Home Malware Programs Potentially Unwanted Programs (PUPs) DirAnalyze

DirAnalyze

Posted: July 12, 2017

Threat Metric

Threat Level: 1/10
Infected PCs: 211
First Seen: July 12, 2017
Last Seen: February 7, 2022
OS(es) Affected: Windows

DirAnalyze is a Potentially Unwanted Program (PUP) whose official website claims that its purpose is to help users free up disk space by removing duplicated files and informing them if any files take up too much disk space automatically. However, it is possible that DirAnalyze may display fraudulent and exaggerated results to convince users that they can free up a lot of disk space by simply paying for the full version of this application. The trial version of DirAnalyze can be installed for free, but it is only able to work as a scanner, which checks the computer and generates a report that consists of information about the large and duplicate files that can be removed.

It seems that the propagation of DirAnalyze happens with the help of software bundling – a method that is often used to spread Potentially Unwanted Programs and other low-quality software. Due to the tricks that software bundles may use, it is possible that some users might install DirAnalyze even though they did not intend to do this. Once this application is installed, it may be started automatically whenever Windows boots, and it may keep displaying reminders, which state that the user has to pay for the full license to complete the recommended optimization tasks.
There are many free PC optimization utilities more functional than DirAnalyze that will not use shady tricks to get users to send money to their publishers. If you have DirAnalyze on your computer, then our recommendation is to remove it as soon as possible, since this application has nothing of value to offer. Its removal can be completed manually, but our advice is to get rid of it by using a reputable anti-malware tool.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

File name without pathsdiskfinder.exeRegexp file mask%WINDIR%\System32\Tasks\DirAnalyzer%WINDIR%\System32\Tasks\SDisk FinderHKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DirAnalyzerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SDisk Finder

Additional Information

The following directories were created:
%PROGRAMFILES%\SDisk Finder%PROGRAMFILES(x86)%\SDisk Finder%PUBLIC%\DiskCleaner
Loading...