cleanmgr.exe

  • File Path: C:\Windows\SysWOW64\cleanmgr.exe
  • Description: Disk Space Cleanup Manager for Windows

Screenshot

cleanmgr.exe cleanmgr.exe cleanmgr.exe

Hashes

Type Hash
MD5 5AB8F80E61D780F31585E612B83FFFAD
SHA1 CC79E333A78DBA85136B9674125E6F48C13B099A
SHA256 21737F8A48F1A7FB7873DFED26836382613DDC9E1DB860D71250B5067C011D82
SHA384 0EA3AC9AD762E37B1789F8ED665E0302AF1AF116748B47ABEE7DED71DCECCF14739A5E06460904F77A545456332116E2
SHA512 B098215E02967963C092161B3A15774886F7276B15D1C297E3ED0FA76CE44068ACF353A44B4891A4574F427848C4D35A1CD229F230FF04B1A6CBAC2073EC0EAB
SSDEEP 3072:rJ8eh6cvBPXSWRf1nhBYoFcBdyqLAEPGRvQhRkKqUa9antF5hvvJkuXpZJq:LHvhBYoFcBMqsE+ohSKq99UF5hvv/
IMP F76A18F264CF5159E816B15A0467A24E
PESHA1 C8003ECCD65001D3EFBCC02C5A5DE7DE4CF231B3
PE256 E8363348996515C388559019C8088D7C33E262FB9B67022231631CD934BECA9E

Runtime Data

Window Title:

USAGE

Open Handles:

Path Type
(R-D) C:\Windows\Fonts\StaticCache.dat File
(R-D) C:\Windows\System32\en-US\cleanmgr.exe.mui File
(RW-) C:\Users\user File
(RW-) C:\Windows File
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627 File
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2 Section
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section
\Sessions\1\Windows\Theme1175649999 Section
\Windows\Theme601709542 Section

Loaded Modules:

Path
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll
C:\Windows\SysWOW64\cleanmgr.exe

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: CLEANMGR.DLL
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/76
  • VirusTotal Link: https://www.virustotal.com/gui/file/21737f8a48f1a7fb7873dfed26836382613ddc9e1db860d71250b5067c011d82/detection

File Similarity (ssdeep match)

File Score
C:\WINDOWS\system32\cleanmgr.exe 66
C:\Windows\system32\cleanmgr.exe 63
C:\Windows\system32\cleanmgr.exe 61
C:\Windows\system32\cleanmgr.exe 66
C:\Windows\system32\cleanmgr.exe 71
C:\Windows\SysWOW64\cleanmgr.exe 63
C:\Windows\SysWOW64\cleanmgr.exe 69
C:\Windows\SysWOW64\cleanmgr.exe 65
C:\WINDOWS\SysWOW64\cleanmgr.exe 63

Possible Misuse

The following table contains possible examples of cleanmgr.exe being misused. While cleanmgr.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_susp_run_folder.yml - 'C:\Windows\System32\cleanmgr.exe' DRL 1.0
sigma proc_creation_win_uac_bypass_cleanmgr.yml description: Detects the pattern of UAC Bypass using scheduled tasks and variable expansion of cleanmgr.exe (UACMe 34) DRL 1.0
sigma proc_creation_win_uac_bypass_cleanmgr.yml CommandLine\|endswith: '"\system32\cleanmgr.exe /autoclean /d C:' DRL 1.0
sigma registry_event_bypass_uac_using_silentcleanup_task.yml description: There is an auto-elevated task called SilentCleanup located in %windir%\system32\cleanmgr.exe This can be abused to elevate any file with Administrator privileges without prompting UAC DRL 1.0
atomic-red-team T1548.002.md There is an auto-elevated task called SilentCleanup located in %windir%\system32\cleanmgr.exe This can be abused to elevate any file with Administrator privileges without prompting UAC (even highest level). MIT License. © 2018 Red Canary

Additional Info*

*The information below is copied from MicrosoftDocs, which is maintained by Microsoft. Available under CC BY 4.0 license.


cleanmgr

Applies to: Windows Server 2022, Windows Server 2019, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2

Clears unnecessary files from your computer’s hard disk. You can use command-line options to specify that Cleanmgr cleans up Temp files, Internet files, downloaded files, and Recycle Bin files. You can then schedule the task to run at a specific time by using the Scheduled Tasks tool.

Syntax

cleanmgr [/d <driveletter>] [/sageset:n]  [/sagerun:n] [/TUNEUP:n] [/LOWDISK] [/VERYLOWDISK]

Parameters

Parameter Description
/d <driveletter> Specifies the drive that you want Disk Cleanup to clean.<p>NOTE: The /d option is not utilized with /sagerun:n.
/sageset:n Displays the Disk Cleanup Settings dialog box and also creates a registry key to store the settings that you select. The n value, which is stored in the registry, allows you to specify tasks for Disk Cleanup to run. The n value can be any integer value from 0 to 9999.
/sagerun:n Runs the specified tasks that are assigned to the n value if you use the /sageset option. All drives on the computer are enumerated and the selected profile runs against each drive.
/tuneup:n Run /sageset and /sagerun for the same n .
/lowdisk Run with the default settings.
/verylowdisk Run with the default settings, no user prompts.
/? Displays help at the command prompt.
Options

The options for the files that you can specify for Disk Cleanup by using /sageset and /sagerun include:

  • Temporary Setup Files - These are files that were created by a Setup program that is no longer running.

  • Downloaded Program Files - Downloaded program files are ActiveX controls and Java programs that are downloaded automatically from the Internet when you view certain pages. These files are temporarily stored in the Downloaded Program Files folder on the hard disk. This option includes a View Files button so that you can see the files before Disk Cleanup removes them. The button opens the C:\Winnt\Downloaded Program Files folder.

  • Temporary Internet Files - The Temporary Internet Files folder contains Web pages that are stored on your hard disk for quick viewing. Disk Cleanup removes these page but leaves your personalized settings for Web pages intact. This option also includes a View Files button, which opens the C:\Documents and Settings\Username\Local Settings\Temporary Internet Files\Content.IE5 folder.

  • Old Chkdsk Files - When Chkdsk checks a disk for errors, Chkdsk might save lost file fragments as files in the root folder on the disk. These files are unnecessary.

  • Recycle Bin - The Recycle Bin contains files that you have deleted from the computer. These files are not permanently removed until you empty the Recycle Bin. This option includes a View Files button that opens the Recycle Bin.<p>Note: A Recycle Bin may appear in more than one drive, for example, not just in %SystemRoot%.

  • Temporary Files - Programs sometimes store temporary information in a Temp folder. Before a program quits, the program usually deletes this information. You can safely delete temporary files that have not been modified within the last week.

  • Temporary Offline Files - Temporary offline files are local copies of recently used network files. These files are automatically cached so that you can use them after you disconnect from the network. A View Files button opens the Offline Files folder.

  • Offline Files - Offline files are local copies of network files that you specifically want to have available offline so that you can use them after you disconnect from the network. A View Files button opens the Offline Files folder.

  • Compress Old Files - Windows can compress files that you have not used recently. Compressing files saves disk space, but you can still use the files. No files are deleted. Because files are compressed at different rates, the displayed amount of disk space that you will gain is approximate. An Options button permits you to specify the number of days to wait before Disk Cleanup compresses an unused file.

  • Catalog Files for the Content Indexer - The Indexing service speeds up and improves file searches by maintaining an index of the files that are on the disk. These Catalog files remain from a previous indexing operation and can be deleted safely.<p>Note: Catalog File may appear in more than one drive, for example, not just in %SystemRoot%.

[!NOTE] If you specify cleaning up the drive that contains the Windows installation, all of these options are available on the Disk Cleanup tab. If you specify any other drive, only the Recycle Bin and the Catalog files for content index options are available on the Disk Cleanup tab.

Examples

To run the Disk Cleanup app so that you can use its dialog box to specify options for use later, saving the settings to the set 1, type the following:

cleanmgr /sageset:1

To run Disk Cleanup and include the options that you specified with the cleanmgr /sageset:1 command, type:

cleanmgr /sagerun:1

To run cleanmgr /sageset:1 and cleanmgr /sagerun:1 together, type:

cleanmgr /tuneup:1

Additional References


MIT License. Copyright (c) 2020-2021 Strontic.