JetClean

By GoldSparrow in Potentially Unwanted Programs
Translate To:

Threat Scorecard

Popularity Rank: 18,684
Threat Level: 80 % (High)
Infected Computers: 2
First Seen: October 5, 2024
Last Seen: September 21, 2025
OS(es) Affected: Windows

JetClean is a misleading system optimizer application that may be installed on your computers when their users download a free program that doesn't make clear that by downloading and installing it on their computers, the users will accept the presence of JetClean on their machines. Sometimes these free programs even disclose the use of this method, called 'bundling' but the computer users that don't read the Terms of Use will not be aware that there will be another program being installed. Also, JetClean can be downloaded and installed by the computer users because JetClean claims to be able to keep their machines clean 'with a single click.

Computer users that believe in JetClean claims and run the application on their machines will receive a report of numerous, serious problems detected by this fake optimizer. Then, JetClean will claim that, to solve the problems that are affecting your machine, you need to purchase its full version, which with 'One-click Clean and Tuneup,' besides being a 'Fast and Powerful Windows Clean,' 'Light, Easy-to-use, and Reliable,' 'Improves PC Performance,' and other useful features. Although JetClean can detect and remove outdated and unnecessary entries from your computer, JetClean may, during their removal process, delete useful and necessary entries, which, instead of helping your machine, will create issues that can prejudice it. Affected computer users have reported that JetClean makes their machines to slow down by using their system resources and displays lots of advertisements that can impair their work. If you downloaded and installed JetClean on your machine or if it appeared due to a bundle, you need to know that JetClean is considered a Possibly Unwanted Program (PUP) by malware experts and is best to be removed. JetClean can be removed manually or with a dedicated malware removal tool.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.Agent.APA
Signature status: No Signature

Known Samples

MD5: 3a02a5bbfb420485b801055e5c5f872c
SHA1: 44133baf009932b3f537aeb413bb8148c39cf6f4
SHA256: 5A38151B58E40345F8096FE20FB9221BBB357095D2346584CFFD2F531A6FAAE0
File Size: 24.58 KB, 24576 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.1
Comments OneDriveUp
Company Name OneDriveUp
File Description OneDriveUp
File Version 1.0.0.1
Internal Name OneDriveApiUp.exe
Legal Copyright Copyright © 2024
Legal Trademarks OneDriveUp
Original Filename OneDriveApiUp.exe
Product Name OneDriveUp
Product Version 1.0.0.1

File Traits

  • .NET
  • x64

Block Information

Total Blocks: 9
Potentially Malicious Blocks: 8
Whitelisted Blocks: 1
Unknown Blocks: 0

Visual Map

x x x x 0 x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Downloader.Agent.APA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider

1 Comment

I've use JetClean on many systems and it works just fine. It is a one-click cleaner, just erasing temp files and trash left behind by uninstalled programs. It's fast and really speeds up any old system loaded with junk. Of course the fastest way to speed up a system is a full new reinstall. It's been scanned by many antivirus and has no virus. BitDefender now deletes it and tells you to buy Their Optimizer software!

Trending

Most Viewed

Loading...