General Info

File name

cleaner-util.exe

Full analysis
https://app.any.run/tasks/ec68c6a5-a9ef-4e52-8eaa-7f0e628e5abc
Verdict
Malicious activity
Analysis date
8/13/2019, 16:55:29
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

9987720f71d56835ac10087f0a5ee246

SHA1

bfe0c4d590d497518104a004e69a381acb2ee781

SHA256

1452cc126d870dff026ec2a21ac3eb7a55962d4bf0d0608519608ad4db04cb4a

SSDEEP

98304:1CgM9k6dxzUi9DGhgWQYqZ7lKUBLOT4PU7MHT4PU7MfVM38N/YhGW1NCYVpWIERo:lMSzhgWQtgN/IGINChRaPGbRfrqNKG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads the Task Scheduler COM API
  • cleaner-util.exe (PID: 3040)
Changes settings of System certificates
  • cleaner-util.exe (PID: 3040)
Loads dropped or rewritten executable
  • cleaner-util.exe (PID: 3040)
Disables Windows Defender
  • cleaner-util.exe (PID: 3040)
Changes Windows auto-update feature
  • cleaner-util.exe (PID: 3040)
Reads the cookies of Google Chrome
  • cleaner-util.exe (PID: 3040)
Reads internet explorer settings
  • cleaner-util.exe (PID: 3040)
Creates files in the user directory
  • cleaner-util.exe (PID: 3040)
Creates a software uninstall entry
  • cleaner-util.exe (PID: 3040)
Creates files in the Windows directory
  • cleaner-util.exe (PID: 3040)
Searches for installed software
  • cleaner-util.exe (PID: 3040)
Reads the cookies of Mozilla Firefox
  • cleaner-util.exe (PID: 3040)
Reads Internet Cache Settings
  • cleaner-util.exe (PID: 3040)
Creates files in the program directory
  • cleaner-util.exe (PID: 3040)
Low-level read access rights to disk partition
  • cleaner-util.exe (PID: 3040)
Executable content was dropped or overwritten
  • cleaner-util.exe (PID: 3040)

No info indicators.

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win64 Executable (generic) (76.4%)
.exe
|   Win32 Executable (generic) (12.4%)
.exe
|   Generic Win/DOS Executable (5.5%)
.exe
|   DOS Executable Generic (5.5%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2019:08:13 16:55:19+02:00
PEType:
PE32
LinkerVersion:
14.16
CodeSize:
2609152
InitializedDataSize:
8142848
UninitializedDataSize:
null
EntryPoint:
0x1ac05b
OSVersion:
6
ImageVersion:
null
SubsystemVersion:
6
Subsystem:
Windows GUI
FileVersionNumber:
2.21.230.0
ProductVersionNumber:
2.21.230.0
FileFlagsMask:
0x0000
FileFlags:
(none)
FileOS:
Unknown (0)
ObjectFileType:
Unknown
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Windows, Latin1
CompanyName:
null
FileDescription:
Программное обеспечение для содержания компьютера в чистоте.
FileVersion:
2.21.230
InternalName:
Чистилка.exe
LegalCopyright:
null
LegalTrademarks1:
null
LegalTrademarks2:
null
OriginalFileName:
Чистилка.exe
ProductName:
Чистилка
ProductVersion:
2.21.230
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
13-Aug-2019 14:55:19
Detected languages
English - United States
Russian - Russia
Debug artifacts
C:\Users\User\JOB\chistilka\cleaner-app\build\bin\cleaner-util.pdb
CompanyName:
null
FileDescription:
Программное обеспечение для содержания компьютера в чистоте.
FileVersion:
2.21.230
InternalName:
Чистилка.exe
LegalCopyright:
null
LegalTrademarks1:
null
LegalTrademarks2:
null
OriginalFilename:
Чистилка.exe
ProductName:
Чистилка
ProductVersion:
2.21.230
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000138
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
13-Aug-2019 14:55:19
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0027CEC3 0x0027D000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.62932
.rdata 0x0027E000 0x001CE320 0x001CE400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 7.24494
.data 0x0044D000 0x00018FF4 0x00013C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 6.48588
.rsrc 0x00466000 0x005C0788 0x005C0800 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 6.78766
.reloc 0x00A27000 0x000217D8 0x00021800 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 6.60604
Resources
1

2

3

4

5

6

9

10

12

70

71

75

76

77

79

102

103

104

105

106

107

108

110

112

113

114

115

116

120

121

123

124

125

126

128

129

130

131

133

134

135

136

137

145

146

147

148

153

154

155

157

158

159

160

161

162

163

165

166

168

169

170

172

176

180

181

183

1076

1111

1124

1127

1130

1190

1203

1225

1226

1227

1228

1229

1230

1233

1235

1238

1241

1251

1254

1255

1257

1258

IDD_PAGE_QUEST

Imports
    KERNEL32.dll

    USER32.dll

    GDI32.dll

    SHELL32.dll

    ole32.dll

    OLEAUT32.dll

    ADVAPI32.dll

    COMCTL32.dll

    UxTheme.dll

    gdiplus.dll

    VERSION.dll

    WININET.dll

    USERENV.dll

    dbghelp.dll

    RPCRT4.dll

    CRYPT32.dll

    imagehlp.dll

    WINHTTP.dll

    WS2_32.dll

    IPHLPAPI.DLL

    PSAPI.DLL

    SHLWAPI.dll

Exports

    No exports.

Screenshots

Processes

Total processes
39
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

+
start cleaner-util.exe no specs cleaner-util.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3748
CMD
"C:\Users\admin\AppData\Local\Temp\cleaner-util.exe"
Path
C:\Users\admin\AppData\Local\Temp\cleaner-util.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\cleaner-util.exe
c:\systemroot\system32\ntdll.dll

PID
3040
CMD
"C:\Users\admin\AppData\Local\Temp\cleaner-util.exe"
Path
C:\Users\admin\AppData\Local\Temp\cleaner-util.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\cleaner-util.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\version.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\schannel.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\program files\mozilla firefox\firefox.exe
c:\program files\google\chrome\application\chrome.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\opera\opera.exe
c:\windows\system32\riched20.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\programdata\чистилка\чистилка.exe
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\users\admin\appdata\local\temp\sciter.dll
c:\windows\system32\winmm.dll
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\mlang.dll
c:\windows\system32\unregmp2.exe
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\ehome\ehres.dll
c:\program files\windows sidebar\sidebar.exe
c:\windows\system32\windowsanytimeupgradeui.exe
c:\program files\dvd maker\dvdmaker.exe
c:\windows\system32\fxsresm.dll
c:\windows\system32\xpsrchvw.exe
c:\windows\system32\gpedit.dll
c:\windows\system32\activeds.dll
c:\windows\system32\adsldpc.dll
c:\windows\system32\atl.dll
c:\windows\system32\dsuiext.dll
c:\windows\system32\mpr.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\dssec.dll
c:\windows\system32\authz.dll
c:\windows\system32\dfscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll

Registry activity

Total events
572
Read events
409
Write events
144
Delete events
19

Modification events

PID
Process
Operation
Key
Name
Value
3040
cleaner-util.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D3C056F-EE0F-45AC-85A2-8812A99E602F}User
3040
cleaner-util.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects
3040
cleaner-util.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D3C056F-EE0F-45AC-85A2-8812A99E602F}Machine
3040
cleaner-util.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D3C056F-EE0F-45AC-85A2-8812A99E602F}Machine\Software
3040
cleaner-util.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D3C056F-EE0F-45AC-85A2-8812A99E602F}Machine\Software\Policies
3040
cleaner-util.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D3C056F-EE0F-45AC-85A2-8812A99E602F}Machine\Software\Policies\Microsoft
3040
cleaner-util.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D3C056F-EE0F-45AC-85A2-8812A99E602F}Machine\Software\Policies\Microsoft\Windows
3040
cleaner-util.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D3C056F-EE0F-45AC-85A2-8812A99E602F}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
3040
cleaner-util.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D3C056F-EE0F-45AC-85A2-8812A99E602F}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
3040
cleaner-util.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D3C056F-EE0F-45AC-85A2-8812A99E602F}Machine\Software\Policies\Microsoft\Windows Defender
3040
cleaner-util.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D3C056F-EE0F-45AC-85A2-8812A99E602F}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\chst
uid
76336796-f94d-4a44-be3e-dfe174129730-46d0e46f0105f2878e2f44ae94080ed6315c4de3
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\chst
prt
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\chst
hwid
048ea7dadfda4e2e7e4c5da96a4934a6d6c67b7a
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\chst
v
2.21.230
3040
cleaner-util.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\33E4E80807204C2B6182A3A14B591ACD25B5F0DB
Blob
03000000010000001400000033E4E80807204C2B6182A3A14B591ACD25B5F0DB1400000001000000140000008D8C5EC454AD8AE177E99BF99B05E1B8018D61E1040000000100000010000000ADAB5C4DF031FB9299F71ADA7E18F6130F00000001000000300000008B612B2190A95B28B866B9BE5D0B95F368C17534AB1DA61A42DFB32766F9AE2908FE6BFD1669BE140EDDAF0D33E95235190000000100000010000000FC741B3B78CFB31E075744FE5D0EEB96180000000100000010000000EA6089055218053DD01E37E1D806EEDF20000000010000001706000030820613308203FBA00302010202107D5B5126B476BA11DB74160BBC530DA7300D06092A864886F70D01010C0500308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F72697479301E170D3138313130323030303030305A170D3330313233313233353935395A30818F310B3009060355040613024742311B30190603550408131247726561746572204D616E636865737465723110300E0603550407130753616C666F726431183016060355040A130F5365637469676F204C696D69746564313730350603550403132E5365637469676F2052534120446F6D61696E2056616C69646174696F6E205365637572652053657276657220434130820122300D06092A864886F70D01010105000382010F003082010A0282010100D67333D6D73C20D000D21745B8D63E07A23FC741EE3230C9B06CFDF49FCB12980F2D3F8D4D010C820F177F622EE9B84879FB16834EADD7322593B707BFB9503FA94CC3402AE939FFD981CA1F163241DA8026B9237A87201EE3FF209A3C95446F8775069040B4329316091008233ED2DD870F6F5D51146A0A69C54F017269CFD3934C6D04A0A31B827EB19AB9EDC59EC537789F9A0834FB562E58C4090E06645BBC37DCF19F2868A856B092A35C9FBB8898081B241DAB3085AEAFB02E9E7A9DC1C0421CE202F0EAE04AD2EF900EB4C14016F06F85424A64F7A430A0FEBF2EA3275A8E8B58B8ADC319178463ED6F56FD83CB6034C474BEE69DDBE1E4E5CA0C5F150203010001A382016E3082016A301F0603551D230418301680145379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB301D0603551D0E041604148D8C5EC454AD8AE177E99BF99B05E1B8018D61E1300E0603551D0F0101FF04040302018630120603551D130101FF040830060101FF020100301D0603551D250416301406082B0601050507030106082B06010505070302301B0603551D200414301230060604551D20003008060667810C01020130500603551D1F044930473045A043A041863F687474703A2F2F63726C2E7573657274727573742E636F6D2F55534552547275737452534143657274696669636174696F6E417574686F726974792E63726C307606082B06010505070101046A3068303F06082B060105050730028633687474703A2F2F6372742E7573657274727573742E636F6D2F555345525472757374525341416464547275737443412E637274302506082B060105050730018619687474703A2F2F6F6373702E7573657274727573742E636F6D300D06092A864886F70D01010C0500038202010032BF61BD0E48C34FC7BA474DF89C781901DC131D806FFCC370B4529A31339A5752FB319E6BA4EF54AA898D401768F811107CD2CAB1F15586C7EEB3369186F63951BF46BF0FA0BAB4F77E49C42A36179EE468397AAF944E566FB27B3BBF0A86BDCDC5771C03B838B1A21F5F7EDB8ADC4648B6680ACFB2B5B4E234E467A93866095ED2B8FC9D283A174027C2724E29FD213C7CCF13FB962CC53144FD13EDD59BA96968777CEEE1FFA4F93638085339A284349C19F3BE0EACD52437EB23A878D0D3E7EF924764623922EFC6F711BE2285C6664424268E10328DC893AE079E833E2FD9F9F5468E63BEC1E6B4DCA6CD21A8860A95D92E85261AFDFCB1B657426D95D133F6391406824138F58F58DC805BA4D57D9578FDA79BFFFDC5A869AB26E7A7A405875BA9B7B8A3200B97A94585DDB38BE589378E290DFC0617F638400E42E41206FB7BF3C6116862DFE398F413D8154F8BB169D91060BC642AEA31B7E4B5A33A149B26E30B7BFD028EB699C138975936F6A874A286B65EEBC664EACFA0A3F96E9EBA2D11B6869808582DC9AC2564F25E75B438C1AE7F5A4683EA51CAB6F19911356BA56A7BC600B0E7F8BE64B2ADC8C2F1ACE351EAA493E079C8E18140C90A5BE1123CC1602AE397C08942CA94CF46981269BB98D0C2D30D724B476EE593C43228638743E4B0323E0AD34BBF239B1429412B9A041F932DF1C739483CAD5A127F
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\EAB040689A0D805B5D6FD654FC168CFF00B78BE3
Blob
030000000100000014000000EAB040689A0D805B5D6FD654FC168CFF00B78BE31400000001000000140000005379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB040000000100000010000000DB78CBD190952735D940BC80AC2432C00F0000000100000030000000435FE6564241D6B3828352EF9BE443D511C21F0AFB325C4038A5820F00D87774A8EF2193DDAAE065B2572FAF2BF0EE63190000000100000010000000EA6089055218053DD01E37E1D806EEDF18000000010000001000000045ED9BBC5E43D3B9ECD63C060DB78E5C20000000010000007B050000308205773082045FA003020102021013EA28705BF4ECED0C36630980614336300D06092A864886F70D01010C0500306F310B300906035504061302534531143012060355040A130B416464547275737420414231263024060355040B131D41646454727573742045787465726E616C20545450204E6574776F726B312230200603550403131941646454727573742045787465726E616C20434120526F6F74301E170D3030303533303130343833385A170D3230303533303130343833385A308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A028202010080126517360EC3DB08B3D0AC570D76EDCD27D34CAD508361E2AA204D092D6409DCCE899FCC3DA9ECF6CFC1DCF1D3B1D67B3728112B47DA39C6BC3A19B45FA6BD7D9DA36342B676F2A93B2B91F8E26FD0EC162090093EE2E874C918B491D46264DB7FA306F188186A90223CBCFE13F087147BF6E41F8ED4E451C61167460851CB8614543FBC33FE7E6C9CFF169D18BD518E35A6A766C87267DB2166B1D49B7803C0503AE8CCF0DCBC9E4CFEAF0596351F575AB7FFCEF93DB72CB6F654DDC8E7123A4DAE4C8AB75C9AB4B7203DCA7F2234AE7E3B68660144E7014E46539B3360F794BE5337907343F332C353EFDBAAFE744E69C76B8C6093DEC4C70CDFE132AECC933B517895678BEE3D56FE0CD0690F1B0FF325266B336DF76E47FA7343E57E0EA566B1297C3284635589C40DC19354301913ACD37D37A7EB5D3A6C355CDB41D712DAA9490BDFD8808A0993628EB566CF2588CD84B8B13FA4390FD9029EEB124C957CF36B05A95E1683CCB867E2E8139DCC5B82D34CB3ED5BFFDEE573AC233B2D00BF3555740949D849581A7F9236E651920EF3267D1C4D17BCC9EC4326D0BF415F40A94444F499E757879E501F5754A83EFD74632FB1506509E658422E431A4CB4F0254759FA041E93D426464A5081B2DEBE78B7FC6715E1C957841E0F63D6E962BAD65F552EEA5CC62808042539B80E2BA9F24C971C073F0D52F5EDEF2F820F0203010001A381F43081F1301F0603551D23041830168014ADBD987A34B426F7FAC42654EF03BDE024CB541A301D0603551D0E041604145379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF30110603551D20040A300830060604551D200030440603551D1F043D303B3039A037A0358633687474703A2F2F63726C2E7573657274727573742E636F6D2F416464547275737445787465726E616C4341526F6F742E63726C303506082B0601050507010104293027302506082B060105050730018619687474703A2F2F6F6373702E7573657274727573742E636F6D300D06092A864886F70D01010C050003820101009365F63783950F5EC3821C1FD677E73C8AC0AA09F0E90B26F1E0C26A75A1C779C9B95260C829120EF0AD03D609C476DFE5A68195A746DA8257A99592C5B68F03226C3377C17B32176E07CE5A14413A05241BF614063BA825240EBBCC2A75DDB970413F7CD0633621071F46FF60A491E167BCDE1F7E1914C9636791EA67076BB48F8BC06E437DC3A1806CB21EBC53857DDC90A1A4BC2DEF4672573505BFBB46BB6E6D3799B6FF239291C66E40F88F2956EA5FD55F1453ACF04F61EAF722CCA7560BE2B8341F26D97B1905683FBA3CD43806A2D3E68F0EE3B4716D4042C584B440952BF465A04879F61D8163969D4F75E0F87CE48EA9D1F2AD8AB38CC721CDC2EF
3040
cleaner-util.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
Proxima Nova Semibold (TrueType)
pns.ttf
3040
cleaner-util.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Чистилка
Publisher
Чистилка
3040
cleaner-util.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Чистилка
DisplayName
Чистилка
3040
cleaner-util.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Чистилка
DisplayIcon
C:\ProgramData\Чистилка\Чистилка.exe
3040
cleaner-util.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Чистилка
DisplayVersion
2.21.230
3040
cleaner-util.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Чистилка
InstallLocation
C:\ProgramData\Чистилка
3040
cleaner-util.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Чистилка
InstallDate
20190813
3040
cleaner-util.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Чистилка
QuietUninstallString
C:\ProgramData\Чистилка\Чистилка.exe /uninstall
3040
cleaner-util.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Чистилка
UninstallString
C:\ProgramData\Чистилка\Чистилка.exe /uninstall
3040
cleaner-util.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Чистилка
URLUpdateInfo
http://chistilka.com
3040
cleaner-util.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Чистилка
URLInfoAbout
http://chistilka.com
3040
cleaner-util.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Чистилка
NoModify
1
3040
cleaner-util.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Чистилка
NoRepair
1
3040
cleaner-util.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Чистилка
runmode
2
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\chst
ticrg
{946AC5EB-3AEE-4D7F-A887-B02344432F40}
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\chst
ticpap
C:\Users\admin\AppData\Local\Temp\cleaner-util.exe
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\chst
scsch_st
1565794586
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\chst
scsch_p
86400
3040
cleaner-util.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%systemroot%\system32\unregmp2.exe,-155
Play digital media including music, videos, CDs, and DVDs.
3040
cleaner-util.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%systemroot%\ehome\ehres.dll,-116
Opens your home entertainment option for digital and on-demand media, including TV, movies, music and pictures.
3040
cleaner-util.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%ProgramFiles%\Windows Sidebar\sidebar.exe,-1012
Add Desktop Gadgets that display personalized slideshows, news feeds, and other customized information.
3040
cleaner-util.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%windir%\system32\WindowsAnytimeUpgradeUI.exe,-2
A convenient and affordable way to upgrade Windows
3040
cleaner-util.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%ProgramFiles%\DVD Maker\DVDMaker.exe,-63385
Burn pictures and video to DVD.
3040
cleaner-util.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%windir%\system32\FXSRESM.dll,-115
Send and receive faxes or scan pictures and documents.
3040
cleaner-util.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%systemroot%\system32\XpsRchVw.exe,-103
View, digitally sign, and set permissions for XPS documents
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D3C056F-EE0F-45AC-85A2-8812A99E602F}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
IncludeRecommendedUpdates
0
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D3C056F-EE0F-45AC-85A2-8812A99E602F}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
AutoInstallMinorUpdates
0
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D3C056F-EE0F-45AC-85A2-8812A99E602F}Machine\Software\Policies\Microsoft\Windows Defender
DisableAntiSpyware
1
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D3C056F-EE0F-45AC-85A2-8812A99E602F}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
DisableRealtimeMonitoring
1
3040
cleaner-util.exe
write
HKEY_CURRENT_USER\Software\Microsoft\chst
st
A2CF525D00000000

Files activity

Executable files
2
Suspicious files
6
Text files
24
Unknown types
12

Dropped files

PID
Process
Filename
Type
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\sciter.dll
executable
MD5: 9d23e2946b37a886dd9b5ce146cdd280
SHA256: 9fabfffee8ef815f6e0f34c8909597ddf360ebff061151f18365202b774ceb20
3040
cleaner-util.exe
C:\ProgramData\Чистилка\Чистилка.exe
executable
MD5: 9987720f71d56835ac10087f0a5ee246
SHA256: 1452cc126d870dff026ec2a21ac3eb7a55962d4bf0d0608519608ad4db04cb4a
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex60D3.tmp\privileged\prefHelper\api.js
text
MD5: d556d42eb386e470f4687599554b9e5a
SHA256: bb94b36cc7234159fd47d2401a0c5571320c32280d0720cc3cb0048364d49f0e
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex814D.tmp\manifest.json
text
MD5: 5219743962bdee411d9cb74d8323128b
SHA256: 000f4ba7abeec2066f8b9407f9cbe4a0f0e5ec01921d40b5472f361ac8c5e287
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex814D.tmp\background.js
text
MD5: 640534c9d6c7ef10deb35c281451f129
SHA256: 4d2502a93d57570c2482bfdd51caa0dd8bb1e78dab27dd95d2b4cd0665938fc4
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex814D.tmp\META-INF\mozilla.sf
text
MD5: dec42d931fa71080140adb39a528f9aa
SHA256: 1978710fd1b668dc0884f9f7bbd46041149c1477ead938b72a890e29927875a3
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex814D.tmp\privileged\prefHelper\schema.json
text
MD5: cf60ce672c8328ddc5fb138c4d85f2f6
SHA256: 680ce3a705134f15e1e51b767f7638c7c0c3405b7dd48048f2b345c363d59095
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex814D.tmp\privileged\study\schema.json
text
MD5: f3b7cea6f4d69f5d59b7ea8b8d1c6f9c
SHA256: aa278c717dccd55768e8ddc48cc4c6195e4f7c4573c70603932af59990adfac2
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex814D.tmp\privileged\prefHelper\api.js
text
MD5: d556d42eb386e470f4687599554b9e5a
SHA256: bb94b36cc7234159fd47d2401a0c5571320c32280d0720cc3cb0048364d49f0e
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex814D.tmp\privileged\multipreffer\schema.json
text
MD5: 470335c6b31ea5882166ea0ed4103fd4
SHA256: 2dcc373fdf0f1b713b3d093d9a4a284836c6dfd14d22839041b4959d918de127
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex814D.tmp\META-INF\mozilla.rsa
cat
MD5: f0e4a031f33697d131f11ef01965f2ad
SHA256: a42144b11fa7441379f5b3336c7a9d04d07c9b59e15c3562430cd803cb3d57ac
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex814D.tmp\privileged\multipreffer\api.js
text
MD5: c18fd9742390e1f6661a031fb8df2beb
SHA256: c93538c99187cc8c3964b8f3b1b7c040862f0b2abdf908352301523a2829a114
3040
cleaner-util.exe
C:\Windows\System32\GroupPolicy\gpt.ini
text
MD5: 6427e1627fb697e73df506a2b5f77d72
SHA256: 3d7852515a0bf5fb21e7bd617587b28631bf49dfe21ba731d567c4c55a6f2f16
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex60D3.tmp\META-INF\manifest.mf
text
MD5: 9d5afaa76fab2aabd0a905278b2baf30
SHA256: 4a53875120469578da9898d3d1239cbffba80fd9a90691cedfc32ea616270c60
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex60D3.tmp\META-INF\mozilla.sf
text
MD5: dec42d931fa71080140adb39a528f9aa
SHA256: 1978710fd1b668dc0884f9f7bbd46041149c1477ead938b72a890e29927875a3
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex60D3.tmp\manifest.json
text
MD5: 5219743962bdee411d9cb74d8323128b
SHA256: 000f4ba7abeec2066f8b9407f9cbe4a0f0e5ec01921d40b5472f361ac8c5e287
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex60D3.tmp\privileged\study\api.js
text
MD5: 2f3a7f390171069e6a5fc4a1a2e8a40f
SHA256: a88ad5287868ed956bec3b2ade4a1db894d9226ee27e8fdfdd0dfe57838e4a28
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex60D3.tmp\background.js
text
MD5: 640534c9d6c7ef10deb35c281451f129
SHA256: 4d2502a93d57570c2482bfdd51caa0dd8bb1e78dab27dd95d2b4cd0665938fc4
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex60D3.tmp\variations.json
text
MD5: 11f13b3a30b6722ace6e875121bddb2b
SHA256: 5d7bfe6e6a5617abd8e5606e0a228dd9012c13925b40a72391b19f1bd5dd44ba
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex60D3.tmp\privileged\prefHelper\schema.json
text
MD5: cf60ce672c8328ddc5fb138c4d85f2f6
SHA256: 680ce3a705134f15e1e51b767f7638c7c0c3405b7dd48048f2b345c363d59095
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex60D3.tmp\privileged\multipreffer\schema.json
text
MD5: 470335c6b31ea5882166ea0ed4103fd4
SHA256: 2dcc373fdf0f1b713b3d093d9a4a284836c6dfd14d22839041b4959d918de127
3040
cleaner-util.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\30D802E0E248FEE17AAF4A62594CC75A
der
MD5: adab5c4df031fb9299f71ada7e18f613
SHA256: 7fa4ff68ec04a99d7528d5085f94907f4d1dd1c5381bacdc832ed5c960214676
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex60D3.tmp\privileged\multipreffer\api.js
text
MD5: c18fd9742390e1f6661a031fb8df2beb
SHA256: c93538c99187cc8c3964b8f3b1b7c040862f0b2abdf908352301523a2829a114
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex60D3.tmp\privileged\study\schema.json
text
MD5: f3b7cea6f4d69f5d59b7ea8b8d1c6f9c
SHA256: aa278c717dccd55768e8ddc48cc4c6195e4f7c4573c70603932af59990adfac2
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex60D3.tmp\META-INF\mozilla.rsa
cat
MD5: f0e4a031f33697d131f11ef01965f2ad
SHA256: a42144b11fa7441379f5b3336c7a9d04d07c9b59e15c3562430cd803cb3d57ac
3040
cleaner-util.exe
C:\ProgramData\Чистилка\config.dat
binary
MD5: 173a89ef37fceded94aacf1f5a5e6662
SHA256: a3bff6586e35ca5c0fac5b563e4a237641cdfd39dc312b5761fd050743a4acba
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cookies
sqlite
MD5: 160e09e0b2075bea45a09c1b8b4cab26
SHA256: 1a82f37fcdc316c48f97b73e3641cd50091f03584d10dde8ffbd29120fb01b2c
3040
cleaner-util.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
––
MD5:  ––
SHA256:  ––
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal
––
MD5:  ––
SHA256:  ––
3040
cleaner-util.exe
C:\ProgramData\Чистилка\config.dat
binary
MD5: ec988912395cfb56296c8db817259087
SHA256: cd05de2dcb8300d1d7c719645293dd16ad8c8118f89b43dd0e5ae135988a24e8
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex814D.tmp\privileged\study\api.js
text
MD5: 2f3a7f390171069e6a5fc4a1a2e8a40f
SHA256: a88ad5287868ed956bec3b2ade4a1db894d9226ee27e8fdfdd0dfe57838e4a28
3040
cleaner-util.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Чистилка\Чистилка Uninstall.lnk
lnk
MD5: 20fa67d7a7b2d60b60a58ba213095a21
SHA256: ebb672b7227f97641fd2a8485efc5b5195cd26c238b93056696b52c5e8c6b67c
3040
cleaner-util.exe
C:\ProgramData\Чистилка\settings.json
binary
MD5: 10c7a57e21d1691e4eec070766968ae3
SHA256: 54212c71fdf73ce365a0a6eac7d6ac759c0ca1199108db6a129537df72b765f8
3040
cleaner-util.exe
C:\Users\Public\Desktop\Чистилка.lnk
lnk
MD5: f0432350f311968238135aaf2d10070f
SHA256: 52aa5f98f0a87400edbac9611ae43f1d5d797c4993c7ef2f762fa92fc0f728c3
3040
cleaner-util.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Чистилка\Чистилка.lnk
lnk
MD5: f0432350f311968238135aaf2d10070f
SHA256: 52aa5f98f0a87400edbac9611ae43f1d5d797c4993c7ef2f762fa92fc0f728c3
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex814D.tmp\META-INF\manifest.mf
text
MD5: 9d5afaa76fab2aabd0a905278b2baf30
SHA256: 4a53875120469578da9898d3d1239cbffba80fd9a90691cedfc32ea616270c60
3040
cleaner-util.exe
C:\Windows\fonts\pns.ttf
ttf
MD5: df8c626474a73ab7a8b511655597c7c4
SHA256: 723091ba5a1b8e65164075516d69c00c71225c6dde61ffc32dd4047803ab42b5
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\cln5394.tmp
compressed
MD5: abee4387ab69da821ed9397cc651597d
SHA256: ac1dfd38d2fa61e28211e196cd3d754f6ccfb220e8c1beba52e54825cf615e22
3040
cleaner-util.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0968A1E3A40D2582E7FD463BAEB59CD
binary
MD5: 9ae0bfd18af8cfcb055cece37205d46f
SHA256: 8e040a5ad045225ec4eda371e4d4b520a0634aac97f977794853ec7e082929d3
3040
cleaner-util.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0968A1E3A40D2582E7FD463BAEB59CD
der
MD5: db78cbd190952735d940bc80ac2432c0
SHA256: 1a5174980a294a528a110726d5855650266c48d9883bea692b67b6d726da98c5
3040
cleaner-util.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\30D802E0E248FEE17AAF4A62594CC75A
binary
MD5: b5feff6d28a297d2b8913d493860d1c1
SHA256: 4b7a3fc479ca4e0516b504da4c07f85019dd8e17e32b15897bf9d2e83ee809b1
3040
cleaner-util.exe
C:\Users\admin\AppData\Local\Temp\fex814D.tmp\variations.json
text
MD5: 11f13b3a30b6722ace6e875121bddb2b
SHA256: 5d7bfe6e6a5617abd8e5606e0a228dd9012c13925b40a72391b19f1bd5dd44ba

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
17
TCP/UDP connections
20
DNS requests
12
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3040 cleaner-util.exe POST 200 52.11.108.211:80 http://api.amplitude.com/httpapi US
text
text
whitelisted
3040 cleaner-util.exe GET 301 62.109.11.221:80 http://chistilka.com/ RU
html
unknown
3040 cleaner-util.exe GET 200 91.199.212.52:80 http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt GB
der
whitelisted
3040 cleaner-util.exe POST 200 216.58.207.46:80 http://www.google-analytics.com/collect US
text
image
whitelisted
3040 cleaner-util.exe GET 200 140.82.35.84:80 http://140.82.35.84/?hwid=6aab97bbec0aedef4de3d798737c0c8b1249f454&lastError=lightStatError_http_error_12002&parter=&uid=76336796-f94d-4a44-be3e-dfe174129730-46d0e46f0105f2878e2f44ae94080ed6315c4de3&version=2.21.230 US
text
unknown
3040 cleaner-util.exe GET 404 54.37.81.78:80 http://54.37.81.78/api/appinstall?bt=BLOCK_OFFER&exhwid=6aab97bbec0aedef4de3d798737c0c8b1249f454&partner=&s_id=&uid=76336796-f94d-4a44-be3e-dfe174129730-46d0e46f0105f2878e2f44ae94080ed6315c4de3&v=2.21.230 FR
html
malicious
3040 cleaner-util.exe POST 200 52.11.108.211:80 http://api.amplitude.com/httpapi US
text
text
whitelisted
3040 cleaner-util.exe POST 200 52.11.108.211:80 http://api.amplitude.com/httpapi US
text
text
whitelisted
3040 cleaner-util.exe POST 200 52.11.108.211:80 http://api.amplitude.com/httpapi US
text
text
whitelisted
3040 cleaner-util.exe GET 200 140.82.35.84:80 http://140.82.35.84/?hwid=6aab97bbec0aedef4de3d798737c0c8b1249f454&lastError=configError&parter=&uid=76336796-f94d-4a44-be3e-dfe174129730-46d0e46f0105f2878e2f44ae94080ed6315c4de3&version=2.21.230 US
text
unknown
3040 cleaner-util.exe GET 200 140.82.35.84:80 http://140.82.35.84/?hwid=6aab97bbec0aedef4de3d798737c0c8b1249f454&lastError=configError&parter=&uid=76336796-f94d-4a44-be3e-dfe174129730-46d0e46f0105f2878e2f44ae94080ed6315c4de3&version=2.21.230 US
text
unknown
3040 cleaner-util.exe POST 200 52.11.108.211:80 http://api.amplitude.com/httpapi US
text
text
whitelisted
3040 cleaner-util.exe POST 200 52.11.108.211:80 http://api.amplitude.com/httpapi US
text
text
whitelisted
3040 cleaner-util.exe POST 200 52.11.108.211:80 http://api.amplitude.com/httpapi US
text
text
whitelisted
3040 cleaner-util.exe POST 200 52.11.108.211:80 http://api.amplitude.com/httpapi US
text
text
whitelisted
3040 cleaner-util.exe POST 200 52.11.108.211:80 http://api.amplitude.com/httpapi US
text
text
whitelisted
3040 cleaner-util.exe POST 200 52.11.108.211:80 http://api.amplitude.com/httpapi US
text
text
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3040 cleaner-util.exe 52.11.108.211:80 Amazon.com, Inc. US unknown
3040 cleaner-util.exe 62.109.11.221:80 JSC ISPsystem RU unknown
3040 cleaner-util.exe 62.109.11.221:443 JSC ISPsystem RU unknown
3040 cleaner-util.exe 91.199.212.52:80 Comodo CA Ltd GB unknown
3040 cleaner-util.exe 54.37.81.78:443 OVH SAS FR malicious
3040 cleaner-util.exe 216.58.207.46:80 Google Inc. US whitelisted
3040 cleaner-util.exe 62.109.13.130:443 JSC ISPsystem RU malicious
3040 cleaner-util.exe 140.82.35.84:80 US unknown
–– –– 54.37.81.78:80 OVH SAS FR malicious
3040 cleaner-util.exe 5.135.140.26:443 OVH SAS FR suspicious
–– –– 5.135.140.26:443 OVH SAS FR suspicious
–– –– 52.11.108.211:80 Amazon.com, Inc. US unknown

DNS requests

Domain IP Reputation
api.amplitude.com 52.25.58.207
52.11.108.211
52.38.44.186
52.10.250.124
52.25.38.243
35.167.14.103
52.34.163.79
52.24.113.255
whitelisted
chistilka.com 62.109.11.221
unknown
crt.sectigo.com 91.199.212.52
unknown
crt.usertrust.com 91.199.212.52
whitelisted
stat2.chistilka.com 54.37.81.78
malicious
www.google-analytics.com 216.58.207.46
whitelisted
chistilka.ru 62.109.13.130
malicious
dns.msftncsi.com No response whitelisted
update.chistilka.com 5.135.140.26
suspicious
pay.chistilka.com 5.135.140.26
suspicious

Threats

No threats detected.

Debug output strings

Process Message
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594
cleaner-util.exe [2019-08-13 15:56:34] M SnapshotSender.cpp:43 Stats send OK, code = 200, {"error":0,"msg":"OK"}, time: 1565704594