File name:

financials-unpacked.exe

Full analysis: https://app.any.run/tasks/3096262c-b457-488d-9ba6-744dfabecf5d
Verdict: Malicious activity
Analysis date: November 22, 2023, 03:23:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

795A6A646C793A041B8BDCA0EA5C75F3

SHA1:

3CD6955C8C7CCE1C6057EE24871AA23A5F1DC92D

SHA256:

CF694369BD2DDF57296A4BDF9C5F45A8AEFC193D8F6B861B9A074F3E507D7382

SSDEEP:

12288:E3H6yScLnqOl0r5Zu0LMFbtizFJ6rAPvOxrcg0i7u48X+OxsSl:E3HzLnqOaNMCFJ6kPvOxrcg0i7uFdsE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • financials-unpacked.exe (PID: 2928)
      • CCleaner.exe (PID: 2988)
    • Connects to the CnC server

      • Synaptics.exe (PID: 3444)
    • Actions looks like stealing of personal data

      • CCleaner.exe (PID: 2988)
    • Steals credentials from Web Browsers

      • CCleaner.exe (PID: 2988)
  • SUSPICIOUS

    • Reads the Internet Settings

      • financials-unpacked.exe (PID: 2928)
      • ._cache_financials-unpacked.exe (PID: 2896)
      • Synaptics.exe (PID: 3444)
      • CCleaner.exe (PID: 2940)
      • CCleaner.exe (PID: 2988)
    • Application launched itself

      • CCleaner.exe (PID: 2940)
    • Checks Windows Trust Settings

      • CCleaner.exe (PID: 2988)
    • Reads Internet Explorer settings

      • CCleaner.exe (PID: 2988)
    • Reads security settings of Internet Explorer

      • CCleaner.exe (PID: 2988)
    • Reads settings of System Certificates

      • CCleaner.exe (PID: 2988)
    • Searches for installed software

      • CCleaner.exe (PID: 2988)
  • INFO

    • Checks supported languages

      • financials-unpacked.exe (PID: 2928)
      • ._cache_financials-unpacked.exe (PID: 2896)
      • Synaptics.exe (PID: 3444)
      • Synaptics.exe (PID: 1608)
      • Synaptics.exe (PID: 1752)
      • Synaptics.exe (PID: 1360)
      • Synaptics.exe (PID: 1032)
      • Synaptics.exe (PID: 1344)
      • Synaptics.exe (PID: 752)
      • Synaptics.exe (PID: 2028)
      • Synaptics.exe (PID: 1904)
      • CCleaner.exe (PID: 2940)
      • Synaptics.exe (PID: 2088)
      • Synaptics.exe (PID: 1276)
      • Synaptics.exe (PID: 2000)
      • CCleaner.exe (PID: 2988)
    • Reads the computer name

      • financials-unpacked.exe (PID: 2928)
      • Synaptics.exe (PID: 3444)
      • Synaptics.exe (PID: 1752)
      • Synaptics.exe (PID: 1608)
      • Synaptics.exe (PID: 1032)
      • Synaptics.exe (PID: 1360)
      • Synaptics.exe (PID: 1344)
      • Synaptics.exe (PID: 752)
      • Synaptics.exe (PID: 1276)
      • Synaptics.exe (PID: 2000)
      • Synaptics.exe (PID: 2028)
      • Synaptics.exe (PID: 1904)
      • Synaptics.exe (PID: 2088)
      • CCleaner.exe (PID: 2940)
      • CCleaner.exe (PID: 2988)
    • Reads the machine GUID from the registry

      • financials-unpacked.exe (PID: 2928)
      • Synaptics.exe (PID: 3444)
      • CCleaner.exe (PID: 2988)
    • Create files in a temporary directory

      • financials-unpacked.exe (PID: 2928)
      • Synaptics.exe (PID: 3444)
    • Creates files in the program directory

      • financials-unpacked.exe (PID: 2928)
      • Synaptics.exe (PID: 3444)
      • CCleaner.exe (PID: 2988)
    • Checks proxy server information

      • ._cache_financials-unpacked.exe (PID: 2896)
      • Synaptics.exe (PID: 3444)
      • CCleaner.exe (PID: 2988)
    • Creates files or folders in the user directory

      • ._cache_financials-unpacked.exe (PID: 2896)
    • Manual execution by a user

      • explorer.exe (PID: 3900)
      • Synaptics.exe (PID: 1752)
      • Synaptics.exe (PID: 1608)
      • Synaptics.exe (PID: 1360)
      • Synaptics.exe (PID: 1032)
      • Synaptics.exe (PID: 1344)
      • Synaptics.exe (PID: 752)
      • Synaptics.exe (PID: 1276)
      • Synaptics.exe (PID: 2028)
      • Synaptics.exe (PID: 2000)
      • Synaptics.exe (PID: 1904)
      • CCleaner.exe (PID: 2940)
      • taskmgr.exe (PID: 2316)
      • WINWORD.EXE (PID: 1088)
      • Synaptics.exe (PID: 2088)
      • explorer.exe (PID: 3504)
    • Reads Environment values

      • CCleaner.exe (PID: 2940)
      • CCleaner.exe (PID: 2988)
    • Reads CPU info

      • CCleaner.exe (PID: 2988)
    • Reads product name

      • CCleaner.exe (PID: 2988)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Borland Delphi 7 (92.8)
.exe | Win32 EXE Yoda's Crypter (3.7)
.exe | Win32 Executable Delphi generic (1.9)
.exe | Win32 Executable (generic) (0.6)
.exe | Win16/32 Executable Delphi generic (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 629760
InitializedDataSize: 198144
UninitializedDataSize: -
EntryPoint: 0x9ab80
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.4
ProductVersionNumber: 1.0.0.4
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Turkish
CharacterSet: Windows, Turkish
CompanyName: Synaptics
FileDescription: Synaptics Pointing Device Driver
FileVersion: 1.0.0.4
InternalName: -
LegalCopyright: -
LegalTrademarks: -
OriginalFileName: -
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
Comments: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
72
Monitored processes
20
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start financials-unpacked.exe no specs ._cache_financials-unpacked.exe synaptics.exe explorer.exe no specs synaptics.exe no specs synaptics.exe no specs synaptics.exe no specs synaptics.exe no specs synaptics.exe no specs synaptics.exe no specs synaptics.exe no specs synaptics.exe no specs synaptics.exe no specs synaptics.exe no specs synaptics.exe no specs taskmgr.exe no specs winword.exe no specs ccleaner.exe no specs ccleaner.exe explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
752"C:\ProgramData\Synaptics\Synaptics.exe" C:\ProgramData\Synaptics\Synaptics.exeexplorer.exe
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\programdata\synaptics\synaptics.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1032"C:\ProgramData\Synaptics\Synaptics.exe" C:\ProgramData\Synaptics\Synaptics.exeexplorer.exe
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\programdata\synaptics\synaptics.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1088"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\timesclients.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
1276"C:\ProgramData\Synaptics\Synaptics.exe" C:\ProgramData\Synaptics\Synaptics.exeexplorer.exe
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\programdata\synaptics\synaptics.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1344"C:\ProgramData\Synaptics\Synaptics.exe" C:\ProgramData\Synaptics\Synaptics.exeexplorer.exe
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\programdata\synaptics\synaptics.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1360"C:\ProgramData\Synaptics\Synaptics.exe" C:\ProgramData\Synaptics\Synaptics.exeexplorer.exe
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\programdata\synaptics\synaptics.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1608"C:\ProgramData\Synaptics\Synaptics.exe" C:\ProgramData\Synaptics\Synaptics.exeexplorer.exe
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\programdata\synaptics\synaptics.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1752"C:\ProgramData\Synaptics\Synaptics.exe" C:\ProgramData\Synaptics\Synaptics.exeexplorer.exe
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\programdata\synaptics\synaptics.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1904"C:\ProgramData\Synaptics\Synaptics.exe" C:\ProgramData\Synaptics\Synaptics.exeexplorer.exe
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\programdata\synaptics\synaptics.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2000"C:\ProgramData\Synaptics\Synaptics.exe" C:\ProgramData\Synaptics\Synaptics.exeexplorer.exe
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\programdata\synaptics\synaptics.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
13 577
Read events
13 162
Write events
270
Delete events
145

Modification events

(PID) Process:(2928) financials-unpacked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2928) financials-unpacked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2928) financials-unpacked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2928) financials-unpacked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2928) financials-unpacked.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3444) Synaptics.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3444) Synaptics.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3444) Synaptics.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3444) Synaptics.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3444) Synaptics.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
7
Suspicious files
10
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
1088WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR621B.tmp.cvr
MD5:
SHA256:
2928financials-unpacked.exeC:\ProgramData\Synaptics\RCX760F.tmpexecutable
MD5:7C5967CA0A1A5E84618BFC5B2020F402
SHA256:B2C86764D4422C52C108A08E705092DD9AD4D0AECDC4E3165BC7A33DDBD4DD9D
2928financials-unpacked.exeC:\ProgramData\Synaptics\Synaptics.exeexecutable
MD5:795A6A646C793A041B8BDCA0EA5C75F3
SHA256:CF694369BD2DDF57296A4BDF9C5F45A8AEFC193D8F6B861B9A074F3E507D7382
2928financials-unpacked.exeC:\Users\admin\AppData\Local\Temp\._cache_financials-unpacked.exeexecutable
MD5:A78CDBEEC7E5DCE0E6985A16EECBE639
SHA256:726A072434E751B2781D49F4F85EC213B60DF0EF6AA6377D5D55FAD0171E7DE9
2988CCleaner.exeC:\Program Files\CCleaner\LOG\event_manager.logtext
MD5:D1047DD6A972B16749366BB8A4971013
SHA256:9670069CBFEED97289B0F7A7D9C05038227A5FE00694E4277F64FB356FF752F4
2988CCleaner.exeC:\Program Files\CCleaner\gcapi_dll.dllexecutable
MD5:F637D5D3C3A60FDDB5DD397556FE9B1D
SHA256:641B843CB6EE7538EC267212694C9EF0616B9AC9AB14A0ABD7CF020678D50B02
2988CCleaner.exeC:\Program Files\CCleaner\gcapi_17006236372988.dllexecutable
MD5:F637D5D3C3A60FDDB5DD397556FE9B1D
SHA256:641B843CB6EE7538EC267212694C9EF0616B9AC9AB14A0ABD7CF020678D50B02
2988CCleaner.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TJ5SY3JYV2PF2ZJEMXBQ.tempbinary
MD5:DDCC92272AB20811861845FED7737339
SHA256:F7EEA6CE6DF66CBCFF9919108E9DA220C7C30565B54A773BA8A505B7596C8BA9
2988CCleaner.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ed7a5cc3cca8d52a.customDestinations-ms~RF199ee6.TMPbinary
MD5:DA39F131D86385E1285BF5489BA6B6F9
SHA256:38C92C3B93D15CCF2E5E59D01D223366D60FF508037EF997C0CDCC11CEC8BAD0
2988CCleaner.exeC:\Program Files\CCleaner\LOG\DriverUpdaterLib.logtext
MD5:C65E65557F5280D56D1062BDF8DD8E47
SHA256:E782AEF0FC1324E9F658F7F81108DBD07792B99B7E45162FB575D58765B7E328
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
20
DNS requests
13
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2896
._cache_financials-unpacked.exe
GET
404
69.50.175.181:80
http://download.bravesentry.com/download.php?&advid=00000717&u=0&p=29945068
unknown
xml
341 b
unknown
3444
Synaptics.exe
GET
404
69.42.215.252:80
http://freedns.afraid.org/api/?action=getdyndns&sha=a30fa98efc092684e8d1c5cff797bcc613562978
unknown
xml
341 b
unknown
2988
CCleaner.exe
GET
404
23.192.45.89:80
http://ncc.avast.com/ncc.txt
unknown
xml
341 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2896
._cache_financials-unpacked.exe
69.50.175.181:80
SOHOSKYWAY1
CA
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
3444
Synaptics.exe
69.42.215.252:80
freedns.afraid.org
AWKNET
US
unknown
3444
Synaptics.exe
142.250.76.142:443
docs.google.com
GOOGLE
US
unknown
2988
CCleaner.exe
23.192.45.89:80
ncc.avast.com
Akamai International B.V.
JP
unknown
2988
CCleaner.exe
34.117.223.223:443
analytics.ff.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2988
CCleaner.exe
104.94.216.88:443
www.ccleaner.com
AKAMAI-AS
KR
unknown

DNS requests

Domain
IP
Reputation
xred.mooo.com
unknown
freedns.afraid.org
  • 69.42.215.252
whitelisted
docs.google.com
  • 142.250.76.142
shared
ncc.avast.com
  • 23.192.45.89
whitelisted
analytics.ff.avast.com
  • 34.117.223.223
whitelisted
www.ccleaner.com
  • 104.94.216.88
whitelisted
ipm-provider.ff.avast.com
  • 34.111.24.1
whitelisted
shepherd.ff.avast.com
  • 34.160.176.28
whitelisted
ip-info.ff.avast.com
  • 34.149.149.62
whitelisted

Threats

PID
Process
Class
Message
1080
svchost.exe
Misc activity
ET INFO DYNAMIC_DNS Query to Abused Domain *.mooo.com
3 ETPRO signatures available at the full report
Process
Message
CCleaner.exe
[2023-11-22 03:27:17.455] [error ] [settings ] [ 2988: 3108] [6000C4: 356] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner.exe
Failed to open log file 'C:\Program Files\CCleaner'
CCleaner.exe
OnLanguage - en
CCleaner.exe
[2023-11-22 03:27:17.970] [error ] [settings ] [ 2988: 1984] [9434E9: 359] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner.exe
[2023-11-22 03:27:17.986] [error ] [Burger ] [ 2988: 1984] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner.exe
[2023-11-22 03:27:17.986] [error ] [Burger ] [ 2988: 1984] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner.exe
startCheckingLicense()
CCleaner.exe
OnLanguage - en
CCleaner.exe
OnLanguage - en
CCleaner.exe
OnLanguage - en