Related blog content
Malwarebytes gets tougher on PUPs
PUP.Optional.SpywareClear is Malwarebytes’ detection name for a system optimizer called Spyware Clear issued by the Crawler Group, LLC and aimed at Windows systems.
This is how the main screen of the system optimizer looks:
You will find these icons in your taskbar, your startmenu, and on your desktop:
and see this warning during install:
and these screens during “operations”:
You may see this entry in your list of installed programs:
and this Browser Helper Object in Internet Explorer:
PUP.Optional.SpywareClear is a so-called “system optimizer”. Typically, “system optimizers” use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems.
PUP.Optional.SpywareClear is usually installed by the users themselves as a result of advertising leading to their website:
Malwarebytes protects users from PUP.Optional.SpywareClear by using real-time protection;
and by blocking their domain:
Malwarebytes can detect and remove PUP.Optional.SpywareClear without further user interaction.
A Malwarebytes log of removal will look similar to this:
Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 6/21/18 Scan Time: 11:05 AM Log File: 4e97a376-7532-11e8-a189-080027235d76.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.374 Update Package Version: 1.0.5564 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 251056 Threats Detected: 158 Threats Quarantined: 158 Time Elapsed: 3 min, 59 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 4 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SC_Svc64.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SpywareClear.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SpywareClearShield.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SpywareClearUpdate.exe, Quarantined, [1456], [187214],1.0.5564 Module: 6 PUP.Optional.SpywareClear, C:\PROGRAM FILES (X86)\SPYWARE CLEAR\TORRENTDLL.DLL, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SCShell64.dll, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SC_Svc64.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SpywareClear.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SpywareClearShield.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SpywareClearUpdate.exe, Quarantined, [1456], [187214],1.0.5564 Registry Key: 45 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{B36D9EA9-ABCA-4F9F-B181-49929A7B73D1}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\SCInternetGuard.ProtNego, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\CLSID\{B36D9EA9-ABCA-4F9F-B181-49929A7B73D1}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{B36D9EA9-ABCA-4F9F-B181-49929A7B73D1}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{B36D9EA9-ABCA-4F9F-B181-49929A7B73D1}\InprocServer32, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{C03C262D-9260-4124-B50E-04FB49ED0504}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\SCInternetGuard.JSObj, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\CLSID\{C03C262D-9260-4124-B50E-04FB49ED0504}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\TYPELIB\{CB83C956-D8A2-40E1-B139-5B8A2F5750DF}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\INTERFACE\{2C50BCEC-DD76-42CF-8CD5-6DE077270CD5}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{2C50BCEC-DD76-42CF-8CD5-6DE077270CD5}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2C50BCEC-DD76-42CF-8CD5-6DE077270CD5}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{CB83C956-D8A2-40E1-B139-5B8A2F5750DF}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{CB83C956-D8A2-40E1-B139-5B8A2F5750DF}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C03C262D-9260-4124-B50E-04FB49ED0504}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C03C262D-9260-4124-B50E-04FB49ED0504}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{C03C262D-9260-4124-B50E-04FB49ED0504}\InprocServer32, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E563E407-B348-41FB-BC3D-EACE3BD4B1A1}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E563E407-B348-41FB-BC3D-EACE3BD4B1A1}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\CLSID\{E563E407-B348-41FB-BC3D-EACE3BD4B1A1}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E563E407-B348-41FB-BC3D-EACE3BD4B1A1}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E563E407-B348-41FB-BC3D-EACE3BD4B1A1}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{E563E407-B348-41FB-BC3D-EACE3BD4B1A1}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{E563E407-B348-41FB-BC3D-EACE3BD4B1A1}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E563E407-B348-41FB-BC3D-EACE3BD4B1A1}\InprocServer32, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{B36D9EA9-ABCA-4F9F-B181-49929A7B73D1}\InprocServer32, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C03C262D-9260-4124-B50E-04FB49ED0504}\InprocServer32, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E563E407-B348-41FB-BC3D-EACE3BD4B1A1}\InprocServer32, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\CLSID\{B36D9EA9-ABCA-4F9F-B181-49929A7B73D1}\InprocServer32, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\CLSID\{C03C262D-9260-4124-B50E-04FB49ED0504}\InprocServer32, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\CLSID\{E563E407-B348-41FB-BC3D-EACE3BD4B1A1}\InprocServer32, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E778C05E-AFF7-4924-B04A-D4084859D53A}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\SCShell.SCShellMenu, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\CLSID\{E778C05E-AFF7-4924-B04A-D4084859D53A}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\SCShell64.SCShellMenu, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E778C05E-AFF7-4924-B04A-D4084859D53A}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E778C05E-AFF7-4924-B04A-D4084859D53A}\InprocServer32, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E778C05E-AFF7-4924-B04A-D4084859D53A}\InprocServer32, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\CLSID\{E778C05E-AFF7-4924-B04A-D4084859D53A}\InprocServer32, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SC_Svc, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5FB600FF-BC65-471F-A3F8-C2666863BA75}_is1, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\SPYWARE CLEAR, Quarantined, [1456], [243468],1.0.5564 PUP.Optional.SpywareClear, HKCU\SOFTWARE\Spyware Clear, Quarantined, [1456], [243467],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\CLASSES\CLSID\{8B01D4B7-0860-452C-AC2B-5CE0140C82D4}, Quarantined, [1456], [168860],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\CONTROLPANEL\NAMESPACE\{8B01D4B7-0860-452C-AC2B-5CE0140C82D4}, Quarantined, [1456], [168860],1.0.5564 Registry Value: 6 PUP.Optional.SpywareClear, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SHELL EXTENSIONS\APPROVED|{E778C05E-AFF7-4924-B04A-D4084859D53A}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\SHELL EXTENSIONS\APPROVED|{E778C05E-AFF7-4924-B04A-D4084859D53A}, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SpywareClearShield, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SpywareClearUpdater, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, HKLM\SOFTWARE\SPYWARE CLEAR|ANTIVIRUSFPSCANHIGH, Quarantined, [1456], [243468],1.0.5564 PUP.Optional.SpywareClear, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SC_SVC|IMAGEPATH, Quarantined, [1456], [243469],1.0.5564 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 15 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Driver, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\PROGRAM FILES (X86)\SPYWARE CLEAR, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Quarantine, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Antivir, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Reports, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Addons, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Shared, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Update, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Down, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\PROGRAMDATA\SPYWARE CLEAR, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\SPYWARE CLEAR, Quarantined, [1456], [187215],1.0.5564 PUP.Optional.SpywareClear, C:\USERS\{username}\APPDATA\ROAMING\SPYWARE CLEAR, Quarantined, [1456], [179820],1.0.5564 PUP.Optional.SpywareClear, C:\USERS\{username}\APPDATA\LOCALLOW\SPYWARE CLEAR, Quarantined, [1456], [510257],1.0.5564 File: 82 PUP.Optional.SpywareClear, C:\PROGRAM FILES (X86)\SPYWARE CLEAR\TORRENTDLL.DLL, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Driver\driver.cab, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Driver\stflt.cat, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Driver\stflt.inf, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Driver\stflt.sys, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\24x7.xml, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\analyze.xml, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\analyzefile.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\bloatware.xml, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\defsyssettings.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\hardfileremover.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\optimizer.xml, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\ov.xml, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\remover.xml, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\restore.xml, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\so.xml, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\startup.xml, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\systemrestore.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\systemsettings.xml, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\unstableaddons.xml, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\Tools\virtualkeyboard.xml, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\com.spywareclear.internetguard.json, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SCInternetGuard.dll, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SCInternetGuard.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SCInternetGuard64.dll, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SCShell.dll, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SCShell64.dll, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SC_Svc64.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SpywareClear.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SpywareClearShield.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\SpywareClearUpdate.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\sqlite3.dll, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\unins000.dat, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\unins000.exe, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\Program Files (x86)\Spyware Clear\unins000.msg, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\DOCUMENTS AND SETTINGS\PUBLIC\Desktop\Spyware Clear.lnk, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\USERS\PUBLIC\DESKTOP\Spyware Clear.lnk, Quarantined, [1456], [187214],1.0.5564 PUP.Optional.SpywareClear, C:\PROGRAMDATA\SPYWARE CLEAR\LNG.INI, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Addons\addons.xml, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\185_en_3.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\186_en_3.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\187_en_11.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\188_en_3.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\191_en_10.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\192_en_4.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\193_en_3.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\251_en_3.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\275_en_2.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\276_en_2.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\277_en_2.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\278_en_2.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\302_en_4.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\308_en_5.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\368_en_2.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\378_en_1.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\383_en_3.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\399_en_1.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\400_en_1.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\News\420_en_1.pngx, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Reports\scan_0001.rpt, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Reports\scan_0002.rpt, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Shared\ST_1_CSD_3.000.000.0008.cab, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Shared\ST_1_CSD_3.000.000.0008.ini, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Shared\ST_1_CSD_3.000.000.0008.torrent, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Shared\ST_1_DB_12.002.019.0000.cab, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Shared\ST_1_DB_12.002.019.0000.ini, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Shared\ST_1_DB_12.002.019.0000.torrent, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Shared\ST_1_DSD_1.000.000.0006.cab, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Shared\ST_1_DSD_1.000.000.0006.ini, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\Shared\ST_1_DSD_1.000.000.0006.torrent, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\SC_CPL.xml, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\ST_CSD.spt, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\ST_DB.spt, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\ST_DSD.spt, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\ST_RL.spt, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Spyware Clear\ST_RTL.spt, Quarantined, [1456], [187213],1.0.5564 PUP.Optional.SpywareClear, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\SPYWARE CLEAR\SPYWARECLEAR.COM.URL, Quarantined, [1456], [187215],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Clear\Spyware Clear.lnk, Quarantined, [1456], [187215],1.0.5564 PUP.Optional.SpywareClear, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Clear\Uninstall Spyware Clear.lnk, Quarantined, [1456], [187215],1.0.5564 PUP.Optional.SpywareClear, C:\Users\{username}\AppData\LocalLow\Spyware Clear\log.txt, Quarantined, [1456], [510257],1.0.5564 PUP.Optional.SpywareClear, C:\USERS\{username}\DESKTOP\SPYWARECLEARSETUP.EXE, Quarantined, [1456], [61985],1.0.5564 PUP.Optional.SpywareClear, C:\USERS\{username}\DOWNLOADS\SPYWARECLEARSETUP.EXE, Quarantined, [1456], [61985],1.0.5564 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end)
Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Here’s how to do it.
If you want to allow the program to connect to the Internet, for example to fetch updates, also add an exclusion of the type Allow an application to connect to the internet and use the Browse button to select the file you wish to grant access.
You may see these entries in FRST logs:
(Crawler Group, LLC) C:\Program Files (x86)\Spyware Clear\SC_Svc64.exe (Crawler Group, LLC) C:\Program Files (x86)\Spyware Clear\SpywareClearUpdate.exe (Crawler Group, LLC) C:\Program Files (x86)\Spyware Clear\SpywareClearShield.exe (Crawler Group, LLC) C:\Program Files (x86)\Spyware Clear\SpywareClear.exe HKLM\...\Run: [SpywareClearShield] => C:\Program Files (x86)\Spyware Clear\SpywareClearShield.exe [5179608 2016-04-07] (Crawler Group, LLC) HKLM\...\Run: [SpywareClearUpdater] => C:\Program Files (x86)\Spyware Clear\SpywareClearUpdate.exe [5509848 2016-04-07] (Crawler Group, LLC) BHO: Spyware Clear Internet Guard -> {E563E407-B348-41FB-BC3D-EACE3BD4B1A1} -> C:\Program Files (x86)\Spyware Clear\SCInternetGuard64.dll [2016-04-07] (Crawler Group, LLC) BHO-x32: Spyware Clear Internet Guard -> {E563E407-B348-41FB-BC3D-EACE3BD4B1A1} -> C:\Program Files (x86)\Spyware Clear\SCInternetGuard.dll [2016-04-07] (Crawler Group, LLC) R2 SC_Svc; C:\Program Files (x86)\Spyware Clear\SC_svc64.exe [3208408 2016-04-07] (Crawler Group, LLC) R2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2011-08-24] (Windows (R) Win 7 DDK provider) C:\ProgramData\Spyware Clear C:\Users\{username}\AppData\LocalLow\Spyware Clear C:\Users\Public\Desktop\Spyware Clear.lnk C:\Users\{username}\AppData\Roaming\Spyware Clear C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Clear C:\Program Files (x86)\Spyware Clear Spyware Clear (HKLM-x32\...\{5FB600FF-BC65-471F-A3F8-C2666863BA75}_is1) (Version: 1.3.1.45 - Crawler Group) <==== ATTENTION FirewallRules: [{D32BAD43-68D2-4E4A-980A-7CDF16E85C1E}] => (Allow) C:\Program Files (x86)\Spyware Clear\SpywareClear.exe FirewallRules: [{941888E3-50AF-4F14-9A4F-5AC25EF2532A}] => (Allow) C:\Program Files (x86)\Spyware Clear\SpywareClearUpdate.exe
Select your language