Duplicate File Cleaner Pro (v3) Flagged as Malware
Posted: Mon Oct 30, 2017 6:45 pm
Wanted to share in case this was a false positive.
Here is what Microsoft Forefront Endpoint is showing:
PUA:Win32/CandyOpen
Alert Level: Severe
Category: Potentially Unwanted Software
Description: This program has potentially unwanted behavior.
Recommended action: Remove this software immediately.
Items:
file:C:\Program Files (x86)\Duplicate Cleaner Pro\DuplicateCleaner.exe
file:C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Pro\Duplicate Cleaner Pro.lnk
file:C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Pro\Duplicate Cleaner Pro.lnk
regkey:HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Duplicate Cleaner Pro
startup:C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Pro\Duplicate Cleaner Pro.lnk
startup:C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Pro\Duplicate Cleaner Pro.lnk
uninstall:HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Duplicate Cleaner Pro
I held on to the version 3 installer, but Forefront removed it when it was flagged.
Here is what Microsoft Forefront Endpoint is showing:
PUA:Win32/CandyOpen
Alert Level: Severe
Category: Potentially Unwanted Software
Description: This program has potentially unwanted behavior.
Recommended action: Remove this software immediately.
Items:
file:C:\Program Files (x86)\Duplicate Cleaner Pro\DuplicateCleaner.exe
file:C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Pro\Duplicate Cleaner Pro.lnk
file:C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Pro\Duplicate Cleaner Pro.lnk
regkey:HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Duplicate Cleaner Pro
startup:C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Pro\Duplicate Cleaner Pro.lnk
startup:C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Pro\Duplicate Cleaner Pro.lnk
uninstall:HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Duplicate Cleaner Pro
I held on to the version 3 installer, but Forefront removed it when it was flagged.