Page 1 of 1

Duplicate File Cleaner Pro (v3) Flagged as Malware

Posted: Mon Oct 30, 2017 6:45 pm
by hammonj7
Wanted to share in case this was a false positive.

Here is what Microsoft Forefront Endpoint is showing:

PUA:Win32/CandyOpen

Alert Level: Severe

Category: Potentially Unwanted Software

Description: This program has potentially unwanted behavior.

Recommended action: Remove this software immediately.

Items:
file:C:\Program Files (x86)\Duplicate Cleaner Pro\DuplicateCleaner.exe
file:C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Pro\Duplicate Cleaner Pro.lnk
file:C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Pro\Duplicate Cleaner Pro.lnk
regkey:HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Duplicate Cleaner Pro
startup:C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Pro\Duplicate Cleaner Pro.lnk
startup:C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Pro\Duplicate Cleaner Pro.lnk
uninstall:HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Duplicate Cleaner Pro

I held on to the version 3 installer, but Forefront removed it when it was flagged.

Re: Duplicate File Cleaner Pro (v3) Flagged as Malware

Posted: Mon Oct 30, 2017 9:43 pm
by DigitalVolcano
It's probably a false positive - this happens sometimes. I've double checked on VirusTotal (Duplicate Cleaner Pro 3.2.7) with the major AV engines and it seems OK.

Be sure to update your virus definitions and software.

Re: Duplicate File Cleaner Pro (v3) Flagged as Malware

Posted: Tue Oct 31, 2017 3:30 pm
by therube
SHA1 hash of what I have on hand.

Duplicate Cleaner Pro 3.27
782651a89c1e3def26e5d0b781be307fba705010