| download: | CDex-2.06.exe |
| Full analysis: | https://app.any.run/tasks/16479e32-d68c-499b-8b7a-48271992f09b |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | June 28, 2018, 22:05:22 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 59819F0C69042270472AB66D7601542F |
| SHA1: | 73FDEA802354866D289B56C74F62C56DEBCA7957 |
| SHA256: | 844CBF018742BE7C1A29037CE33FBBD4A006D1F45F53C3ED552FD5EE3F2BAEA4 |
| SSDEEP: | 393216:bqeOzs2D3Gy5UOhCYGiimJBMm0UWDkqt2t+tymd2OVson5NjKFAK/iPGDWb+OW:bz32rayC5H2MmW7Et+AmNPHjKF/KPCNX |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:01:30 04:57:41+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26112 |
| InitializedDataSize: | 141824 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x34a5 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.6.0.2018 |
| ProductVersionNumber: | 2.6.0.2018 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | http://cdex.mu/ |
| CompanyName: | CDex |
| FileDescription: | CDex - Digital Audio CD Extractor and Converter |
| FileVersion: | 2.06.0.2018 |
| InternalName: | - |
| LegalCopyright: | © Georgy Berdyshev |
| OriginalFileName: | CDex-2.06.exe |
| ProductName: | CDex |
| ProductVersion: | 2.06.0.2018 |
| Publisher: | CDex.mu |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 30-Jan-2018 03:57:41 |
| Detected languages: |
|
| Comments: | http://cdex.mu/ |
| CompanyName: | CDex |
| FileDescription: | CDex - Digital Audio CD Extractor and Converter |
| FileVersion: | 2.06.0.2018 |
| InternalName: | - |
| LegalCopyright: | © Georgy Berdyshev |
| OriginalFilename: | CDex-2.06.exe |
| ProductName: | CDex |
| ProductVersion: | 2.06.0.2018 |
| Publisher: | CDex.mu |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000D8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 30-Jan-2018 03:57:41 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00006409 | 0x00006600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.41622 |
.rdata | 0x00008000 | 0x0000138E | 0x00001400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.14383 |
.data | 0x0000A000 | 0x00020358 | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.0044 |
.ndata | 0x0002B000 | 0x00038000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x00063000 | 0x0006AAC0 | 0x0006AC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72701 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.28813 | 1070 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 4.76582 | 74792 | UNKNOWN | English - United States | RT_ICON |
3 | 2.75245 | 41064 | UNKNOWN | English - United States | RT_ICON |
4 | 5.06473 | 9640 | UNKNOWN | English - United States | RT_ICON |
5 | 5.11164 | 4264 | UNKNOWN | English - United States | RT_ICON |
6 | 5.50666 | 3752 | UNKNOWN | English - United States | RT_ICON |
7 | 5.86809 | 2216 | UNKNOWN | English - United States | RT_ICON |
8 | 3.08091 | 1640 | UNKNOWN | English - United States | RT_ICON |
9 | 4.05667 | 1384 | UNKNOWN | English - United States | RT_ICON |
10 | 5.36179 | 1128 | UNKNOWN | English - United States | RT_ICON |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 292 | cmd /d /c del "C:\Users\admin\AppData\Local\Temp\D17114~2.DAT" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 308 | C:\Windows\system32\wbem\unsecapp.exe -Embedding | C:\Windows\system32\wbem\unsecapp.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Sink to receive asynchronous callbacks for WMI client application Exit code: 0 Version: 10.0.10586.117 (th2_release.160212-2359) Modules
| |||||||||||||||
| 352 | "C:\ProgramData\Package Cache\{56e11d69-7cc9-40a5-a4f9-8f6190c4d84d}\VC_redist.x86.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={2019b6a0-8533-4a04-ac0e-b2c10bdb9841} -burn.embedded BurnPipe.{52EECAB0-A08D-4493-942C-3E7AC63C1F27} {368CF42B-4D48-48C8-984E-5E771486408F} 1840 -burn.unelevated BurnPipe.{F542C43A-9144-4836-B790-FB69321D1508} {3D9914B9-4FDC-40CA-939A-C5B9B7503BEB} 1072 | C:\ProgramData\Package Cache\{56e11d69-7cc9-40a5-a4f9-8f6190c4d84d}\VC_redist.x86.exe | — | VC_redist.x86.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25810 Exit code: 0 Version: 14.12.25810.0 Modules
| |||||||||||||||
| 384 | TIMEOUT 1 | C:\Windows\system32\timeout.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 416 | "C:\Program Files\AVAST Software\Avast\RegSvr.exe" "C:\Program Files\AVAST Software\Avast\aswAMSI.dll" | C:\Program Files\AVAST Software\Avast\RegSvr.exe | — | instup.exe | |||||||||||
User: admin Company: AVAST Software Integrity Level: HIGH Description: Avast Antivirus Installer Exit code: 0 Version: 18.5.3931.0 Modules
| |||||||||||||||
| 560 | "C:\Users\admin\AppData\Local\Temp\tmp6238903\fatasile.exe" /instlref="a" /LRUN="0Czx1Y0U1B1P1C1B1Y1T1Q1H1L1G1Y0A1E1E0D1T2Z1T1Y0L1F1R1T1I1Y0T1P1H1E1Y1B1SyBtDtAtF1Q1T2Z" /mhp /gu="10" /mds /aflt="bgy_cdxfs_18_26_13" /RSF="792" /mnt /ext="pilp" /noadmin /nochrome /adt="tE1L1R1V2Y1L1QzuyDtByDyEtDtDyE0A0A0DtBtCtAyCyEyBtTtE1L1R1V1B1Q2ZzutBtDtCzztDyCtBzztBtAtDyCtByEyBtBtAtTtE1Q1G1Izu2Y1G1J1G1F2W1GtTtE1Q1G1I1M2YzuyD" /flow="1R1M0I1G1B2Z1T1I1I0E2V2Z" /sfns="2StCtBtDyEzztC0E0DtGtAtDtDzztGtCzytA0EtGyBtByE0EtGzy0BzyyEyEzzyCzy0D0D0Ezz2Q" | C:\Users\admin\AppData\Local\Temp\tmp6238903\fatasile.exe | — | fatasile.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 648 | "C:\Program Files\AVAST Software\Avast\setup\instup.exe" /instop:check_for_updates /wait | C:\Program Files\AVAST Software\Avast\setup\instup.exe | AvastSvc.exe | ||||||||||||
User: SYSTEM Company: AVAST Software Integrity Level: SYSTEM Description: Avast Antivirus Installer Exit code: 0 Version: 18.5.3931.0 Modules
| |||||||||||||||
| 792 | "C:\Users\admin\AppData\Local\Temp\CDex-2.06.exe" | C:\Users\admin\AppData\Local\Temp\CDex-2.06.exe | explorer.exe | ||||||||||||
User: admin Company: CDex Integrity Level: HIGH Description: CDex - Digital Audio CD Extractor and Converter Exit code: 0 Version: 2.06.0.2018 Modules
| |||||||||||||||
| 944 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1072 | "C:\ProgramData\Package Cache\{56e11d69-7cc9-40a5-a4f9-8f6190c4d84d}\VC_redist.x86.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={2019b6a0-8533-4a04-ac0e-b2c10bdb9841} -burn.embedded BurnPipe.{52EECAB0-A08D-4493-942C-3E7AC63C1F27} {368CF42B-4D48-48C8-984E-5E771486408F} 1840 | C:\ProgramData\Package Cache\{56e11d69-7cc9-40a5-a4f9-8f6190c4d84d}\VC_redist.x86.exe | — | VC_redist.x86.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25810 Exit code: 0 Version: 14.12.25810.0 Modules
| |||||||||||||||
| (PID) Process: | (792) CDex-2.06.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\93\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (792) CDex-2.06.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (792) CDex-2.06.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (792) CDex-2.06.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CDex-2_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (792) CDex-2.06.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CDex-2_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (792) CDex-2.06.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CDex-2_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (792) CDex-2.06.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CDex-2_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (792) CDex-2.06.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CDex-2_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (792) CDex-2.06.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CDex-2_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (792) CDex-2.06.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CDex-2_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 792 | CDex-2.06.exe | C:\Users\admin\AppData\Local\Temp\001AE9F4.log | — | |
MD5:— | SHA256:— | |||
| 792 | CDex-2.06.exe | C:\Users\admin\AppData\Local\Temp\nskE080.tmp\Fusion.dll | executable | |
MD5:— | SHA256:— | |||
| 792 | CDex-2.06.exe | C:\Users\admin\AppData\Local\Temp\nsd176384333057\csshover3.htc | html | |
MD5:52FA0DA50BF4B27EE625C80D36C67941 | SHA256:E37E99DDFC73AC7BA774E23736B2EF429D9A0CB8C906453C75B14C029BDD5493 | |||
| 792 | CDex-2.06.exe | C:\Users\admin\AppData\Local\Temp\nskE080.tmp\LangDLL.dll | executable | |
MD5:3DD80DFF583544514EEB3A5ED851A519 | SHA256:86CFF5EACA76C49F924CB123D242FDCFD45AB99C4B638D3B8F4A8CFB1970AB5B | |||
| 792 | CDex-2.06.exe | C:\Users\admin\AppData\Local\Temp\nskE080.tmp\System.dll | executable | |
MD5:75ED96254FBF894E42058062B4B4F0D1 | SHA256:A632D74332B3F08F834C732A103DAFEB09A540823A2217CA7F49159755E8F1D7 | |||
| 792 | CDex-2.06.exe | C:\Users\admin\AppData\Local\Temp\nsd176384333057\css\sdk-ui\images\progress-bg.png | image | |
MD5:E9F12F92A9EEB8EBE911080721446687 | SHA256:C1CF449536BC2778E27348E45F0F53D04C284109199FB7A9AF7A61016B91F8BC | |||
| 792 | CDex-2.06.exe | C:\Users\admin\AppData\Local\Temp\nsd176384333057\css\main.css | text | |
MD5:9B27E2A266FE15A3AABFE635C29E8923 | SHA256:166AA42BC5216C5791388847AE114EC0671A0D97B9952D14F29419B8BE3FB23F | |||
| 792 | CDex-2.06.exe | C:\Users\admin\AppData\Local\Temp\nsd176384333057\css\sdk-ui\button.css | text | |
MD5:37E1FF96E084EC201F0D95FEEF4D5E94 | SHA256:8E806F5B94FC294E918503C8053EF1284E4F4B1E02C7DA4F4635E33EC33E0534 | |||
| 792 | CDex-2.06.exe | C:\Users\admin\AppData\Local\Temp\nsd176384333057\css\ie6_main.css | text | |
MD5:74F08D5A243AE79F1DE64DFFDAF846CB | SHA256:15590060BFD227F656E569031113A080E0D45621A5C944DFC352F869EADAFEF2 | |||
| 792 | CDex-2.06.exe | C:\Users\admin\AppData\Local\Temp\nsd176384333057\css\sdk-ui\browse.css | text | |
MD5:6009D6E864F60AEA980A9DF94C1F7E1C | SHA256:5EF48A8C8C3771B4F233314D50DD3B5AFDCD99DD4B74A9745C8FE7B22207056D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
792 | CDex-2.06.exe | HEAD | 200 | 146.185.27.53:80 | http://cdneu.stocksigngift.com/ofr/Tavasat/Tavasat_09Feb17.cis | GB | — | — | malicious |
792 | CDex-2.06.exe | POST | 200 | 54.76.13.179:80 | http://rp.stocksigngift.com/ | IE | — | — | malicious |
792 | CDex-2.06.exe | POST | 200 | 54.76.13.179:80 | http://rp.stocksigngift.com/ | IE | — | — | malicious |
792 | CDex-2.06.exe | POST | 200 | 54.76.13.179:80 | http://rp.stocksigngift.com/ | IE | — | — | malicious |
792 | CDex-2.06.exe | POST | 200 | 52.48.96.210:80 | http://os.stocksigngift.com/Fusioncdex/ | IE | binary | 668 Kb | malicious |
792 | CDex-2.06.exe | POST | 200 | 54.76.13.179:80 | http://rp.stocksigngift.com/ | IE | — | — | malicious |
792 | CDex-2.06.exe | POST | 200 | 54.76.13.179:80 | http://rp.stocksigngift.com/ | IE | — | — | malicious |
792 | CDex-2.06.exe | POST | 200 | 54.76.13.179:80 | http://rp.stocksigngift.com/ | IE | — | — | malicious |
792 | CDex-2.06.exe | POST | 200 | 54.76.13.179:80 | http://rp.stocksigngift.com/ | IE | — | — | malicious |
792 | CDex-2.06.exe | POST | 200 | 54.76.13.179:80 | http://rp.stocksigngift.com/ | IE | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
792 | CDex-2.06.exe | 54.76.13.179:80 | rp.stocksigngift.com | Amazon.com, Inc. | IE | unknown |
792 | CDex-2.06.exe | 52.48.96.210:80 | os.stocksigngift.com | Amazon.com, Inc. | IE | whitelisted |
792 | CDex-2.06.exe | 146.185.27.53:80 | img.stocksigngift.com | UK-2 Limited | GB | malicious |
4020 | instup.exe | 2.16.186.104:80 | k6375621.iavs9x.u.avast.com | Akamai International B.V. | — | whitelisted |
4020 | instup.exe | 5.45.62.121:443 | auth.ff.avast.com | AVAST Software s.r.o. | NL | malicious |
4020 | instup.exe | 2.16.186.50:80 | k6375621.iavs9x.u.avast.com | Akamai International B.V. | — | whitelisted |
4020 | instup.exe | 2.16.186.57:80 | f6761140.vpsnitro.u.avast.com | Akamai International B.V. | — | whitelisted |
4020 | instup.exe | 2.16.186.105:80 | f6761140.vpsnitro.u.avast.com | Akamai International B.V. | — | whitelisted |
1452 | instup.exe | 8.8.8.8:53 | — | Google Inc. | US | malicious |
1452 | instup.exe | 2.16.186.115:80 | j2123265.vpsnitrotiny.u.avast.com | Akamai International B.V. | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
rp.stocksigngift.com |
| malicious |
os.stocksigngift.com |
| malicious |
img.stocksigngift.com |
| malicious |
cdneu.stocksigngift.com |
| malicious |
cdnus.stocksigngift.com |
| malicious |
www.google-analytics.com |
| whitelisted |
v7event.stats.avast.com |
| whitelisted |
shepherd.ff.avast.com |
| whitelisted |
alpha-license-dealer.ff.avast.com |
| whitelisted |
alpha-iqs.ff.avast.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
792 | CDex-2.06.exe | Misc activity | [PT ADWARE] PUP.Optional.InstallCore Artifact M2 |
792 | CDex-2.06.exe | Misc activity | [PT ADWARE] PUP.Optional.InstallCore Artifact M1 |
792 | CDex-2.06.exe | Misc activity | [PT ADWARE] PUP.Optional.InstallCore Artifact M3 |
792 | CDex-2.06.exe | Misc activity | [PT ADWARE] PUP.Optional.InstallCore Artifact M4 |
2056 | AvEmUpdate.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
instup.exe | [2018-06-28 22:06:56.911] [error ] [settings ] [ 4020: 1896] Failed to get program directory
Exception: Unable to retrieve path of the program directory!
Code: 0x00000002 (2)
|
AvastSvc.exe | [2018-06-28 22:08:09.833] [error ] [aavm ] [ 1508: 4068] Exception: Could not delay load dll: anen.dll
Code: 0x0000007e (126)
|
AvastSvc.exe | [2018-06-28 22:08:10.192] [error ] [ffl2 ] [ 1508: 3416] failed to load key 0 (error 2)
|
AvastSvc.exe | [2018-06-28 22:08:10.192] [error ] [av_pp_prov ] [ 1508: 4068] app.alpha.GetAvailableTrials failed: Request 'app.alpha.GetAvailableTrials' was not processed. Routing parameters:
|
AvastSvc.exe | [2018-06-28 22:08:10.411] [error ] [av_pp_prov ] [ 1508: 2460] app.alpha.GetAvailableTrials failed: Request 'app.alpha.GetAvailableTrials' was not processed. Routing parameters:
|
AvastSvc.exe | [2018-06-28 22:08:10.536] [error ] [av_pp_prov ] [ 1508: 2124] app.alpha.GetAvailableTrials failed: Request 'app.alpha.GetAvailableTrials' was not processed. Routing parameters:
|
AvastSvc.exe | [2018-06-28 22:08:10.802] [error ] [av_pp_prov ] [ 1508: 4008] app.alpha.GetAvailableTrials failed: Request 'app.alpha.GetAvailableTrials' was not processed. Routing parameters:
|
AvastSvc.exe | [2018-06-28 22:08:11.145] [error ] [ffl2 ] [ 1508: 1332] failed to load key 0 (error 2)
|
AvastSvc.exe | [2018-06-28 22:08:11.630] [error ] [av_pp_prov ] [ 1508: 2660] GetCleanupLicenseParams: Unable to open the license file 'C:\ProgramData\AVAST Software\Subscriptions\license.avastgf'!
|
AvastSvc.exe | [2018-06-28 22:08:11.630] [error ] [av_pp_prov ] [ 1508: 2660] Exception: Request 'app.pam.GetBrowserLeakedPassword' was not processed. Routing parameters:
|