Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- System Back Door
- Cloaked Malware
- Malicious Software
- Worm
File Behavior
CLEAN.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- The Process is polymorphic and can change its structure
- Adds a Registry Key (RUN) to auto start Programs on system start up
- This Process Deletes Other Processes From Disk
- Executes a Process
- This process creates other processes on disk
- Registers a Dynamic Link Library File
- Writes to another Process's Virtual Memory (Process Hijacking)
- Enables an In Process Object/Server - Common with DLL Injections
- Creates system tray popups, messages, errors and security warnings
CLEAN.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Created as a process on disk
- Terminated as a Process
- Deleted as a process from disk
- Executed from Temporary Folders
- Created by processes which appear to be checking for interception by security products
Country Of Origin
The filename CLEAN.EXE was first seen on May 31 2007 in the following geographical regions of the Webroot community:
- Germany on May 31 2007
- Serbia on May 31 2007
- Spain on Oct 26 2007
- Argentina on Oct 26 2007
- The United States on Jan 23 2008
- Mexico on Mar 6 2008
- Egypt on Apr 8 2008
File Name Aliases
CLEAN.EXE can also use the following file names:
- CLEAN2.EXE
- VIRUS5/CLEAN.EXE
- TIDY.EXE
- DOCS/CLEAN.EXE
- AUTOPLAY/DOCS/CLEAN.EXE
- IR_EXT_TEMP_0/AUTOPLAY/DOCS/CLEAN.EXE
- KASPERSKY_ANTI_BLACKLIST1.EXE
- KASPERSKY CZYCZCZENIE KLUCZA REJESTRU.EXE
Filesizes
The following file size has been seen:
- 1,351,680 bytes
- 7,680 bytes
- 20,480 bytes
- 192,512 bytes
- 110,592 bytes
- 282,996 bytes
- 32,768 bytes
File Type
The filename CLEAN.EXE is used by multiple object types including executable programs,objects,self extracting compressed files.
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.