We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
PUA:Win32/PiriformBundler
Aliases: No associated aliases
Summary
Certain installers for free and 14-day trial versions of CCleaner, Defraggler, Recuva, and Speccy come with bundled applications, including applications that are not required or developed by the same publisher Piriform. While the bundled applications themselves are legitimate, bundling of software, especially products from other providers, can result in unexpected software activity that can negatively impact user experiences. To protect Windows users, Microsoft Defender Antivirus detects installers for Piriform applications that exhibit this behavior as potentially unwanted applications (PUA).
The installers detected as PUA include installers of CCleaner, Defraggler, Recuva, and Speccy that have been found bundling the following applications. Note that these are normal applications that are not detected by Microsoft Defender Antivirus.
- Google Chrome
- Google Toolbar
- Avast Free Antivirus
- AVG Antivirus Free
While these installers do provide an option to opt out, some users can easily inadvertently install these bundled applications.
Some instances of these installers are detected as the following:
With PUA protection turned on, Microsoft Defender Antivirus automatically identifies and blocks potentially unwanted applications detected based on Microsoft detection criteria. Updating your antimalware definitions and running a full scan can help remove specific components detected under that criteria.