General Info

File name

BleachBit-2.1-setup-English.exe

Full analysis
https://app.any.run/tasks/0f018fdf-4fae-4ad4-8973-838020cb932f
Verdict
Malicious activity
Analysis date
2/11/2019, 12:06:54
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5

9d8be4d5b2c0f0cbd744e7b0014e7f08

SHA1

690f8e86dc8b1d2e9760e7ffbaa483c048acc61b

SHA256

49611a37cac1741d9209d32403abff9140c7cf3a81295a27100338298a68f82a

SSDEEP

196608:TOlHwcm4TaenIAxWmt6LxPnYQJOhZLV3z:TqJTakt6lPpJ0hz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads the Task Scheduler COM API
  • explorer.exe (PID: 3172)
Starts NET.EXE for service management
  • BleachBit.exe (PID: 4064)
Actions looks like stealing of personal data
  • BleachBit.exe (PID: 4064)
Uses NET.EXE to stop Windows Update service
  • BleachBit.exe (PID: 4064)
Application was dropped or rewritten from another process
  • BleachBit.exe (PID: 4064)
Loads dropped or rewritten executable
  • BleachBit.exe (PID: 4064)
  • BleachBit-2.1-setup-English.exe (PID: 3152)
  • BleachBit-2.1-setup-English.exe (PID: 3856)
Removes files from Windows directory
  • BleachBit.exe (PID: 4064)
Uses TASKKILL.EXE to kill process
  • BleachBit.exe (PID: 4064)
Creates files in the user directory
  • BleachBit.exe (PID: 4064)
Loads Python modules
  • BleachBit.exe (PID: 4064)
Creates a software uninstall entry
  • BleachBit-2.1-setup-English.exe (PID: 3152)
Application launched itself
  • BleachBit-2.1-setup-English.exe (PID: 3856)
Executable content was dropped or overwritten
  • BleachBit-2.1-setup-English.exe (PID: 3856)
  • BleachBit-2.1-setup-English.exe (PID: 3152)
Creates files in the program directory
  • BleachBit-2.1-setup-English.exe (PID: 3152)

No info indicators.

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (67.4%)
.dll
|   Win32 Dynamic Link Library (generic) (14.2%)
.exe
|   Win32 Executable (generic) (9.7%)
.exe
|   Generic Win/DOS Executable (4.3%)
.exe
|   DOS Executable Generic (4.3%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:12:15 23:24:32+01:00
PEType:
PE32
LinkerVersion:
6
CodeSize:
25088
InitializedDataSize:
118784
UninitializedDataSize:
1024
EntryPoint:
0x3328
OSVersion:
4
ImageVersion:
6
SubsystemVersion:
4
Subsystem:
Windows GUI
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
15-Dec-2018 22:24:32
Detected languages
English - United States
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000D8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
15-Dec-2018 22:24:32
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x00006077 0x00006200 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.40386
.rdata 0x00008000 0x00001250 0x00001400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.04481
.data 0x0000A000 0x0001A838 0x00000400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 5.22445
.ndata 0x00025000 0x0001E000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rsrc 0x00043000 0x00004C48 0x00004E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.72993
Resources
1

2

3

4

5

6

7

102

103

104

105

106

107

110

111

Imports
    KERNEL32.dll

    USER32.dll

    GDI32.dll

    SHELL32.dll

    ADVAPI32.dll

    COMCTL32.dll

    ole32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
53
Monitored processes
11
Malicious processes
3
Suspicious processes
0

Behavior graph

+
start drop and start bleachbit-2.1-setup-english.exe bleachbit-2.1-setup-english.exe bleachbit.exe taskkill.exe no specs explorer.exe no specs explorer.exe no specs explorer.exe no specs net.exe no specs net1.exe no specs net.exe no specs net1.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3856
CMD
"C:\Users\admin\Desktop\BleachBit-2.1-setup-English.exe"
Path
C:\Users\admin\Desktop\BleachBit-2.1-setup-English.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\desktop\bleachbit-2.1-setup-english.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\users\admin\appdata\local\temp\nstf64d.tmp\system.dll
c:\users\admin\appdata\local\temp\nstf64d.tmp\userinfo.dll
c:\users\admin\appdata\local\temp\nstf64d.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\local\temp\nstf64d.tmp\langdll.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nstf64d.tmp\nsdialogs.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll

PID
3152
CMD
"C:\Users\admin\Desktop\BleachBit-2.1-setup-English.exe" /UAC:3010E /NCRC
Path
C:\Users\admin\Desktop\BleachBit-2.1-setup-English.exe
Indicators
Parent process
BleachBit-2.1-setup-English.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\desktop\bleachbit-2.1-setup-english.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\users\admin\appdata\local\temp\nsh19b3.tmp\system.dll
c:\users\admin\appdata\local\temp\nsh19b3.tmp\userinfo.dll
c:\users\admin\appdata\local\temp\nsh19b3.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\local\temp\nsh19b3.tmp\langdll.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\bleachbit\uninstall.exe
c:\program files\bleachbit\bleachbit.exe
c:\program files\bleachbit\bleachbit_console.exe
c:\users\admin\appdata\local\temp\nsh19b3.tmp\nsdialogs.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\netutils.dll

PID
4064
CMD
"C:\Program Files\BleachBit\BleachBit.exe"
Path
C:\Program Files\BleachBit\BleachBit.exe
Indicators
Parent process
BleachBit-2.1-setup-English.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Free space and maintain privacy
Version
2.1
Modules
Image
c:\program files\bleachbit\bleachbit.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\bleachbit\python27.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\program files\bleachbit\glib._glib.pyd
c:\program files\bleachbit\libglib-2.0-0.dll
c:\program files\bleachbit\intl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\bleachbit\libgthread-2.0-0.dll
c:\program files\bleachbit\gobject._gobject.pyd
c:\program files\bleachbit\libgobject-2.0-0.dll
c:\program files\bleachbit\gtk._gtk.pyd
c:\program files\bleachbit\libcairo-2.dll
c:\program files\bleachbit\freetype6.dll
c:\program files\bleachbit\libfontconfig-1.dll
c:\program files\bleachbit\libexpat-1.dll
c:\program files\bleachbit\libpng14-14.dll
c:\program files\bleachbit\zlib1.dll
c:\windows\system32\msimg32.dll
c:\program files\bleachbit\libgdk-win32-2.0-0.dll
c:\program files\bleachbit\libgdk_pixbuf-2.0-0.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\program files\bleachbit\libgio-2.0-0.dll
c:\windows\system32\dnsapi.dll
c:\program files\bleachbit\libgmodule-2.0-0.dll
c:\program files\bleachbit\libpango-1.0-0.dll
c:\program files\bleachbit\libpangocairo-1.0-0.dll
c:\program files\bleachbit\libpangoft2-1.0-0.dll
c:\program files\bleachbit\libpangowin32-1.0-0.dll
c:\program files\bleachbit\libgtk-win32-2.0-0.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\bleachbit\libatk-1.0-0.dll
c:\windows\system32\winspool.drv
c:\program files\bleachbit\cairo._cairo.pyd
c:\program files\bleachbit\gio._gio.pyd
c:\program files\bleachbit\pango.pyd
c:\program files\bleachbit\atk.pyd
c:\program files\bleachbit\pangocairo.pyd
c:\windows\system32\cryptbase.dll
c:\windows\system32\sspicli.dll
c:\program files\bleachbit\_hashlib.pyd
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\bleachbit\pywintypes27.dll
c:\windows\system32\oleaut32.dll
c:\program files\bleachbit\win32file.pyd
c:\windows\system32\mswsock.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\program files\bleachbit\_sqlite3.pyd
c:\program files\bleachbit\sqlite3.dll
c:\program files\bleachbit\win32api.pyd
c:\windows\system32\version.dll
c:\windows\system32\secur32.dll
c:\program files\bleachbit\win32gui.pyd
c:\program files\bleachbit\win32process.pyd
c:\windows\system32\psapi.dll
c:\program files\bleachbit\_ctypes.pyd
c:\program files\bleachbit\pythoncom27.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\bleachbit\win32com.shell.shell.pyd
c:\windows\system32\profapi.dll
c:\program files\bleachbit\_socket.pyd
c:\program files\bleachbit\_ssl.pyd
c:\program files\bleachbit\psutil._psutil_windows.pyd
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wtsapi32.dll
c:\program files\bleachbit\pyexpat.pyd
c:\program files\bleachbit\lib\gtk-2.0\2.10.0\engines\libwimp.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\mscms.dll
c:\windows\system32\userenv.dll
c:\windows\system32\icm32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\program files\bleachbit\unicodedata.pyd
c:\windows\system32\apphelp.dll
c:\program files\bleachbit\win32service.pyd
c:\windows\system32\net.exe

PID
3804
CMD
taskkill.exe /f /IM explorer.exe
Path
C:\Windows\system32\taskkill.exe
Indicators
No indicators
Parent process
BleachBit.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
1044
CMD
C:\Windows\explorer.exe C:\Windows\explorer.exe
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
BleachBit.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll

PID
1672
CMD
C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll

PID
3172
CMD
"C:\Windows\explorer.exe"
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\imageres.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\iedkcs32.dll
c:\windows\system32\ie4uinit.exe
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sndvolsso.dll
c:\windows\system32\hid.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\timedate.cpl
c:\windows\system32\atl.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gameux.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wer.dll
c:\windows\system32\shacct.dll
c:\windows\system32\samlib.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\authui.dll
c:\windows\system32\cryptui.dll
c:\program files\bleachbit\bleachbit.exe
c:\windows\system32\winsta.dll
c:\windows\system32\devicecenter.dll
c:\windows\system32\stobject.dll
c:\windows\system32\batmeter.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\psapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\installer\{90140000-003d-0000-0000-0000000ff1ce}\wordicon.exe
c:\users\admin\desktop\bleachbit-2.1-setup-english.exe
c:\windows\system32\es.dll
c:\windows\system32\prnfldr.dll
c:\windows\system32\winspool.drv
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\dxp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\syncreg.dll
c:\windows\ehome\ehsso.dll
c:\windows\system32\netshell.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\alttab.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\pnidui.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\ncsi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wwanapi.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\qagent.dll
c:\windows\system32\srchadmin.dll
c:\windows\system32\sxs.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\mlang.dll
c:\windows\system32\bthprops.cpl
c:\windows\system32\synccenter.dll
c:\windows\system32\actioncenter.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\hgcpl.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\fxsst.dll
c:\windows\system32\fxsapi.dll
c:\windows\system32\fxsresm.dll
c:\windows\system32\fxssvc.exe

PID
3772
CMD
net stop wuauserv
Path
C:\Windows\system32\net.exe
Indicators
No indicators
Parent process
BleachBit.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Net Command
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\net.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\mpr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\net1.exe

PID
2924
CMD
C:\Windows\system32\net1 stop wuauserv
Path
C:\Windows\system32\net1.exe
Indicators
No indicators
Parent process
net.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Net Command
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\net1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\samlib.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netmsg.dll

PID
3332
CMD
net start wuauserv
Path
C:\Windows\system32\net.exe
Indicators
No indicators
Parent process
BleachBit.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Net Command
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\net.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\mpr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\apphelp.dll

PID
3900
CMD
C:\Windows\system32\net1 start wuauserv
Path
C:\Windows\system32\net1.exe
Indicators
No indicators
Parent process
net.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Net Command
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\net1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\samlib.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netmsg.dll

Registry activity

Total events
2298
Read events
2162
Write events
120
Delete events
16

Modification events

PID
Process
Operation
Key
Name
Value
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BleachBit
InstallLocation
C:\Program Files\BleachBit
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BleachBit
DisplayName
BleachBit 2.1
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BleachBit
UninstallString
"C:\Program Files\BleachBit\uninstall.exe" /allusers
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BleachBit
DisplayVersion
2.1
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BleachBit
DisplayIcon
C:\Program Files\BleachBit\BleachBit.exe,0
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BleachBit
Publisher
BleachBit
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BleachBit
NoModify
1
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BleachBit
NoRepair
1
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BleachBit
HelpLink
https://www.bleachbit.org/help
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BleachBit
URLInfoAbout
https://www.bleachbit.org/
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BleachBit
URLUpdateInfo
https://www.bleachbit.org/download
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
52
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
53
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\shell\shred.bleachbit
Shred with BleachBit
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\shell\shred.bleachbit\command
"C:\Program Files\BleachBit\bleachbit.exe" --gui --no-uac --shred "%1"
3152
BleachBit-2.1-setup-English.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BleachBit
EstimatedSize
9828
3152
BleachBit-2.1-setup-English.exe
write
HKEY_CURRENT_USER\Software\BleachBit
Installer Language
1033
4064
BleachBit.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
4064
BleachBit.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count
4064
BleachBit.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
54
4064
BleachBit.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
4064
BleachBit.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
4064
BleachBit.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\pem
4064
BleachBit.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU
4064
BleachBit.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.pem
4064
BleachBit.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\Folder
4064
BleachBit.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
4064
BleachBit.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
4064
BleachBit.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
PendingFileRenameOperations
\??\C:\Windows\WindowsUpdate.log
4064
BleachBit.exe
delete key
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
4064
BleachBit.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2
4064
BleachBit.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
1672
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
1672
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3172
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
CleanShutdown
0
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{e1a82db3-a9f0-11e7-b142-806e6f6e6963}
Data
000000000DF0ADBA01000000080000000000008000000000000000300000000000000000FF00E703FF0000001600000084BAB9BC0400000000000000000000000000000000000000000000000000000000005C005C003F005C00530054004F005200410047004500230056006F006C0075006D00650023007B00660039006500330036006300340036002D0031006400340030002D0031003100650038002D0039003400310037002D003800300036006500360066003600650036003900360033007D002300300030003000300030003000300030003000300031003000300030003000300023007B00350033006600350036003300300064002D0062003600620066002D0031003100640030002D0039003400660032002D003000300061003000630039003100650066006200380062007D000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005C005C003F005C0056006F006C0075006D0065007B00650031006100380032006400620033002D0061003900660030002D0031003100650037002D0062003100340032002D003800300036006500360066003600650036003900360033007D005C000000530079007300740065006D002000520065007300650072007600650064000000000000000000000000000000000000000000000000000000000000000000000000004E005400460053000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{e1a82db3-a9f0-11e7-b142-806e6f6e6963}
Generation
2
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{e1a82db4-a9f0-11e7-b142-806e6f6e6963}
Data
000000000DF0ADBA41000000080000000000008000000000000000300000000000000000FF00E703FF000000160000004736BAC40440000001000000000000000000000000000000000000000000000000005C005C003F005C00530054004F005200410047004500230056006F006C0075006D00650023007B00660039006500330036006300340036002D0031006400340030002D0031003100650038002D0039003400310037002D003800300036006500360066003600650036003900360033007D002300300030003000300030003000300030003000360035003000300030003000300023007B00350033006600350036003300300064002D0062003600620066002D0031003100640030002D0039003400660032002D003000300061003000630039003100650066006200380062007D000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005C005C003F005C0056006F006C0075006D0065007B00650031006100380032006400620034002D0061003900660030002D0031003100650037002D0062003100340032002D003800300036006500360066003600650036003900360033007D005C0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000004E005400460053000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{e1a82db4-a9f0-11e7-b142-806e6f6e6963}
Generation
2
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count
HRZR_PGYPHNPbhag:pgbe
FFFFFFFF000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYPHNPbhag:pgbe
FFFFFFFF000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
02
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
FFFFFFFF
3172
explorer.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BleachBit\BleachBit Debugging Terminal.lnk
1
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BleachBit\BleachBit Debugging Terminal.lnk
1
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BleachBit\BleachBit No UAC.lnk
1
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BleachBit\BleachBit No UAC.lnk
1
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BleachBit\BleachBit.lnk
1
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BleachBit\BleachBit.lnk
1
3172
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
3172
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
0000000001000000020000000700000006000000030000000500000004000000FFFFFFFF
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\SysTray
Services
31
3172
explorer.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\HomeGroup\UIStatusCache
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\HomeGroup\UIStatusCache
UIStatus
544
3172
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\HomeGroup\UIStatusCache
OnlyMember
0

Files activity

Executable files
60
Suspicious files
6
Text files
145
Unknown types
19

Dropped files

PID
Process
Filename
Type
3856
BleachBit-2.1-setup-English.exe
C:\Users\admin\AppData\Local\Temp\nstF64D.tmp\UserInfo.dll
executable
MD5: 7836f464ae0102452e94a363b491b759
SHA256: 11adf8916947b5a20a071b494fa034cf62769dcc6293a1340b29a5bb29ac8e87
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\pyexpat.pyd
executable
MD5: 0afd71e41411c875f54decdc242bc96d
SHA256: c84769b2ae7662924d4fe9e0297547088ee7113e35028bb5075029198c3347b8
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\cairo._cairo.pyd
executable
MD5: f26693dc59678519a3e5c7304a02599c
SHA256: 65231e28446ef6c32507dce06b1d51459b6889f5d1a9e58b11c86d2902941389
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\python27.dll
executable
MD5: 1e834633c7e8627984fb3c09fe8eb98b
SHA256: 9d034d768b5179be9b809248c9f0a1a9a07e7dc2b50d293ebb62997c5fd035d2
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\_ssl.pyd
executable
MD5: a6b3b4ff457c94dd5ebf343498791003
SHA256: 44b10179d8e375bfca2394ca555f1a7cdabc97f3834787b8b5c4e54eb1067997
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\gio._gio.pyd
executable
MD5: a78722d8fe91d01afeada6e29f88bd2e
SHA256: 1d9a2655e28c3246086647a040abcf24c598329058d05b73ad6e08e3221e9916
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\_hashlib.pyd
executable
MD5: 4b0b3b4ddcbb700098c4504517a63097
SHA256: a968df624c9d03f4d757ce8877d80e4006b9224bfa0ada012a10cbc3e310bd47
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\pythoncom27.dll
executable
MD5: 31e46e15dcc212338df09bd51370a99e
SHA256: 5be6dd58f7967a4878859ba86fece75e29624cf6575e278edf19418155ac59f3
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\atk.pyd
executable
MD5: 1c024e5f7463dca0bb79578aca416c67
SHA256: 00771d2af39f749d72538398289072ad51092b2a148f787ba11798750e8b566a
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\win32gui.pyd
executable
MD5: cf37d925170343f3b997ca1ded28e603
SHA256: 81d5d5ba7cd6ed91635d0be6742805e8fe535e974f25808d8a11e8e0ebcc9b09
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\_socket.pyd
executable
MD5: 8e56091fb3f2116af977f3e6c53b6141
SHA256: 406a449dc5063eeadf9de1878585ca8f719b5acaf88e1de16bfe9046bb7a8e63
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\pango.pyd
executable
MD5: 8941c7ec9f5bb792512dc7de6df3ba9c
SHA256: 10fe63c6dc02604fa30892490d1716c26c4721764be3e7f761b0499319997401
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\win32file.pyd
executable
MD5: 77d22a665fea21f410616e1f19d301de
SHA256: 4e72e795a1fa556d557345699b8fd87e71d68616b7388af76376a91e1ce44387
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\bleachbit_console.exe
executable
MD5: 73ca0d1f4088aba7596b80f5f9e79578
SHA256: d441e31b354a224da237d32414ddfc7b7995bc1849d3ab52f4015d8abb36e104
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\bleachbit.exe
executable
MD5: dfaff7c682fbb3767bdeed8a3e6d5009
SHA256: e9a393496a83b774097aebdbb3855b855c8d668f113083c952aeb2bd8b5acb84
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\psutil._psutil_windows.pyd
executable
MD5: c6aaad9859d57d2d7f96ea9890b0a3ad
SHA256: d448c8d8a2e2d2d2f2e28a4c5fa418eb2b27a7f2e27a6584267ce525b5eac4f1
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\win32api.pyd
executable
MD5: 95a31bcf6a12d643092c132126a748c7
SHA256: 8281bb1d289065b73c2eb6b2565c842f26d3585eae4d54f8e42e090376eefe68
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\freetype6.dll
executable
MD5: 6b3d4d6ed730a06ca3cf155c5b2a26c2
SHA256: 49a25280b62f5535cd9a378582fefc2d3194f94668ffbd1937c37d98ba93e05d
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\_sqlite3.pyd
executable
MD5: 40b023be874ec2ace39495c235bdaad1
SHA256: 861658e53b67f95006004fe30b3072607457a2f0292234fff602243bda59e814
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\pangocairo.pyd
executable
MD5: 99312a2aa151d27efb11cb972985cec6
SHA256: 4fedddf2d213a12a49fb94e4ed3123a1f8444e4769318a0f38c6e453f058ea15
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\zlib1.dll
executable
MD5: 9ce87f6ef0cb0d844e905171073e4770
SHA256: e2226dd7190e785fdc6c46a85cb53be1964da86f108e10c0310c1d99c725f163
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libexpat-1.dll
executable
MD5: 77717f84cd70510721bccb8aa2441c97
SHA256: 1f8e511a74aeed12c47139abffd70a9ab4c5885173424583ac2ace32a1d594c7
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\_ctypes.pyd
executable
MD5: cb2198c7ef3571943c100f17147f1502
SHA256: a3b3da69fddffb50eb7baceb0a6b998041ac61937e79e93e490c5f7ee15790e0
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libgtk-win32-2.0-0.dll
executable
MD5: 9fa09bed6ab9c6c16450941ee45f53d6
SHA256: d0becaf0ce9bd6b76ef2d86c0861fcad5fc026368fd1912f7d326322f160dc90
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\win32clipboard.pyd
executable
MD5: 25c9b8e58aeb724b565fc911817b5e11
SHA256: 148899dcf07dd3c9dcbe7a7f4af25c0b12a6455b0cda7c61fc51a3b52e1d9445
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\glib._glib.pyd
executable
MD5: 99bf7871af94886f19930f3aba17cada
SHA256: 7ae6e2bda7a5c15d93dadb53251a7f4636163698a3d315c8d64f597c9955e9db
3152
BleachBit-2.1-setup-English.exe
C:\Users\admin\AppData\Local\Temp\nsh19B3.tmp\LangDLL.dll
executable
MD5: de3558ce305e32f742ff25b697407fec
SHA256: 98160b4ebb4870f64b13a45f5384b693614ae5ca1b5243edf461ca0b5a6d479a
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libpangoft2-1.0-0.dll
executable
MD5: 473fbf268220cd38f2542f3e0e4634bc
SHA256: 36cb023fef925401ec214ec523843105a55c6106f421ff24045b86a4f2eaa60f
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\win32process.pyd
executable
MD5: 1523b59acde0d47c3a302b0556a4291b
SHA256: 7293c95a31bb34f2bd3f6a212bc5510623c5f03ab51c9c0ae0cb0a5d11aa5d74
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\gobject._gobject.pyd
executable
MD5: 4361a2f4b14aa40dbbd845cb2b9a3b8d
SHA256: 148197e503b36fbfb3276b3da4132d67177c003e9d3f557551e78d96f9e0accb
3152
BleachBit-2.1-setup-English.exe
C:\Users\admin\AppData\Local\Temp\nsh19B3.tmp\UAC.dll
executable
MD5: 4814167aa1c7ec892e84907094646faa
SHA256: 32dd7269abf5a0e5db888e307d9df313e87cef4f1b597965a9d8e00934658822
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libpangowin32-1.0-0.dll
executable
MD5: 40793bfd0bdffbd6f98c5200111c4582
SHA256: 5d159f40380ad2589a85d041234552c57d69edcb4b034c6701ef754d5dc7a114
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\unicodedata.pyd
executable
MD5: 7fa31e0b8af15c15ef8b478bd08882a6
SHA256: 1fc7b2e8ff32cf5832af0d5357b9a873ab68ef1aa873cf39e42be363223e972d
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\intl.dll
executable
MD5: 104a6f1de27e1861fd6245018a80734f
SHA256: ab3a8539bc012d203dae33428a6f34b947fa2e39daac7da298830d1a4f8b9500
3152
BleachBit-2.1-setup-English.exe
C:\Users\admin\AppData\Local\Temp\nsh19B3.tmp\System.dll
executable
MD5: fbe295e5a1acfbd0a6271898f885fe6a
SHA256: a1390a78533c47e55cc364e97af431117126d04a7faed49390210ea3e89dd0e1
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libpng14-14.dll
executable
MD5: a3362cdd2ab3c3f1019f53711d67078b
SHA256: 044abaf4f5c3d6e0294964b1b65af85e1b03282aa5447faac6424ac20271e3ed
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\win32com.shell.shell.pyd
executable
MD5: 5c1a22d94b92278a3f0a3eb5157870ad
SHA256: 72d778c00ad0773949fdcad2d9aae8feb79c734fd8bee25f51a593ad85378348
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libatk-1.0-0.dll
executable
MD5: ba91082c3ed5a9f4c167ecaa9fb49bf0
SHA256: d303752f85db339932ef1c30da0d8ce823f57a7f2fb218229a5c286b3ad84c41
3152
BleachBit-2.1-setup-English.exe
C:\Users\admin\AppData\Local\Temp\nsh19B3.tmp\UserInfo.dll
executable
MD5: 7836f464ae0102452e94a363b491b759
SHA256: 11adf8916947b5a20a071b494fa034cf62769dcc6293a1340b29a5bb29ac8e87
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libpangocairo-1.0-0.dll
executable
MD5: a3b36a5c105bfe432b56e1ad95957c32
SHA256: 4bc0362925d18b5430399abbe30a493f4c7ebec7ee289166e26c49a0969e2d3c
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\sqlite3.dll
executable
MD5: 05c5e18639033d2a94a66306d105a016
SHA256: e5770ce0415be438510c196dc6da0e1918c2e2788b12f9f6a4599431cdf50802
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libcairo-2.dll
executable
MD5: f9db27dc8baa46ab23f286dbe15bb521
SHA256: 959529882443882fbb719dd753caafde3f39ff6ab30b3a597e0f008a6e08b233
3856
BleachBit-2.1-setup-English.exe
C:\Users\admin\AppData\Local\Temp\nstF64D.tmp\nsDialogs.dll
executable
MD5: ab101f38562c8545a641e95172c354b4
SHA256: 3cdf3e24c87666ed5c582b8b028c01ee6ac16d5a9b8d8d684ae67605376786ea
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\gtk._gtk.pyd
executable
MD5: 0b8d60b7492af6bbd4d209cd95abe174
SHA256: e05b29a7217d49a7c124eac57d06b5cb3770956051f9ff3971630212d28b2d39
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\win32service.pyd
executable
MD5: 76765cf7319d873011725164cd7343dc
SHA256: b4278dc18a0a4c5382577b9598e0a3d3ca67e3d8871d7900dc0d0bb50df4ce94
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libfontconfig-1.dll
executable
MD5: 5a775b7d1fc597853a8eb659ee4c1d0f
SHA256: 7df6ff8cb62fc7c5d424da9febf1408e860ad4de1def818c0e2fe6fe3dceb8ee
3856
BleachBit-2.1-setup-English.exe
C:\Users\admin\AppData\Local\Temp\nstF64D.tmp\LangDLL.dll
executable
MD5: de3558ce305e32f742ff25b697407fec
SHA256: 98160b4ebb4870f64b13a45f5384b693614ae5ca1b5243edf461ca0b5a6d479a
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libgdk_pixbuf-2.0-0.dll
executable
MD5: a195a877df222062fb74936b23e0327b
SHA256: 6581457254d43289cbecb2f17210552ea02479b878b29d1e718c1a0773c279d1
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\lib\gtk-2.0\2.10.0\engines\libwimp.dll
executable
MD5: 42f75968c96d7065dc4b2ebcd9ae68b2
SHA256: 156f624dd7c0da7e64d6d47396547686e1d161d8afcaa8e799f9863a9c2aced3
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libgdk-win32-2.0-0.dll
executable
MD5: 6aa70f70907fbb6ffeabeedc5822ba54
SHA256: eea8b269aef1663ae97212a8662f7ba5a8b7f3512755737ffd59b12b5ddd1096
3856
BleachBit-2.1-setup-English.exe
C:\Users\admin\AppData\Local\Temp\nstF64D.tmp\System.dll
executable
MD5: fbe295e5a1acfbd0a6271898f885fe6a
SHA256: a1390a78533c47e55cc364e97af431117126d04a7faed49390210ea3e89dd0e1
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libpango-1.0-0.dll
executable
MD5: e6c0f78d61eaed0b23e54a8084f8302b
SHA256: 176f477be360ffd9e03f93301003fb18ef0cfd598970c664e1f34ba45c4f1d07
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\uninstall.exe
executable
MD5: 8817d9ac3a545ad420a19fc206463035
SHA256: a0b946692ca94e05a78eb89019ddcfb932d774bdfed322c97a925f5c9a13bc8a
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libgmodule-2.0-0.dll
executable
MD5: c1bd6cb60721961945f3c080e377cda1
SHA256: d38fb8ae5a1edb0e1ff94242a4e9115eaba01b31ab4268795683f69fe1ef1cc1
3856
BleachBit-2.1-setup-English.exe
C:\Users\admin\AppData\Local\Temp\nstF64D.tmp\UAC.dll
executable
MD5: 4814167aa1c7ec892e84907094646faa
SHA256: 32dd7269abf5a0e5db888e307d9df313e87cef4f1b597965a9d8e00934658822
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libgobject-2.0-0.dll
executable
MD5: 5ad052a72d2ccc72f167be96c376f7cf
SHA256: d332edc9aecad378f4e8b44f52f7b9a1aa24e65e5162b1905e358f5ad0ec7424
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libgthread-2.0-0.dll
executable
MD5: a523388ffd85d4cb432f9ab5ca6cb004
SHA256: c4a3a919aab1508b54e4b912315d840cacba3e125553882092ac3a5204694070
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libglib-2.0-0.dll
executable
MD5: 672f6ca14bbf65a048bf5860f9e78067
SHA256: 43190b8796870f9ac0fd062d67121ee5d6febe3e8bf268a72e7fded5ac3bad30
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\libgio-2.0-0.dll
executable
MD5: 53ec8e8af4c47a1aa7b83f54507efb74
SHA256: 77a4885fd29230dd7235c9ff161e210aa872ce059649a0b8546f34d160556506
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\pywintypes27.dll
executable
MD5: e7724dd9a5d8d095d8e5b8e5ad5f9c0d
SHA256: 28f74b865a5c1b26ea73ad52466f75dd39c93f6f4162e040fec0297d4aaa57ef
3152
BleachBit-2.1-setup-English.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BleachBit\BleachBit No UAC.lnk
lnk
MD5: a9802f19257259544a074fc1cf1d0882
SHA256: 513e1283617d10fd547343981cb19100202ae73be0c98130a59418dac585e9be
3152
BleachBit-2.1-setup-English.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BleachBit\Uninstall.lnk
lnk
MD5: 529bbbbcf3cf84bf14a6142a9826ed61
SHA256: f1ec29632ef8c4db792912655c4c4804772dcbeeeb99ccda1a8f82752c872a05
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db
sqlite
MD5: 96273942bdc68017b98c0fa76e9c5cda
SHA256: 9d19ad5f11e4ce52217ea51847391bfa90bd36482852527cc00a3424845c6dad
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\bleachbit.png
image
MD5: 5d9d52ceedde77c5d466580e7d8bc4da
SHA256: fa51e4372d692f891fa7725b28bf2b6462f33e30cd57da75ded16c73a4e4fb7b
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\themes\MS-Windows\gtk-2.0\gtkrc
text
MD5: 94d104680cec5f3d8bbec56258d0c926
SHA256: e9dd3015f76e05f185ebe7564d364aef8b8168b05e62421c99875e14e4597977
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\wordpad.xml
xml
MD5: 4b78e46efc8a0c238b7d6cc4f8280907
SHA256: cc0cfaeede175d74fababe07a203ada17b7f680bd4016ecbdca11f5290c439c0
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\yahoo_messenger.xml
xml
MD5: 4b80d70ec939d686c7339880d03e4184
SHA256: 90a915662234239572c2b003da9b19db4e18b9ea0e1a747532f709f6b1536f06
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\winzip.xml
xml
MD5: 5706c515b7aa91efedd4804a8c8f2850
SHA256: 6195afad2c9f65fd4c497510adfd34fc523c789baad0b7a10218c5e5585f162e
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\windows_defender.xml
xml
MD5: 642cdb186d28f4a087b34de6ab60ee98
SHA256: b0bf01b5c630baaae5b6c374dce5f018e1130ef2be08456675afcebad708b4e4
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\windows_explorer.xml
xml
MD5: 0585927e83bc0311736bdda123bd7299
SHA256: 6db27eccc6fa7420a13413098265486d16a79e3ed2a2b837c4273797a92957b2
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\windows_media_player.xml
xml
MD5: 18c85885539800de5a81191562e0fc8d
SHA256: 776f8c9be47a2aa79577fa3f87b70853646868d0d95160745b2bf8de10ee436b
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\winrar.xml
xml
MD5: 982ef13ae27c99748757a164d76bb4c6
SHA256: 3c3e466ac9f839c21a02178c7cff9caa5421393b9d7ea9bd819e9ea87a6a0b80
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\waterfox.xml
xml
MD5: f95bdb076af8703245509977b40026f1
SHA256: b0265a54856b13d49834c9293e1a764b4dd9029eb24e7ac34f6e25164d6d4e81
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\winamp.xml
xml
MD5: a92a38bbab5bf248ff2c0b71b031f7fe
SHA256: 738b91993f5601ffaf52c6dc17015953a9f8769df79ac3e7774df3ef34f9643e
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\vuze.xml
xml
MD5: ad0279b828751b5664229cde6cd4f5a8
SHA256: 4f594da13b0b85c0241ea3be51eefe2794c63dc6fa9b541885ed425083036e01
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\warzone2100.xml
xml
MD5: 4cd1b56741b387e08a8be608043ade85
SHA256: 60adc2491e88f2aa997838bdcdb2f81427236c99b832ed268caa52362587c835
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\vlc.xml
xml
MD5: 59407dc5630002c60653e8ec4fe56b65
SHA256: 8a1d3ab6b78f0de477f96284212e903763381217ba4ee8f6b9c6044265df4893
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\thunderbird.xml
xml
MD5: a43b9ab7ad3662b95372ec49f6ed3f82
SHA256: 5d7501109dd6fc344cf9a12fa5d3d0c87d517cbd4ee0921c275c917db8e6550a
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\smartftp.xml
xml
MD5: 5bc94fe97be96962c0fc8ff4e5eac10c
SHA256: 6498bfc79521f21f26c8cea0d893ad976859f6e78088ca519d4d45f733a7d25d
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\vim.xml
xml
MD5: e62a50eee9a653fa9d57c76318a8264c
SHA256: d3ea00fbcfe21fbd60306bf7aedac7d5a511e7e1fd87875779acfe647e6e8be5
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\skype.xml
xml
MD5: d32c0e11ca49f27f29416220dfd15e7c
SHA256: 92eb9e7c7f0f52053cc264a12ce7b23c9f41dfb8b976fbd699654585f4f638c6
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\teamviewer.xml
xml
MD5: f4bd2d3150d85cd74a2d5e37084140c5
SHA256: 0879823522931ae52b81c357246dc9c4736899b318473125063f1f1d3bf90a41
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\tortoisesvn.xml
xml
MD5: 142dcb3be527c2eeb1cb0ef03bf444e1
SHA256: 0381384e4042c796f143a4a5ccaad9ebf3ff8d0ec6be2c0d74bd99fd6172dd2e
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\secondlife_viewer.xml
xml
MD5: e260313bcd517e462e69f3fe2435e934
SHA256: 9a020f1084dcea0c555b35f5eba978f94b30d08dc3913e0ee4cce0a177e5dcc7
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\pidgin.xml
xml
MD5: 045e2db85d09760c1364e931b50b5ce4
SHA256: 35727f6de914c1d89990566d2f5d30bafeeb7e74257d82459683bfab7ef4ce33
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\silverlight.xml
xml
MD5: 39b4a534a4541588b0c6d57e0028d11a
SHA256: be644613ba50a31f2d9eb353592d6949f6e23ff7c60d4f6539bfb1f9ed1ab406
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\realplayer.xml
xml
MD5: bf7d8ff2dd0ad65a09cb08d64f6a91f7
SHA256: b1615cd58e05362c8ded167680628cf784484c3e7f27cb1290f722a7066f0064
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\screenlets.xml
xml
MD5: dfb583701e71ba6f7945b7134c423263
SHA256: 326e7b55546451b5c71d08a986dab6af16020f4ada2eee4d359d0dfa6a894a49
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\seamonkey.xml
xml
MD5: 792176d14e4d506ad86638a8d949d584
SHA256: 49c175c74c32b7edc2931dfef744bd6309406590e7aa75b32f7ea96d73541e21
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\safari.xml
xml
MD5: 5dda5c22a9b40b6ac9ca4e9510272c2f
SHA256: a3a317cb70e7d2276b4e9b9f950278feed6b99bd0779a27bf0e60d3b5c777ff4
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\libreoffice.xml
xml
MD5: 8a0a2f11fb9594973fd9b615aa66c6c4
SHA256: 352a46bba56e9e4bf7ee77a5f804f617a9778e696519ecd44b8a8a28e30fcc74
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\miro.xml
xml
MD5: 57356db7d3d26484227f22ec2654779d
SHA256: c4e9a7eb635c0d7571ccdeed244216671cd97858d86dff0e5e3b9cb36b9621a7
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\paint.xml
xml
MD5: 7477deaf8b168cf480cc354803ddcdbd
SHA256: 8353334b17b659b0e09e015f049759a77edb10f1649330ec0e6fe6a92d92f2f5
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\java.xml
xml
MD5: 4f1145573b9d37b26ccd41db7cc83d19
SHA256: 08cf82d9751f5cbb3b27ea1b924f52ad763e6f2595c2acf3ced013f340580f78
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\internet_explorer.xml
xml
MD5: 8d2e03bdeae41e59bbcfaa752e3c5c72
SHA256: 2215ba893a95dea3e63507869da6f89fe6e9aa03af282ea11da832fdbc98943f
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\hexchat.xml
xml
MD5: af83107ee935ec408c716be026c7681a
SHA256: 18b8a66f1dbf51cae99ac23081bc261accb6d3cc85ad86e1dfaccb255e8c1637
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\hippo_opensim_viewer.xml
xml
MD5: e6a7e5017b955b3776d4facddf4ac3c1
SHA256: 9b3aecb53483016ebf88d3bbc226e3676c91109399c8768c68329f51c3bd6788
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\microsoft_office.xml
xml
MD5: cf68ed03b941706e6ef884063f433452
SHA256: 18a50a8b2f15ae240839484fd80807fd87367d166c04b945d08d24841ce62aa3
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\opera.xml
xml
MD5: bef6078e74f0b493170f5d47b66fdb46
SHA256: 61ea41df0ded4f95c3111a09bfd4dcda79761d5d36b64447c32a169fadbd75bc
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\octave.xml
xml
MD5: b125c63969012ba06aa0a8b49249bb2a
SHA256: fe7ae79000ac1e9269afc49e43e2ab79451151b3fcfb35e5e3f0d036b5bc9583
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\google_earth.xml
xml
MD5: d93573c2c8505a754c45eeb59b19cfe9
SHA256: fdb15cc731eb4900972e583eb4d21e7be395dde17669a5fdd61f8badd8af5701
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\google_chrome.xml
xml
MD5: 6e2ec9c5eca014960990688f864185b6
SHA256: 0b76b247c483430b6d756c6e2ea8939c96d8da6dbe2d4f0797eda3c7c1af66bb
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\gimp.xml
xml
MD5: fa49375a400e3f3f93682156096a10f9
SHA256: f540abd5d938dd40aa8ce52163f255b23fe2ba50a883778f2daf398bc77cce48
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\flash.xml
xml
MD5: 5a21233a1211582ff07b8cd855e4659b
SHA256: e26c6f5aa957bc7db7e6fe6dff96d03dce3c4adffc716d819f7a965aa4787370
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\google_toolbar.xml
xml
MD5: 21df427907ae0dac6130a14026539c82
SHA256: bc521893f1de5f2cd5d9952eb5a8549adb5ccc14784cf70cd3cba3d3398d1ddc
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\filezilla.xml
xml
MD5: d48c1acc079fe57f9aa93714e02c6702
SHA256: dc0a9a6a51a9626067d414dcf01b982bd7aeab7aeddb3710711a900a08a8ead1
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\adobe_reader.xml
xml
MD5: 58907a19d3d0857e743f26c4070183e2
SHA256: 0277e00a809bd029c9be4b03da5a2f0808f8fc5acd15a1b61de1fb1f732d1767
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\amule.xml
xml
MD5: b3d40e961d39f3e13c1c6e1de0ae61f7
SHA256: 11c89844aafbc9960190bff42c2dc5e7c5baa58dee5d7b8bf971cfc8478ab32d
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\chromium.xml
xml
MD5: 9c80d849bd654c9908859f288ff82548
SHA256: 2e4e811ee23c4d7c203b0bd7ad32127dc182a04fdfbe3ab6dc076b89efc7bb6e
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\biglybt.xml
xml
MD5: a06fde5931a182c5c912ad185cbd81ab
SHA256: 4896c8e794c27f926e12c129e80df95129ed3676bb1c0bca41ea68b5c33342b9
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\firefox.xml
xml
MD5: 948f0fc98ddb887167f6cf2b435d1e90
SHA256: f7eabd7ab5bddaae826d615a484d05be2d4be0ecf3269691495d87ea84e5b655
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\share\cleaners\deepscan.xml
xml
MD5: db51358d433f4b653f01f654c2c58334
SHA256: 9e7b1928fadcee9bddaf4fe15551cb7a1442fac1ec27fd93fef1a6c9a05ec40c
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\etc\pango\pango.aliases
text
MD5: 56483dca651577b6af50c3b50423067a
SHA256: 9050f342ddd762b5f49bd87b8bf939a6a95494a5d261065c71cebd02e5b624ae
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data
sqlite
MD5: 6c88fc59e2d9641df1d7100eb485c233
SHA256: 78e48b05ba1f64e701e6caa490188e8397b6c6bcd53e6487fff4d22934bc165f
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\etc\pango\pango.modules
text
MD5: 3cc07360a38c040c4d31ab7601f16d23
SHA256: 515029dcdd87a94be02ccaf04e125d52bd604f8276ff940fff4fb941fe614cea
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\COPYING
text
MD5: c678957b0c8e964aa6c70fd77641a71e
SHA256: e79e9c8a0c85d735ff98185918ec94ed7d175efc377012787aebcf3b80f0d90b
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\etc\fonts\fonts.dtd
text
MD5: 9a099c7722190e00548c0d8375bdc24b
SHA256: 59e0c39bd4ccc6c07e44e91d5915af2bb7887d1c1d15b2ea94f54ef8ca890066
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\etc\gtk-2.0\im-multipress.conf
text
MD5: c358838e1789c1d4e6da7f525fc922cf
SHA256: d52dfea88f5964b7581c93cdea1a3e47dd7b1d8334e8f5eb53018711428221ed
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\etc\gtk-2.0\gtkrc
text
MD5: 1b1f4fb8eedfb0f02622b008b69c34c6
SHA256: f4e249084177f6540a70bc756abf1ae7c199f4872cb4d43ed81577a7ba22b437
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\etc\fonts\fonts.conf
xml
MD5: 4291285924e90d1a1fcf1ddfc51adad3
SHA256: 68011bc3741ebcea48f08ff2aed8519762a946f3e0fb9c224b1d3810ebf5bf4b
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\etc\gtk-2.0\gtk.immodules
text
MD5: 42eab99cc5b52ac5e20e4c28ecbf3a5e
SHA256: e010afd880bea689c2ce4c095081cb75572f02fe8a0f759769f638c9170631e8
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal
––
MD5:  ––
SHA256:  ––
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\previews_opt_out.db
sqlite
MD5: 1f5c8a4313e6faf8957aa7f71e79b218
SHA256: c03e8913476a93156a0af3696032c2d523396b12220ef24220cfccccf72b4a1d
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\previews_opt_out.db-journal
––
MD5:  ––
SHA256:  ––
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History
sqlite
MD5: c8dfbd01f106310d78e45dce2530da2a
SHA256: 03f71400339c865f773412fbc9d6af021f7bc0e7c8fefbf3fe68ec52e4462deb
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Origin Bound Certs
sqlite
MD5: 1add6c750bed75d3448ebe970d9c5cde
SHA256: c2eb07abaaf1fe6751462c58d0187811cc2886ebad694027c91c32dfb8f5c4f5
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History-journal
––
MD5:  ––
SHA256:  ––
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Origin Bound Certs-journal
––
MD5:  ––
SHA256:  ––
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: c70c572a2ea87b9687d9eb477b4e8ea3
SHA256: 6495a311ed1e2e28326b2c36d43184a5b2d349e39596f8ae777408e73ab4f676
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: 86ca89afa4ba3a87408768eaf6433c57
SHA256: b4b04d12ffe37fa5ea1a476c75e9bfd68402bf1dc3096d042f349001007b9c54
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Favicons
sqlite
MD5: 79b14d9ebcaa9d4504143e9b933c8a5d
SHA256: 6d1bc1cede4b726075c85cc9c63aae0064dacd23f0371a2683a13a0bbf1ddbae
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
––
MD5:  ––
SHA256:  ––
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data
sqlite
MD5: 551cd4dd520e6a6f88af1eab8c31d32e
SHA256: dd7eaef0f93dff0fbcd0535c4c519217a184c455a5a9888a247f9376bfe8c7c0
3172
explorer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
binary
MD5: 2034995f0bbaa16db835b462eb78152a
SHA256: 62ce260f5e10fc17bf63faafa39912febf61d20fad51cc11606a295801743799
3172
explorer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
vxd
MD5: d19d2dbcf116a4cb9f5fedbcad9c9f33
SHA256: 723ffbee70bccf84084457b6c1374f9b484a6a7282f8b12fcb2805751ab0fe59
3172
explorer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
binary
MD5: b623140136560adaf3786e262c01676f
SHA256: ee3e1212dbd47e058e30b119a92f853d3962558065fa3065ad5c1d47654c4140
3172
explorer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
binary
MD5: 40208d46ccb89b1749c419e751697a83
SHA256: 8b02755694ee6cebcb756398c714467e70bef2f3ec300b1f5db0bdf3bf179ded
3172
explorer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
binary
MD5: 3e9c4eaba2c54dfe525197d54dc10532
SHA256: 05da3daa836dc6ed72144dff35f8d90396b4d524dc35ef8d8cd01d86855be858
3172
explorer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
binary
MD5: ae08a2f7fbf44ad3cb6cbc529df8b1dd
SHA256: 8429d5c6eb134eb64d8b0f3ecce83ab4d4d16e73c2d76993163372692b65ea8f
3152
BleachBit-2.1-setup-English.exe
C:\Program Files\BleachBit\library.zip
compressed
MD5: 123441f2c7cb8ea78bf2d3a972cfd420
SHA256: 012bfd8a7ffd1ee7ee832ae7bbebb293bfe4f2d408c6e338dbb14815eccedc07
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite
sqlite
MD5: ef7a1f6657184d0018a407b0bbe62be4
SHA256: eb8355dbf393dd67ec97a16ea90610256798d6fc4e96b4c22bbd11c37866ad19
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite-journal
––
MD5:  ––
SHA256:  ––
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite
sqlite
MD5: 942d27d86f9dd5fff8df6030f3e777a9
SHA256: 04fc86ae300db5a8554bee619371c357538c6056e8bd3bda4272b568b5c6b45d
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Temp\etilqs_qC562RiWbmzyxUX
––
MD5:  ––
SHA256:  ––
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-wal
––
MD5:  ––
SHA256:  ––
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-shm
––
MD5:  ––
SHA256:  ––
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite
sqlite
MD5: 9b89bb84173cd0e2439cbdca1d73a785
SHA256: 8e54ebf8b023f9d767a179eab3bdce89cdd663b8bb0bad63edf971a225570e06
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite-journal
––
MD5:  ––
SHA256:  ––
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite
sqlite
MD5: 074f2b7a2b4cff7aec61fc8d1d628404
SHA256: ba419e999859145d7e8127572ca3bf1cfbb3091673e9a69120f05f7b654a1e1e
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite-shm
––
MD5:  ––
SHA256:  ––
4064
BleachBit.exe
C:\Users\admin\AppData\Local\Temp\etilqs_rsX67k0AkEIv9b6
––
MD5:  ––
SHA256:  ––
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite-wal
––
MD5:  ––
SHA256:  ––
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\BleachBit\bleachbit.ini
text
MD5: a0075eb87c6f0d4bc1e6e535d0231d77
SHA256: 716aeafd03ad83406707953b1fdf0982d02889f46f9b096572a1b9ca212550cb
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\BleachBit\bleachbit.ini
text
MD5: 0c45c8f7810345aef27cb58761d3fd53
SHA256: 3ee4660a752b4096accaf5a5b9413b3abe58647446a03c048a29e4a175e8616e
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\BleachBit\bleachbit.ini
text
MD5: 2e28fb2ac0e3a416766cf9a26b5dc1c3
SHA256: 126449b0c1743b4633af10f7492e8be65aa59cf84912a97ef3d2e33c81b20572
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\BleachBit\bleachbit.ini
text
MD5: 6c1ec0475a7f403339131836e234445a
SHA256: 1c078cb69c3e79e9e6b082ddab81334e58301ec3d3eaf897c42375e3bb365d40
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\BleachBit\bleachbit.ini
text
MD5: 2c8d7bf54a6b2764baabf3ac5a34a4bf
SHA256: 6046ec118d124855ce67a063290f54674755442df7ed0328aeb2479e5097ce90
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\BleachBit\bleachbit.ini
text
MD5: 4cdb887907deaed90899fc1e42b2ffeb
SHA256: 9f21342be7953421a42d80cd8bf688208a185430b42cffbaa6119458d622bf91
4064
BleachBit.exe
C:\Users\admin\AppData\Roaming\BleachBit\bleachbit.ini
text
MD5: bc36c44008abd6b74eb15e454736cab7
SHA256: b477c8037f0787771bab3207d1cdc94e3da875971e14b8cc37ff0500b1473e74
4064