Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\webappsstore.sqlite-shm
|
data
|
dropped
|
||
C:\Users\user\Downloads\2f4bfd42-2fd8-46c8-95e4-68502d31c004.tmp
|
Zip archive data, at least v2.0 to extract, compression method=deflate
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\000002.dbtmp
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\CURRENT (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\MANIFEST-000002
|
MPEG-4 LOAS
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\33CUD2J1\C0XLFJ0M.txt
|
Generic INItialization configuration [Common]
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\AN5UOLP8\info[1].json
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\V01.chk
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\V01.log
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
|
Extensible storage engine DataBase, version 0x620, checksum 0x78318f8e, page size 32768, Windows version 10.0
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.jfm
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\6358C710-B89F-46B9-93F2-F6CAC44F5286
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\D566D7D7-DCD6-471C-8109-BE0AD33199E3
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\F07D8C6A-04B6-4025-869C-70A788D7B5C0
|
data
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\B249ZNM80TU3VQ2OKGVN.temp
|
data
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\cc3891bee323ecc0.customDestinations-ms (copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:44:14 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:44:14 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:44:14 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:44:14 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:44:14 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\Downloads\ccsetup629.zip (copy)
|
Zip archive data, at least v2.0 to extract, compression method=deflate
|
dropped
|
||
C:\Users\user\Downloads\ccsetup629.zip.crdownload (copy)
|
Zip archive data, at least v2.0 to extract, compression method=deflate
|
dropped
|
||
C:\Users\user\Downloads\ccsetup629\Data\burger_client\8866F8A9-70C9-43A2-BFBE-EE00AA2DC417\44ED97C8-2D40-4A50-913D-673F6858B9AF
|
data
|
dropped
|
||
C:\Users\user\Downloads\ccsetup629\Data\burger_client\8866F8A9-70C9-43A2-BFBE-EE00AA2DC417\7d846b03-5697-42ad-987c-9d397e36e919
|
data
|
dropped
|
||
C:\Users\user\Downloads\ccsetup629\Data\usercfg.ini
|
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\Downloads\ccsetup629\LOG\DriverUpdEng.log
|
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\Downloads\ccsetup629\LOG\burger_client\8866F8A9-70C9-43A2-BFBE-EE00AA2DC417\44ED97C8-2D40-4A50-913D-673F6858B9AF
|
data
|
dropped
|
||
C:\Users\user\Downloads\ccsetup629\LOG\burger_client\8866F8A9-70C9-43A2-BFBE-EE00AA2DC417\78181805-65b0-48ec-b23e-bb9eea753fff
|
data
|
dropped
|
||
C:\Users\user\Downloads\ccsetup629\LOG\su_controller.log
|
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\Downloads\ccsetup629\Setup\config.def
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\Downloads\ccsetup629\ccleaner.ini
|
Microsoft HTML Help Project
|
modified
|
||
C:\Users\user\Downloads\ccsetup629\gcapi_17297235455428.dll (copy)
|
PE32+ executable (DLL) (console) x86-64, for MS Windows
|
dropped
|
||
C:\Users\user\Downloads\ccsetup629\gcapi_dll.dll
|
PE32+ executable (DLL) (console) x86-64, for MS Windows
|
dropped
|
||
C:\Users\user\Downloads\ccsetup629\lc.dat (copy)
|
data
|
dropped
|
||
C:\Windows\Tasks\CCleanerCrashReporting.job
|
data
|
dropped
|
||
C:\Windows\Temp\waapi-1729723784\db0796778834078181e5dc1f
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Windows\Temp\waapi-1729723784\lc.dat
|
data
|
dropped
|
There are 32 hidden files, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
ipm-gcp-prod.ff.avast.com
|
34.111.24.1
|
||
shepherd-gcp.ff.avast.com
|
34.160.176.28
|
||
ip-info-gcp.ff.avast.com
|
34.111.175.102
|
||
www.google.com
|
142.250.186.68
|
||
analytics-prod-gcp.ff.avast.com
|
34.117.223.223
|
||
download.ccleaner.com
|
unknown
|
||
shepherd.ff.avast.com
|
unknown
|
||
www.ccleaner.com
|
unknown
|
||
analytics.avcdn.net
|
unknown
|
||
ip-info.ff.avast.com
|
unknown
|
||
ipm-provider.ff.avast.com
|
unknown
|
||
ipmcdn.avast.com
|
unknown
|
There are 2 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
142.250.186.68
|
www.google.com
|
United States
|
||
142.250.185.78
|
unknown
|
United States
|
||
34.111.24.1
|
ipm-gcp-prod.ff.avast.com
|
United States
|
||
34.111.175.102
|
ip-info-gcp.ff.avast.com
|
United States
|
||
2.19.225.128
|
unknown
|
European Union
|
||
1.1.1.1
|
unknown
|
Australia
|
||
108.177.15.84
|
unknown
|
United States
|
||
172.217.18.14
|
unknown
|
United States
|
||
192.168.2.16
|
unknown
|
unknown
|
||
192.168.2.7
|
unknown
|
unknown
|
||
23.212.89.211
|
unknown
|
United States
|
||
192.168.2.9
|
unknown
|
unknown
|
||
34.160.176.28
|
shepherd-gcp.ff.avast.com
|
United States
|
||
216.58.206.35
|
unknown
|
United States
|
||
142.250.181.227
|
unknown
|
United States
|
||
34.117.223.223
|
analytics-prod-gcp.ff.avast.com
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
There are 7 hidden IPs, click here to show them.