General Info Watch the FULL Interactive Analysis at ANY.RUN!

File name

Updater.exe

Verdict
Malicious activity
Analysis date
2/10/2019, 17:41:33
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

5bd49441c440e12e2ce4f845c097d45f

SHA1

2089a1a6cb1fa4939b2f485d957824b26e141c66

SHA256

2f47127fc0288f75ea114e09d9fcec0b77436b334d1ac2b35ca9733f1ce89bad

SSDEEP

12288:xyPiSl3xuVgz2XIlggggMkBdqi4LHgbPrNDqlEZB32EnBqQGsjhaHSPZYA+aFALM:3Sl3xuVHXuggggMRLsN2lEXHBqQG6hTv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
120 seconds
Additional time used
60 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • CCUpdate.exe (PID: 348)
  • CCleaner.exe (PID: 3184)
  • CCUpdate.exe (PID: 3580)
  • CCUpdate.exe (PID: 3388)
  • CCUpdate.exe (PID: 2904)
Loads the Task Scheduler COM API
  • CCUpdate.exe (PID: 3248)
  • CCleaner.exe (PID: 3184)
  • CCUpdate.exe (PID: 3580)
  • Updater.exe (PID: 2296)
Loads dropped or rewritten executable
  • CCUpdate.exe (PID: 3388)
  • Updater.exe (PID: 3092)
Downloads executable files from the Internet
  • CCUpdate.exe (PID: 3580)
  • Updater.exe (PID: 2296)
Starts itself from another location
  • CCUpdate.exe (PID: 348)
Low-level read access rights to disk partition
  • CCleaner.exe (PID: 3184)
  • CCUpdate.exe (PID: 3388)
  • CCUpdate.exe (PID: 3248)
  • CCUpdate.exe (PID: 3580)
  • Updater.exe (PID: 2296)
  • CCUpdate.exe (PID: 348)
  • CCUpdate.exe (PID: 2904)
  • Updater.exe (PID: 3092)
Executable content was dropped or overwritten
  • CCUpdate.exe (PID: 3580)
  • CCUpdate.exe (PID: 2904)
  • Updater.exe (PID: 3092)
  • Updater.exe (PID: 2296)
  • CCUpdate.exe (PID: 348)
Creates files in the program directory
  • CCUpdate.exe (PID: 3580)
  • CCUpdate.exe (PID: 3248)
  • CCUpdate.exe (PID: 348)
  • CCUpdate.exe (PID: 2904)
  • Updater.exe (PID: 2296)
Application launched itself
  • CCUpdate.exe (PID: 3580)
  • Updater.exe (PID: 2296)
Creates a software uninstall entry
  • Updater.exe (PID: 3092)
Reads settings of System Certificates
  • CCleaner.exe (PID: 3184)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win64 Executable (generic) (76.4%)
.exe
|   Win32 Executable (generic) (12.4%)
.exe
|   Generic Win/DOS Executable (5.5%)
.exe
|   DOS Executable Generic (5.5%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2019:02:04 13:09:11+01:00
PEType:
PE32
LinkerVersion:
14.15
CodeSize:
434176
InitializedDataSize:
162304
UninitializedDataSize:
null
EntryPoint:
0x4053f
OSVersion:
5.1
ImageVersion:
null
SubsystemVersion:
5.1
Subsystem:
Windows GUI
FileVersionNumber:
19.2.566.0
ProductVersionNumber:
19.2.566.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Windows, Latin1
CompanyName:
Piriform Software Ltd
FileDescription:
CCleaner emergency updater
FileVersion:
19.2.566.0
InternalName:
CCUpdate.exe
LegalCopyright:
Copyright © 2005-2019 Piriform Software Ltd
OriginalFileName:
CCUpdate.exe
ProductName:
Piriform Updater
ProductVersion:
19.2.566.0
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
04-Feb-2019 12:09:11
Detected languages
English - United States
Debug artifacts
D:\BUILD\work\01\ec99741887596299\BUILDS\Release\x86\CCUpdate.pdb
CompanyName:
Piriform Software Ltd
FileDescription:
CCleaner emergency updater
FileVersion:
19.2.566.0
InternalName:
CCUpdate.exe
LegalCopyright:
Copyright © 2005-2019 Piriform Software Ltd
OriginalFilename:
CCUpdate.exe
ProductName:
Piriform Updater
ProductVersion:
19.2.566.0
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000138
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
04-Feb-2019 12:09:11
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x00069F86 0x0006A000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.66588
.rdata 0x0006B000 0x0001E5DE 0x0001E600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.08765
.data 0x0008A000 0x00001FA4 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.81081
.rsrc 0x0008C000 0x00001E50 0x00002000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.73397
.reloc 0x0008E000 0x0000523C 0x00005400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 6.60273
Resources
1

4

Imports
    KERNEL32.dll

    ADVAPI32.dll

    ole32.dll

    OLEAUT32.dll

    WININET.dll

    WINHTTP.dll

    RPCRT4.dll

    Cabinet.dll

    DNSAPI.dll

    WS2_32.dll

    PSAPI.DLL

    USERENV.dll

    VERSION.dll

    WTSAPI32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
42
Monitored processes
9
Malicious processes
5
Suspicious processes
3

Behavior graph

+
start drop and start drop and start drop and start drop and start drop and start updater.exe no specs updater.exe updater.exe ccupdate.exe ccupdate.exe ccupdate.exe ccupdate.exe ccupdate.exe ccleaner.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3072
CMD
"C:\Users\admin\Updater.exe"
Path
C:\Users\admin\Updater.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Piriform Software Ltd
Description
CCleaner emergency updater
Version
19.2.566.0
Modules
Image
c:\users\admin\updater.exe
c:\systemroot\system32\ntdll.dll

PID
2296
CMD
"C:\Users\admin\Updater.exe"
Path
C:\Users\admin\Updater.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Piriform Software Ltd
Description
CCleaner emergency updater
Version
19.2.566.0
Modules
Image
c:\users\admin\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\qmgrprxy.dll

PID
3092
CMD
CCUpdate.exe /emupdater /applydll "C:\Program Files\CCleaner\Setup\4fe2c851-5ba7-4c3c-a924-923d5360507f.dll"
Path
C:\Users\admin\Updater.exe
Indicators
Parent process
Updater.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Piriform Software Ltd
Description
CCleaner emergency updater
Version
19.2.566.0
Modules
Image
c:\users\admin\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\program files\ccleaner\setup\4fe2c851-5ba7-4c3c-a924-923d5360507f.dll
c:\windows\system32\shell32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\ccupdate.exe

PID
2904
CMD
"C:\Users\admin\AppData\Local\Temp\\CCUpdate.exe" /emupdater /applycab "C:\Users\admin\AppData\Local\Temp\ccEB32.tmp"
Path
C:\Users\admin\AppData\Local\Temp\CCUpdate.exe
Indicators
Parent process
Updater.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Piriform Ltd
Description
CCleaner emergency updater
Version
17, 8, 77, 0
Modules
Image
c:\users\admin\appdata\local\temp\ccupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\apphelp.dll
c:\program files\ccleaner\setup\50156eff-4195-4e60-9a34-37df63e3c58f\ccupdate.exe

PID
348
CMD
CCUpdate.exe /emupdater /applyupdate "C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\update.xml"
Path
C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\CCUpdate.exe
Indicators
Parent process
CCUpdate.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Piriform Ltd
Description
CCleaner emergency updater
Version
18.6.553.0
Modules
Image
c:\program files\ccleaner\setup\50156eff-4195-4e60-9a34-37df63e3c58f\ccupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\apphelp.dll
c:\program files\ccleaner\ccupdate.exe

PID
3580
CMD
dummy /emupdater /reg
Path
C:\Program Files\CCleaner\CCUpdate.exe
Indicators
Parent process
CCUpdate.exe
User
admin
Integrity Level
HIGH
Exit code
1237
Version:
Company
Piriform Ltd
Description
CCleaner emergency updater
Version
18.6.553.0
Modules
Image
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\clbcatq.dll
c:\users\admin\updater.exe
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msutb.dll
c:\windows\system32\msctf.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winsta.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernelbase.dll
c:\systemroot\system32\ntdll.dll
c:\program files\ccleaner\ccupdate.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\rsaenh.dll
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\qmgrprxy.dll

PID
3388
CMD
CCUpdate.exe /emupdater /applydll "C:\Program Files\CCleaner\Setup\2250eff8-d9a3-4ac2-bba8-e8ee42ef867f.dll"
Path
C:\Program Files\CCleaner\CCUpdate.exe
Indicators
Parent process
CCUpdate.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Piriform Ltd
Description
CCleaner emergency updater
Version
18.6.553.0
Modules
Image
c:\program files\ccleaner\ccupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\program files\ccleaner\setup\2250eff8-d9a3-4ac2-bba8-e8ee42ef867f.dll
c:\windows\system32\shell32.dll

PID
3248
CMD
dummy /emupdater
Path
C:\Program Files\CCleaner\CCUpdate.exe
Indicators
Parent process
CCUpdate.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Piriform Software Ltd
Description
CCleaner emergency updater
Version
19.2.566.0
Modules
Image
c:\program files\ccleaner\ccupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\qmgrprxy.dll

PID
3184
CMD
dummy /ccupdate
Path
C:\Program Files\CCleaner\CCleaner.exe
Indicators
Parent process
Updater.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Piriform Ltd
Description
CCleaner
Version
5.46.0.6652
Modules
Image
c:\program files\ccleaner\ccleaner.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winspool.drv
c:\windows\system32\winmm.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\esent.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll

Registry activity

Total events
205
Read events
182
Write events
23
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
2296
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Piriform\CCleaner
Patches
5=1549816955
2296
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Piriform\CCleaner
LastAppliedPatchId
5
3092
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Piriform\CCleaner
MigrationCookie
w6|v5.35.0.6210
3092
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CCleaner
VersionMajor
5
3092
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CCleaner
VersionMinor
46
3092
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CCleaner
DisplayVersion
5.46
348
CCUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Piriform\CCleaner
UpdateVersion
2
348
CCUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Piriform\CCleaner
MicroUpdates
10=1549816956
3580
CCUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Piriform\CCleaner
Patches
5=1549816955
3580
CCUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Piriform\CCleaner
UpdateVersion
10
3580
CCUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Piriform\CCleaner
MicroUpdates
10=1549816956
3580
CCUpdate.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
PendingFileRenameOperations
\??\C:\Program Files\CCleaner\CCUpdate.exe.154981695637502
3580
CCUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Piriform\CCleaner\EmUpdatePending
MicroUpdates
10=1549816956
3184
CCleaner.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US

Files activity

Executable files
183
Suspicious files
3
Text files
5
Unknown types
0

Dropped files

PID Process Filename Type
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1049.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1087.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1087.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1090.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1062.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1109.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1068.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1092.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1071.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1104.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1061.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1104.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1081.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1079.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1067.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1102.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1092.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1104.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1065.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1068.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1081.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1092.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1063.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1068.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1109.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1081.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1066.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1079.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1102.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1090.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1048.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1067.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1079.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1102.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1060.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1071.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1087.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-9999.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1057.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1067.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-2070.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-2070.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1058.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1071.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-2052.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-2052.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1048.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1066.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1155.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-5146.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1055.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1065.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1155.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1155.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1049.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1066.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1110.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-3098.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1050.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1065.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-2052.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-2074.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1051.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1063.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1110.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1110.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1053.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1063.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-2070.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\CCUpdate.exe executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1054.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1062.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-2074.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\CCleaner.exe.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1052.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1062.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1109.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1028.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1035.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1060.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-9999.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1028.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1036.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1059.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-9999.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\uninst.exe executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1043.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1060.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-3098.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1025.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1038.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1059.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-2074.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1026.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1042.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1054.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-5146.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1025.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1045.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1058.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1035.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\uninst.exe.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1041.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1057.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1035.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1030.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1044.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1055.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-3098.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1031.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1040.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1057.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-5146.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1026.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1046.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1054.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1029.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1030.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1037.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1058.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1029.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\CCleaner.exe executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1027.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1055.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1027.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1032.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1031.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1051.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1027.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1031.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\uninst.exe executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1052.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1043.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1032.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1032.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1049.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1061.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1034.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1030.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1051.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1053.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1037.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1025.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1050.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1061.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1037.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1026.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1050.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1045.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1034.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1034.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1052.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1043.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1036.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1028.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1044.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1053.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1036.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1029.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1046.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1045.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1042.dll executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\CCleaner64.exe executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1048.dll executable
3580 CCUpdate.exe C:\Program Files\CCleaner\Setup\2250eff8-d9a3-4ac2-bba8-e8ee42ef867f.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1038.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\CCUpdate.exe executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1040.dll executable
3580 CCUpdate.exe C:\Program Files\CCleaner\Setup\c9efc196-d492-432e-ac37-3c3a8fa1be16\Updater.exe executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1042.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\CCleaner.exe executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1040.dll.154981695032801 executable
3580 CCUpdate.exe C:\Program Files\CCleaner\CCUpdate.exe.154981695637502 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1041.dll executable
3092 Updater.exe C:\Users\admin\AppData\Local\Temp\ccupdate.exe executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1046.dll executable
3580 CCUpdate.exe C:\Program Files\CCleaner\CCUpdate.exe executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1038.dll executable
2296 Updater.exe C:\Program Files\CCleaner\Setup\4fe2c851-5ba7-4c3c-a924-923d5360507f.dll executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1044.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1041.dll.154981695032801 executable
348 CCUpdate.exe C:\Program Files\CCleaner\Lang\lang-1090.dll.154981695032801 executable
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\Lang\lang-1059.dll executable
3580 CCUpdate.exe C:\Program Files\CCleaner\Setup\c9efc196-d492-432e-ac37-3c3a8fa1be16\update.xml xml
2296 Updater.exe C:\Program Files\CCleaner\Setup\f64f086c-4478-476c-aeb0-138d37e685a3.cab compressed
3388 CCUpdate.exe C:\Users\admin\AppData\Local\Temp\asw9dee351f391768a9.tmp ––
3388 CCUpdate.exe C:\Users\admin\AppData\Local\Temp\aswd66b3b10699b33fa.tmp ––
3388 CCUpdate.exe C:\Users\admin\AppData\Local\Temp\aswe453bfda801a6806.tmp ––
3092 Updater.exe C:\Users\admin\AppData\Local\Temp\asw691ad9d01f6f37d0.tmp ––
3580 CCUpdate.exe C:\Program Files\CCleaner\Setup\0a663502-9002-4cc1-ba54-6565d86ead06.ini ––
3248 CCUpdate.exe C:\Program Files\CCleaner\Setup\905c729f-33ba-41a4-af70-07b76d0ec097\update.xml ––
3248 CCUpdate.exe C:\Program Files\CCleaner\Setup\de9c119e-166b-4fa1-b68d-0ffb73373306.cab ––
3248 CCUpdate.exe C:\Program Files\CCleaner\Setup\bcede19f-dbb5-46c7-929e-7193d295ff2d.xml ––
3248 CCUpdate.exe C:\Program Files\CCleaner\Setup\0d0d3d0c-e305-4d40-b2ac-bf6f8cf132bd.ini ini
2296 Updater.exe C:\Program Files\CCleaner\Setup\5ac8f3f1-c12a-40cb-ab05-9d44fe812f5d\update.xml ––
2296 Updater.exe C:\Program Files\CCleaner\Setup\160fc5d4-c1c9-45f3-aadc-84bc09e83727.xml ––
3092 Updater.exe C:\Users\admin\AppData\Local\Temp\asw dd72618d923bc31.tmp ––
2904 CCUpdate.exe C:\Program Files\CCleaner\Setup\50156eff-4195-4e60-9a34-37df63e3c58f\update.xml text
3580 CCUpdate.exe C:\Program Files\CCleaner\CCUpdate.ini text
3580 CCUpdate.exe C:\Program Files\CCleaner\Setup\a2adb74c-2a70-4bd0-b907-fef8a7ff81a5.cab compressed
3580 CCUpdate.exe C:\Program Files\CCleaner\Setup\710042a3-e137-43c6-ac95-bdff5eefb4ad\update.xml xml
3092 Updater.exe C:\Users\admin\AppData\Local\Temp\asw1b477bb6724673d0.tmp ––
3092 Updater.exe C:\Users\admin\AppData\Local\Temp\ccEB32.tmp ––
3092 Updater.exe C:\Users\admin\AppData\Local\Temp\aswa7af0f49bef25ec4.tmp ––
3580 CCUpdate.exe C:\Program Files\CCleaner\Setup\487f6915-cb10-4a9e-8a9e-931970b8944a.cab compressed
3092 Updater.exe C:\Users\admin\AppData\Local\Temp\asw957fa7202f244137.tmp ––
3092 Updater.exe C:\Users\admin\AppData\Local\Temp\ccuE584.tmp ––
3092 Updater.exe C:\Users\admin\AppData\Local\Temp\aswdae6b8ea78dda1ea.tmp ––
3092 Updater.exe C:\Users\admin\AppData\Local\Temp\aswea80508d27bb0d39.tmp ––
3092 Updater.exe C:\Users\admin\AppData\Local\Temp\asw5c85ce97a1798d17.tmp ––
3092 Updater.exe C:\Users\admin\AppData\Local\Temp\asw57f62917b0454b92.tmp ––
3092 Updater.exe C:\Users\admin\AppData\Local\Temp\asw4d60b1e386d9b3aa.tmp ––
3580 CCUpdate.exe C:\Program Files\CCleaner\Setup\8e801dee-4860-4772-a01c-c551cb3f5be9.xml ––
2296 Updater.exe C:\Program Files\CCleaner\Setup\05125a60-dfd0-4173-bfaa-8e6b3aeb2529.ini ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
44
TCP/UDP connections
25
DNS requests
43
Threats
2

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2296 Updater.exe GET 200 5.62.38.21:80 http://ip-info.ff.avast.com/v2/info NL
text
whitelisted
2296 Updater.exe HEAD 200 2.16.186.49:80 http://emupdate.avcdn.net/files/emupdate/pong.txt unknown
––
––
whitelisted
2296 Updater.exe GET 200 2.16.186.56:80 http://ccleaner.tools.avcdn.net/tools/ccleaner/update/patches.ini unknown
ini
malicious
2296 Updater.exe GET 200 2.16.186.56:80 http://ccleaner.tools.avcdn.net/tools/ccleaner/update/20180205.dll unknown
executable
malicious
3092 Updater.exe GET 200 5.62.38.21:80 http://ip-info.ff.avast.com/v2/info NL
text
whitelisted
3092 Updater.exe GET 200 216.58.207.78:80 http://www.google-analytics.com/collect?v=1&tid=UA-58120669-26&t=event&cid=97b7721c4994e2556ff6a439510f665db45337a341a47e15f4997584423bf714&ec=20180910&ea=executed&el=1&ev=0 US
image
whitelisted
3092 Updater.exe GET 200 216.58.207.78:80 http://www.google-analytics.com/collect?v=1&tid=UA-58120669-26&t=event&cid=97b7721c4994e2556ff6a439510f665db45337a341a47e15f4997584423bf714&ec=20180910&ea=version&el=5.35.0.6210&ev=0 US
image
whitelisted
3092 Updater.exe GET 200 216.58.207.78:80 http://www.google-analytics.com/collect?v=1&tid=UA-58120669-26&t=event&cid=97b7721c4994e2556ff6a439510f665db45337a341a47e15f4997584423bf714&ec=20180910&ea=version_check&el=1&ev=0 US
image
whitelisted
3092 Updater.exe GET 200 216.58.207.78:80 http://www.google-analytics.com/collect?v=1&tid=UA-58120669-26&t=event&cid=97b7721c4994e2556ff6a439510f665db45337a341a47e15f4997584423bf714&ec=20180910&ea=version_check_1_new&el=1&ev=0 US
image
whitelisted
3092 Updater.exe GET 200 216.58.207.78:80 http://www.google-analytics.com/collect?v=1&tid=UA-58120669-26&t=event&cid=97b7721c4994e2556ff6a439510f665db45337a341a47e15f4997584423bf714&ec=20180910&ea=edition&el=Free&ev=0 US
image
whitelisted
3092 Updater.exe GET 200 2.16.186.56:80 http://ccleaner.tools.avcdn.net/tools/ccleaner/update/20180205-ccupdate-5_40_r4.cab unknown
compressed
malicious
3092 Updater.exe GET 200 216.58.207.78:80 http://www.google-analytics.com/collect?v=1&tid=UA-58120669-26&t=event&cid=97b7721c4994e2556ff6a439510f665db45337a341a47e15f4997584423bf714&ec=20180910&ea=cab-downloaded-ccu&el=1&ev=0 US
image
whitelisted
3092 Updater.exe GET 200 216.58.207.78:80 http://www.google-analytics.com/collect?v=1&tid=UA-58120669-26&t=event&cid=97b7721c4994e2556ff6a439510f665db45337a341a47e15f4997584423bf714&ec=20180910&ea=cab-extract&el=1&ev=0 US
image
whitelisted
3092 Updater.exe GET 200 2.16.186.56:80 http://ccleaner.tools.avcdn.net/tools/ccleaner/update/20180205-ccleaner-5_46.cab unknown
compressed
malicious
3092 Updater.exe GET 200 216.58.207.78:80 http://www.google-analytics.com/collect?v=1&tid=UA-58120669-26&t=event&cid=97b7721c4994e2556ff6a439510f665db45337a341a47e15f4997584423bf714&ec=20180910&ea=cab-downloaded-cc&el=1&ev=0 US
image
whitelisted
2904 CCUpdate.exe GET 200 5.62.38.21:80 http://ip-info.ff.avast.com/v2/info NL
text
whitelisted
348 CCUpdate.exe GET 200 5.62.38.21:80 http://ip-info.ff.avast.com/v2/info NL
text
whitelisted
3580 CCUpdate.exe GET 200 5.62.38.21:80 http://ip-info.ff.avast.com/v2/info NL
text
whitelisted
3580 CCUpdate.exe GET 200 2.16.186.73:80 http://emupdate.avcdn.net/files/emupdate/pong.txt unknown
text
whitelisted
3580 CCUpdate.exe GET 200 2.16.186.56:80 http://ccleaner.tools.avcdn.net/tools/ccleaner/update/patches.ini unknown
ini
malicious
3580 CCUpdate.exe GET 200 2.16.186.56:80 http://ccleaner.tools.avcdn.net/tools/ccleaner/update/20180205.dll unknown
executable
malicious
3388 CCUpdate.exe GET 200 5.62.38.21:80 http://ip-info.ff.avast.com/v2/info NL
text
whitelisted
3388 CCUpdate.exe GET 200 216.58.207.78:80 http://www.google-analytics.com/collect?v=1&tid=UA-58120669-26&t=event&cid=97b7721c4994e2556ff6a439510f665db45337a341a47e15f4997584423bf714&ec=20180910&ea=executed&el=1&ev=0 US
image
whitelisted
3388 CCUpdate.exe GET 200 216.58.207.78:80 http://www.google-analytics.com/collect?v=1&tid=UA-58120669-26&t=event&cid=97b7721c4994e2556ff6a439510f665db45337a341a47e15f4997584423bf714&ec=20180910&ea=version&el=5.46.0.6652&ev=0 US
image
whitelisted
3388 CCUpdate.exe GET 200 216.58.207.78:80 http://www.google-analytics.com/collect?v=1&tid=UA-58120669-26&t=event&cid=97b7721c4994e2556ff6a439510f665db45337a341a47e15f4997584423bf714&ec=20180910&ea=version_check&el=0&ev=0 US
image
whitelisted
3580 CCUpdate.exe GET 200 2.16.186.56:80 http://ccleaner.tools.avcdn.net/tools/ccleaner/update/updates.xml unknown
xml
malicious
3580 CCUpdate.exe GET 200 2.16.186.56:80 http://ccleaner.tools.avcdn.net/tools/ccleaner/update/ccprobe.cab unknown
compressed
malicious
3580 CCUpdate.exe GET 404 91.213.143.7:80 http://public.avast.com/dev/avast_proj/CCProbeStub.cab CZ
xml
unknown
–– –– HEAD 404 91.213.143.7:80 http://public.avast.com/dev/avast_proj/CCProbeStub.cab CZ
––
––
unknown
3580 CCUpdate.exe GET 200 2.16.186.56:80 http://ccleaner.tools.avcdn.net/tools/ccleaner/update/ccupdate10.cab unknown
compressed
malicious
3580 CCUpdate.exe GET 200 216.58.207.78:80 http://www.google-analytics.com/collect?v=1&tid=UA-58120669-26&dh=uupdates.ccleaner.com&cid=00000000-0000-4000-8000-d6f7f2be5127&t=event&ec=uVersion-10&ea=0&el=6575-0 US
image
whitelisted
3248 CCUpdate.exe GET 200 5.62.38.21:80 http://ip-info.ff.avast.com/v2/info NL
text
whitelisted
3248 CCUpdate.exe HEAD 200 2.16.186.73:80 http://emupdate.avcdn.net/files/emupdate/pong.txt unknown
––
––
whitelisted
3248 CCUpdate.exe GET 200 2.16.186.56:80 http://ccleaner.tools.avcdn.net/tools/ccleaner/update/patches.ini unknown
ini
malicious
3248 CCUpdate.exe GET 200 2.16.186.56:80 http://ccleaner.tools.avcdn.net/tools/ccleaner/update/updates.xml unknown
xml
malicious
3248 CCUpdate.exe GET 200 2.16.186.56:80 http://ccleaner.tools.avcdn.net/tools/ccleaner/update/ccprobe.cab unknown
compressed
malicious
3248 CCUpdate.exe GET 404 91.213.143.7:80 http://public.avast.com/dev/avast_proj/CCProbeStub.cab CZ
xml
unknown
–– –– HEAD 404 91.213.143.7:80 http://public.avast.com/dev/avast_proj/CCProbeStub.cab CZ
––
––
unknown
3092 Updater.exe GET 200 216.58.207.78:80 http://www.google-analytics.com/collect?v=1&tid=UA-58120669-26&t=event&cid=97b7721c4994e2556ff6a439510f665db45337a341a47e15f4997584423bf714&ec=20180910&ea=ini_file&el=0&ev=0 US
image
whitelisted
3092 Updater.exe GET 200 216.58.207.78:80 http://www.google-analytics.com/collect?v=1&tid=UA-58120669-26&t=event&cid=97b7721c4994e2556ff6a439510f665db45337a341a47e15f4997584423bf714&ec=20180910&ea=finished&el=1&ev=0 US
image
whitelisted
2296 Updater.exe GET 200 2.16.186.56:80 http://ccleaner.tools.avcdn.net/tools/ccleaner/update/updates.xml unknown
xml
malicious
2296 Updater.exe GET 200 2.16.186.56:80 http://ccleaner.tools.avcdn.net/tools/ccleaner/update/ccprobe.cab unknown
compressed
malicious
2296 Updater.exe GET 404 91.213.143.7:80 http://public.avast.com/dev/avast_proj/CCProbeStub.cab CZ
xml
unknown
–– –– HEAD 404 91.213.143.7:80 http://public.avast.com/dev/avast_proj/CCProbeStub.cab CZ
––
––
unknown

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2296 Updater.exe 5.62.38.21:80 AVAST Software s.r.o. NL unknown
2296 Updater.exe 2.16.186.73:80 Akamai International B.V. –– whitelisted
2296 Updater.exe 2.16.186.49:80 Akamai International B.V. –– whitelisted
2296 Updater.exe 2.16.186.56:80 Akamai International B.V. –– whitelisted
3092 Updater.exe 5.62.38.21:80 AVAST Software s.r.o. NL unknown
3092 Updater.exe 216.58.207.78:80 Google Inc. US whitelisted
3092 Updater.exe 2.16.186.56:80 Akamai International B.V. –– whitelisted
2904 CCUpdate.exe 5.62.38.21:80 AVAST Software s.r.o. NL unknown
348 CCUpdate.exe 5.62.38.21:80 AVAST Software s.r.o. NL unknown
3580 CCUpdate.exe 5.62.38.21:80 AVAST Software s.r.o. NL unknown
3580 CCUpdate.exe 2.16.186.73:80 Akamai International B.V. –– whitelisted
3580 CCUpdate.exe 2.16.186.56:80 Akamai International B.V. –– whitelisted
3388 CCUpdate.exe 5.62.38.21:80 AVAST Software s.r.o. NL unknown
3388 CCUpdate.exe 216.58.207.78:80 Google Inc. US whitelisted
3580 CCUpdate.exe 91.213.143.7:80 AVAST Software s.r.o. CZ unknown
3580 CCUpdate.exe 216.58.207.78:80 Google Inc. US whitelisted
3248 CCUpdate.exe 5.62.38.21:80 AVAST Software s.r.o. NL unknown
3248 CCUpdate.exe 2.16.186.73:80 Akamai International B.V. –– whitelisted
3248 CCUpdate.exe 2.16.186.56:80 Akamai International B.V. –– whitelisted
3248 CCUpdate.exe 91.213.143.7:80 AVAST Software s.r.o. CZ unknown
2296 Updater.exe 91.213.143.7:80 AVAST Software s.r.o. CZ unknown
3184 CCleaner.exe 5.62.40.203:443 AVAST Software s.r.o. DE unknown

DNS requests

Domain IP Reputation
ip-info.ff.avast.com 5.62.38.20
5.62.38.21
whitelisted
emupdate.avcdn.net 2.16.186.73
2.16.186.49
whitelisted
dns.msftncsi.com 131.107.255.255
whitelisted
ccleaner.tools.avcdn.net 2.16.186.59
2.16.186.56
malicious
www.google-analytics.com 216.58.207.78
whitelisted
public.avast.com 91.213.143.7
unknown
analytics.ff.avast.com 5.62.40.203
77.234.45.54
whitelisted

Threats

PID Process Class Message
2296 Updater.exe Potential Corporate Privacy Violation ET POLICY PE EXE or DLL Windows file download HTTP
3580 CCUpdate.exe Potential Corporate Privacy Violation ET POLICY PE EXE or DLL Windows file download HTTP

Debug output strings

No debug info.