Technical Information
- [<HKLM>\Software\Classes\cclaunch\shell\open\command] '' = '"%ProgramFiles%\CCleaner\ccleaner.exe" /%1'
- <SYSTEM32>\tasks\ccleanerskipuac
- %TEMP%\7zipsfx.000\chrome.reg
- %ProgramFiles%\ccleaner\lang\lang-1065.dll
- %ProgramFiles%\ccleaner\lang\lang-1061.dll
- %ProgramFiles%\ccleaner\lang\lang-1058.dll
- %ProgramFiles%\ccleaner\lang\lang-1066.dll
- %ProgramFiles%\ccleaner\lang\lang-1050.dll
- %ProgramFiles%\ccleaner\lang\lang-1026.dll
- %ProgramFiles%\ccleaner\lang\lang-5146.dll
- %ProgramFiles%\ccleaner\lang\lang-1067.dll
- %ProgramFiles%\ccleaner\lang\lang-1071.dll
- %ProgramFiles%\ccleaner\lang\lang-2074.dll
- %ProgramFiles%\ccleaner\lang\lang-3098.dll
- %ProgramFiles%\ccleaner\lang\lang-1052.dll
- %ProgramFiles%\ccleaner\lang\lang-1063.dll
- %ProgramFiles%\ccleaner\lang\lang-1110.dll
- %ProgramFiles%\ccleaner\lang\lang-1048.dll
- %ProgramFiles%\ccleaner\lang\lang-1025.dll
- %ProgramFiles%\ccleaner\lang\lang-1051.dll
- %ProgramFiles%\ccleaner\lang\lang-1109.dll
- %ProgramFiles%\ccleaner\winapp2.ini
- %ProgramFiles%\ccleaner\lang\lang-1068.dll
- %ProgramFiles%\ccleaner\ccleaner.ini
- %ProgramFiles%\ccleaner\uninst.exe
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\ccleaner\ccleaner homepage.url
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\ccleaner\ccleaner.lnk
- C:\users\public\desktop\ccleaner.lnk
- %ProgramFiles%\ccleaner\lang\lang-1104.dll
- %ProgramFiles%\ccleaner\lang\lang-1081.dll
- %ProgramFiles%\ccleaner\lang\lang-1055.dll
- %ProgramFiles%\ccleaner\lang\lang-1054.dll
- %ProgramFiles%\ccleaner\lang\lang-1092.dll
- %ProgramFiles%\ccleaner\lang\lang-1057.dll
- %ProgramFiles%\ccleaner\lang\lang-1102.dll
- %ProgramFiles%\ccleaner\lang\lang-1062.dll
- %ProgramFiles%\ccleaner\lang\lang-1087.dll
- %ProgramFiles%\ccleaner\lang\lang-1059.dll
- %ProgramFiles%\ccleaner\lang\lang-1060.dll
- %ProgramFiles%\ccleaner\lang\lang-1079.dll
- %ProgramFiles%\ccleaner\lang\lang-9999.dll
- %ProgramFiles%\ccleaner\lang\lang-1032.dll
- %ProgramFiles%\ccleaner\lang\lang-1041.dll
- %ProgramFiles%\ccleaner\ccleaner64.exe
- %TEMP%\nskdc5c.tmp\inetc.dll
- %TEMP%\nskdc5c.tmp\nsprocess.dll
- %TEMP%\nskdc5c.tmp\g\pfwww.dll
- %TEMP%\nskdc5c.tmp\g\gtb\toolbar-screenshot.jpg
- %TEMP%\nskdc5c.tmp\g\gtb\toolbar.html
- %TEMP%\nskdc5c.tmp\g\gcapi_dll.dll
- %ProgramFiles%\ccleaner\branding.dll
- %TEMP%\nskdc5c.tmp\g\gtapi_signed.dll
- %TEMP%\nskdc5c.tmp\system.dll
- %TEMP%\nsedc3b.tmp
- %TEMP%\7zipsfx.000\branding.dll
- %TEMP%\7zipsfx.000\ccsetup507pro.exe
- %TEMP%\7zipsfx.000\ccleaner.dat
- %TEMP%\7zipsfx.000\winapp2.ini
- %TEMP%\7zipsfx.000\ccleaner.ini
- %TEMP%\nskdc5c.tmp\userinfo.dll
- %ProgramFiles%\ccleaner\lang\lang-1034.dll
- %ProgramFiles%\ccleaner\lang\lang-1027.dll
- %ProgramFiles%\ccleaner\lang\lang-1049.dll
- %ProgramFiles%\ccleaner\lang\lang-2052.dll
- %ProgramFiles%\ccleaner\lang\lang-1029.dll
- %ProgramFiles%\ccleaner\lang\lang-1038.dll
- %ProgramFiles%\ccleaner\lang\lang-1046.dll
- %ProgramFiles%\ccleaner\lang\lang-1035.dll
- %ProgramFiles%\ccleaner\lang\lang-1030.dll
- %ProgramFiles%\ccleaner\lang\lang-1028.dll
- %ProgramFiles%\ccleaner\lang\lang-1037.dll
- %ProgramFiles%\ccleaner\lang\lang-1045.dll
- %ProgramFiles%\ccleaner\lang\lang-1036.dll
- %ProgramFiles%\ccleaner\lang\lang-1043.dll
- %ProgramFiles%\ccleaner\lang\lang-2070.dll
- %ProgramFiles%\ccleaner\lang\lang-1040.dll
- %ProgramFiles%\ccleaner\lang\lang-1044.dll
- %ProgramFiles%\ccleaner\lang\lang-1042.dll
- %ProgramFiles%\ccleaner\lang\lang-1053.dll
- %ProgramFiles%\ccleaner\lang\lang-1031.dll
- %ProgramFiles%\ccleaner\ccleaner.dat
- %TEMP%\nskdc5c.tmp\g\gcapi_dll.dll
- %TEMP%\nskdc5c.tmp\g\gtapi_signed.dll
- %TEMP%\nskdc5c.tmp\g\gtb\toolbar-screenshot.jpg
- %TEMP%\nskdc5c.tmp\g\gtb\toolbar.html
- %TEMP%\nskdc5c.tmp\g\pfwww.dll
- %TEMP%\nskdc5c.tmp\inetc.dll
- %TEMP%\nskdc5c.tmp\nsprocess.dll
- %TEMP%\nskdc5c.tmp\system.dll
- %TEMP%\nskdc5c.tmp\userinfo.dll
- %TEMP%\7zipsfx.000\branding.dll
- %TEMP%\7zipsfx.000\ccleaner.dat
- %TEMP%\7zipsfx.000\ccleaner.ini
- %TEMP%\7zipsfx.000\ccsetup507pro.exe
- %TEMP%\7zipsfx.000\chrome.reg
- %TEMP%\7zipsfx.000\winapp2.ini
- 'se#####.piriform.com':80
- 'li######api.ccleaner.com':443
- 'x.##2.us':80
- 'microsoft.com':80
- 'o.##2.us':80
- 'oc##.###tg2.amazontrust.com':80
- 'oc##.####ca1.amazontrust.com':80
- http://se#####.piriform.com/installcheck.aspx?p=################################################
- http://x.##2.us/x.cer
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://o.##2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
- http://oc##.###tg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
- http://oc##.####ca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D
- 'li######api.ccleaner.com':443
- DNS ASK se#####.piriform.com
- DNS ASK li######api.ccleaner.com
- DNS ASK x.##2.us
- DNS ASK microsoft.com
- DNS ASK o.##2.us
- DNS ASK oc##.###tg2.amazontrust.com
- DNS ASK oc##.####ca1.amazontrust.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'PiriformRegistration' WindowName: ''
- ClassName: '#32770' WindowName: 'Piriform CCleaner'
- ClassName: 'ThunderRT6FormDC' WindowName: 'CCleaner'
- ClassName: 'PiriformCCleaner' WindowName: ''
- ClassName: '#32770' WindowName: ''
- '%TEMP%\7zipsfx.000\ccsetup507pro.exe' /S
- '%ProgramFiles%\ccleaner\ccleaner64.exe' /createSkipUAC
- '%WINDIR%\syswow64\cmd.exe' /c xcopy branding.dll "%ProgramFiles%\CCleaner\" /s /e /i /y /h /r /k' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c xcopy ccleaner.ini "%ProgramFiles%\CCleaner\" /s /e /i /y /h /r /k' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c xcopy winapp2.ini "%ProgramFiles%\CCleaner\" /s /e /i /y /h /r /k' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c xcopy CCleaner.dat "%ProgramFiles%\CCleaner\" /s /e /i /y /h /r /k' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /s chrome.reg
- '%WINDIR%\syswow64\cmd.exe' /c xcopy branding.dll "%ProgramFiles%\CCleaner\" /s /e /i /y /h /r /k
- '%WINDIR%\syswow64\xcopy.exe' branding.dll "%ProgramFiles%\CCleaner\" /s /e /i /y /h /r /k
- '%WINDIR%\syswow64\cmd.exe' /c xcopy ccleaner.ini "%ProgramFiles%\CCleaner\" /s /e /i /y /h /r /k
- '%WINDIR%\syswow64\xcopy.exe' ccleaner.ini "%ProgramFiles%\CCleaner\" /s /e /i /y /h /r /k
- '%WINDIR%\syswow64\cmd.exe' /c xcopy winapp2.ini "%ProgramFiles%\CCleaner\" /s /e /i /y /h /r /k
- '%WINDIR%\syswow64\xcopy.exe' winapp2.ini "%ProgramFiles%\CCleaner\" /s /e /i /y /h /r /k
- '%WINDIR%\syswow64\cmd.exe' /c xcopy CCleaner.dat "%ProgramFiles%\CCleaner\" /s /e /i /y /h /r /k
- '%WINDIR%\syswow64\xcopy.exe' CCleaner.dat "%ProgramFiles%\CCleaner\" /s /e /i /y /h /r /k