "NoRepair"="REG_DWORD", 1
       "Publisher"="REG_SZ", "Dev360Labs Limited"
       "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\Dev360 Cleaner\unins000.exe" /SILENT"
       "UninstallString"="REG_SZ", ""C:\Program Files (x86)\Dev360 Cleaner\unins000.exe""
    [HKEY_CURRENT_USER\Software\Dev360 Cleaner]
       "AdsAntivirusLink"="REG_SZ", "http://webtools.avanquest.com/redirect.cfm?eredirectId=Avanquest/OneSafe_PC_Cleaner_Antivirus_EN.htm"
       "AdsAntivirusName"="REG_SZ", "Ad-Aware"
       "AdsBuyNowURL"="REG_SZ", "http://www.dev360labs.com/redirect.php?redirectId=DEV360/Cross_Sell/PC_Driver_Buy_01.htm"
       "AdsDownloadURL"="REG_SZ", "http://dev360labs.com/files/cross-sell/dev360drivermanager.exe"
       "AfterInstallURL"="REG_SZ", "http://www.dev360labs.com/redirect.php?redirectId=DEV360/PC_Cleaner_Post_Install_02.htm"
       "AntivirusNotifier"="REG_DWORD", 1
       "BackupDir"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Dev360 Cleaner\Backup"
       "BuildID"="REG_SZ", "AQEN_DEV360_CLEANER_V5"
       "BuyNowURL"="REG_SZ", "http://www.dev360labs.com/redirect.php?redirectId=DEV360/PC_Cleaner_Buy_02.htm"
       "CacheNotifier"="REG_DWORD", 1
       "CompilerVersion"="REG_SZ", "Apr2016"
       "CrashNotifier"="REG_DWORD", 1
       "DiskNotifier"="REG_DWORD", 1
       "DisplayName"="REG_SZ", "Dev360 Cleaner"
       "ExitSP1"="REG_DWORD", 1
       "ExitSP2"="REG_DWORD", 1
       "HideAfterInstallURL"="REG_DWORD", 1
       "HomePageURL"="REG_SZ", "http://dev360labs.com"
       "InstallationDate"="REG_BINARY, ....
       "IsRetailVersion"="REG_DWORD", 0
       "ItemsFixed"="REG_DWORD", 0
       "ItemsToFix"="REG_DWORD", 108
       "ItemsToPrivacyScan"="REG_SZ", "1111"
       "ItemsToRecoveryScan"="REG_SZ", "1111"
       "ItemsToRegistryScan"="REG_SZ", "1111111111"
       "Language"="REG_DWORD", 1
       "LastCleanExecuted"="REG_DWORD", 0
       "LastNotificationTime"="REG_BINARY, ....
       "LastScanCanceled"="REG_DWORD", 0
       "LastScanChecked"="REG_SZ", "1111011"
       "LastScanDate"="REG_BINARY, ....
       "LastScanFound"="REG_DWORD", 108
       "LastUpdateChecking"="REG_BINARY, ....
       "LogDir"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Dev360 Cleaner\Log"
       "MemoryNotifier"="REG_DWORD", 1
       "MinFreeDiskSpace"="REG_DWORD", 10
       "MinFreeMemory"="REG_DWORD", 10
       "NewAppNotifier"="REG_DWORD", 1
       "NewToolbarNotifier"="REG_DWORD", 1
       "NLaunches"="REG_DWORD", 1
       "OnWinStartup"="REG_DWORD", 0
       "ProURL"="REG_SZ", "http://www.dev360labs.com/redirect.php?redirectId=DEV360/PC_Cleaner_Upsell_PRO.htm"
       "RenewURL"="REG_SZ", "http://www.dev360labs.com/redirect.php?redirectId=DEV360/PC_Cleaner_Renew.htm"
       "s_SmartDate"="REG_BINARY, ....
       "s_SmartEnabled"="REG_DWORD", 1
       "s_SmartMode"="REG_DWORD", 0
       "ShowErrorsInBuyNowLink"="REG_DWORD", 0
       "ShowRebootMessage"="REG_DWORD", 1
       "ShowRecycleBin"="REG_DWORD", 1
       "SizeToClean"="REG_SZ", "305.31 MB"
       "StartupNotifier"="REG_DWORD", 1
       "SupportURL"="REG_SZ", "http://dev360labs.com/support.html"
       "UndoDir"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Dev360 Cleaner\Undo"
       "UninstallNotifier"="REG_DWORD", 1
       "UninstallURL"="REG_SZ", "http://www.dev360labs.com/redirect.php?redirectId=DEV360/PC_Cleaner_Uninstall_02.htm"
       "UpdateReminderDisabled"="REG_DWORD", 0
       "UpgradeID"="REG_SZ", "AQEN_DEV360_CLEANER"
       "UseAds"="REG_DWORD", 1
       "UseExclusions"="REG_DWORD", 1
       "Version"="REG_SZ", "5.0"
Malwarebytes Anti-Malware log:
 
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 5/26/2016
Scan Time: 8:39 AM
Logfile: mbamDev360Cleaner.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.05.26.01
Rootkit Database: v2016.05.20.01
License: Premium
Malware Protection: Disabled
Malicious Website Protection: Enabled
Self-protection: Enabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {username}

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 311884
Time Elapsed: 8 min, 27 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 2
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\D360Schedule.exe, 3004, Delete-on-Reboot, [1564a9319504c4725cff2945956f966a]
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\Dev360Cleaner.exe, 3968, Delete-on-Reboot, [ccad57831a7fc86ebd9e6d01d430e21e]

Modules: 1
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\sqlite3.dll, Delete-on-Reboot, [0c6dc4161386181e66b25d505ea406fa], 

Registry Keys: 3
PUP.Optional.Dev360Cleaner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Dev360 Cleaner Schedule, Delete-on-Reboot, [4a2f36a4cfca6dc906ff6f70fe0529d7], 
PUP.Optional.Dev360Cleaner, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Dev360 Cleaner_is1, Quarantined, [2f4a7f5b24750f27a165ad3203007c84], 
PUP.Optional.Dev360Cleaner, HKCU\SOFTWARE\Dev360 Cleaner, Quarantined, [344531a9584166d04db7ebf4030008f8], 

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 7
PUP.Optional.Dev360Cleaner, C:\Users\{username}\AppData\Roaming\Dev360 Cleaner, Quarantined, [cfaadefc19809c9a5bbbc6e7d62c4fb1], 
PUP.Optional.Dev360Cleaner, C:\Users\{username}\AppData\Roaming\Dev360 Cleaner\Backup, Quarantined, [cfaadefc19809c9a5bbbc6e7d62c4fb1], 
PUP.Optional.Dev360Cleaner, C:\Users\{username}\AppData\Roaming\Dev360 Cleaner\Log, Quarantined, [cfaadefc19809c9a5bbbc6e7d62c4fb1], 
PUP.Optional.Dev360Cleaner, C:\Users\{username}\AppData\Roaming\Dev360 Cleaner\Undo, Quarantined, [cfaadefc19809c9a5bbbc6e7d62c4fb1], 
PUP.Optional.Dev360Cleaner, C:\Users\{username}\Documents\Dev360 Cleaner, Quarantined, [9ddc1dbd13860432987fe0cd788a3ac6], 
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner, Delete-on-Reboot, [0c6dc4161386181e66b25d505ea406fa], 
PUP.Optional.Dev360Cleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dev360 Cleaner, Quarantined, [ed8c13c76b2e52e435e41c91ef1330d0], 

Files: 22
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\D360Schedule.exe, Delete-on-Reboot, [1564a9319504c4725cff2945956f966a], 
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\Dev360Cleaner.exe, Delete-on-Reboot, [ccad57831a7fc86ebd9e6d01d430e21e], 
PUP.Optional.Dev360Cleaner, C:\Users\{username}\Desktop\Dev360 Cleaner.exe, Quarantined, [5d1c4d8d8811999d213a75f9e024f30d], 
PUP.Optional.Dev360Cleaner, C:\Users\{username}\Desktop\Dev360 Cleaner.lnk, Quarantined, [e594815939600b2b709132ad867dc53b], 
PUP.Optional.Dev360Cleaner, C:\Windows\System32\Tasks\Dev360 Cleaner Schedule, Quarantined, [3d3c9941c3d6b77f38ca21be21e2fc04], 
PUP.Optional.Dev360Cleaner, C:\Users\{username}\Documents\Dev360 Cleaner\CookieExclusions.txt, Quarantined, [9ddc1dbd13860432987fe0cd788a3ac6], 
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\Animation.gif, Quarantined, [0c6dc4161386181e66b25d505ea406fa], 
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\Dev360Cleaner.chm, Quarantined, [0c6dc4161386181e66b25d505ea406fa], 
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\English.ini, Quarantined, [0c6dc4161386181e66b25d505ea406fa], 
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\file_id.diz, Quarantined, [0c6dc4161386181e66b25d505ea406fa], 
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\HomePage.url, Quarantined, [0c6dc4161386181e66b25d505ea406fa], 
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\RList.txt, Quarantined, [0c6dc4161386181e66b25d505ea406fa], 
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\SList.db, Quarantined, [0c6dc4161386181e66b25d505ea406fa], 
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\SList.txt, Quarantined, [0c6dc4161386181e66b25d505ea406fa], 
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\sqlite3.dll, Delete-on-Reboot, [0c6dc4161386181e66b25d505ea406fa], 
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\unins000.dat, Quarantined, [0c6dc4161386181e66b25d505ea406fa], 
PUP.Optional.Dev360Cleaner, C:\Program Files (x86)\Dev360 Cleaner\unins000.exe, Quarantined, [0c6dc4161386181e66b25d505ea406fa], 
PUP.Optional.Dev360Cleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dev360 Cleaner\Check updates.lnk, Quarantined, [ed8c13c76b2e52e435e41c91ef1330d0], 
PUP.Optional.Dev360Cleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dev360 Cleaner\Dev360 Cleaner on the Web.lnk, Quarantined, [ed8c13c76b2e52e435e41c91ef1330d0], 
PUP.Optional.Dev360Cleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dev360 Cleaner\Dev360 Cleaner.lnk, Quarantined, [ed8c13c76b2e52e435e41c91ef1330d0], 
PUP.Optional.Dev360Cleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dev360 Cleaner\Help.lnk, Quarantined, [ed8c13c76b2e52e435e41c91ef1330d0], 
PUP.Optional.Dev360Cleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dev360 Cleaner\Uninstall Dev360 Cleaner.lnk, Quarantined, [ed8c13c76b2e52e435e41c91ef1330d0], 

Physical Sectors: 0
(No malicious items detected)


(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.