I am reporting a potentially serious Software Remover / Software Updater incident.
Environment
- Windows 11 Pro 64-bit, build 26200
- CCleaner 7.10.1464.0
- Google Chrome 150.0.7871.125 before the incident
Intended action
At approximately 15:35 local time (UTC+8) on 21 August 2026, I opened CCleaner intending only to uninstall Proton VPN. I did not intend to uninstall or update Google Chrome.
What happened
- Windows UserAssist records show CCleaner 7 launching at 15:35:12.
- The Chrome version and Application directories were modified at 15:35:56–15:35:57.
- C:\Program Files\Google\Chrome\Application\chrome.exe and chrome_proxy.exe disappeared.
- Chrome’s desktop, Start Menu, and pinned-taskbar shortcuts disappeared.
- Chrome remained registered as installed as version 150.0.7871.125.
- Approximately 486 MB of Chrome program payload remained, including chrome.dll and the Google-signed installer, but the browser could no longer launch.
- The complete Chrome user profile remained intact (about 9.2 GB, including Bookmarks, History, Login Data, Preferences, and extensions).
- Chrome’s registry InstallSource pointed to CCleaner 7’s data\su_data cache.
- Microsoft Defender recorded no threat remediation, and there was no Chrome-related MSI uninstall event.
- Proton VPN removal was also incomplete: the TAP-ProtonVPN driver and disconnected network adapter remained.
I recovered Chrome only by installing the current official Google MSI, which upgraded it to 151.0.7922.174. The existing browser profile loaded normally afterward.
Request
Please investigate CCleaner’s Software Remover and Software Updater transaction logs for the session beginning at about 15:35:12 local time. I would like to know whether Chrome was unintentionally included in a removal action, whether an automatic Chrome update removed the launch files and failed before replacing them, or whether another CCleaner component modified the Chrome installation.
I preserved a read-only evidence bundle before repairing Chrome, including raw UserAssist values, timestamps, registry exports, SHA-256 manifests, installer events, and repair logs. I can provide the privacy-reviewed evidence privately to CCleaner staff on request.
So what you are actually saying is that it was only the shortcuts that were removed.
Annoying, but you could have put those back* without having to completely reinstall Chrome, although it looks like you needed a version update anyway.
Why the shortcuts were removed I have no idea, however I suspect a bug in the Proton uninstall data itself.
CCleaner doesn’t actually uninstall anything, it simply calls the existing Windows uninstaller (which then calls the programmes own uninstaller if one exists).
This is only a guess but I suspect that when installed Proton may ‘hook’ itself into the shortcuts so that it launches whenever you launch your browser, so it may be that removing that ‘hook’ during the uninstall may also remove the shortcuts?
*I’m sure you know this, but for anyone who doesn’t, you can easily create shortcuts for any executable programme that is installed on your computer.
- In File Explorer brows to the programme’s .exe file and right-click it to open the context menu.
- In Win 11 select “Show more options” (not needed in Win10 context menu).
- Select “Send to”
- Select "Desktop (create shortcut).
Both “Pin to Start” and “Pin to Taskbar” are also context menu items when you right-click the .exe file as above.
Or once you have the desktop shortcut you can simply right-click that and select “Pin to Start”, and “Pin to Taskbar” in the same way.
EDIT- Regarding the non-removal of the TAP and network adaptor I found this:
https://www.reddit.com/r/ProtonVPN/comments/huu7kf/protonvpn_tap_doesnt_let_me_uninstall/
Thanks for replying, but I need to correct one important misunderstanding: this was not only a shortcut issue.
The actual executables C:\Program Files\Google\Chrome\Application\chrome.exe and chrome_proxy.exe were missing. Therefore, there was no executable to which a newly created shortcut could point. Chrome could not be launched directly from its installation directory either.
At the same time, Windows still registered Chrome 150.0.7871.125 as installed, and approximately 486 MB of Chrome program files remained, including chrome.dll. The user profile also survived intact. This was therefore a broken and internally inconsistent Chrome installation—not merely deleted shortcuts.
Recovery required installing a newer official Google-signed MSI with administrator privileges. Only then were chrome.exe, chrome_proxy.exe, the shortcuts, and normal launch functionality restored. Recreating shortcuts alone could not have repaired it.
The preserved evidence also shows CCleaner starting at 15:35:12 and Chrome’s Application/version directories changing at 15:35:56–15:35:57. Chrome’s registered InstallSource pointed to CCleaner 7’s data\su_data cache. Proton’s removal was incomplete as well, leaving its TAP device and driver package behind.
I agree that the exact internal cause still needs investigation, but describing the incident as “only the shortcuts were removed” does not match the captured system state. I have preserved the pre-repair evidence and can provide it privately to CCleaner staff.
Thank you. I now have direct evidence from CCleaner’s own internal logs that resolves the uncertainty about what performed the deletion.
In CCleaner 7.10.1464.0’s ccleaner_modules.log, the Software Remover module ([soft_rem]) recorded the following sequence at 07:35:49–07:35:57 in the log, corresponding to approximately 15:35 local time:
Deleting software with key 8726c2edb1852fe59a523f2f88b9c698
Software information for Proton
- Its collected resource list included a Chrome Web App
Proton.ico, the shared C:\Program Files\Google\Chrome\Application\chrome.exe, Chrome’s Start Menu/Desktop/taskbar shortcuts, chrome_proxy.exe, and shortcuts belonging to another unrelated Chrome PWA.
Deleting file C:\Program Files\Google\Chrome\Application\chrome.exe
Set delete on reboot directly on path C:\Program Files\Google\Chrome\Application\chrome.exe was logged multiple times.
Deleting file C:\Program Files\Google\Chrome\Application\chrome_proxy.exe
Set delete on reboot directly on path C:\Program Files\Google\Chrome\Application\chrome_proxy.exe was also logged multiple times.
Immediately afterward, the same log separately recorded:
Deleting software with key Proton VPN_is1
Software information for Proton VPN
This shows that CCleaner Software Remover processed two distinct entries: a Chrome-installed web app named “Proton” and the actual Proton VPN installation. While removing the web app entry, CCleaner incorrectly treated Chrome’s shared host executables—and even shortcuts belonging to another PWA—as resources owned by that app, then deleted them itself. These entries were emitted by CCleaner’s [soft_rem] module before it began processing the separate Proton VPN entry, so this cannot be explained as merely Proton VPN’s own uninstaller deleting shortcuts.
The delayed deletion also caused the problem to recur after repair. Chrome 151.0.7922.174 was successfully restored at 16:21; both executables were present, Google-signed, and Chrome launched normally. After rebooting at 19:37, chrome.exe and chrome_proxy.exe disappeared again. Chrome’s Application directory changed at 19:37:43, before CCleaner and Google Updater started at approximately 19:37:46. This precisely matches CCleaner’s earlier Set delete on reboot records. The repair-time MSI log had also reported MsiSystemRebootPending=1.
Google Updater explicitly skipped its update check after boot, and Microsoft Defender recorded no Chrome remediation. I have now recovered Chrome a second time only after stopping and disabling the CCleaner service and force-repairing it with the official Google-signed MSI.
Please escalate this to the development team as a serious cross-application deletion bug in Software Remover’s resource-ownership logic. A web app uninstaller must never treat a shared shortcut target such as chrome.exe or chrome_proxy.exe as a file owned by that web app.
I have preserved the complete original CCleaner logs, the reboot-recurrence evidence, hashes, MSI logs, and a privacy-reviewed extract. I can provide the full material through a private channel to CCleaner staff.
Hi @Lio_Green,
Thank you for reporting this issue.
Please follow these steps to help us investigate the issue:
- Download and install the CCleaner Support Tool using the link below: https://download.ccleaner.com/CCleanerSupportTool.exe
- Replicate the issue on your end.
- Run the tool to generate the logs.
- At the end of the process, you’ll receive a 5-digit File ID.
Please share that File ID with me so I can review the logs and investigate further.
If you have any issues, please let me know.
Thank you for the instructions.
For safety, I cannot intentionally reproduce this issue again on the affected production machine. The issue has already occurred twice: first during the Software Remover operation, and again after reboot because CCleaner had scheduled chrome.exe and chrome_proxy.exe for deletion on reboot.
The complete CCleaner logs from the original incident are still available and have been preserved with SHA-256 hashes. The internal ccleaner_modules.log contains the full [soft_rem] sequence, including the incorrect resource attribution and the explicit Deleting file and Set delete on reboot directly on path entries.
Can I run the CCleaner Support Tool now, without reproducing the destructive action again, so that it collects and uploads the existing logs?
I am willing to provide the resulting File ID once the existing logs have been collected.
Thank you for the instructions.
For safety, I cannot intentionally reproduce this issue again on the affected production machine. The issue has already occurred twice: first during the Software Remover operation, and again after reboot because CCleaner had scheduled chrome.exe and chrome_proxy.exe for deletion on reboot.
The complete CCleaner logs from the original incident are still available and have been preserved with SHA-256 hashes. The internal ccleaner_modules.log contains the full [soft_rem] sequence, including the incorrect resource attribution and the explicit Deleting file and Set delete on reboot directly on path entries.
Can I run the CCleaner Support Tool now, without reproducing the destructive action again, so that it collects and uploads the existing logs?
I am willing to provide the resulting File ID once the existing logs have been collected.
I hope Laurence_CCleaner or someone may clarify a more general Driver Updater issue. Prompted in part by Avast pestering I have just acquired CCleaner’s paid version which has identified 21 outdated drivers.
Given the the problems raised above, I hesitate to select all especially since I have little/no idea about some. For example: NNVVHCI Enumerator, a series of Intel root ports, Microsofl-UEFI complian system from 2006, etc.
Any (accessible, fool-proof) advice will be much appreciated.