Skip to main content
Microsoft Security Intelligence
Published Jul 27, 2020 | Updated Aug 03, 2020

PUA:Win32/PiriformBundler

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

Certain installers for free and 14-day trial versions of CCleaner, Defraggler, Recuva, and Speccy come with bundled applications, including applications that are not required or developed by the same publisher Piriform. While the bundled applications themselves are legitimate, bundling of software, especially products from other providers, can result in unexpected software activity that can negatively impact user experiences. To protect Windows users, Microsoft Defender Antivirus detects installers for Piriform applications that exhibit this behavior as potentially unwanted applications (PUA)

The installers detected as PUA include installers of CCleaner, Defraggler, Recuva, and Speccy that have been found bundling the following applications. Note that these are normal applications that are not detected by Microsoft Defender Antivirus. 

  • Google Chrome
  • Google Toolbar
  • Avast Free Antivirus
  • AVG Antivirus Free

While these installers do provide an option to opt out, some users can easily inadvertently install these bundled applications.

Some instances of these installers are detected as the following:

With PUA protection turned on, Microsoft Defender Antivirus automatically identifies and blocks potentially unwanted applications detected based on Microsoft detection criteria. Updating your antimalware definitions and running a full scan can help remove specific components detected under that criteria.

Follow us