File name:

PlantsVsZombiesRH.exe

Full analysis: https://app.any.run/tasks/a726be72-8571-4dde-96f1-37711925c609
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: October 26, 2024, 19:15:27
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

93FA75014C24F05DFE9FEDC716F4F9F7

SHA1:

E2A67ADF343FA65CC1597A261C31B352CDB3BB62

SHA256:

C3C877EE9929FA9EE01CBA544D1C16CA5B4C2E5DE4B5B388AB8AE00A0B4D478D

SSDEEP:

24576:Q7gQwHki3jW1Z0qzYIoHX7cD/xauD55wItdAkZIgdMqo:Q7g41Z0qzYIoHX7cD/xauD55wItdAkma

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • CCleaner64.exe (PID: 6792)
      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
    • Steals credentials from Web Browsers

      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
    • Changes the autorun value in the registry

      • CCleaner64.exe (PID: 528)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • CCleaner64.exe (PID: 6792)
      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
    • Reads the date of Windows installation

      • CCleaner64.exe (PID: 6792)
      • CCleaner64.exe (PID: 616)
    • Application launched itself

      • CCleaner64.exe (PID: 6792)
      • CCleaner64.exe (PID: 616)
    • Executable content was dropped or overwritten

      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
    • Reads Internet Explorer settings

      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
    • Searches for installed software

      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
    • Checks Windows Trust Settings

      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
    • The process verifies whether the antivirus software is installed

      • CCleaner64.exe (PID: 528)
    • Checks for external IP

      • CCleaner64.exe (PID: 616)
  • INFO

    • Manual execution by a user

      • CCleaner64.exe (PID: 6792)
      • Taskmgr.exe (PID: 6908)
      • Taskmgr.exe (PID: 1280)
    • Reads the computer name

      • CCleaner64.exe (PID: 6792)
      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
      • OfficeClickToRun.exe (PID: 5736)
    • Reads Environment values

      • CCleaner64.exe (PID: 6792)
      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
    • The process uses the downloaded file

      • CCleaner64.exe (PID: 6792)
      • CCleaner64.exe (PID: 616)
    • Checks supported languages

      • CCleaner64.exe (PID: 6792)
      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
      • OfficeClickToRun.exe (PID: 5736)
    • Process checks computer location settings

      • CCleaner64.exe (PID: 6792)
      • CCleaner64.exe (PID: 616)
    • Sends debugging messages

      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
    • Reads product name

      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
    • Reads CPU info

      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
    • Reads the machine GUID from the registry

      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
      • OfficeClickToRun.exe (PID: 5736)
    • Creates files in the program directory

      • CCleaner64.exe (PID: 616)
      • CCleaner64.exe (PID: 528)
    • Creates files or folders in the user directory

      • CCleaner64.exe (PID: 616)
    • Reads the software policy settings

      • CCleaner64.exe (PID: 528)
      • CCleaner64.exe (PID: 616)
    • Checks proxy server information

      • CCleaner64.exe (PID: 616)
      • OfficeClickToRun.exe (PID: 5736)
    • Reads Microsoft Office registry keys

      • OfficeClickToRun.exe (PID: 5736)
    • Reads security settings of Internet Explorer

      • Taskmgr.exe (PID: 1280)
    • Executes as Windows Service

      • OfficeClickToRun.exe (PID: 5736)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:04:27 05:47:46+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.28
CodeSize: 51712
InitializedDataSize: 618496
UninitializedDataSize: -
EntryPoint: 0x1260
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2022.3.20.42458
ProductVersionNumber: 2022.3.20.42458
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 2022.3.20.8562138
LegalCopyright: (c) 2005-2024 Unity Technologies. All rights reserved.
ProductVersion: 2022.3.20f1c1 (82a5dab7aa2a)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start plantsvszombiesrh.exe no specs ccleaner64.exe ccleaner64.exe ccleaner64.exe taskmgr.exe no specs taskmgr.exe officeclicktorun.exe

Process information

PID
CMD
Path
Indicators
Parent process
528"C:\Program Files\CCleaner\CCleaner64.exe" /monitorC:\Program Files\CCleaner\CCleaner64.exe
CCleaner64.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
CCleaner
Version:
6.20.0.10897
Modules
Images
c:\program files\ccleaner\ccleaner64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
616"C:\Program Files\CCleaner\CCleaner64.exe" /uacC:\Program Files\CCleaner\CCleaner64.exe
CCleaner64.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
CCleaner
Exit code:
0
Version:
6.20.0.10897
Modules
Images
c:\program files\ccleaner\ccleaner64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
1280"C:\WINDOWS\system32\taskmgr.exe" /0C:\Windows\System32\Taskmgr.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Manager
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
5736"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /serviceC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Office Click-to-Run (SxS)
Version:
16.0.16026.20140
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
5944"C:\Users\admin\AppData\Local\Temp\PlantsVsZombiesRH.exe" C:\Users\admin\AppData\Local\Temp\PlantsVsZombiesRH.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225781
Version:
2022.3.20.8562138
Modules
Images
c:\users\admin\appdata\local\temp\plantsvszombiesrh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
6792"C:\Program Files\CCleaner\CCleaner64.exe" C:\Program Files\CCleaner\CCleaner64.exe
explorer.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
MEDIUM
Description:
CCleaner
Exit code:
0
Version:
6.20.0.10897
Modules
Images
c:\program files\ccleaner\ccleaner64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
6908"C:\WINDOWS\system32\taskmgr.exe" /0C:\Windows\System32\Taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Manager
Exit code:
3221226540
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
Total events
19 819
Read events
19 681
Write events
84
Delete events
54

Modification events

(PID) Process:(616) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:writeName:DAST
Value:
10/26/2024 19:17:04
(PID) Process:(616) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:writeName:T8062
Value:
0
(PID) Process:(616) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:writeName:UpdateBackground
Value:
1
(PID) Process:(616) CCleaner64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
Operation:writeName:SystemRestorePointCreationFrequency
Value:
0
(PID) Process:(616) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:CCleaner PostInstall
Value:
(PID) Process:(616) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:writeName:FTU
Value:
06/02/2024|3|1
(PID) Process:(616) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:delete valueName:GUID
Value:
(PID) Process:(616) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:delete valueName:GD
Value:
(PID) Process:(616) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:delete valueName:SetupGD
Value:
(PID) Process:(616) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:writeName:NumOfOutdatedDrivers
Value:
0
Executable files
5
Suspicious files
14
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
616CCleaner64.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\ccupdate629_free[1].exe
MD5:
SHA256:
616CCleaner64.exeC:\Program Files\CCleaner\temp_ccupdate\ccupdate629_free.exe
MD5:
SHA256:
616CCleaner64.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ccc0fa1b9f86f7b3.customDestinations-msbinary
MD5:6F8F5AD2FBADCDB535DD539391FC352D
SHA256:78935B0781E31559B57010ABB5BC9305A818813843235244F77CF79EC0DF0F4C
616CCleaner64.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:1896F483AF507232DF1320CD59D776E5
SHA256:158B05BEDD787D6673653BEB0BE50E9E1FDB7FFD63169B85061A327AAAD1DED6
616CCleaner64.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ALQK5LOKBY3FV3ZXLNX3.tempbinary
MD5:6F8F5AD2FBADCDB535DD539391FC352D
SHA256:78935B0781E31559B57010ABB5BC9305A818813843235244F77CF79EC0DF0F4C
616CCleaner64.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:FD0E0E9196C63EC4F5595316F9508EC7
SHA256:8AD5D29AADB3D935EDA6D2EB8B651E8CD6B2D4C320D94EFE399512727FC6D32E
616CCleaner64.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E573CDF4C6D731D56A665145182FD759_AFB3BE9383420FBAFF24AD413EEA555Ebinary
MD5:3769420FF3691FEF49B8F93438757D5C
SHA256:8F7D2680698B687C871807AEFA47BF89E98C6EDA0DC1604ACE876A58E853AB56
616CCleaner64.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E573CDF4C6D731D56A665145182FD759_AFB3BE9383420FBAFF24AD413EEA555Ebinary
MD5:39933963835459F03B9C343963C29513
SHA256:562AAEEE9686BB91E0B876C65582525FBA99467D1FA7846F038911E6B7E64C65
616CCleaner64.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:126F3CE75A435A704959114924ABB013
SHA256:8073BFF5CC2A415502691C34D210F26EECEC226E273C81C1389825E78A6F94C6
616CCleaner64.exeC:\Program Files\CCleaner\gcapi_dll.dllexecutable
MD5:F17F96322F8741FE86699963A1812897
SHA256:8B6CE3A640E2D6F36B0001BE2A1ABB765AE51E62C314A15911E75138CBB544BB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
56
DNS requests
38
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
616
CCleaner64.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
616
CCleaner64.exe
GET
200
2.19.198.72:80
http://ncc.avast.com/ncc.txt
unknown
whitelisted
616
CCleaner64.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAXfj0A2M0oL7zuU%2F%2F2jetU%3D
unknown
whitelisted
616
CCleaner64.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
whitelisted
616
CCleaner64.exe
GET
200
142.250.185.163:80
http://c.pki.goog/r/r1.crl
unknown
whitelisted
616
CCleaner64.exe
GET
200
142.250.185.163:80
http://o.pki.goog/s/wr3/70Q/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQSq0i5t2Pafi2Gw9uzwnc7KTctWgQUx4H1%2FY6I2QA8TWOiUDEkoM4j%2FiMCEQDvREseTpN%2BJxCI23i31F5J
unknown
whitelisted
528
CCleaner64.exe
GET
200
2.19.198.72:80
http://ncc.avast.com/ncc.txt
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.48.23.166:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
23.48.23.166:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5488
MoUsoCoreWorker.exe
23.218.209.163:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
23.218.209.163:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4360
SearchApp.exe
104.126.37.154:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.166
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.218.209.163
whitelisted
google.com
  • 142.250.181.238
whitelisted
www.bing.com
  • 104.126.37.154
  • 104.126.37.179
  • 104.126.37.155
  • 104.126.37.139
  • 104.126.37.153
  • 104.126.37.160
  • 104.126.37.137
  • 104.126.37.186
  • 104.126.37.163
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.2
  • 40.126.31.69
  • 20.190.159.4
  • 20.190.159.23
  • 20.190.159.68
  • 40.126.31.71
  • 20.190.159.71
  • 20.190.159.73
whitelisted
th.bing.com
  • 104.126.37.139
  • 104.126.37.154
  • 104.126.37.137
  • 104.126.37.153
  • 104.126.37.155
  • 104.126.37.179
  • 104.126.37.168
  • 104.126.37.160
  • 104.126.37.163
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted

Threats

PID
Process
Class
Message
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
Process
Message
CCleaner64.exe
[2024-10-26 19:17:04.522] [error ] [settings ] [ 616: 3000] [000000: 0] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner64.exe
[2024-10-26 19:17:04.522] [error ] [ini_access ] [ 616: 3000] [000000: 0] Incorrect ini_accessor configuration! Fixing relative input path to avoid recursion. Input was: Setup
CCleaner64.exe
Failed to open log file 'C:\Program Files\CCleaner'
CCleaner64.exe
OnLanguage - en
CCleaner64.exe
[2024-10-26 19:17:05.272] [error ] [settings ] [ 616: 6412] [D2EC45: 356] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner64.exe
[2024-10-26 19:17:05.288] [error ] [Burger ] [ 616: 6412] [904E07: 253] [23.2.1118.0] [BurgerReporter.cpp] [253] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner64.exe
[2024-10-26 19:17:05.288] [error ] [Burger ] [ 616: 6412] [904E07: 253] [23.2.1118.0] [BurgerReporter.cpp] [253] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner64.exe
file:///tis/optimizer.tis(1131) : warning :'await' should be used only inside 'async' or 'event'
CCleaner64.exe
file:///tis/optimizer.tis(1288) : warning :'async' does not contain any 'await'
CCleaner64.exe
startCheckingLicense()