File name:

CCleaner Professional 5.45.6611 Slim Keygen [CracksMind].zip

Full analysis: https://app.any.run/tasks/42b3d12b-15a1-40ba-ab42-97f0654dcdfa
Verdict: Malicious activity
Analysis date: August 16, 2018, 10:08:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

E9ABBFE825AE20FC32F8BCD78AF7E908

SHA1:

7A1664BA2821741E379DECD6709C0339212F74BC

SHA256:

136EC0F2A116C291808306BA071578FB8F7F19C7A62A03CE7C66612BF97B461F

SSDEEP:

393216:Szxw2RLzBbouqejqzOx/p/SYW+DY8gLF5C:ixws99x/IY7YNLTC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • CCleaner.exe (PID: 3272)
      • CCUpdate.exe (PID: 3692)
      • CCleaner.exe (PID: 2860)
      • CCleaner.exe (PID: 3596)
      • CCleaner.exe (PID: 2464)
      • cr-piriform.exe (PID: 3340)
    • Changes the autorun value in the registry

      • CCUpdate.exe (PID: 3692)
      • CCleaner.exe (PID: 2464)
    • Loads the Task Scheduler COM API

      • CCleaner.exe (PID: 2860)
      • CCUpdate.exe (PID: 3692)
      • CCleaner.exe (PID: 3272)
      • CCleaner.exe (PID: 2464)
      • CCleaner.exe (PID: 3596)
    • Loads dropped or rewritten executable

      • ccsetup545_slim.exe (PID: 700)
    • Changes settings of System certificates

      • CCleaner.exe (PID: 3596)
    • Actions looks like stealing of personal data

      • CCleaner.exe (PID: 3596)
  • SUSPICIOUS

    • Modifies the open verb of a shell class

      • ccsetup545_slim.exe (PID: 700)
    • Executable content was dropped or overwritten

      • ccsetup545_slim.exe (PID: 700)
    • Creates files in the program directory

      • ccsetup545_slim.exe (PID: 700)
      • CCUpdate.exe (PID: 3692)
    • Reads internet explorer settings

      • CCleaner.exe (PID: 3596)
      • CCleaner.exe (PID: 2464)
    • Creates a software uninstall entry

      • ccsetup545_slim.exe (PID: 700)
    • Low-level read access rights to disk partition

      • CCUpdate.exe (PID: 3692)
      • ccsetup545_slim.exe (PID: 700)
      • CCleaner.exe (PID: 3596)
      • CCleaner.exe (PID: 2464)
    • Creates files in the user directory

      • CCleaner.exe (PID: 3596)
      • CCleaner.exe (PID: 2464)
    • Application launched itself

      • CCleaner.exe (PID: 3596)
    • Adds / modifies Windows certificates

      • CCleaner.exe (PID: 3596)
    • Changes IE settings (feature browser emulation)

      • CCleaner.exe (PID: 3596)
    • Reads CPU info

      • CCleaner.exe (PID: 2464)
    • Reads Internet Cache Settings

      • CCleaner.exe (PID: 3596)
    • Starts Internet Explorer

      • CCleaner.exe (PID: 3596)
  • INFO

    • Dropped object may contain URL's

      • CCleaner.exe (PID: 3596)
      • iexplore.exe (PID: 3100)
      • iexplore.exe (PID: 3236)
      • ccsetup545_slim.exe (PID: 700)
    • Reads settings of System Certificates

      • CCleaner.exe (PID: 3596)
      • iexplore.exe (PID: 3236)
      • CCleaner.exe (PID: 2464)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3236)
    • Creates files in the user directory

      • iexplore.exe (PID: 3236)
    • Changes internet zones settings

      • iexplore.exe (PID: 3100)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: 0x0800
ZipCompression: None
ZipModifyDate: 2018:08:16 10:06:12
ZipCRC: 0x540a28d9
ZipCompressedSize: 110
ZipUncompressedSize: 110
ZipFileName: CCleaner Professional 5.45.6611 Slim Keygen [CracksMind]/Visit SnowFiles.com.url
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
15
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe no specs notepad.exe no specs ccsetup545_slim.exe no specs ccsetup545_slim.exe winrar.exe no specs ccleaner.exe no specs winrar.exe no specs ccupdate.exe msinfo32.exe no specs ccleaner.exe no specs ccleaner.exe ccleaner.exe cr-piriform.exe no specs iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
384"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\CCleaner Professional 5.45.6611 Slim Keygen [CracksMind]\Downloaded from CracksMind.Com.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
700"C:\Users\admin\Desktop\CCleaner Professional 5.45.6611 Slim Keygen [CracksMind]\ccsetup545_slim.exe" C:\Users\admin\Desktop\CCleaner Professional 5.45.6611 Slim Keygen [CracksMind]\ccsetup545_slim.exe
explorer.exe
User:
admin
Company:
Piriform Ltd
Integrity Level:
HIGH
Description:
CCleaner Installer
Exit code:
0
Version:
5.45.190.6611
Modules
Images
c:\users\admin\desktop\ccleaner professional 5.45.6611 slim keygen [cracksmind]\ccsetup545_slim.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2084"C:\Windows\system32\msinfo32.exe" "C:\Users\admin\Desktop\CORE.NFO"C:\Windows\system32\msinfo32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
System Information
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msinfo32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2336"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CCleaner Professional 5.45.6611 Slim Keygen [CracksMind].zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2464"C:\Program Files\CCleaner\CCleaner.exe" /monitorC:\Program Files\CCleaner\CCleaner.exe
CCleaner.exe
User:
admin
Company:
Piriform Ltd
Integrity Level:
HIGH
Description:
CCleaner
Exit code:
0
Version:
5.45.190.6611
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2692"C:\Users\admin\Desktop\CCleaner Professional 5.45.6611 Slim Keygen [CracksMind]\ccsetup545_slim.exe" C:\Users\admin\Desktop\CCleaner Professional 5.45.6611 Slim Keygen [CracksMind]\ccsetup545_slim.exeexplorer.exe
User:
admin
Company:
Piriform Ltd
Integrity Level:
MEDIUM
Description:
CCleaner Installer
Exit code:
3221226540
Version:
5.45.190.6611
Modules
Images
c:\users\admin\desktop\ccleaner professional 5.45.6611 slim keygen [cracksmind]\ccsetup545_slim.exe
c:\systemroot\system32\ntdll.dll
2860"C:\Program Files\CCleaner\CCleaner.exe" C:\Program Files\CCleaner\CCleaner.exeexplorer.exe
User:
admin
Company:
Piriform Ltd
Integrity Level:
MEDIUM
Description:
CCleaner
Exit code:
0
Version:
5.45.190.6611
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3100"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
CCleaner.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3140"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Keygen.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
3236"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3100 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
3 776
Read events
3 389
Write events
380
Delete events
7

Modification events

(PID) Process:(2336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2336) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CCleaner Professional 5.45.6611 Slim Keygen [CracksMind].zip
(PID) Process:(2336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2C0000002C000000EC03000021020000
(PID) Process:(2336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
66
Suspicious files
11
Text files
115
Unknown types
8

Dropped files

PID
Process
Filename
Type
2336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2336.30611\CCleaner Professional 5.45.6611 Slim Keygen [CracksMind]\Visit SnowFiles.com.url
MD5:
SHA256:
2336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2336.30611\CCleaner Professional 5.45.6611 Slim Keygen [CracksMind]\Visit CracksMind.com.url
MD5:
SHA256:
2336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2336.30611\CCleaner Professional 5.45.6611 Slim Keygen [CracksMind]\Visit TutsGalaxy.com for tutorials free courses.url
MD5:
SHA256:
2336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2336.30611\CCleaner Professional 5.45.6611 Slim Keygen [CracksMind]\Downloaded from CracksMind.Com.txt
MD5:
SHA256:
2336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2336.30611\CCleaner Professional 5.45.6611 Slim Keygen [CracksMind]\Keygen.rar
MD5:
SHA256:
2336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2336.30611\CCleaner Professional 5.45.6611 Slim Keygen [CracksMind]\ccsetup545_slim.exe
MD5:
SHA256:
700ccsetup545_slim.exeC:\Users\admin\AppData\Local\Temp\CheckUpdate.log
MD5:
SHA256:
700ccsetup545_slim.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HHUAAB7W\installcheck[1].aspxtext
MD5:
SHA256:
700ccsetup545_slim.exeC:\Program Files\CCleaner\Lang\lang-1049.dllexecutable
MD5:
SHA256:
700ccsetup545_slim.exeC:\Program Files\CCleaner\Lang\lang-1042.dllexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
65
DNS requests
33
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3692
CCUpdate.exe
GET
200
2.16.186.56:80
http://ccleaner.tools.avcdn.net/tools/ccleaner/update/updates.xml
unknown
xml
678 b
whitelisted
3236
iexplore.exe
GET
200
151.101.2.202:80
http://www.ccleaner.com/go/app_cc_reg_purchase?a=0&v=5.45.6611&l=1033&t=4&m=1
US
html
1.81 Kb
whitelisted
3596
CCleaner.exe
GET
200
151.101.2.202:80
http://www.ccleaner.com/auto?a=0&p=cc&v=5.45.6611&l=1033&lk=&mk=BGKP-I9IF-8RSW-23YZ-UVRG-BSB9-I2HQ-F69D-78KP&o=6.1W3&au=1&mx=97B7721C4994E2556FF6A439510F665D6CA7AC11BFA3F8260558A5AD8348A1A4&gd=d15400ab-5d7e-4b7e-b9f0-cc8b3299f907
US
text
21 b
whitelisted
3596
CCleaner.exe
GET
200
151.101.2.109:80
http://license.piriform.com/activate/?p=ccpro&c=cc&cv=5.45.6611&l=1033&lk=C2YW-8XDF-SMDA-UN7X-8ZPC&mk=BGKP-I9IF-8RSW-23YZ-UVRG-BSB9-I2HQ-F69D-78KP&mx=97B7721C4994E2556FF6A439510F665D6CA7AC11BFA3F8260558A5AD8348A1A4&gd=d15400ab-5d7e-4b7e-b9f0-cc8b3299f907
US
text
14 b
whitelisted
3236
iexplore.exe
GET
200
216.58.215.232:80
http://www.googletagmanager.com/gtm.js?id=GTM-KFXRTR
US
text
31.2 Kb
whitelisted
3596
CCleaner.exe
GET
200
151.101.2.109:80
http://license.piriform.com/activate/?p=ccpro&c=cc&cv=5.45.6611&l=1033&lk=C2YW-8XDF-SMDA-UN7X-8ZPC&mk=BGKP-I9IF-8RSW-23YZ-UVRG-BSB9-I2HQ-F69D-78KP&mx=97B7721C4994E2556FF6A439510F665D6CA7AC11BFA3F8260558A5AD8348A1A4&gd=d15400ab-5d7e-4b7e-b9f0-cc8b3299f907
US
text
14 b
whitelisted
3692
CCUpdate.exe
GET
200
2.16.186.56:80
http://ccleaner.tools.avcdn.net/tools/ccleaner/update/patches.ini
unknown
ini
96 b
whitelisted
3236
iexplore.exe
GET
200
130.211.5.208:80
http://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js
US
text
20.4 Kb
whitelisted
3236
iexplore.exe
GET
200
151.101.2.202:80
http://www.ccleaner.com/favicon.ico
US
image
2.65 Kb
whitelisted
3596
CCleaner.exe
GET
200
151.101.2.109:80
http://license.piriform.com/verify/?p=ccpro&c=cc&cv=5.45.6611&l=1033&lk=CJ9T-J7CU-SPNV-GWMB-WBEC&mk=BGKP-I9IF-8RSW-23YZ-UVRG-BSB9-I2HQ-F69D-78KP&mx=97B7721C4994E2556FF6A439510F665D6CA7AC11BFA3F8260558A5AD8348A1A4&gd=d15400ab-5d7e-4b7e-b9f0-cc8b3299f907
US
text
17 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
700
ccsetup545_slim.exe
77.234.45.54:443
analytics.ff.avast.com
AVAST Software s.r.o.
DE
unknown
3692
CCUpdate.exe
5.62.38.20:80
ip-info.ff.avast.com
AVAST Software s.r.o.
NL
suspicious
700
ccsetup545_slim.exe
151.101.0.64:80
service.piriform.com
Fastly
US
whitelisted
3692
CCUpdate.exe
2.16.186.49:80
emupdate.avcdn.net
Akamai International B.V.
whitelisted
3692
CCUpdate.exe
2.16.186.56:80
ccleaner.tools.avcdn.net
Akamai International B.V.
whitelisted
2464
CCleaner.exe
77.234.45.54:443
analytics.ff.avast.com
AVAST Software s.r.o.
DE
unknown
2464
CCleaner.exe
151.101.2.109:443
license.piriform.com
Fastly
US
suspicious
3596
CCleaner.exe
151.101.2.109:80
license.piriform.com
Fastly
US
suspicious
3596
CCleaner.exe
151.101.2.202:443
www.ccleaner.com
Fastly
US
suspicious
2464
CCleaner.exe
5.62.38.44:443
ipm-provider.ff.avast.com
AVAST Software s.r.o.
NL
unknown

DNS requests

Domain
IP
Reputation
analytics.ff.avast.com
  • 77.234.45.54
  • 5.45.59.12
  • 77.234.45.53
whitelisted
service.piriform.com
  • 151.101.0.64
  • 151.101.64.64
  • 151.101.128.64
  • 151.101.192.64
whitelisted
ip-info.ff.avast.com
  • 5.62.38.21
  • 5.62.38.20
whitelisted
emupdate.avcdn.net
  • 2.16.186.73
  • 2.16.186.49
whitelisted
ccleaner.tools.avcdn.net
  • 2.16.186.59
  • 2.16.186.56
whitelisted
www.ccleaner.com
  • 151.101.2.202
  • 151.101.66.202
  • 151.101.130.202
  • 151.101.194.202
whitelisted
license.piriform.com
  • 151.101.2.109
  • 151.101.66.109
  • 151.101.130.109
  • 151.101.194.109
whitelisted
ipm-provider.ff.avast.com
  • 5.62.38.44
  • 5.45.62.78
  • 5.62.38.45
  • 5.45.62.79
whitelisted
www.googletagmanager.com
  • 216.58.215.232
whitelisted
ssl.google-analytics.com
  • 172.217.168.40
whitelisted

Threats

PID
Process
Class
Message
3596
CCleaner.exe
Misc activity
SUSPICIOUS [PTsecurity] Bundled.Toolbar.Google potentially unsafe
No debug info