ccleaner64.exe

CCleaner

Piriform Ltd

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘CCleaner Monitoring’.
Publisher:
Piriform Ltd  (signed and verified)

Product:
CCleaner

Version:
5, 08, 00, 5308

MD5:
69345e5573f185d771645e8bda013c69

SHA-1:
9d26067fed49da0a167e6fe60051253481eb805f

SHA-256:
c6f07bff962018a4731f0d62a3ac838e50493a44ba53732a8ac88f952e8420e7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 2:05:38 AM UTC  (today)

File size:
8 MB (8,418,584 bytes)

Product version:
5, 08, 00, 5308

Copyright:
Copyright © 2005-2015 Piriform Ltd

Original file name:
ccleaner.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ccleaner\ccleaner64.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/25/2013 7:00:00 AM

Valid to:
9/25/2015 6:59:59 AM

Subject:
CN=Piriform Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Piriform Ltd, L=London, S=London, C=GB

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
785AF6D521F67E132D53385742CE9B35

File PE Metadata
Compilation timestamp:
7/18/2015 1:07:58 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:cC/3GpxvLAF2hcF9S9wzP2m93jDjPLOq7hjBck:cC/Cd9+2m93jXd7hmk

Entry address:
0xFD3EC

Entry point:
48, 83, EC, 28, E8, 8F, FD, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 48, 85, C9, 0F, 84, 9C, 00, 00, 00, 53, 48, 83, EC, 20, 48, 8B, D9, B9, 0D, 00, 00, 00, E8, A5, EF, 00, 00, 90, 48, 8B, 4B, 08, 48, 85, C9, 74, 1B, F0, FF, 09, 75, 16, 48, 8B, 4B, 08, 48, 8D, 05, 6B, 19, 48, 00, 48, 3B, C8, 74, 06, E8, AD, D0, FF, FF, 90, B9, 0D, 00, 00, 00, E8, 76, EE, 00, 00, 48, 83, 3B, 00, 74, 3C, B9, 0C, 00, 00, 00, E8, 66, EF, 00, 00, 90, 48, 8B, 0B, E8, 51, A9, 00, 00, 48, 8B, 0B, 48, 85, C9, 74, 17, 83...
 
[+]

Entropy:
6.2721

Code size:
4 MB (4,175,872 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
CCleaner Monitoring

Command:
"C:\Program Files\ccleaner\ccleaner64.exe" \monitor


Scan ccleaner64.exe - Powered by Reason Core Security