Once this type of software are installed and embedded into the computer CleanMyMac aka BrickMyMac
Start Over from Scratch
Heavy Handed - Yes ?
Effective in removing this software - Yes
For Apple Silicon computer >> Use Disk Utility to erase a Mac with Apple silicon.
CleanMyMac , aka “ BrickMyMac “
New macOS Malware "Cthulhu Stealer" Targets Apple Users' Data
Specific to CleanMyMac aka “ BrickMyMac “
To put the CleanMyMac in context and the damages it may have or has already done.
This application can or will Muck Up your User Account ( Home Folder ) of this machine.
It does not touch the Operating System itself unless you consider your User Account ( Home Folder ) as part of the Operating System
Then in that specific context - it has Mucked Up the Operating System
In which case, the Operating System is hosed
Always make a Time Machine Backup before proceeding
If going this route - I suggest Not using Startup Assist to migrate everything back.
This will probably Re-Introduce ( CleanMyMac aka BrickMyMac ) back into the Operating System
Without harping on the usage of Commercial VPNs you may consider your option very carefully
They may not be what one believes they are doing for the computer and what they actually are doing behind the scenes
https://gist.github.com/joepie91/5a9909939e6ce7d09e29
A - System extension blocked - There are system extensions awaiting user approval.
A- System modifications - There are a large number of system modifications running in the background.
A - Configuration Files:
/etc/hosts - Count: 12
A - qbittorrent.app - Great Source for picking up Cracked Software that can contain all kinds of Malware and Adware
A - Antivirus software: Apple and CleanMyMac
A - Launchd: /Library/LaunchDaemons/com.macpaw.CleanMyMac2.Agent.plist
A - AdBlockVPNMacOSProvider - version 2.1.8 (App Store - installed 2024-11-27)
A - NordVPN Threat Protection Pro™ - version 8.33.0 (Nordvpn S.A. - installed 2025-01-20)
A - [Waiting for authorization] DuckDuckGo VPN Network Extension - version 1.120.0 (Duck Duck Go, Inc. - installed 2025-01-03)