ProcessClean.exe

ProcessClean Application

Process Clean Corp

The application ProcessClean.exe by Process Clean Corp has been detected as a potentially unwanted program by 2 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ProcessClean’. While running, it connects to the Internet address i0-h0-s48.p59-icn.cdngp.net on port 80 using the HTTP protocol.
Publisher:
ProcessClean  (signed by Process Clean Corp)

Product:
ProcessClean Application

Version:
2.3.5.2

MD5:
9d18703556480b068a0110b59c574ec3

SHA-1:
66b53dc9af1d0dc99a1fc4562c078ed802c01508

SHA-256:
0e2d8039b6df0b54a752f66a6c33f2d67afdf2a7553277ccaa53cf807e29f36a

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
5/10/2025 8:19:00 PM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Suspicious
17666

Reason Heuristics
PUP.ProcessCleanCorp (M)
15.8.24.17

File size:
3.7 MB (3,919,632 bytes)

Product version:
2.3.5.2

Copyright:
Copyright (c) 2012 ProcessClean, All right

Original file name:
ProcessClean.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\processclean\processclean.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
5/21/2012 9:00:00 AM

Valid to:
5/22/2014 8:59:59 AM

Subject:
CN=Process Clean Corp, O=Process Clean Corp, L="Yeongju Si ", S=GYEONGSANGBUK-DO, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
476625C5531BFCE9A4340ADFE494739F

File PE Metadata
Compilation timestamp:
1/7/2013 3:34:20 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:h4fBlz4pyJSzUkTdl2+6uMMCOEwiIWYiA1Fddx04A1fM:CZi6iphIIVinM

Entry address:
0x1284C8

Entry point:
55, 8B, EC, B9, 05, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, B8, 58, 4F, 52, 00, E8, 7E, EA, ED, FF, 8B, 1D, D4, 03, 53, 00, 33, C0, 55, 68, A0, 86, 52, 00, 64, FF, 30, 64, 89, 20, A1, B0, 03, 53, 00, 80, 38, 00, 0F, 85, 81, 01, 00, 00, 8B, 03, E8, 91, AE, F4, FF, E8, 98, AE, ED, FF, 83, F8, 03, 7C, 44, 8D, 55, EC, B8, 01, 00, 00, 00, E8, E6, AE, ED, FF, 8B, 45, EC, BA, B8, 86, 52, 00, E8, 3D, CC, ED, FF, 75, 28, 8B, 03, B2, 01, E8, 1A, CD, F4, FF, 8B, 0D, 50, 03, 53, 00, 8B, 03, 8B, 15, 18, 34, 4F, 00...
 
[+]

Entropy:
6.4547

Developed / compiled with:
Microsoft Visual C++

Code size:
1.2 MB (1,208,320 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ProcessClean

Command:
"C:\Program Files\processclean\processclean.exe"


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to cache.google.com  (59.18.45.182:443)

TCP (HTTP):
Connects to a23-33-151-247.deploy.static.akamaitechnologies.com  (23.33.151.247:80)

TCP (HTTP):
Connects to i0-h0-s43.p59-icn.cdngp.net  (14.0.67.90:80)

TCP (HTTP):
Connects to i0-h0-s48.p59-icn.cdngp.net  (14.0.67.95:80)

TCP (HTTP):
Connects to a23-62-233-163.deploy.static.akamaitechnologies.com  (23.62.233.163:80)

Remove ProcessClean.exe - Powered by Reason Core Security