NCleaner.exe

네이버 클리너

NAVER Corp.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘NCleaner’.
Publisher:
NAVER Corporation  (signed by NAVER Corp.)

Product:
네이버 클리너

Version:
1.0.64.166

MD5:
a925f6eb53a2428bdb8d753cedf2f909

SHA-1:
cebb93301d8f7c444856526e9996a3e8023986fe

SHA-256:
274dfa8e1c8eeb79b1a669edf6c2178b9c99889f07871f04d797242222cb0ff9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 2:52:13 PM UTC  (today)

File size:
3.1 MB (3,219,952 bytes)

Product version:
1.0.64.166

Copyright:
Copyright 2007

Original file name:
NCleaner.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\naver\navercleaner\ncleaner.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/5/2015 9:00:00 AM

Valid to:
11/5/2016 8:59:59 AM

Subject:
CN=NAVER Corp., O=NAVER Corp., L=Seongnam-si, S=Gyeonggi-do, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
32C9125CE7052360AE8EF2F97D7F8AB0

File PE Metadata
Compilation timestamp:
11/23/2015 3:19:17 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x124354

Entry point:
FB, D3, E0, 3E, C0, EC, 4A, DC, 96, F7, EA, 2A, 7A, 6E, BB, DF, 39, 09, E5, AF, DC, 3B, 17, 1F, 22, 63, 3A, DB, B1, 6B, 65, 95, A7, AB, 9A, 92, 82, 31, F6, BB, 0B, 7B, 65, 64, 63, 69, E9, 94, 62, 6B, 2A, 18, 79, E1, 88, 93, 2F, B8, C3, 7F, F6, F6, C7, 71, 33, 5F, 6C, 4A, 96, DB, 83, 55, 9A, 2F, 86, 09, 5B, 89, A0, E1, 14, AD, 9E, E5, AC, 6C, 68, 18, 02, 4B, 75, 39, F2, 47, DE, 07, 7F, E5, D8, 6D, 76, 3E, 72, 79, 37, 2D, 81, 00, 58, EE, 9B, BE, F6, D1, 06, 02, B3, 9A, 9B, AB, 74, 5F, 27, 26, 78, 94, 1F, 0D...
 
[+]

Entropy:
6.3205

Code size:
1.7 MB (1,736,704 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NCleaner

Command:
"C:\Program Files\naver\navercleaner\ncleaner.exe" \reboot


Scan NCleaner.exe - Powered by Reason Core Security