Home Possibly Unwanted Program UPCleaner

UPCleaner

Posted: July 13, 2015

Threat Metric

Ranking: 6,814
Threat Level: 1/10
Infected PCs: 66,933
First Seen: July 13, 2015
Last Seen: October 11, 2023
OS(es) Affected: Windows


UPCleaner by Brotsoft Technology is a fake system optimization utility that the experts suggest you avoid. UPCleaner is classified as a Potentially Unwanted Program (PUP) for two reasons. First, UPCleaner may not be able to improve the performance of your system. Second, UPCleaner may fill your Web clients with many suspicious commercial materials, which may cause an array of problems. The developer of UPCleaner may rely on the misleading bundling method for its distribution. You may install the PUP when you load freeware bundles unwittingly. You should never trust questionable platforms like the torrent trackers to prevent giving access to such dubious applications. You should invest some time, and conduct the setup process via the 'Advanced' menu. It may let you uncheck unwanted components of the bundle manually. Soon after its installation, UPCleaner may start showing you fabricated scan results. You will certainly notice frightening notifications about the security state of your PC. According to this PUP, your system may be in a terrible condition due to hundreds of Registry errors and junk files. You should not let this information disturb you because it is a lie. The purpose of this tactic is to make you click on the 'Fix Now' button. The official product page of UPCleaner claims that it is freeware, but this statement also doesn't correspond to the truth. Only the trial version is free of charge. If you attempt to fix the issues, which may not even exist in reality, you will be transferred to an online purchase page. You should not buy the full version of UPCleaner as it may be equally unreliable. During its presence in your system, this PUP also may generate intrusive pop-ups, banners, interstitial ads and other commercial materials. Some of them may try to manipulate you into downloading additional dubious applications. You should delete UPCleaner with a dedicated security solution to fix your Web clients and stop the bogus scan processes.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\UPCleaner\1.6.3.17195\UGSvc.exe File name: UGSvc.exe
Size: 675.91 KB (675912 bytes)
MD5: ad0828e89ecef14d2e225b8381c03cf9
Detection count: 1,223
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\UPCleaner\1.6.3.17195\UGSvc.exe
Group: Malware file
Last Updated: July 22, 2022
%PROGRAMFILES(x86)%\UPCleaner\1.6.3.17195\UG.exe File name: UG.exe
Size: 490.48 KB (490488 bytes)
MD5: 2106a5603e8f984337c84c9ae63ac5e1
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\UPCleaner\1.6.3.17195
Group: Malware file
Last Updated: November 12, 2021
F:\MASA ÜSTÜ ÇALIŞMALAR\masa üstü çalışmalar son 1\KISA YOLLAR\UPCleanerInst.exe File name: UPCleanerInst.exe
Size: 1.29 MB (1293824 bytes)
MD5: a341144b88ed0246c0817d0ee928ce49
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Path: F:\MASA ÜSTÜ ÇALIŞMALAR\masa üstü çalışmalar son 1\KISA YOLLAR\UPCleanerInst.exe
Group: Malware file
Last Updated: May 1, 2023
%PROGRAMFILES(x86)%\UPCleaner\1.4.62.15819\UGSvc.exe File name: UGSvc.exe
Size: 675.25 KB (675256 bytes)
MD5: 9485ced8c3bf694fa9cdef1119a0f864
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\UPCleaner\1.4.62.15819
Group: Malware file
Last Updated: March 23, 2016
%PROGRAMFILES(x86)%\UPCleaner\1.5.27.16073\UGSvc.exe File name: UGSvc.exe
Size: 675.91 KB (675912 bytes)
MD5: e339da31b4b62b081fcf6d46ec97fb2b
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\UPCleaner\1.5.27.16073
Group: Malware file
Last Updated: March 23, 2016
%PROGRAMFILES%\UPCleaner\1.6.3.17195\UGCClean.exe File name: UGCClean.exe
Size: 81.6 KB (81608 bytes)
MD5: b06cd6a3b07644e2c34e6eaef8aec843
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\UPCleaner\1.6.3.17195
Group: Malware file
Last Updated: November 12, 2021
%PROGRAMFILES%\UPCleaner\1.6.3.17195\UPKernel.sys File name: UPKernel.sys
Size: 39.28 KB (39288 bytes)
MD5: 76e362587ea0e8f48e88ec7ecec8b944
Detection count: 66
File type: System file
Mime Type: unknown/sys
Path: %PROGRAMFILES%\UPCleaner\1.6.3.17195
Group: Malware file
Last Updated: April 2, 2016
%PROGRAMFILES%\UPCleaner\1.6.3.17195\UGProtect.sys File name: UGProtect.sys
Size: 45.56 KB (45560 bytes)
MD5: 71939153b565b662fd0c288b15c7f764
Detection count: 64
File type: System file
Mime Type: unknown/sys
Path: %PROGRAMFILES%\UPCleaner\1.6.3.17195
Group: Malware file
Last Updated: April 2, 2016
%PROGRAMFILES%\UPCleaner\1.6.3.17195\UGKrnlDrv.sys File name: UGKrnlDrv.sys
Size: 77.81 KB (77816 bytes)
MD5: 11ab58f20823a0fe265ea5ea87f1a941
Detection count: 63
File type: System file
Mime Type: unknown/sys
Path: %PROGRAMFILES%\UPCleaner\1.6.3.17195
Group: Malware file
Last Updated: April 2, 2016
%PROGRAMFILES%\UPCleaner\1.6.3.17195\UGBroMon.sys File name: UGBroMon.sys
Size: 48.88 KB (48888 bytes)
MD5: f7603e7465a01509a73c7d2dba06effd
Detection count: 62
File type: System file
Mime Type: unknown/sys
Path: %PROGRAMFILES%\UPCleaner\1.6.3.17195
Group: Malware file
Last Updated: April 2, 2016
%PROGRAMFILES%\UPCleaner\1.6.3.17195\npf.sys File name: npf.sys
Size: 36.6 KB (36600 bytes)
MD5: 774009e61026d81f5e17b8af6586902a
Detection count: 61
File type: System file
Mime Type: unknown/sys
Path: %PROGRAMFILES%\UPCleaner\1.6.3.17195
Group: Malware file
Last Updated: April 2, 2016
C:\Program Files (x86)\upcleaner\1.6.3.17195\UGunInstall.exe File name: UGunInstall.exe
Size: 1.25 MB (1258432 bytes)
MD5: 0dc39520d650949ca8b21bfe32c8698c
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\upcleaner\1.6.3.17195\UGunInstall.exe
Group: Malware file
Last Updated: November 12, 2021
%PROGRAMFILES(x86)%\UPCleaner\1.6.3.17195\UGSoftMgr.exe File name: UGSoftMgr.exe
Size: 823.48 KB (823480 bytes)
MD5: d652287a4282ac11f6bf9e096b321aee
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\UPCleaner\1.6.3.17195
Group: Malware file
Last Updated: November 12, 2021
%PROGRAMFILES(x86)%\UPCleaner\1.5.36.16098\UGTray.exe File name: UGTray.exe
Size: 1.01 MB (1017728 bytes)
MD5: 035d022e2db0c5dbceafef7975a6ce91
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\UPCleaner\1.5.36.16098
Group: Malware file
Last Updated: September 17, 2020
%PROGRAMFILES(x86)%\UPCleaner\1.5.36.16098\UGExperience.exe File name: UGExperience.exe
Size: 194.9 KB (194904 bytes)
MD5: 245d25c813ca1cf44ba0ce76b039950c
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\UPCleaner\1.5.36.16098
Group: Malware file
Last Updated: September 17, 2020
%PROGRAMFILES(x86)%\UPCleaner\1.5.36.16098\UG.exe File name: UG.exe
Size: 490.48 KB (490488 bytes)
MD5: 00296a16be145087950eecd073737247
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\UPCleaner\1.5.36.16098
Group: Malware file
Last Updated: September 17, 2020
%PROGRAMFILES(x86)%\UPCleaner\1.4.62.15819\UGTray.exe File name: UGTray.exe
Size: 991.62 KB (991624 bytes)
MD5: 1c4422a444bd2884d1e03d5256da66a7
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\UPCleaner\1.4.62.15819
Group: Malware file
Last Updated: April 2, 2016
%PROGRAMFILES(x86)%\UPCleaner\1.4.63.15825\UGSvc.exe File name: UGSvc.exe
Size: 675.25 KB (675256 bytes)
MD5: d6ac80f735e75deff17a535114c30eb5
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\UPCleaner\1.4.63.15825
Group: Malware file
Last Updated: March 23, 2016
%TEMP%\ultimate_pc_cleaner.exe File name: ultimate_pc_cleaner.exe
Size: 27.33 MB (27339672 bytes)
MD5: 07c813bc5cc3ccd95517e7518ff70347
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: August 15, 2020
%PROGRAMFILES(x86)%\UPCleaner\1.5.32.16087\UGSvc.exe File name: UGSvc.exe
Size: 675.91 KB (675912 bytes)
MD5: 3b8dca970bb56727aeb5477557972801
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\UPCleaner\1.5.32.16087
Group: Malware file
Last Updated: March 23, 2016
%PROGRAMFILES(x86)%\UPCleaner\1.6.3.17195\UGSvc.exe File name: UGSvc.exe
Size: 675.91 KB (675912 bytes)
MD5: 1c7933a564576f20e8602090c10a5c4b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\UPCleaner\1.6.3.17195
Group: Malware file
Last Updated: April 2, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathUPCleaner.lnkRegexp file mask%APPDATA%\ultimate_pc_cleaner.exeHKEY..\..\..\..{RegistryKeys}Software\QGuan72564SOFTWARE\Wow6432Node\Microsoft\Tracing\BanUpdataT_RASAPI32SYSTEM\ControlSet001\Enum\Root\LEGACY_UGBROMONSYSTEM\ControlSet001\Enum\Root\LEGACY_UGKRNLDRVSYSTEM\ControlSet001\Enum\Root\LEGACY_UGPROTECTSYSTEM\ControlSet001\Services\UGKrnlDrvSYSTEM\ControlSet002\Enum\Root\LEGACY_UGBROMONSYSTEM\ControlSet002\Enum\Root\LEGACY_UGKRNLDRVSYSTEM\ControlSet002\Enum\Root\LEGACY_UGPROTECTSYSTEM\ControlSet002\Services\UGKrnlDrvSYSTEM\CurrentControlSet\Enum\Root\LEGACY_UGBROMONSYSTEM\CurrentControlSet\Enum\Root\LEGACY_UGKRNLDRVSYSTEM\CurrentControlSet\Enum\Root\LEGACY_UGPROTECTSYSTEM\CurrentControlSet\Services\UGKrnlDrvHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{FCB860B2-EA0A-45D7-BD1C-9D790AD36F12}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\UPCleaner%APPDATA%\UPUpdata%PROGRAMFILES%\UPCleaner%PROGRAMFILES(x86)%\UPCleaner%WINDIR%\SysWOW64\config\systemprofile\AppData\Roaming\UPUpdata
The following URL's were detected:
uportal.upcleaner.net
Loading...