Technical Information
- %WINDIR%\temp\asw.4fda3667ae73927f\avast_one_setup_online_x64.exe
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\uat_1392.dll
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\setup.def
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\stats.ini.tmp
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\avbugreport_x64_ais-985.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\avdump_x64_ais-985.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\avdump_x86_ais-985.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\offertool_x64_ais-985.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\sbr_x64_ais-985.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\asw75cd5a0abd96e2ff.tmp
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\aswfec37dcd1e54dae6.tmp
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\asw526eee803832e92a.tmp
- C:\users\public\documents\aswoffertool.exe
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\asw69c7c4d468ddb769.tmp
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\asw13138a1916810392.tmp
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\aswc98e272a45745386.tmp
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\uat_1160.dll
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\program.def
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\part-jrog2-53.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\part-vps_windows-20120105.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\vps.def
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\gcapi_16069783812432.dll
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\gcapi_1606978381504.dll
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\servers.def.lkg
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\aswf4ff96f87c73eeb0.tmp
- %ALLUSERSPROFILE%\avast software\persistent data\avast\logs\event_manager.log
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\part-vps_windows-20110904.vpx
- %ALLUSERSPROFILE%\avast software\persistent data\avast\logs\setup.log.tmp.1b44cfe9-26e1-48ad-a0f2-a1768fb9a3a7
- %ALLUSERSPROFILE%\avast software\persistent data\avast\logs\setup.log
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\servers.def
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\config.def
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\config.def.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\instup.exe
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\instcont_x64_ais-985.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\part-jrog2-73a.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\part-prg_ais-14090985.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\part-setup_ais-14090985.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\prod-pgm.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\config.ini
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\prod-vps.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\servers.def.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\htmlayout.dll
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\setgui_x64_ais-985.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\uat.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\uat64.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\uata64.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\instup.dll
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\instup_x64_ais-985.vpx
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\config.def.new
- %ALLUSERSPROFILE%\avast software\persistent data\avast\logs\event_manager.log.tmp.64ee6ac6-7e90-465f-962b-9739cc2a634e
- C:\users\public\documents\gcapi_16069783822312.dll
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\uat_1392.dll
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\uat_1160.dll
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\gcapi_16069783812432.dll
- C:\users\public\documents\gcapi_16069783822312.dll
- C:\users\public\documents\aswoffertool.exe
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\gcapi_1606978381504.dll
- from %ALLUSERSPROFILE%\avast software\persistent data\avast\logs\setup.log.tmp.1b44cfe9-26e1-48ad-a0f2-a1768fb9a3a7 to %ALLUSERSPROFILE%\avast software\persistent data\avast\logs\setup.log
- from %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\config.def.new to %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\config.def
- from %ALLUSERSPROFILE%\avast software\persistent data\avast\logs\event_manager.log.tmp.64ee6ac6-7e90-465f-962b-9739cc2a634e to %ALLUSERSPROFILE%\avast software\persistent data\avast\logs\event_manager.log
- from %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\stats.ini.tmp to %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\stats.ini
- from %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\asw75cd5a0abd96e2ff.tmp to %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\avbugreport.exe
- from %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\aswfec37dcd1e54dae6.tmp to %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\avdump.exe
- from %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\aswf4ff96f87c73eeb0.tmp to %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\instup.exe
- from %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\asw526eee803832e92a.tmp to %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\instup.dll
- from %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\asw69c7c4d468ddb769.tmp to %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\aswoffertool.exe
- from %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\asw13138a1916810392.tmp to %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\sbr.exe
- from %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\aswc98e272a45745386.tmp to %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\htmlayout.dll
- %WINDIR%\temp\asw.1e4dae5e5e0eb3ff\config.def.new
- http://ia####.u.avast.com/iavs9x/avast_one_setup_online_x64.exe
- http://www.go#####analytics.com/collect?av##################################################################################################################################
- http://n2######.iavs9x.u.avast.com/iavs9x/servers.def.vpx
- http://r0######.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx
- http://r0######.iavs9x.u.avast.com/iavs9x/avbugreport_x64_ais-985.vpx
- http://r0######.iavs9x.u.avast.com/iavs9x/avdump_x64_ais-985.vpx
- http://r0######.iavs9x.u.avast.com/iavs9x/avdump_x86_ais-985.vpx
- http://r0######.iavs9x.u.avast.com/iavs9x/offertool_x64_ais-985.vpx
- http://r0######.iavs9x.u.avast.com/iavs9x/sbr_x64_ais-985.vpx
- http://s1######.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx
- http://y9######.vps18tiny.u.avcdn.net/vps18tiny/prod-vps.vpx
- http://y9######.vps18tiny.u.avcdn.net/vps18tiny/part-jrog2-53.vpx
- http://y9######.vps18tiny.u.avcdn.net/vps18tiny/part-vps_windows-20120105.vpx
- http://www.go#####analytics.com/collect
- http://v7#####.stats.avast.com/cgi-bin/iavsevents.cgi
- DNS ASK v7#####.stats.avast.com
- DNS ASK y9######.vps18tiny.u.avcdn.net
- DNS ASK s-#####tiny.avcdn.net
- DNS ASK r9######.vps18tiny.u.avcdn.net
- DNS ASK r0######.vps18tiny.u.avcdn.net
- DNS ASK h4######.vps18tiny.u.avcdn.net
- DNS ASK f3######.vps18tiny.u.avcdn.net
- DNS ASK t1######.iavs9x.u.avast.com
- DNS ASK s1######.iavs9x.u.avast.com
- DNS ASK p9######.iavs9x.u.avast.com
- DNS ASK l4######.iavs9x.u.avast.com
- DNS ASK s-####9x.avcdn.net
- DNS ASK r3######.iavs9x.u.avast.com
- DNS ASK r0######.iavs9x.u.avast.com
- DNS ASK n2######.iavs9x.u.avast.com
- DNS ASK m0######.iavs9x.u.avast.com
- DNS ASK c3######.iavs9x.u.avast.com
- DNS ASK sh#####d.ff.avast.com
- DNS ASK go#####analytics.com
- DNS ASK ia####.u.avast.com
- DNS ASK al########nse-dealer.ff.avast.com
- DNS ASK ss#.####le-analytics.com
- '%WINDIR%\temp\asw.4fda3667ae73927f\avast_one_setup_online_x64.exe' /ga_clientid:470e5424-c865-45d8-b281-faa8b0f84068 /edat_dir:%WINDIR%\Temp\asw.4fda3667ae73927f
- '%WINDIR%\temp\asw.1e4dae5e5e0eb3ff\instup.exe' /sfx:lite /sfxstorage:%WINDIR%\Temp\asw.1e4dae5e5e0eb3ff /edition:22 /prod:ais /guid:5cee9a42-acf2-4f20-b25f-c9ac365ece57 /ga_clientid:470e5424-c865-45d8-b281-faa8b0f84068 /ga_clientid:470e5424...
- '%WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\instup.exe' /sfx /sfxstorage:%WINDIR%\Temp\asw.1e4dae5e5e0eb3ff /edition:22 /prod:ais /guid:5cee9a42-acf2-4f20-b25f-c9ac365ece57 /ga_clientid:470e5424-c865-45d8-b281-faa8b0f84068 /edat_dir:%WINDIR%\Temp\as...
- '%WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\aswoffertool.exe' -checkGToolbar -elevated
- '%WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\aswoffertool.exe' -checkChrome -elevated
- '%WINDIR%\temp\asw.1e4dae5e5e0eb3ff\new_14090985\aswoffertool.exe' -checkChromeReactivation -elevated -bc=AVFA
- 'C:\users\public\documents\aswoffertool.exe' -checkChromeReactivation -bc=AVFA