Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'AVG7_CC' = '%ProgramFiles%\Grisoft\AVG7\avgcc.exe /STARTUP'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgwlx64] 'DLLName' = 'avgwlx64.dll'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgwlx64] 'Logon' = 'WLEventLogon'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgwlx64] 'Startup' = 'WLEventStartup'
- [<HKLM>\System\CurrentControlSet\Services\Avg7UpdSvc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Avg7UpdSvc] 'ImagePath' = '%ProgramFiles%\Grisoft\AVG7\avgupsvc.exe'
- [<HKLM>\System\CurrentControlSet\Services\AvgMfx64] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\AvgMfx64] 'ImagePath' = '<DRIVERS>\avgmfx64.sys'
- [<HKLM>\System\CurrentControlSet\Services\Avg7Alrt] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Avg7Alrt] 'ImagePath' = '%ProgramFiles%\Grisoft\AVG7\avgamsvr.exe'
- [<HKLM>\System\CurrentControlSet\Services\AvgCoreSvc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\AvgCoreSvc] 'ImagePath' = '%ProgramFiles%\Grisoft\AVG7\avgrssvc.exe'
- [<HKLM>\System\CurrentControlSet\Services\AvgCln64] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\AvgCln64] 'ImagePath' = '<DRIVERS>\avgcln64.sys'
- %TEMP%\rarsfx0\install.cmd
- %ProgramFiles(x86)%\grisoft\avg7\license_us.txt
- %ProgramFiles(x86)%\grisoft\avg7\dfncfgfr.dat
- %ProgramFiles(x86)%\grisoft\avg7\dfncfg.dat
- %ProgramFiles(x86)%\grisoft\avg7\avgxch32.dll
- %ProgramFiles(x86)%\grisoft\avg7\avguss.chm
- %ProgramFiles(x86)%\grisoft\avg7\sporder.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgwb.dat
- %ProgramFiles(x86)%\grisoft\avg7\avgw.exe
- %ProgramFiles(x86)%\grisoft\avg7\avgres.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgvv.exe
- %ProgramFiles(x86)%\grisoft\avg7\avgtitle.dat
- %ProgramFiles(x86)%\grisoft\avg7\avgtest.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgset.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgsea64.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgse.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgmvfl.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgscan.exe
- %ProgramFiles(x86)%\grisoft\avg7\avgscan.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgtmgr.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgf.dll
- %ProgramFiles(x86)%\grisoft\avg7\contact_us.txt
- %ProgramFiles(x86)%\grisoft\avg7\setup.dat
- %WINDIR%\temp\udd2603.tmp
- C:\users\public\desktop\avg 7.5.lnk
- %PROGRAMDATA%\microsoft\windows\start menu\programs\avg 7.5\uninstall avg.lnk
- %PROGRAMDATA%\microsoft\windows\start menu\programs\avg 7.5\avg virus vault.lnk
- %PROGRAMDATA%\microsoft\windows\start menu\programs\avg 7.5\avg control center.lnk
- %PROGRAMDATA%\microsoft\windows\start menu\programs\avg 7.5\avg test center.lnk
- <SYSTEM32>\avgwlx64.dll
- <DRIVERS>\avgcln64.sys
- %ProgramFiles(x86)%\grisoft\avg7\order_us.txt
- %ProgramFiles(x86)%\grisoft\avg7\order_us.pdf
- %ProgramFiles(x86)%\grisoft\avg7\setupus.lns
- %ProgramFiles(x86)%\grisoft\avg7\setup.exe
- %ProgramFiles(x86)%\grisoft\avg7\dbghelp.dll
- %ProgramFiles(x86)%\grisoft\avg7\mfc71.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgupsvc.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgupsvc.exe
- %ProgramFiles(x86)%\grisoft\avg7\register_us.txt
- %ProgramFiles(x86)%\grisoft\avg7\register_us.pdf
- <DRIVERS>\avgmfx64.sys
- %ProgramFiles(x86)%\grisoft\avg7\avgrep.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgoff2k.dll
- %ProgramFiles(x86)%\grisoft\avg7\avginet.dll
- %ProgramFiles(x86)%\grisoft\avg7\incavi.avm
- %ProgramFiles(x86)%\grisoft\avg7\miniavi.avg
- %ProgramFiles(x86)%\grisoft\avg7\avi7.avg
- %ProgramFiles(x86)%\grisoft\avg7\avg6cmpt.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgbat.bav
- %ProgramFiles(x86)%\grisoft\avg7\set_vers.cfg
- %ProgramFiles(x86)%\grisoft\avg7\avg.snu
- %ProgramFiles(x86)%\grisoft\avg7\avgabout.dll
- %TEMP%\rarsfx1\setupus.lns
- %TEMP%\rarsfx1\setup.dat
- %TEMP%\rarsfx1\files.dat
- %TEMP%\rarsfx1\afuinst64.dat
- %TEMP%\rarsfx1\sporder.dll
- %TEMP%\rarsfx1\avgsetup.exe
- %TEMP%\rarsfx1\license_us.txt
- %TEMP%\rarsfx0\hidcon.exe
- %TEMP%\rarsfx0\avg75free.exe
- %TEMP%\rarsfx1\trialkey.dat
- %ProgramFiles(x86)%\grisoft\avg7\avgamsvr.exe
- %ProgramFiles(x86)%\grisoft\avg7\avg7us.lng
- %ProgramFiles(x86)%\grisoft\avg7\avgklib.dll
- %ProgramFiles(x86)%\grisoft\avg7\avginet.exe
- %ProgramFiles(x86)%\grisoft\avg7\avgctrl.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgvault.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgunarc.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgupdln.exe
- %ProgramFiles(x86)%\grisoft\avg7\avgupd.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgtres.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgmail.dll
- %ProgramFiles(x86)%\grisoft\avg7\avglng.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgeud32.dll
- %ProgramFiles(x86)%\grisoft\avg7\avglog.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgamint.dll
- %ProgramFiles(x86)%\grisoft\avg7\avghlog.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgcore.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgcfg.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgcckrn.dll
- %ProgramFiles(x86)%\grisoft\avg7\avgcc.exe
- %ProgramFiles(x86)%\grisoft\avg7\avgrssvc.exe
- %ProgramFiles(x86)%\grisoft\avg7\avgwsc.exe
- %ProgramFiles(x86)%\grisoft\avg7\avgamsps.dll
- %PROGRAMDATA%\grisoft\avg7data\avg7log.log
- %TEMP%\avg7inst.log
- %WINDIR%\temp\udd2603.tmp
- %TEMP%\rarsfx1\afuinst64.dat
- %TEMP%\rarsfx1\avgsetup.exe
- %TEMP%\rarsfx1\files.dat
- %TEMP%\rarsfx1\license_us.txt
- %TEMP%\rarsfx1\setup.dat
- %TEMP%\rarsfx1\setupus.lns
- %TEMP%\rarsfx1\sporder.dll
- %TEMP%\rarsfx1\trialkey.dat
- %TEMP%\rarsfx0\avg75free.exe
- %TEMP%\rarsfx0\hidcon.exe
- %TEMP%\rarsfx0\install.cmd
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\rarsfx0\hidcon.exe' install.cmd
- '%TEMP%\rarsfx0\avg75free.exe' /HIDE /DONT_START_APPS /NO_WELCOME /NO_AVGW_STARTUP /QUIT_IF_INSTALLED
- '%TEMP%\rarsfx1\avgsetup.exe' /HIDE /DONT_START_APPS /NO_WELCOME /NO_AVGW_STARTUP /QUIT_IF_INSTALLED
- '%TEMP%\rarsfx1\afuinst64.dat' -v -6 -e "%TEMP%\afuinst64.log"
- '%WINDIR%\syswow64\cmd.exe' /c install.cmd