Jump to content

Recommended Posts

What is CleanMyPC?

CleanMyPC is a system optimizer that triggers our PUP detection rules. By doing so we offer users a choice to consider whether they want to use this software. More information can be found on our Malwarebytes Labs blog.

How do I know if I am affected by CleanMyPC?

This is how the main screen of the system optimizer looks:

main.png

You will find these icons in your taskbar, your startmenu, and on your desktop:

icons.png

and see these windows during install:

warning0.png

warning1.png

warning2.png

and this type of screens during operations:

warning5.png

You may see this entry in your list of installed programs:

warning4.png

and this task in your list of Scheduled Tasks:

warning3.png

How did CleanMyPC get on my computer?

These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their website:

website.png

How do I remove CleanMyPC?

Our program Malwarebytes can detect and remove this PUP.

  • Please download Malwarebytes for Windows to your desktop.
  • Double-click MBSetup.exe and follow the prompts to install the program.
  • When your Malwarebytes for Windows installation completes, the program opens to the Welcome to Malwarebytes screen.
  • Click on the Get started button.
  • Click Scan to start a Threat Scan.
  • When the scan is finished click Quarantine to remove the found threats.
  • Reboot the system if prompted to complete the removal process.

Is there anything else I need to do to get rid of CleanMyPC?

  • No, Malwarebytes removes CleanMyPC completely.

What if I want to keep CleanMyPC?

Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Here’s how to do it.

  • Open Malwarebytes for Windows.
  • Click the Detection History
  • Click the Allow List
  • To add an item to the Allow List, click Add.
  • Select the exclusion type Allow a file or folder and use the Select a folder button to select the main folder for the software that you wish to keep.
  • Repeat this for any secondary files or folder(s) that belong to the software.

If you want to allow the program to connect to the Internet, for example to fetch updates, also add an exclusion of the type Allow an application to connect to the internet and use the Browse button to select the file you wish to grant access.

How would the full version of Malwarebytes help protect me?

We hope our application and this guide have helped you in dealing with this system optimizer.

As you can see below the full version of Malwarebytes would have warned you against the CleanMyPC installer.
 

protection1.png


Technical details for experts

You may see these entries in FRST logs:
 

(MacPaw INC -> MacPaw Inc.) C:\Program Files\CleanMyPC\CleanMyPC.exe
(MacPaw INC -> MacPaw Inc.) C:\Program Files\CleanMyPC\CleanMyPCService.exe
Task: {97A5411A-67C5-4185-AC8F-DCB8098AD05C} - System32\Tasks\CMPCUAC => C:\Program Files\CleanMyPC\CleanMyPC.exe [24297584 2020-09-01] (MacPaw INC -> MacPaw Inc.)
R2 CleanMyPCService; C:\Program Files\CleanMyPC\CleanMyPCService.exe [497264 2020-09-01] (MacPaw INC -> MacPaw Inc.)
C:\Program Files\Common Files\MacPaw
C:\Windows\system32\Tasks\CMPCUAC
C:\Users\Public\Desktop\CleanMyPC.lnk
C:\ProgramData\Desktop\CleanMyPC.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CleanMyPC
C:\Program Files\CleanMyPC
C:\ProgramData\MacPaw Inc

CleanMyPC version 1.10.7.2050 (HKLM\...\{90385FF3-6721-4DCD-AD11-FEBA397F4FE9}_is1) (Version: 1.10.7.2050 - MacPaw, Inc.)
ContextMenuHandlers1: [CMPCContextMenu] -> {1650dc30-2343-498a-b49a-37b90918f611} => C:\Program Files\CleanMyPC\CleanMyPCShell.DLL [2020-09-01] (MacPaw INC -> MacPaw Inc.)
ContextMenuHandlers4: [CMPCContextMenu] -> {1650dc30-2343-498a-b49a-37b90918f611} => C:\Program Files\CleanMyPC\CleanMyPCShell.DLL [2020-09-01] (MacPaw INC -> MacPaw Inc.)

Alterations made by the installer:
 

File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Program Files\CleanMyPC
       Adds the file base.dat"="9/1/2020 4:59 PM, 336656 bytes, A
       Adds the file CleanMyPC.exe"="9/1/2020 4:59 PM, 24297584 bytes, A
       Adds the file CleanMyPC.Tools.exe"="9/1/2020 4:59 PM, 776816 bytes, A
       Adds the file CleanMyPCService.exe"="9/1/2020 4:59 PM, 497264 bytes, A
       Adds the file CleanMyPCShell.dll"="9/1/2020 4:59 PM, 1033840 bytes, A
       Adds the file CleanMyPCSystemInterop.exe"="9/1/2020 4:59 PM, 429680 bytes, A
       Adds the file cmp-help.ico"="12/9/2019 6:41 PM, 74242 bytes, A
       Adds the file cmp-uninstall.ico"="12/9/2019 6:41 PM, 370070 bytes, A
       Adds the file cmp-uninstall-im.bmp"="9/10/2020 8:56 AM, 216534 bytes, A
       Adds the file Common.dll"="9/1/2020 4:59 PM, 737392 bytes, A
       Adds the file Data.dll"="9/1/2020 4:59 PM, 2359408 bytes, A
       Adds the file DevMateKit.dll"="9/1/2020 4:59 PM, 1361520 bytes, A
       Adds the file ICSharpCode.SharpZipLib.dll"="1/26/2020 5:00 PM, 188416 bytes, A
       Adds the file InstallerExtensions.exe"="9/1/2020 4:59 PM, 995440 bytes, A
       Adds the file Interop.Shell32.dll"="12/9/2019 6:41 PM, 39424 bytes, A
       Adds the file Interop.UIAutomationClient.dll"="12/29/2015 6:34 AM, 98464 bytes, A
       Adds the file Interop.WMPLib.dll"="12/9/2019 6:41 PM, 339968 bytes, A
       Adds the file is-9UURR.tmp"="9/1/2020 4:59 PM, 1033840 bytes, A
       Adds the file log4net.dll"="3/8/2017 7:26 PM, 276480 bytes, A
       Adds the file Microsoft.Expression.Interactions.dll"="6/1/2015 3:31 PM, 108168 bytes, A
       Adds the file Newtonsoft.Json.dll"="11/9/2019 12:56 AM, 700336 bytes, A
       Adds the file opensource.txt"="12/9/2019 6:41 PM, 10601 bytes, A
       Adds the file RegistryCleaner.dll"="9/1/2020 4:59 PM, 77424 bytes, A
       Adds the file ReminderSystem.exe"="9/1/2020 4:59 PM, 911984 bytes, A
       Adds the file scmn.dll"="9/1/2020 4:59 PM, 626288 bytes, A
       Adds the file SearchHelper.dll"="9/1/2020 4:59 PM, 196720 bytes, A
       Adds the file SecureEraseDropAgent.exe"="9/1/2020 4:59 PM, 930928 bytes, A
       Adds the file service.txt"="9/10/2020 8:56 AM, 4866 bytes, A
       Adds the file SharpRaven.dll"="12/11/2019 7:14 PM, 80896 bytes, A
       Adds the file sinf.dll"="9/1/2020 4:59 PM, 133232 bytes, A
       Adds the file sma.dll"="9/1/2020 4:59 PM, 61040 bytes, A
       Adds the file smau.dll"="9/1/2020 4:59 PM, 77936 bytes, A
       Adds the file smdm.dll"="9/1/2020 4:59 PM, 66672 bytes, A
       Adds the file smlg.dll"="9/1/2020 4:59 PM, 52336 bytes, A
       Adds the file smln.dll"="9/1/2020 4:59 PM, 1575536 bytes, A
       Adds the file smmc.dll"="9/1/2020 4:59 PM, 214640 bytes, A
       Adds the file smu.dll"="9/1/2020 4:59 PM, 177264 bytes, A
       Adds the file SQLite.Interop.dll"="10/27/2019 6:41 AM, 1631744 bytes, A
       Adds the file System.Data.SQLite.dll"="10/27/2019 6:40 AM, 355328 bytes, A
       Adds the file System.Management.Automation.dll"="3/19/2019 6:45 AM, 3010560 bytes, A
       Adds the file System.Runtime.CompilerServices.Unsafe.dll"="11/15/2019 8:37 AM, 16968 bytes, A
       Adds the file System.Windows.Interactivity.dll"="6/1/2015 3:31 PM, 55904 bytes, A
       Adds the file ToggleSwitch.dll"="9/8/2015 4:32 PM, 44032 bytes, A
       Adds the file UIAComWrapper.dll"="12/29/2015 6:34 AM, 185856 bytes, A
       Adds the file unins000.msg"="9/10/2020 8:53 AM, 22845 bytes, A
       Adds the file unins001.dat"="9/10/2020 8:56 AM, 153344 bytes, A
       Adds the file unins001.exe"="9/10/2020 8:56 AM, 2907920 bytes, A
       Adds the file unins001.msg"="9/10/2020 8:56 AM, 22845 bytes, A
       Adds the file Unity.Abstractions.dll"="1/6/2020 1:20 AM, 65024 bytes, A
       Adds the file Unity.Container.dll"="1/6/2020 1:20 AM, 146944 bytes, A
    Adds the folder C:\Program Files\CleanMyPC\Locale
    Adds the folder C:\Program Files\CleanMyPC\Logs
       Adds the file log1.log"="9/10/2020 8:57 AM, 1385 bytes, A
    Adds the folder C:\Program Files\CleanMyPC\Sounds
       Adds the file cleancomplete.wav"="12/9/2019 6:41 PM, 455328 bytes, A
       Adds the file cmpc_2ndswipe.mp3"="12/9/2019 6:41 PM, 46008 bytes, A
       Adds the file cmpc_clickhere.mp3"="12/9/2019 6:41 PM, 134825 bytes, A
       Adds the file cmpc_logo.mp3"="12/9/2019 6:41 PM, 294690 bytes, A
       Adds the file searchcomplete.wav"="12/9/2019 6:41 PM, 455328 bytes, A
    Adds the folder C:\Program Files\Common Files\MacPaw
       Adds the file exception.dat"="9/10/2020 8:55 AM, 1854 bytes, A
    Adds the folder C:\ProgramData\MacPaw Inc\CleanMyPC\Data
       Adds the file cid.dat"="9/10/2020 8:54 AM, 41 bytes, A
       Adds the file wl.dat"="9/10/2020 8:55 AM, 2265088 bytes, A
    Adds the folder C:\ProgramData\MacPaw Inc\CleanMyPC\DM
       Adds the file 0937873f-f37b-d8cf-873d-c1b70679d5f0"="9/10/2020 8:56 AM, 496 bytes, A
       Adds the file SID.info"="9/10/2020 8:53 AM, 100 bytes, A
    Adds the folder C:\ProgramData\MacPaw Inc\CleanMyPC\Logs
       Adds the file logCMPC_09_10_2020_065345.log"="9/10/2020 8:56 AM, 1449 bytes, A
    Adds the folder C:\ProgramData\MacPaw Inc\CleanMyPC\Settings
       Adds the file Reminders.dat"="9/10/2020 8:53 AM, 536 bytes, A
       Adds the file Settings.dat"="9/10/2020 8:57 AM, 3264 bytes, A
       Adds the file UnistallList.dat"="9/10/2020 8:56 AM, 13628 bytes, A
       Adds the file UserLists.dat"="9/10/2020 8:56 AM, 320 bytes, A
    Adds the folder C:\ProgramData\MacPaw Inc\CleanMyPC\Settings\Backup
       Adds the file base.dat.0.bak"="9/10/2020 8:56 AM, 340128 bytes, A
       Adds the file Reminders.dat.0.bak"="9/10/2020 8:53 AM, 536 bytes, A
       Adds the file Settings.dat.0.bak"="9/10/2020 8:57 AM, 3264 bytes, A
       Adds the file UserLists.dat.0.bak"="9/10/2020 8:56 AM, 320 bytes, A
    Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CleanMyPC
       Adds the file CleanMyPC Customer Support.lnk"="9/10/2020 8:56 AM, 1192 bytes, A
       Adds the file CleanMyPC.lnk"="9/10/2020 8:56 AM, 842 bytes, A
       Adds the file Remove apps with CleanMyPC.lnk"="9/10/2020 8:56 AM, 868 bytes, A
       Adds the file Uninstall CleanMyPC.lnk"="9/10/2020 8:56 AM, 1715 bytes, A
    In the existing folder C:\Users\{username}\Desktop
       Adds the file CleanMyPC .exe"="9/10/2020 8:48 AM, 28945560 bytes, A
    In the existing folder C:\Users\Public\Desktop
       Adds the file CleanMyPC.lnk"="9/10/2020 8:56 AM, 824 bytes, A
    In the existing folder C:\Windows\System32\Tasks
       Adds the file CMPCUAC"="9/10/2020 8:56 AM, 2938 bytes, A

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\CMPCContextMenu]
       "(Default)"="REG_SZ", "{1650dc30-2343-498a-b49a-37b90918f611}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1650DC30-2343-498A-B49A-37B90918F611}]
       "(Default)"="REG_SZ", "CMPCShell.CMPCContextMenu"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1650DC30-2343-498A-B49A-37B90918F611}\Implemented Categories\{62C8FE65-4EBB-45e7-B440-6E39B2CDBF29}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1650DC30-2343-498A-B49A-37B90918F611}\InprocServer32]
       "(Default)"="REG_SZ", "mscoree.dll"
       "Assembly"="REG_SZ", "CleanMyPCShell, Version=1.10.7.2050, Culture=neutral, PublicKeyToken=24a230d4163302c0"
       "Class"="REG_SZ", "CMPCShell.CMPCContextMenu"
       "CodeBase"="REG_SZ", "file:///C:/Program Files/CleanMyPC/CleanMyPCShell.DLL"
       "RuntimeVersion"="REG_SZ", "v4.0.30319"
       "ThreadingModel"="REG_SZ", "Both"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1650DC30-2343-498A-B49A-37B90918F611}\InprocServer32\1.10.7.2050]
       "Assembly"="REG_SZ", "CleanMyPCShell, Version=1.10.7.2050, Culture=neutral, PublicKeyToken=24a230d4163302c0"
       "Class"="REG_SZ", "CMPCShell.CMPCContextMenu"
       "CodeBase"="REG_SZ", "file:///C:/Program Files/CleanMyPC/CleanMyPCShell.DLL"
       "RuntimeVersion"="REG_SZ", "v4.0.30319"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1650DC30-2343-498A-B49A-37B90918F611}\ProgId]
       "(Default)"="REG_SZ", "CMPCShell.CMPCContextMenu"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shell\Securely empty Recycle Bin with CleanMyPC]
       "CommandStateHandler"="REG_SZ", "{c9298eef-69dd-4cdd-b153-bdbc38486781}"
       "Icon"="REG_SZ", ""C:\Program Files\CleanMyPC\CleanMyPCShell.dll",-101"
       "useFor"="REG_SZ", "CleanMyPC"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shell\Securely empty Recycle Bin with CleanMyPC\command]
       "(Default)"="REG_SZ", "C:\Program Files\CleanMyPC\CleanMyPC.exe /SecureTrash"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\cmpc]
       "(Default)"="REG_SZ", "URL:CleanMyPC Protocol"
       "URL Protocol"="REG_SZ", ""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\cmpc\shell\open\command]
       "(Default)"="REG_SZ", ""C:\Program Files\CleanMyPC\CleanMyPC.exe" "%1""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CMPCShell.CMPCContextMenu]
       "(Default)"="REG_SZ", "CMPCShell.CMPCContextMenu"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CMPCShell.CMPCContextMenu\CLSID]
       "(Default)"="REG_SZ", "{1650DC30-2343-498A-B49A-37B90918F611}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\CMPCContextMenu]
       "(Default)"="REG_SZ", "{1650dc30-2343-498a-b49a-37b90918f611}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\CMPCContextMenu]
       "(Default)"="REG_SZ", "{1650dc30-2343-498a-b49a-37b90918f611}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\CleanMyPC]
       "AllowAnonymousReport"="REG_DWORD", 1
       "alp"="REG_DWORD", 1
       "CU"="REG_SZ", "Complete Uninstall by CleanMyPC"
       "frsc"="REG_DWORD", 0
       "fsc"="REG_DWORD", 0
       "InstallDate"="REG_SZ", "2020-09-10T08:53:46"
       "InstallKey"="REG_SZ", "F9F0042B-AD55-457A-B803-C98D0E223BC2"
       "IsFirst"="REG_DWORD", 0
       "lang"="REG_SZ", "english"
       "QE"="REG_SZ", "Secure Erase by CleanMyPC"
       "tccn"="REG_SZ", "True"
       "trc"="REG_SZ", "False"
       "ttsas"="REG_SZ", "1599721005"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90385FF3-6721-4DCD-AD11-FEBA397F4FE9}_is1]
       "DisplayIcon"="REG_SZ", "C:\Program Files\CleanMyPC\cmp-uninstall.ico"
       "DisplayName"="REG_SZ", "CleanMyPC version 1.10.7.2050"
       "DisplayVersion"="REG_SZ", "1.10.7.2050"
       "EstimatedSize"="REG_DWORD", 49269
       "Inno Setup: App Path"="REG_SZ", "C:\Program Files\CleanMyPC"
       "Inno Setup: Icon Group"="REG_SZ", "CleanMyPC"
       "Inno Setup: Language"="REG_SZ", "english"
       "Inno Setup: Setup Version"="REG_SZ", "6.0.3 (u)"
       "Inno Setup: User"="REG_SZ", "{username}"
       "InstallDate"="REG_SZ", "20200910"
       "InstallLocation"="REG_SZ", "C:\Program Files\CleanMyPC\"
       "MajorVersion"="REG_DWORD", 1
       "MinorVersion"="REG_DWORD", 10
       "NoModify"="REG_DWORD", 1
       "NoRepair"="REG_DWORD", 1
       "Publisher"="REG_SZ", "MacPaw, Inc."
       "QuietUninstallString"="REG_SZ", ""C:\Program Files\CleanMyPC\unins001.exe" /SILENT"
       "UninstallString"="REG_SZ", ""C:\Program Files\CleanMyPC\unins001.exe" /SILENT /CUSTOMUNINSTALLPROMPT"
       "URLInfoAbout"="REG_SZ", "http://www.macpaw.com"
       "VersionMajor"="REG_DWORD", 1
       "VersionMinor"="REG_DWORD", 10
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\CleanMyPCService]
       "DelayedAutostart"="REG_DWORD", 1
       "Description"="REG_SZ", "Monitoring junk on removable devices connected to your PC"
       "DisplayName"="REG_SZ", "CleanMyPC Watcher"
       "ErrorControl"="REG_DWORD", 1
       "ImagePath"="REG_EXPAND_SZ, "C:\Program Files\CleanMyPC\CleanMyPCService.exe"
       "ObjectName"="REG_SZ", "LocalSystem"
       "Start"="REG_DWORD", 2
       "Type"="REG_DWORD", 16
       "WOW64"="REG_DWORD", 1
    [HKEY_USERS\.DEFAULT\Software\CleanMyPC]
       "SID"="REG_BINARY, ..................................................
    [HKEY_USERS\.DEFAULT\Software\CleanMyPC\DM]
       "5b8274ce-015a-9bc9-06af-231de0bd667d"="REG_BINARY, ..............................................
    [HKEY_CURRENT_USER\Software\CleanMyPC]
       "SID"="REG_BINARY, ..................................................
       "tfValue"="REG_DWORD", 2
    [HKEY_CURRENT_USER\Software\CleanMyPC\DM]
       "22f6f1df-a49c-ca34-2ee1-b5abbbfcba87"="REG_BINARY, ...............................................
       "3e27fdc9-bfc0-b679-1261-14e7ecf657b8"="REG_BINARY, ...............................................
       "4bc85ca7-f0e0-6113-1960-57aed648084d"="REG_BINARY, ...............................................
       "54b4f7be-bd6d-121a-e154-6e1240fcdd76"="REG_BINARY, ...............................................
       "5b8274ce-015a-9bc9-06af-231de0bd667d"="REG_BINARY, ................................................
       "9dd1c440-689a-2c6b-b189-0c91b27bfd2e"="REG_BINARY, ................................................
       "a04cf0a4-a168-e5a6-c798-237a57bdb436"="REG_BINARY, ..............................................
       "da8eb2d0-94e8-71ca-5c26-63956c1f7165"="REG_BINARY, ..............................................
       "de5b6743-ee4f-295e-1ca5-a3711d99fd45"="REG_BINARY, ...............................................
       "feedbackForm"="REG_BINARY, ............................................

Malwarebytes log:
 

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 9/10/20
Scan Time: 9:08 AM
Log File: 75c9c5f0-f334-11ea-a8c3-00ffdcc6fdfc.json

-Software Information-
Version: 4.2.0.82
Components Version: 1.0.1036
Update Package Version: 1.0.29633
License: Premium

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {computername}\{username}

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 231467
Threats Detected: 29
Threats Quarantined: 27
Time Elapsed: 7 min, 15 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 1
PUP.Optional.CleanMyPC, C:\PROGRAM FILES\CLEANMYPC\CLEANMYPCSERVICE.EXE, Quarantined, 3294, 855199, , , , , 3B2600C431EE1A18F58399E4B81F217F, C1C8612F435C28124AADA9A441F8B8FDD91617E6C9609E469A4DD23160B79694

Module: 2
PUP.Optional.CleanMyPC, C:\PROGRAM FILES\CLEANMYPC\CLEANMYPCSERVICE.EXE, Quarantined, 3294, 855199, , , , , 3B2600C431EE1A18F58399E4B81F217F, C1C8612F435C28124AADA9A441F8B8FDD91617E6C9609E469A4DD23160B79694
PUP.Optional.CleanMyPC, C:\PROGRAM FILES\CLEANMYPC\SQLITE.INTEROP.DLL, Quarantined, 3294, 855194, , , , , E9E0EC1803156A133259F286DE2CFE59, 6231D0F17272B67842616F797416DD6C4C764F6C5F19132A688DB9D4D212B019

Registry Key: 14
PUP.Optional.CleanMyPC, HKLM\SOFTWARE\CLASSES\CMPCShell.CMPCContextMenu, Quarantined, 3294, 856997, , , , , , 
PUP.Optional.CleanMyPC, HKLM\SOFTWARE\CLASSES\CLSID\{1650DC30-2343-498A-B49A-37B90918F611}, Quarantined, 3294, 856997, 1.0.29633, , ame, , , 
PUP.Optional.CleanMyPC, HKCU\SOFTWARE\CleanMyPC, Quarantined, 3294, 423646, 1.0.29633, , ame, , , 
PUP.Optional.CleanMyPC, HKU\S-1-5-18\SOFTWARE\CleanMyPC, Quarantined, 3294, 423646, 1.0.29633, , ame, , , 
PUP.Optional.CleanMyPC, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{90385FF3-6721-4DCD-AD11-FEBA397F4FE9}_is1, Quarantined, 3294, 424038, 1.0.29633, , ame, , , 
PUP.Optional.CleanMyPC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CleanMyPCService, Quarantined, 3294, 855199, 1.0.29633, , ame, , , 
PUP.Optional.CleanMyPC, HKLM\SOFTWARE\MICROSOFT\TRACING\CleanMyPCService_RASAPI32, Quarantined, 3294, 424037, 1.0.29633, , ame, , , 
PUP.Optional.CleanMyPC, HKLM\SOFTWARE\MICROSOFT\TRACING\CleanMyPCService_RASMANCS, Quarantined, 3294, 424037, 1.0.29633, , ame, , , 
PUP.Optional.CleanMyPC, HKLM\SOFTWARE\MICROSOFT\TRACING\CleanMyPC_RASAPI32, Quarantined, 3294, 424037, 1.0.29633, , ame, , , 
PUP.Optional.CleanMyPC, HKLM\SOFTWARE\MICROSOFT\TRACING\CleanMyPC_RASMANCS, Quarantined, 3294, 424037, 1.0.29633, , ame, , , 
PUP.Optional.CleanMyPC, HKLM\SOFTWARE\CleanMyPC, Quarantined, 3294, 423644, 1.0.29633, , ame, , , 
PUP.Optional.CleanMyPC, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\CMPCUAC, Quarantined, 3294, 855198, , , , , , 
PUP.Optional.CleanMyPC, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{97A5411A-67C5-4185-AC8F-DCB8098AD05C}, Quarantined, 3294, 855198, , , , , , 
PUP.Optional.CleanMyPC, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{97A5411A-67C5-4185-AC8F-DCB8098AD05C}, Quarantined, 3294, 855198, , , , , , 

Registry Value: 1
PUP.Optional.CleanMyPC, HKLM\SOFTWARE\CLASSES\CLSID\{1650DC30-2343-498A-B49A-37B90918F611}|, Quarantined, 3294, 856997, 1.0.29633, , ame, , , 

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 3
PUP.Optional.CleanMyPC, C:\PROGRAM FILES\CLEANMYPC, Removal Failed, 3294, 855194, 1.0.29633, , ame, , , 
PUP.Optional.CleanMyPC, C:\PROGRAMDATA\MACPAW INC\CLEANMYPC, Removal Failed, 3294, 855195, 1.0.29633, , ame, , , 
PUP.Optional.CleanMyPC, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CLEANMYPC, Quarantined, 3294, 855196, 1.0.29633, , ame, , , 

File: 8
PUP.Optional.CleanMyPC, C:\USERS\PUBLIC\DESKTOP\CLEANMYPC.LNK, Quarantined, 3294, 424036, 1.0.29633, , ame, , 7577237DB45B5F9494D01282A198F350, 197981D7ABECC13AC1FB5B3BA8FB613F172B4B01BD7AA9A34E9B750D8149E516
PUP.Optional.CleanMyPC, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CleanMyPC\CleanMyPC Customer Support.lnk, Quarantined, 3294, 855196, , , , , E3145775CEFED41388FF8A98939CB03D, D8F7284C0C31EEE1068BB75FB7BA34164F736DE8130AC6E18AE0BB107C187C23
PUP.Optional.CleanMyPC, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CleanMyPC\CleanMyPC.lnk, Quarantined, 3294, 855196, , , , , 0B5FD053128A42181E6A4382E71534B4, 0BBAF6A031077EAAA8C272952F98576474C520F995EB2DC7B3CD4D684A0BFC27
PUP.Optional.CleanMyPC, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CleanMyPC\Remove apps with CleanMyPC.lnk, Quarantined, 3294, 855196, , , , , 38DEC6D5CBA7124B0830AC2C6167A504, 2D15115602747BA7464BC9C1800F2D78D3C1F64454999DD1EE38366CD5F602FC
PUP.Optional.CleanMyPC, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CleanMyPC\Uninstall CleanMyPC.lnk, Quarantined, 3294, 855196, , , , , 7050B74B41B9EB0A3B92F7C472FCCBA8, 4E61BFEC52A7EBD8BB6C3A6FCB8D142293FB51DE4DB82D6E1A1AE607E392B417
PUP.Optional.CleanMyPC, C:\PROGRAM FILES\CLEANMYPC\CLEANMYPCSERVICE.EXE, Quarantined, 3294, 855199, , , , , 3B2600C431EE1A18F58399E4B81F217F, C1C8612F435C28124AADA9A441F8B8FDD91617E6C9609E469A4DD23160B79694
PUP.Optional.CleanMyPC, C:\PROGRAM FILES\CLEANMYPC\SQLITE.INTEROP.DLL, Quarantined, 3294, 855194, 1.0.29633, , ame, , E9E0EC1803156A133259F286DE2CFE59, 6231D0F17272B67842616F797416DD6C4C764F6C5F19132A688DB9D4D212B019
PUP.Optional.CleanMyPC, C:\WINDOWS\SYSTEM32\TASKS\CMPCUAC, Quarantined, 3294, 855198, 1.0.29633, , ame, , 9B10D37184B5C93DA45FD5F559FBC1C9, 20F79DF86B3B273EEB4267461A92D8D2F5E63FB8A7C37EA439A28F74619086D8

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

As mentioned before the full version of Malwarebytes could have protected your computer against this threat.
We use different ways of protecting your computer(s):

  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention

Save yourself the hassle and get protected.

Link to post
Share on other sites
  • Recently Browsing   0 members

    No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.