General Info

File name

minecraft_2978705639.exe

Full analysis
https://app.any.run/tasks/0e3951cf-b5a1-442c-b330-b28b7b95dfb2
Verdict
Malicious activity
Analysis date
6/12/2019, 09:33:10
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

adware

installcore

pup

loader

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

45572df30eef7614831609762ac131e5

SHA1

1009546e1239af102c3028912bb888bf1d33ccb9

SHA256

d4295d1dba4082a8c5beb15a9e74f97246dcb9d0c1e99b47c9119226828b6371

SSDEEP

49152:3zYFaQp/iTU2hPSRmpwXGwt4rnp+c7jiecNukOM/AWi:8IiiTJSAKXTtogvd1zi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • sbr.exe (PID: 1364)
  • avast_free_antivirus_setup_online.exe (PID: 3568)
  • instup.exe (PID: 3308)
  • instup.exe (PID: 3708)
  • avastfreeantivirussetuponline.m.exe (PID: 2864)
Changes the autorun value in the registry
  • instup.exe (PID: 3708)
Loads dropped or rewritten executable
  • instup.exe (PID: 3308)
Downloads executable files from the Internet
  • avastfreeantivirussetuponline.m.exe (PID: 2864)
Connects to CnC server
  • minecraft_2978705639.exe (PID: 2576)
Changes settings of System certificates
  • minecraft_2978705639.exe (PID: 2576)
INSTALLCORE was detected
  • minecraft_2978705639.exe (PID: 2576)
Low-level read access rights to disk partition
  • instup.exe (PID: 3708)
  • avast_free_antivirus_setup_online.exe (PID: 3568)
  • instup.exe (PID: 3308)
  • avastfreeantivirussetuponline.m.exe (PID: 2864)
Executable content was dropped or overwritten
  • instup.exe (PID: 3708)
  • instup.exe (PID: 3308)
  • avast_free_antivirus_setup_online.exe (PID: 3568)
  • avastfreeantivirussetuponline.m.exe (PID: 2864)
  • minecraft_2978705639.exe (PID: 2576)
Removes files from Windows directory
  • instup.exe (PID: 3308)
  • instup.exe (PID: 3708)
Starts itself from another location
  • instup.exe (PID: 3308)
Creates files in the program directory
  • instup.exe (PID: 3308)
  • avast_free_antivirus_setup_online.exe (PID: 3568)
Starts CMD.EXE for commands execution
  • minecraft_2978705639.exe (PID: 2576)
  • cmd.exe (PID: 2036)
Application launched itself
  • cmd.exe (PID: 2036)
  • minecraft_2978705639.exe (PID: 2844)
Executes application which crashes
  • minecraft_2978705639.exe (PID: 2576)
Starts CMD.EXE for self-deleting
  • minecraft_2978705639.exe (PID: 2576)
Creates files in the Windows directory
  • instup.exe (PID: 3708)
  • instup.exe (PID: 3308)
  • avast_free_antivirus_setup_online.exe (PID: 3568)
  • avastfreeantivirussetuponline.m.exe (PID: 2864)
Creates files in the user directory
  • minecraft_2978705639.exe (PID: 2576)
Reads Environment values
  • minecraft_2978705639.exe (PID: 2576)
Reads internet explorer settings
  • minecraft_2978705639.exe (PID: 2576)
Adds / modifies Windows certificates
  • minecraft_2978705639.exe (PID: 2576)
Searches for installed software
  • minecraft_2978705639.exe (PID: 2576)
Dropped object may contain Bitcoin addresses
  • instup.exe (PID: 3708)
Reads settings of System Certificates
  • minecraft_2978705639.exe (PID: 2576)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable Delphi generic (45.2%)
.dll
|   Win32 Dynamic Link Library (generic) (20.9%)
.exe
|   Win32 Executable (generic) (14.3%)
.exe
|   Win16/32 Executable Delphi generic (6.6%)
.exe
|   Generic Win/DOS Executable (6.3%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:04:06 16:39:04+02:00
PEType:
PE32
LinkerVersion:
2.25
CodeSize:
66560
InitializedDataSize:
53760
UninitializedDataSize:
null
EntryPoint:
0x117dc
OSVersion:
5
ImageVersion:
6
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
1.2.5.3
ProductVersionNumber:
0.0.0.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
This installation was built with Inno Setup.
CompanyName:
FileDescription:
Wizard Internet web Setup
FileVersion:
1.2.5.3
LegalCopyright:
Web
ProductName:
Wizard Internet web
ProductVersion:
3.5.6
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
06-Apr-2016 14:39:04
Detected languages
Dutch - Netherlands
English - United States
Comments:
This installation was built with Inno Setup.
CompanyName:
null
FileDescription:
Wizard Internet web Setup
FileVersion:
1.2.5.3
LegalCopyright:
Web
ProductName:
Wizard Internet web
ProductVersion:
3.5.6
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0050
Pages in file:
0x0002
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x000F
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x001A
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
8
Time date stamp:
06-Apr-2016 14:39:04
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000F244 0x0000F400 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.39292
.itext 0x00011000 0x00000F64 0x00001000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 5.73386
.data 0x00012000 0x00000C88 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.29672
.bss 0x00013000 0x000056BC 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.idata 0x00019000 0x00000E04 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.59781
.tls 0x0001A000 0x00000008 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rdata 0x0001B000 0x00000018 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 0.204488
.rsrc 0x0001C000 0x0000B200 0x0000B200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.14255
Resources
1

2

3

4

4091

4092

4093

4094

4095

4096

11111

CHARTABLE

DVCLAL

PACKAGEINFO

MAINICON

Imports
    oleaut32.dll

    advapi32.dll

    user32.dll

    kernel32.dll

    comctl32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
51
Monitored processes
12
Malicious processes
6
Suspicious processes
0

Behavior graph

+
start drop and start download and start drop and start drop and start drop and start minecraft_2978705639.exe no specs #INSTALLCORE minecraft_2978705639.exe avastfreeantivirussetuponline.m.exe avast_free_antivirus_setup_online.exe instup.exe ntvdm.exe no specs cmd.exe no specs cmd.exe no specs timeout.exe no specs cmd.exe no specs instup.exe sbr.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2844
CMD
"C:\Users\admin\AppData\Local\Temp\minecraft_2978705639.exe"
Path
C:\Users\admin\AppData\Local\Temp\minecraft_2978705639.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Wizard Internet web Setup
Version
1.2.5.3
Modules
Image
c:\users\admin\appdata\local\temp\minecraft_2978705639.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\psapi.dll
c:\windows\system32\mpr.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\sspicli.dll

PID
2576
CMD
"C:\Users\admin\AppData\Local\Temp\minecraft_2978705639.exe" /RSF /ppn:YyhwYgxaFRAiP211FM5W /mnl
Path
C:\Users\admin\AppData\Local\Temp\minecraft_2978705639.exe
Indicators
Parent process
minecraft_2978705639.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Wizard Internet web Setup
Version
1.2.5.3
Modules
Image
c:\users\admin\appdata\local\temp\minecraft_2978705639.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\psapi.dll
c:\windows\system32\mpr.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\olepro32.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\mlang.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\jscript.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\dxtrans.dll
c:\windows\system32\atl.dll
c:\windows\system32\ddrawex.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\dxtmsft.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\in364bb553\6548bb05_stp\avastfreeantivirussetuponline.m.exe
c:\windows\system32\ntvdm.exe

PID
2864
CMD
"C:\Users\admin\AppData\Local\Temp\in364BB553\6548BB05_stp\avastfreeantivirussetuponline.m.exe" /silent /psh:Oe4VZXm1RGx8t0UZfLMwHn+xRW9q9BUscbVBaXW3R2l+t0lrf7VIaXqwVzcq4RQqccYnGR/TVzs+5EJqcbRBYHSzRm10tkH+RwAAAEyHcVg= /ws
Path
C:\Users\admin\AppData\Local\Temp\in364BB553\6548BB05_stp\avastfreeantivirussetuponline.m.exe
Indicators
Parent process
minecraft_2978705639.exe
User
admin
Integrity Level
HIGH
Version:
Company
AVAST Software
Description
Avast Antivirus Installer
Version
2.1.1252.0
Modules
Image
c:\users\admin\appdata\local\temp\in364bb553\6548bb05_stp\avastfreeantivirussetuponline.m.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\temp\asw.2614fb0033c7d57b\avast_free_antivirus_setup_online.exe
c:\windows\system32\apphelp.dll

PID
3568
CMD
"C:\Windows\Temp\asw.2614fb0033c7d57b\avast_free_antivirus_setup_online.exe" /silent /psh:Oe4VZXm1RGx8t0UZfLMwHn+xRW9q9BUscbVBaXW3R2l+t0lrf7VIaXqwVzcq4RQqccYnGR/TVzs+5EJqcbRBYHSzRm10tkH+RwAAAEyHcVg= /ws /ga_clientid:abc50b12-548a-4806-a8a7-109fc09c39df /edat_dir:C:\Windows\Temp\asw.2614fb0033c7d57b
Path
C:\Windows\Temp\asw.2614fb0033c7d57b\avast_free_antivirus_setup_online.exe
Indicators
Parent process
avastfreeantivirussetuponline.m.exe
User
admin
Integrity Level
HIGH
Version:
Company
AVAST Software
Description
Avast Antivirus Installer
Version
19.5.4444.0
Modules
Image
c:\windows\temp\asw.2614fb0033c7d57b\avast_free_antivirus_setup_online.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\apphelp.dll
c:\windows\temp\asw.374d836e693fc255\instup.exe

PID
3308
CMD
"C:\Windows\Temp\asw.374d836e693fc255\instup.exe" /cookie:mmm_irs_ppi_002_451_m /edition:1 /ga_clientid:abc50b12-548a-4806-a8a7-109fc09c39df /guid:dc2e2031-d64c-4a86-9b5e-7f8674c49d65 /prod:ais /sfx:lite /sfxstorage:C:\Windows\Temp\asw.374d836e693fc255 /silent /psh:Oe4VZXm1RGx8t0UZfLMwHn+xRW9q9BUscbVBaXW3R2l+t0lrf7VIaXqwVzcq4RQqccYnGR/TVzs+5EJqcbRBYHSzRm10tkH+RwAAAEyHcVg= /ws /ga_clientid:abc50b12-548a-4806-a8a7-109fc09c39df /edat_dir:C:\Windows\Temp\asw.2614fb0033c7d57b
Path
C:\Windows\Temp\asw.374d836e693fc255\instup.exe
Indicators
Parent process
avast_free_antivirus_setup_online.exe
User
admin
Integrity Level
HIGH
Version:
Company
AVAST Software
Description
Avast Antivirus Installer
Version
19.5.4444.0
Modules
Image
c:\windows\temp\asw.374d836e693fc255\instup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\temp\asw.374d836e693fc255\instup.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msimg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\secur32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\credssp.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\windows\temp\asw.374d836e693fc255\uat_3308.dll
c:\windows\temp\asw.374d836e693fc255\new_1305094a\avbdbad.tmp
c:\windows\temp\asw.374d836e693fc255\new_1305094a\avddbbe.tmp
c:\windows\temp\asw.374d836e693fc255\new_1305094a\insdbcf.tmp
c:\windows\temp\asw.374d836e693fc255\new_1305094a\insdbdf.tmp
c:\windows\temp\asw.374d836e693fc255\new_1305094a\aswdc7d.tmp
c:\windows\temp\asw.374d836e693fc255\new_1305094a\htmdc9d.tmp
c:\windows\system32\apphelp.dll
c:\windows\temp\asw.374d836e693fc255\new_1305094a\instup.exep

PID
2052
CMD
"C:\Windows\system32\ntvdm.exe" -i1
Path
C:\Windows\system32\ntvdm.exe
Indicators
No indicators
Parent process
minecraft_2978705639.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
NTVDM.EXE
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\ntvdm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\winmm.dll
c:\windows\system32\ntvdmd.dll
c:\windows\system32\vdmredir.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll

PID
2588
CMD
"C:\Windows\System32\cmd.exe" /C start microsoft-edge:https://minecraft.es.downloadastro.com/thank_you/?utm_source=ira&utm_medium=offer&utm_campaign=minecraft
Path
C:\Windows\System32\cmd.exe
Indicators
No indicators
Parent process
minecraft_2978705639.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\propsys.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\duser.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\xmllite.dll

PID
2036
CMD
/d /c TIMEOUT 3 & cmd /d /c del "C:\Users\admin\AppData\Local\Temp\MINECR~1.EXE"
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
minecraft_2978705639.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\timeout.exe

PID
3580
CMD
TIMEOUT 3
Path
C:\Windows\system32\timeout.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
timeout - pauses command processing
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\timeout.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
1696
CMD
cmd /d /c del "C:\Users\admin\AppData\Local\Temp\MINECR~1.EXE"
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3708
CMD
"C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\instup.exe" /cookie:mmm_irs_ppi_002_451_m /edat_dir:C:\Windows\Temp\asw.2614fb0033c7d57b /edition:1 /ga_clientid:abc50b12-548a-4806-a8a7-109fc09c39df /guid:dc2e2031-d64c-4a86-9b5e-7f8674c49d65 /online_installer /prod:ais /psh:Oe4VZXm1RGx8t0UZfLMwHn+xRW9q9BUscbVBaXW3R2l+t0lrf7VIaXqwVzcq4RQqccYnGR/TVzs+5EJqcbRBYHSzRm10tkH+RwAAAEyHcVg= /sfx /sfxstorage:C:\Windows\Temp\asw.374d836e693fc255 /silent /ws
Path
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\instup.exe
Indicators
Parent process
instup.exe
User
admin
Integrity Level
HIGH
Version:
Company
AVAST Software
Description
Avast Antivirus Installer
Version
19.5.4444.0
Modules
Image
c:\windows\temp\asw.374d836e693fc255\new_1305094a\instup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\temp\asw.374d836e693fc255\new_1305094a\instup.dllp
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msimg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\secur32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imm32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msctf.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\windows\temp\asw.374d836e693fc255\uat_3708.dll
c:\windows\system32\credssp.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\apphelp.dll
c:\windows\temp\asw.374d836e693fc255\new_1305094a\sbr.exe

PID
1364
CMD
"C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\sbr.exe" 3708 "Avast Antivirus setup" "Avast Antivirus is being installed. Do not shut down your computer!"
Path
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\sbr.exe
Indicators
No indicators
Parent process
instup.exe
User
admin
Integrity Level
HIGH
Version:
Company
AVAST Software
Description
Shutdown blocker
Version
19.5.4444.0
Modules
Image
c:\windows\temp\asw.374d836e693fc255\new_1305094a\sbr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\oleaut32.dll

Registry activity

Total events
3641
Read events
1151
Write events
2490
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
2844
minecraft_2978705639.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2844
minecraft_2978705639.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2576
minecraft_2978705639.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
2576
minecraft_2978705639.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2576
minecraft_2978705639.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\minecraft_2978705639_RASAPI32
EnableFileTracing
0
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\minecraft_2978705639_RASAPI32
EnableConsoleTracing
0
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\minecraft_2978705639_RASAPI32
FileTracingMask
4294901760
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\minecraft_2978705639_RASAPI32
ConsoleTracingMask
4294901760
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\minecraft_2978705639_RASAPI32
MaxFileSize
1048576
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\minecraft_2978705639_RASAPI32
FileDirectory
%windir%\tracing
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\minecraft_2978705639_RASMANCS
EnableFileTracing
0
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\minecraft_2978705639_RASMANCS
EnableConsoleTracing
0
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\minecraft_2978705639_RASMANCS
FileTracingMask
4294901760
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\minecraft_2978705639_RASMANCS
ConsoleTracingMask
4294901760
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\minecraft_2978705639_RASMANCS
MaxFileSize
1048576
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\minecraft_2978705639_RASMANCS
FileDirectory
%windir%\tracing
2576
minecraft_2978705639.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2576
minecraft_2978705639.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000071000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
Name
minecraft_2978705639.exe
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
ID
1459953544
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
0F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE09000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C01400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB5748501D00000001000000100000005B3B67000EEB80022E42605B6B3B72400B000000010000000E000000740068006100770074006500000003000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B812000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
190000000100000010000000DC73F9B71E16D51D26527D32B11A6A3D03000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B810B000000010000000E00000074006800610077007400650000001D00000001000000100000005B3B67000EEB80022E42605B6B3B72401400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB57485053000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B060105050703030F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE2000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A
Blob
0F00000001000000140000000F6AAD4C3FE04619CDC8B2BD655AA1A26042E6500B000000010000005400000053007400610072006600690065006C006400200043006C00610073007300200032002000430065007200740069006600690063006100740069006F006E00200041007500740068006F007200690074007900000053000000010000004800000030463021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C03021060B6086480186FD6E0107170330123010060A2B0601040182373C0101030200C009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B060105050703036200000001000000200000001465FA205397B876FAA6F0A9958E5590E40FCC7FAA4FB7C2C8677521FB5FB658140000000100000014000000BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E71D000000010000001000000090C4F4233B006B7BFAA6ADCD8F577D77030000000100000014000000AD7E1C28B064EF8F6003402014C3D0E3370EB58A2000000001000000130400003082040F308202F7A003020102020100300D06092A864886F70D01010505003068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F72697479301E170D3034303632393137333931365A170D3334303632393137333931365A3068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F7269747930820120300D06092A864886F70D01010105000382010D00308201080282010100B732C8FEE971A60485AD0C1164DFCE4DEFC80318873FA1ABFB3CA69FF0C3A1DAD4D86E2B5390FB24A43E84F09EE85FECE52744F528A63F7BDEE02AF0C8AF532F9ECA0501931E8F661C39A74DFA5AB673042566EB777FE759C64A99251454EB26C7F37F19D530708FAFB0462AFFADEB29EDD79FAA0487A3D4F989A5345FDB43918236D9663CB1B8B982FD9C3A3E10C83BEF0665667A9B19183DFF71513C302E5FBE3D7773B25D066CC323569A2B8526921CA702B3E43F0DAF087982B8363DEA9CD335B3BC69CAF5CC9DE8FD648D1780336E5E4A5D99C91E87B49D1AC0D56E1335235EDF9B5F3DEFD6F776C2EA3EBB780D1C42676B04D8F8D6DA6F8BF244A001AB020103A381C53081C2301D0603551D0E04160414BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E73081920603551D2304818A3081878014BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E7A16CA46A3068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F72697479820100300C0603551D13040530030101FF300D06092A864886F70D01010505000382010100059D3F889DD1C91A55A1AC69F3F359DA9B01871A4F57A9A179092ADBF72FB21ECCC75E6AD88387A197EF49353E7706415862BF8E58B80A673FECB3DD21661FC954FA72CC3D4C40D881AF779E837ABBA2C7F534178ED91140F4FC2C2A4D157FA7625D2E25D3000B201A1D68F917B8F4BD8BED2859DD4D168B1783C8B265C72D7AA5AABC53866DDD57A4CAF820410B68F0F4FB74BE565D7A79F5F91D85E32D95BEF5719043CC8D1F9A000A8729E95522580023EAE31243295B4708DD8C416A6506A8E521AA41B4952195B97DD134AB13D6ADBCDCE23D39CDBD3E7570A1185903C922B48F9CD55E2AD7A5B6D40A6DF8B74011469A1F790E62BF0F97ECE02F1F1794
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A
Blob
040000000100000010000000324A4BBBC863699BBE749AC6DD1D4624030000000100000014000000AD7E1C28B064EF8F6003402014C3D0E3370EB58A1D000000010000001000000090C4F4233B006B7BFAA6ADCD8F577D77140000000100000014000000BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E76200000001000000200000001465FA205397B876FAA6F0A9958E5590E40FCC7FAA4FB7C2C8677521FB5FB65809000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000004800000030463021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C03021060B6086480186FD6E0107170330123010060A2B0601040182373C0101030200C00B000000010000005400000053007400610072006600690065006C006400200043006C00610073007300200032002000430065007200740069006600690063006100740069006F006E00200041007500740068006F00720069007400790000000F00000001000000140000000F6AAD4C3FE04619CDC8B2BD655AA1A26042E6502000000001000000130400003082040F308202F7A003020102020100300D06092A864886F70D01010505003068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F72697479301E170D3034303632393137333931365A170D3334303632393137333931365A3068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F7269747930820120300D06092A864886F70D01010105000382010D00308201080282010100B732C8FEE971A60485AD0C1164DFCE4DEFC80318873FA1ABFB3CA69FF0C3A1DAD4D86E2B5390FB24A43E84F09EE85FECE52744F528A63F7BDEE02AF0C8AF532F9ECA0501931E8F661C39A74DFA5AB673042566EB777FE759C64A99251454EB26C7F37F19D530708FAFB0462AFFADEB29EDD79FAA0487A3D4F989A5345FDB43918236D9663CB1B8B982FD9C3A3E10C83BEF0665667A9B19183DFF71513C302E5FBE3D7773B25D066CC323569A2B8526921CA702B3E43F0DAF087982B8363DEA9CD335B3BC69CAF5CC9DE8FD648D1780336E5E4A5D99C91E87B49D1AC0D56E1335235EDF9B5F3DEFD6F776C2EA3EBB780D1C42676B04D8F8D6DA6F8BF244A001AB020103A381C53081C2301D0603551D0E04160414BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E73081920603551D2304818A3081878014BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E7A16CA46A3068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F72697479820100300C0603551D13040530030101FF300D06092A864886F70D01010505000382010100059D3F889DD1C91A55A1AC69F3F359DA9B01871A4F57A9A179092ADBF72FB21ECCC75E6AD88387A197EF49353E7706415862BF8E58B80A673FECB3DD21661FC954FA72CC3D4C40D881AF779E837ABBA2C7F534178ED91140F4FC2C2A4D157FA7625D2E25D3000B201A1D68F917B8F4BD8BED2859DD4D168B1783C8B265C72D7AA5AABC53866DDD57A4CAF820410B68F0F4FB74BE565D7A79F5F91D85E32D95BEF5719043CC8D1F9A000A8729E95522580023EAE31243295B4708DD8C416A6506A8E521AA41B4952195B97DD134AB13D6ADBCDCE23D39CDBD3E7570A1185903C922B48F9CD55E2AD7A5B6D40A6DF8B74011469A1F790E62BF0F97ECE02F1F1794
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A
Blob
190000000100000010000000FD960962AC6938E0D4B0769AA1A64E260F00000001000000140000000F6AAD4C3FE04619CDC8B2BD655AA1A26042E6500B000000010000005400000053007400610072006600690065006C006400200043006C00610073007300200032002000430065007200740069006600690063006100740069006F006E00200041007500740068006F007200690074007900000053000000010000004800000030463021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C03021060B6086480186FD6E0107170330123010060A2B0601040182373C0101030200C009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B060105050703036200000001000000200000001465FA205397B876FAA6F0A9958E5590E40FCC7FAA4FB7C2C8677521FB5FB658140000000100000014000000BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E71D000000010000001000000090C4F4233B006B7BFAA6ADCD8F577D77030000000100000014000000AD7E1C28B064EF8F6003402014C3D0E3370EB58A040000000100000010000000324A4BBBC863699BBE749AC6DD1D46242000000001000000130400003082040F308202F7A003020102020100300D06092A864886F70D01010505003068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F72697479301E170D3034303632393137333931365A170D3334303632393137333931365A3068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F7269747930820120300D06092A864886F70D01010105000382010D00308201080282010100B732C8FEE971A60485AD0C1164DFCE4DEFC80318873FA1ABFB3CA69FF0C3A1DAD4D86E2B5390FB24A43E84F09EE85FECE52744F528A63F7BDEE02AF0C8AF532F9ECA0501931E8F661C39A74DFA5AB673042566EB777FE759C64A99251454EB26C7F37F19D530708FAFB0462AFFADEB29EDD79FAA0487A3D4F989A5345FDB43918236D9663CB1B8B982FD9C3A3E10C83BEF0665667A9B19183DFF71513C302E5FBE3D7773B25D066CC323569A2B8526921CA702B3E43F0DAF087982B8363DEA9CD335B3BC69CAF5CC9DE8FD648D1780336E5E4A5D99C91E87B49D1AC0D56E1335235EDF9B5F3DEFD6F776C2EA3EBB780D1C42676B04D8F8D6DA6F8BF244A001AB020103A381C53081C2301D0603551D0E04160414BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E73081920603551D2304818A3081878014BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E7A16CA46A3068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F72697479820100300C0603551D13040530030101FF300D06092A864886F70D01010505000382010100059D3F889DD1C91A55A1AC69F3F359DA9B01871A4F57A9A179092ADBF72FB21ECCC75E6AD88387A197EF49353E7706415862BF8E58B80A673FECB3DD21661FC954FA72CC3D4C40D881AF779E837ABBA2C7F534178ED91140F4FC2C2A4D157FA7625D2E25D3000B201A1D68F917B8F4BD8BED2859DD4D168B1783C8B265C72D7AA5AABC53866DDD57A4CAF820410B68F0F4FB74BE565D7A79F5F91D85E32D95BEF5719043CC8D1F9A000A8729E95522580023EAE31243295B4708DD8C416A6506A8E521AA41B4952195B97DD134AB13D6ADBCDCE23D39CDBD3E7570A1185903C922B48F9CD55E2AD7A5B6D40A6DF8B74011469A1F790E62BF0F97ECE02F1F1794
2576
minecraft_2978705639.exe
write
HKEY_CURRENT_USER\Software\undefined
minecraft.exe
1560324833042,https://launcher.mojang.com/download/MinecraftInstaller.msi
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
57
2576
minecraft_2978705639.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
58
2864
avastfreeantivirussetuponline.m.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
PendingFileRenameOperations
\??\C:\Windows\Temp\asw.2614fb0033c7d57b
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
0
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
6
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
12
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
18
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
25
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
31
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
37
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
43
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
50
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
56
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
62
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
68
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
75
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
81
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
87
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
93
3568
avast_free_antivirus_setup_online.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
SfxInstProgress
100
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\AVAST Software\Avast
SetupLog
C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log
3308
instup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Title
Updating the product
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
0
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
0
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
DNS resolving
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
100
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: servers.def.vpx
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: prod-pgm.vpx
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Checking install conditions
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
1
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
2
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
3
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
4
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
5
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
6
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
8
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
10
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
11
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
12
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
13
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
14
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
15
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
16
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
17
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
18
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
20
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
22
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
23
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
24
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
25
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
26
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
28
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
29
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
30
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
32
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
34
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
35
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
36
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
37
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
38
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
39
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
40
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
41
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
42
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
43
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
44
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
45
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
46
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
47
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
48
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
49
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
50
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
51
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
52
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
53
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
54
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
55
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
56
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
57
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
58
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
59
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
60
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
61
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
62
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
63
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
64
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
65
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
66
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
67
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
68
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
69
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
70
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
71
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
72
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
73
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
74
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
75
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
76
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
77
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
78
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
79
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
80
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
81
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
82
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
83
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
84
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
85
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
86
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
87
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
88
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
90
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
91
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
93
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
95
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
97
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
99
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: avbugreport_ais-94a.vpx
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: avbugreport_ais
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
16
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
7
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
19
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
31
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
92
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: avdump_x86_ais-94a.vpx
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: avdump_x86_ais
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
33
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: instcont_ais
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
50
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: instup_ais
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
66
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
9
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
21
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
27
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
33
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
89
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
94
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
96
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Syncer
98
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: offertool_ais-94a.vpx
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: offertool_ais
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
83
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: setgui_ais
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_UpdateSetup_Main
100
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: AvBugReport.exe
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: AvDump.exe
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: instup.exe
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: instup.dll
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: aswOfferTool.exe
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Extracting file: HTMLayout.dll
3308
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Replacing files
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\AVAST Software\Avast
SetupLog
C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
100
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
0
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
52
3708
instup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Checking install conditions
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
AvRepair
"C:\Program Files\AVAST Software\Avast\setup\instup.exe" /instop:repair /wait
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Title
Installing the product
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
0
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
1
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
2
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
3
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
4
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
5
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
6
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
7
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
8
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
9
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
10
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
11
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
12
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
13
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
14
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
15
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
16
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
17
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
18
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
19
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
20
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
21
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
22
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
23
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
24
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
25
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
26
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
28
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
29
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
30
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
31
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
32
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
33
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
34
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
35
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
36
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
37
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
38
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
39
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
40
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
41
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
42
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
43
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
44
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
45
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
46
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
47
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
48
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
49
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
50
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
51
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
53
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
54
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
55
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
56
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
57
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
58
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
59
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
60
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
61
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
62
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
63
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
64
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
65
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
66
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
67
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
68
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
69
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
70
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
71
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
72
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
73
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
74
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
75
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
76
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
77
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
78
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
79
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
80
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
81
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
82
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
83
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
85
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
86
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
87
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
88
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
89
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
90
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
91
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
93
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
95
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
97
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
98
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: jrog2-17.vpx
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: jrog2
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
1
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
27
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
84
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
92
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
94
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
96
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Syncer
99
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_cleanup_x86-7d0.vpx
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: ais_cmp_cleanup_x86
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
2
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_datascan_x86-7e1.vpx
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: ais_cmp_datascan_x86
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
4
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_gamingmode-82d.vpx
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: ais_cmp_gamingmode
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
5
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_idp_x86-82c.vpx
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: ais_cmp_idp_x86
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
7
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_pwdman-848.vpx
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: ais_cmp_pwdman
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
8
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_pwdman_x86-7e1.vpx
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: ais_cmp_pwdman_x86
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
10
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_rescuedisk_x86-7e1.vpx
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: ais_cmp_rescuedisk_x86
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
11
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_secdns_hlp_x86-7e1.vpx
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: ais_cmp_secdns_hlp_x86
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
13
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_cmp_swhealth_x86-7e1.vpx
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: ais_cmp_swhealth_x86
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
14
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_core-896.vpx
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: ais_core
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
15
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_dll_eng-882.vpx
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: ais_dll_eng
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
17
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
File downloaded: ais_dll_eng_x86-7e1.vpx
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Description
Updating package: ais_dll_eng_x86
3708
instup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
InstupProgress_Installation_Main
18

Files activity

Executable files
24
Suspicious files
48
Text files
98
Unknown types
1

Dropped files

PID
Process
Filename
Type
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\6548BB05_stp\avastfreeantivirussetuponline.m.exe
executable
MD5: db0f47766ce8fb10e26e959ef78b9b0e
SHA256: 7cacb1acfe4ebd29805bbf61e2734043b3ace498981698032c8f19be20c77df7
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\avdump_x86_ais-94a.vpx
executable
MD5: a004a96aa184cf4406227e1c1600ac58
SHA256: 72e5d3c59b04978d51e0724dda6264b2b7af39df93d66dd33998ee78fccdecb8
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\avbugreport_ais-94a.vpx
executable
MD5: 5cf1efaea1583ff283695c220f892f6c
SHA256: 5f9115ff8074f39bf51c86bed6271b2e3aadd30422710ad4f9782cbd3aa4d993
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\instup.exe
executable
MD5: 511891bf9f89661251c0f97b013f1159
SHA256: 67a046e12e783712f4cb72db7a036e16ade014bdbd1807874005bb1bb7786e20
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\instcont_ais-94a.vpx
executable
MD5: 511891bf9f89661251c0f97b013f1159
SHA256: 67a046e12e783712f4cb72db7a036e16ade014bdbd1807874005bb1bb7786e20
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\aswOfferTool.exe
executable
MD5: 465e32ef3f0c199f797d2bcb49801f3f
SHA256: 19f1f74cf96886ac60b09e1c0c610e0bd86936686bc61a75a6a21560279146b3
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\Instup.exe
executable
MD5: 511891bf9f89661251c0f97b013f1159
SHA256: 67a046e12e783712f4cb72db7a036e16ade014bdbd1807874005bb1bb7786e20
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\AvDump.exe
executable
MD5: a004a96aa184cf4406227e1c1600ac58
SHA256: 72e5d3c59b04978d51e0724dda6264b2b7af39df93d66dd33998ee78fccdecb8
2864
avastfreeantivirussetuponline.m.exe
C:\Windows\Temp\asw.2614fb0033c7d57b\avast_free_antivirus_setup_online.exe
executable
MD5: c01faeddcab7361f323336a780d34b80
SHA256: 134942bdee7c54a44a1d8e95a16eeed1c8ca2747479a6db70afa9f3a7d8fe0a5
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\HTMLayout.dll
executable
MD5: d5a2180271a4d6bdf25bd29edba4d3c6
SHA256: 2aacd032e6f805c127f0a44d0615efedf95ce8780f50ccbaefb1407ed69b83d1
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\instup_ais-94a.vpx
executable
MD5: 17353a81ca1c16c2faf1cf54322f2fc4
SHA256: 5ca6b3256ee98952b34dea68ec761963464f865d0ab2d55a174477e67b27f3c7
2576
minecraft_2978705639.exe
C:\Users\admin\Downloads\minecraft.exe
executable
MD5: a5b7fb34e00b1467f73691a426a26eaa
SHA256: 96481bdddf7d8b4f3a8a1de6622c2a6cd81d205a83bbf0974f9e683f14b72332
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\offertool_ais-94a.vpx
executable
MD5: 465e32ef3f0c199f797d2bcb49801f3f
SHA256: 19f1f74cf96886ac60b09e1c0c610e0bd86936686bc61a75a6a21560279146b3
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\instup.dll
executable
MD5: 17353a81ca1c16c2faf1cf54322f2fc4
SHA256: 5ca6b3256ee98952b34dea68ec761963464f865d0ab2d55a174477e67b27f3c7
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\AvBugReport.exe
executable
MD5: 5cf1efaea1583ff283695c220f892f6c
SHA256: 5f9115ff8074f39bf51c86bed6271b2e3aadd30422710ad4f9782cbd3aa4d993
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\09502CA9_stp.msi
executable
MD5: a5b7fb34e00b1467f73691a426a26eaa
SHA256: 96481bdddf7d8b4f3a8a1de6622c2a6cd81d205a83bbf0974f9e683f14b72332
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\AvBDBAD.tmp
executable
MD5: 5cf1efaea1583ff283695c220f892f6c
SHA256: 5f9115ff8074f39bf51c86bed6271b2e3aadd30422710ad4f9782cbd3aa4d993
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\sbr.exe
executable
MD5: 6eee54024f4cdf2c19a67d52979949c5
SHA256: 4e974527a719407c523941ed1da5b9484bd27169c44cad2273767a6ca532da69
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\insDBCF.tmp
executable
MD5: 511891bf9f89661251c0f97b013f1159
SHA256: 67a046e12e783712f4cb72db7a036e16ade014bdbd1807874005bb1bb7786e20
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\setgui_ais-94a.vpx
executable
MD5: d5a2180271a4d6bdf25bd29edba4d3c6
SHA256: 2aacd032e6f805c127f0a44d0615efedf95ce8780f50ccbaefb1407ed69b83d1
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\AvDDBBE.tmp
executable
MD5: a004a96aa184cf4406227e1c1600ac58
SHA256: 72e5d3c59b04978d51e0724dda6264b2b7af39df93d66dd33998ee78fccdecb8
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\insDBDF.tmp
executable
MD5: 17353a81ca1c16c2faf1cf54322f2fc4
SHA256: 5ca6b3256ee98952b34dea68ec761963464f865d0ab2d55a174477e67b27f3c7
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\HTMLayout.dll
executable
MD5: d5a2180271a4d6bdf25bd29edba4d3c6
SHA256: 2aacd032e6f805c127f0a44d0615efedf95ce8780f50ccbaefb1407ed69b83d1
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
binary
MD5: e5f3b6e8c2621543d46d210e4bd85f66
SHA256: 58e695f1bbc2caadf8e12abec867ede191b0ff89279a9a3ee877f981091a5ff9
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_cmp_datascan_x86-7e1.vpx
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_cleanup_x86-7d0.vpx
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_cmp_cleanup_x86-7d0.vpx
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_cmp_cleanup_x86-7d0.vpx
binary
MD5: dc36d6372c88e7e25d22c3339a5c6dd3
SHA256: b7ea553d5575fe3e270236b0d5ca709af5606de0ddc8705e825921188d66e3bf
3708
instup.exe
C:\Program Files\AVAST Software\Avast\setup\jrog2-17.vpx
binary
MD5: d2683e2b17979ca8ca3086c5ad574888
SHA256: bf2aab779b30a4a0a39fdaa6bedb05cde543b8369f0683140962bdf4abbf48cc
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\jrog2-17.vpx
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_dll_eng_x86-7e1.vpx
binary
MD5: 828d3d5c06005fd89ebdc982adac6ec3
SHA256: 69df11be3d9a2934ac8dbfe4a7ea06e4c3cd69f45edd837a83c2cbf28834a184
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\config.def.ini
text
MD5: e4e7d861ec743624be7f0f81c1d59adc
SHA256: d637043420610183b78b8120011936627cfb41abc965782e2ece3866719a59ad
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\config.def
text
MD5: b581a1ed7ebe2baf8b748748f38e79cd
SHA256: 2ea9143432ffbcd680d0b78445641b54ab3d7438f37cd45f104a65581f512e37
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\avast5.ini
text
MD5: 6eb999fbfa8aab37f19f95330d534b3e
SHA256: 29f5b8895ba304f8e4a9d75dc720599ea81febb04082177a9f1b8ce1bcc0630e
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\config.def.new
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\vps.def
text
MD5: 20b8074e83fc24210e772e555c8612cf
SHA256: 489e61b010e5d70a9c8ffb000043ec877f6e0cf7f750402d85f2e28c880e41de
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\part-vps_windows-19061103.vpx
binary
MD5: 4025058e5be57385584e36d0ad72df27
SHA256: 2cb2d8c211b6f2db58a4b3f20fd30b5ddb1f0ddf97a3eb0ffcd92f36dd26ff5a
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\part-jrog2-17.vpx
binary
MD5: e9d50d39d0718b450b9ffa482108dda9
SHA256: b6439bd2bfba217a178612f739793b8fa3f8409330a47da4a9e43fe085db1438
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\prod-vps.vpx
binary
MD5: 1e5d7ea2063f663b7c0363e5e0ede865
SHA256: 47f7c521bc4fcc882771d4715ecdfb6d76e8a8754bc40689085663505dc9e452
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\setup.def
text
MD5: bdbfee15a44c5862bb9ec21fd5bb312c
SHA256: a6e05020125adc65ee9102f408ffe6222a5eea29cdb4a5a88df4731e96a76ed7
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\program.def
text
MD5: bdbfee15a44c5862bb9ec21fd5bb312c
SHA256: a6e05020125adc65ee9102f408ffe6222a5eea29cdb4a5a88df4731e96a76ed7
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\uat_3708.dll
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\prod-pgm.vpx
binary
MD5: 9f7631ed7a52d0466990bc6f3e09a032
SHA256: de86bf7de2438f809c3df72c239be73d091e9801b3cf287750ec0b3fd075f381
3308
instup.exe
C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\event_manager.log
text
MD5: d59c3621b8ae7535d3ad992ed98088c5
SHA256: 27c00f8bb13dc0b0f616ce4bb647be9804b0d2a11c4031494d3d7b1ef6351397
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\0013E429.log
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\0013E40A.log
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_dll_eng-882.vpx
binary
MD5: 9739e730b0d6021e36614de568569618
SHA256: e9025950d694bdd32f245aca24a64c5b10e1f987a98b70263fd9cdd2d2049bba
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_dll_eng-882.vpx
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_core-896.vpx
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_core-896.vpx
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_swhealth_x86-7e1.vpx
binary
MD5: 43bab08f6035ba050ecc7e977d027f62
SHA256: 0c7ef614706d7573c8944932660702f0dba434cf4a7cb28a3d2bcaf9eed4d1b2
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_cmp_swhealth_x86-7e1.vpx
––
MD5:  ––
SHA256:  ––
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\HTMDC9D.tmp
––
MD5:  ––
SHA256:  ––
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\aswDC7D.tmp
––
MD5:  ––
SHA256:  ––
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\New_1305094a\insDBDF.tmp
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_secdns_hlp_x86-7e1.vpx
binary
MD5: df128faebb5c3d308ea90eb4551f002b
SHA256: 615f2e9fb77e202dfb1688bc086f519f0d220c8c7464099a808ddee9c77445ea
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_cmp_secdns_hlp_x86-7e1.vpx
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_rescuedisk_x86-7e1.vpx
binary
MD5: 539fbcbde74a83e2262f573004d9afa0
SHA256: 7e51ff41a5c50ba4eef31905694a3acefa2e71254b03cdcd91805810e8b56717
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_cmp_rescuedisk_x86-7e1.vpx
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_pwdman_x86-7e1.vpx
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_cmp_pwdman_x86-7e1.vpx
––
MD5:  ––
SHA256:  ––
2052
ntvdm.exe
C:\Users\admin\AppData\Local\Temp\scsC50A.tmp
––
MD5:  ––
SHA256:  ––
2052
ntvdm.exe
C:\Users\admin\AppData\Local\Temp\scsC509.tmp
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_cmp_pwdman_x86-7e1.vpx
binary
MD5: 892c00b6d37f7d9447b660c551743715
SHA256: b710ec53da787a054984e19ccf08d79250e12f170b0613f5e0726cde9570fb09
3708
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_pwdman-848.vpx
binary
MD5: f80a0cdb98b32690dda3ff91842b5e50
SHA256: 466ee12701766ee19a3967344e4997e5005440b273021a272f93d990cc759de6
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_cmp_pwdman-848.vpx
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_idp_x86-82c.vpx
––
MD5:  ––
SHA256:  ––
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\setup.def
text
MD5: bdbfee15a44c5862bb9ec21fd5bb312c
SHA256: a6e05020125adc65ee9102f408ffe6222a5eea29cdb4a5a88df4731e96a76ed7
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\uat_3308.dll
––
MD5:  ––
SHA256:  ––
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\prod-pgm.vpx
binary
MD5: 9f7631ed7a52d0466990bc6f3e09a032
SHA256: de86bf7de2438f809c3df72c239be73d091e9801b3cf287750ec0b3fd075f381
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\servers.def.lkg
text
MD5: c66eff1e07edd34ae3465b8fb23020f1
SHA256: 8eb05c4d9b307cf69ed5f13dac4b18c912ea11b2230e62d9891ef1c138380a42
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\servers.def
text
MD5: c66eff1e07edd34ae3465b8fb23020f1
SHA256: 8eb05c4d9b307cf69ed5f13dac4b18c912ea11b2230e62d9891ef1c138380a42
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\servers.def.vpx
binary
MD5: 7eae1fa681ab95d4d84aaecef04da987
SHA256: b413a4900f70a8dc71c2d492944e14c1c3902a9b0705e6d73245c1d8645f5be4
3308
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\config.def.new
––
MD5:  ––
SHA256:  ––
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\instup_ais-94a.vpx
––
MD5:  ––
SHA256:  ––
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\setgui_ais-94a.vpx
binary
MD5: d7a710a8633bb94d4f1a5ed052a929f8
SHA256: 40dd953c3ca5911270f8695c3bcaa4574260631d3c36ab266076ee28ffafe64b
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_cmp_idp_x86-82c.vpx
––
MD5:  ––
SHA256:  ––
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\instcont_ais-94a.vpx
binary
MD5: c3e791803772f24460c9fe6e3c6c38be
SHA256: c6c58a0e732ae786fec96fe503a12855ad91405e8e9a44b0591e2fc69a8ceb8a
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\uata64.vpx
binary
MD5: 8948185cf32882b5dc2cb46fda4986e6
SHA256: 555f85304046bf0c6d4f910fea321054542bddb250e84f16246d3755908e9dd8
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_cmp_idp_x86-82c.vpx
binary
MD5: 50be39c8ed17612e91ed0c9712c67d39
SHA256: 5c383fa3ba9cac29a8f711233cf3dbb6a19f90917b5f3cc448c3187bdcf125e0
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\uat64.vpx
binary
MD5: c148641133403571bae9b2eba10eaa7c
SHA256: 2a0aa54adfc77a1a4d48fb8ac7de6c00975577f31b6fea4a65f0804d530eb1a4
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\servers.def.vpx
binary
MD5: 7eae1fa681ab95d4d84aaecef04da987
SHA256: b413a4900f70a8dc71c2d492944e14c1c3902a9b0705e6d73245c1d8645f5be4
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\uat.vpx
binary
MD5: edd268f8a10b717be1aae9074d16bbb0
SHA256: 8e5ed4912e271023cb50050b42dc57fb352a92267c31a31e2bda67f7a90316b2
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\config.def.vpx
binary
MD5: 3e028cdcb68033cd9179536e950b2813
SHA256: 7481b5a33f2755577f8e895d9d2e0fdc230e34e8c8aeb03dec8aa09a1044a095
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\part-setup_ais-1305094a.vpx
binary
MD5: 85b26bce5ebac30f39e2ac5f28f34e91
SHA256: c82475d6ccbc0df01357d06a682c537a7291ff7ab78a5cd357d7ba2da3718098
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\config.def
text
MD5: fc357ae0e850a950a4ec8908742757a7
SHA256: fd8cf7058e41f9de30fe1d1d1b60ab09404af740798be3d1e30bb71cbb7d7d30
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\part-vps_windows-19051904.vpx
binary
MD5: b7e46f6b6db5c7aa23cf10e46a8c081c
SHA256: c86c36913063548608d877a0ebb1a0d03a272c0321f7cfa89ff80384b8aa8fa6
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\prod-vps.vpx
binary
MD5: aaff22ae2d6c859e339b38290c2339b3
SHA256: 901debebb43c0354ef9901beaf55dca0c2d55ac6fc1a9660d5c1fd12a319b0f2
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\servers.def
text
MD5: c66eff1e07edd34ae3465b8fb23020f1
SHA256: 8eb05c4d9b307cf69ed5f13dac4b18c912ea11b2230e62d9891ef1c138380a42
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\part-jrog2-35f.vpx
binary
MD5: 582cfb61ae51d009224adfe807fbd58b
SHA256: ae99b49d83045a2a0be0f738fbea83287ecf3b9ea2071938ceec447accc1ed8c
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\part-prg_ais-1305094a.vpx
binary
MD5: 73fe8f43aaa5dc3697124f04d598529c
SHA256: 7c212bc606cab013ee8515095667668ff891a4c6b49623605f9dd3aabe42783d
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\prod-pgm.vpx
binary
MD5: 9f7631ed7a52d0466990bc6f3e09a032
SHA256: de86bf7de2438f809c3df72c239be73d091e9801b3cf287750ec0b3fd075f381
3568
avast_free_antivirus_setup_online.exe
C:\Windows\Temp\asw.374d836e693fc255\cookie.bin
text
MD5: 0ca781cfa931f2f0d9f9dbd0ba264811
SHA256: e24cb3abb41d4b83c1d02d48442a41835989f95844a81f7638da5864684c57c5
3568
avast_free_antivirus_setup_online.exe
Setup.log
––
MD5:  ––
SHA256:  ––
3708
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_gamingmode-82d.vpx
binary
MD5: 9b175f794193e724fece325f195b2664
SHA256: a24f02b79d179e7afcdc885b535b0f4e04931b0a9677949826f984bd4081c8a8
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_cmp_gamingmode-82d.vpx
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\09502CA9_stp.dat.part
binary
MD5: f20bfab1bbde45a08e1405a7c46cbe92
SHA256: d431bf0d7dc8deea2e234f99ebb58161bee3082e4eb9eb98d0691208f551bb13
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_cmp_gamingmode-82d.vpx
binary
MD5: 2387221cb530eb19463083563f88452d
SHA256: fbb4ad0b14c7a1a0a1b07749abf47bc344d46a49c1b3992d921b2b0d6bfc13f5
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\09502CA9_stp.dat.tmp
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\09502CA9_stp.dat
––
MD5:  ––
SHA256:  ––
2864
avastfreeantivirussetuponline.m.exe
C:\windows\temp\asw.2614fb0033c7d57b\ecoo.edat
text
MD5: 0ca781cfa931f2f0d9f9dbd0ba264811
SHA256: e24cb3abb41d4b83c1d02d48442a41835989f95844a81f7638da5864684c57c5
3708
instup.exe
C:\Program Files\AVAST Software\Avast\setup\ais_cmp_datascan_x86-7e1.vpx
binary
MD5: 81b0964d8ae01b41eb43e1ee4e515c9d
SHA256: fd21ed47290451f0b23e992a15f8c749b9630308faa4ea28977470350935f88b
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\6548BB05_stp.dat.part
binary
MD5: e8fd82b35ef37a0786ad4670698ee1dc
SHA256: 345d5826d40558479b8e1e39e16ed288b9dde1afbe2c9a6c4dd4579fdee80e57
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\6548BB05_stp.dat
binary
MD5: 783fc7fa368a131a4bc589abd32aed8c
SHA256: 8c342945fbf01059c5c2fbde4150f67df7450dbfffad79183e9a6ad4b8623263
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\6548BB05_stp.dat.tmp
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\001349AE.log
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
compressed
MD5: 41577a5ab6a7d917cddeeddc2ef52d53
SHA256: 695fcbf6d5b0a83f6671ea2063aa9e2d45d263a108e826f21186b4a7f05925ff
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\Tar9C96.tmp
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\Cab9C95.tmp
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\Tar9BD9.tmp
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\Cab9BD8.tmp
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\070E0202839D9D67350CD2613E78E416
binary
MD5: 52e9246004a9e46002b9e63ffb238449
SHA256: 1b8306761cc4f0d7ddf8de4d237b92dada43f9cc17c8f7f24610eb70d1a65568
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\070E0202839D9D67350CD2613E78E416
der
MD5: 55540a230bdab55187a841cfe1aa1545
SHA256: d73494e3446b02167573b3cde3ae1c8584ac26e15e45ac3ec0326708425d90fb
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\Tar9BC7.tmp
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\Cab9BC6.tmp
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\BL\yt13.html
html
MD5: 41fe45a8406a0c8aec470180aa23bedb
SHA256: a8dc12a0a150793a25fc8d9bc6511b6fbabf5b4c9abf4af93c65f20826601a1a
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\BF_YL\we23.html
html
MD5: f44fe01996c6ccf478eedf839c9aff9f
SHA256: b9a65628749309eee149cf9d8ea2b02d1e68df74518933aa03fe79d2baa0cf6b
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\BL\yt17.html
html
MD5: 6ab7cce58c2b3596cd4f62fd646eb199
SHA256: 6da3012edd312c491c9a387efae8a6dceaf2fcb14fcd9ecdf923673ab593f589
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\BF_YL\wp24.html
html
MD5: 4e1fbd1b00200772639dfe0dd05d3d3b
SHA256: 211614a416e30dc66ec39726151da58576282745026651d18523f677c669587b
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\0013662F.log
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\79BAAFD6_stp\we23.html
html
MD5: f44fe01996c6ccf478eedf839c9aff9f
SHA256: b9a65628749309eee149cf9d8ea2b02d1e68df74518933aa03fe79d2baa0cf6b
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\79BAAFD6_stp\wp24.html
html
MD5: 4e1fbd1b00200772639dfe0dd05d3d3b
SHA256: 211614a416e30dc66ec39726151da58576282745026651d18523f677c669587b
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\4960DF71_stp\yt13.html
html
MD5: 41fe45a8406a0c8aec470180aa23bedb
SHA256: a8dc12a0a150793a25fc8d9bc6511b6fbabf5b4c9abf4af93c65f20826601a1a
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\4960DF71_stp\yt17.html
html
MD5: 6ab7cce58c2b3596cd4f62fd646eb199
SHA256: 6da3012edd312c491c9a387efae8a6dceaf2fcb14fcd9ecdf923673ab593f589
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\79BAAFD6_stp.dat.part
binary
MD5: eb580b8aa30a8810bc7b27fa88c016a6
SHA256: ed5898dc515fe8209f9fd432dd32ebdc467f52a7f6cec42ede7e1f956346c665
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\79BAAFD6_stp.dat
binary
MD5: ec97803e3e59311f9aaa382cbd2b4151
SHA256: 50397c464d43ae8761d69a651d0fe1f87e33fe5befe0643cf152dbf1fbe84fc6
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\79BAAFD6_stp.dat.tmp
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\teal_logo_white[1].png
image
MD5: fce86292d644232f3498d0461eff47bd
SHA256: 6f3e47f0f9551a6aff50bf490e5f5f19f0572007b393f2cb4b406e8e5300678c
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\4960DF71_stp.dat.part
binary
MD5: 3cb8814f4a4476c702a75cfb42c9dd86
SHA256: cf20a2de74cd239cb17baaf839c082fc4fed562eeaad4b99c17f2b91db8c7215
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\4960DF71_stp.dat
binary
MD5: 182d6b9fae110c0c9b183464eb95a49f
SHA256: c2262f229a1337dcec84d562df882e05c31a2d62233757a4fbdfcadffe8c6ba0
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\4960DF71_stp.dat.tmp
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\EN[1].png
image
MD5: 0ba047fbf67fe4a099714e856cf78bf3
SHA256: 4ecb40e153d8d72fd5b2acc550143961f8b09340109106e7e071ea5a21333c16
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\teal_logo[1].png
image
MD5: 94863cc7ea1eaa0343a829925b3bfd56
SHA256: 2a76cdfd493f3beefb47f8d04e57001b40621a9b51185ba0ff0dc3dc40ab4317
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Tefenece_logo_black[1].png
image
MD5: a53385c7239a3a59b0f2a3ccd46bf2bc
SHA256: 64389d10ba157c1cb2644efad182af0c4173745e92559181db697ae50de785b8
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Jimomoromoj_logo[1].png
image
MD5: a42fffd68be18b8ae986986a71521138
SHA256: 61a11ed258dc9bc734bdd2370d9ab39aeefe8817bf0765f8a66e8ee6dedf1a65
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\logo_comp[1].png
image
MD5: 61505efafa51406086b32ac885d37807
SHA256: 2eda136d8645862194ef932b7a06714b9c49fc7b884424aa7758358d704b0e97
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\in364BB553\icut.dat
binary
MD5: 576166b408e8218e067a962b6ddf82e8
SHA256: 789fb0f7cd59b46cc27104bf17b9302397d8283c68af327f0e62bfce55d5e34d
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\EN[1].png
image
MD5: 46bd51d12590a67a66cc21ba18059a20
SHA256: 731cfc592c539f564a7d6c24bc196ce59ef7f47dfab1cd0cfec25d2e0313d4ee
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\bg_comp[1].png
image
MD5: 965619ea661d15494bcabac08d1761f5
SHA256: 8bfc99d5cc3d9cddb44d77160d3c09a3a5ec629cde7bb7d64bd86a023dcbdb73
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 1b14a0d73facb1582248c4a7f30fc5fc
SHA256: 840bcb6ce0ff2c87c1f75a8b9ec1c8ec1d2f0e89be8e4eae431d63b275fc501e
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\minecraft-32[1].jpg
image
MD5: 1917ca0de525ce20247b0c1c01c08079
SHA256: 227a611a38e3e0100e4b02a9710c9661a462abd5c7dec6a29adda830c903b88b
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\bootstrap_24771.html
html
MD5: 1ea9e5b417811379e874ad4870d5c51a
SHA256: f076773a6e3ae0f1cee3c69232779a1aaaf05202db472040c0c8ea4a70af173a
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\00134B25.log
––
MD5:  ––
SHA256:  ––
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\locale\JA.locale
html
MD5: ac9b17068fbb1ac1a08a698a71d91dcb
SHA256: 107f8a219d0dc41f90eed7472cdef5f35d7113988910f51ba9a27b4a9f7f83c8
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\locale\RU.locale
html
MD5: 4f428ca8e27bdc1a92c86701754dda50
SHA256: beeae35eeac6da3094202f771672e8e190e8477383116538d71a822de643aad8
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\locale\PL.locale
html
MD5: 9067c36859a5183860172775d8dba3a7
SHA256: 08b1b15250aef33a848ebc621b1b31fc7f0d0473d5ba0060bd1ee8967a3785c1
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\locale\PT.locale
html
MD5: aa4a9b603d417a69610703a39d8c75cd
SHA256: 0357ab429e10c0756b460354be1fd6ae16ecc82ee7bfb495385ad191a9904917
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\locale\NL.locale
html
MD5: 6d5544c9f8f865182bfe2fb4dde5bd25
SHA256: 43825594abebd3d1aba6d4e4c522c30e4c8a6d983de622ec0cc7f9ed1aa805bf
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\locale\TR.locale
html
MD5: b9ff99ffbbf2b48666c6aca6208a941e
SHA256: 64a4938dba08b07be144e0e3b0def6ea3fd2393f915a8a593c535475a956f433
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\replacer\pref.json
text
MD5: ff1716a9f34a35ffcca47abe9d6b4819
SHA256: 171bde79660e40c31d087021581b35ef982dc22b9c0dd15d1a0d59013605b7b5
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\locale\ES.locale
html
MD5: 195ee63630ce978b60f9a68d03190f8d
SHA256: 326f67fcaa43286eb28406cc1f04737c5b47bfeb889c052ab98e9f340628ff89
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\locale\EL.locale
html
MD5: d4fab8053bb975931b82d7592ec5652e
SHA256: f89f2fda3081ca1b34ec28499ce21592579f073c7c24480ce8f15eaa8f1a1640
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\locale\DE.locale
html
MD5: 598c9179f7f9551cdb12898e4cb0d156
SHA256: c28db5167426756e180a74b7b85afa0cf4f8ca7b9aa21b4091d8038fece7f15b
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\locale\EN.locale
html
MD5: c4832f772b7dccf7f5ac195c8cb24aed
SHA256: b281ba524fc62e213853593185f2342223d41565f18bdb1b242f151439d1e0d9
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\locale\ID.locale
html
MD5: ca24b20e4df57666accfe6fb653e46a5
SHA256: 88d731b63f5c2339fd9de224ba62a470086ec8e8bf55e8fb0cf690bcf9576fe3
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\locale\FR.locale
html
MD5: 3bee22c7391a8c6f95df59599bc5571b
SHA256: 0aaacfd9c6ce7a38f17f919985111e6194dcf545c760086f6c788bd510ac29a8
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\locale\CS.locale
html
MD5: 101dab6f22bfb56fac4729b94b9ca8de
SHA256: 6d9af94772fbcaf49255c6b024832a923f196fc6d6eb330878c8153aeda8fc28
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\locale\IT.locale
html
MD5: ba5cd879bd34a728f849eb019ec121b0
SHA256: 778719ed583286c57ea0f6035f080097b3a22661b78e33caa3545f1a50303dbc
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\libs\localAssests\icc\icc_v5_8.cis
binary
MD5: d3275dae3b2da9508907b2e97cd72712
SHA256: 9ae11521ced6ba7905386fbbc151c039eb056140d57413103ec0d164e94b9d03
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\Quick_Specs.png
image
MD5: 07cd59b954e8495ad6cd6a7c11d2de86
SHA256: 6e6b964fd79b4a3461f128e2ed145b9b641d108b8616695f36387661cae995bb
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\ProgressBar.png
image
MD5: f5d2570779e9311622cbe1f9c167c1dd
SHA256: 66143e0d85226dab11ee8c9ac6ed5130adc6847cb7f16293ec4824ed67274563
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\Resume_Button.png
image
MD5: 9d31583bcfad58a6b9ddeaf44549a5e6
SHA256: e466a2db2f755d9eb68619439af37ff4e45559b7a3f476e226ab2a11aeadae1a
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\libs\localAssests\icut\icut_v2_2.cis
binary
MD5: 6eea368901ea5a93df886508c3fdfb6d
SHA256: 6e7d76f573135648243b15da732272e8e6f0c8948834ec88ac9f9f13045cae8e
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\sponsored.png
image
MD5: e3758d529f93fee4807f5ea95fbc1a6c
SHA256: 8d46eb0c60043dcb7d79ab3d0525148fc901764620c02e4b9c5dd8b0e9026303
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\Grey_Button.png
image
MD5: 3f1c87febf008eb9483a62e7df2ca33b
SHA256: f871ee6320d922ba6488e38b207c4de0277407a74d548c54f127ce260d7360e3
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\Loader.gif
image
MD5: afc685139a108e33bd945d5a3ff64122
SHA256: 4d70f45a9c69d8ce2e630214c1b2871454d631ccf9d88976470170d0e106acbc
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\Grey_Button_Hover.png
image
MD5: e889d2f749cabb076a85cbb3551dccb7
SHA256: 301d4debf6110943c7f9f8e9b6861c10ad867e9e576723e22f35500340b090f1
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\Icon_Generic.png
image
MD5: a35aeb077ffa7ffb4382c639743d29cc
SHA256: dccfb478e6097086d886b5a01d120bf511b381982b0975e0c65eab3846e4234d
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\Pause_Button.png
image
MD5: 84b37cb510f50c8fea812eb308d3f03f
SHA256: 7bf800336671204de36b7d1f6ceffdff830040f51d21bc44f220f68d72cf492b
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\Progress.png
image
MD5: 91463cb3f1df3d42a5d41aba563f22ea
SHA256: 2de52a019e6291c1ae75c2f7a81f33e84ad1aba0cf7cd6d6f609a9c31618fbb0
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\Color_Button_Hover.png
image
MD5: e889d2f749cabb076a85cbb3551dccb7
SHA256: 301d4debf6110943c7f9f8e9b6861c10ad867e9e576723e22f35500340b090f1
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\sdk-ui\images\progress-bg2.png
image
MD5: b582d9a67bfe77d523ba825fd0b9dae3
SHA256: ab4eeb3ea1eef4e84cb61eccb0ba0998b32108d70b3902df3619f4d9393f74c3
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\sdk-ui\images\progress-bg.png
image
MD5: e9f12f92a9eeb8ebe911080721446687
SHA256: c1cf449536bc2778e27348e45f0f53d04c284109199fb7a9af7a61016b91f8bc
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\BG.png
image
MD5: 22071ea52eb25760bb4fde138f54f4db
SHA256: 341fc883ac5d382e277e0f8cbcec1f6f9ac2f42d3b94e6f41d4bff7df98ebaf6
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\Color_Button.png
image
MD5: 3f1c87febf008eb9483a62e7df2ca33b
SHA256: f871ee6320d922ba6488e38b207c4de0277407a74d548c54f127ce260d7360e3
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\Close.png
image
MD5: eb3faba60d15801f5bffc470e11a6d39
SHA256: 6397bb5fbd89138650acd51c48b622a7dbd6b3ec3816b4f6f94c2d55dc16ba58
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\sdk-ui\images\progress-bg-corner.png
image
MD5: 608f1f20cd6ca9936eaa7e8c14f366be
SHA256: 86b6e6826bcde2955d64d4600a4e01693522c1fddf156ce31c4ba45b3653a7bd
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\images\Close_Hover.png
image
MD5: eb3faba60d15801f5bffc470e11a6d39
SHA256: 6397bb5fbd89138650acd51c48b622a7dbd6b3ec3816b4f6f94c2d55dc16ba58
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\sdk-ui\_progress-bar.scss
text
MD5: 0dce8b2d152948a7c134bfb98cb09522
SHA256: 2d92f324b5e52b412057b5a7cc428665ee5205d07022c681e99b631d20a5137e
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_z-index.scss
text
MD5: 76a55c9ab774e449c10487624ac3f45e
SHA256: 176c81a57205a8496a0a472bdead1de1350beb5fc03ea339703c65d2a29a0b93
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_width-height.scss
text
MD5: dd8af246e3a767aeb684a8272fc7c2c9
SHA256: 86d060bfd279cf4e9cbbaa9a3f444da99339f247af0c9d9e85b109a31474bdd9
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\sdk-ui\_browse.scss
text
MD5: 6009d6e864f60aea980a9df94c1f7e1c
SHA256: 5ef48a8c8c3771b4f233314d50dd3b5afdcd99dd4b74a9745c8fe7b22207056d
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\sdk-ui\_checkbox.scss
text
MD5: 64773c6b0e3413c81aebc46cce8c9318
SHA256: b09504c1bf0486d3ec46500592b178a3a6c39284672af8815c3687cc3d29560d
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\sdk-ui\images\button-bg.png
image
MD5: 98b1de48dfa64dc2aa1e52facfbee3b0
SHA256: 2693930c474fe640e2fe8d6ef98abe2ecd303d2392c3d8b2e006e8942ba8f534
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\sdk-ui\_button.scss
text
MD5: cfe3a6bdd0517296eb8217d40a7acb4f
SHA256: 2ee3a84389a7073946f77e3a5c3780caa17e1656e65a953dc0d8b91b89209060
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_visibility.scss
text
MD5: 02061aea75eac76fff1d2a8e9607d64c
SHA256: f32292cf3212f83814c985aa82f0f8a0e8dada0aee81cd7401aa3aac08e45bc0
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_display.scss
text
MD5: 7fc18252c6212f1ebb349b5f7f429217
SHA256: 1b1f774d3b163c1ba9c86cad87d4b594fba588a364132121f8a234f149816429
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_padding.scss
text
MD5: 839ce4bba9e717524487b58757ea63da
SHA256: 54c64f48133908b48ed7c739a95b9edca865b3a89bdaa34d29973652c3648ede
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_positions.scss
text
MD5: d70ee316e26374f839174916490e937e
SHA256: 3affbaeb6f57451faf94ca9cbcab2504ef75df0e8570aa7be99dd52c9cecb8e7
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_margin.scss
text
MD5: e83d43d06045e990e910e494aebae8ae
SHA256: 15484f9e0794f7526e5671615bcdbb436dc7f53012387821d2163ce59fa5e84b
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_float.scss
text
MD5: bc5eb91b59a99e0fc439e02f80319975
SHA256: eaf9d36e3e75177e64090ac71c6fcf9bb6465cd21f5c0a5ccb05666033609da8
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_typography.scss
text
MD5: 0d6e99087615172921e0383b0bce87d2
SHA256: a94bd2fb6595faea527116d8d8ee090ff74e89216ef3c9260f5f0b5bfa330e0e
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_lists.scss
text
MD5: bda575f11636073d71b86b89c94c6e42
SHA256: b15b8db0368e31991fbe43c121409484562e20fb9599b5b3828e3093217de163
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\_variables.scss
text
MD5: 07922410c30f0117cbc3c140f14aea88
SHA256: af1999b49c03f5dcbb19466466fac2d8172c684c0ff18931b85a8d0a06332c73
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\_functions.scss
text
MD5: 8f7259de64f6ddf352bf461f44d34a81
SHA256: 80edc9d67172bc830d68d33f4547735fb072cadf3ef25aab37a10b50db87a069
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_clearfix.scss
text
MD5: add166bc071472dc105f4734d2dcf0e2
SHA256: 75ebe8b4a4cbbac0eb4de35b60972452b4526c56eefb5186dd40a92c70773377
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\_helpers.scss
text
MD5: 5f158dbbd9fc4594a2f6c13854501916
SHA256: bf12b79f67f1cb9988797f7d81f6f504c8dfe0f0435482e64819a140dbc8da14
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_backgrounds.scss
text
MD5: 6092a3768f84cfbc6e5c52301f5b63ea
SHA256: 8a22a3285f3c7d82aa1a4273bdd62729da241723507c1ecd5d2fd0a24c12e23b
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_border-radius.scss
text
MD5: 6bdf3fd89410e39d33f8137e04ad4a16
SHA256: 2c6b98cb19c3e3a0e37472767c53df213243ae92bc80ef9a7f5baa17f7b6fa31
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_border.scss
text
MD5: 681fb7eb197e8e7ebd89f828d1181fd6
SHA256: 51e8afa69ed6d92eb82f71939b0b8fd34ef23faecee457698238e5a4f28df984
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_colors.scss
text
MD5: 2da278fbb61e370e0cc9f548e8154e1c
SHA256: 857a73fc1da7cf54525048aa60ec9e2f07328ee1d718a66e3b17186170bb5b5b
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\helpers\_align.scss
text
MD5: bbbbd243f9525acc7dc6077010627409
SHA256: 1f11b5f53e0aa7da1a1559a1a5cdd52bf03119ea74e5091462461c550e9288db
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\main.scss
text
MD5: b4eae633b051b31e767b0689a13f4e86
SHA256: 543b421d13ee28fa31050063916780ecf4d69321fcea4f6f4e9abc531260be71
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\main.css
text
MD5: c7708b9a7c7e96af91df3377e81c68a2
SHA256: ad7d578f634b351fd3144dfd740635fec6f4baa964679df954ac8f2ffaf85b75
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\swAgent.css
text
MD5: 2543e3af757c7d7c8a26c7cf57795f60
SHA256: c38892a06c8f50c6386ed794af4f1ea3e1897ad5f0c7e19594d9ea7b20cfb3f1
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\ie6_main.scss
text
MD5: d10348d17adf8a90670696728f54562d
SHA256: e8a3d15cf32009b01b9145b6e62ff6caa9c2981f81ce063578c73c7adff08dfc
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\css\ie6_main.css
text
MD5: ad234e6a62580f62019c78b2a718de00
SHA256: c4f2684f16c8e4553cc29c604a2f505399039638a34e652a7a1acdeb157a0861
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\form.bmp.Mask
binary
MD5: d2fc989f9c2043cd32332ec0fad69c70
SHA256: 27dd029405cbfb0c3bf8bac517be5db9aa83e981b1dc2bd5c5d6c549fa514101
2576
minecraft_2978705639.exe
C:\Users\admin\AppData\Local\Temp\inH126404647510\csshover3.htc
html
MD5: 52fa0da50bf4b27ee625c80d36c67941
SHA256: e37e99ddfc73ac7ba774e23736b2ef429d9a0cb8c906453c75b14c029bdd5493
3708
instup.exe
C:\Windows\Temp\asw.374d836e693fc255\ais_dll_eng_x86-7e1.vpx
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
57
TCP/UDP connections
56
DNS requests
61
Threats
6

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2576 minecraft_2978705639.exe POST 200 52.214.73.247:80 http://ww42.tiritoyot-fow.com/ IE
binary
––
––
malicious
2576 minecraft_2978705639.exe POST 200 52.212.157.66:80 http://server.tiritoyot-fow.com/ IE
binary
text
malicious
2576 minecraft_2978705639.exe POST 200 52.214.73.247:80 http://ww42.tiritoyot-fow.com/ IE
binary
––
––
malicious
2576 minecraft_2978705639.exe POST 200 52.51.129.59:80 http://api.tiritoyot-fow.com/ IE
binary
binary
malicious
2576 minecraft_2978705639.exe GET 200 192.96.201.162:80 http://img.tiritoyot-fow.com/img/Tavasat/15Feb17/v2/EN.png US
image
suspicious
2576 minecraft_2978705639.exe GET 200 192.96.201.162:80 http://img.tiritoyot-fow.com/img/Sibarasawi/bg_comp.png US
image
suspicious
2576 minecraft_2978705639.exe HEAD 200 185.59.222.146:80 http://cdn.tiritoyot-fow.com/ofr/Niniwic/YL/Niniwic_Tefenece_12Apr16 NL
––
––
suspicious
2576 minecraft_2978705639.exe GET 200 192.96.201.162:80 http://img.tiritoyot-fow.com/img/Sibarasawi/logo_comp.png US
image
suspicious
2576 minecraft_2978705639.exe GET 200 192.96.201.162:80 http://img.tiritoyot-fow.com/img/Jimomoromoj/Jimomoromoj_logo.png US
image
suspicious
2576 minecraft_2978705639.exe HEAD 200 185.59.222.146:80 http://cdn.tiritoyot-fow.com/ofr/Webinebinec/Webinebinec_Links_13Oct15 NL
––
––
suspicious
2576 minecraft_2978705639.exe GET 200 199.201.110.78:80 http://secure.tiritoyot-fow.com/ofr/Niniwic/YL/Niniwic_Tefenece_12Apr16 US
binary
suspicious
2576 minecraft_2978705639.exe GET 200 192.96.201.162:80 http://img.tiritoyot-fow.com/img/Tefenece/Tefenece_logo_black.png US
image
suspicious
2576 minecraft_2978705639.exe GET 200 192.96.201.162:80 http://img.tiritoyot-fow.com/img/Vavavag/V2/EN.png US
image
suspicious
2576 minecraft_2978705639.exe GET 200 185.59.222.146:80 http://cdn.tiritoyot-fow.com/ofr/Webinebinec/Webinebinec_Links_13Oct15 NL
binary
suspicious
2576 minecraft_2978705639.exe GET 200 192.96.201.162:80 http://img.tiritoyot-fow.com/img/Webinebinec/teal_logo.png US
image
suspicious
2576 minecraft_2978705639.exe GET 200 192.96.201.162:80 http://img.tiritoyot-fow.com/img/Webinebinec/teal_logo_white.png US
image
suspicious
2576 minecraft_2978705639.exe POST 200 52.214.73.247:80 http://ww42.tiritoyot-fow.com/ IE
binary
––
––
malicious
2576 minecraft_2978705639.exe HEAD 200 185.59.222.146:80 http://cdn.tiritoyot-fow.com/ofr/Tavasat/Tavasat_18Jan19_m NL
binary
suspicious
2576 minecraft_2978705639.exe GET 200 199.201.110.78:80 http://secure.tiritoyot-fow.com/ofr/Tavasat/Tavasat_18Jan19_m US
binary
suspicious
2576 minecraft_2978705639.exe GET 200 13.33.216.127:80 http://x.ss2.us/x.cer US
der
whitelisted
2576 minecraft_2978705639.exe GET 200 8.241.122.126:80 http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab US
compressed
whitelisted
2576 minecraft_2978705639.exe POST 200 52.214.73.247:80 http://ww42.tiritoyot-fow.com/ IE
binary
––
––
malicious
2864 avastfreeantivirussetuponline.m.exe POST 204 5.62.40.203:80 http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi DE
text
––
––
whitelisted
2864 avastfreeantivirussetuponline.m.exe POST 200 216.58.206.14:80 http://www.google-analytics.com/collect US
text
image
whitelisted
2576 minecraft_2978705639.exe POST 200 52.214.73.247:80 http://ww42.tiritoyot-fow.com/ IE
binary
––
––
malicious
2864 avastfreeantivirussetuponline.m.exe GET 200 2.16.186.104:80 http://iavs9x.u.avast.com/iavs9x/avast_free_antivirus_setup_online.exe unknown
executable
whitelisted
2576 minecraft_2978705639.exe POST 200 52.214.73.247:80 http://ww42.tiritoyot-fow.com/ IE
binary
––
––
malicious
2864 avastfreeantivirussetuponline.m.exe POST 200 216.58.206.14:80 http://www.google-analytics.com/collect US
text
image
whitelisted
2864 avastfreeantivirussetuponline.m.exe POST 204 5.62.40.203:80 http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi DE
text
––
––
whitelisted
3568 avast_free_antivirus_setup_online.exe POST 204 5.62.40.203:80 http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi DE
text
––
––
whitelisted
3568 avast_free_antivirus_setup_online.exe GET 200 216.58.206.14:80 http://www.google-analytics.com/collect?aiid=mmm_irs_ppi_002_451_m&an=Free&av=19.5.4444&cd=stub-extended&cd3=Online&cid=dc2e2031-d64c-4a86-9b5e-7f8674c49d65&dt=Installation&t=screenview&tid=UA-58120669-3&v=1 US
image
whitelisted
3308 instup.exe GET 200 23.192.162.171:80 http://v6831430.iavs9x.u.avast.com/iavs9x/servers.def.vpx US
binary
whitelisted
3308 instup.exe GET 200 23.192.162.201:80 http://d4479313.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx US
binary
suspicious
3308 instup.exe GET 200 23.192.162.201:80 http://d4479313.iavs9x.u.avast.com/iavs9x/avbugreport_ais-94a.vpx US
binary
suspicious
3308 instup.exe GET 200 23.192.162.201:80 http://d4479313.iavs9x.u.avast.com/iavs9x/avdump_x86_ais-94a.vpx US
binary
suspicious
3308 instup.exe GET 200 23.192.162.201:80 http://d4479313.iavs9x.u.avast.com/iavs9x/offertool_ais-94a.vpx US
binary
suspicious
2576 minecraft_2978705639.exe POST 200 52.214.73.247:80 http://ww42.tiritoyot-fow.com/ IE
binary
––
––
malicious
3708 instup.exe GET 200 23.192.162.201:80 http://s0383910.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx US
binary
suspicious
3708 instup.exe GET 200 23.192.162.186:80 http://t7758057.vps18tiny.u.avcdn.net/vps18tiny/prod-vps.vpx US
binary
whitelisted
3708 instup.exe GET 200 23.192.162.186:80 http://t7758057.vps18tiny.u.avcdn.net/vps18tiny/part-jrog2-17.vpx US
binary
whitelisted
3708 instup.exe GET 200 23.192.162.186:80 http://t7758057.vps18tiny.u.avcdn.net/vps18tiny/part-vps_windows-19061103.vpx US
binary
whitelisted
3708 instup.exe POST 204 77.234.45.53:80 http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi DE
text
––
––
whitelisted
3708 instup.exe POST 204 5.62.40.203:80 http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi DE
text
––
––
whitelisted
3708 instup.exe GET 200 23.192.162.186:80 http://t7758057.vps18tiny.u.avcdn.net/vps18tiny/jrog2-17.vpx US
binary
whitelisted
3708 instup.exe GET 200 23.192.162.201:80 http://s0383910.iavs9x.u.avast.com/iavs9x/ais_cmp_cleanup_x86-7d0.vpx US
binary
suspicious
3708 instup.exe GET 200 23.192.162.201:80 http://s0383910.iavs9x.u.avast.com/iavs9x/ais_cmp_datascan_x86-7e1.vpx US
binary
suspicious
3708 instup.exe GET 200 23.192.162.201:80 http://s0383910.iavs9x.u.avast.com/iavs9x/ais_cmp_gamingmode-82d.vpx US
binary
suspicious
3708 instup.exe GET 200 23.192.162.201:80 http://s0383910.iavs9x.u.avast.com/iavs9x/ais_cmp_idp_x86-82c.vpx US
binary
suspicious
3708 instup.exe GET 200 23.192.162.201:80 http://s0383910.iavs9x.u.avast.com/iavs9x/ais_cmp_pwdman-848.vpx US
binary
suspicious
3708 instup.exe GET 200 23.192.162.201:80 http://s0383910.iavs9x.u.avast.com/iavs9x/ais_cmp_pwdman_x86-7e1.vpx US
binary
suspicious
3708 instup.exe GET 200 23.192.162.201:80 http://s0383910.iavs9x.u.avast.com/iavs9x/ais_cmp_rescuedisk_x86-7e1.vpx US
binary
suspicious
3708 instup.exe GET 200 23.192.162.201:80 http://s0383910.iavs9x.u.avast.com/iavs9x/ais_cmp_secdns_hlp_x86-7e1.vpx US
binary
suspicious
3708 instup.exe GET 200 23.192.162.201:80 http://s0383910.iavs9x.u.avast.com/iavs9x/ais_cmp_swhealth_x86-7e1.vpx US
binary
suspicious
3708 instup.exe GET 200 23.192.162.201:80 http://s0383910.iavs9x.u.avast.com/iavs9x/ais_core-896.vpx US
binary
suspicious
3708 instup.exe GET 200 23.192.162.201:80 http://s0383910.iavs9x.u.avast.com/iavs9x/ais_dll_eng-882.vpx US
binary
suspicious
3708 instup.exe GET 200 23.192.162.201:80 http://s0383910.iavs9x.u.avast.com/iavs9x/ais_dll_eng_x86-7e1.vpx US
binary
suspicious
3708 instup.exe GET –– 23.192.162.201:80 http://s0383910.iavs9x.u.avast.com/iavs9x/ais_gen_core_x86-7e1.vpx US
––
––
suspicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2576 minecraft_2978705639.exe 52.214.73.247:80 Amazon.com, Inc. IE malicious
2576 minecraft_2978705639.exe 52.212.157.66:80 Amazon.com, Inc. IE malicious
2576 minecraft_2978705639.exe 104.25.53.103:443 Cloudflare Inc US shared
2576 minecraft_2978705639.exe 52.51.129.59:80 Amazon.com, Inc. IE malicious
2576 minecraft_2978705639.exe 192.96.201.162:80 Leaseweb USA, Inc. US suspicious
2576 minecraft_2978705639.exe 185.59.222.146:80 Datacamp Limited NL malicious
2576 minecraft_2978705639.exe 199.201.110.78:80 Namecheap, Inc. US suspicious
2576 minecraft_2978705639.exe 54.192.102.51:443 Amazon.com, Inc. US unknown
2576 minecraft_2978705639.exe 13.33.216.127:80 Amazon.com, Inc. US unknown
2576 minecraft_2978705639.exe 8.241.122.126:80 Level 3 Communications, Inc. US unknown
2864 avastfreeantivirussetuponline.m.exe 216.58.206.14:80 Google Inc. US whitelisted
2864 avastfreeantivirussetuponline.m.exe 5.62.40.203:80 AVAST Software s.r.o. DE unknown
2864 avastfreeantivirussetuponline.m.exe 2.16.186.104:80 Akamai International B.V. –– whitelisted
3568 avast_free_antivirus_setup_online.exe 5.62.40.203:80 AVAST Software s.r.o. DE unknown
3568 avast_free_antivirus_setup_online.exe 216.58.206.14:80 Google Inc. US whitelisted
3308 instup.exe 77.234.44.62:443 AVAST Software s.r.o. US unknown
–– –– 8.8.8.8:53 Google Inc. US whitelisted
3308 instup.exe 23.192.162.171:80 Akamai International B.V. US unknown
3308 instup.exe 23.192.162.201:80 Akamai International B.V. US whitelisted
3708 instup.exe 8.8.8.8:53 Google Inc. US whitelisted
3708 instup.exe 23.192.162.201:80 Akamai International B.V. US whitelisted
3708 instup.exe 23.192.162.186:80 Akamai International B.V. US unknown
3708 instup.exe 77.234.44.62:443 AVAST Software s.r.o. US unknown
3708 instup.exe 5.45.58.75:443 AVAST Software s.r.o. CZ unknown
–– –– 77.234.45.249:443 AVAST Software s.r.o. DE unknown
3708 instup.exe 77.234.45.53:80 AVAST Software s.r.o. DE unknown
3708 instup.exe 5.62.40.203:80 AVAST Software s.r.o. DE unknown

DNS requests

Domain IP Reputation
ww42.tiritoyot-fow.com 52.214.73.247
54.194.149.175
malicious
server.tiritoyot-fow.com 52.212.157.66
52.209.116.64
18.203.190.76
malicious
pic.downloadastro.com 104.25.53.103
104.25.54.103
unknown
api.tiritoyot-fow.com 52.51.129.59
52.50.98.206
52.31.245.195
malicious
img.tiritoyot-fow.com 192.96.201.162
suspicious
cdn.tiritoyot-fow.com 185.59.222.146
suspicious
secure.tiritoyot-fow.com 199.201.110.78
suspicious
launcher.mojang.com 54.192.102.51
suspicious
x.ss2.us 13.33.216.127
13.33.216.149
13.33.216.79
13.33.216.13
whitelisted
www.download.windowsupdate.com 8.241.122.126
67.27.234.254
67.26.75.254
67.27.158.126
8.241.122.254
whitelisted
v7event.stats.avast.com 5.62.40.203
77.234.45.53
whitelisted
www.google-analytics.com 216.58.206.14
whitelisted
iavs9x.u.avast.com 2.16.186.104
2.16.186.50
whitelisted
shepherd.ff.avast.com No response whitelisted
b1477563.iavs9x.u.avast.com 23.192.162.171
23.192.162.201
suspicious
d4130079.iavs9x.u.avast.com 23.192.162.171
23.192.162.201
suspicious
d4479313.iavs9x.u.avast.com 23.192.162.171
23.192.162.201
suspicious
s-iavs9x.avcdn.net 23.40.96.152
malicious
v6831430.iavs9x.u.avast.com 23.192.162.171
23.192.162.201
whitelisted
t7758057.iavs9x.u.avast.com 23.192.162.171
23.192.162.201
suspicious
b4380882.iavs9x.u.avast.com 23.192.162.171
23.192.162.201
suspicious
j4501229.iavs9x.u.avast.com 23.192.162.171
23.192.162.201
whitelisted
s0383910.iavs9x.u.avast.com 23.192.162.171
23.192.162.201
suspicious
w5810700.iavs9x.u.avast.com 23.192.162.171
23.192.162.201
whitelisted
b1477563.vps18tiny.u.avcdn.net 23.192.162.179
23.192.162.186
whitelisted
k5854113.vps18tiny.u.avcdn.net 23.192.162.179
23.192.162.186
whitelisted
g5569634.vps18tiny.u.avcdn.net 23.192.162.179
23.192.162.186
suspicious
p3357684.vps18tiny.u.avcdn.net 23.192.162.179
23.192.162.186
whitelisted
t7758057.vps18tiny.u.avcdn.net 23.192.162.179
23.192.162.186
whitelisted
s-vps18tiny.avcdn.net 23.40.96.152
malicious
alpha-license-dealer.ff.avast.com 5.45.58.75
69.94.69.205
5.45.58.61
whitelisted
alpha-iqs.ff.avast.com 77.234.45.249
5.62.40.210
77.234.45.250
whitelisted

Threats

PID Process Class Message
2576 minecraft_2978705639.exe Misc activity ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M2
2576 minecraft_2978705639.exe Misc activity ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M1
2576 minecraft_2978705639.exe Misc activity ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M3
2576 minecraft_2978705639.exe Misc activity ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M4
2864 avastfreeantivirussetuponline.m.exe Potential Corporate Privacy Violation ET POLICY PE EXE or DLL Windows file download HTTP

1 ETPRO signatures available at the full report

Debug output strings

No debug info.