URL:

https://cdn-download.avgbrowser.com/avg/avg_secure_browser_setup.exe?nouac=1&cid=9228

Full analysis: https://app.any.run/tasks/2ef42ada-8ba1-42ba-8b8e-8389a70fd256
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: January 03, 2025, 04:24:32
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
loader
evasion
Indicators:
MD5:

1364290496368E5012D121755A90843B

SHA1:

257EED0383451A6344CC53CBC82C6E95C2E52032

SHA256:

A1F91E3CFBA508311C937A391EE1250A7164F383E161C19B2F25EA95E26B4B2C

SSDEEP:

3:N8cQFnp6SHXyK5tCS3iY4/+RPafXXdn:2cgnUaiK5jSY4/+RPaf9n

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • ajEAC4.exe (PID: 1228)
    • Actions looks like stealing of personal data

      • ajEAC4.exe (PID: 1228)
      • AVGBrowser.exe (PID: 6520)
    • Changes the autorun value in the registry

      • AVGBrowserUpdate.exe (PID: 5536)
      • AVGBrowser.exe (PID: 5572)
      • AVGBrowser.exe (PID: 1792)
      • AVGBrowser.exe (PID: 768)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • avg_secure_browser_setup.exe (PID: 644)
      • ajEAC4.exe (PID: 1228)
      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
      • AVGBrowserInstaller.exe (PID: 7064)
      • setup.exe (PID: 6316)
    • The process verifies whether the antivirus software is installed

      • avg_secure_browser_setup.exe (PID: 644)
      • ajEAC4.exe (PID: 1228)
    • Reads the BIOS version

      • ajEAC4.exe (PID: 1228)
      • AVGBrowser.exe (PID: 5572)
      • AVGBrowser.exe (PID: 1792)
      • AVGBrowser.exe (PID: 768)
      • AVGBrowser.exe (PID: 6564)
    • Reads security settings of Internet Explorer

      • ajEAC4.exe (PID: 1228)
      • AVGBrowserUpdate.exe (PID: 5536)
      • AVGBrowserProtect.exe (PID: 4876)
      • setup.exe (PID: 6528)
      • AVGBrowser.exe (PID: 7144)
      • ShellExperienceHost.exe (PID: 6732)
    • Searches for installed software

      • ajEAC4.exe (PID: 1228)
      • setup.exe (PID: 6316)
      • AVGBrowser.exe (PID: 5572)
      • AVGBrowser.exe (PID: 1792)
      • AVGBrowser.exe (PID: 768)
      • AVGBrowser.exe (PID: 6564)
    • Checks Windows Trust Settings

      • ajEAC4.exe (PID: 1228)
    • Starts itself from another location

      • AVGBrowserUpdate.exe (PID: 5536)
    • Creates/Modifies COM task schedule object

      • AVGBrowserUpdateComRegisterShell64.exe (PID: 5404)
      • AVGBrowserUpdate.exe (PID: 2992)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 420)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 7152)
      • AVGBrowserUpdate.exe (PID: 5536)
    • Potential Corporate Privacy Violation

      • AVGBrowserUpdate.exe (PID: 440)
    • Process requests binary or script from the Internet

      • AVGBrowserUpdate.exe (PID: 440)
    • Application launched itself

      • setup.exe (PID: 6316)
      • AVGBrowser.exe (PID: 5572)
      • AVGBrowser.exe (PID: 1792)
      • AVGBrowser.exe (PID: 6500)
      • setup.exe (PID: 6528)
      • AVGBrowser.exe (PID: 768)
      • AVGBrowser.exe (PID: 4020)
      • AVGBrowser.exe (PID: 6564)
      • AVGBrowser.exe (PID: 6520)
    • Creates a software uninstall entry

      • setup.exe (PID: 6316)
      • ajEAC4.exe (PID: 1228)
      • AVGBrowser.exe (PID: 5572)
      • AVGBrowser.exe (PID: 1792)
      • AVGBrowser.exe (PID: 768)
      • AVGBrowser.exe (PID: 6564)
    • The process checks if it is being run in the virtual environment

      • AVGBrowser.exe (PID: 1792)
      • AVGBrowser.exe (PID: 768)
      • AVGBrowser.exe (PID: 6564)
    • Reads the date of Windows installation

      • setup.exe (PID: 6528)
      • AVGBrowser.exe (PID: 7144)
      • AVGBrowser.exe (PID: 1920)
    • Reads Mozilla Firefox installation path

      • AVGBrowser.exe (PID: 768)
    • Checks for external IP

      • AVGBrowser.exe (PID: 6176)
      • AVGBrowser.exe (PID: 1216)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 6308)
    • The sample compiled with arabic language support

      • chrome.exe (PID: 6308)
      • avg_secure_browser_setup.exe (PID: 644)
      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
      • ajEAC4.exe (PID: 1228)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 6308)
    • The process uses the downloaded file

      • chrome.exe (PID: 7140)
      • chrome.exe (PID: 6308)
    • Checks supported languages

      • avg_secure_browser_setup.exe (PID: 644)
      • ajEAC4.exe (PID: 1228)
      • AVGBrowserUpdate.exe (PID: 5536)
      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 2992)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 5404)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 420)
      • AVGBrowserUpdate.exe (PID: 5556)
      • AVGBrowserUpdate.exe (PID: 3208)
      • AVGBrowserUpdate.exe (PID: 440)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 7152)
      • AVGBrowserInstaller.exe (PID: 7064)
      • setup.exe (PID: 6316)
      • setup.exe (PID: 4244)
      • AVGBrowserCrashHandler.exe (PID: 1856)
      • AVGBrowserCrashHandler64.exe (PID: 1868)
      • AVGBrowser.exe (PID: 5572)
      • AVGBrowser.exe (PID: 7152)
      • AVGBrowser.exe (PID: 4704)
      • AVGBrowser.exe (PID: 1796)
      • AVGBrowser.exe (PID: 6416)
      • AVGBrowser.exe (PID: 6548)
      • AVGBrowser.exe (PID: 7060)
      • AVGBrowser.exe (PID: 776)
      • AVGBrowser.exe (PID: 6016)
      • AVGBrowser.exe (PID: 1792)
      • AVGBrowser.exe (PID: 1344)
      • AVGBrowser.exe (PID: 6176)
      • AVGBrowser.exe (PID: 1856)
      • AVGBrowser.exe (PID: 3052)
      • AVGBrowser.exe (PID: 6168)
      • AVGBrowser.exe (PID: 1200)
      • AVGBrowser.exe (PID: 6544)
      • AVGBrowser.exe (PID: 2600)
      • AVGBrowser.exe (PID: 5880)
      • AVGBrowser.exe (PID: 6508)
      • AVGBrowser.exe (PID: 3632)
      • AVGBrowser.exe (PID: 5392)
      • AVGBrowser.exe (PID: 3656)
      • AVGBrowser.exe (PID: 1684)
      • AVGBrowser.exe (PID: 3092)
      • AVGBrowser.exe (PID: 3876)
      • AVGBrowser.exe (PID: 1192)
      • AVGBrowser.exe (PID: 4668)
      • AVGBrowser.exe (PID: 3144)
      • AVGBrowser.exe (PID: 2280)
      • AVGBrowser.exe (PID: 6420)
      • AVGBrowser.exe (PID: 2224)
      • AVGBrowser.exe (PID: 5880)
      • AVGBrowser.exe (PID: 6016)
      • AVGBrowser.exe (PID: 7008)
      • AVGBrowser.exe (PID: 1016)
      • AVGBrowser.exe (PID: 1304)
      • AVGBrowser.exe (PID: 3632)
      • AVGBrowser.exe (PID: 4876)
      • AVGBrowser.exe (PID: 6952)
      • AVGBrowser.exe (PID: 1200)
      • AVGBrowser.exe (PID: 628)
      • AVGBrowser.exe (PID: 1920)
      • AVGBrowser.exe (PID: 5556)
      • AVGBrowser.exe (PID: 6180)
      • AVGBrowser.exe (PID: 4308)
      • AVGBrowser.exe (PID: 3864)
      • AVGBrowser.exe (PID: 2904)
      • AVGBrowser.exe (PID: 4968)
      • AVGBrowser.exe (PID: 836)
      • AVGBrowser.exe (PID: 3888)
      • AVGBrowser.exe (PID: 7008)
      • AVGBrowser.exe (PID: 7024)
      • AVGBrowser.exe (PID: 6500)
      • AVGBrowser.exe (PID: 5876)
      • AVGBrowserProtect.exe (PID: 4876)
      • AVGBrowser.exe (PID: 1348)
      • AVGBrowser.exe (PID: 1480)
      • AVGBrowser.exe (PID: 5456)
      • AVGBrowser.exe (PID: 1076)
      • AVGBrowser.exe (PID: 1328)
      • setup.exe (PID: 3772)
      • AVGBrowser.exe (PID: 7144)
      • AVGBrowser.exe (PID: 768)
      • AVGBrowser.exe (PID: 1620)
      • setup.exe (PID: 6528)
      • AVGBrowser.exe (PID: 1076)
      • AVGBrowser.exe (PID: 4648)
      • AVGBrowser.exe (PID: 6176)
      • AVGBrowser.exe (PID: 5752)
      • AVGBrowser.exe (PID: 204)
      • AVGBrowser.exe (PID: 4036)
      • AVGBrowser.exe (PID: 3996)
      • AVGBrowser.exe (PID: 6416)
      • AVGBrowser.exe (PID: 3544)
      • AVGBrowser.exe (PID: 1920)
      • AVGBrowser.exe (PID: 6528)
      • AVGBrowser.exe (PID: 7004)
      • AVGBrowser.exe (PID: 4444)
      • AVGBrowser.exe (PID: 6564)
      • AVGBrowser.exe (PID: 3656)
      • AVGBrowser.exe (PID: 4020)
      • AVGBrowser.exe (PID: 2120)
      • AVGBrowser.exe (PID: 6172)
      • AVGBrowser.exe (PID: 1216)
      • AVGBrowser.exe (PID: 6516)
      • AVGBrowser.exe (PID: 7032)
      • AVGBrowser.exe (PID: 4624)
      • AVGBrowser.exe (PID: 1292)
      • AVGBrowser.exe (PID: 7064)
      • AVGBrowser.exe (PID: 6572)
      • AVGBrowser.exe (PID: 1828)
      • AVGBrowser.exe (PID: 2212)
      • AVGBrowser.exe (PID: 4672)
      • AVGBrowser.exe (PID: 6520)
      • AVGBrowser.exe (PID: 3688)
      • AVGBrowser.exe (PID: 3724)
      • AVGBrowser.exe (PID: 2232)
      • AVGBrowser.exe (PID: 6936)
      • AVGBrowser.exe (PID: 6856)
      • AVGBrowser.exe (PID: 3692)
      • AVGBrowser.exe (PID: 6792)
      • AVGBrowser.exe (PID: 4384)
      • ShellExperienceHost.exe (PID: 6732)
      • AVGBrowser.exe (PID: 4592)
      • AVGBrowser.exe (PID: 6748)
      • AVGBrowser.exe (PID: 2676)
    • The sample compiled with english language support

      • avg_secure_browser_setup.exe (PID: 644)
      • ajEAC4.exe (PID: 1228)
      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
      • AVGBrowserUpdate.exe (PID: 440)
      • AVGBrowserInstaller.exe (PID: 7064)
      • setup.exe (PID: 6316)
    • Reads the computer name

      • avg_secure_browser_setup.exe (PID: 644)
      • ajEAC4.exe (PID: 1228)
      • AVGBrowserUpdate.exe (PID: 5536)
      • AVGBrowserUpdate.exe (PID: 2992)
      • AVGBrowserUpdate.exe (PID: 3208)
      • AVGBrowserUpdate.exe (PID: 5556)
      • AVGBrowserUpdate.exe (PID: 440)
      • AVGBrowserInstaller.exe (PID: 7064)
      • setup.exe (PID: 6316)
      • AVGBrowser.exe (PID: 5572)
      • AVGBrowser.exe (PID: 4704)
      • AVGBrowser.exe (PID: 6416)
      • AVGBrowser.exe (PID: 1792)
      • AVGBrowser.exe (PID: 3052)
      • AVGBrowser.exe (PID: 6168)
      • AVGBrowser.exe (PID: 6500)
      • AVGBrowserProtect.exe (PID: 4876)
      • AVGBrowser.exe (PID: 836)
      • AVGBrowser.exe (PID: 7144)
      • AVGBrowser.exe (PID: 768)
      • AVGBrowser.exe (PID: 1620)
      • setup.exe (PID: 6528)
      • AVGBrowser.exe (PID: 6176)
      • AVGBrowser.exe (PID: 1076)
      • AVGBrowser.exe (PID: 1920)
      • AVGBrowser.exe (PID: 4020)
      • AVGBrowser.exe (PID: 6528)
      • AVGBrowser.exe (PID: 6564)
      • AVGBrowser.exe (PID: 3656)
      • AVGBrowser.exe (PID: 7032)
      • AVGBrowser.exe (PID: 1216)
      • AVGBrowser.exe (PID: 2212)
      • AVGBrowser.exe (PID: 6520)
      • AVGBrowser.exe (PID: 6792)
      • ShellExperienceHost.exe (PID: 6732)
    • Reads Environment values

      • avg_secure_browser_setup.exe (PID: 644)
      • ajEAC4.exe (PID: 1228)
      • AVGBrowser.exe (PID: 5572)
      • AVGBrowser.exe (PID: 1792)
      • AVGBrowser.exe (PID: 768)
      • AVGBrowser.exe (PID: 6564)
    • Process checks computer location settings

      • avg_secure_browser_setup.exe (PID: 644)
      • ajEAC4.exe (PID: 1228)
      • AVGBrowserUpdate.exe (PID: 5536)
      • AVGBrowser.exe (PID: 5572)
      • AVGBrowser.exe (PID: 7060)
      • AVGBrowser.exe (PID: 6548)
      • AVGBrowser.exe (PID: 776)
      • AVGBrowser.exe (PID: 1792)
      • AVGBrowser.exe (PID: 1200)
      • AVGBrowser.exe (PID: 3876)
      • AVGBrowser.exe (PID: 5392)
      • AVGBrowser.exe (PID: 3864)
      • AVGBrowser.exe (PID: 2904)
      • AVGBrowser.exe (PID: 1348)
      • AVGBrowser.exe (PID: 7144)
      • AVGBrowser.exe (PID: 768)
      • AVGBrowser.exe (PID: 5752)
      • AVGBrowser.exe (PID: 7004)
      • AVGBrowser.exe (PID: 4036)
      • AVGBrowser.exe (PID: 6416)
      • AVGBrowser.exe (PID: 204)
      • AVGBrowser.exe (PID: 3544)
      • AVGBrowser.exe (PID: 3996)
      • AVGBrowser.exe (PID: 1920)
      • AVGBrowser.exe (PID: 6172)
      • AVGBrowser.exe (PID: 6564)
      • AVGBrowser.exe (PID: 1292)
      • AVGBrowser.exe (PID: 7064)
      • AVGBrowser.exe (PID: 1828)
      • AVGBrowser.exe (PID: 4624)
      • AVGBrowser.exe (PID: 3692)
      • AVGBrowser.exe (PID: 6572)
      • AVGBrowser.exe (PID: 2232)
      • AVGBrowser.exe (PID: 3724)
      • AVGBrowser.exe (PID: 6936)
      • AVGBrowser.exe (PID: 6856)
    • Create files in a temporary directory

      • avg_secure_browser_setup.exe (PID: 644)
      • ajEAC4.exe (PID: 1228)
      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 440)
      • AVGBrowser.exe (PID: 5572)
      • AVGBrowser.exe (PID: 1792)
      • AVGBrowser.exe (PID: 768)
      • AVGBrowser.exe (PID: 6564)
    • Sends debugging messages

      • avg_secure_browser_setup.exe (PID: 644)
      • ajEAC4.exe (PID: 1228)
    • Reads the software policy settings

      • ajEAC4.exe (PID: 1228)
      • AVGBrowserUpdate.exe (PID: 5556)
      • AVGBrowserUpdate.exe (PID: 440)
    • Reads the machine GUID from the registry

      • ajEAC4.exe (PID: 1228)
      • AVGBrowserUpdate.exe (PID: 5536)
      • AVGBrowserUpdate.exe (PID: 440)
      • AVGBrowser.exe (PID: 5572)
      • AVGBrowser.exe (PID: 1792)
      • AVGBrowser.exe (PID: 768)
      • AVGBrowser.exe (PID: 6564)
    • Checks proxy server information

      • ajEAC4.exe (PID: 1228)
      • AVGBrowserUpdate.exe (PID: 5556)
      • AVGBrowserUpdate.exe (PID: 440)
      • AVGBrowser.exe (PID: 5572)
      • AVGBrowser.exe (PID: 1792)
      • AVGBrowserProtect.exe (PID: 4876)
      • AVGBrowser.exe (PID: 768)
      • AVGBrowser.exe (PID: 6564)
    • Creates files or folders in the user directory

      • ajEAC4.exe (PID: 1228)
      • AVGBrowserUpdate.exe (PID: 5536)
      • AVGBrowserUpdate.exe (PID: 440)
      • AVGBrowserInstaller.exe (PID: 7064)
      • setup.exe (PID: 4244)
      • setup.exe (PID: 6316)
      • AVGBrowser.exe (PID: 5572)
      • AVGBrowser.exe (PID: 6416)
      • AVGBrowser.exe (PID: 1344)
      • AVGBrowser.exe (PID: 1792)
      • AVGBrowser.exe (PID: 3052)
      • AVGBrowser.exe (PID: 5876)
      • AVGBrowser.exe (PID: 6500)
      • AVGBrowser.exe (PID: 768)
      • setup.exe (PID: 6528)
      • AVGBrowser.exe (PID: 6176)
      • AVGBrowser.exe (PID: 4020)
      • AVGBrowser.exe (PID: 3656)
      • AVGBrowser.exe (PID: 6564)
      • AVGBrowser.exe (PID: 1216)
    • The sample compiled with bulgarian language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • The sample compiled with czech language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • The sample compiled with german language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • The sample compiled with japanese language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • The sample compiled with portuguese language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • The sample compiled with french language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • The sample compiled with Indonesian language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • The sample compiled with Italian language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • The sample compiled with korean language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • The sample compiled with swedish language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • The sample compiled with polish language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • The sample compiled with russian language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • The sample compiled with slovak language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • The sample compiled with chinese language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • The sample compiled with turkish language support

      • AVGBrowserUpdateSetup.exe (PID: 4640)
      • AVGBrowserUpdate.exe (PID: 5536)
    • Reads CPU info

      • AVGBrowser.exe (PID: 1792)
      • AVGBrowser.exe (PID: 768)
      • AVGBrowser.exe (PID: 6564)
    • Manual execution by a user

      • AVGBrowser.exe (PID: 6564)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
275
Monitored processes
139
Malicious processes
13
Suspicious processes
2

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs avg_secure_browser_setup.exe ajeac4.exe avgbrowserupdatesetup.exe avgbrowserupdate.exe avgbrowserupdate.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdate.exe avgbrowserupdate.exe no specs avgbrowserupdate.exe chrome.exe no specs avgbrowserinstaller.exe setup.exe setup.exe no specs chrome.exe no specs avgbrowsercrashhandler.exe no specs avgbrowsercrashhandler64.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowserprotect.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs setup.exe no specs setup.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs chrome.exe no specs chrome.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs shellexperiencehost.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
204"C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exe" --type=renderer --string-annotations=is-enterprise-managed=no --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --field-trial-handle=3312,i,6584862248514486914,5518113991943860935,262144 --variations-seed-version --mojo-platform-channel-handle=3320 /prefetch:1C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
LOW
Description:
AVG Secure Browser
Exit code:
0
Version:
131.0.27760.140
420"C:\Users\admin\AppData\Local\AVG\Browser\Update\1.8.1693.6\AVGBrowserUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\AVG\Browser\Update\1.8.1693.6\AVGBrowserUpdateComRegisterShell64.exeAVGBrowserUpdate.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
AVG Browser Com Register Shell 64
Exit code:
0
Version:
1.8.1693.6
Modules
Images
c:\users\admin\appdata\local\avg\browser\update\1.8.1693.6\avgbrowserupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
440"C:\Users\admin\AppData\Local\AVG\Browser\Update\AVGBrowserUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\AVG\Browser\Update\AVGBrowserUpdate.exe
svchost.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
AVG Browser
Exit code:
0
Version:
1.8.1693.6
Modules
Images
c:\users\admin\appdata\local\avg\browser\update\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
628"C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --field-trial-handle=4120,i,2574111663728628735,9386994638179183937,262144 --variations-seed-version --mojo-platform-channel-handle=4268 /prefetch:8C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
LOW
Description:
AVG Secure Browser
Exit code:
0
Version:
131.0.27760.140
644"C:\Users\admin\Downloads\avg_secure_browser_setup.exe" C:\Users\admin\Downloads\avg_secure_browser_setup.exe
chrome.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
AVG Secure Browser Setup
Exit code:
3221225547
Version:
8.11.9.7512
Modules
Images
c:\users\admin\downloads\avg_secure_browser_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
768AVGBrowser.exe --check-run=src=installerC:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exe
ajEAC4.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
AVG Secure Browser
Exit code:
0
Version:
131.0.27760.140
776"C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exe" --type=renderer --string-annotations=is-enterprise-managed=no --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=3396,i,11888414578589681897,15049123271604788840,262144 --variations-seed-version --mojo-platform-channel-handle=3540 /prefetch:1C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
LOW
Description:
AVG Secure Browser
Exit code:
0
Version:
131.0.27760.140
Modules
Images
c:\users\admin\appdata\local\avg\browser\application\avgbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\avg\browser\application\131.0.27760.140\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
836"C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --field-trial-handle=5432,i,2574111663728628735,9386994638179183937,262144 --variations-seed-version --mojo-platform-channel-handle=5716 /prefetch:8C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
AVG Secure Browser
Exit code:
0
Version:
131.0.27760.140
1016"C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --field-trial-handle=5036,i,2574111663728628735,9386994638179183937,262144 --variations-seed-version --mojo-platform-channel-handle=5508 /prefetch:8C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
LOW
Description:
AVG Secure Browser
Exit code:
0
Version:
131.0.27760.140
1076"C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exe" --type=utility --utility-sub-type=chrome.mojom.ProfileImport --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --field-trial-handle=5268,i,2574111663728628735,9386994638179183937,262144 --variations-seed-version --mojo-platform-channel-handle=4384 /prefetch:8C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
AVG Secure Browser
Exit code:
0
Version:
131.0.27760.140
Total events
43 352
Read events
41 418
Write events
1 843
Delete events
91

Modification events

(PID) Process:(6308) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6308) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6308) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6308) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(6308) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(7140) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
01000000000000003CAF4769975DDB01
(PID) Process:(1228) ajEAC4.exeKey:HKEY_CURRENT_USER\SOFTWARE\AVG\Browser
Operation:writeName:installer_run_count
Value:
1
(PID) Process:(1228) ajEAC4.exeKey:HKEY_CURRENT_USER\SOFTWARE\AVG\Browser
Operation:writeName:machine_id
Value:
0000B0E1009ABA5E95F7227E57434874
(PID) Process:(1228) ajEAC4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1228) ajEAC4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
184
Suspicious files
797
Text files
182
Unknown types
29

Dropped files

PID
Process
Filename
Type
6308chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF135e5f.TMP
MD5:
SHA256:
6308chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF135e5f.TMP
MD5:
SHA256:
6308chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6308chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF135e5f.TMP
MD5:
SHA256:
6308chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF135e5f.TMP
MD5:
SHA256:
6308chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6308chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
6308chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
6308chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF135e6f.TMP
MD5:
SHA256:
6308chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
33
TCP/UDP connections
157
DNS requests
163
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.32.238.112:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6528
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
2676
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2676
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6308
chrome.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
6308
chrome.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
6308
chrome.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAQ1YD96iIrhbAWwDxU8xvw%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4308
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.32.238.112:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.21.110.139:443
www.bing.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6700
chrome.exe
23.32.238.98:443
cdn-download.avgbrowser.com
Akamai International B.V.
DE
malicious
6308
chrome.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.32.238.112
  • 23.32.238.107
whitelisted
www.microsoft.com
  • 2.23.181.156
  • 95.101.149.131
whitelisted
google.com
  • 142.250.185.78
whitelisted
www.bing.com
  • 2.21.110.139
  • 2.21.110.146
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
cdn-download.avgbrowser.com
  • 23.32.238.98
  • 23.32.238.153
malicious
accounts.google.com
  • 74.125.71.84
  • 173.194.79.84
whitelisted
go.microsoft.com
  • 23.56.254.14
whitelisted
sb-ssl.google.com
  • 142.250.186.110
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
Process
Message
avg_secure_browser_setup.exe
2025-01-03T04:25:15 [libnsis] {00000284:000006e0} <2:Info> (893f00f663353e48\src\jsis-plugins\plugins\Plugin.cpp:82) JSIS Plugin logging enabled
avg_secure_browser_setup.exe
2025-01-03T04:25:15 [libnsis] {00000284:000006e0} <4:Error> (893f00f663353e48\src\jsis-plugins\plugins\UtilitiesPlugin\TagData.cpp:85) 0x00000400000715 91aa05bf654a77ad\src\sbplugins\windows\RCData.cpp:62
avg_secure_browser_setup.exe
2025-01-03T04:25:15 [libnsis] {00000284:000006e0} <1:Debug> (91aa05bf654a77ad\src\sbplugins\windows\RCData.cpp:62) Throwing exception 0x00000400000715
ajEAC4.exe
2025-01-03T04:25:16 [libnsis] {000004cc:00001424} <2:Info> (893f00f663353e48\src\jsis-plugins\plugins\Plugin.cpp:82) JSIS Plugin logging enabled
ajEAC4.exe
2025-01-03T04:25:17 [libnsis] {000004cc:00001424} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:75) Execute Sqlite query SELECT ((visits.visit_time/1000000)-11644473600) /60 /60 / 24 AS vtime FROM 'visits' WHERE vtime >= 20061 AND vtime <= 20092 GROUP BY vtime
ajEAC4.exe
2025-01-03T04:25:17 [libnsis] {000004cc:00001424} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:38) Oepn Sqlite DB C:\Users\admin\AppData\Local\Temp\nsoEB9E.tmp\CR.History.tmp
ajEAC4.exe
2025-01-03T04:25:17 [libnsis] {000004cc:00001424} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:38) Oepn Sqlite DB C:\Users\admin\AppData\Local\Temp\nsoEB9E.tmp\CR.History.tmp
ajEAC4.exe
2025-01-03T04:25:17 [libnsis] {000004cc:00001424} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:75) Execute Sqlite query SELECT ((visits.visit_time/1000000)-11644473600) /60 /60 / 24 AS vtime FROM 'visits' WHERE vtime >= 20061 AND vtime <= 20092 GROUP BY vtime
ajEAC4.exe
2025-01-03T04:25:17 [libnsis] {000004cc:00001424} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:38) Oepn Sqlite DB C:\Users\admin\AppData\Local\Temp\nsoEB9E.tmp\FF.places.tmp
ajEAC4.exe
2025-01-03T04:25:17 [libnsis] {000004cc:00001424} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:75) Execute Sqlite query SELECT last_visit_date / 1000000 /60 /60 / 24 AS vtime FROM 'moz_places' WHERE vtime >= 20061 AND vtime <= 20092 GROUP BY vtime