General Info

URL

http://148.72.214.65/avast.exe

Full analysis
https://app.any.run/tasks/f78f5589-c81c-4d22-bd63-f7da22064747
Verdict
Malicious activity
Analysis date
7/18/2019, 09:26:06
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

loader

Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 67.0.4 (x86 en-US) (67.0.4)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • instup.exe (PID: 3096)
  • avast[1].exe (PID: 2532)
  • sbr.exe (PID: 2840)
  • avast[1].exe (PID: 3212)
  • instup.exe (PID: 2184)
Loads dropped or rewritten executable
  • instup.exe (PID: 3096)
  • instup.exe (PID: 2184)
Downloads executable files from IP
  • iexplore.exe (PID: 3632)
Downloads executable files from the Internet
  • iexplore.exe (PID: 3632)
Changes the autorun value in the registry
  • instup.exe (PID: 2184)
Creates files in the program directory
  • instup.exe (PID: 3096)
  • avast[1].exe (PID: 2532)
Executable content was dropped or overwritten
  • instup.exe (PID: 2184)
  • instup.exe (PID: 3096)
  • iexplore.exe (PID: 3472)
  • avast[1].exe (PID: 2532)
  • iexplore.exe (PID: 3632)
Creates or modifies windows services
  • instup.exe (PID: 2184)
Low-level read access rights to disk partition
  • instup.exe (PID: 2184)
  • instup.exe (PID: 3096)
  • avast[1].exe (PID: 2532)
Dropped object may contain Bitcoin addresses
  • instup.exe (PID: 2184)
Reads Internet Cache Settings
  • iexplore.exe (PID: 3472)
  • iexplore.exe (PID: 3632)
Application launched itself
  • iexplore.exe (PID: 3472)
Creates files in the user directory
  • iexplore.exe (PID: 3632)
Changes internet zones settings
  • iexplore.exe (PID: 3472)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
41
Monitored processes
7
Malicious processes
5
Suspicious processes
0

Behavior graph

+
drop and start drop and start start drop and start drop and start drop and start iexplore.exe iexplore.exe avast[1].exe no specs avast[1].exe instup.exe instup.exe sbr.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3472
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\i0488cjo\avast[1].exe
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mlang.dll

PID
3632
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3472 CREDAT:71937
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wpc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll

PID
3212
CMD
"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\avast[1].exe"
Path
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\avast[1].exe
Indicators
No indicators
Parent process
iexplore.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
AVAST Software
Description
Avast Antivirus Installer
Version
17.3.3443.0
Modules
Image
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\i0488cjo\avast[1].exe
c:\systemroot\system32\ntdll.dll

PID
2532
CMD
"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\avast[1].exe"
Path
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\avast[1].exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
HIGH
Version:
Company
AVAST Software
Description
Avast Antivirus Installer
Version
17.3.3443.0
Modules
Image
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\i0488cjo\avast[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\_av_iup.tm~a02552\instup.exe

PID
3096
CMD
"C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\instup.exe" /edition:1 /ga_clientid:b7b4ef6d-0fa2-4b1a-b389-d695b9eff5c8 /guid:048351b1-1798-45bf-a3d2-a930dcb6eb38 /prod:ais /sfx:lite /sfxstorage:C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552
Path
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\instup.exe
Indicators
Parent process
avast[1].exe
User
admin
Integrity Level
HIGH
Version:
Company
AVAST Software
Description
Avast Antivirus Installer
Version
17.3.3443.0
Modules
Image
c:\users\admin\appdata\local\temp\_av_iup.tm~a02552\instup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\psapi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\users\admin\appdata\local\temp\_av_iup.tm~a02552\instup.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msimg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dnsapi.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\users\admin\appdata\local\temp\_av_iup.tm~a02552\htmlayout.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\users\admin\appdata\local\temp\_av_iup.tm~a02552\uat.vpx.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\_av_iup.tm~a02552\new_1306094f\instup.exe

PID
2184
CMD
"C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\New_1306094f\instup.exe" /edition:1 /ga_clientid:b7b4ef6d-0fa2-4b1a-b389-d695b9eff5c8 /guid:048351b1-1798-45bf-a3d2-a930dcb6eb38 /online_installer /prod:ais /sfx /sfxstorage:C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552
Path
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\New_1306094f\instup.exe
Indicators
Parent process
instup.exe
User
admin
Integrity Level
HIGH
Version:
Company
AVAST Software
Description
Avast Antivirus Installer
Version
19.6.4546.0
Modules
Image
c:\users\admin\appdata\local\temp\_av_iup.tm~a02552\new_1306094f\instup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\users\admin\appdata\local\temp\_av_iup.tm~a02552\new_1306094f\instup.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msimg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\secur32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\users\admin\appdata\local\temp\_av_iup.tm~a02552\uat_2184.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\schannel.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\users\admin\appdata\local\temp\_av_iup.tm~a02552\new_1306094f\htmlayout.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\_av_iup.tm~a02552\new_1306094f\sbr.exe

PID
2840
CMD
"C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\New_1306094f\sbr.exe" 2184 "Avast Antivirus setup" "Avast Antivirus is being installed. Do not shut down your computer!"
Path
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\New_1306094f\sbr.exe
Indicators
No indicators
Parent process
instup.exe
User
admin
Integrity Level
HIGH
Version:
Company
AVAST Software
Description
Shutdown blocker
Version
19.6.4546.0
Modules
Image
c:\users\admin\appdata\local\temp\_av_iup.tm~a02552\new_1306094f\sbr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

Registry activity

Total events
4983
Read events
818
Write events
4162
Delete events
3

Modification events

PID
Process
Operation
Key
Name
Value
3472
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019032320190324
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000077000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{574AC093-A92D-11E9-B506-5254004A04AF}
0
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
1
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E30707000400120007001A0017001B00
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
1
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E30707000400120007001A0017001B00
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
1
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E30707000400120007001A001700D700
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
16
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
1
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E30707000400120007001A001700F600
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
240
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
1
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E30707000400120007001A001700E001
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
64
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E30707000400120007001A0021001F0200000000
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
NotifyDownloadComplete
yes
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071820190719
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019071820190719
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071820190719
CachePrefix
:2019071820190719:
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071820190719
CacheLimit
8192
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071820190719
CacheOptions
11
3472
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071820190719
CacheRepair
0
3632
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018082820180829
3632
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019071820190719
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019071820190719
3632
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019071820190719
CachePrefix
:2019071820190719:
3632
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019071820190719
CacheLimit
8192
3632
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019071820190719
CacheOptions
11
3632
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019071820190719
CacheRepair
0
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
0
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
6
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
13
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
20
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
26
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
33
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
40
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
46
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
53
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
60
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
66
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
73
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
80
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
86
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
93
2532
avast[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
100
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\AVAST Software\Avast
SetupLog
C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
0
3096
instup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Title
Updating the product
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
0
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
0
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: servers.def.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\instup_RASAPI32
EnableFileTracing
0
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\instup_RASAPI32
EnableConsoleTracing
0
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\instup_RASAPI32
FileTracingMask
4294901760
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\instup_RASAPI32
ConsoleTracingMask
4294901760
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\instup_RASAPI32
MaxFileSize
1048576
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\instup_RASAPI32
FileDirectory
%windir%\tracing
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\instup_RASMANCS
EnableFileTracing
0
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\instup_RASMANCS
EnableConsoleTracing
0
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\instup_RASMANCS
FileTracingMask
4294901760
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\instup_RASMANCS
ConsoleTracingMask
4294901760
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\instup_RASMANCS
MaxFileSize
1048576
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\instup_RASMANCS
FileDirectory
%windir%\tracing
3096
instup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3096
instup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000078000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
100
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: servers.def.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: prod-pgm.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: prod-pgm.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: uat.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: uat.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: part-prg_ais-1306094f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
2
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
5
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
7
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
12
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
15
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
20
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
23
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
25
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
37
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
40
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
42
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
45
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
48
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
53
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
55
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
61
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
63
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
66
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
74
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
79
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
82
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
84
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
87
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
89
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
92
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
95
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
97
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: part-prg_ais-1306094f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: part-setup_ais-1306094f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
9
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
18
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
22
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
35
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
51
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
58
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
68
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
77
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
93
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: part-setup_ais-1306094f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: prod-vps.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: prod-vps.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: part-iex-c.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: part-iex-c.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: part-jrog2-1bc3.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: part-jrog2-1bc3.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: part-vps_win32-19071704.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: part-vps_win32-19071704.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: avbugreport_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
1
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
3
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
4
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
6
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
8
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
10
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
11
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
13
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
14
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
16
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
17
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
19
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
21
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
24
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
26
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
27
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
28
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
29
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
30
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
31
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
32
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
34
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
36
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
38
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
39
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
41
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
43
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
44
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
46
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
47
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
49
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
50
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
52
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
54
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
56
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
57
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
59
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
60
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
62
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
64
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
65
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
67
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
69
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
70
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
71
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
72
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
73
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
75
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
76
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
78
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
80
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
81
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
83
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
85
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
86
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
88
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
90
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
91
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
94
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
96
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
98
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
99
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: avbugreport_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: avbugreport_ais
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
7
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: avbugreport_x64_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
33
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
14
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: avbugreport_x64_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: avbugreport_x64_ais
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: avdump_x64_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: avdump_x64_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: avdump_x64_ais
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
21
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: avdump_x86_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: avdump_x86_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: avdump_x86_ais
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
28
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: instcont_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: instcont_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: instcont_ais
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
35
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: instcont_x64_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: instcont_x64_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: instcont_x64_ais
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
42
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: instup_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: instup_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: instup_ais
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
50
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: instup_x64_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: instup_x64_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: instup_x64_ais
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
57
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: offertool_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: offertool_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: offertool_ais
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
64
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: offertool_x64_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: offertool_x64_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: offertool_x64_ais
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
71
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: sbr_x64_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: sbr_x64_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: sbr_x64_ais
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
78
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: sbr_x86_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: sbr_x86_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: sbr_x86_ais
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
85
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: setgui_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: setgui_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: setgui_ais
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
92
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Downloading file: setgui_x64_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: setgui_x64_ais-94f.vpx
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: setgui_x64_ais
3096
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
100
2184
instup.exe
delete key
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aswProbeKey
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\partmgr
EnableCounterForIoctl
1
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\AVAST Software\Avast
SetupLog
C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
100
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
0
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
52
2184
instup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Checking install conditions
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
AvRepair
"C:\Program Files\AVAST Software\Avast\setup\instup.exe" /instop:repair /wait
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Title
Installing the product
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
0
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
1
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
2
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
3
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
4
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
5
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
6
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
7
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
8
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
9
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
10
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
11
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
12
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
13
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
14
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
15
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
16
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
17
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
18
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
19
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
20
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
21
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
22
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
23
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
24
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
25
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
26
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
27
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
28
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
29
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
30
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
31
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
32
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
33
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
34
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
35
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
36
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
37
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
38
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
39
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
40
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
41
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
42
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
43
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
44
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
45
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
46
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
47
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
48
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
49
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
50
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
51
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
53
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
54
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
55
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
56
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
57
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
58
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
59
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
60
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
61
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
62
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
63
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
64
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
65
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
66
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
67
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
68
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
69
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
70
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
71
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
72
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
73
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
74
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
75
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
76
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
77
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
78
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
79
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
80
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
81
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
82
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
83
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
84
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
85
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
86
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
87
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
88
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
89
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
90
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
91
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
92
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
93
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
94
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
95
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
96
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
97
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
98
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
99
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: jrog2-3f.vpx
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: jrog2
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
1
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_bpc-7e7.vpx
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: ais_cmp_bpc
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
2
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_cleanup_x86-7d0.vpx
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: ais_cmp_cleanup_x86
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
4
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_datascan_x86-7e6.vpx
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: ais_cmp_datascan_x86
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
5
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_gamingmode-832.vpx
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: ais_cmp_gamingmode
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
7
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_idp_x86-831.vpx
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: ais_cmp_idp_x86
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
8
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_pwdman-848.vpx
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: ais_cmp_pwdman
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
10
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_pwdman_x86-7e6.vpx
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: ais_cmp_pwdman_x86
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
11
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_rescuedisk_x86-7e6.vpx
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: ais_cmp_rescuedisk_x86
2184
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
13

Files activity

Executable files
32
Suspicious files
32
Text files
30
Unknown types
5

Dropped files

PID
Process
Filename
Type
3632
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UQN9ZKLG\avast[1].exe
executable
MD5: c88058a73584415bdf167f8bae5f81ef
SHA256: 03b8840c6b91154214b01fddaff8ed2c6c0a7bfc4d3710b6107e0e15a4b5d036
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\avbugreport_ais-94f.vpx
executable
MD5: 5acafc0ef056b503a146354ab8bce439
SHA256: d6af366d7d3f69375706470bdcee7e1b2e2aa754593abd26c92e62616ef891cf
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\New_1306094f\instup.exe
executable
MD5: 490fff97ce25f802091bc736d3938de8
SHA256: 6d15d8536667003b35827f6124491c40c0ea0c94e53bd1ddbbf8cce9e85caea0
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\uat.vpx.dll
executable
MD5: e833a273d0a35df2a6169cc25e5ca837
SHA256: 6aa76943dc99516e3b353559de28c670da7bae42b19f8c1c0af111a56178b329
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\New_1306094f\Instup.dll
executable
MD5: 0563efd03dbab1128d3f5176064d7717
SHA256: 730149e2bd9cf939a78013308ed17ba76ae6b18919746cf66237f28cf87db845
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\setgui_x64_ais-94f.vpx
executable
MD5: 2ec8d4690a98ac78aa7a40a717706860
SHA256: b5f267833dc2c32cec90162c9c25c4918aaa892142a09dd22786899572049506
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\New_1306094f\HTMLayout.dll
executable
MD5: 0666018d5fdf493a65b222c1d885d123
SHA256: b356e968a7c082820ef1988fa57d64f9c2b43b5214160a628cb6bbabaa5c5dcd
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\Instup.dll
executable
MD5: e14b062a20cdd6dc6061fbfa1fdb065f
SHA256: 1688b43ca91678b4fd4dd229781c42d9b50044e1fc3afb971846419042b8986e
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\New_1306094f\aswOfferTool.exe
executable
MD5: 04b00fa3879d090a59d0f1a5b2fd363a
SHA256: 52aa6ad3ac357075d8ff55cca5931cc8388966a840302a2b484c79f3c4d104d4
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\setgui_ais-8f3.vpx
executable
MD5: ce710c8f9198f996c52c232756de2682
SHA256: 4f1a52b194e55c110a21377e796171a748120e4eafc53e31019a7c304e65dc01
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\New_1306094f\avBugReport.exe
executable
MD5: 5acafc0ef056b503a146354ab8bce439
SHA256: d6af366d7d3f69375706470bdcee7e1b2e2aa754593abd26c92e62616ef891cf
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\avbugreport_x64_ais-94f.vpx
executable
MD5: 24da0045e6546496ac3bfe507bd067cb
SHA256: a248ffbc1cbba4ab333667d0a53fd993c650a51c8f6038915700d68822f7ee93
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\HTMLayout.dll
executable
MD5: ce710c8f9198f996c52c232756de2682
SHA256: 4f1a52b194e55c110a21377e796171a748120e4eafc53e31019a7c304e65dc01
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\setgui_ais-94f.vpx
executable
MD5: 0666018d5fdf493a65b222c1d885d123
SHA256: b356e968a7c082820ef1988fa57d64f9c2b43b5214160a628cb6bbabaa5c5dcd
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\New_1306094f\AvDump32.exe
executable
MD5: b6a813e9be193f2146a878738ee26f1d
SHA256: 5d4c497d8d6d6b1acd3fb19051ddba3b112214157a9bca082bda95a611a95ba0
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\avdump_x64_ais-94f.vpx
executable
MD5: 33688c0049d9f672a3abae085d354fad
SHA256: a764ef1717edc0c4bd29f0239d85f1d1912f9ab72abbd981d752f350c512a690
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\Instup.exe
executable
MD5: 564b0ff17982bb0fe9bfd71991c164b4
SHA256: 1a5ffa675c2753b1ef4978b79387f959bf21369d6ddb8fd6fd4ed50ededd7b94
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\avdump_x86_ais-94f.vpx
executable
MD5: b6a813e9be193f2146a878738ee26f1d
SHA256: 5d4c497d8d6d6b1acd3fb19051ddba3b112214157a9bca082bda95a611a95ba0
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\New_1306094f\AvDump64.exe
executable
MD5: 33688c0049d9f672a3abae085d354fad
SHA256: a764ef1717edc0c4bd29f0239d85f1d1912f9ab72abbd981d752f350c512a690
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\instcont_ais-94f.vpx
executable
MD5: 490fff97ce25f802091bc736d3938de8
SHA256: 6d15d8536667003b35827f6124491c40c0ea0c94e53bd1ddbbf8cce9e85caea0
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\instcont_ais-8f3.vpx
executable
MD5: 564b0ff17982bb0fe9bfd71991c164b4
SHA256: 1a5ffa675c2753b1ef4978b79387f959bf21369d6ddb8fd6fd4ed50ededd7b94
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\instcont_x64_ais-94f.vpx
executable
MD5: c6a441d7dcf32d891dcd940077d05e2b
SHA256: f1163e2a471e9150a66a1190e746d5b360cfc3ea162d3cc572bdcdf9a0f91351
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\uat_2184.dll
executable
MD5: e833a273d0a35df2a6169cc25e5ca837
SHA256: 6aa76943dc99516e3b353559de28c670da7bae42b19f8c1c0af111a56178b329
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\instup_ais-94f.vpx
executable
MD5: 0563efd03dbab1128d3f5176064d7717
SHA256: 730149e2bd9cf939a78013308ed17ba76ae6b18919746cf66237f28cf87db845
3472
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\avast[1].exe
executable
MD5: c88058a73584415bdf167f8bae5f81ef
SHA256: 03b8840c6b91154214b01fddaff8ed2c6c0a7bfc4d3710b6107e0e15a4b5d036
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\sbr_x86_ais-94f.vpx
executable
MD5: 4c6b9e189bbd8487d18694db2984bf56
SHA256: d16353f1e36d7a718448e05d95434eaddf37d069a0a69ebeeec92f4cc879f0a9
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\New_1306094f\sbr.exe
executable
MD5: 0fe858dceb732bb1fe79a656c4655906
SHA256: e0d25baa08624e4204c4aa7360a12e1c10fc807ec7265ea968a18c33a16506f8
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\offertool_ais-94f.vpx
executable
MD5: 04b00fa3879d090a59d0f1a5b2fd363a
SHA256: 52aa6ad3ac357075d8ff55cca5931cc8388966a840302a2b484c79f3c4d104d4
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\instup_x64_ais-94f.vpx
executable
MD5: 449440cc5e13aea5b163172f503feda9
SHA256: 9a000da7e78a52efd7d9dc34a4cb5dd5aa7af9b6a8f3e7ff684227ec880bba16
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\offertool_x64_ais-94f.vpx
executable
MD5: 04b00fa3879d090a59d0f1a5b2fd363a
SHA256: 52aa6ad3ac357075d8ff55cca5931cc8388966a840302a2b484c79f3c4d104d4
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\sbr_x64_ais-94f.vpx
executable
MD5: cadab35508133dbdd70ef1b9aa59d4f6
SHA256: d68ab235ecd240e6c952407b62749ef5b911daa47e361c0619fd22c6697fe5f0
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\instup_ais-8f3.vpx
executable
MD5: e14b062a20cdd6dc6061fbfa1fdb065f
SHA256: 1688b43ca91678b4fd4dd229781c42d9b50044e1fc3afb971846419042b8986e
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\part-iex-c.vpx
binary
MD5: 813b81d5d99c58ab4b1d0d7688e331cf
SHA256: 638ab1af7bf4f73a6b4a43fe0006834346c4f19bc5b880901a93ac06027afbed
3096
instup.exe
C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\event_manager.log
text
MD5: aec701f7b2b416cdf6c3ec26e715c7f5
SHA256: e25ffc413cec5cfc9e7019da47b495840660bc87263554fa7bc092ab3df365cb
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\ais_cmp_pwdman_x86-7e6.vpx
––
MD5:  ––
SHA256:  ––
2184
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_pwdman-848.vpx
binary
MD5: f80a0cdb98b32690dda3ff91842b5e50
SHA256: 466ee12701766ee19a3967344e4997e5005440b273021a272f93d990cc759de6
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\ais_cmp_pwdman-848.vpx
––
MD5:  ––
SHA256:  ––
2184
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_idp_x86-831.vpx
––
MD5:  ––
SHA256:  ––
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\ais_cmp_idp_x86-831.vpx
––
MD5:  ––
SHA256:  ––
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\ais_cmp_idp_x86-831.vpx
binary
MD5: 0b108f5095f54630041fb2272c9350d4
SHA256: 473e10a897c6b5296eb2b83aebf97d322b36341efd4daec29f93f1fa2b93ce1b
2184
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_gamingmode-832.vpx
binary
MD5: ad86976f9e193532096f937c72f173d8
SHA256: 454bc11b90567ff95108aa4c41b681ca5ada4621725200ad4d00799924fd212c
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\ais_cmp_gamingmode-832.vpx
––
MD5:  ––
SHA256:  ––
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\ais_cmp_gamingmode-832.vpx
binary
MD5: efa04ecb3cd61825e0bb1041e7c61cd5
SHA256: f948128920c0398c98a07f8795bd830da048a681eaa77753f8c0d734ecebc460
2184
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_datascan_x86-7e6.vpx
binary
MD5: 2d394cbdd324b31cc00523b8725738e9
SHA256: 925e1833c6f3d196a5da57647f069c436d6c63abeeb29a0f7cb9260836c84bc1
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\ais_cmp_datascan_x86-7e6.vpx
––
MD5:  ––
SHA256:  ––
2184
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_cleanup_x86-7d0.vpx
––
MD5:  ––
SHA256:  ––
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\ais_cmp_cleanup_x86-7d0.vpx
––
MD5:  ––
SHA256:  ––
2184
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_bpc-7e7.vpx
binary
MD5: 6a1910c51f39d1d89946615ad7c532f7
SHA256: 8d5a3de2b259d2c0fb35ad6d424ffa1dc00f890ace85b7c37932aeadb6482359
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\ais_cmp_bpc-7e7.vpx
––
MD5:  ––
SHA256:  ––
2184
instup.exe
C:\Program Files\AVAST Software\Avast\setup\jrog2-3f.vpx
binary
MD5: b804653211b87ec11a62a402c29e9e78
SHA256: 2a0600c6c5ec97bd3815eeb372d1f9866d903e438bce7be675e8c0212c9f1b14
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\jrog2-3f.vpx
––
MD5:  ––
SHA256:  ––
2184
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_rescuedisk_x86-7e6.vpx
binary
MD5: 79c7842ff53da0e8e9406993d5cedb39
SHA256: 62856f1220f4fa4faede5b849a8f622c22bd2758c7a64f9fafa83a511af1098b
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\config.def.ini
text
MD5: 6f4d9abce521659ad77e1cd813879377
SHA256: 5a80e7a8d7dc45cc0366ec6f9a319635f3b2747bb1525bf3f771ca58b2e3d725
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\avast5.ini
text
MD5: cc02188f6ecd57f5b9df9678dc122a97
SHA256: 7b15f2e7123bfa53ac0a8d0fbab6ae92cc284f0d39d1697f9e0d5c7f0116caf5
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\config.def
text
MD5: c9ec849e5c82e9990ee42db8ef42dcbc
SHA256: 0a887fdfc76218a795d0381df0377c4cc5757ef0a1e7d81bd3bbde2ab2281ec8
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\part-vps_win32-19071704.vpx
binary
MD5: f0627fcce8650f0e085511981aaccbc6
SHA256: 9aa0b871906fc25bf1fd9ce0922812979a4342e354f370efb5f85495bbb4e42b
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\part-jrog2-1bc3.vpx
binary
MD5: 2a4bc5e9464c58bb159c669b45a5595e
SHA256: aa10072db11d13240e4b9ed1993eff6137ca0d252674a7959144429ef18c5bf7
3632
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\prod-vps.vpx
binary
MD5: 969c9fd955c933b4739acbf3069cf09b
SHA256: 2a2211a396c0bc8805e5925d2a4f424c7fb5fb80848680c6843eeb8bbc3d5483
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\part-setup_ais-1306094f.vpx
binary
MD5: d43c656ba133d6d107028ca07bd54e4a
SHA256: d80010fd09f4d99299ed056af4b9b331d2329db6dd199e2205464c9cf82c782e
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\part-prg_ais-1306094f.vpx
binary
MD5: d5c827b8675624c8b2a0c18be73f0ff9
SHA256: 729f383501633ce4c2a69f9a6a71c21f75e0218cd6d8f408c3ad5e608b6e3ad3
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\config.def.new
––
MD5:  ––
SHA256:  ––
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\uat.vpx
binary
MD5: cff9e16c6c1d126fe4fffd84ce7c521c
SHA256: 34cfeb70fc79cddf823104b5c4596497daccc959ef60e95a832639da55d96a68
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\prod-pgm.vpx
binary
MD5: 80daa082f361c1915ec7cf61e896b61a
SHA256: 61b4e370c4ac620dc9956e3e44888f6e93c3954fab1a2ba4d776fcae87ec0283
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\servers.def
text
MD5: c66eff1e07edd34ae3465b8fb23020f1
SHA256: 8eb05c4d9b307cf69ed5f13dac4b18c912ea11b2230e62d9891ef1c138380a42
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\servers.def.lkg
text
MD5: c66eff1e07edd34ae3465b8fb23020f1
SHA256: 8eb05c4d9b307cf69ed5f13dac4b18c912ea11b2230e62d9891ef1c138380a42
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\servers.def.vpx
binary
MD5: 7eae1fa681ab95d4d84aaecef04da987
SHA256: b413a4900f70a8dc71c2d492944e14c1c3902a9b0705e6d73245c1d8645f5be4
3096
instup.exe
event_manager.log
––
MD5:  ––
SHA256:  ––
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\config.def
text
MD5: cab9f7c780452cbe56ec71100c30c0ec
SHA256: a32a1c4c86f6aef270a12ad53da4ef632a56e5368664de9affa91507a54d446b
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\config.def.new
––
MD5:  ––
SHA256:  ––
3632
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
dat
MD5: d7a950fefd60dbaa01df2d85fefb3862
SHA256: 75d0b1743f61b76a35b1fedd32378837805de58d79fa950cb6e8164bfa72073a
3472
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{574AC093-A92D-11E9-B506-5254004A04AF}.dat
––
MD5:  ––
SHA256:  ––
3472
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DF7F13ACA2E364C2A3.TMP
––
MD5:  ––
SHA256:  ––
3632
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Low\JavaDeployReg.log
text
MD5: cc8c1d44b86cf6457f7473ace24e6c04
SHA256: 29fd1d2eafa5f9cc3a1587ad0dd4ac9ca35f42832d04d28ddba2bd613a78e89a
3096
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\Stats.ini
text
MD5: c274c9d0e51558d8b2a9fb0d37257a85
SHA256: c9d26522f58123da489067f2c79579db4656e6e216ab20e0b21efd097b5f3dfc
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\vps.def
text
MD5: 8cf97eae26fb6652b7d45dfb530f5fb3
SHA256: e402895ac7269d72c2643249f58c3d891022de0845c739308610c09b38289aa0
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\part-vps_windows-19071601.vpx
binary
MD5: 6a8741550e0ee0bde5adb227726be99e
SHA256: bcb96ac3399a65b323e5cf7c96bc47188ae844f49f1224d96cf617f140a96e68
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\part-jrog2-3f.vpx
binary
MD5: a076aa5a601b9f6fa3ec39a307106aee
SHA256: 6cf1d495c20706ef6c6c5a4b52aabb61b78bab464ba0fb857326f8d5c4398af4
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\prod-vps.vpx
binary
MD5: 8d300f4ec02fc0e5770e8405b8326f44
SHA256: 7181f3ca66bc2c804e1ad6e911c6b8fe2e3d11612cfb11ddaeaed3066933c618
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\setup.def
text
MD5: 6f7bc4c5506a19ed51d4456fd26ef59f
SHA256: 4a4dea3e018171d2de8c352e62235f3938e720e8df71475b0caf6ef78d1fa91b
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\prod-vps.vpx
binary
MD5: 261b5418032e18dc18f23c97b4770d17
SHA256: 937a791dfb0f53c0bead790206dd95271e5f5cae5285df5a891e7d9865a1c4e6
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\program.def
text
MD5: 6f7bc4c5506a19ed51d4456fd26ef59f
SHA256: 4a4dea3e018171d2de8c352e62235f3938e720e8df71475b0caf6ef78d1fa91b
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\servers.def
text
MD5: 195cdcaaed78d2b59abc94f8c0d441f5
SHA256: 6db1cbefdc21b46405e404c868b4e76383ab1b34b81ae29bae8cf06fd81587cf
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\uat.vpx
binary
MD5: 230679b369be23aac783566f0664e374
SHA256: 454ae72dd98aea9f8cf5b913ac3cdac645d97028eae5d9644c0185637bbfbc9d
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\servers.def.vpx
binary
MD5: 60a1d68a3eb8557ba79867b62568e94e
SHA256: c609f87f0ba0e36054dd13c96ba5d846f1bd916d6a7789e0e2c0fb9319eb8c1d
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\prod-pgm.vpx
binary
MD5: 1d63992dd06c368a035800199e70e946
SHA256: 224340741b1138fb901817fcf0fda1607b30696ae047ed67f6a5cc3dc8e49626
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\part-vps_win32-17032902.vpx
binary
MD5: 5b17c42a8e762c3a0af80f4da2b937be
SHA256: 0fc1c42772ccac65c3ef1e858034bbfbc5fa960f1926d9e8800625f5a5850ae5
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\part-setup_ais-110308f3.vpx
binary
MD5: 30a1f660e7d60644e5fce5fdb7073ab0
SHA256: 521eb3bc3ddae6a62423d42814d6358a55ae17a846f255c602160df0997dd472
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\part-jrog2-13e9.vpx
binary
MD5: 46bd224bd2c723c2b924c33f325ca00e
SHA256: 1e470a2c0d10ccda609d052283ca684fa6e5ac35f26fdd3f8ace3aad085f5895
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\part-iex-9.vpx
binary
MD5: b28c0b9bf41f9460c51b92d965e06123
SHA256: 96ad342f6cb2986b3bc5e33619c4d4ba561ecae2a0974b3fc520e516097014f6
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\part-prg_ais-110308f3.vpx
binary
MD5: 2883541ff4dbc7fdbdd6f7864577e3a4
SHA256: 853a4ea4327401e976f4954147428a2f55b4baefa5738b2d79b2890efe45a1c7
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\config.def
text
MD5: 344dbbfb31f97581e0d099290e66f336
SHA256: 42c381823ec2d9d8710bb527c984ad1d59c7b5331420164aa5b0f4e33ef90c17
2532
avast[1].exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\config.def.vpx
binary
MD5: fcb47b03c20ef58e759b923898f996c5
SHA256: 401e46a24114ed4ace82172a08864496009a0535cf997fa90f78ece852b85bc8
2532
avast[1].exe
Setup.log
––
MD5:  ––
SHA256:  ––
3472
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019071820190719\index.dat
dat
MD5: d698f728bdc9f36f09880ff9ba24842c
SHA256: 4bfbce8a044eb1b10475e25d5a32781a05d986ee5e75970f240992fc35f38314
3632
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019071820190719\index.dat
dat
MD5: ef0cf7b99198f62c164b20d9dc7e7120
SHA256: c1d92348e2ac76bb142b92fca0c68facc7c673b7ac18d64047d3a36d09110370
3632
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
dat
MD5: 769ea0256c53e6f544ce79cd5d6d181c
SHA256: bcb6522e3547a58e327652b5bfd892b7180ec28d710eb316989f9de0f7885123
3472
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UQN9ZKLG\avast[1].exe:Zone.Identifier
text
MD5: fbccf14d504b7b2dbcb5a5bda75bd93b
SHA256: eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
3472
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\avast[1].exe:Zone.Identifier
text
MD5: fbccf14d504b7b2dbcb5a5bda75bd93b
SHA256: eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
2184
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_pwdman_x86-7e6.vpx
––
MD5:  ––
SHA256:  ––
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\prod-pgm.vpx
binary
MD5: 80daa082f361c1915ec7cf61e896b61a
SHA256: 61b4e370c4ac620dc9956e3e44888f6e93c3954fab1a2ba4d776fcae87ec0283
3472
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{574AC094-A92D-11E9-B506-5254004A04AF}.dat
binary
MD5: a5c0129016e195f7374b7efb351d8ebf
SHA256: f41b8f61803929c406b04d2d00d12fbbb747d83117547bbe459f06b044723abd
3472
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DFE968FEF06E841D5F.TMP
––
MD5:  ––
SHA256:  ––
3472
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\favicon[1].png
image
MD5: 9fb559a691078558e77d6848202f6541
SHA256: 6d8a01dc7647bc218d003b58fe04049e24a9359900b7e0cebae76edf85b8b914
3472
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
––
MD5:  ––
SHA256:  ––
3472
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\favicon[1].ico
––
MD5:  ––
SHA256:  ––
3632
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat
dat
MD5: 1a939439ee73bf93baaefda1d4ae3e0a
SHA256: 2d81bab9555491fd1eab664f912d9ddec73bdabda579f6506f867a63d42df88a
3632
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D09IRBNZ\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
3632
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UQN9ZKLG\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
3632
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1ZARSHAU\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
3632
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FCXRMIXQ\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
3472
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Feeds Cache\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
3632
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
2184
instup.exe
C:\Users\admin\AppData\Local\Temp\_av_iup.tm~a02552\ais_cmp_rescuedisk_x86-7e6.vpx
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
42
TCP/UDP connections
57
DNS requests
112
Threats
3

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3632 iexplore.exe GET 200 148.72.214.65:80 http://148.72.214.65/avast.exe US
executable
suspicious
3472 iexplore.exe GET 200 204.79.197.200:80 http://www.bing.com/favicon.ico US
image
whitelisted
2532 avast[1].exe POST 204 5.62.40.203:80 http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi DE
text
––
––
whitelisted
2532 avast[1].exe GET 200 172.217.23.142:80 http://www.google-analytics.com/collect?an=Free&av=17.3.3443&cd=stub-extended&cd3=Online&cid=048351b1-1798-45bf-a3d2-a930dcb6eb38&dt=Installation&t=screenview&tid=UA-58120669-3&v=1 US
image
whitelisted
3096 instup.exe GET 200 2.16.186.104:80 http://g0511470.iavs9x.u.avast.com/iavs9x/servers.def.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.50:80 http://d0211227.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.104:80 http://z2217299.iavs9x.u.avast.com/iavs9x/uat.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.50:80 http://p4085325.iavs9x.u.avast.com/iavs9x/part-prg_ais-1306094f.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.104:80 http://v7630928.iavs9x.u.avast.com/iavs9x/part-setup_ais-1306094f.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.105:80 http://r5525652.vpsnitro.u.avast.com/vpsnitro/prod-vps.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.57:80 http://p3713387.vpsnitro.u.avast.com/vpsnitro/part-iex-c.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.57:80 http://s7284151.vpsnitro.u.avast.com/vpsnitro/part-jrog2-1bc3.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.57:80 http://w9448963.vpsnitro.u.avast.com/vpsnitro/part-vps_win32-19071704.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.104:80 http://s4705686.iavs9x.u.avast.com/iavs9x/avbugreport_ais-94f.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.50:80 http://s4705686.iavs9x.u.avast.com/iavs9x/avbugreport_x64_ais-94f.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.104:80 http://s4705686.iavs9x.u.avast.com/iavs9x/avdump_x64_ais-94f.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.50:80 http://s4705686.iavs9x.u.avast.com/iavs9x/avdump_x86_ais-94f.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.50:80 http://s4705686.iavs9x.u.avast.com/iavs9x/instcont_x64_ais-94f.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.104:80 http://s4705686.iavs9x.u.avast.com/iavs9x/instup_ais-94f.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.50:80 http://s4705686.iavs9x.u.avast.com/iavs9x/instup_x64_ais-94f.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.104:80 http://s4705686.iavs9x.u.avast.com/iavs9x/offertool_ais-94f.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.50:80 http://s4705686.iavs9x.u.avast.com/iavs9x/offertool_x64_ais-94f.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.104:80 http://s4705686.iavs9x.u.avast.com/iavs9x/sbr_x64_ais-94f.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.50:80 http://s4705686.iavs9x.u.avast.com/iavs9x/sbr_x86_ais-94f.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.50:80 http://s4705686.iavs9x.u.avast.com/iavs9x/setgui_ais-94f.vpx unknown
binary
whitelisted
3096 instup.exe GET 200 2.16.186.104:80 http://s4705686.iavs9x.u.avast.com/iavs9x/setgui_x64_ais-94f.vpx unknown
binary
whitelisted
2184 instup.exe GET 200 88.221.134.59:80 http://r7110576.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx unknown
binary
suspicious
2184 instup.exe GET 200 2.16.186.112:80 http://b4380882.vps18tiny.u.avcdn.net/vps18tiny/prod-vps.vpx unknown
binary
malicious
2184 instup.exe GET 200 2.16.186.112:80 http://b4380882.vps18tiny.u.avcdn.net/vps18tiny/part-jrog2-3f.vpx unknown
binary
malicious
2184 instup.exe POST 204 5.62.40.211:80 http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi DE
text
––
––
whitelisted
2184 instup.exe POST 204 5.62.40.203:80 http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi DE
text
––
––
whitelisted
2184 instup.exe GET 200 2.16.186.112:80 http://b4380882.vps18tiny.u.avcdn.net/vps18tiny/jrog2-3f.vpx unknown
binary
malicious
2184 instup.exe GET 200 88.221.134.59:80 http://r7110576.iavs9x.u.avast.com/iavs9x/ais_cmp_bpc-7e7.vpx unknown
binary
suspicious
2184 instup.exe GET 200 88.221.134.59:80 http://r7110576.iavs9x.u.avast.com/iavs9x/ais_cmp_cleanup_x86-7d0.vpx unknown
binary
suspicious
2184 instup.exe GET 200 88.221.134.59:80 http://r7110576.iavs9x.u.avast.com/iavs9x/ais_cmp_datascan_x86-7e6.vpx unknown
binary
suspicious
2184 instup.exe GET 200 88.221.134.59:80 http://r7110576.iavs9x.u.avast.com/iavs9x/ais_cmp_gamingmode-832.vpx unknown
binary
suspicious
2184 instup.exe GET 200 88.221.134.59:80 http://r7110576.iavs9x.u.avast.com/iavs9x/ais_cmp_idp_x86-831.vpx unknown
binary
suspicious
2184 instup.exe GET 200 88.221.134.59:80 http://r7110576.iavs9x.u.avast.com/iavs9x/ais_cmp_pwdman-848.vpx unknown
binary
suspicious
2184 instup.exe GET 200 88.221.134.59:80 http://r7110576.iavs9x.u.avast.com/iavs9x/ais_cmp_pwdman_x86-7e6.vpx unknown
binary
suspicious
2184 instup.exe GET 200 88.221.134.59:80 http://r7110576.iavs9x.u.avast.com/iavs9x/ais_cmp_rescuedisk_x86-7e6.vpx unknown
binary
suspicious
2184 instup.exe GET –– 88.221.134.59:80 http://r7110576.iavs9x.u.avast.com/iavs9x/ais_cmp_safeprice-7d6.vpx unknown
––
––
suspicious
–– –– GET –– 88.221.134.59:80 http://r7110576.iavs9x.u.avast.com/iavs9x/ais_cmp_secdns_hlp_x86-7e6.vpx unknown
––
––
suspicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3632 iexplore.exe 148.72.214.65:80 US suspicious
3472 iexplore.exe 204.79.197.200:80 Microsoft Corporation US whitelisted
2532 avast[1].exe 5.62.40.203:80 AVAST Software s.r.o. DE unknown
2532 avast[1].exe 172.217.23.142:80 Google Inc. US whitelisted
3096 instup.exe 5.62.40.208:80 AVAST Software s.r.o. DE unknown
3096 instup.exe 5.62.38.32:443 AVAST Software s.r.o. NL unknown
3096 instup.exe 77.234.43.231:443 AVAST Software s.r.o. GB unknown
3096 instup.exe 5.45.62.121:443 AVAST Software s.r.o. NL malicious
3096 instup.exe 2.16.186.50:80 Akamai International B.V. –– whitelisted
3096 instup.exe 2.16.186.104:80 Akamai International B.V. –– whitelisted
3096 instup.exe 2.16.186.105:80 Akamai International B.V. –– whitelisted
3096 instup.exe 2.16.186.57:80 Akamai International B.V. –– whitelisted
2184 instup.exe 8.8.8.8:53 Google Inc. US whitelisted
2184 instup.exe 88.221.134.59:80 Akamai International B.V. –– unknown
2184 instup.exe 2.16.186.112:80 Akamai International B.V. –– whitelisted
2184 instup.exe 77.234.44.81:443 AVAST Software s.r.o. US unknown
2184 instup.exe 5.62.38.32:443 AVAST Software s.r.o. NL unknown
2184 instup.exe 77.234.43.231:443 AVAST Software s.r.o. GB unknown
2184 instup.exe 5.62.40.211:80 AVAST Software s.r.o. DE unknown
2184 instup.exe 5.62.38.45:443 AVAST Software s.r.o. NL unknown
2184 instup.exe 5.62.40.203:80 AVAST Software s.r.o. DE unknown
–– –– 88.221.134.59:80 Akamai International B.V. –– unknown

DNS requests

Domain IP Reputation
www.bing.com 204.79.197.200
13.107.21.200
whitelisted
v7event.stats.avast.com 5.62.40.203
5.62.40.211
whitelisted
www.google-analytics.com 172.217.23.142
whitelisted
shepherd.ff.avast.com 5.62.40.208
77.234.44.81
whitelisted
alpha-license-dealer.ff.avast.com 5.62.38.32
5.62.38.17
5.62.38.35
whitelisted
alpha-iqs.ff.avast.com 77.234.43.231
77.234.43.236
77.234.43.230
whitelisted
auth.ff.avast.com 5.45.62.121
5.45.59.35
whitelisted
g0511470.iavs9x.u.avast.com 2.16.186.104
2.16.186.50
whitelisted
d0211227.iavs9x.u.avast.com 2.16.186.50
2.16.186.104
whitelisted
z2217299.iavs9x.u.avast.com 2.16.186.104
2.16.186.50
whitelisted
p4085325.iavs9x.u.avast.com 2.16.186.50
2.16.186.104
whitelisted
v7630928.iavs9x.u.avast.com No response whitelisted
r5525652.vpsnitro.u.avast.com No response whitelisted
p3713387.vpsnitro.u.avast.com 2.16.186.57
2.16.186.105
whitelisted
s7284151.vpsnitro.u.avast.com 2.16.186.57
2.16.186.105
whitelisted
w9448963.vpsnitro.u.avast.com 2.16.186.57
2.16.186.105
whitelisted
s4705686.iavs9x.u.avast.com 2.16.186.104
2.16.186.50
whitelisted
f3355109.iavs9x.u.avast.com 88.221.134.56
88.221.134.59
whitelisted
g5569634.iavs9x.u.avast.com 88.221.134.56
88.221.134.59
whitelisted
r7110576.iavs9x.u.avast.com 88.221.134.56
88.221.134.59
suspicious
z3746924.iavs9x.u.avast.com 88.221.134.56
88.221.134.59
whitelisted
s-iavs9x.avcdn.net 96.16.109.105
malicious
m5972635.iavs9x.u.avast.com 88.221.134.56
88.221.134.59
whitelisted
b1477563.vps18tiny.u.avcdn.net No response whitelisted
b4380882.vps18tiny.u.avcdn.net No response malicious
d3336443.vps18tiny.u.avcdn.net No response malicious
l2350042.vps18tiny.u.avcdn.net No response malicious
r4907515.vps18tiny.u.avcdn.net No response malicious
s-vps18tiny.avcdn.net No response malicious
ipm-provider.ff.avast.com 5.62.38.206
5.62.38.45
5.62.38.204
5.62.38.203
5.62.38.143
5.62.38.152
5.62.40.18
5.62.38.205
5.62.38.155
5.62.40.16
5.62.38.153
5.62.38.44
whitelisted

Threats

PID Process Class Message
3632 iexplore.exe A Network Trojan was detected ET INFO Executable Download from dotted-quad Host
3632 iexplore.exe Potential Corporate Privacy Violation ET POLICY PE EXE or DLL Windows file download HTTP
3632 iexplore.exe Potentially Bad Traffic ET INFO SUSPICIOUS Dotted Quad Host MZ Response

Debug output strings

Process Message
instup.exe [2019-07-18 07:27:03.855] [error ] [Ares ] [ 2184: 2124] Unable to resolve hosts after 2500 ms (258, The wait operation timed out.)