Home Possibly Unwanted Program PUP.Mr PC Cleaner

PUP.Mr PC Cleaner

Posted: January 23, 2014

Threat Metric

Ranking: 4,027
Threat Level: 1/10
Infected PCs: 29,967
First Seen: January 23, 2014
Last Seen: October 17, 2023
OS(es) Affected: Windows


Mr. PC Cleaner is a system optimization utility whose marketing methodology bears a strong resemblance to the traditional tactics of rogue file cleaners. Mr. PC Cleaner's website sometimes is promoted through browser hijackers and adware products that modify your Web browser, seemingly in an effort to encourage you to purchase the Mr. PC Cleaner's software. Although malware experts currently identify Mr. PC Cleaner as a Potentially Unwanted Program, its classification easily could be moved to that of a threat once additional analyzes are completed. Until then, whenever you're provided system information from Mr. PC Cleaner or its site, you should act with all due caution, and remove Mr. PC Cleaner through traditional PC security strategies if Mr. PC Cleaner should be installed without your participation.

When Cleaning Your Computer is About Boasts More Than Hygiene

Although many invasive forms of fake system cleaners and security programs easily can be identified as misleading practices, the lines between unwanted and threatening software aren't always clear-cut. Mr. PC Cleaner is one case of a 'gray area' product that currently is considered a PUP, which is a result of its apparent lack of significant harmful features. However, this classification isn't an endorsement of Mr. PC Cleaner as a PC-cleaning product, and malware researchers recommend that you don't take Mr. PC Cleaner's advice, alone, for determining any system optimization issues that you might have.

While Mr. PC Cleaner's marketing points aren't entirely truthful, malware researchers haven't found Mr. PC Cleaner guilty of causing major security issues or attacks against PCs that have Mr. PC Cleaner installed. For now, Mr. PC Cleaner is categorized as a PUP, similar to adware or unwanted browser plugins, and its presence may be considered undesirable without being a security hazard that's equivalent to that of an infection by a backdoor Trojan, worm or rootkit.

The PC-Cleaning Man's Secretly Dirty Past

Even if you're willing to overlook the exaggerations and questionable features of Mr. PC Cleaner, you may want to look askance at some of the promotional efforts that separate PC threats have used to encourage Mr. PC Cleaner's purchase. Past attacks confirmed by malware experts have involved the installation of unrelated browser hijackers, adware and other Web browser-based PUPs that provide redirects to Mr. PC Cleaner's website. These redirects also may block access to legitimate PC security websites, which makes them likely sources of various security problems.

Browsers being redirected to the Mr. PC Cleaner website or the unwanted installation of the actual Mr. PC Cleaner-related software should be dealt with via anti-malware tools that are designed to uninstall all types of unasked for computer products. DingoDeals and SearchDeals by Injekt are two types of adware that often are noted being installed with browser hijackers for Mr. PC Cleaner, although other PC threats also may be identified. So far, only Chrome has been confirmed to be affected by this issue, although the recent identification of this campaign (as of late 2013) makes it entirely probable that other browsers also could be modified.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\My Documents\Downloads\CLEANPC365_1.12.0Full.exe File name: CLEANPC365_1.12.0Full.exe
Size: 22.72 MB (22721768 bytes)
MD5: a450a96eb019e2aeb409ae3144bbc9d2
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\My Documents\Downloads
Group: Malware file
Last Updated: September 29, 2023

Registry Modifications

The following newly produced Registry Values are:

File name without pathCLEANPC365.lnkHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\Applications\cleanpc365Tray.exeSOFTWARE\Classes\Installer\Features\25D6927ADE625F24591CDD95E56D3619SOFTWARE\Classes\Installer\Products\25D6927ADE625F24591CDD95E56D3619SOFTWARE\Classes\Installer\UpgradeCodes\EAD39CDD5C107C34E85684B2D0B6ACEF\25D6927ADE625F24591CDD95E56D3619Software\cleanpc365SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\CLEANPC365.exeSOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\EAD39CDD5C107C34E85684B2D0B6ACEF\25D6927ADE625F24591CDD95E56D3619SOFTWARE\Microsoft\Windows\CurrentVersion\Run\CommonToolkitTray_cleanpc365SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CLEANPC365SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A7296D52-26ED-42F5-95C1-DD595ED66391}SOFTWARE\Wow6432Node\cleanpc365SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\CLEANPC365.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FileAssociation\NoStartPageAppUserModelIDs\Fighters.SLOW-PCfighter.EULASOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FileAssociation\NoStartPageAppUserModelIDs\Fighters.SLOW-PCfighter.LogCollectorSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FileAssociation\NoStartPageAppUserModelIDs\Fighters.SLOW-PCfighter.LogsSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\CommonToolkitTray_cleanpc365

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\cleanpc365%ALLUSERSPROFILE%\cleanpc365%APPDATA%\cleanpc365%PROGRAMFILES%\cleanpc365%PROGRAMFILES(X86)%\cleanpc365
Loading...