Trojan.Win32.Swrort.3_ebce751e01

Trojan.Win32.Swrort.3.FD, mzpefinder_pcap_file.YR (Lavasoft MAS) Behaviour: Trojan The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete o...
Blog rating:5 out of5 with1 ratings

Trojan.Win32.Swrort.3_ebce751e01

by malwarelabrobot on April 25th, 2015 in Malware Descriptions.

Trojan.Win32.Swrort.3.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Trojan


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: ebce751e01575edb9cd3c3d01ef16edd
SHA1: 1596910550854cf6dd54467de2d34b6ad25657db
SHA256: d4d90ca981ea4434143ea9a01cfb30bde02d4561377ec25a1981c92c9fd03b36
SSDeep: 12288:gB3C06MXKzHs5ePdKNzlFzLXUoMpRqJo9QznVBQrzEAz4VUhLD5 qs9czG15onzc:gBWMXKzHs5ePdKNzlFzLXUoMpRqJo9QZ
Size: 604712 bytes
File type: EXE
Platform: WIN32
Entropy: Not Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2012-02-19 17:01:57
Analyzed on: Windows7Ada SP1 64-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

No specific payload has been found.

Process activity

The Trojan creates the following process(es):

GoogleUpdate.exe:1176
GoogleUpdate.exe:2424
GoogleUpdate.exe:2556
GoogleUpdate.exe:1856
GoogleUpdate.exe:1932
GoogleUpdaterService_B33FC4DD36A473C6.exe:1412
aswOfferTool.exe:1344
aswOfferTool.exe:2944
aswOfferTool.exe:304
aswOfferTool.exe:2256
aswOfferTool.exe:2784
GoogleToolbarNotifier.exe:2468
GoogleToolbarNotifier.exe:2728
RegSvr32.exe:2432
RegSvr32.exe:2468
RegSvr32.exe:1368
RegSvr32.exe:2916
setup___.exe:1816
GoogleUpdaterService.exe:2800
GoogleUpdaterService.exe:1604
OLBPre.exe:2252
RegSvr64.exe:2964
RegSvr64.exe:956
RegSvr64.exe:1012
RegSvr64.exe:1176
googletoolbarinstaller_en_signed.exe:2660
GoogleUpdateSetup_1.3.21.169.exe:580
MPBSETUP.exe:1752
gtoolbar_setup_14298696672256.exe:1760
instup.exe:3916
instup.exe:1544
instup.exe:4084
instup.exe:3784
instup.exe:2812
instup.exe:3376
instup.exe:3756
instup.exe:3584
instup.exe:3708
instup.exe:3412
instup.exe:4012
instup.exe:3368
instup.exe:3296
instup.exe:3176
SearchWithGoogleUpdate_6F4EEAE8D7FCDAD8.exe:1368
avBugReport.exe:836
aswRunDll.exe:1760
aswRunDll.exe:3820
keytool.exe:3472
regsvr32.exe:1636
%original file name%.exe:1824
BackupSetup.exe:536
9fc49b8a-7b2d-463c-978b-474af67c44b7.exe:2792
AvastEmUpdate.exe:2412
GoogleToolbarManager_BA9226F4C70BECC2.exe:2636
GoogleToolbarManager_BA9226F4C70BECC2.exe:2412
GoogleToolbarManager_BA9226F4C70BECC2.exe:2064

The Trojan injects its code into the following process(es):

werfault.exe:2576
AvastSvc.exe:832

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process GoogleUpdate.exe:1856 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\GUM1B3D.tmp\goopdate.dll (872 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_en.dll (864 bytes)

The process GoogleUpdate.exe:1932 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\Google\Update\Install\{A7B6D392-0D13-454B-A517-CBD6C019C7CC}\googletoolbarinstaller_en_signed.exe (38780 bytes)
C:\Windows\Temp\gui3EC4.tmp (15 bytes)
%Program Files% (x86)\Google\Update\Download\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\0.0.0.0\googletoolbarinstaller_en_signed.exe (38295 bytes)

The process GoogleUpdaterService_B33FC4DD36A473C6.exe:1412 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe (390 bytes)

The process aswOfferTool.exe:1344 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\Public\Documents\gcapi_14298695221344.dll (368 bytes)

The process aswOfferTool.exe:2944 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\gcapi_14298695222944.dll (184 bytes)
C:\Users\Public\Documents\aswOfferTool.exe (23811 bytes)

The process aswOfferTool.exe:304 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\gcapi_1429869522304.dll (368 bytes)

The process aswOfferTool.exe:2256 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\gtoolbar_setup_14298696672256.exe (1635 bytes)

The process aswOfferTool.exe:2784 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\gtapi_14298695222784.dll (146 bytes)

The process GoogleToolbarNotifier.exe:2468 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll (983 bytes)
%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\gtn.dll (147 bytes)

The process RegSvr32.exe:2432 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log (484 bytes)

The process RegSvr32.exe:2468 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log (458 bytes)

The process RegSvr32.exe:1368 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log (462 bytes)

The process RegSvr32.exe:2916 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log (468 bytes)

The process setup___.exe:1816 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x64_ais-89e.vpx (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instcont_ais-89e.vpx (75 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-iex-1.vpx (217 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup.exe (412 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\servers.def (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x86_ais-89e.vpx (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-prg_ais-89e.vpx (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\prod-ais.vpx (354 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\prod-vps.vpx (452 bytes)
C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log (2022 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\setgui_ais-89e.vpx (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avbugreport_ais-89e.vpx (553 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-vps_win32-14102100.vpx (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\HTMLayout.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-jrog2-bb9.vpx (676 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avBugReport.exe (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\Instup.dll (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\servers.def.vpx (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-setup_ais-89e.vpx (75 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup_ais-89e.vpx (2 bytes)

The process OLBPre.exe:2252 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\OLBPre\state.jdat (428 bytes)
%Program Files% (x86)\OLBPre\aff.jdat (200 bytes)

The process RegSvr64.exe:2964 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log (476 bytes)

The process RegSvr64.exe:956 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log (466 bytes)

The process RegSvr64.exe:1012 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log (484 bytes)

The process RegSvr64.exe:1176 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log (472 bytes)

The process googletoolbarinstaller_en_signed.exe:2660 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarUser_32_52E818EF81C83A9B.exe (620 bytes)
%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbar_64_62C1B48EAF0FD125.dll (514 bytes)
%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_0A4439FF67F61065.dll (2 bytes)
%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_64_2AD99D2EA038D2F2.dll (489 bytes)
C:\Windows\System32\config\SOFTWARE (99158 bytes)
C:\ (96 bytes)
%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_32_75A7C54F0BE42E8E.dll (149 bytes)
%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarUser_64_4D9709C1FA1422BA.exe (801 bytes)
%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbar.7.5.6227.252.manifest.xml (36 bytes)
%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe (50 bytes)
%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbar_32_3934E923EEC91A78.dll (390 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GoogleToolbarInstaller2.log (43867 bytes)
%Program Files% (x86)\Google\Google Toolbar\Component\SearchWithGoogleUpdate_6F4EEAE8D7FCDAD8.exe (50 bytes)
C:\Windows (288 bytes)
C:\$Directory (384 bytes)
%Program Files% (x86)\Google\Google Toolbar\Component\GoogleUpdateSetup_5CC4B0F53D73AD88.exe (1480 bytes)
%Program Files% (x86)\Google\Google Toolbar\Component\GoogleUpdaterService_B33FC4DD36A473C6.exe (390 bytes)
C:\Windows\System32\config\SOFTWARE.LOG1 (94108 bytes)
%Program Files% (x86)\Google\Google Toolbar\Component\GoogleCld_187F9D811452062B.dll (50 bytes)

The process GoogleUpdateSetup_1.3.21.169.exe:580 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\GUM1B3D.tmp\goopdateres_bn.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_ur.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_kn.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_gu.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_sl.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_mr.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_el.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_fil.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_ja.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp (28 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_et.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_zh-CN.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_es-419.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_pt-BR.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_uk.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_hu.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\GoogleUpdateOnDemand.exe (59 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_da.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_fr.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_de.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_th.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\npGoogleUpdate3.dll (838 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_vi.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_bg.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_pt-PT.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_sv.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_lt.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_ko.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdate.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_sr.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_zh-TW.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_ar.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_tr.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_it.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_is.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_no.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_ro.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_en-GB.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\psuser.dll (163 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_hi.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_hr.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_fa.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\GoogleUpdate.exe (234 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_id.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\GoogleCrashHandler.exe (237 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_am.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_nl.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\GoogleUpdateSetup.exe (5873 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_cs.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_ca.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_ru.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_lv.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_fi.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_iw.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\GoogleUpdateHelper.msi (26 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_sw.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\psmachine.dll (163 bytes)
%Program Files% (x86)\GUM1B3D.tmp\GoogleCrashHandler64.exe (550 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_en.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\GoogleUpdateBroker.exe (59 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_ta.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_te.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_ml.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_ms.dll (1702 bytes)
%Program Files% (x86)\GUT1B3E.tmp (63108 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_sk.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_pl.dll (1702 bytes)
%Program Files% (x86)\GUM1B3D.tmp\goopdateres_es.dll (1702 bytes)

The process MPBSETUP.exe:1752 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc7E15.tmp\NSISdl.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aff.conf (111 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\BackupSetup.exe (72675 bytes)

The process gtoolbar_setup_14298696672256.exe:1760 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GoogleUpdateSetup_1.3.21.169.exe (26262 bytes)

The process instup.exe:3916 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log (10438 bytes)

The process instup.exe:1544 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\atl110.dll (164 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\sasF297.tmp (532 bytes)
C:\Windows\System32\Tasks (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\zh_TW\mesF3A1.tmp (11 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\en\mesF40F.tmp (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GoogleToolbarInstaller2.log (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\sasF61B.tmp (532 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_o7.map (163 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF553.tmp (159 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\mocks\gptF1CC.tmp (422 bytes)
%Program Files%\AVAST Software\Avast\ffmFBEE.tmp (985 bytes)
%Program Files%\AVAST Software\Avast\WebRep\Chrome\AswF18F.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF53F.tmp (715 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\winbar\winF746.tmp (18 bytes)
C:\Windows\Prefetch (672 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\indF053.tmp (3 bytes)
%Program Files% (x86)\Google\Google Toolbar\GoogleToolbarHelperPatch_signed.msp (126 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F61D.tmp (566 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\iplugins-4.vpx.dld (423 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ur\mesF49C.tmp (15 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF01D.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\locales\hu.FEE5.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icoF5CC.tmp (7 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\zh_TW\mesF49F.tmp (11 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF030.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (4 bytes)
%Program Files% (x86)\Google\Update\Download\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\0.0.0.0\googletoolbarinstaller_en_signed.exe (436 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_EE3.tmp (66 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_C9A.tmp (18 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\fi\mesF424.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_E96.tmp (57 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF66D.tmp (557 bytes)
%Program Files%\AVAST Software\Avast\Setup\Stats.txt (8 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_w6.map (13 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\ialF4DB.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs\jquF1A6.tmp (219 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF579.tmp (215 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_F85.tmp (12 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\butEFC1.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF58E.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\RescueDisk\waiF0BD.tmp (3 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\whiC66.tmp (2 bytes)
C:\ProgramData\AVAST Software\Avast\sounds\1033\scaF812.tmp (37 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_gen_gui_cef-7ce.vpx (7815 bytes)
C:\Windows\winsxs (1906 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_C88.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\shoF6FE.tmp (582 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_js.map (6 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F61E.tmp (619 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\de\mesF300.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x64\AvaFA43.tmp (9 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF51F.tmp (736 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\da\mesF3FD.tmp (11 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\sv\mesF478.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF66E.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\resources\resFBBC.tmp (344 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFD9.tmp (1 bytes)
C:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\mfc110u.dll (678 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ms\mesF360.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\AvaF84A.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\locales\en-FEB8.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\BroEF59.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301 (16 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_cmp_webrep-7ed.vpx (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_cmp_grimefighter-7eb.vpx.dld (225848 bytes)
C:\Windows\System32\drivers\aswHwid.sys (29 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_E25.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\RescueDisk\aswF0BA.tmp (44 bytes)
%Program Files%\AVAST Software\Avast\locales\kn.FEF8.tmp (30 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\hr\mesF428.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF646.tmp (812 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_crt_x64-7e4.vpx.dld (143341 bytes)
C:\ProgramData\AVAST Software\Avast\sounds\fw_FA1C.tmp (24 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\sasF608.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\pt_BR\mesF374.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ca\mesF3CC.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\scrEF48.tmp (27 bytes)
C:\$Directory (5728 bytes)
%Program Files%\AVAST Software\Avast\flash\ammap\ammF9BA.tmp (30 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF01E.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\flash\ammap (4 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF006.tmp (1 bytes)
%Program Files% (x86)\Google\Google Toolbar\GoogleToolbarHelper_signed.msi (28 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF576.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\fr\mesF327.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\it\mesF43B.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\locales (20 bytes)
%Program Files%\AVAST Software\Avast\setup\aswEEE4.tmp (23811 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_cmp_webrep-7ed.vpx.dld (110225 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F2AC.tmp (413 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF043.tmp (1 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF01F.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_CCC.tmp (5879 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFD8.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\he\mesF328.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\arrF4DC.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\locales\bn.FEA3.tmp (28 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_x64-7f5.vpx (392 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF505.tmp (227 bytes)
%Program Files%\AVAST Software\Avast\locales\nb.FF0F.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\setup\iplugins\ISt9B5.tmp (28 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\aswFEE.tmp (463 bytes)
%Program Files%\AVAST Software\Avast (32 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\pinF607.tmp (3 bytes)
%Program Files%\AVAST Software\Avast\RescueDisk\uiLF0BC.tmp (294 bytes)
%Program Files%\AVAST Software\Avast\1033\AvaF7EA.tmp (135 bytes)
%Program Files%\AVAST Software\Avast\setup\setC65.tmp (5 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\de\mesF3FE.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\vi\mesF39F.tmp (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\bn\mesF3CB.tmp (19 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F630.tmp (413 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ur\mesF39E.tmp (15 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5A4.tmp (294 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\blocker\bloF4B5.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\asO64.tmp (456 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\swh1056.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF59F.tmp (450 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\maiF6AB.tmp (738 bytes)
%Program Files%\AVAST Software\Avast\setup\instcont_ais-8aa.vpx (4185 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\seaF6E6.tmp (11 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ca\mesF2FD.tmp (12 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF007.tmp (1 bytes)
C:\ProgramData\AVAST Software\Avast\log\PushPin0.log (157 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\jquF699.tmp (92 bytes)
%Program Files%\AVAST Software\Avast\VisF8A0.tmp (254 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5B7.tmp (470 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\3.gEF99.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\sk\mesF475.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\locales\lv.FEFB.tmp (15 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x64\PolFA54.tmp (9 bytes)
%Program Files%\AVAST Software\Avast\HTMEEE3.tmp (22575 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF551.tmp (343 bytes)
%Program Files%\AVAST Software\Avast\aswF78A.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFFDA.tmp (442 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\he\mesF426.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\aswFDD.tmp (127 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF50A.tmp (724 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ko\mesF43D.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\setup\part-vps_win32-15042301.vpx (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F633.tmp (1 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\blaEFC0.tmp (43 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\aswFAA.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\AhR77.tmp (303 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\vps_win64-ca0.vpx.dld (166124 bytes)
%Program Files%\AVAST Software\Avast\setup\Inf\x64\aswF11B.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\asw1098.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\safeshop (4 bytes)
%Program Files%\AVAST Software\Avast\OpenVPN\driver\win64\ndis6\aswF0F4.tmp (6 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF209.tmp (357 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_gen_tools_x64-7e2.vpx (1 bytes)
%Program Files%\AVAST Software\Avast\OpenVPN\driver\win64\ndis6\aswF0F3.tmp (10 bytes)
%Program Files%\AVAST Software\Avast\ComF87F.tmp (3 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_core-7f5.vpx (3692 bytes)
C:\Windows\System32\config\SYSTEM (15750 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFD6.tmp (793 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\fblF4DF.tmp (3 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_ECE.tmp (17 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_cmp_grimefighter-7eb.vpx (392 bytes)
C:\ProgramData\AVAST Software\Avast\Fonts\OpeFA07.tmp (222 bytes)
%Program Files%\AVAST Software\Avast\ashF8C1.tmp (104 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\conEF6C.tmp (184 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F631.tmp (481 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\credentials\creF4C8.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_cmp_rescuedisk-7f5.vpx.dld (18805 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF66F.tmp (679 bytes)
C:\Windows\winsxs\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396\atl110.dll (192 bytes)
%Program Files%\AVAST Software\Avast\aswF94F.tmp (102 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF032.tmp (1 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF003.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\logFA31.tmp (114 bytes)
C:\ProgramData\AVAST Software\Avast\log\Instup.log (2840 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\settings\optF6E8.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icoF5CE.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\defs\aswdefs.ini (32 bytes)
%Program Files%\AVAST Software\Avast\locales\el.FEB7.tmp (24 bytes)
%Program Files% (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\avaF4DD.tmp (3 bytes)
%Program Files%\AVAST Software\Avast\aswF14D.tmp (33 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\aswCmnOS.dll (131 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF58D.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\aswFDE.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\locales\sv.FF48.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\zh_CN\mesF49E.tmp (11 bytes)
C:\Windows\avaFA30.tmp (43 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF259.tmp (260 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_ECD.tmp (8 bytes)
C:\ProgramData\Google\Custom Buttons\toolbar.google.com_O8Y91YHB24Z6SR0SGYSK.XML (16 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\lv\mesF35F.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\ashF8B1.tmp (891 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\nonF01A.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\asw1002.tmp (167 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\temF1F4.tmp (20 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_elf.map (81 bytes)
%Program Files%\AVAST Software\Avast\aswF068.tmp (78 bytes)
%Program Files%\AVAST Software\Avast\snxF11A.tmp (336 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x86\AvaFB08.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_F0E.tmp (73 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFF0.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ja\mesF43C.tmp (14 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF008.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_EE7.tmp (59 bytes)
%Program Files%\AVAST Software\Avast\avaF985.tmp (76 bytes)
%Program Files%\AVAST Software\Avast\libFC4E.tmp (5879 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_E35.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\AvSF849.tmp (69 bytes)
%Program Files%\AVAST Software\Avast\locales\gu.FEE1.tmp (26 bytes)
%Program Files%\AVAST Software\Avast\locales\ar.FE91.tmp (21 bytes)
%Program Files%\AVAST Software\Avast\OpenVPN\driver\win64\ndis6\delF105.tmp (154 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\sitecorrect\sitF730.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\locales\zh-FF6F.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\Certificates (4 bytes)
%Program Files%\AVAST Software\Avast\locales\et.FECC.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\flaF4E0.tmp (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\aswOfferTool.exe (291 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\settings\setF6FA.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\mocks\ga.F4B0.tmp (439 bytes)
%Program Files%\AVAST Software\Avast\flash\ammap\icons\pinF9E1.tmp (382 bytes)
%Program Files%\AVAST Software\Avast\aswF971.tmp (406 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_F40.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_cmp_bpc-7e5.vpx (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_crt_x86-7e3.vpx.dld (108256 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\es\mesF411.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\queF1E4.tmp (31 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\id\mesF43A.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\License\EULFF94.tmp (15 bytes)
%Program Files%\AVAST Software\Avast\setup\config.def (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\winbar\tesF743.tmp (11 bytes)
%Program Files%\AVAST Software\Avast\OpenVPN\driver\win64\ndis6\aswF104.tmp (44 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF20C.tmp (463 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\bg\mesF2EB.tmp (14 bytes)
C:\ProgramData\AVAST Software\Avast\Fonts\OpeFA08.tmp (217 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ru\mesF465.tmp (16 bytes)
%Program Files%\AVAST Software\Avast\locales\th.FF5B.tmp (27 bytes)
C:\ (296 bytes)
%Program Files%\AVAST Software\Avast\1033\aswF7EE.tmp (101 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\gadEFD4.tmp (11 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\ialF1E2.tmp (38 bytes)
C:\Windows\System32\asw62C.tmp (2105 bytes)
%Program Files%\AVAST Software\Avast\sslFF82.tmp (294 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_EFC.tmp (1 bytes)
C:\ProgramData\AVAST Software\Avast\Fonts\OpeFA06.tmp (212 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData (676 bytes)
%Program Files% (x86)\Google\Google Toolbar\GoogleToolbarUser_64.exe (401 bytes)
%Program Files%\AVAST Software\Avast\ashFFA6.tmp (722 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x64\AvaFA44.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\settings\optF6E9.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_elfa.map (28 bytes)
%Program Files%\AVAST Software\Avast\AavFF95.tmp (319 bytes)
%Program Files%\AVAST Software\Avast\schF9F4.tmp (90 bytes)
%Program Files%\AVAST Software\Avast\aswFFED.tmp (600 bytes)
%Program Files%\AVAST Software\Avast\AhR43.tmp (93 bytes)
%Program Files%\AVAST Software\Avast\asw8A.tmp (171 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\da\mesF2FF.tmp (11 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_ECF.tmp (28 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF031.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\setup\insEEC2.tmp (4185 bytes)
%Program Files%\AVAST Software\Avast\locales\bg.FE92.tmp (23 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF51E.tmp (666 bytes)
C:\ProgramData\AVAST Software\Avast\sounds\1033\welF816.tmp (20 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\jquF6A9.tmp (15 bytes)
%Program Files%\AVAST Software\Avast\ashF8C2.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F62F.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_EE4.tmp (120 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFEC.tmp (1 bytes)
C:\Users\Public\Desktop\Avast Free Antivirus.lnk (1 bytes)
%Program Files%\AVAST Software\Avast\aswF079.tmp (392 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFD7.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_ECA.tmp (361 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF644.tmp (909 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\oveF3B4.tmp (23 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\algEA7.tmp (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_cmp_secureline-7ce.vpx.dld (18351 bytes)
%Program Files%\AVAST Software\Avast\flash\ammap\empF9CC.tmp (11 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\sasF286.tmp (307 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x64\atlFA56.tmp (192 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF21D.tmp (343 bytes)
%Program Files% (x86)\Google\Google Toolbar (4 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_swf.map (29 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\el\mesF40E.tmp (16 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\bn\mesF2EC.tmp (19 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\asw1000.tmp (457 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_cmp_secureline_x64-7cf.vpx (300 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\unsF01C.tmp (5 bytes)
%Program Files%\AVAST Software\Avast\locales\ca.FEA4.tmp (15 bytes)
%Program Files%\AVAST Software\Avast\Certificates\digF86D.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts (4 bytes)
%Program Files%\AVAST Software\Avast\aswF984.tmp (103 bytes)
%Program Files%\AVAST Software\Avast\setup\part-prg_ais-8aa.vpx (11 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\sitecorrect\sitF731.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2C3.tmp (559 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF20D.tmp (470 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF232.tmp (2 bytes)
C:\ProgramData\AVAST Software\Avast\sounds\thrFA1E.tmp (21 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\mocks\omnF1CD.tmp (770 bytes)
%Program Files%\AVAST Software\Avast\AvaF067.tmp (143 bytes)
%Program Files%\AVAST Software\Avast\locales\mr.FF0D.tmp (26 bytes)
%Program Files%\AVAST Software\Avast\AhR87.tmp (72 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\credentials\creF4C9.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF671.tmp (653 bytes)
%Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFFEB.tmp (272 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\shoF6FF.tmp (535 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5B9.tmp (470 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF58A.tmp (264 bytes)
%Program Files%\AVAST Software\Avast\locales\fi.FECE.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_res-7f5.vpx (392 bytes)
%Program Files%\AVAST Software\Avast\setup\servers.def.vpx (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\asw1001.tmp (408 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF58F.tmp (287 bytes)
%Program Files%\AVAST Software\Avast\aswF93B.tmp (64 bytes)
%Program Files%\AVAST Software\Avast\avaF986.tmp (428 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\it\mesF34C.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\aswF917.tmp (356 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF005.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F2AB.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_str.map (8 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\uk\mesF39D.tmp (16 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_gen_streamfilter-7f5.vpx (679 bytes)
%Program Files%\AVAST Software\Avast\aswF77A.tmp (662 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\winbar (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs\q.jF1B9.tmp (58 bytes)
%Program Files%\AVAST Software\Avast\aswF12D.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\setup\part-jrog2-d50.vpx (903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\HTMLayout.dll (291 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF234.tmp (1 bytes)
C:\Windows\winsxs\Manifests (4963 bytes)
%Program Files%\AVAST Software\Avast\aswF.tmp (608 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_gen_openssl-7d4.vpx (1 bytes)
%Program Files% (x86) (100 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_sl.map (2 bytes)
%Program Files%\AVAST Software\Avast\setup\prod-vps.vpx (450 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF004.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\zh_CN\mesF3A0.tmp (11 bytes)
C:\ProgramData\AVAST Software\Avast\sounds\1033\pupF811.tmp (54 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_ECB.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\fa\mesF413.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\optF1E3.tmp (4 bytes)
C:\Windows\System32\drivers\aswRvrt.sys (601 bytes)
%Program Files% (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (311 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\cs\mesF2FE.tmp (12 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\secF01B.tmp (6 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF670.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GoogleToolbarInstaller1.log (8 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\safeshop\avaF6BF.tmp (256 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\15.EF94.tmp (2 bytes)
C:\Windows (580 bytes)
C:\ProgramData\AVAST Software\Avast\sounds\scaFA1D.tmp (24 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\shoF700.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\setup\servers.def (17 bytes)
%Program Files%\AVAST Software\Avast\1033\BooF7EC.tmp (24 bytes)
C:\Windows\Temp (8 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF574.tmp (646 bytes)
%Program Files%\AVAST Software\Avast\aswF906.tmp (941 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba (4 bytes)
%Program Files%\AVAST Software\Avast\locales\cs.FEA5.tmp (14 bytes)
C:\Windows\winsxs\Manifests\amd64_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_6aa8346920c8423b.manifest (612 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\aswFEF.tmp (624 bytes)
%Program Files%\AVAST Software\Avast\AvaFB6D.tmp (392 bytes)
%Program Files%\AVAST Software\Avast\locales\ru.FF24.tmp (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_tools_x64-7e2.vpx.dld (15807 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_mx4.map (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_cmp_secureline_x64-7cf.vpx.dld (3117 bytes)
%Program Files%\AVAST Software\Avast\1033\aswF7ED.tmp (678 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\app745D.tmp (3073 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x86\AvaFB07.tmp (9 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\mocks\ga.F1CB.tmp (439 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F632.tmp (1 bytes)
%Program Files% (x86)\Google\Google Toolbar\Component (4 bytes)
%Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFF93.tmp (93 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\avaF1CE.tmp (684 bytes)
%Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFFD9.tmp (65 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\logF26F.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_cmp_rescuedisk-7f5.vpx (965 bytes)
%Program Files%\AVAST Software\Avast\locales\sw.FF49.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\CrtCheck32.dll (57 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ms\mesF44E.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_dyna.map (272 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF58C.tmp (4 bytes)
%Program Files% (x86)\Google\Update (4 bytes)
%Program Files%\AVAST Software\Avast\OpenVPN (4 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF019.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF65C.tmp (556 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\chrF190.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F299.tmp (566 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\aswFCB.tmp (446 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5A1.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\aswF972.tmp (47 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\be\mesF3C9.tmp (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_gui-7d5.vpx.dld (98753 bytes)
C:\Windows\winsxs\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.manifest (608 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\css\setF1F6.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\aswF939.tmp (648 bytes)
%Program Files%\AVAST Software\Avast\pdfFF71.tmp (16 bytes)
C:\ProgramData\AVAST Software\Avast\avast5.ini (4678 bytes)
%Program Files%\AVAST Software\Avast\1033\BCUF827.tmp (27 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\css\extF1F5.tmp (60 bytes)
%Program Files%\AVAST Software\Avast\locales\de.FEB6.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\sasF61C.tmp (836 bytes)
%Program Files%\AVAST Software\Avast\locales\ko.FEF9.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\cerEC9.tmp (237 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_EDF.tmp (5 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\quiF6BE.tmp (110 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates (8 bytes)
%Program Files%\AVAST Software\Avast\locales\sk.FF25.tmp (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\tr\mesF38C.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF508.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF257.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_dll_eng-7f5.vpx (794 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\sasF285.tmp (580 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF21F.tmp (744 bytes)
C:\Windows\System32\drivers\aswVmm.sys (1425 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF66C.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_EE6.tmp (9 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\asw10D9.tmp (551 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF4F4.tmp (665 bytes)
%Program Files%\AVAST Software\Avast\dbgF987.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\be\mesF2EA.tmp (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_FB6BD2AF592BD59C48D4520A31AC1EA3 (4 bytes)
%Program Files% (x86)\Google (4 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\14.EF93.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_gen_crt_x64-7e4.vpx (392 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\ext1033.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\asw9B.tmp (198 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\avaF1CF.tmp (74 bytes)
%Program Files%\AVAST Software\Avast\AhA76.tmp (169 bytes)
%Program Files%\AVAST Software\Avast\locales\nl.FF1F.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\uie1067.tmp (59 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\10.EF7F.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF575.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5A0.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF256.tmp (2 bytes)
C:\Windows\winsxs\Manifests\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.cat (9 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\ArPFA8.tmp (52 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\9.gEFBE.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\locales\uk.FF5D.tmp (22 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x86\mfcFB0C.tmp (392 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\sl\mesF388.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x64\PolFA55.tmp (612 bytes)
C:\Users\Public (4 bytes)
%Program Files%\AVAST Software\Avast\Set31.tmp (674 bytes)
%Program Files%\AVAST Software\Avast\aswF94E.tmp (335 bytes)
%Program Files%\AVAST Software\Avast\setup\HTMEEC3.tmp (22575 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x86 (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\logF5F1.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\ash88.tmp (382 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF231.tmp (733 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\algo.dll (146 bytes)
%Program Files%\AVAST Software\Avast\locales\te.FF5A.tmp (30 bytes)
%Program Files%\AVAST Software\Avast\setup\ngiodriver_x64_ais-8aa.vpx (17 bytes)
%Program Files%\AVAST Software\Avast\locales\es.FECB.tmp (15 bytes)
%Program Files%\AVAST Software\Avast\1033\BasF7EB.tmp (63 bytes)
C:\$ConvertToNonresident (16 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\sr\mesF477.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\pt_BR\mesF452.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\flash\amlF9B8.tmp (54 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\app745E.tmp (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\vps_32-1000.vpx.dld (9387949 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\config.def.new (196 bytes)
%Program Files%\AVAST Software\Avast\flash\ammap\ammF9B9.tmp (51 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x64 (4 bytes)
%Program Files%\AVAST Software\Avast\1033\aswF800.tmp (442 bytes)
%Program Files%\AVAST Software\Avast\locales\id.FEF5.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\aswF929.tmp (127 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_java.map (976 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\attEFBF.tmp (6 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ru\mesF377.tmp (16 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\xinF697.tmp (3 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_EE8.tmp (238 bytes)
%Program Files%\AVAST Software\Avast\locales\tr.FF5C.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\safeshop\safF6D2.tmp (354 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_tools-7e2.vpx.dld (21843 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\winbar\winF747.tmp (45 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F29A.tmp (619 bytes)
%Program Files%\AVAST Software\Avast\locales\pt-FF21.tmp (14 bytes)
C:\ProgramData (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\et\mesF315.tmp (11 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\8.gEFAE.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\flash\ammap\maps\worF9E3.tmp (127 bytes)
%Program Files%\AVAST Software\Avast\ashF8F4.tmp (269 bytes)
%Program Files%\AVAST Software\Avast\locales\lt.FEFA.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img (28 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\sk\mesF378.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\alg1069.tmp (3 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_dex.map (1 bytes)
%Program Files%\AVAST Software\Avast\aswF94D.tmp (281 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_EFB.tmp (79 bytes)
%Program Files%\AVAST Software\Avast\setup\part-iex-4.vpx (232 bytes)
C:\ProgramData\AVAST Software\Avast\Fonts\OpeF9F5.tmp (224 bytes)
%Program Files%\AVAST Software\Avast\locales\fa.FECD.tmp (19 bytes)
%Program Files%\AVAST Software\Avast\locales\sl.FF46.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\setup\SnxF119.tmp (59 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\safezone\safF6D4.tmp (948 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_cmp_bpc-7e5.vpx.dld (52103 bytes)
C:\Windows\Prefetch\GOOGLEUPDATE.EXE-648FB068.pf (49 bytes)
%Program Files%\AVAST Software\Avast\aswF759.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\ash89.tmp (126 bytes)
%Program Files%\AVAST Software\Avast\setup\avBEEF5.tmp (11518 bytes)
%Program Files%\AVAST Software\Avast\locales\filFECF.tmp (15 bytes)
%Program Files%\AVAST Software\Avast\aswF748.tmp (565 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\defEC8.tmp (7 bytes)
%Program Files%\AVAST Software\Avast\aswF960.tmp (47 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x64\mfcFA57.tmp (392 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\gooF4F1.tmp (3 bytes)
%Program Files%\AVAST Software\Avast\setup\jrog2-d50.vpx (3 bytes)
%Program Files%\AVAST Software\Avast\flash\ammap\icons\arrF9CD.tmp (76 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x86\PolFB09.tmp (9 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\pt_PT\mesF375.tmp (12 bytes)
C:\ProgramData\AVAST Software\Avast\sounds (4 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\Sf21045.tmp (803 bytes)
%Program Files%\AVAST Software\Avast\AavF828.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icoF26C.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\Sf.F87.tmp (532 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\hu\mesF429.tmp (13 bytes)
C:\ProgramData\AVAST Software\Avast\sounds\1033\thrF814.tmp (31 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF02F.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\aswF93A.tmp (123 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\aswCmnBS.dll (446 bytes)
%Program Files%\AVAST Software\Avast\aswFFEC.tmp (78 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_openssl-7d4.vpx.dld (32164 bytes)
C:\ProgramData\AVAST Software\Avast\Fonts (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\sasF284.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\sasF619.tmp (580 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp (4 bytes)
%Program Files%\AVAST Software\Avast\JsoF89F.tmp (81 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFED.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_x64-7f5.vpx.dld (108247 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icoF26B.tmp (989 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ro\mesF464.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\setup\Inf\x64 (4 bytes)
%Program Files% (x86)\OLBPre (4 bytes)
%Program Files%\AVAST Software\Avast\OpenVPN\driver\win64\ndis6\tapF106.tmp (88 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\tumF684.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\imgF5EF.tmp (17 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF21E.tmp (674 bytes)
C:\Windows\winsxs\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396\msvcr110.dll (849 bytes)
%Program Files%\AVAST Software\Avast\flash\ammap\icons\flaF9E0.tmp (378 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF235.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF577.tmp (5 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF233.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\locales\hr.FEE4.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\WebRep\Chrome\AswF14E.tmp (642 bytes)
%Program Files%\AVAST Software\Avast\setup\prod-ais.vpx (356 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\logF5F3.tmp (1 bytes)
C:\Windows\System32\wdi (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\nl\mesF362.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\Setup\Stats.ini (1241 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\winbar\winF745.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\flash\ammap\ammF9CB.tmp (5 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\vklF696.tmp (3 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\indF064.tmp (3 bytes)
C:\Windows\Installer\381d.msi (28 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\safezone\safF6E5.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\winbar\tesF744.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_EE2.tmp (16 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\optF3B3.tmp (422 bytes)
%Program Files%\AVAST Software\Avast\setup\vps_win32-100f.vpx (1944 bytes)
%Program Files% (x86)\Google\Update\Download (4 bytes)
C:\Windows\winsxs\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396 (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\oveF3B5.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\avaF208.tmp (3 bytes)
C:\Windows\winsxs\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.cat (9 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_cmp_secureline-7ce.vpx (771 bytes)
%Program Files%\AVAST Software\Avast\ashF8F5.tmp (186 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF002.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\locales\es-FECA.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_F10.tmp (788 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\tr\mesF47A.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_EFA.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\lv\mesF43E.tmp (12 bytes)
C:\Windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d} (4 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_CCB.tmp (986 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688 (24 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_F84.tmp (23 bytes)
%Program Files%\AVAST Software\Avast\1033\uiLF801.tmp (294 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\arrF1F7.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_FB6BD2AF592BD59C48D4520A31AC1EA3 (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\jrog2-d50.vpx.dld (104385 bytes)
%Program Files%\AVAST Software\Avast\CrtFA42.tmp (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ar\mesF2E9.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\snxF107.tmp (277 bytes)
%Program Files%\AVAST Software\Avast\WebRep\Chrome (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5A2.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F2AE.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFFC9.tmp (89 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\aswFCC.tmp (434 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF509.tmp (463 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\hovF2D9.tmp (802 bytes)
%Program Files%\AVAST Software\Avast\ComF86E.tmp (575 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFEB.tmp (1 bytes)
C:\Windows\winsxs\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396\msvcp110.dll (661 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\nb\mesF361.tmp (11 bytes)
%Program Files%\AVAST Software\Avast\aswEF47.tmp (71 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF230.tmp (787 bytes)
%Program Files%\AVAST Software\Avast\OpenVPN\opeF0E0.tmp (622 bytes)
%Program Files%\Windows Sidebar (4 bytes)
%Program Files%\AVAST Software\Avast\aswFFB6.tmp (375 bytes)
%Program Files%\AVAST Software\Avast\locales\ro.FF23.tmp (15 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_EE5.tmp (524 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\~tmp_aswInstUpHttpGet (210 bytes)
%Program Files%\AVAST Software\Avast\RegFFFF.tmp (577 bytes)
C:\ProgramData\AVAST Software\Avast\snxF108.tmp (15 bytes)
C:\Windows\System32\drivers\aswMonFlt.sys (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_gui_cef-7ce.vpx.dld (1618398 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale (4 bytes)
%Program Files%\AVAST Software\Avast\setup\part-setup_ais-8aa.vpx (601 bytes)
%Program Files%\AVAST Software\Avast\1033\aswF7FF.tmp (629 bytes)
C:\Windows\System32\drivers\aswRdr2.sys (601 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\et\mesF412.tmp (11 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs\lodF1B7.tmp (223 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\mocks\mapF4B2.tmp (605 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF258.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_mx95.map (9 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\gpbF1E1.tmp (23 bytes)
C:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\msvcr110.dll (1751 bytes)
%Program Files%\AVAST Software\Avast\locales\he.FEE2.tmp (16 bytes)
%Program Files%\AVAST Software\Avast\flash\ammap\icons\croF9CF.tmp (234 bytes)
C:\ProgramData\AVAST Software\Avast\HtmlData\ima9D.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\cefFBDD.tmp (427 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\aswFBB.tmp (508 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_F41.tmp (7 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5A3.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\extF2D8.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\locales\ja.FEF7.tmp (16 bytes)
C:\Windows\winsxs\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.manifest (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_F42.tmp (149 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_C9B.tmp (392 bytes)
C:\Users\"%CurrentUserName%"\Desktop (4 bytes)
%Program Files%\AVAST Software\Avast\aswF94C.tmp (81 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\17.EF96.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\fr\mesF425.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F2AD.tmp (481 bytes)
C:\Windows\winsxs\Manifests\amd64_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_6aa8346920c8423b.cat (9 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs\jquF1B6.tmp (15 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\id\mesF34B.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\cleF4C7.tmp (37 bytes)
%Program Files%\AVAST Software\Avast\ashF8E3.tmp (392 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\sl\mesF476.tmp (12 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\16.EF95.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\th\mesF38B.tmp (19 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\nb\mesF44F.tmp (11 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images (16 bytes)
%Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFFC8.tmp (29 bytes)
%Program Files%\AVAST Software\Avast\setup\InsEEC1.tmp (66235 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\aswEngin.dll (49 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\butEFC2.tmp (1 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\5.gEFAB.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\setup\vps_win64-ca0.vpx (392 bytes)
%Program Files%\AVAST Software\Avast\Certificates\ARAEF25.tmp (8 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\mocks\gptF4B1.tmp (439 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_ECC.tmp (6 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\logF603.tmp (3 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\gadEFD5.tmp (16 bytes)
%Program Files%\AVAST Software\Avast\aswF961.tmp (544 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs\proF1B8.tmp (60 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\tweF685.tmp (3 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\ReqF1A1.tmp (3 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\skin\oveF3B7.tmp (3 bytes)
C:\Windows\Temp\gui3EC4.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\creF4CA.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF51B.tmp (875 bytes)
%Program Files%\AVAST Software\Avast\Certificates\avaF86B.tmp (1 bytes)
C:\ProgramData\AVAST Software\Avast\sounds\1033\susF813.tmp (45 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\utiF066.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\uk\mesF49B.tmp (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_core-7f5.vpx.dld (440486 bytes)
%Program Files%\AVAST Software\Avast\aswF779.tmp (72 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_E46.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\asw10C8.tmp (488 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF25A.tmp (259 bytes)
%Program Files%\AVAST Software\Avast\OpenVPN\driver\win64\ndis6\addF0F2.tmp (126 bytes)
%Program Files%\AVAST Software\Avast\locales\am.FE90.tmp (19 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF564.tmp (367 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_E97.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF58B.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\fi\mesF326.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\phishing\phiF6BC.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\fwA1043.tmp (44 bytes)
%Program Files%\AVAST Software\Avast\setup\setup.ini.tmp (9 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5B8.tmp (260 bytes)
%Program Files%\AVAST Software\Avast\flash\amcF9B7.tmp (32 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\logF606.tmp (974 bytes)
%Program Files%\AVAST Software\Avast\flash\ammap\icons\bubF9CE.tmp (217 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F634.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_C89.tmp (21 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\cs\mesF3EC.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\BroEF6A.tmp (42 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ko\mesF34E.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\shoF720.tmp (322 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x86\msvFB6C.tmp (875 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\balF4B4.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2D5.tmp (557 bytes)
%Program Files%\AVAST Software\Avast\logF9F3.tmp (104 bytes)
%Program Files%\AVAST Software\Avast\Reg21.tmp (716 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_F20.tmp (392 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF550.tmp (726 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\abeF1A2.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\locales\it.FEF6.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\aswEF26.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_gen_gui-7d5.vpx (392 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF51C.tmp (144 bytes)
%Program Files%\AVAST Software\Avast\locales\ml.FF0C.tmp (34 bytes)
%Program Files%\AVAST Software\Avast\icuFBEF.tmp (780 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_cmp_swhealth-7f5.vpx.dld (24476 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x86\atlFB0B.tmp (164 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\blocker\bloF4C6.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\es\mesF314.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFFB7.tmp (364 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5CB.tmp (436 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF657.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\modules\UtiF3B2.tmp (8 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\pt_PT\mesF463.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\en_GB\mesF313.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_gen_crt_x86-7e3.vpx (392 bytes)
%Program Files%\AVAST Software\Avast\locales\sr.FF47.tmp (21 bytes)
%Program Files%\AVAST Software\Avast\setup (16 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_EE1.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\RescueDisk (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5B6.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\safeshop\cslF6C0.tmp (202 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\13.EF92.tmp (2 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameEF6E.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\hi\mesF427.tmp (18 bytes)
C:\Users\adm (8 bytes)
%Program Files%\AVAST Software\Avast\setup\iplugins-4.vpx (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content (288 bytes)
C:\ProgramData\AVAST Software\Avast\HtmlData\Blo9C.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\flash\ammap\icons\zooF9E2.tmp (198 bytes)
C:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\msvcp110.dll (1071 bytes)
%Program Files%\AVAST Software\Avast\OpenVPN\driver\win64\ndis6 (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2D6.tmp (679 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\2.gEF98.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icoF5CF.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\traF683.tmp (162 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFEE.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img (49 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\vi\mesF49D.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\setup\setFA20.tmp (5 bytes)
%Program Files%\AVAST Software\Avast\AvaF85B.tmp (343 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ja\mesF34D.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_F0D.tmp (221 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\logF5F2.tmp (801 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5CA.tmp (259 bytes)
%Program Files%\AVAST Software\Avast\asO44.tmp (415 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFDA.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\aswFA9.tmp (221 bytes)
%Program Files%\AVAST Software\Avast\setup\selfdefense_x86_ais-8aa.vpx (2321 bytes)
%Program Files%\AVAST Software\Avast\locales\vi.FF6E.tmp (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_streamfilter_x64-7f5.vpx.dld (3610 bytes)
%Program Files%\AVAST Software\Avast\OpenVPN\lzoF0DF.tmp (83 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\shoF6FD.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x86\msvFB5B.tmp (535 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_cmp_swhealth-7f5.vpx (1 bytes)
%Program Files%\AVAST Software\Avast\setup\avbugreport_ais-8aa.vpx (11518 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\11.EF80.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_EE9.tmp (995 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\bs.F1A3.tmp (11 bytes)
%Program Files%\AVAST Software\Avast\locales\pt-FF22.tmp (14 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFDB.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\setup\vps_32-1000.vpx (11077 bytes)
%Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFFFE.tmp (137 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F2BF.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\safeshop\safF6D1.tmp (15 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_E56.tmp (392 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5B5.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\phishing\phiF6BD.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\aswScan.dll (167 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF20A.tmp (227 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\sv\mesF38A.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\OpenVPN\libF0DE.tmp (65 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\safeshop\safF6D3.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\hu\mesF32B.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF65B.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF246.tmp (287 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\lodF6AA.tmp (223 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\extF4CB.tmp (59 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software\Avast Free Antivirus.lnk (1 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_gen_streamfilter_x64-7f5.vpx (137 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\sasF298.tmp (836 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_CCA.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\ashF8E2.tmp (645 bytes)
C:\ProgramData\AVAST Software\Avast\SecureLine\secF0F1.tmp (10 bytes)
C:\Windows\SoftwareDistribution\DataStore\Logs (4 bytes)
C:\ProgramData\AVAST Software\Avast\sounds\virFA1F.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2D7.tmp (653 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\1.gEF7E.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\temF732.tmp (18 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\logF604.tmp (7 bytes)
C:\ProgramData\AVAST Software\Avast\Fonts\RobFA09.tmp (141 bytes)
C:\Windows\winsxs\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396\mfc110u.dll (920 bytes)
C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log (884350 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2D4.tmp (556 bytes)
C:\Windows\System32\config\SYSTEM.LOG1 (18577 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\fa\mesF316.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\setup\setgui_ais-8aa.vpx (22575 bytes)
%Program Files%\AVAST Software\Avast\setup\offertool_ais-8aa.vpx (23811 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 (4 bytes)
C:\Windows\winsxs\Manifests\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.manifest (2 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\butEFC3.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\Pus1044.tmp (664 bytes)
%Program Files%\AVAST Software\Avast\locales\ms.FF0E.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF659.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\mesF3A2.tmp (2 bytes)
C:\Windows\Prefetch\REGSVR32.EXE-55A4EE79.pf (28 bytes)
%Program Files%\AVAST Software\Avast\setup\instup_ais-8aa.vpx (66235 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ar\mesF3C8.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\avH20.tmp (409 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x64\msvFAE6.tmp (849 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF51D.tmp (182 bytes)
%Program Files%\AVAST Software\Avast\setup\selfdefense_x64_ais-8aa.vpx (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\Instup.dll (1746 bytes)
%Program Files%\AVAST Software\Avast\asuF12C.tmp (88 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2C0.tmp (909 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\logF281.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\CrtFAF6.tmp (54 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_C87.tmp (19 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\en\mesF302.tmp (14 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\logF26E.tmp (5 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\logF270.tmp (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (4 bytes)
%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\gth.dll (40 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2C1.tmp (812 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\logF283.tmp (503 bytes)
%Program Files%\AVAST Software\Avast\WebRep\Chrome\AswF18D.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x86\PolFB0A.tmp (608 bytes)
C:\ProgramData\AVAST Software\Avast\sounds\1033\virF815.tmp (40 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\7.gEFAD.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icoF5CD.tmp (12 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFF1.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\flash\ammap\ammF9CA.tmp (3 bytes)
C:\Windows\System32\drivers\aswSP.sys (2321 bytes)
%Program Files%\AVAST Software\Avast\locales\fr.FEE0.tmp (15 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\lisF86.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\pl\mesF451.tmp (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_dll_eng-7f5.vpx.dld (25252 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\sr\mesF389.tmp (12 bytes)
%Program Files% (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (258 bytes)
%Program Files%\AVAST Software\Avast\RescueDisk\AvaF0A8.tmp (478 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\insF5F0.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\aswCmnIS.dll (438 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\shoF6FC.tmp (322 bytes)
%Program Files%\AVAST Software\Avast\setup\CRT\x64\msvFAE5.tmp (661 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF506.tmp (358 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF578.tmp (5 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\balF1D0.tmp (94 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales (4 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\gadEF6D.tmp (886 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\hi\mesF329.tmp (18 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\lis1068.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\en_GB\mesF410.tmp (11 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\BCU1013.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\RescueDisk\waiF0DD.tmp (3 bytes)
C:\ProgramData\AVAST Software\Avast\avaFA1B.tmp (5 bytes)
%Program Files%\AVAST Software\Avast\locales\ta.FF59.tmp (32 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF682.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\logF605.tmp (503 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\insF3B6.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\Certificates\digF86C.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\RescueDisk\BasF0B9.tmp (63 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_F53.tmp (1 bytes)
C:\Windows\AppCompat\Programs\RecentFileCache.bcf (200 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\4.gEFAA.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\pl\mesF363.tmp (12 bytes)
C:\ProgramData\AVAST Software\Avast (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_streamfilter-7f5.vpx.dld (11832 bytes)
%Program Files%\AVAST Software\Avast\locales\zh-FF70.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF507.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\setup\ais_gen_tools-7e2.vpx (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\shoF6FB.tmp (318 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\logF282.tmp (801 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_bhv.map (424 bytes)
%Program Files%\AVAST Software\Avast\ash65.tmp (441 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\greF4F2.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF20B.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\th\mesF479.tmp (19 bytes)
%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\Readme.url (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF552.tmp (646 bytes)
C:\Windows\System32\drivers\aswSnx.sys (7385 bytes)
%Program Files%\AVAST Software\Avast\aswF7D9.tmp (85 bytes)
%Program Files%\AVAST Software\Avast\cefFBCC.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF4F3.tmp (357 bytes)
%Program Files%\AVAST Software\Avast\locales\da.FEB5.tmp (13 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\el\mesF301.tmp (16 bytes)
%Program Files%\AVAST Software\Avast\WebRep\Chrome\AswF18E.tmp (295 bytes)
%Program Files%\AVAST Software\Avast\locales\hi.FEE3.tmp (26 bytes)
%Program Files% (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (196 bytes)
C:\Windows\System32 (480 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\jquF698.tmp (93 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ro\mesF376.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\avBEF05.tmp (11518 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_EE0.tmp (5 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\logF271.tmp (7 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_F54.tmp (392 bytes)
%Program Files%\AVAST Software\Avast\aswF918.tmp (311 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\12.EF81.tmp (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\mocks\omnF4B3.tmp (770 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\avaEF6B.tmp (7 bytes)
%Program Files%\AVAST Software\Avast\libFF72.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF645.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\locales\pl.FF20.tmp (14 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\6.gEFAC.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\sasF61A.tmp (307 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\seaF6E7.tmp (341 bytes)
%Program Files%\AVAST Software\Avast\1033 (4 bytes)
%Program Files%\AVAST Software\Avast\aswF973.tmp (22 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F2BE.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\vps_win32-100f.vpx.dld (257579 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_F0F.tmp (20 bytes)
%Program Files%\AVAST Software\Avast\AhR42.tmp (118 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs\eveF1A5.tmp (16 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\hr\mesF32A.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF51A.tmp (470 bytes)
%Program Files%\AVAST Software\Avast\locales\en-FEB9.tmp (12 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFEF.tmp (1 bytes)
%Program Files%\AVAST Software\Avast\RescueDisk\aswF0BB.tmp (76 bytes)
%Program Files%\AVAST Software\Avast\setup\ngiodriver_x86_ais-8aa.vpx (17 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF658.tmp (862 bytes)
C:\ProgramData\AVAST Software\Avast\sounds\1033 (4 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\bg\mesF3CA.tmp (14 bytes)
C:\Windows\Installer (8 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\safeshop\safF6D0.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_res-7f5.vpx.dld (71340 bytes)
%Program Files%\AVAST Software\Avast\BCUEF49.tmp (643 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF65A.tmp (559 bytes)
C:\Users\Public\Documents (4 bytes)
C:\ProgramData\AVAST Software\Avast\Fonts\RobFA0A.tmp (140 bytes)
C:\Windows\System32\drivers\aswStm.sys (673 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs\cslF1A4.tmp (202 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\18.EF97.tmp (2 bytes)
%Program Files%\AVAST Software\Avast\aswF916.tmp (81 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\db_C76.tmp (233 bytes)
%Program Files%\AVAST Software\Avast\cefFBDE.tmp (580 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\avaF4DE.tmp (4 bytes)
%Program Files%\AVAST Software\Avast\AavF838.tmp (291 bytes)
%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\indF065.tmp (25 bytes)
C:\Windows\winsxs\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.cat (9 bytes)
%Program Files%\AVAST Software\Avast\WebRep\IE\_locales\nl\mesF450.tmp (12 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2C2.tmp (862 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301\Sf1F88.tmp (96 bytes)
%Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\imgF26D.tmp (17 bytes)

The process instup.exe:4084 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log (10438 bytes)

The process instup.exe:3784 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log (10438 bytes)

The process instup.exe:2812 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x64_ais-89e.vpx (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x64_ais-8a7-8a6.vpx.dld (257 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\servers.def.vpx.dld (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instcont_ais-8aa-8a7.vpx.dld (1921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\selfdefense_x86_ais-8aa.vpx (427 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instcont_ais-8a7-8a6.vpx.dld (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x64_ais-8a0-89e.vpx.dld (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avbugreport_ais-8a7-8a6.vpx.dld (3949 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instcont_ais-8aa.vpx (598 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup_ais-8a7-8a6.vpx.dld (25237 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\setgui_ais-8a6-8a0.vpx.dld (17620 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x86_ais-8aa-8a7.vpx.dld (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instcont_ais-8a6-8a0.vpx.dld (9216 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\avBugReport.exe (11518 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avbugreport_ais-8aa.vpx (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup_ais-8aa.vpx (780 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\prod-ais.vpx.dld (356 bytes)
C:\Windows\System32 (468 bytes)
C:\ (96 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\servers.def (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\setgui_ais-8aa.vpx (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\instup.exe (4787 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\setgui_ais-8a7-8a6.vpx.dld (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avbugreport_ais-89e.vpx (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x64_ais-8aa-8a7.vpx.dld (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\Instup.dll (1358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-vps_win32-15042301.vpx.dld (214 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup_ais-89e.vpx (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\selfdefense_x64_ais-8aa.vpx.dld (13107 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\aswSetupConfig.ini (758 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avbugreport_ais-8a0-89e.vpx.dld (3918 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avbugreport_ais-8a6-8a0.vpx.dld (16591 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\prod-vps.vpx.dld (450 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\setgui_ais-8aa-8a7.vpx.dld (214 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\HTMLayout.dll (22575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\setgui_ais-8a0-89e.vpx.dld (6233 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x86_ais-8a7-8a6.vpx.dld (256 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x86_ais-8a6-8a0.vpx.dld (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x86_ais-8aa.vpx (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\offertool_ais-8aa.vpx (3 bytes)
C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log (47434 bytes)
C:\Windows\System32\config\SYSTEM.LOG1 (4459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\selfdefense_x86_ais-8aa.vpx.dld (11031 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\aswOfferTool.exe (23811 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\setgui_ais-89e.vpx (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup_ais-8a0-89e.vpx.dld (12133 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup_ais-8a6-8a0.vpx.dld (52071 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x86_ais-89e.vpx (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instcont_ais-89e.vpx (204 bytes)
C:\Windows\System32\config\SYSTEM (3235 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x64_ais-8a6-8a0.vpx.dld (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-jrog2-d50.vpx.dld (903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup_ais-8aa-8a7.vpx.dld (26477 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-iex-4.vpx.dld (232 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-setup_ais-8aa.vpx.dld (3166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x64_ais-8aa.vpx (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\servers.def.lkg (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-prg_ais-8aa.vpx.dld (1344 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instcont_ais-8a0-89e.vpx.dld (2 bytes)
C:\Windows (192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x86_ais-8a0-89e.vpx.dld (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\offertool_ais-8aa.vpx.dld (55822 bytes)
C:\$Directory (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avbugreport_ais-8aa-8a7.vpx.dld (10493 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\Instup.dll (66235 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\selfdefense_x64_ais-8aa.vpx (442 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\HTMLayout.dll (291 bytes)

The process instup.exe:3376 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log (10438 bytes)

The process instup.exe:3756 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log (10718 bytes)

The process instup.exe:3584 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log (10438 bytes)

The process instup.exe:3708 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log (10438 bytes)

The process instup.exe:3412 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log (10438 bytes)

The process instup.exe:4012 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log (10438 bytes)

The process instup.exe:3368 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log (10438 bytes)

The process instup.exe:3296 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log (10438 bytes)

The process instup.exe:3176 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log (11350 bytes)

The process SearchWithGoogleUpdate_6F4EEAE8D7FCDAD8.exe:1368 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\gtn.dll (144 bytes)
%Program Files% (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (79 bytes)
%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\gth.dll (40 bytes)
%Program Files%\Google\GoogleToolbarNotifier\5.10.11023.1534\swg64.dll (298 bytes)
%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll (981 bytes)
%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\Readme.url (212 bytes)

The process AvastSvc.exe:832 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000085.bin (320 bytes)
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\45781A86D7D79A4E3FE6F4DF8CDF171D_E0B7CDE0B6AB7ABECB214E5A7A028B64 (1520 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000006e.bin (228 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000030.bin (275 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000014.bin (342 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000004.bin (9 bytes)
C:\ProgramData\AVAST Software\Avast\log\StreamFilter.log (4230 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000007d.bin (315 bytes)
C:\ProgramData\AVAST Software\Avast\wscert.der (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000098.bin (551 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000031.bin (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000002f.bin (6 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000033.bin (177 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000050.bin (615 bytes)
C:\ProgramData\AVAST Software\Avast\URL.db (528641 bytes)
C:\ProgramData\AVAST Software\Avast\log\softwarehealth.log (57 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg15042302000000a0.bin (177 bytes)
C:\ProgramData\AVAST Software\Avast\report\WebShield.txt (138 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000052.bin (167 bytes)
C:\Windows\TEMP\_avast_\ws09CDCBC8.dat (944 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000088.bin (164 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000051.bin (4 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000007a.bin (177 bytes)
C:\ProgramData\AVAST Software\Avast\log\Grimefighter.log (1382 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000008c.bin (4 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000005d.bin (183 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg15042302000000a3.bin (164 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000087.bin (2 bytes)
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\edebdb5e5c006a3a2136a47fd2342bbe_c0322acd-5e5d-42f0-b163-c591ee6ff5b9 (102 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000005.bin (843 bytes)
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A92F33496848CFF4F115ED04BCDD933A_6C14F82F698E40985D569864739DB21B (1 bytes)
C:\ProgramData\AVAST Software\Avast\snx_lconfig.xml (4814 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000001e.bin (5 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000009f.bin (264 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000026.bin (9 bytes)
C:\snx_rhive{316f7b84-deb2-11e4-b648-005056210174}.TM.blf (2654 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000039.bin (155 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000025.bin (294 bytes)
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bb87d795d8de56e15dd2d7704498f1b8_c0322acd-5e5d-42f0-b163-c591ee6ff5b9 (102 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000016.bin (209 bytes)
C:\ProgramData\AVAST Software\Avast\report\FileSystemShield.txt (138 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000093.bin (4 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000000e.bin (183 bytes)
C:\snx_rhive{316f7b84-deb2-11e4-b648-005056210174}.TMContainer00000000000000000002.regtrans-ms (712 bytes)
C:\ProgramData\AVAST Software\Avast\log\Mail.log (4429 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000078.bin (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000044.bin (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000006.bin (459 bytes)
C:\ProgramData\AVAST Software\Avast\log\AvastSvc.log (31420 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000068.bin (272 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000006c.bin (198 bytes)
C:\ProgramData\AVAST Software\Avast\log\SecureLine.log (1070 bytes)
C:\snx_rhive{316f7b84-deb2-11e4-b648-005056210174}.TMContainer00000000000000000001.regtrans-ms (1224 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000003d.bin (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000055.bin (3 bytes)
C:\Windows\TEMP\_avast_\ws0A47E810.dat (1111 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000057.bin (186 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000073.bin (3 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000004c.bin (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000072.bin (183 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000079.bin (130 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000009a.bin (189 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000049.bin (448 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000036.bin (924 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000011.bin (283 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000005b.bin (859 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000083.bin (6 bytes)
C:\ProgramData\AVAST Software\Avast\SecureLine\client.ovpn (187 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000006f.bin (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000002e.bin (243 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000037.bin (169 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000002d.bin (347 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000010.bin (7 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000099.bin (6 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000096.bin (130 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000021.bin (203 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000006.bin (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000038.bin (3 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000008f.bin (8 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000007f.bin (222 bytes)
C:\ProgramData\AVAST Software\Avast\Log.db (233646 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000007c.bin (153 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000043.bin (1 bytes)
C:\snx_rhive (1123 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000013.bin (166 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000003.bin (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000004f.bin (168 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000070.bin (158 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000028.bin (9 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000022.bin (9 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000006a.bin (3 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000004e.bin (241 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000003e.bin (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000001c.bin (479 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000047.bin (286 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000005a.bin (3 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000000.bin (155 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000002b.bin (5 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000086.bin (293 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000089.bin (8 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000097.bin (804 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000008.bin (6 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg15042302000000a2.bin (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000058.bin (581 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000065.bin (188 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000009b.bin (179 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000032.bin (312 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000067.bin (3 bytes)
C:\ProgramData\AVAST Software\Avast\log\StreamingUpdate.log (125 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000095.bin (217 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000001.bin (375 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000004d.bin (604 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000054.bin (303 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000008b.bin (8 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000066.bin (747 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000009.bin (184 bytes)
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\45781A86D7D79A4E3FE6F4DF8CDF171D_E0B7CDE0B6AB7ABECB214E5A7A028B64 (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000077.bin (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000041.bin (1 bytes)
C:\ProgramData\AVAST Software\Avast\spool\suspic\{5A3F9B39-FD0E-4314-AA1E-7F3588216579}.suspic (5222 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000001d.bin (9 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000027.bin (9 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000000c.bin (4 bytes)
C:\ProgramData\AVAST Software\Avast\FileInfo2.db (2788 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000008.bin (161 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000001a.bin (6 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000040.bin (5 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000000a.bin (240 bytes)
C:\ProgramData\AVAST Software\Avast\journal\journal13B15994 (125988 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000042.bin (897 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000000b.bin (142 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000076.bin (332 bytes)
C:\ProgramData\AVAST Software\Avast\chest\index.xml (116 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000060.bin (217 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000007.bin (225 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000012.bin (309 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000009d.bin (215 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000059.bin (199 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000084.bin (226 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000005f.bin (207 bytes)
C:\ProgramData\AVAST Software\Avast\avast5.ini (1113152 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000003b.bin (840 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000003.bin (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000075.bin (594 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000069.bin (710 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000009e.bin (4 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000009.bin (131 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000002a.bin (9 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000056.bin (190 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000004.bin (9 bytes)
C:\ProgramData\AVAST Software\Avast\log\Resident.log (41 bytes)
C:\ProgramData\AVAST Software\Avast\db_storage.dat (16 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000034.bin (5 bytes)
C:\ProgramData\AVAST Software\Avast\report\EmailShield.txt (138 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000090.bin (8 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000005e.bin (3 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000007e.bin (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000003f.bin (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000024.bin (654 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000007.bin (141 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000017.bin (283 bytes)
C:\Windows\TEMP\_avast_\ws09CDC998.dat (319 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000000d.bin (233 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000000f.bin (280 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000094.bin (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000006b.bin (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg15042302000000a4.bin (337 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000018.bin (181 bytes)
C:\ProgramData\AVAST Software\Avast\log\EventLog.log (992 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000008e.bin (234 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg15042302000000a1.bin (131 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000004a.bin (135 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000009c.bin (130 bytes)
C:\ProgramData\AVAST Software\Avast\log\autosandbox.log (1496 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000035.bin (198 bytes)
C:\Windows\TEMP\_avast_\ws09CDCAB0.dat (556 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000001b.bin (157 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000063.bin (5 bytes)
C:\ProgramData\AVAST Software\Avast\spool\suspic\{B93E86A2-4ED7-45BD-8692-45349ACB8CE1}.suspic (4170 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000007b.bin (6 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000001.bin (4 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000053.bin (226 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000004b.bin (381 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000002.bin (8 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000001f.bin (7 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000062.bin (273 bytes)
C:\Windows\TEMP\GeoInfo.tmp (135 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000003a.bin (308 bytes)
C:\ProgramData\AVAST Software\Avast\log\Chest.log (34 bytes)
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4de477a8df4f16d076ef8dbe12e0bb46_c0322acd-5e5d-42f0-b163-c591ee6ff5b9 (102 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000003c.bin (3 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000046.bin (199 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000080.bin (271 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000019.bin (290 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000061.bin (766 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000074.bin (157 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000082.bin (3 bytes)
C:\snx_rhive.LOG1 (1048 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000023.bin (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000005c.bin (204 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000064.bin (225 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000002c.bin (1 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000081.bin (240 bytes)
%Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000005.bin (1 bytes)
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A92F33496848CFF4F115ED04BCDD933A_6C14F82F698E40985D569864739DB21B (1520 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000020.bin (412 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000048.bin (3 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000002.bin (7 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000071.bin (921 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000006d.bin (461 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000092.bin (8 bytes)
C:\ProgramData\AVAST Software\Avast\exclusions.ini (210 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000008d.bin (148 bytes)
%Program Files%\AVAST Software\Avast\Setup\config.def.new (100 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000045.bin (931 bytes)
C:\ProgramData\AVAST Software\Avast\log\CommChannel.Protocol.log (2 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000029.bin (3 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000008a.bin (8 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000015.bin (5 bytes)
%Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000091.bin (8 bytes)

The process avBugReport.exe:836 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Avast\log\BugReport.log (2 bytes)

The process aswRunDll.exe:1760 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log (372 bytes)

The process aswRunDll.exe:3820 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log (606 bytes)

The process keytool.exe:3472 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\PROGRAM FILES (X86)\Java\jre6\lib\security\cacerts (445925 bytes)

The process regsvr32.exe:1636 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\Google\GoogleToolbarNotifier\5.10.11023.1534\swg64.dll (299 bytes)

The process %original file name%.exe:1824 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn935F.tmp (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup___.exe (356166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\NSISdl14.dll (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\ButtonEvent.dll (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx485A.tmp (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\modern-wizard.bmp (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MPBSETUP.EXE (5597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\NSISdl.dll (2202 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\logo.bmp (1568 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\System.dll (47 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsh190D.tmp (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\mypcbackup_image.bmp (1568 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss1BBD.tmp (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsm1CD6.tmp (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\ThreadTimer.dll (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\nsDialogs.dll (23 bytes)

The process BackupSetup.exe:536 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\OLBPre\es_ES.mo (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\nsExec.dll (14 bytes)
%Program Files% (x86)\OLBPre\pt_PT.mo (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\Desktop\MyPC Backup.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\AccessControl.dll (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\nsSCM.dll (13 bytes)
%Program Files% (x86)\OLBPre\it_IT.mo (1856 bytes)
%Program Files% (x86)\OLBPre\de_DE.mo (1856 bytes)
%Program Files% (x86)\OLBPre\fr_FR.mo (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\nsRandom.dll (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn8382.tmp (52076 bytes)
%Program Files% (x86)\OLBPre\OLBPre.exe.config (203 bytes)
%Program Files% (x86)\OLBPre\OLBPre.exe (35833 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\DotNetChecker.dll (1597 bytes)
%Program Files% (x86)\OLBPre\brand.jdat (17848 bytes)
%Program Files% (x86)\OLBPre\uninst.exe (1026 bytes)
%Program Files% (x86)\OLBPre\LinqBridge.dll (1856 bytes)

The process 9fc49b8a-7b2d-463c-978b-474af67c44b7.exe:2792 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aeu64AC.tmp.dld (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aeu5DF7.tmp.dld (35 bytes)

The process AvastEmUpdate.exe:2412 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\AVAST Software\Avast\setup\45db3fb7-4838-48e8-8387-b5bc4e296450.xml (11 bytes)
C:\ProgramData\AVAST Software\Avast\AvastEmUpdate.ini (34 bytes)
%Program Files%\AVAST Software\Avast\setup\f250f4e7-9d83-458a-8282-b8a5853969a0.ini (4 bytes)
%Program Files%\AVAST Software\Avast\setup\9fc49b8a-7b2d-463c-978b-474af67c44b7.exe (1255 bytes)

The process GoogleToolbarManager_BA9226F4C70BECC2.exe:2636 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\Google\Custom Buttons\toolbar.google.com_O8Y91YHB24Z6SR0SGYSK.XML (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GoogleToolbarInstaller1.log (3169 bytes)

The process GoogleToolbarManager_BA9226F4C70BECC2.exe:2412 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GoogleToolbarInstaller1.log (2410 bytes)

The process GoogleToolbarManager_BA9226F4C70BECC2.exe:2064 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (1281 bytes)
%Program Files% (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (673 bytes)
%Program Files% (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GoogleToolbarInstaller1.log (41490 bytes)
%Program Files% (x86)\Google\Google Toolbar\GoogleToolbarHelper_signed.msi (28 bytes)
%Program Files% (x86)\Google\Google Toolbar\GoogleToolbarUser_64.exe (2321 bytes)
%Program Files% (x86)\Google\Google Toolbar\GoogleToolbarHelperPatch_signed.msp (125 bytes)

Registry activity

The process GoogleUpdate.exe:1176 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"usagestats" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"uid"
"old-uid"
"eulaaccepted"

The process GoogleUpdate.exe:2424 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Google\Update\proxy]
"source" = "IEWPAD"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"uid"
"old-uid"

The process GoogleUpdate.exe:2556 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Google\Update\proxy]
"source" = "auto"

[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\42857855FB0EA43F54C9911E30E7791D8CE82705]
"Blob" = "14 00 00 00 01 00 00 00 14 00 00 00 50 EA 73 89"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"uid"
"old-uid"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates]
"42857855FB0EA43F54C9911E30E7791D8CE82705"

The process GoogleUpdate.exe:1856 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"usagestats" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"uid"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"UpdateAvailableSince"
"UpdateAvailableCount"

[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"eulaaccepted"

[HKCU\Software\Google\Update]
"old-uid"

[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"old-uid"

[HKCU\Software\Google\Update]
"uid"

The process GoogleUpdate.exe:1932 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"DayOfLastActivity" = "4294967295"
"usagestats" = "0"
"pv" = "7.5.6227.252"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\CurrentState]
"InstallProgressPercent" = "4294967295"
"StateValue" = "3"
"DownloadTimeRemainingMs" = "4294967295"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"LastCheckSuccess" = "1429869683"

[HKCU\Software\Google\Update\proxy]
"source" = "IEWPAD"

[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"DayOfInstall" = "3035"
"InstallTime" = "1429869677"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\CurrentState]
"InstallTimeRemainingMs" = "4294967295"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"DayOfLastRollCall" = "4294967295"
"brand" = "AVNH"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\CurrentState]
"DownloadProgressPercent" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"LastInstallerExtraCode1"
"LastInstallerSuccessLaunchCmdLine"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientStateMedium\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"eulaaccepted"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"UpdateAvailableCount"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientStateMedium\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"usagestats"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"ap"

[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"LastInstallerResult"
"old-uid"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"iid"

[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"uid"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"LastInstallerResult"

[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"LastInstallerResultUIString"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"eulaaccepted"
"UpdateAvailableSince"
"LastInstallerError"
"LastInstallerResultUIString"
"experiment_labels"
"tttoken"

[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"LastInstallerError"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"browser"
"LastInstallerExtraCode1"
"LastInstallerSuccessLaunchCmdLine"

The process GoogleUpdaterService_B33FC4DD36A473C6.exe:1412 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Common\Google Updater\apps\tbie]
"auto" = "0"

[HKLM\SOFTWARE\Wow6432Node\Google\Common\Google Updater]
"Path" = "%Program Files% (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe"
"Version" = "2.4.2617.4952"

The process aswOfferTool.exe:304 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\GCAPITemp]
"test" = "te}"

The Trojan deletes the following registry key(s):

[HKLM\SOFTWARE\Wow6432Node\Google\GCAPITemp]

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\GCAPITemp]
"test"

The process aswOfferTool.exe:2784 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar]
"test" = "test"

[HKLM\SOFTWARE\Wow6432Node\Google\No Toolbar Offer Until]
"Avast Software s.r.o." = "20151024"

The Trojan deletes the following registry key(s):

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar]

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar]
"test"

[HKLM\SOFTWARE\Wow6432Node\Google\No Toolbar Offer Until]
"Avast Software s.r.o."

The process GoogleToolbarNotifier.exe:2468 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\ProtectorExe.ProtectorHost.1\CLSID]
"(Default)" = "{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}"

[HKCR\Wow6432Node\Interface\{F1A383D4-0364-4092-82E0-C39DAE5D801D}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AF606610-3627-4DF2-A6D5-32C6A355ACD1}\TypeLib]
"Version" = "1a.0"

[HKCR\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}]
"(Default)" = "IProtectorLib7"

[HKCR\Wow6432Node\Interface\{91959FBB-853A-4AC7-A082-2DDF787F4CA9}\TypeLib]
"Version" = "1a.0"

[HKCR\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}]
"(Default)" = "IProtector11"

[HKCR\Interface\{F1A383D4-0364-4092-82E0-C39DAE5D801D}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{F1A383D4-0364-4092-82E0-C39DAE5D801D}\TypeLib]
"Version" = "1a.0"

[HKCR\Interface\{2212951C-1623-4095-906B-AC50B8F91016}]
"(Default)" = "IProtector2"

[HKCR\Interface\{480AD54B-C652-44B9-BCF6-746745055CD3}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\InprocServer32]
"(Default)" = "%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll"

[HKCR\Wow6432Node\Interface\{1F7328B7-E25A-4527-B24B-D9173401BB89}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{AF606610-3627-4DF2-A6D5-32C6A355ACD1}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{AF606610-3627-4DF2-A6D5-32C6A355ACD1}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}]
"(Default)" = "IProtector8"

[HKCR\Wow6432Node\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{2351B346-00E8-4EAC-9B75-B138B465D659}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}]
"(Default)" = "IProtector6"

[HKCR\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}\TypeLib]
"Version" = "1a.0"

[HKCR\Interface\{91959FBB-853A-4AC7-A082-2DDF787F4CA9}]
"(Default)" = "IProtectorHost2"

[HKCR\Wow6432Node\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\ProgID]
"(Default)" = "protector_dll.ProtectorLib.1"

[HKCR\Interface\{91959FBB-853A-4AC7-A082-2DDF787F4CA9}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}\TypeLib]
"Version" = "1a.0"

[HKCR\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{AF606610-3627-4DF2-A6D5-32C6A355ACD1}]
"(Default)" = "IProtectorLib"

[HKCR\Wow6432Node\Interface\{6C110376-C248-47F6-9DB2-CFCDEADB6A3E}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{2212951C-1623-4095-906B-AC50B8F91016}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{6C110376-C248-47F6-9DB2-CFCDEADB6A3E}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}]
"(Default)" = "IProtector3"

[HKCR\Interface\{DA69D3CC-7676-4A65-889F-C052977F1AA9}\TypeLib]
"Version" = "1a.0"

[HKCR\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\1a.0]
"(Default)" = "protector_dllLib"

[HKCR\Interface\{480AD54B-C652-44B9-BCF6-746745055CD3}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{2212951C-1623-4095-906B-AC50B8F91016}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\AppID\{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}]
"(Default)" = "protector_dll"

[HKCR\Interface\{277FD1E8-9884-4E0A-9392-7CFF83F067B2}]
"(Default)" = "IProtector9"

[HKCR\Interface\{2212951C-1623-4095-906B-AC50B8F91016}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\AppID\{A97CA128-6998-4F8E-807E-8ED05FADAFB0}]
"(Default)" = "ProtectorExe"

[HKCR\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}]
"(Default)" = "IProtectorLib8"

[HKCR\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}]
"(Default)" = "IProtectorLib8"

[HKCR\Wow6432Node\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
"(Default)" = "Google Toolbar Notifier BHO"

[HKCR\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{A0CF48B9-DB91-49A5-BEE7-2FB45BA2F610}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{9891812B-5820-4A77-827E-772B200239E1}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}]
"AppID" = "{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{80B84A0A-EDA4-47fd-8BE1-6B49F4197EE5}]
"AppPath" = "%Program Files% (x86)\Google\GoogleToolbarNotifier"

[HKCR\Wow6432Node\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}]
"(Default)" = "IProtectorLib7"

[HKCR\protector_dll.ProtectorLib.1]
"(Default)" = "ProtectorLib Class"

[HKCR\Wow6432Node\Interface\{9891812B-5820-4A77-827E-772B200239E1}]
"(Default)" = "IProtector4"

[HKCR\Wow6432Node\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}]
"Depend" = "%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\gtn.dll"

[HKCR\Wow6432Node\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}]
"(Default)" = "ProtectorLib Class"

[HKCR\Wow6432Node\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}\TypeLib]
"Version" = "1a.0"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{80B84A0A-EDA4-47fd-8BE1-6B49F4197EE5}]
"AppName" = "GoogleToolbarNotifier.exe"

[HKCR\Wow6432Node\Interface\{1F7328B7-E25A-4527-B24B-D9173401BB89}]
"(Default)" = "IProtector5"

[HKCR\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}]
"(Default)" = "IProtectorLib5"

[HKCR\Wow6432Node\Interface\{9891812B-5820-4A77-827E-772B200239E1}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{2212951C-1623-4095-906B-AC50B8F91016}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{9891812B-5820-4A77-827E-772B200239E1}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{A0CF48B9-DB91-49A5-BEE7-2FB45BA2F610}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{1F7328B7-E25A-4527-B24B-D9173401BB89}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}]
"(Default)" = "ProtectorHost Class"

[HKCR\Interface\{9891812B-5820-4A77-827E-772B200239E1}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{DA69D3CC-7676-4A65-889F-C052977F1AA9}]
"(Default)" = "IProtectorHost"

[HKCR\Wow6432Node\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}\InprocServer32]
"(Default)" = "%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll"

[HKCR\Interface\{6C110376-C248-47F6-9DB2-CFCDEADB6A3E}]
"(Default)" = "IProtector10"

[HKCR\Wow6432Node\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\Interface\{A0CF48B9-DB91-49A5-BEE7-2FB45BA2F610}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{F1A383D4-0364-4092-82E0-C39DAE5D801D}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\VersionIndependentProgID]
"(Default)" = "protector_dll.ProtectorBho"

[HKCR\Wow6432Node\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{6C110376-C248-47F6-9DB2-CFCDEADB6A3E}]
"(Default)" = "IProtector10"

[HKCR\Wow6432Node\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\ProgID]
"(Default)" = "ProtectorExe.ProtectorHost.1"

[HKCR\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{91959FBB-853A-4AC7-A082-2DDF787F4CA9}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{2351B346-00E8-4EAC-9B75-B138B465D659}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{DA69D3CC-7676-4A65-889F-C052977F1AA9}\TypeLib]
"Version" = "1a.0"

[HKCR\protector_dll.ProtectorLib\CurVer]
"(Default)" = "protector_dll.ProtectorLib.1"

[HKCR\Interface\{91959FBB-853A-4AC7-A082-2DDF787F4CA9}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{9891812B-5820-4A77-827E-772B200239E1}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{2212951C-1623-4095-906B-AC50B8F91016}]
"(Default)" = "IProtector2"

[HKCR\Interface\{1F7328B7-E25A-4527-B24B-D9173401BB89}]
"(Default)" = "IProtector5"

[HKCR\Interface\{6C110376-C248-47F6-9DB2-CFCDEADB6A3E}\TypeLib]
"Version" = "1a.0"

[HKCR\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{6C110376-C248-47F6-9DB2-CFCDEADB6A3E}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}\TypeLib]
"Version" = "1a.0"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{80B84A0A-EDA4-47fd-8BE1-6B49F4197EE5}]
"AppPath" = "%Program Files% (x86)\Google\GoogleToolbarNotifier"

[HKCR\Interface\{DA69D3CC-7676-4A65-889F-C052977F1AA9}]
"(Default)" = "IProtectorHost"

[HKCR\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}]
"(Default)" = "IProtector3"

[HKCR\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\AppID\ProtectorExe.EXE]
"AppID" = "{A97CA128-6998-4F8E-807E-8ED05FADAFB0}"

[HKCR\Wow6432Node\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
"AppID" = "{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}"

[HKCR\protector_dll.Protector.1\CLSID]
"(Default)" = "{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}"

[HKCR\ProtectorExe.ProtectorHost\CLSID]
"(Default)" = "{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}"

[HKCR\protector_dll.ProtectorBho]
"(Default)" = "Google Toolbar Notifier BHO"

[HKCR\Wow6432Node\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\AppID\protector_dll.DLL]
"AppID" = "{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}"

[HKCR\Interface\{91959FBB-853A-4AC7-A082-2DDF787F4CA9}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{DA69D3CC-7676-4A65-889F-C052977F1AA9}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{A0CF48B9-DB91-49A5-BEE7-2FB45BA2F610}]
"(Default)" = "IProtectorLib2"

[HKCR\Interface\{F1A383D4-0364-4092-82E0-C39DAE5D801D}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}\ProgID]
"(Default)" = "protector_dll.Protector.1"

[HKCR\Wow6432Node\Interface\{1F7328B7-E25A-4527-B24B-D9173401BB89}\TypeLib]
"Version" = "1a.0"

[HKCR\Interface\{2212951C-1623-4095-906B-AC50B8F91016}\TypeLib]
"Version" = "1a.0"

[HKCR\Interface\{480AD54B-C652-44B9-BCF6-746745055CD3}]
"(Default)" = "IProtectorLib6"

[HKCR\protector_dll.Protector\CLSID]
"(Default)" = "{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}"

[HKCR\Wow6432Node\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\VersionIndependentProgID]
"(Default)" = "ProtectorExe.ProtectorHost"

[HKCR\Wow6432Node\Interface\{2212951C-1623-4095-906B-AC50B8F91016}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}]
"(Default)" = "IProtector7"

[HKCR\Wow6432Node\Interface\{2351B346-00E8-4EAC-9B75-B138B465D659}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\ProtectorExe.ProtectorHost]
"(Default)" = "ProtectorHost Class"

[HKCR\Wow6432Node\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{9891812B-5820-4A77-827E-772B200239E1}]
"(Default)" = "IProtector4"

[HKCR\Wow6432Node\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\protector_dll.ProtectorBho.1\CLSID]
"(Default)" = "{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}"

[HKCR\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\1a.0\HELPDIR]
"(Default)" = "%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534"

[HKCR\Wow6432Node\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\protector_dll.ProtectorBho.1]
"(Default)" = "Google Toolbar Notifier BHO"

[HKCR\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}]
"(Default)" = "IProtectorLib3"

[HKCR\Wow6432Node\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\VersionIndependentProgID]
"(Default)" = "protector_dll.ProtectorLib"

[HKCR\Wow6432Node\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}]
"(Default)" = "IProtector11"

[HKCR\Wow6432Node\Interface\{F1A383D4-0364-4092-82E0-C39DAE5D801D}]
"(Default)" = "IProtector12"

[HKCR\Wow6432Node\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\1a.0\FLAGS]
"(Default)" = "0"

[HKCR\Wow6432Node\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}\VersionIndependentProgID]
"(Default)" = "protector_dll.Protector"

[HKCR\Interface\{AF606610-3627-4DF2-A6D5-32C6A355ACD1}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{277FD1E8-9884-4E0A-9392-7CFF83F067B2}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{A0CF48B9-DB91-49A5-BEE7-2FB45BA2F610}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ProgID]
"(Default)" = "protector_dll.ProtectorBho.1"

[HKCR\protector_dll.ProtectorLib.1\CLSID]
"(Default)" = "{84798B8E-69F8-4846-9516-373C2996E2F7}"

[HKCR\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}]
"(Default)" = "IProtectorLib3"

[HKCR\Interface\{9891812B-5820-4A77-827E-772B200239E1}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}]
"AppID" = "{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}"

[HKCR\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}\TypeLib]
"Version" = "1a.0"

[HKCR\Interface\{A0CF48B9-DB91-49A5-BEE7-2FB45BA2F610}\TypeLib]
"Version" = "1a.0"

[HKCR\Interface\{2351B346-00E8-4EAC-9B75-B138B465D659}]
"(Default)" = "IProtector"

[HKCR\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}]
"(Default)" = "IProtector6"

[HKCR\Interface\{2351B346-00E8-4EAC-9B75-B138B465D659}\TypeLib]
"Version" = "1a.0"

[HKCR\ProtectorExe.ProtectorHost.1]
"(Default)" = "ProtectorHost Class"

[HKCR\Wow6432Node\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\protector_dll.Protector\CurVer]
"(Default)" = "protector_dll.Protector.1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{80B84A0A-EDA4-47fd-8BE1-6B49F4197EE5}]
"AppName" = "GoogleToolbarNotifier.exe"

[HKCR\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}\TypeLib]
"Version" = "1a.0"

[HKCR\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{277FD1E8-9884-4E0A-9392-7CFF83F067B2}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}\TypeLib]
"Version" = "1a.0"

[HKCR\AppID\{A97CA128-6998-4F8E-807E-8ED05FADAFB0}]
"RunAs" = "Interactive User"

[HKCR\Wow6432Node\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}]
"(Default)" = "IProtectorLib5"

[HKCR\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}\TypeLib]
"Version" = "1a.0"

[HKCR\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{A0CF48B9-DB91-49A5-BEE7-2FB45BA2F610}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{80B84A0A-EDA4-47fd-8BE1-6B49F4197EE5}]
"Policy" = "3"

[HKCR\protector_dll.ProtectorBho\CLSID]
"(Default)" = "{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}"

[HKCR\Wow6432Node\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}\TypeLib]
"Version" = "1a.0"

[HKCR\Interface\{1F7328B7-E25A-4527-B24B-D9173401BB89}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}]
"AppID" = "{A97CA128-6998-4F8E-807E-8ED05FADAFB0}"

[HKCR\Wow6432Node\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\LocalServer32]
"(Default)" = "%Program Files% (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

[HKCR\protector_dll.ProtectorBho\CurVer]
"(Default)" = "protector_dll.ProtectorBho.1"

[HKCR\Wow6432Node\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\ProtectorExe.ProtectorHost\CurVer]
"(Default)" = "ProtectorExe.ProtectorHost.1"

[HKCR\Wow6432Node\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{DA69D3CC-7676-4A65-889F-C052977F1AA9}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\1a.0\0\win32]
"(Default)" = "%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll"

[HKCR\Wow6432Node\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{80B84A0A-EDA4-47fd-8BE1-6B49F4197EE5}]
"Policy" = "3"

[HKCR\Wow6432Node\Interface\{6C110376-C248-47F6-9DB2-CFCDEADB6A3E}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{480AD54B-C652-44B9-BCF6-746745055CD3}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{F1A383D4-0364-4092-82E0-C39DAE5D801D}]
"(Default)" = "IProtector12"

[HKCR\Wow6432Node\Interface\{91959FBB-853A-4AC7-A082-2DDF787F4CA9}]
"(Default)" = "IProtectorHost2"

[HKCR\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{2351B346-00E8-4EAC-9B75-B138B465D659}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{1F7328B7-E25A-4527-B24B-D9173401BB89}\TypeLib]
"Version" = "1a.0"

[HKCR\protector_dll.Protector.1]
"(Default)" = "Protector Class"

[HKCR\Wow6432Node\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\InprocServer32]
"(Default)" = "%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll"

[HKCR\protector_dll.Protector]
"(Default)" = "Protector Class"

[HKCR\protector_dll.ProtectorLib\CLSID]
"(Default)" = "{84798B8E-69F8-4846-9516-373C2996E2F7}"

[HKCR\Interface\{AF606610-3627-4DF2-A6D5-32C6A355ACD1}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{277FD1E8-9884-4E0A-9392-7CFF83F067B2}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{DA69D3CC-7676-4A65-889F-C052977F1AA9}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}]
"(Default)" = "IProtector8"

[HKCR\Wow6432Node\Interface\{2351B346-00E8-4EAC-9B75-B138B465D659}]
"(Default)" = "IProtector"

[HKCR\Wow6432Node\Interface\{2351B346-00E8-4EAC-9B75-B138B465D659}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{277FD1E8-9884-4E0A-9392-7CFF83F067B2}]
"(Default)" = "IProtector9"

[HKCR\Interface\{F1A383D4-0364-4092-82E0-C39DAE5D801D}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{DA69D3CC-7676-4A65-889F-C052977F1AA9}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}]
"(Default)" = "Protector Class"

[HKCR\Interface\{277FD1E8-9884-4E0A-9392-7CFF83F067B2}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}]
"(Default)" = "IProtectorLib4"

[HKCR\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}]
"(Default)" = "IProtector7"

[HKCR\Interface\{AF606610-3627-4DF2-A6D5-32C6A355ACD1}]
"(Default)" = "IProtectorLib"

[HKCR\Wow6432Node\Interface\{277FD1E8-9884-4E0A-9392-7CFF83F067B2}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}]
"(Default)" = "IProtectorLib4"

[HKCR\protector_dll.ProtectorLib]
"(Default)" = "ProtectorLib Class"

[HKCR\Wow6432Node\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{AF606610-3627-4DF2-A6D5-32C6A355ACD1}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{480AD54B-C652-44B9-BCF6-746745055CD3}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{480AD54B-C652-44B9-BCF6-746745055CD3}]
"(Default)" = "IProtectorLib6"

[HKCR\Wow6432Node\Interface\{6C110376-C248-47F6-9DB2-CFCDEADB6A3E}\TypeLib]
"Version" = "1a.0"

[HKCR\Interface\{480AD54B-C652-44B9-BCF6-746745055CD3}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{480AD54B-C652-44B9-BCF6-746745055CD3}\TypeLib]
"Version" = "1a.0"

[HKCR\Wow6432Node\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Wow6432Node\Interface\{A0CF48B9-DB91-49A5-BEE7-2FB45BA2F610}]
"(Default)" = "IProtectorLib2"

[HKCR\Wow6432Node\Interface\{1F7328B7-E25A-4527-B24B-D9173401BB89}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{91959FBB-853A-4AC7-A082-2DDF787F4CA9}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\Interface\{277FD1E8-9884-4E0A-9392-7CFF83F067B2}\TypeLib]
"Version" = "1a.0"

The process GoogleToolbarNotifier.exe:2728 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Google\GoogleToolbarNotifier\Stats]
"HideUI_Throttled" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\GoogleToolbarNotifier_RASAPI32]
"EnableConsoleTracing" = "0"

[HKCU\Software\Google\GoogleToolbarNotifier\Stats]
"DetectChange_DS" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "7A 9A 94 9F 75 7E D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Google\GoogleToolbarNotifier]
"FirstRun" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Google\GoogleToolbarNotifier\Stats]
"Icon_Click" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\GoogleToolbarNotifier_RASAPI32]
"FileDirectory" = "%windir%\tracing"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "25 CC 85 1E BF 72 D0 01"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\GoogleToolbarNotifier_RASAPI32]
"EnableFileTracing" = "0"

[HKCU\Software\Google\GoogleToolbarNotifier]
"UpdateURL" = "http://clients1.google.com/tools/swg2/update"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Google\GoogleToolbarNotifier]
"lds" = "http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7"

[HKCU\Software\Google\GoogleToolbarNotifier\Stats]
"ShowUI_TrayIcon" = "0"

[HKCU\Software\Google\GoogleToolbarNotifier]
"DefaultLanguage" = "en"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Google\GoogleToolbarNotifier]
"TS" = "1429869682"

[HKCU\Software\Google\GoogleToolbarNotifier\Stats]
"Bubble_Click" = "0"
"UserAllowChange_DS" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\GoogleToolbarNotifier_RASAPI32]
"ConsoleTracingMask" = "4294901760"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

[HKCU\Software\Google\GoogleToolbarNotifier]
"AppPath" = "%Program Files% (x86)\Google\GoogleToolbarNotifier"

[HKCU\Software\Google\GoogleToolbarNotifier\Stats]
"ShowUI_Popup" = "0"

[HKCU\Software\Google\GoogleToolbarNotifier]
"InstalledVersion" = "5.10.11023.1534"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 43 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Google\GoogleToolbarNotifier\Stats]
"LastReportTime" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Google\GoogleToolbarNotifier\Temp]
"scShowTrayIcon" = "ffffffff"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\GoogleToolbarNotifier_RASAPI32]
"MaxFileSize" = "1048576"

[HKCU\Software\Google\GoogleToolbarNotifier]
"UsageStat" = "1"

[HKCU\Software\Google\GoogleToolbarNotifier\Stats]
"ModifyUI_UserIntent" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\GoogleToolbarNotifier_RASAPI32]
"FileTracingMask" = "4294901760"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
"WpadDecision" = "0"

[HKCU\Software\Google\GoogleToolbarNotifier]
"Version" = "5.10.11023.1534"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoDetect"

[HKCU\Software\Google\GoogleToolbarNotifier]
"WantProductRestart"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Google\GoogleToolbarNotifier]
"ts"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Google\GoogleToolbarNotifier]
"DSPSuspended"
"SuspendedDS"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"

The process RegSvr32.exe:2432 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\Wow6432Node\CLSID\{704ECB6B-8215-4B6E-9220-6B74D64D3327}]
"(Default)" = "DNTRule Class"

[HKCR\Wow6432Node\Interface\{2F954446-F141-40B4-B61F-1C67F142B7A8}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{8191D75A-9849-4956-BAA1-E30286B075E7}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{8191D75A-9849-4956-BAA1-E30286B075E7}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\Interface\{DAF611F6-C2A6-41E8-B9A9-AFC0EFFDA9ED}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{90865748-A347-49AD-ABCA-2368F98B4820}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{836DE9F2-7F9C-41C5-9C54-30E2AC156546}]
"(Default)" = "_IBrokerServerEvents"

[HKCR\Wow6432Node\Interface\{836DE9F2-7F9C-41C5-9C54-30E2AC156546}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{DAF611F6-C2A6-41E8-B9A9-AFC0EFFDA9ED}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{C8D8CA8E-15CE-4143-9E3E-89294A453003}\Version]
"(Default)" = "1.0"

[HKCR\Interface\{5C25A83F-07A6-426F-A89D-27003DFCEE31}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{F6804C21-CBF4-4CD1-B684-901BC639CAAD}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{FEBE3226-4703-4756-AA88-95316EFB71FF}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{81F6CBBF-955D-4898-9166-92A4C19291F6}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{1433A87C-BD3C-4404-AECB-44B9506DF106}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\CLSID\{F4FB18A4-CE06-4ABC-B3BD-16774A4FA95C}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\Interface\{FEBE3226-4703-4756-AA88-95316EFB71FF}]
"(Default)" = "IBSTRArray"

[HKCR\Interface\{FEBE3226-4703-4756-AA88-95316EFB71FF}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{6CF036DD-D284-4725-BAD7-936F25F638BB}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{0EF4D762-CA12-414E-BFCB-1257EFBCB4FE}]
"(Default)" = "Phishing Class"

[HKCR\Interface\{2F954446-F141-40B4-B61F-1C67F142B7A8}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{30A77BB1-3288-4C35-ADC2-B6D072AF2FEA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{02099F5F-2F76-48A0-85C6-717112E764AC}]
"(Default)" = "IBrokerServer"

[HKCR\Interface\{E52F2A1E-10F8-4A05-BFEF-344821B00B59}]
"(Default)" = "ISettings"

[HKCR\Wow6432Node\CLSID\{90865748-A347-49AD-ABCA-2368F98B4820}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\Interface\{6CF036DD-D284-4725-BAD7-936F25F638BB}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{30A77BB1-3288-4C35-ADC2-B6D072AF2FEA}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{1433A87C-BD3C-4404-AECB-44B9506DF106}]
"(Default)" = "Safeshop Class"

[HKCR\Wow6432Node\Interface\{FEBE3226-4703-4756-AA88-95316EFB71FF}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{C72EA03D-BEFE-47D8-942E-8A6B6585C2DD}\Version]
"(Default)" = "1.0"

[HKCR\TypeLib\{6DFA2AA7-8234-46E2-A8E2-96794315C122}\1.0]
"(Default)" = "aswWrcIEBrokerLib"

[HKCR\Wow6432Node\Interface\{30A77BB1-3288-4C35-ADC2-B6D072AF2FEA}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\TypeLib\{6DFA2AA7-8234-46E2-A8E2-96794315C122}\1.0\HELPDIR]
"(Default)" = "%Program Files%\AVAST Software\Avast"

[HKCR\Interface\{6CF036DD-D284-4725-BAD7-936F25F638BB}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{30A77BB1-3288-4C35-ADC2-B6D072AF2FEA}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{6DFA2AA7-8234-46E2-A8E2-96794315C122}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Interface\{81F6CBBF-955D-4898-9166-92A4C19291F6}]
"(Default)" = "IBrokerNotification"

[HKCR\Wow6432Node\CLSID\{288ABA12-FA03-4D06-AC55-6D5E28966DC2}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Wow6432Node\CLSID\{E2D61D62-743B-42A0-9D50-A4CA9945BC43}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Wow6432Node\Interface\{7B2E6D96-F09A-4ABE-B3D5-21B60980CA77}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{1BFD0426-F112-4ACA-AE8B-38125BC588DB}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{0EF4D762-CA12-414E-BFCB-1257EFBCB4FE}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\Interface\{73DECDB5-56E1-40E2-B7CE-8748FD093C2B}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{2F954446-F141-40B4-B61F-1C67F142B7A8}]
"(Default)" = "ISearchColoringRule"

[HKCR\Interface\{FEBE3226-4703-4756-AA88-95316EFB71FF}]
"(Default)" = "IBSTRArray"

[HKCR\Interface\{5C25A83F-07A6-426F-A89D-27003DFCEE31}]
"(Default)" = "IUrlInfoArray"

[HKCR\Wow6432Node\Interface\{F6804C21-CBF4-4CD1-B684-901BC639CAAD}]
"(Default)" = "IBlocker"

[HKCR\Wow6432Node\CLSID\{288ABA12-FA03-4D06-AC55-6D5E28966DC2}]
"(Default)" = "Typo Class"

[HKCR\Wow6432Node\Interface\{836DE9F2-7F9C-41C5-9C54-30E2AC156546}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\Interface\{07B9DDB7-F0AC-4000-82B0-7E47F2FA22D9}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{6DFA2AA7-8234-46E2-A8E2-96794315C122}\1.0\0\win32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Interface\{8191D75A-9849-4956-BAA1-E30286B075E7}]
"(Default)" = "INotificationsArray"

[HKCR\Wow6432Node\CLSID\{C8D8CA8E-15CE-4143-9E3E-89294A453003}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Wow6432Node\CLSID\{90865748-A347-49AD-ABCA-2368F98B4820}]
"(Default)" = "UrlInfo Class"

[HKCR\Wow6432Node\CLSID\{C72EA03D-BEFE-47D8-942E-8A6B6585C2DD}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{07B9DDB7-F0AC-4000-82B0-7E47F2FA22D9}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{35866E0F-FEC8-4461-8593-6DD7089DCAB6}]
"(Default)" = "BSTRArray Class"

[HKCR\Wow6432Node\Interface\{538283B3-D33F-43C0-8904-09AA164CBF39}]
"(Default)" = "IUrlInfo"

[HKCR\Wow6432Node\CLSID\{6BB027E1-C358-49CA-96C6-A765EEAD7008}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{6CF036DD-D284-4725-BAD7-936F25F638BB}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{72CEEE9E-0D2A-48D0-A940-5C8CB639A91B}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\CLSID\{6BB027E1-C358-49CA-96C6-A765EEAD7008}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Interface\{DAF611F6-C2A6-41E8-B9A9-AFC0EFFDA9ED}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\CLSID\{5CA7F0F6-F479-426C-AE5E-A434EA76BE81}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Wow6432Node\Interface\{07B9DDB7-F0AC-4000-82B0-7E47F2FA22D9}]
"(Default)" = "IWebRep"

[HKCR\Wow6432Node\Interface\{1BFD0426-F112-4ACA-AE8B-38125BC588DB}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{73DECDB5-56E1-40E2-B7CE-8748FD093C2B}]
"(Default)" = "IDNTRule"

[HKCR\Wow6432Node\CLSID\{F4FB18A4-CE06-4ABC-B3BD-16774A4FA95C}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{07B9DDB7-F0AC-4000-82B0-7E47F2FA22D9}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{836DE9F2-7F9C-41C5-9C54-30E2AC156546}]
"(Default)" = "_IBrokerServerEvents"

[HKCR\Interface\{81F6CBBF-955D-4898-9166-92A4C19291F6}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{E52F2A1E-10F8-4A05-BFEF-344821B00B59}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{6CF036DD-D284-4725-BAD7-936F25F638BB}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{0EF4D762-CA12-414E-BFCB-1257EFBCB4FE}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Interface\{2F954446-F141-40B4-B61F-1C67F142B7A8}]
"(Default)" = "ISearchColoringRule"

[HKCR\Wow6432Node\CLSID\{704ECB6B-8215-4B6E-9220-6B74D64D3327}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\CLSID\{F4FB18A4-CE06-4ABC-B3BD-16774A4FA95C}\Version]
"(Default)" = "1.0"

[HKCR\Interface\{7B2E6D96-F09A-4ABE-B3D5-21B60980CA77}]
"(Default)" = "_IServiceEvents"

[HKCR\Interface\{538283B3-D33F-43C0-8904-09AA164CBF39}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\CLSID\{C8D8CA8E-15CE-4143-9E3E-89294A453003}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{836DE9F2-7F9C-41C5-9C54-30E2AC156546}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{E2D61D62-743B-42A0-9D50-A4CA9945BC43}\Version]
"(Default)" = "1.0"

[HKCR\Wow6432Node\CLSID\{5CA7F0F6-F479-426C-AE5E-A434EA76BE81}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{02099F5F-2F76-48A0-85C6-717112E764AC}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{704ECB6B-8215-4B6E-9220-6B74D64D3327}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{8191D75A-9849-4956-BAA1-E30286B075E7}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{538283B3-D33F-43C0-8904-09AA164CBF39}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{288ABA12-FA03-4D06-AC55-6D5E28966DC2}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\Interface\{FEBE3226-4703-4756-AA88-95316EFB71FF}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{1BFD0426-F112-4ACA-AE8B-38125BC588DB}]
"(Default)" = "ITypo"

[HKCR\Interface\{02099F5F-2F76-48A0-85C6-717112E764AC}]
"(Default)" = "IBrokerServer"

[HKCR\Wow6432Node\CLSID\{1433A87C-BD3C-4404-AECB-44B9506DF106}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Wow6432Node\CLSID\{0EF4D762-CA12-414E-BFCB-1257EFBCB4FE}\Version]
"(Default)" = "1.0"

[HKCR\Wow6432Node\Interface\{E52F2A1E-10F8-4A05-BFEF-344821B00B59}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{E2D61D62-743B-42A0-9D50-A4CA9945BC43}]
"(Default)" = "Blocker Class"

[HKCR\Wow6432Node\CLSID\{5CA7F0F6-F479-426C-AE5E-A434EA76BE81}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{7B2E6D96-F09A-4ABE-B3D5-21B60980CA77}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{FEBE3226-4703-4756-AA88-95316EFB71FF}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{72CEEE9E-0D2A-48D0-A940-5C8CB639A91B}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Wow6432Node\CLSID\{72CEEE9E-0D2A-48D0-A940-5C8CB639A91B}]
"(Default)" = "Service Class"

[HKCR\Wow6432Node\Interface\{30A77BB1-3288-4C35-ADC2-B6D072AF2FEA}]
"(Default)" = "IService"

[HKCR\Wow6432Node\Interface\{E52F2A1E-10F8-4A05-BFEF-344821B00B59}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\CLSID\{4C3DA18A-A416-4B52-A867-2C3DC0A415B6}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\CLSID\{72CEEE9E-0D2A-48D0-A940-5C8CB639A91B}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{30A77BB1-3288-4C35-ADC2-B6D072AF2FEA}]
"(Default)" = "IService"

[HKCR\Wow6432Node\CLSID\{C8D8CA8E-15CE-4143-9E3E-89294A453003}]
"(Default)" = "Notification Class"

[HKCR\Wow6432Node\CLSID\{C72EA03D-BEFE-47D8-942E-8A6B6585C2DD}]
"(Default)" = "SearchColoringRule Class"

[HKCR\Interface\{7B2E6D96-F09A-4ABE-B3D5-21B60980CA77}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{E52F2A1E-10F8-4A05-BFEF-344821B00B59}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{538283B3-D33F-43C0-8904-09AA164CBF39}]
"(Default)" = "IUrlInfo"

[HKCR\Wow6432Node\CLSID\{35866E0F-FEC8-4461-8593-6DD7089DCAB6}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{73DECDB5-56E1-40E2-B7CE-8748FD093C2B}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{81F6CBBF-955D-4898-9166-92A4C19291F6}]
"(Default)" = "IBrokerNotification"

[HKCR\Wow6432Node\Interface\{E52F2A1E-10F8-4A05-BFEF-344821B00B59}]
"(Default)" = "ISettings"

[HKCR\Wow6432Node\Interface\{DAF611F6-C2A6-41E8-B9A9-AFC0EFFDA9ED}]
"(Default)" = "ISafeshop"

[HKCR\Wow6432Node\CLSID\{E2D61D62-743B-42A0-9D50-A4CA9945BC43}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\CLSID\{E3E156D0-EF1D-42C3-A24C-8798D5DC2E93}]
"(Default)" = "Settings Class"

[HKCR\Wow6432Node\Interface\{7B2E6D96-F09A-4ABE-B3D5-21B60980CA77}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{07B9DDB7-F0AC-4000-82B0-7E47F2FA22D9}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{538283B3-D33F-43C0-8904-09AA164CBF39}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{F6804C21-CBF4-4CD1-B684-901BC639CAAD}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{DAF611F6-C2A6-41E8-B9A9-AFC0EFFDA9ED}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{5C25A83F-07A6-426F-A89D-27003DFCEE31}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{8191D75A-9849-4956-BAA1-E30286B075E7}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{07B9DDB7-F0AC-4000-82B0-7E47F2FA22D9}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{8191D75A-9849-4956-BAA1-E30286B075E7}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{F6804C21-CBF4-4CD1-B684-901BC639CAAD}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{90865748-A347-49AD-ABCA-2368F98B4820}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Wow6432Node\CLSID\{0EF4D762-CA12-414E-BFCB-1257EFBCB4FE}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\CLSID\{4C3DA18A-A416-4B52-A867-2C3DC0A415B6}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\Interface\{73DECDB5-56E1-40E2-B7CE-8748FD093C2B}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{30A77BB1-3288-4C35-ADC2-B6D072AF2FEA}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{02099F5F-2F76-48A0-85C6-717112E764AC}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{8191D75A-9849-4956-BAA1-E30286B075E7}]
"(Default)" = "INotificationsArray"

[HKCR\Wow6432Node\CLSID\{C8D8CA8E-15CE-4143-9E3E-89294A453003}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{538283B3-D33F-43C0-8904-09AA164CBF39}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{1BFD0426-F112-4ACA-AE8B-38125BC588DB}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{F6804C21-CBF4-4CD1-B684-901BC639CAAD}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{07B9DDB7-F0AC-4000-82B0-7E47F2FA22D9}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\CLSID\{6BB027E1-C358-49CA-96C6-A765EEAD7008}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{1BFD0426-F112-4ACA-AE8B-38125BC588DB}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\Interface\{7B2E6D96-F09A-4ABE-B3D5-21B60980CA77}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{6CF036DD-D284-4725-BAD7-936F25F638BB}]
"(Default)" = "IPhishing"

[HKCR\Wow6432Node\CLSID\{4C3DA18A-A416-4B52-A867-2C3DC0A415B6}]
"(Default)" = "NotificationsArray Class"

[HKCR\Interface\{02099F5F-2F76-48A0-85C6-717112E764AC}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\Interface\{02099F5F-2F76-48A0-85C6-717112E764AC}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{5C25A83F-07A6-426F-A89D-27003DFCEE31}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\CLSID\{704ECB6B-8215-4B6E-9220-6B74D64D3327}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Wow6432Node\CLSID\{E3E156D0-EF1D-42C3-A24C-8798D5DC2E93}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{2F954446-F141-40B4-B61F-1C67F142B7A8}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{72CEEE9E-0D2A-48D0-A940-5C8CB639A91B}\Version]
"(Default)" = "1.0"

[HKCR\Wow6432Node\Interface\{73DECDB5-56E1-40E2-B7CE-8748FD093C2B}]
"(Default)" = "IDNTRule"

[HKCR\Interface\{E52F2A1E-10F8-4A05-BFEF-344821B00B59}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\CLSID\{288ABA12-FA03-4D06-AC55-6D5E28966DC2}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{1BFD0426-F112-4ACA-AE8B-38125BC588DB}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\CLSID\{F4FB18A4-CE06-4ABC-B3BD-16774A4FA95C}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Wow6432Node\CLSID\{704ECB6B-8215-4B6E-9220-6B74D64D3327}\Version]
"(Default)" = "1.0"

[HKCR\Wow6432Node\CLSID\{6BB027E1-C358-49CA-96C6-A765EEAD7008}]
"(Default)" = "BrokerServer Class"

[HKCR\Wow6432Node\CLSID\{35866E0F-FEC8-4461-8593-6DD7089DCAB6}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Interface\{538283B3-D33F-43C0-8904-09AA164CBF39}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{4C3DA18A-A416-4B52-A867-2C3DC0A415B6}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Interface\{836DE9F2-7F9C-41C5-9C54-30E2AC156546}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\CLSID\{1433A87C-BD3C-4404-AECB-44B9506DF106}\Version]
"(Default)" = "1.0"

[HKCR\Interface\{81F6CBBF-955D-4898-9166-92A4C19291F6}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{E3E156D0-EF1D-42C3-A24C-8798D5DC2E93}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\CLSID\{C72EA03D-BEFE-47D8-942E-8A6B6585C2DD}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Wow6432Node\Interface\{30A77BB1-3288-4C35-ADC2-B6D072AF2FEA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{1BFD0426-F112-4ACA-AE8B-38125BC588DB}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{73DECDB5-56E1-40E2-B7CE-8748FD093C2B}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{4C3DA18A-A416-4B52-A867-2C3DC0A415B6}\Version]
"(Default)" = "1.0"

[HKCR\Interface\{81F6CBBF-955D-4898-9166-92A4C19291F6}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\CLSID\{35866E0F-FEC8-4461-8593-6DD7089DCAB6}\Version]
"(Default)" = "1.0"

[HKCR\Interface\{6CF036DD-D284-4725-BAD7-936F25F638BB}]
"(Default)" = "IPhishing"

[HKCR\Interface\{DAF611F6-C2A6-41E8-B9A9-AFC0EFFDA9ED}]
"(Default)" = "ISafeshop"

[HKCR\Interface\{FEBE3226-4703-4756-AA88-95316EFB71FF}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{6CF036DD-D284-4725-BAD7-936F25F638BB}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{6BB027E1-C358-49CA-96C6-A765EEAD7008}\Version]
"(Default)" = "1.0"

[HKCR\Wow6432Node\Interface\{F6804C21-CBF4-4CD1-B684-901BC639CAAD}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{02099F5F-2F76-48A0-85C6-717112E764AC}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{E2D61D62-743B-42A0-9D50-A4CA9945BC43}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{2F954446-F141-40B4-B61F-1C67F142B7A8}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\CLSID\{E3E156D0-EF1D-42C3-A24C-8798D5DC2E93}\Version]
"(Default)" = "1.0"

[HKCR\Wow6432Node\CLSID\{90865748-A347-49AD-ABCA-2368F98B4820}\Version]
"(Default)" = "1.0"

[HKCR\Wow6432Node\Interface\{81F6CBBF-955D-4898-9166-92A4C19291F6}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{E52F2A1E-10F8-4A05-BFEF-344821B00B59}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{836DE9F2-7F9C-41C5-9C54-30E2AC156546}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{5C25A83F-07A6-426F-A89D-27003DFCEE31}]
"(Default)" = "IUrlInfoArray"

[HKCR\Wow6432Node\CLSID\{1433A87C-BD3C-4404-AECB-44B9506DF106}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\CLSID\{5CA7F0F6-F479-426C-AE5E-A434EA76BE81}\Version]
"(Default)" = "1.0"

[HKCR\Wow6432Node\Interface\{8191D75A-9849-4956-BAA1-E30286B075E7}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{1BFD0426-F112-4ACA-AE8B-38125BC588DB}]
"(Default)" = "ITypo"

[HKCR\Wow6432Node\CLSID\{288ABA12-FA03-4D06-AC55-6D5E28966DC2}\Version]
"(Default)" = "1.0"

[HKCR\Interface\{836DE9F2-7F9C-41C5-9C54-30E2AC156546}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{02099F5F-2F76-48A0-85C6-717112E764AC}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{35866E0F-FEC8-4461-8593-6DD7089DCAB6}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\Interface\{5C25A83F-07A6-426F-A89D-27003DFCEE31}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{73DECDB5-56E1-40E2-B7CE-8748FD093C2B}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\Interface\{81F6CBBF-955D-4898-9166-92A4C19291F6}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{5C25A83F-07A6-426F-A89D-27003DFCEE31}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Interface\{07B9DDB7-F0AC-4000-82B0-7E47F2FA22D9}]
"(Default)" = "IWebRep"

[HKCR\Wow6432Node\CLSID\{F4FB18A4-CE06-4ABC-B3BD-16774A4FA95C}]
"(Default)" = "WebRep Class"

[HKCR\Wow6432Node\CLSID\{E3E156D0-EF1D-42C3-A24C-8798D5DC2E93}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker32.dll"

[HKCR\Interface\{5C25A83F-07A6-426F-A89D-27003DFCEE31}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{DAF611F6-C2A6-41E8-B9A9-AFC0EFFDA9ED}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{7B2E6D96-F09A-4ABE-B3D5-21B60980CA77}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{7B2E6D96-F09A-4ABE-B3D5-21B60980CA77}]
"(Default)" = "_IServiceEvents"

[HKCR\Wow6432Node\CLSID\{C72EA03D-BEFE-47D8-942E-8A6B6585C2DD}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{F6804C21-CBF4-4CD1-B684-901BC639CAAD}]
"(Default)" = "IBlocker"

[HKCR\Interface\{73DECDB5-56E1-40E2-B7CE-8748FD093C2B}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{2F954446-F141-40B4-B61F-1C67F142B7A8}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{F6804C21-CBF4-4CD1-B684-901BC639CAAD}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{2F954446-F141-40B4-B61F-1C67F142B7A8}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{5CA7F0F6-F479-426C-AE5E-A434EA76BE81}]
"(Default)" = "UrlInfoArray Class"

[HKCR\Wow6432Node\Interface\{DAF611F6-C2A6-41E8-B9A9-AFC0EFFDA9ED}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\Wow6432Node\Interface\{538283B3-D33F-43C0-8904-09AA164CBF39}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

The process RegSvr32.exe:2468 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\Interface\{040CF329-035F-4985-A198-CC17D02AE06E}]
"(Default)" = "IsbScanner"

[HKCR\Wow6432Node\CLSID\{f414c260-6ac0-11cf-b6d1-00aa00bbbb58}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\AhAScr.dll"

[HKCR\Wow6432Node\CLSID\{f414c262-6ac0-11cf-b6d1-00aa00bbbb58}\InprocServer32]
"Default Engine" = "C:\Windows\SysWOW64\jscript.dll"

[HKCR\AvAScr.sbScanner\CurVer]
"(Default)" = "AvAScr.sbScanner.1"

[HKCR\AvAScr.sbScanner]
"(Default)" = "sbScanner Class"

[HKCR\AvAScr.sbScanner.1\CLSID]
"(Default)" = "{7BFC2BD7-0937-41EA-8872-CE3B27E08F84}"

[HKCR\TypeLib\{03A25D6C-293E-4420-8551-E580F8009343}\1.0\0\win32]
"(Default)" = "%Program Files%\AVAST Software\Avast\AhAScr.dll"

[HKCR\Wow6432Node\Interface\{040CF329-035F-4985-A198-CC17D02AE06E}\TypeLib]
"(Default)" = "{03A25D6C-293E-4420-8551-E580F8009343}"

[HKCR\Wow6432Node\CLSID\{7BFC2BD7-0937-41EA-8872-CE3B27E08F84}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\AhAScr.dll"

[HKCR\AvAScr.sbScanner\CLSID]
"(Default)" = "{7BFC2BD7-0937-41EA-8872-CE3B27E08F84}"

[HKCR\Wow6432Node\CLSID\{7BFC2BD7-0937-41EA-8872-CE3B27E08F84}\VersionIndependentProgID]
"(Default)" = "AvAScr.sbScanner"

[HKCR\Wow6432Node\CLSID\{f414c260-6ac0-11cf-b6d1-00aa00bbbb58}\InprocServer32]
"Default Engine" = "C:\Windows\SysWOW64\jscript.dll"

[HKCR\Wow6432Node\CLSID\{7BFC2BD7-0937-41EA-8872-CE3B27E08F84}\ProgID]
"(Default)" = "AvAScr.sbScanner.1"

[HKCR\Interface\{040CF329-035F-4985-A198-CC17D02AE06E}\TypeLib]
"Version" = "1.0"
"(Default)" = "{03A25D6C-293E-4420-8551-E580F8009343}"

[HKCR\TypeLib\{03A25D6C-293E-4420-8551-E580F8009343}\1.0\HELPDIR]
"(Default)" = "%Program Files%\AVAST Software\Avast"

[HKCR\Wow6432Node\CLSID\{f414c262-6ac0-11cf-b6d1-00aa00bbbb58}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\AhAScr.dll"

[HKCR\AvAScr.sbScanner.1]
"(Default)" = "sbScanner Class"

[HKCR\TypeLib\{03A25D6C-293E-4420-8551-E580F8009343}\1.0]
"(Default)" = "AvAScr 1.0 Type Library"

[HKCR\TypeLib\{03A25D6C-293E-4420-8551-E580F8009343}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Wow6432Node\Interface\{040CF329-035F-4985-A198-CC17D02AE06E}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{7BFC2BD7-0937-41EA-8872-CE3B27E08F84}\InprocServer32]
"ThreadingModel" = "Both"

[HKCR\Wow6432Node\CLSID\{7BFC2BD7-0937-41EA-8872-CE3B27E08F84}]
"(Default)" = "sbScanner Class"

[HKCR\Wow6432Node\CLSID\{7BFC2BD7-0937-41EA-8872-CE3B27E08F84}\TypeLib]
"(Default)" = "{03A25D6C-293E-4420-8551-E580F8009343}"

[HKCR\AppID\AvAScr.DLL]
"AppID" = "{66A841F2-956C-4631-BFE7-C90225F417D6}"

[HKCR\Wow6432Node\Interface\{040CF329-035F-4985-A198-CC17D02AE06E}]
"(Default)" = "IsbScanner"

[HKCR\Wow6432Node\Interface\{040CF329-035F-4985-A198-CC17D02AE06E}\TypeLib]
"Version" = "1.0"

[HKCR\AppID\{66A841F2-956C-4631-BFE7-C90225F417D6}]
"(Default)" = "AvAScr"

[HKCR\Wow6432Node\CLSID\{7BFC2BD7-0937-41EA-8872-CE3B27E08F84}]
"AppID" = "{66A841F2-956C-4631-BFE7-C90225F417D6}"

[HKCR\Interface\{040CF329-035F-4985-A198-CC17D02AE06E}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

The process RegSvr32.exe:1368 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\Outlook\Addins\avast.AsOutExt]
"LoadBehavior" = "3"

[HKCR\Wow6432Node\Interface\{F64B349A-BD50-415F-9F99-72E00C161493}\TypeLib]
"Version" = "1.0"

[HKCR\avast.AsOutExt.1\CLSID]
"(Default)" = "{B342E21B-AD7E-4568-AE3F-D0D844537A7A}"

[HKCR\Interface\{F64B349A-BD50-415F-9F99-72E00C161493}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\Outlook\Addins\avast.AsOutExt]
"CommandLineSafe" = "0"
"RequireShutdownNotification" = "1"

[HKCR\Wow6432Node\CLSID\{B342E21B-AD7E-4568-AE3F-D0D844537A7A}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\asOutExt.dll"

[HKCR\Interface\{CD2CE11F-5C26-4217-A773-914FADDA6FD9}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{F64B349A-BD50-415F-9F99-72E00C161493}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{EDDBDEA4-5C07-453F-BE8C-81D738984381}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Wow6432Node\CLSID\{B342E21B-AD7E-4568-AE3F-D0D844537A7A}\VersionIndependentProgID]
"(Default)" = "avast.AsOutExt"

[HKCR\Interface\{CD2CE11F-5C26-4217-A773-914FADDA6FD9}\TypeLib]
"(Default)" = "{EDDBDEA4-5C07-453F-BE8C-81D738984381}"

[HKCR\avast.AsOutExt\CurVer]
"(Default)" = "avast.AsOutExt.1"

[HKCR\Wow6432Node\CLSID\{B342E21B-AD7E-4568-AE3F-D0D844537A7A}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{F64B349A-BD50-415F-9F99-72E00C161493}\TypeLib]
"(Default)" = "{EDDBDEA4-5C07-453F-BE8C-81D738984381}"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\Outlook\Addins\avast.AsOutExt]
"FriendlyName" = "avast! Addin"

[HKCR\TypeLib\{EDDBDEA4-5C07-453F-BE8C-81D738984381}\1.0]
"(Default)" = "AsOutExt 1.0 Type Library"

[HKCR\TypeLib\{EDDBDEA4-5C07-453F-BE8C-81D738984381}\1.0\0\win32]
"(Default)" = "%Program Files%\AVAST Software\Avast\asOutExt.dll"

[HKCR\Wow6432Node\CLSID\{B342E21B-AD7E-4568-AE3F-D0D844537A7A}\ProgID]
"(Default)" = "avast.AsOutExt.1"

[HKCR\TypeLib\{EDDBDEA4-5C07-453F-BE8C-81D738984381}\1.0\HELPDIR]
"(Default)" = "%Program Files%\AVAST Software\Avast"

[HKCR\Wow6432Node\Interface\{CD2CE11F-5C26-4217-A773-914FADDA6FD9}\TypeLib]
"(Default)" = "{EDDBDEA4-5C07-453F-BE8C-81D738984381}"

[HKCR\Wow6432Node\Interface\{F64B349A-BD50-415F-9F99-72E00C161493}\TypeLib]
"(Default)" = "{EDDBDEA4-5C07-453F-BE8C-81D738984381}"

[HKCR\Interface\{CD2CE11F-5C26-4217-A773-914FADDA6FD9}]
"(Default)" = "IAddin"

[HKCR\Interface\{CD2CE11F-5C26-4217-A773-914FADDA6FD9}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{B342E21B-AD7E-4568-AE3F-D0D844537A7A}\TypeLib]
"(Default)" = "{EDDBDEA4-5C07-453F-BE8C-81D738984381}"

[HKCR\avast.AsOutExt.1]
"(Default)" = "Addin Class"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\Outlook\Addins\avast.AsOutExt]
"Description" = "avast! Outlook Addin"

[HKCR\Interface\{F64B349A-BD50-415F-9F99-72E00C161493}]
"(Default)" = "IRibbonWrapper"

[HKCR\Wow6432Node\CLSID\{B342E21B-AD7E-4568-AE3F-D0D844537A7A}]
"(Default)" = "Addin Class"

[HKCR\Wow6432Node\Interface\{F64B349A-BD50-415F-9F99-72E00C161493}]
"(Default)" = "IRibbonWrapper"

[HKCR\avast.AsOutExt]
"(Default)" = "Addin Class"

[HKCR\Wow6432Node\CLSID\{B342E21B-AD7E-4568-AE3F-D0D844537A7A}\Version]
"(Default)" = "1.0"

[HKCR\Interface\{F64B349A-BD50-415F-9F99-72E00C161493}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\Interface\{CD2CE11F-5C26-4217-A773-914FADDA6FD9}]
"(Default)" = "IAddin"

[HKCR\Wow6432Node\Interface\{CD2CE11F-5C26-4217-A773-914FADDA6FD9}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{CD2CE11F-5C26-4217-A773-914FADDA6FD9}\TypeLib]
"Version" = "1.0"

The process RegSvr32.exe:2916 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\Interface\{B674F15F-2411-438F-A87F-7897BB0C1E19}]
"(Default)" = "IWebRepClient"

[HKCR\Wow6432Node\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\Implemented Categories]
"(Default)" = ""

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00AB3925-B470-4264-B354-03E373074F23}]
"AppPath" = "%Program Files%\AVAST Software\Avast\"

[HKCR\Interface\{B674F15F-2411-438F-A87F-7897BB0C1E19}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{3856F531-CD1E-4B00-91C7-ED75EC8E7C18}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{24417BBE-7FC9-437A-92AF-0EB37B2E6916}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00AB3925-B470-4264-B354-03E373074F23}]
"Policy" = "3"

[HKCR\Wow6432Node\Interface\{B674F15F-2411-438F-A87F-7897BB0C1E19}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{B674F15F-2411-438F-A87F-7897BB0C1E19}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{6B795924-95E7-4D31-8521-407360C3AA0B}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Wow6432Node\CLSID\{FAB4DAA3-9B61-488C-ACD5-BD33DA07FF87}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\CLSID\{FAB4DAA3-9B61-488C-ACD5-BD33DA07FF87}\TypeLib]
"(Default)" = "{aswWrcIELibUUID}"

[HKCR\Wow6432Node\Interface\{170125EF-36E8-412D-9402-B05F9AEF5411}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{170125EF-36E8-412D-9402-B05F9AEF5411}]
"(Default)" = "_IWebRepClientEvents"

[HKCR\TypeLib\{6B795924-95E7-4D31-8521-407360C3AA0B}\1.0\HELPDIR]
"(Default)" = "%Program Files%\AVAST Software\Avast"

[HKCR\Wow6432Node\Interface\{B674F15F-2411-438F-A87F-7897BB0C1E19}]
"(Default)" = "IWebRepClient"

[HKCR\Interface\{170125EF-36E8-412D-9402-B05F9AEF5411}\TypeLib]
"Version" = "1.0"
"(Default)" = "{6B795924-95E7-4D31-8521-407360C3AA0B}"

[HKCR\Interface\{3856F531-CD1E-4B00-91C7-ED75EC8E7C18}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{24417BBE-7FC9-437A-92AF-0EB37B2E6916}]
"(Default)" = "IHttpPassthrouAPP"

[HKCR\Wow6432Node\CLSID\{0DC2520C-BBAA-4A6A-89C8-58811E761A6B}]
"(Default)" = "BHOWorkerThread Class"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
"(Default)" = "avast! Online Security"

[HKCR\Wow6432Node\Interface\{3856F531-CD1E-4B00-91C7-ED75EC8E7C18}\TypeLib]
"(Default)" = "{6B795924-95E7-4D31-8521-407360C3AA0B}"

[HKCR\Interface\{3856F531-CD1E-4B00-91C7-ED75EC8E7C18}\TypeLib]
"(Default)" = "{6B795924-95E7-4D31-8521-407360C3AA0B}"

[HKCR\TypeLib\{6B795924-95E7-4D31-8521-407360C3AA0B}\1.0]
"(Default)" = "aswWrcIELib"

[HKCR\Wow6432Node\Interface\{689B356D-1C7D-42DF-9480-2B493A009BB6}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{3856F531-CD1E-4B00-91C7-ED75EC8E7C18}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{689B356D-1C7D-42DF-9480-2B493A009BB6}]
"(Default)" = "IHttpProtocolSink"

[HKCR\Wow6432Node\Interface\{3856F531-CD1E-4B00-91C7-ED75EC8E7C18}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{24417BBE-7FC9-437A-92AF-0EB37B2E6916}]
"(Default)" = "IHttpPassthrouAPP"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00AB3925-B470-4264-B354-03E373074F23}]
"AppName" = "aswWrcIELoader32.exe"

[HKCR\Wow6432Node\CLSID\{FAB4DAA3-9B61-488C-ACD5-BD33DA07FF87}]
"(Default)" = "BHOWorkerThreadTask Class"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
"NoExplorer" = "1"

[HKCR\Wow6432Node\CLSID\{FAB4DAA3-9B61-488C-ACD5-BD33DA07FF87}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWebRepIE.dll"

[HKCR\TypeLib\{6B795924-95E7-4D31-8521-407360C3AA0B}\1.0\0\win32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWebRepIE.dll"

[HKCR\Wow6432Node\CLSID\{0DC2520C-BBAA-4A6A-89C8-58811E761A6B}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\Interface\{689B356D-1C7D-42DF-9480-2B493A009BB6}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{0DC2520C-BBAA-4A6A-89C8-58811E761A6B}\TypeLib]
"(Default)" = "{aswWrcIELibUUID}"

[HKCR\Wow6432Node\Interface\{24417BBE-7FC9-437A-92AF-0EB37B2E6916}\TypeLib]
"(Default)" = "{6B795924-95E7-4D31-8521-407360C3AA0B}"

[HKCR\Interface\{689B356D-1C7D-42DF-9480-2B493A009BB6}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{24417BBE-7FC9-437A-92AF-0EB37B2E6916}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\Interface\{170125EF-36E8-412D-9402-B05F9AEF5411}\TypeLib]
"(Default)" = "{6B795924-95E7-4D31-8521-407360C3AA0B}"

[HKCR\Wow6432Node\Interface\{689B356D-1C7D-42DF-9480-2B493A009BB6}\TypeLib]
"(Default)" = "{6B795924-95E7-4D31-8521-407360C3AA0B}"

[HKCR\Wow6432Node\Interface\{170125EF-36E8-412D-9402-B05F9AEF5411}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
"(Default)" = ""

[HKCR\Wow6432Node\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
"(Default)" = "avast! Online Security"

[HKCR\Interface\{B674F15F-2411-438F-A87F-7897BB0C1E19}\TypeLib]
"(Default)" = "{6B795924-95E7-4D31-8521-407360C3AA0B}"

[HKCR\Wow6432Node\Interface\{24417BBE-7FC9-437A-92AF-0EB37B2E6916}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{FAB4DAA3-9B61-488C-ACD5-BD33DA07FF87}\Version]
"(Default)" = "1.0"

[HKCR\Interface\{24417BBE-7FC9-437A-92AF-0EB37B2E6916}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{0DC2520C-BBAA-4A6A-89C8-58811E761A6B}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWebRepIE.dll"

[HKCR\Interface\{170125EF-36E8-412D-9402-B05F9AEF5411}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\Version]
"(Default)" = "1.0"

[HKCR\Interface\{689B356D-1C7D-42DF-9480-2B493A009BB6}\TypeLib]
"(Default)" = "{6B795924-95E7-4D31-8521-407360C3AA0B}"

[HKCR\Wow6432Node\Interface\{B674F15F-2411-438F-A87F-7897BB0C1E19}\TypeLib]
"(Default)" = "{6B795924-95E7-4D31-8521-407360C3AA0B}"

[HKCR\Interface\{B674F15F-2411-438F-A87F-7897BB0C1E19}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{24417BBE-7FC9-437A-92AF-0EB37B2E6916}\TypeLib]
"(Default)" = "{6B795924-95E7-4D31-8521-407360C3AA0B}"

[HKCR\Wow6432Node\Interface\{3856F531-CD1E-4B00-91C7-ED75EC8E7C18}]
"(Default)" = "IOneTab"

[HKCR\Wow6432Node\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWebRepIE.dll"

[HKCR\Wow6432Node\Interface\{689B356D-1C7D-42DF-9480-2B493A009BB6}]
"(Default)" = "IHttpProtocolSink"

[HKCR\Wow6432Node\CLSID\{0DC2520C-BBAA-4A6A-89C8-58811E761A6B}\Version]
"(Default)" = "1.0"

[HKCR\Wow6432Node\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\TypeLib]
"(Default)" = "{6B795924-95E7-4D31-8521-407360C3AA0B}"

[HKCR\Interface\{3856F531-CD1E-4B00-91C7-ED75EC8E7C18}]
"(Default)" = "IOneTab"

[HKCR\Interface\{689B356D-1C7D-42DF-9480-2B493A009BB6}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{170125EF-36E8-412D-9402-B05F9AEF5411}]
"(Default)" = "_IWebRepClientEvents"

The process setup___.exe:1816 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\AvastPersistentStorage]
"SfxInstProgress" = "0"

The process GoogleUpdaterService.exe:2800 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\Wow6432Node\Interface\{C07A89E4-82A3-4A29-9908-DFC9DEBF8267}]
"(Default)" = "ISilentUpdater"

[HKCR\TypeLib\{5924C60B-6D7F-4AD6-8084-24A59431C967}\1.0\HELPDIR]
"(Default)" = ""

[HKCR\Interface\{5C8CE0B5-6DA0-49A1-B675-78FD03EA3224}]
"(Default)" = "IUpdaterScheduler"

[HKCR\Interface\{5C8CE0B5-6DA0-49A1-B675-78FD03EA3224}\TypeLib]
"(Default)" = "{5924C60B-6D7F-4AD6-8084-24A59431C967}"

[HKCR\AppID\GoogleUpdaterService.exe]
"AppID" = "{61E28BF8-C02B-499F-8E7A-34C1E4A1C649}"

[HKCR\Wow6432Node\CLSID\{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}\TypeLib]
"(Default)" = "{5924C60B-6D7F-4AD6-8084-24A59431C967}"

[HKCR\GUSchedulerCtl.UpdaterScheduler]
"(Default)" = "Google Updater Scheduler class"

[HKCR\Interface\{C07A89E4-82A3-4A29-9908-DFC9DEBF8267}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\Interface\{C07A89E4-82A3-4A29-9908-DFC9DEBF8267}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{C07A89E4-82A3-4A29-9908-DFC9DEBF8267}\TypeLib]
"(Default)" = "{5924C60B-6D7F-4AD6-8084-24A59431C967}"

[HKCR\Wow6432Node\CLSID\{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}\ProgID]
"(Default)" = "GUServiceCtl.SilentUpdater.1"

[HKCR\Wow6432Node\CLSID\{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}]
"AppID" = "{61E28BF8-C02B-499F-8E7A-34C1E4A1C649}"

[HKCR\Wow6432Node\CLSID\{B53B7061-6584-46AA-A033-D610EB10BD9B}\LocalServer32]
"(Default)" = "%Program Files% (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe"

[HKCR\Wow6432Node\CLSID\{B53B7061-6584-46AA-A033-D610EB10BD9B}]
"(Default)" = "Google Updater Scheduler class"

[HKCR\Wow6432Node\Interface\{C07A89E4-82A3-4A29-9908-DFC9DEBF8267}\TypeLib]
"Version" = "1.0"

[HKCR\GUServiceCtl.SilentUpdater]
"(Default)" = "Google Silent Updater class"

[HKCR\GUServiceCtl.SilentUpdater\CLSID]
"(Default)" = "{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}"

[HKCR\Wow6432Node\CLSID\{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}]
"(Default)" = "Google Silent Updater class"

[HKCR\Interface\{5C8CE0B5-6DA0-49A1-B675-78FD03EA3224}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{B53B7061-6584-46AA-A033-D610EB10BD9B}\TypeLib]
"(Default)" = "{5924C60B-6D7F-4AD6-8084-24A59431C967}"

[HKCR\GUSchedulerCtl.UpdaterScheduler.1\CLSID]
"(Default)" = "{B53B7061-6584-46AA-A033-D610EB10BD9B}"

[HKCR\GUServiceCtl.SilentUpdater\CurVer]
"(Default)" = "GUServiceCtl.SilentUpdater.1"

[HKCR\Wow6432Node\Interface\{C07A89E4-82A3-4A29-9908-DFC9DEBF8267}\TypeLib]
"(Default)" = "{5924C60B-6D7F-4AD6-8084-24A59431C967}"

[HKCR\AppID\{61E28BF8-C02B-499F-8E7A-34C1E4A1C649}]
"LocalService" = "gusvc"

[HKCR\Wow6432Node\CLSID\{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}\LocalServer32]
"(Default)" = "%Program Files% (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe"

[HKCR\Wow6432Node\Interface\{5C8CE0B5-6DA0-49A1-B675-78FD03EA3224}]
"(Default)" = "IUpdaterScheduler"

[HKCR\AppID\{61E28BF8-C02B-499F-8E7A-34C1E4A1C649}]
"(Default)" = "gusvc"

[HKCR\TypeLib\{5924C60B-6D7F-4AD6-8084-24A59431C967}\1.0]
"(Default)" = "Google Updater Service 1.0 Type Library"

[HKCR\GUServiceCtl.SilentUpdater.1\CLSID]
"(Default)" = "{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}"

[HKCR\Wow6432Node\CLSID\{B53B7061-6584-46AA-A033-D610EB10BD9B}\VersionIndependentProgID]
"(Default)" = "GUSchedulerCtl.UpdaterScheduler"

[HKCR\Wow6432Node\CLSID\{B53B7061-6584-46AA-A033-D610EB10BD9B}]
"AppID" = "{61E28BF8-C02B-499F-8E7A-34C1E4A1C649}"

[HKCR\GUServiceCtl.SilentUpdater.1]
"(Default)" = "Google Silent Updater class"

[HKCR\Wow6432Node\Interface\{5C8CE0B5-6DA0-49A1-B675-78FD03EA3224}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{5924C60B-6D7F-4AD6-8084-24A59431C967}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Wow6432Node\Interface\{5C8CE0B5-6DA0-49A1-B675-78FD03EA3224}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{C07A89E4-82A3-4A29-9908-DFC9DEBF8267}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{5924C60B-6D7F-4AD6-8084-24A59431C967}\1.0\0\win32]
"(Default)" = "%Program Files% (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe"

[HKCR\Wow6432Node\CLSID\{B53B7061-6584-46AA-A033-D610EB10BD9B}\ProgID]
"(Default)" = "GUSchedulerCtl.UpdaterScheduler.1"

[HKCR\Interface\{5C8CE0B5-6DA0-49A1-B675-78FD03EA3224}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}\VersionIndependentProgID]
"(Default)" = "GUServiceCtl.SilentUpdater"

[HKCR\Interface\{C07A89E4-82A3-4A29-9908-DFC9DEBF8267}]
"(Default)" = "ISilentUpdater"

[HKCR\GUSchedulerCtl.UpdaterScheduler\CLSID]
"(Default)" = "{B53B7061-6584-46AA-A033-D610EB10BD9B}"

[HKCR\GUSchedulerCtl.UpdaterScheduler.1]
"(Default)" = "Google Updater Scheduler class"

[HKCR\GUSchedulerCtl.UpdaterScheduler\CurVer]
"(Default)" = "GUSchedulerCtl.UpdaterScheduler.1"

[HKCR\Wow6432Node\Interface\{5C8CE0B5-6DA0-49A1-B675-78FD03EA3224}\TypeLib]
"(Default)" = "{5924C60B-6D7F-4AD6-8084-24A59431C967}"

The Trojan deletes the following value(s) in system registry:

[HKCR\AppID\{61E28BF8-C02B-499F-8E7A-34C1E4A1C649}]
"LocalService"

The process GoogleUpdaterService.exe:1604 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Common\Google Updater\apps\swg]
"auto" = "0"

The process RegSvr64.exe:2964 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\AvastGUIProxy.GUIProxy.1\CLSID]
"(Default)" = "{429E8C83-CFF1-46CF-A211-446EF84559B7}"

[HKCR\Wow6432Node\Interface\{554EA8B8-2FA4-4AE2-B5C0-E8E3AE5E8E9C}]
"(Default)" = "IGUIProxy"

[HKCR\TypeLib\{9D902657-7F21-4329-AA09-8FFFD9948511}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\AvastGUIProxy.GUIProxyState.1]
"(Default)" = "GUIProxyState Class"

[HKCR\CLSID\{8E90925C-69DB-4260-B69B-55EE0D1BB743}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\AvastGUIProxy64.dll"
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{8E90925C-69DB-4260-B69B-55EE0D1BB743}\VersionIndependentProgID]
"(Default)" = "AvastGUIProxy.GUIProxyState"

[HKCR\AvastGUIProxy.GUIProxyState\CurVer]
"(Default)" = "AvastGUIProxy.GUIProxyState.1"

[HKCR\AvastGUIProxy.GUIProxy]
"(Default)" = "GUIProxy Class"

[HKCR\CLSID\{8E90925C-69DB-4260-B69B-55EE0D1BB743}\TypeLib]
"(Default)" = "{9D902657-7F21-4329-AA09-8FFFD9948511}"

[HKCR\Interface\{3F8A39E9-332F-46C7-AF16-BEE00F27812F}\TypeLib]
"(Default)" = "{9D902657-7F21-4329-AA09-8FFFD9948511}"

[HKCR\Interface\{554EA8B8-2FA4-4AE2-B5C0-E8E3AE5E8E9C}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{429E8C83-CFF1-46CF-A211-446EF84559B7}\VersionIndependentProgID]
"(Default)" = "AvastGUIProxy.GUIProxy"

[HKCR\Wow6432Node\Interface\{554EA8B8-2FA4-4AE2-B5C0-E8E3AE5E8E9C}\TypeLib]
"Version" = "1.0"

[HKCR\CLSID\{8E90925C-69DB-4260-B69B-55EE0D1BB743}\ProgID]
"(Default)" = "AvastGUIProxy.GUIProxyState.1"

[HKCR\Wow6432Node\Interface\{3F8A39E9-332F-46C7-AF16-BEE00F27812F}]
"(Default)" = "IGUIProxyState"

[HKCR\AvastGUIProxy.GUIProxy.1]
"(Default)" = "GUIProxy Class"

[HKCR\Interface\{554EA8B8-2FA4-4AE2-B5C0-E8E3AE5E8E9C}]
"(Default)" = "IGUIProxy"

[HKCR\Interface\{3F8A39E9-332F-46C7-AF16-BEE00F27812F}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{3F8A39E9-332F-46C7-AF16-BEE00F27812F}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{8E90925C-69DB-4260-B69B-55EE0D1BB743}]
"(Default)" = "GUIProxyState Class"

[HKCR\Wow6432Node\Interface\{554EA8B8-2FA4-4AE2-B5C0-E8E3AE5E8E9C}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{429E8C83-CFF1-46CF-A211-446EF84559B7}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\AvastGUIProxy64.dll"
"ThreadingModel" = "Apartment"

[HKCR\TypeLib\{9D902657-7F21-4329-AA09-8FFFD9948511}\1.0\0\win64]
"(Default)" = "%Program Files%\AVAST Software\Avast\AvastGUIProxy64.dll"

[HKCR\CLSID\{429E8C83-CFF1-46CF-A211-446EF84559B7}\ProgID]
"(Default)" = "AvastGUIProxy.GUIProxy.1"

[HKCR\AvastGUIProxy.GUIProxyState]
"(Default)" = "GUIProxyState Class"

[HKCR\CLSID\{429E8C83-CFF1-46CF-A211-446EF84559B7}]
"(Default)" = "GUIProxy Class"

[HKCR\Wow6432Node\Interface\{554EA8B8-2FA4-4AE2-B5C0-E8E3AE5E8E9C}\TypeLib]
"(Default)" = "{9D902657-7F21-4329-AA09-8FFFD9948511}"

[HKCR\Wow6432Node\Interface\{3F8A39E9-332F-46C7-AF16-BEE00F27812F}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{9D902657-7F21-4329-AA09-8FFFD9948511}\1.0\HELPDIR]
"(Default)" = "%Program Files%\AVAST Software\Avast"

[HKCR\Wow6432Node\Interface\{3F8A39E9-332F-46C7-AF16-BEE00F27812F}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{3F8A39E9-332F-46C7-AF16-BEE00F27812F}]
"(Default)" = "IGUIProxyState"

[HKCR\Interface\{554EA8B8-2FA4-4AE2-B5C0-E8E3AE5E8E9C}\TypeLib]
"(Default)" = "{9D902657-7F21-4329-AA09-8FFFD9948511}"

[HKCR\AppID\AvastGUIProxy.DLL]
"AppID" = "{5020EF2C-60F4-47BE-8918-A167229B11EE}"

[HKCR\Wow6432Node\Interface\{3F8A39E9-332F-46C7-AF16-BEE00F27812F}\TypeLib]
"(Default)" = "{9D902657-7F21-4329-AA09-8FFFD9948511}"

[HKCR\TypeLib\{9D902657-7F21-4329-AA09-8FFFD9948511}\1.0]
"(Default)" = "AvastGUIProxy 1.0 Type Library"

[HKCR\AppID\{5020EF2C-60F4-47BE-8918-A167229B11EE}]
"(Default)" = "AvastGUIProxy"

[HKCR\AvastGUIProxy.GUIProxyState.1\CLSID]
"(Default)" = "{8E90925C-69DB-4260-B69B-55EE0D1BB743}"

[HKCR\AvastGUIProxy.GUIProxy\CLSID]
"(Default)" = "{429E8C83-CFF1-46CF-A211-446EF84559B7}"

[HKCR\AvastGUIProxy.GUIProxy\CurVer]
"(Default)" = "AvastGUIProxy.GUIProxy.1"

[HKCR\Interface\{554EA8B8-2FA4-4AE2-B5C0-E8E3AE5E8E9C}\TypeLib]
"Version" = "1.0"

[HKCR\CLSID\{429E8C83-CFF1-46CF-A211-446EF84559B7}\TypeLib]
"(Default)" = "{9D902657-7F21-4329-AA09-8FFFD9948511}"

[HKCR\AvastGUIProxy.GUIProxyState\CLSID]
"(Default)" = "{8E90925C-69DB-4260-B69B-55EE0D1BB743}"

The process RegSvr64.exe:956 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\CLSID\{B342E21B-AD7E-4568-AE3F-D0D844537A7A}\Version]
"(Default)" = "1.0"

[HKCR\avast.AsOutExt.1\CLSID]
"(Default)" = "{B342E21B-AD7E-4568-AE3F-D0D844537A7A}"

[HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\avast.AsOutExt]
"FriendlyName" = "avast! Addin"

[HKCR\CLSID\{B342E21B-AD7E-4568-AE3F-D0D844537A7A}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{B342E21B-AD7E-4568-AE3F-D0D844537A7A}]
"(Default)" = "Addin Class"

[HKCR\CLSID\{B342E21B-AD7E-4568-AE3F-D0D844537A7A}\TypeLib]
"(Default)" = "{EDDBDEA4-5C07-453F-BE8C-81D738984381}"

[HKCR\avast.AsOutExt\CurVer]
"(Default)" = "avast.AsOutExt.1"

[HKCR\TypeLib\{EDDBDEA4-5C07-453F-BE8C-81D738984381}\1.0\0\win64]
"(Default)" = "%Program Files%\AVAST Software\Avast\asOutExt64.dll"

[HKCR\CLSID\{B342E21B-AD7E-4568-AE3F-D0D844537A7A}\ProgID]
"(Default)" = "avast.AsOutExt.1"

[HKCR\avast.AsOutExt]
"(Default)" = "Addin Class"

[HKCR\CLSID\{B342E21B-AD7E-4568-AE3F-D0D844537A7A}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\asOutExt64.dll"

[HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\avast.AsOutExt]
"CommandLineSafe" = "0"
"LoadBehavior" = "3"

[HKCR\CLSID\{B342E21B-AD7E-4568-AE3F-D0D844537A7A}\VersionIndependentProgID]
"(Default)" = "avast.AsOutExt"

[HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\avast.AsOutExt]
"Description" = "avast! Outlook Addin"

[HKCR\avast.AsOutExt.1]
"(Default)" = "Addin Class"

[HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\avast.AsOutExt]
"RequireShutdownNotification" = "1"

The process RegSvr64.exe:1012 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\CLSID\{C8D8CA8E-15CE-4143-9E3E-89294A453003}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{0EF4D762-CA12-414E-BFCB-1257EFBCB4FE}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{6BB027E1-C358-49CA-96C6-A765EEAD7008}]
"(Default)" = "BrokerServer Class"

[HKCR\CLSID\{704ECB6B-8215-4B6E-9220-6B74D64D3327}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

[HKCR\CLSID\{6BB027E1-C358-49CA-96C6-A765EEAD7008}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

[HKCR\CLSID\{F4FB18A4-CE06-4ABC-B3BD-16774A4FA95C}]
"(Default)" = "WebRep Class"

[HKCR\CLSID\{0EF4D762-CA12-414E-BFCB-1257EFBCB4FE}]
"(Default)" = "Phishing Class"

[HKCR\CLSID\{704ECB6B-8215-4B6E-9220-6B74D64D3327}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{288ABA12-FA03-4D06-AC55-6D5E28966DC2}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{72CEEE9E-0D2A-48D0-A940-5C8CB639A91B}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{F4FB18A4-CE06-4ABC-B3BD-16774A4FA95C}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{C72EA03D-BEFE-47D8-942E-8A6B6585C2DD}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{E2D61D62-743B-42A0-9D50-A4CA9945BC43}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{5CA7F0F6-F479-426C-AE5E-A434EA76BE81}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{288ABA12-FA03-4D06-AC55-6D5E28966DC2}]
"(Default)" = "Typo Class"

[HKCR\CLSID\{C8D8CA8E-15CE-4143-9E3E-89294A453003}]
"(Default)" = "Notification Class"

[HKCR\CLSID\{E2D61D62-743B-42A0-9D50-A4CA9945BC43}]
"(Default)" = "Blocker Class"

[HKCR\CLSID\{72CEEE9E-0D2A-48D0-A940-5C8CB639A91B}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{35866E0F-FEC8-4461-8593-6DD7089DCAB6}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{35866E0F-FEC8-4461-8593-6DD7089DCAB6}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{72CEEE9E-0D2A-48D0-A940-5C8CB639A91B}]
"(Default)" = "Service Class"

[HKCR\TypeLib\{6DFA2AA7-8234-46E2-A8E2-96794315C122}\1.0\0\win64]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

[HKCR\CLSID\{288ABA12-FA03-4D06-AC55-6D5E28966DC2}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{C8D8CA8E-15CE-4143-9E3E-89294A453003}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

[HKCR\CLSID\{1433A87C-BD3C-4404-AECB-44B9506DF106}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{6BB027E1-C358-49CA-96C6-A765EEAD7008}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{704ECB6B-8215-4B6E-9220-6B74D64D3327}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{5CA7F0F6-F479-426C-AE5E-A434EA76BE81}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

[HKCR\CLSID\{C72EA03D-BEFE-47D8-942E-8A6B6585C2DD}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{E3E156D0-EF1D-42C3-A24C-8798D5DC2E93}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

[HKCR\CLSID\{35866E0F-FEC8-4461-8593-6DD7089DCAB6}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

[HKCR\CLSID\{C8D8CA8E-15CE-4143-9E3E-89294A453003}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{E2D61D62-743B-42A0-9D50-A4CA9945BC43}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{5CA7F0F6-F479-426C-AE5E-A434EA76BE81}]
"(Default)" = "UrlInfoArray Class"

[HKCR\CLSID\{4C3DA18A-A416-4B52-A867-2C3DC0A415B6}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{90865748-A347-49AD-ABCA-2368F98B4820}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

[HKCR\CLSID\{72CEEE9E-0D2A-48D0-A940-5C8CB639A91B}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

[HKCR\CLSID\{C72EA03D-BEFE-47D8-942E-8A6B6585C2DD}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{4C3DA18A-A416-4B52-A867-2C3DC0A415B6}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{5CA7F0F6-F479-426C-AE5E-A434EA76BE81}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{72CEEE9E-0D2A-48D0-A940-5C8CB639A91B}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{6BB027E1-C358-49CA-96C6-A765EEAD7008}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{288ABA12-FA03-4D06-AC55-6D5E28966DC2}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{F4FB18A4-CE06-4ABC-B3BD-16774A4FA95C}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{E3E156D0-EF1D-42C3-A24C-8798D5DC2E93}]
"(Default)" = "Settings Class"

[HKCR\CLSID\{E3E156D0-EF1D-42C3-A24C-8798D5DC2E93}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{1433A87C-BD3C-4404-AECB-44B9506DF106}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{E3E156D0-EF1D-42C3-A24C-8798D5DC2E93}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{288ABA12-FA03-4D06-AC55-6D5E28966DC2}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

[HKCR\CLSID\{4C3DA18A-A416-4B52-A867-2C3DC0A415B6}]
"(Default)" = "NotificationsArray Class"

[HKCR\CLSID\{C72EA03D-BEFE-47D8-942E-8A6B6585C2DD}]
"(Default)" = "SearchColoringRule Class"

[HKCR\CLSID\{704ECB6B-8215-4B6E-9220-6B74D64D3327}]
"(Default)" = "DNTRule Class"

[HKCR\CLSID\{0EF4D762-CA12-414E-BFCB-1257EFBCB4FE}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{F4FB18A4-CE06-4ABC-B3BD-16774A4FA95C}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

[HKCR\CLSID\{0EF4D762-CA12-414E-BFCB-1257EFBCB4FE}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

[HKCR\CLSID\{1433A87C-BD3C-4404-AECB-44B9506DF106}]
"(Default)" = "Safeshop Class"

[HKCR\CLSID\{5CA7F0F6-F479-426C-AE5E-A434EA76BE81}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{4C3DA18A-A416-4B52-A867-2C3DC0A415B6}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

[HKCR\CLSID\{6BB027E1-C358-49CA-96C6-A765EEAD7008}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{E3E156D0-EF1D-42C3-A24C-8798D5DC2E93}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{35866E0F-FEC8-4461-8593-6DD7089DCAB6}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{35866E0F-FEC8-4461-8593-6DD7089DCAB6}]
"(Default)" = "BSTRArray Class"

[HKCR\CLSID\{1433A87C-BD3C-4404-AECB-44B9506DF106}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{90865748-A347-49AD-ABCA-2368F98B4820}]
"(Default)" = "UrlInfo Class"

[HKCR\CLSID\{90865748-A347-49AD-ABCA-2368F98B4820}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{90865748-A347-49AD-ABCA-2368F98B4820}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{E2D61D62-743B-42A0-9D50-A4CA9945BC43}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{4C3DA18A-A416-4B52-A867-2C3DC0A415B6}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{F4FB18A4-CE06-4ABC-B3BD-16774A4FA95C}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{90865748-A347-49AD-ABCA-2368F98B4820}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{C8D8CA8E-15CE-4143-9E3E-89294A453003}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{704ECB6B-8215-4B6E-9220-6B74D64D3327}\TypeLib]
"(Default)" = "{6DFA2AA7-8234-46E2-A8E2-96794315C122}"

[HKCR\CLSID\{0EF4D762-CA12-414E-BFCB-1257EFBCB4FE}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{1433A87C-BD3C-4404-AECB-44B9506DF106}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

[HKCR\CLSID\{E2D61D62-743B-42A0-9D50-A4CA9945BC43}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWrcIEBroker64.dll"

The process RegSvr64.exe:1176 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00AB3925-B470-4264-B354-03E373074F23}]
"AppName" = "aswWrcIELoader32.exe"
"Policy" = "3"

[HKCR\CLSID\{0DC2520C-BBAA-4A6A-89C8-58811E761A6B}]
"(Default)" = "BHOWorkerThread Class"

[HKCR\CLSID\{FAB4DAA3-9B61-488C-ACD5-BD33DA07FF87}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{FAB4DAA3-9B61-488C-ACD5-BD33DA07FF87}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWebRepIE64.dll"

[HKCR\CLSID\{0DC2520C-BBAA-4A6A-89C8-58811E761A6B}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\TypeLib]
"(Default)" = "{6B795924-95E7-4D31-8521-407360C3AA0B}"

[HKCR\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\Implemented Categories]
"(Default)" = ""

[HKCR\CLSID\{0DC2520C-BBAA-4A6A-89C8-58811E761A6B}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWebRepIE64.dll"

[HKCR\CLSID\{0DC2520C-BBAA-4A6A-89C8-58811E761A6B}\TypeLib]
"(Default)" = "{aswWrcIELibUUID}"

[HKCR\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{FAB4DAA3-9B61-488C-ACD5-BD33DA07FF87}\InprocServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWebRepIE64.dll"

[HKCR\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
"(Default)" = ""

[HKCR\CLSID\{0DC2520C-BBAA-4A6A-89C8-58811E761A6B}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\TypeLib\{6B795924-95E7-4D31-8521-407360C3AA0B}\1.0\0\win64]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswWebRepIE64.dll"

[HKCR\CLSID\{FAB4DAA3-9B61-488C-ACD5-BD33DA07FF87}\TypeLib]
"(Default)" = "{aswWrcIELibUUID}"

[HKCR\CLSID\{FAB4DAA3-9B61-488C-ACD5-BD33DA07FF87}]
"(Default)" = "BHOWorkerThreadTask Class"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00AB3925-B470-4264-B354-03E373074F23}]
"AppPath" = "%Program Files%\AVAST Software\Avast\"

[HKCR\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
"(Default)" = "avast! Online Security"

It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
"(Default)" = "avast! Online Security"

"NoExplorer" = "1"

The process googletoolbarinstaller_en_signed.exe:2660 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Branding]
"sin" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Component]
"NextVersion" = "7.5.6227.252"
"currentVersion" = "7.5.6227.252"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Branding]
"ein" = "1"

[HKCU\Software\Google\Google Toolbar\4.0\Setup]
"InstallProgress" = "3"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 44 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "25 CC 85 1E BF 72 D0 01"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar]
"test" = "41"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\4.0\Setup]
"EnabledExperiments" = "POSI,PUMA"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

[HKCU\Software\Google\Google Toolbar\4.0\Setup]
"Command" = "2"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\4.0\Setup]
"FirstInstallTime" = "1429869682"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Google\Google Toolbar]
"LastInstallError"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Component]
"NextVersion"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Component]
"PrimaryInstallDone"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\4.0\Setup]
"FailedInstallPing"

The process instup.exe:3916 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupLog" = "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"RestartSuspendCounter"

The process instup.exe:1544 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"GadgetFolder" = "\??\%Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget"

[HKCR\Wow6432Node\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}\InProcServer32]
"ReleaseName" = "%Program Files%\AVAST Software\Avast\ashShell.dll"

[HKCR\AvastPersistentStorage]
"InstupProgress_Title" = "Installing the product"

[HKLM\System\CurrentControlSet\services\aswMonFlt]
"ImagePath" = "\SystemRoot\system32\drivers\aswMonFlt.sys"

[HKCR\Wow6432Node\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}\InProcServer32]
"ThreadingModel" = "Apartment"

[HKCR\avast\ShellEx\ContextMenuHandlers]
"(Default)" = "{472083B0-C522-11CF-8763-00608CC02F24}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_none_465fa0e2615861d0\11.0]
"11.0.60610.1" = "01"

[HKLM\System\CurrentControlSet\services\aswSP]
"Description" = "avast! Self Protection"

[HKCR\avastthemefile]
"(Default)" = "avast! theme file"

[HKCR\Folder\ShellEx\ContextMenuHandlers\avast]
"(Default)" = "{472083B0-C522-11CF-8763-00608CC02F24}"

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%Program Files% (x86)\Google\Update\1.3.25.11, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\nsSCM.dll, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\, , \??\%Program Files%\AVAST Software\Avast\setup\SnxReboot.txt,"

[HKCR\AvastPersistentStorage]
"InstupProgress_Description" = "Checking install conditions"

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupLog" = "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log"

[HKLM\System\CurrentControlSet\services\aswSnx\Parameters]
"datafolder" = "\??\C:\ProgramData\AVAST Software\Avast"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Avast]
"VersionMinor" = "2"

[HKLM\System\CurrentControlSet\services\aswRdr]
"ImagePath" = "\SystemRoot\system32\drivers\aswRdr2.sys"

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"ProgramFilesFolder" = "\??\%Program Files%"

[HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}\InProcServer32]
"ReleaseName" = "%Program Files%\AVAST Software\Avast\ashShA64.dll"

[HKCR\.avastvpn]
"Content Type" = "application/avast-avastvpn"

[HKLM\System\CurrentControlSet\Services\aswVmm]
"Description" = "avast! VM Monitor"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc110.crt_2036b14a11e83e4a_none_0b20a8ff883c3a4a]
"(Default)" = "11.0"

[HKCR\AvastPersistentStorage]
"Guid" = "1b9818a2-3789-4442-9fc3-714a6e217daf"

[HKLM\System\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance]
"Altitude" = "137600"

[HKLM\System\CurrentControlSet\services\aswSnx\Parameters]
"ProgramFolder" = "\??\%Program Files%\AVAST Software\Avast"

[HKCR\.avasttheme]
"Content Type" = "application/avast-theme"

[HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Version" = "10.2.0.187"

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupVersion" = "2218"

[HKCR\AllFilesystemObjects\shellex\ContextMenuHandlers\00avast]
"(Default)" = "{472083B0-C522-11CF-8763-00608CC02F24}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_none_5679bb9c25dbf18d\11.0]
"11.0.60610.1" = "01"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Avast]
"Publisher" = "AVAST Software"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc110.crt_2036b14a11e83e4a_none_c373722873c01144]
"(Default)" = "11.0"

[HKCR\avastthemefile]
"BrowserFlags" = "8"

[HKCR\avastlicfile\shell\open\command]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswChLic.exe %1"

[HKCR\avastconfigfile\shell\open\command]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswChLic.exe %1"

[HKCR\Wow6432Node\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}\InProcServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\ashShell.dll"

[HKLM\System\CurrentControlSet\services\aswHwid]
"ImagePath" = "\SystemRoot\system32\drivers\aswHwid.sys"

[HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}\InProcServer32]
"ThreadingModel" = "Apartment"

[HKLM\System\CurrentControlSet\services\avast! Antivirus]
"Description" = "Manages and implements Avast antivirus services for this computer. This includes the real-time shields, the virus chest and the scheduler."

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"Registration" = "C6 FF C6 FF C6 FF C6 FF C6 FF C6 FF C6 FF C6 FF"

[HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}\InProcServer32]
"(Default)" = "%Program Files%\AVAST Software\Avast\ashShA64.dll"

[HKCR\avastthemefile]
"EditFlags" = "65536"

[HKLM\System\CurrentControlSet\services\aswMonFlt\Instances]
"DefaultInstance" = "aswMonFlt Instance"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"

[HKLM\System\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance]
"Flags" = "0"

[HKCR\avastvpnfile]
"(Default)" = "avast! SecureLine License"

[HKCR\avastconfigfile]
"(Default)" = "avast! config file"

[HKLM\System\CurrentControlSet\services\aswSP\Instances\aswSP Instance]
"Altitude" = "388400"

[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_none_465fa0e2615861d0\11.0]
"(Default)" = "11.0.60610.1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"

[HKCR\.avasttheme]
"(Default)" = "avastthemefile"

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"datafolder" = "\??\C:\ProgramData\AVAST Software\Avast"

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupFolder" = "%Program Files%\AVAST Software\Avast\setup"

[HKCR\Wow6432Node\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
"(Default)" = "avast"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Avast]
"InstallSource" = "%Program Files%\AVAST Software\Avast\Setup"

[HKCR\*\shellex\ContextMenuHandlers\avast]
"(Default)" = "{472083B0-C522-11CF-8763-00608CC02F24}"

[HKCR\avastsoundsfile\shell\open\command]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswChLic.exe %1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_none_465fa0e2615861d0]
"(Default)" = "11.0"

[HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
"(Default)" = "avast"

[HKLM\System\CurrentControlSet\services\aswSP]
"ImagePath" = "\SystemRoot\system32\drivers\aswSP.sys"

[HKCR\.avastsounds]
"(Default)" = "avastsoundsfile"

[HKLM\System\CurrentControlSet\services\aswRdr]
"Description" = "avast! WFP Redirect driver"

[HKLM\System\CurrentControlSet\services\aswStm]
"ImagePath" = "\SystemRoot\system32\drivers\aswStm.sys"

[HKCR\.avastlic]
"Content Type" = "application/avast-license"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc110.crt_2036b14a11e83e4a_none_0b20a8ff883c3a4a\11.0]
"(Default)" = "11.0.60610.1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_none_5679bb9c25dbf18d\11.0]
"(Default)" = "11.0.60610.1"

[HKLM\System\CurrentControlSet\services\aswMonFlt]
"Description" = "avast! mini-filter driver (aswMonFlt)"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc110.crt_2036b14a11e83e4a_none_c373722873c01144\11.0]
"(Default)" = "11.0.60610.1"

[HKCR\avastvpnfile\shell\open\command]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswChLic.exe %1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Avast]
"UninstallString" = "%Program Files%\AVAST Software\Avast\Setup\Instup.exe /control_panel /instop:uninstall"

[HKCR\avastsoundsfile]
"BrowserFlags" = "8"

[HKCR\AvastPersistentStorage]
"GuidCreated" = "1429869521"

[HKLM\System\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance]
"Flags" = "0"

[HKCR\avastlicfile]
"BrowserFlags" = "8"

[HKCR\avastvpnfile]
"EditFlags" = "65536"

[HKCR\avastlicfile]
"EditFlags" = "65536"

[HKCR\avastconfigfile]
"EditFlags" = "65536"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Avast]
"DisplayName" = "Avast Free Antivirus"

[HKLM\System\CurrentControlSet\services\aswSP\Instances\aswSP Instance]
"Flags" = "0"

[HKCR\avastconfigfile]
"BrowserFlags" = "8"

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"datafolder" = "C:\ProgramData\AVAST Software\Avast"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Avast]
"InstallLocation" = "%Program Files%\AVAST Software\Avast"

[HKLM\System\CurrentControlSet\services\aswHwid]
"Description" = "avast! HardwareID"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast]
"(Default)" = "{472083B0-C522-11CF-8763-00608CC02F24}"

[HKCR\avastthemefile\shell\open\command]
"(Default)" = "%Program Files%\AVAST Software\Avast\aswChLic.exe %1"

[HKCR\AvastPersistentStorage]
"InstupProgress_Installation_Syncer" = "0"

[HKCR\.avastconfig]
"Content Type" = "application/avast-config"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"SoftwareSASGeneration" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Avast]
"DisplayVersion" = "10.2.2218"

[HKCR\AvastPersistentStorage]
"InstupProgress_Installation_Main" = "0"

[HKCR\.avastlic]
"(Default)" = "avastlicfile"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc110.crt_2036b14a11e83e4a_none_c373722873c01144\11.0]
"11.0.60610.1" = "01"

[HKCR\Wow6432Node\CLSID\{3D85851B-40FE-4472-9722-6F69B5517476}\InprocServer32]
"(Default)" = "C:\Windows\SysWow64\urlmon.dll"

[HKLM\System\CurrentControlSet\services\aswSnx]
"Description" = "avast! virtualization driver (aswSnx)"

[HKLM\System\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance]
"Altitude" = "320700"

[HKLM\System\CurrentControlSet\services\aswSnx\Instances]
"DefaultInstance" = "aswSnx Instance"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Avast]
"DisplayIcon" = "%Program Files%\AVAST Software\Avast\AvastUI.exe"

[HKCR\avastsoundsfile]
"EditFlags" = "65536"
"(Default)" = "avast! soundpack file"

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"ProgramFolder" = "\??\%Program Files%\AVAST Software\Avast"

[HKLM\SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com" = "%Program Files%\AVAST Software\Avast\WebRep\FF"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_none_5679bb9c25dbf18d]
"(Default)" = "11.0"

[HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"update_url" = "https://clients2.google.com/service/update2/crx"

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"Version" = "10.2"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Avast]
"VersionMajor" = "10"
"ModifyPath" = "%Program Files%\AVAST Software\Avast\Setup\Instup.exe /control_panel /instop:change"

[HKCR\.avastvpn]
"(Default)" = "avastvpnfile"

[HKCR\Wow6432Node\CLSID\{3D85851B-40FE-4472-9722-6F69B5517476}]
"(Default)" = "Internet Explorer URL Monitor Extensions"

[HKCR\.avastsounds]
"Content Type" = "application/avast-sounds"

[HKLM\System\CurrentControlSet\services\aswSP\Instances]
"DefaultInstance" = "aswSP Instance"

[HKCR\.avastconfig]
"(Default)" = "avastconfigfile"

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"RestartSuspendCounter" = "1"

[HKCR\avastlicfile]
"(Default)" = "avast! license file"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\42857855FB0EA43F54C9911E30E7791D8CE82705]
"Blob" = "03 00 00 00 01 00 00 00 14 00 00 00 42 85 78 55"

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"ProgramFolder" = "%Program Files%\AVAST Software\Avast"

[HKLM\System\CurrentControlSet\services\aswStm]
"Description" = "avast! StreamFilter Callout Driver"

[HKCR\avastvpnfile]
"BrowserFlags" = "8"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc110.crt_2036b14a11e83e4a_none_0b20a8ff883c3a4a\11.0]
"11.0.60610.1" = "01"

[HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Path" = "%Program Files%\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx"

[HKCR\Wow6432Node\CLSID\{3D85851B-40FE-4472-9722-6F69B5517476}\MiscStatus]
"Status" = "397186"

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"RegData" = "0C 11 B3 B4 66 11 B3 B4 66 11 B3 B4 66 11 B3 B4"

[HKLM\System\CurrentControlSet\services\aswSnx]
"ImagePath" = "\SystemRoot\system32\drivers\aswSnx.sys"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe" = "%Program Files%\AVAST Software\Avast\AvastUI.exe /nogui"

The Trojan deletes the following registry key(s):

[HKLM\System\CurrentControlSet\Services\aswProbeKey]

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\aswSP]
"WOW64"

[HKLM\System\CurrentControlSet\services\aswRdr]
"DeleteFlag"

[HKLM\System\CurrentControlSet\services\avast! Antivirus]
"DeleteFlag"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates]
"42857855FB0EA43F54C9911E30E7791D8CE82705"

[HKLM\System\CurrentControlSet\Services\aswVmm]
"WOW64"

[HKLM\System\CurrentControlSet\services\aswStm]
"WOW64"

[HKLM\System\CurrentControlSet\services\aswMonFlt]
"DeleteFlag"

[HKLM\System\CurrentControlSet\services\aswRvrt]
"WOW64"

[HKLM\System\CurrentControlSet\services\aswHwid]
"DeleteFlag"

[HKLM\System\CurrentControlSet\Services\aswVmm]
"DeleteFlag"

[HKLM\System\CurrentControlSet\services\aswStm]
"DeleteFlag"

[HKLM\System\CurrentControlSet\services\aswSnx]
"WOW64"
"DeleteFlag"

[HKLM\System\CurrentControlSet\services\aswRvrt]
"ImagePath"

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"LicenseFile"

[HKLM\System\CurrentControlSet\services\aswSP]
"DeleteFlag"

[HKLM\System\CurrentControlSet\services\aswRvrt]
"DeleteFlag"

[HKLM\System\CurrentControlSet\services\aswRdr]
"WOW64"

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"UpdateVersion"

[HKLM\System\CurrentControlSet\Services\aswVmm]
"ImagePath"

[HKLM\System\CurrentControlSet\services\aswMonFlt]
"WOW64"

[HKLM\System\CurrentControlSet\services\aswHwid]
"WOW64"

The Trojan disables automatic startup of the application by deleting the following autorun value:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast5"

"avast"

The process instup.exe:4084 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupLog" = "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"RestartSuspendCounter"

The process instup.exe:3784 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupLog" = "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"RestartSuspendCounter"

The process instup.exe:2812 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\AvastPersistentStorage]
"InstupProgress_Description" = "Downloading file: servers.def.vpx.dld"
"InstupProgress_Title" = "Updating the product"
"InstupProgress_UpdateSetup_Syncer" = "0"

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupLog" = "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log"

[HKCR\AvastPersistentStorage]
"InstupProgress_UpdateSetup_Main" = "0"

The process instup.exe:3376 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupLog" = "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"RestartSuspendCounter"

The process instup.exe:3756 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupLog" = "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"RestartSuspendCounter"

The process instup.exe:3584 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupLog" = "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"RestartSuspendCounter"

The process instup.exe:3708 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupLog" = "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"RestartSuspendCounter"

The process instup.exe:3412 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupLog" = "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"RestartSuspendCounter"

The process instup.exe:4012 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupLog" = "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"RestartSuspendCounter"

The process instup.exe:3368 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupLog" = "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"RestartSuspendCounter"

The process instup.exe:3296 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupLog" = "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"RestartSuspendCounter"

The process instup.exe:3176 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"SetupLog" = "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\aswSP\Parameters]
"RestartSuspendCounter"

The process SearchWithGoogleUpdate_6F4EEAE8D7FCDAD8.exe:1368 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\GoogleToolbarNotifier]
"Version" = "5.10.11023.1534"
"ID" = "7a84db8082774391b17b4432f8f57454"

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%Program Files% (x86)\Google\Update\1.3.25.11, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\nsSCM.dll, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\, , \??\%Program Files%\AVAST Software\Avast\setup\SnxReboot.txt, , \??\%Program Files%\AVAST Software\Avast\setup, , \??\%Program Files%\AVAST Software\Avast\setup\settings-8aa.ori, , \??\%Program Files%\AVAST Software\Avast\setup, , \??\%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534,"

[HKCU\Software\Google\GoogleToolbarNotifier\Temp]
"ust" = "100"

[HKLM\SOFTWARE\Wow6432Node\Google\GoogleToolbarNotifier\Clients]
"ietb" = "0"

[HKLM\SOFTWARE\Wow6432Node\Google\GoogleToolbarNotifier]
"brand" = "AVNH"

The Trojan deletes the following registry key(s):

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]

The process AvastSvc.exe:832 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\SystemCertificates\avast! SSL Scanner Cache\Certificates\2BC1DD5944956B56E69A0955107E80D83CE04750]
"Blob" = "03 00 00 00 01 00 00 00 14 00 00 00 2B C1 DD 59"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\42857855FB0EA43F54C9911E30E7791D8CE82705]
"Blob" = "04 00 00 00 01 00 00 00 10 00 00 00 C6 8B 99 30"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\avast! SSL Scanner Cache\Certificates\99ED84453B939925E7FDA58E25D90EE3AD38DA40]
"Blob" = "03 00 00 00 01 00 00 00 14 00 00 00 99 ED 84 45"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A38E2AA3FFB487795E0522BFBD2E783C73493A54]
"Blob" = "03 00 00 00 01 00 00 00 14 00 00 00 A3 8E 2A A3"

[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\System\CurrentControlSet\services\avast! Antivirus]
"Group" = "ShellSvcGroup"

[HKLM\System\CurrentControlSet\services\aswRdr\Parameters]
"MSIgnoreLSPDefault" = ""

[HKLM\SOFTWARE\Microsoft\SystemCertificates\avast! SSL Scanner Cache\Certificates\A38E2AA3FFB487795E0522BFBD2E783C73493A54]
"Blob" = "03 00 00 00 01 00 00 00 14 00 00 00 A3 8E 2A A3"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\SystemCertificates\avast! SSL Scanner Cache\Certificates]
"99ED84453B939925E7FDA58E25D90EE3AD38DA40"
"2BC1DD5944956B56E69A0955107E80D83CE04750"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates]
"A38E2AA3FFB487795E0522BFBD2E783C73493A54"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates]
"42857855FB0EA43F54C9911E30E7791D8CE82705"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\avast! SSL Scanner Cache\Certificates]
"A38E2AA3FFB487795E0522BFBD2E783C73493A54"

The process regsvr32.exe:1636 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\ProgID]
"(Default)" = "ProtectorExe.ProtectorHost.1"

[HKCR\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}]
"(Default)" = "ProtectorHost Class"

[HKCR\protector_dll.ProtectorBho\CurVer]
"(Default)" = "protector_dll.ProtectorBho.1"

[HKCR\protector_dll.ProtectorLib\CurVer]
"(Default)" = "protector_dll.ProtectorLib.1"

[HKCR\AppID\{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}]
"(Default)" = "protector_dll"

[HKCR\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}]
"(Default)" = "ProtectorLib Class"

[HKCR\protector_dll.ProtectorBho.1\CLSID]
"(Default)" = "{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}"

[HKCR\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\VersionIndependentProgID]
"(Default)" = "protector_dll.ProtectorLib"

[HKCR\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\VersionIndependentProgID]
"(Default)" = "protector_dll.ProtectorBho"

[HKCR\protector_dll.ProtectorBho.1]
"(Default)" = "Google Toolbar Notifier BHO"

[HKCR\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\protector_dll.ProtectorLib\CLSID]
"(Default)" = "{84798B8E-69F8-4846-9516-373C2996E2F7}"

[HKCR\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\protector_dll.ProtectorLib.1\CLSID]
"(Default)" = "{84798B8E-69F8-4846-9516-373C2996E2F7}"

[HKCR\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}]
"AppID" = "{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}"

[HKCR\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}]
"AppID" = "{A97CA128-6998-4F8E-807E-8ED05FADAFB0}"

[HKCR\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\InprocServer32]
"(Default)" = "%Program Files%\Google\GoogleToolbarNotifier\5.10.11023.1534\swg64.dll"

[HKCR\protector_dll.ProtectorLib]
"(Default)" = "ProtectorLib Class"

[HKCR\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}]
"Depend" = "%Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\gtn.dll"

[HKCR\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\ProgID]
"(Default)" = "protector_dll.ProtectorLib.1"

[HKCR\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\VersionIndependentProgID]
"(Default)" = "ProtectorExe.ProtectorHost"

[HKCR\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\LocalServer32]
"(Default)" = "%Program Files% (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

[HKCR\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
"AppID" = "{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}"

[HKCR\protector_dll.ProtectorLib.1]
"(Default)" = "ProtectorLib Class"

[HKCR\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ProgID]
"(Default)" = "protector_dll.ProtectorBho.1"

[HKCR\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\TypeLib]
"(Default)" = "{C7CB459A-7261-4AE6-A87A-17041EE98A40}"

[HKCR\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
"(Default)" = "Google Toolbar Notifier BHO"

[HKCR\protector_dll.ProtectorBho]
"(Default)" = "Google Toolbar Notifier BHO"

[HKCR\AppID\protector_dll.DLL]
"AppID" = "{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}"

[HKCR\protector_dll.ProtectorBho\CLSID]
"(Default)" = "{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}"

[HKCR\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\InprocServer32]
"(Default)" = "%Program Files%\Google\GoogleToolbarNotifier\5.10.11023.1534\swg64.dll"

The process %original file name%.exe:1824 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process BackupSetup.exe:536 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%Program Files% (x86)\Google\Update\1.3.25.11, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\nsSCM.dll,"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OLBPre]
"DisplayVersion" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OLBPre]
"DisplayName" = "MyPC Backup"
"DisplayIcon" = "%Program Files% (x86)\OLBPre\uninst.exe"
"Publisher" = "MyPC Backup"
"HelpLink" = "http://support.mypcbackup.com"
"URLInfoAbout" = "http://www.mypcbackup.com"
"UninstallString" = "%Program Files% (x86)\OLBPre\uninst.exe"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process 9fc49b8a-7b2d-463c-978b-474af67c44b7.exe:2792 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "7A 9A 94 9F 75 7E D0 01"
"WpadDecisionReason" = "1"
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 46 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
"AutoDetect"

The process AvastEmUpdate.exe:2412 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 45 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Wow6432Node\AVAST Software\Avast]
"Patches" = "229=1429869687"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
"AutoDetect"

The process GoogleToolbarManager_BA9226F4C70BECC2.exe:2636 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Component\NonManifest\C:\ProgramData\Google\Custom Buttons]
"toolbar.google.com_O8Y91YHB24Z6SR0SGYSK.XML" = "1"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Component\Used]
"GoogleToolbarDynamic_mui_en.dll" = "1"

The process GoogleToolbarManager_BA9226F4C70BECC2.exe:2412 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Component\Used]
"GoogleToolbarManager.exe" = "1"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"pv" = "7.5.6227.252"

The process GoogleToolbarManager_BA9226F4C70BECC2.exe:2064 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
"(Default)" = "Google Toolbar Helper"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]
"DisplayVersion" = "7.5.6227.252"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\4.0\Setup]
"ToastOfferTime" = "0"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Installations]
"1429869681" = "v=7.5.6227.252&tbbrand=AVNH&i=0"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE0B94B9-335F-4d2c-8B43-DACCD1EA6FF1}]
"AppPath" = "%Program Files% (x86)\Google\Google Toolbar"

[HKCR\Wow6432Node\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
"(Default)" = "Google Toolbar Helper"

[HKCR\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}\InprocServer32]
"(Default)" = "%Program Files% (x86)\Google\Google Toolbar\GoogleToolbar_64.dll"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\4.0\Setup]
"SystemPatchLevel" = "1"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\GoogleUpdate]
"InstallTimestamp" = "1429869678"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1A972DAF-A7EC-4ce3-B6C9-7B523CD6685F}]
"Policy" = "3"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE0B94B9-335F-4d2c-8B43-DACCD1EA6FF1}]
"Policy" = "3"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]
"Publisher" = "Google Inc."

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Component\Used]
"GoogleUpdaterService.exe" = "1"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = "00"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Branding]
"InstallType" = "3"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE0B94B9-335F-4d2c-8B43-DACCD1EA6FF1}]
"AppName" = "GoogleToolbarUser_64.exe"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = "00"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\4.0\Setup]
"AllowInteractions" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]
"DisplayName" = "Google Toolbar for Internet Explorer"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1A972DAF-A7EC-4ce3-B6C9-7B523CD6685F}]
"AppPath" = "%Program Files% (x86)\Google\Google Toolbar"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\4.0\Setup]
"EnableUsageStats" = "1"

[HKCR\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}\InprocServer32]
"(Default)" = "%Program Files% (x86)\Google\Google Toolbar\GoogleToolbar_64.dll"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1A972DAF-A7EC-4ce3-B6C9-7B523CD6685F}]
"AppName" = "GoogleToolbarUser_32.exe"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]
"UninstallString" = "%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe /uninstall"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE0B94B9-335F-4d2c-8B43-DACCD1EA6FF1}]
"AppName" = "GoogleToolbarUser_64.exe"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Component\Used]
"SearchWithGoogleUpdate.exe" = "1"

[HKCU\Software\Google\Google Toolbar\4.0\Options]
"{14C626CA-ACAB-46e5-8A99-53C9E11CCCA0}_enabled" = "0"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Branding]
"InstallTime" = "1429869678"

[HKCR\Installer\Products\18555481990E8AB4CBB63FB4F26006C0]
"AuthorizedLUAApp" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]
"DisplayIcon" = "%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"cmd_7.5.6227.252_7" = "%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe /execute:7"

[HKCU\Software\Google\Google Toolbar\4.0\Options]
"ButtonPageRank" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1A972DAF-A7EC-4ce3-B6C9-7B523CD6685F}]
"AppPath" = "%Program Files% (x86)\Google\Google Toolbar"

[HKCU\Software\Google\Google Toolbar\4.0\Options]
"ToastSetDefaultSearch" = "3"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar]
"test" = "41"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1A972DAF-A7EC-4ce3-B6C9-7B523CD6685F}]
"AppName" = "GoogleToolbarUser_32.exe"

[HKCR\Wow6432Node\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]
"(Default)" = "Google Toolbar"

[HKCR\Wow6432Node\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Google\Google Toolbar\4.0\Options]
"ToastSetPageRank" = "2"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\GoogleUpdate]
"InstallResult" = "pi"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"cmd_7.5.6227.252_5" = "%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe /execute:5"

[HKCR\Wow6432Node\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\4.0\Setup]
"EulaAccepted" = "1"

[HKCU\Software\Microsoft\Internet Explorer\Main]
"Enable Browser Extensions" = "yes"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE0B94B9-335F-4d2c-8B43-DACCD1EA6FF1}]
"Policy" = "3"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E\@%SystemRoot%\system32]
"dnsapi.dll,-103" = "Domain Name System (DNS) Server Trust"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]
"Compatibility Flags" = "1024"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"cmd_7.5.6227.252_9" = "%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe /execute:9"
"cmd_7.5.6227.252_8" = "%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe /execute:8"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Component\Used]
"GoogleToolbarManager.exe" = "1"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"cmd_7.5.6227.252_6" = "%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe /execute:6"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Branding]
"brand" = "AVNH"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"cmd_7.5.6227.252_4" = "%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe /execute:4"
"cmd_7.5.6227.252_3" = "%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe /execute:3"
"cmd_7.5.6227.252_2" = "%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe /execute:2"
"cmd_7.5.6227.252_1" = "%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe /execute:1"
"cmd_7.5.6227.252_0" = "%Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe /execute:0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1A972DAF-A7EC-4ce3-B6C9-7B523CD6685F}]
"Policy" = "3"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E\@%SystemRoot%\system32]
"p2pcollab.dll,-8042" = "Peer to Peer Trust"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Component]
"PrimaryInstallDone" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]
"Compatibility Flags" = "1024"

[HKCU\Software\Google\Google Toolbar\4.0\Options]
"ToastSetHomePage" = "3"
"BrowseByName" = "0"
"RbbsBreak" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"GTB7.5" = ""

[HKCR\Wow6432Node\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}\InprocServer32]
"(Default)" = "%Program Files% (x86)\Google\Google Toolbar\GoogleToolbar_32.dll"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"GTB7.5" = ""

[HKCU\Software\Google\Google Toolbar\4.0\Options]
"UsageStatsEnabled" = "1"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\4.0\Setup]
"DisableBrowseByName" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]
"MinorVersion" = "5"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"Name" = "Google Toolbar"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\Branding]
"ID" = "94394E1F1F38CEBAA4CC598C9A5F7962A4932kYVRG"

[HKCR\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]
"InstallLocation" = "%Program Files% (x86)\Google\Google Toolbar\"
"NoModify" = "1"
"MajorVersion" = "7"
"NoRepair" = "1"

[HKCR\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]
"(Default)" = "Google Toolbar"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"brand" = "AVNH"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE0B94B9-335F-4d2c-8B43-DACCD1EA6FF1}]
"AppPath" = "%Program Files% (x86)\Google\Google Toolbar"

[HKCR\Wow6432Node\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}\InprocServer32]
"(Default)" = "%Program Files% (x86)\Google\Google Toolbar\GoogleToolbar_32.dll"

The Trojan deletes the following registry key(s):

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories64\{00021493-0000-0000-C000-000000000046}]
[HKCR\Wow6432Node\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ProgID]
[HKCR\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\TypeLib]
[HKCR\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\Programmable]
[HKCR\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\InprocServer32]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories64\{00021493-0000-0000-C000-000000000046}\Enum]
[HKCR\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\VersionIndependentProgID]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]
[HKCU\Software\Classes\Local Settings\MuiCache\2C]
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
[HKCR\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ProgID]
[HKCR\Wow6432Node\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\TypeLib]
[HKCR\Wow6432Node\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\VersionIndependentProgID]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021494-0000-0000-C000-000000000046}\Enum]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021494-0000-0000-C000-000000000046}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021493-0000-0000-C000-000000000046}]
[HKCR\Wow6432Node\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\Programmable]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories64\{00021494-0000-0000-C000-000000000046}]
[HKCR\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories64\{00021494-0000-0000-C000-000000000046}\Enum]
[HKCR\Wow6432Node\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKCR\Wow6432Node\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\InprocServer32]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021493-0000-0000-C000-000000000046}\Enum]

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\4.0\Setup]
"UseIe64"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"

[HKCU\Software\Google\Google Toolbar\4.0\Options]
"Vendor"

[HKCU\Software\Google\Google Toolbar\4.0]
"Update"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\4.0\Setup]
"RefreshIE"

[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}]
"lang"

[HKLM\SOFTWARE\Wow6432Node\Google\Google Toolbar\4.0\Setup]
"WelcomePage"

Dropped PE files

MD5 File path
5d4bc124faae6730ac002cdb67bf1a1c c:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
786996ff4ea890b9f43ed68dd55ffd7b c:\Program Files (x86)\Google\Google Toolbar\Component\GoogleCld_187F9D811452062B.dll
c74e54032b25934882f5da142135f6e4 c:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_32_75A7C54F0BE42E8E.dll
d257b5fafad4fe93cd13ac792bf9b152 c:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_64_2AD99D2EA038D2F2.dll
d59b2b86e3b0f21c42700cb4f60c8f4d c:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_0A4439FF67F61065.dll
327c893aa5966ac436ca275f8d64c8c0 c:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe
adf24d7a7195453f85e2f5cef3cbcc33 c:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarUser_32_52E818EF81C83A9B.exe
852fd4db3205ff0cb6d8f473776f99b1 c:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarUser_64_4D9709C1FA1422BA.exe
aa9bc44f6d065f76902e516d0b45db6d c:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbar_32_3934E923EEC91A78.dll
ba214814e91a9eae3eeeaed77841f82a c:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbar_64_62C1B48EAF0FD125.dll
1f2afab903c0d48480561f3bbd4539c2 c:\Program Files (x86)\Google\Google Toolbar\Component\GoogleUpdateSetup_5CC4B0F53D73AD88.exe
4beaf576cb43358c4db9f45ac7c09cdb c:\Program Files (x86)\Google\Google Toolbar\Component\GoogleUpdaterService_B33FC4DD36A473C6.exe
78206b34bd050db564bf5b4b8c697925 c:\Program Files (x86)\Google\Google Toolbar\Component\SearchWithGoogleUpdate_6F4EEAE8D7FCDAD8.exe
adf24d7a7195453f85e2f5cef3cbcc33 c:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
852fd4db3205ff0cb6d8f473776f99b1 c:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_64.exe
aa9bc44f6d065f76902e516d0b45db6d c:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
ba214814e91a9eae3eeeaed77841f82a c:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
34c575178bacadb9744f3fb7f86b5ee3 c:\Program Files (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\gth.dll
c9188d8d26ceedbe77fa96f128f10fec c:\Program Files (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\gtn.dll
68ba0437b07cd40c453c606dd762f6e0 c:\Program Files (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll
5d61be7db55b026a5d61a3eed09d0ead c:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
5050eb8b35a2ec4e17772690bb3e815c c:\Program Files (x86)\Google\Update\Download\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\0.0.0.0\googletoolbarinstaller_en_signed.exe
5050eb8b35a2ec4e17772690bb3e815c c:\Program Files (x86)\Google\Update\Install\{A7B6D392-0D13-454B-A517-CBD6C019C7CC}\googletoolbarinstaller_en_signed.exe
e5cc3997457cd365e43c19f0f9110148 c:\Program Files (x86)\OLBPre\LinqBridge.dll
e409cbd276b76296e21296c399077964 c:\Program Files (x86)\OLBPre\OLBPre.exe
660605e24b0cf1068bfbb4a4ec647652 c:\Program Files (x86)\OLBPre\uninst.exe
7739c76e103fa520a01d5745c6f0d836 c:\Program Files\AVAST Software\Avast\1033\BCULangRes_1033.dll
5d5e0b26bd4925967e795006452d9c64 c:\Program Files\AVAST Software\Avast\1033\Base.dll
d0ce8f4df0435c2c557273ff0f788f35 c:\Program Files\AVAST Software\Avast\1033\Boot.dll
53a01c12583b6061c31698f6b9ca7fb5 c:\Program Files\AVAST Software\Avast\1033\uiLangRes.dll
324376e364d0491a3d32ddc8a07a6bbb c:\Program Files\AVAST Software\Avast\Aavm4h.dll
d10b15d6babf8387ff8a8aaccd7c093c c:\Program Files\AVAST Software\Avast\AavmRpch.dll
efbaf5e62c20fabd09c52ff6c8ae1eb6 c:\Program Files\AVAST Software\Avast\AavmRpch64.dll
95cffee1551e33e663d554e2fbd83801 c:\Program Files\AVAST Software\Avast\AhAScr.dll
68c5dcbaaaa6caad57f9cda8b94f2811 c:\Program Files\AVAST Software\Avast\AhResMai.dll
8389d2407451d8ab3117dca36a20ee9d c:\Program Files\AVAST Software\Avast\AhResStd.dll
8fe99f1aff5aeac000cb646e421c8cf2 c:\Program Files\AVAST Software\Avast\AhResWS.dll
aaa82fd6c6222b9533520e326c6c651b c:\Program Files\AVAST Software\Avast\AhResWS2.dll
774474fd350facabf8b2235faba556b7 c:\Program Files\AVAST Software\Avast\AvSSHook.dll
c50b830ca9bcd63754928cd6c0e2b114 c:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
a72be5e214a65d8556f81eb330f57155 c:\Program Files\AVAST Software\Avast\AvastGUIProxy64.dll
54236e79a44f909612391c8a2d70d512 c:\Program Files\AVAST Software\Avast\AvastSvc.exe
31ea4bc4328bdbc50cd5ca4870f09e06 c:\Program Files\AVAST Software\Avast\AvastUI.exe
b15f597ac2a2d66ac4a0ac96de68557e c:\Program Files\AVAST Software\Avast\BCUCmnRes.dll
8d9a2881c641074ae002e7d1c9a0bb3d c:\Program Files\AVAST Software\Avast\BrowserCleanup.exe
ce52ccc47f916f19d71b839cc1829b54 c:\Program Files\AVAST Software\Avast\CommChannel.dll
b93377ed3ecd4bc4aadf74a68c2b68b1 c:\Program Files\AVAST Software\Avast\CommonRes.dll
9051107c2131715ec66e7d8875126de3 c:\Program Files\AVAST Software\Avast\CrtCheck32.dll
4cbc6295203c914561f1c6b168af64a8 c:\Program Files\AVAST Software\Avast\CrtCheck64.exe
2427406f4aa14011911a18a4aac865fa c:\Program Files\AVAST Software\Avast\HTMLayout.dll
1bc3368e7c13fa7ceacd9d3e41eea36d c:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
e4abc023e251d2bb6b98c9fcaf5cf16d c:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\ndis6\aswTap.sys
28f0acf7643966318c8b47b64f85dadf c:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\ndis6\tapinstall.exe
2540fa75ceafd9d52cbfe63198d42aad c:\Program Files\AVAST Software\Avast\OpenVPN\libeay32.dll
677862c14112da5a13013609657d5a18 c:\Program Files\AVAST Software\Avast\OpenVPN\libpkcs11-helper-1.dll
22b892b2eb5d6f3e236a9f13ffae4ee2 c:\Program Files\AVAST Software\Avast\OpenVPN\lzo2.dll
7e170a9fe11b1710d472139d5948b8b5 c:\Program Files\AVAST Software\Avast\OpenVPN\openvpn.exe
7bc66bf9eb965eab0907943872e9b811 c:\Program Files\AVAST Software\Avast\OpenVPN\ssleay32.dll
6563c1850620104f3d2a1aa3c1cf0ba5 c:\Program Files\AVAST Software\Avast\RegSvr32.exe
5bfe3e0bf988240920cf3bd1ccda1b14 c:\Program Files\AVAST Software\Avast\RegSvr64.exe
67c8d5d56c6e28866ae2311ceec8f9ee c:\Program Files\AVAST Software\Avast\RescueDisk\AvastPE2.exe
5d5e0b26bd4925967e795006452d9c64 c:\Program Files\AVAST Software\Avast\RescueDisk\Base.dll
ffe556bb4115a4aca7f6e0b472d87ce8 c:\Program Files\AVAST Software\Avast\RescueDisk\aswRegLib.dll
ea6c34de64d83fbde7caa5666fc781cd c:\Program Files\AVAST Software\Avast\RescueDisk\aswShMin.exe
53a01c12583b6061c31698f6b9ca7fb5 c:\Program Files\AVAST Software\Avast\RescueDisk\uiLangRes.dll
673046cab1e33fd0733b11f4d457910b c:\Program Files\AVAST Software\Avast\SetupInf64.exe
4454d476781dd19375828ef7c1e2d510 c:\Program Files\AVAST Software\Avast\VisthAux.exe
9f822261284cfd84638e3b96b449c0d7 c:\Program Files\AVAST Software\Avast\asOutExt.dll
0046389897086e67d9fd85dd759e2e70 c:\Program Files\AVAST Software\Avast\asOutExt64.dll
412350fcf57a83664b65d521cfae8167 c:\Program Files\AVAST Software\Avast\ashBase.dll
c5ae09c02db271fdf38c07f19d42609b c:\Program Files\AVAST Software\Avast\ashMaiSv.dll
e1c6baa37e64696490390b89047b68a9 c:\Program Files\AVAST Software\Avast\ashQuick.exe
d55436a361d3c10c0e4922ac5e8129ee c:\Program Files\AVAST Software\Avast\ashServ.dll
2557136a395d5a62f4fa024e9ed56a4a c:\Program Files\AVAST Software\Avast\ashShA64.dll
4c235455ba906beb43fc899b77668f06 c:\Program Files\AVAST Software\Avast\ashShell.dll
b557cb17d1a0939b9191944aeb0252fb c:\Program Files\AVAST Software\Avast\ashTask.dll
fdaf2e84e880238fa0769bc3eff08a1d c:\Program Files\AVAST Software\Avast\ashTaskEx.dll
8d488ce66391e789ed1d2882af2b9e24 c:\Program Files\AVAST Software\Avast\ashUpd.exe
b2bc0f09a1b7fca91b8f2afdc5e47a24 c:\Program Files\AVAST Software\Avast\ashWebSv.dll
c36cd03ca418201d29262c838850207e c:\Program Files\AVAST Software\Avast\ashWsFtr.dll
dc8cfeeba75a2fec5be4fec48dd4c71a c:\Program Files\AVAST Software\Avast\asulaunch.exe
7a18e6d6b50e9a1504fab897a0997d8a c:\Program Files\AVAST Software\Avast\aswAra.dll
38d6a4793e9a8b10027ba557516fd0fd c:\Program Files\AVAST Software\Avast\aswAraSr.exe
04ac7d0eeaf0aa0ae5e7a8631b896ce3 c:\Program Files\AVAST Software\Avast\aswAux.dll
cf478a5bfe2e06cb9f05d1dd85327141 c:\Program Files\AVAST Software\Avast\aswChLic.exe
3f13f6097b6693a15eacbac3d083aa4b c:\Program Files\AVAST Software\Avast\aswCmnBS.dll
7f54cdae5635deef75061f09c12c5ce5 c:\Program Files\AVAST Software\Avast\aswCmnIS.dll
0285d178c4882810381a71606c93a6ed c:\Program Files\AVAST Software\Avast\aswCmnOS.dll
9a294720aab24893cb72d8292236a1ed c:\Program Files\AVAST Software\Avast\aswData.dll
aebbcd56f205e487ff779df02a96ef7c c:\Program Files\AVAST Software\Avast\aswDld.dll
5a627374da3aa5b499f0fb682e55ba2b c:\Program Files\AVAST Software\Avast\aswDnsCache.dll
33e791cebbd799e45b0f1a976c09fefa c:\Program Files\AVAST Software\Avast\aswEngLdr.dll
33f7ef5c1b460950812cd4dc5a70cc85 c:\Program Files\AVAST Software\Avast\aswJSScan.dll
fc1aeb2454d0a0da4ebbd226a58e7ae5 c:\Program Files\AVAST Software\Avast\aswJsFlt.dll
8bed75bd2d7606805b4ccd9011c43595 c:\Program Files\AVAST Software\Avast\aswJsFlt64.dll
061f6b5d628c8addb2d1f87a3b88fcd7 c:\Program Files\AVAST Software\Avast\aswLSRun.dll
ae098e835009a5cecfaf4a275bd4f55f c:\Program Files\AVAST Software\Avast\aswLog.dll
76b7796a2e4764062f35a470859e1790 c:\Program Files\AVAST Software\Avast\aswPatchMgt.dll
b24202c9bcd3386b27e1f905f592f4a4 c:\Program Files\AVAST Software\Avast\aswProperty.dll
a671cb082d7d1c4be45232a72fa29bb5 c:\Program Files\AVAST Software\Avast\aswProperty64.dll
9f2c6e220a048bb1189a17ad88821eb4 c:\Program Files\AVAST Software\Avast\aswRec.dll
a0c0bc5f9aa1542c0454dd7520bf8fa4 c:\Program Files\AVAST Software\Avast\aswRemoteCache.dll
9f1eefc30cf51d4f5d48161c4bafecce c:\Program Files\AVAST Software\Avast\aswRunDll.exe
c6167dc05e56ccd36a9ec16704456052 c:\Program Files\AVAST Software\Avast\aswRvrt.dll
6055b7c3cd0f97667140227b73c87130 c:\Program Files\AVAST Software\Avast\aswSqLt.dll
f4497ddeb65fc9ea278edcc19ab238f9 c:\Program Files\AVAST Software\Avast\aswStreamFilter.dll
66e0912ed2f9ff12733619f0577b9ef4 c:\Program Files\AVAST Software\Avast\aswStrm.dll
58655e2798eab2b693efeaada116669d c:\Program Files\AVAST Software\Avast\aswUtil.dll
7375902d7c04a7707673485756013943 c:\Program Files\AVAST Software\Avast\aswVmm.dll
a65dc30d7ead2e3c939c59e4c058e40f c:\Program Files\AVAST Software\Avast\aswW8ntf.dll
d289d1f55fa6286e95b709c545e3e442 c:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
7a6e20f618a617384e0440540a919437 c:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
ba8b380ca2a21a4de12161214078bfdd c:\Program Files\AVAST Software\Avast\aswWrcIEBroker32.dll
b3779e17d3fa0594e18d93f3be29dc83 c:\Program Files\AVAST Software\Avast\aswWrcIEBroker64.dll
481186c3eba8974a50f5c61889627bd3 c:\Program Files\AVAST Software\Avast\aswWrcIELoader32.exe
b194c59a3d9e8cc8e8ec8271f8e5fb23 c:\Program Files\AVAST Software\Avast\aswWrcIELoader64.exe
9c3349c17d49917ac24fa8d585d722df c:\Program Files\AVAST Software\Avast\avBugReport.exe
82bd61f4d2e8438df07701459d1bc26e c:\Program Files\AVAST Software\Avast\avHandleService.exe
ab75d87c16b94e8ec80dbc7636235baa c:\Program Files\AVAST Software\Avast\avastIP.dll
658f096e0a363e46f1b9fdae98489f24 c:\Program Files\AVAST Software\Avast\avastSS.dll
5c5e3afd499e5146fef1da5ef8a23205 c:\Program Files\AVAST Software\Avast\dbghelp.dll
2a0af094576bb549499538161ab54ba4 c:\Program Files\AVAST Software\Avast\defs\15042301\ArPot.dll
c66946d78bfabc38253123280b0088d8 c:\Program Files\AVAST Software\Avast\defs\15042301\BCUEngine.dll
31f192710a0b4f3909643071d26f3a0d c:\Program Files\AVAST Software\Avast\defs\15042301\PushPin.dll
d37995f87cfc5c96af62f836c97e0475 c:\Program Files\AVAST Software\Avast\defs\15042301\Sf.bin
90ae51f722beff4f11f8acf84b1cf6e6 c:\Program Files\AVAST Software\Avast\defs\15042301\Sf1.bin
ddbc96a4ef7c3f1da11125d9c77b7446 c:\Program Files\AVAST Software\Avast\defs\15042301\Sf2.dll
75343bdb2b8dfda6851f1c522355ca0d c:\Program Files\AVAST Software\Avast\defs\15042301\algo.dll
27dfe2092e10d5a96d5f2c9c79406fe8 c:\Program Files\AVAST Software\Avast\defs\15042301\algo64.dll
373fc71054a0af865e61a61079001a10 c:\Program Files\AVAST Software\Avast\defs\15042301\aswAR.dll
52d6587dad6c2857fdbcc80f7dc32938 c:\Program Files\AVAST Software\Avast\defs\15042301\aswBoot.dll
53c4f451f60065ed8a8b998301a095cd c:\Program Files\AVAST Software\Avast\defs\15042301\aswBoot64.dll
2bf45d4668eeba48b6045ad16d482206 c:\Program Files\AVAST Software\Avast\defs\15042301\aswCleanerDLL.dll
f78d8404f204ec44de6cdff7163f99d8 c:\Program Files\AVAST Software\Avast\defs\15042301\aswCmnBS.dll
02c4527ff7caf3829ccef34f98d07662 c:\Program Files\AVAST Software\Avast\defs\15042301\aswCmnIS.dll
c12ac7fda455d77da7500b8c36623b18 c:\Program Files\AVAST Software\Avast\defs\15042301\aswCmnIS64.dll
8c23e7a0cc32dc449e79408f4bae1c2c c:\Program Files\AVAST Software\Avast\defs\15042301\aswCmnOS.dll
868699392b4aa48505a765eab18737e4 c:\Program Files\AVAST Software\Avast\defs\15042301\aswEngin.dll
ca7b5f897f0c8c9013e357eaf5d502c0 c:\Program Files\AVAST Software\Avast\defs\15042301\aswFiDb.dll
5b0dbed9e2f9180c01ae505ce39b0900 c:\Program Files\AVAST Software\Avast\defs\15042301\aswHds.dll
c1cc8ba8ba5a2cb302ab271bcf80cb0a c:\Program Files\AVAST Software\Avast\defs\15042301\aswRawFS.dll
f3b204b6fb444f7cd5ff6514ac7dfd3e c:\Program Files\AVAST Software\Avast\defs\15042301\aswRawFS64.dll
fade1505301d0fd2b8d43a35a257810d c:\Program Files\AVAST Software\Avast\defs\15042301\aswRep.dll
7e7dbf942fe3b83277035e75d291aff3 c:\Program Files\AVAST Software\Avast\defs\15042301\aswScan.dll
92b479c77df906f707bf6d2d0edc08e4 c:\Program Files\AVAST Software\Avast\defs\15042301\exts.dll
cedd489d31582031b09707222800fedb c:\Program Files\AVAST Software\Avast\defs\15042301\fwAux.dll
274ae568af94eb03760c2179101b3b77 c:\Program Files\AVAST Software\Avast\defs\15042301\swhealthex.dll
d4fe63cb994bed3ac1f3dec83294b21e c:\Program Files\AVAST Software\Avast\defs\15042301\uiext.dll
8418b9a157ef4a826ea274a590ac7d7a c:\Program Files\AVAST Software\Avast\ffmpegsumo.dll
1c90330daef6acc78ad6c906a46a26d6 c:\Program Files\AVAST Software\Avast\libcef.dll
2540fa75ceafd9d52cbfe63198d42aad c:\Program Files\AVAST Software\Avast\libeay32.dll
e171bf7bb72025749d4e660f2c49d3ad c:\Program Files\AVAST Software\Avast\log.dll
3a906ee402fdb1cb9c257ae7bd0cf47a c:\Program Files\AVAST Software\Avast\log64.dll
48f607566dd271ff01989b761cfdb30d c:\Program Files\AVAST Software\Avast\pdf.dll
5e1e9e96da5d74139e6a8174419fe3b3 c:\Program Files\AVAST Software\Avast\sched.exe
614b85d56ff75d098acbff722f6943a3 c:\Program Files\AVAST Software\Avast\screenhooks32.dll
fe00086a2fc935af640c7f302c12fe89 c:\Program Files\AVAST Software\Avast\setup\CRT\x64\atl110.dll
f110cf19d56f58606eaae8a685279338 c:\Program Files\AVAST Software\Avast\setup\CRT\x64\mfc110u.dll
7caa1b97a3311eb5a695e3c9028616e7 c:\Program Files\AVAST Software\Avast\setup\CRT\x64\msvcp110.dll
7c3b449f661d99a9b1033a14033d2987 c:\Program Files\AVAST Software\Avast\setup\CRT\x64\msvcr110.dll
315d47153122903c52051b7027988f85 c:\Program Files\AVAST Software\Avast\setup\CRT\x86\atl110.dll
b8de851298e99a005bfd34aa906b3fe8 c:\Program Files\AVAST Software\Avast\setup\CRT\x86\mfc110u.dll
3e29914113ec4b968ba5eb1f6d194a0a c:\Program Files\AVAST Software\Avast\setup\CRT\x86\msvcp110.dll
4ba25d2cbe1587a841dcfb8c8c4a6ea6 c:\Program Files\AVAST Software\Avast\setup\CRT\x86\msvcr110.dll
2427406f4aa14011911a18a4aac865fa c:\Program Files\AVAST Software\Avast\setup\HTMLayout.dll
9ca2fdd44f7c1f8ac1652f6c2638cfed c:\Program Files\AVAST Software\Avast\setup\Inf\x64\aswBoot.exe
b5b4c90e9f52da8586f1e5461ad90a5d c:\Program Files\AVAST Software\Avast\setup\Inf\x64\aswHwid.sys
300cb8e510855189cad0b72ffb5590cb c:\Program Files\AVAST Software\Avast\setup\Inf\x64\aswMonFlt.sys
6d37d8db30d086739507c5f6e542656a c:\Program Files\AVAST Software\Avast\setup\Inf\x64\aswRdr2.sys
07e32dfca422a2920482d762d01957ec c:\Program Files\AVAST Software\Avast\setup\Inf\x64\aswRvrt.sys
b1368be5f6ba529e0886f4da2361bd2d c:\Program Files\AVAST Software\Avast\setup\Inf\x64\aswSP.sys
3b4ac2dbfc86f7247c1ff1faf2860530 c:\Program Files\AVAST Software\Avast\setup\Inf\x64\aswSnx.sys
6e53278eccffbc2acc2a5006745ed4bb c:\Program Files\AVAST Software\Avast\setup\Inf\x64\aswStm.sys
91782404718c6352c26b3242bac3f0f1 c:\Program Files\AVAST Software\Avast\setup\Inf\x64\aswVmm.sys
fe30dc121cf05554d134666f5d4a60e4 c:\Program Files\AVAST Software\Avast\setup\Instup.dll
89a40d4bf237ad4fecc2dd53e6c232b5 c:\Program Files\AVAST Software\Avast\setup\aswOfferTool.exe
9c3349c17d49917ac24fa8d585d722df c:\Program Files\AVAST Software\Avast\setup\avBugReport.exe
9c3349c17d49917ac24fa8d585d722df c:\Program Files\AVAST Software\Avast\setup\avbugreport_ais-8aa.vpx
57eccc846599d803c909cf4ac2f66d74 c:\Program Files\AVAST Software\Avast\setup\instcont_ais-8aa.vpx
57eccc846599d803c909cf4ac2f66d74 c:\Program Files\AVAST Software\Avast\setup\instup.exe
fe30dc121cf05554d134666f5d4a60e4 c:\Program Files\AVAST Software\Avast\setup\instup_ais-8aa.vpx
2ab6fe92f7cbbcd7f239ac3d53f4fb6c c:\Program Files\AVAST Software\Avast\setup\iplugins\IStats.dll
b9cf3294c13cdea624ab95ca3e2e483f c:\Program Files\AVAST Software\Avast\setup\ngiodriver_x64_ais-8aa.vpx
9988fc825675d4d3e2298537fc78e303 c:\Program Files\AVAST Software\Avast\setup\ngiodriver_x86_ais-8aa.vpx
89a40d4bf237ad4fecc2dd53e6c232b5 c:\Program Files\AVAST Software\Avast\setup\offertool_ais-8aa.vpx
b1368be5f6ba529e0886f4da2361bd2d c:\Program Files\AVAST Software\Avast\setup\selfdefense_x64_ais-8aa.vpx
cb2b9fbff7a3104a6aa60e797156800f c:\Program Files\AVAST Software\Avast\setup\selfdefense_x86_ais-8aa.vpx
2427406f4aa14011911a18a4aac865fa c:\Program Files\AVAST Software\Avast\setup\setgui_ais-8aa.vpx
b20060a3b091f4280cedb391ab2eee2a c:\Program Files\AVAST Software\Avast\snxhk.dll
0a699a5c80d964aa0519467e49507dc7 c:\Program Files\AVAST Software\Avast\snxhk64.dll
7bc66bf9eb965eab0907943872e9b811 c:\Program Files\AVAST Software\Avast\ssleay32.dll
f440fbe175ee3222a3424a9b9b2030a0 c:\Program Files\Google\GoogleToolbarNotifier\5.10.11023.1534\swg64.dll
062670ff6d10750af99bf774f7d10eeb c:\Users\"%CurrentUserName%"\AppData\Local\Temp\BackupSetup.exe
42c2ac94749aae293ed08951a6974d96 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\MPBSETUP.EXE
c89f9905c394349cc4650154b551aa31 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\HTMLayout.dll
f38eae2cb101ef33d6e17185c3acbfb5 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\Instup.dll
2427406f4aa14011911a18a4aac865fa c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\HTMLayout.dll
fe30dc121cf05554d134666f5d4a60e4 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\Instup.dll
89a40d4bf237ad4fecc2dd53e6c232b5 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\aswOfferTool.exe
9c3349c17d49917ac24fa8d585d722df c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\avBugReport.exe
57eccc846599d803c909cf4ac2f66d74 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\instup.exe
490b18ab2e9206716a195b36d8dfba4a c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avBugReport.exe
9c3349c17d49917ac24fa8d585d722df c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avbugreport_ais-8aa.vpx
57eccc846599d803c909cf4ac2f66d74 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instcont_ais-8aa.vpx
ddfe4e2ad5dbf09a7a5f19f4c6c1bab4 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup.exe
fe30dc121cf05554d134666f5d4a60e4 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup_ais-8aa.vpx
b9cf3294c13cdea624ab95ca3e2e483f c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x64_ais-8aa.vpx
9988fc825675d4d3e2298537fc78e303 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x86_ais-8aa.vpx
89a40d4bf237ad4fecc2dd53e6c232b5 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\offertool_ais-8aa.vpx
b1368be5f6ba529e0886f4da2361bd2d c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\selfdefense_x64_ais-8aa.vpx
cb2b9fbff7a3104a6aa60e797156800f c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\selfdefense_x86_ais-8aa.vpx
2427406f4aa14011911a18a4aac865fa c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\setgui_ais-8aa.vpx
62efa7b730eb0523a026ea4325403b77 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\nsSCM.dll
73a0c739e3c73d4888c89a1672198bd6 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup___.exe
2169b4b1efaa3453a4da732f1f94c1e1 c:\Windows\avastSS.scr
fe00086a2fc935af640c7f302c12fe89 c:\Windows\winsxs\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396\atl110.dll
f110cf19d56f58606eaae8a685279338 c:\Windows\winsxs\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396\mfc110u.dll
7caa1b97a3311eb5a695e3c9028616e7 c:\Windows\winsxs\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396\msvcp110.dll
7c3b449f661d99a9b1033a14033d2987 c:\Windows\winsxs\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396\msvcr110.dll
315d47153122903c52051b7027988f85 c:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\atl110.dll
b8de851298e99a005bfd34aa906b3fe8 c:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\mfc110u.dll
3e29914113ec4b968ba5eb1f6d194a0a c:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\msvcp110.dll
4ba25d2cbe1587a841dcfb8c8c4a6ea6 c:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\msvcr110.dll

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

No information is available.

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 34112 34304 4.21647 6ca1d9841c2a281f0f5832d82e94e172
.data 40960 144 512 0.828479 0ad9ffdcc2a511d78b357c4ee09d8315
.rdata 45056 9272 9728 3.95192 d69f87f60d1706780564584091c4f989
.bss 57344 153732 0 0 d41d8cd98f00b204e9800998ecf8427e
.idata 212992 4868 5120 3.57929 24608b57776bb98c5a5db8bcba4b0aa5
.ndata 221184 200704 1024 0 0f343b0931126a20f133d67c2b018a3b
.rsrc 421888 123832 123904 4.35405 6d276f6df912d346067603a47814e9ea

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://stats.zemobile.com/piwik.php?idsite=1&rec=1&action_name=INICIO&url=http://wizinstall.com/INICIO&_cvar={"1":["PRODUCTO","Avast Antivirus"],"2":["TARGET0","fr-tele"],"3":["FORMA DE PAGO","v1-3"],"4":["DOMINIO","installfoox.com"],"5":["OFERTA","no"]} 46.105.97.102
hxxp://stats.zemobile.com/piwik.php?idsite=1&rec=1&action_name=WARNING/PAIS/fr/US&url=http://wizinstall.com/WARNING/PAIS/fr/US 46.105.97.102
hxxp://stats.zemobile.com/piwik.php?idsite=1&rec=1&action_name=WARNING/IDIOMA/1036/1033&url=http://wizinstall.com/WARNING/IDIOMA/1036/1033 46.105.97.102
hxxp://stats.zemobile.com/piwik.php?idsite=1&rec=1&action_name=Mostrar oferta/MYPCBACKUP&url=http://wizinstall.com/Mostrar oferta/MYPCBACKUP 46.105.97.102
hxxp://s3-website-us-east-1.amazonaws.com/09053f748038e4cb59688a657cb25688/Cloud_Backup_Setup.exe
hxxp://track.mypcbackup.com/a2f8abf7/D0wnloads-English/MyPCBackup_Setup.exe 184.154.139.131
hxxp://mypcbackup.jdibackup.netdna-cdn.com/MyPCBackup_Setup.exe
hxxp://s3-eu-west-1.amazonaws.com/setup-free/avast.exe 54.231.132.112
hxxp://stats.zemobile.com/piwik.php?idsite=1&rec=1&action_name=FIN&url=http://wizinstall.com/FIN 46.105.97.102
hxxp://e3442.g.akamaiedge.net/vers/setup_config.ini
hxxp://a1639.g1.akamai.net/iavs9x/servers.def.vpx
hxxp://a1639.g1.akamai.net/iavs9x/prod-ais.vpx
hxxp://a1639.g1.akamai.net/iavs9x/part-prg_ais-8aa.vpx
hxxp://a1639.g1.akamai.net/iavs9x/part-setup_ais-8aa.vpx
hxxp://a1639.g1.akamai.net/ivps9x/prod-vps.vpx
hxxp://a1639.g1.akamai.net/ivps9x/part-iex-4.vpx
hxxp://a1639.g1.akamai.net/ivps9x/part-jrog2-d50.vpx
hxxp://a1639.g1.akamai.net/ivps9x/part-vps_win32-15042301.vpx
hxxp://a1639.g1.akamai.net/iavs9x/avbugreport_ais-8a0-89e.vpx
hxxp://a1639.g1.akamai.net/iavs9x/avbugreport_ais-8a6-8a0.vpx
hxxp://a1639.g1.akamai.net/iavs9x/avbugreport_ais-8a7-8a6.vpx
hxxp://a1639.g1.akamai.net/iavs9x/avbugreport_ais-8aa-8a7.vpx
hxxp://a1639.g1.akamai.net/iavs9x/instcont_ais-8a0-89e.vpx
hxxp://a1639.g1.akamai.net/iavs9x/instcont_ais-8a6-8a0.vpx
hxxp://a1639.g1.akamai.net/iavs9x/instcont_ais-8a7-8a6.vpx
hxxp://a1639.g1.akamai.net/iavs9x/instcont_ais-8aa-8a7.vpx
hxxp://a1639.g1.akamai.net/iavs9x/instup_ais-8a0-89e.vpx
hxxp://a1639.g1.akamai.net/iavs9x/instup_ais-8a6-8a0.vpx
hxxp://a1639.g1.akamai.net/iavs9x/instup_ais-8a7-8a6.vpx
hxxp://a1639.g1.akamai.net/iavs9x/instup_ais-8aa-8a7.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ngiodriver_x64_ais-8a0-89e.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ngiodriver_x64_ais-8a6-8a0.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ngiodriver_x64_ais-8a7-8a6.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ngiodriver_x64_ais-8aa-8a7.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ngiodriver_x86_ais-8a0-89e.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ngiodriver_x86_ais-8a6-8a0.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ngiodriver_x86_ais-8a7-8a6.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ngiodriver_x86_ais-8aa-8a7.vpx
hxxp://a1639.g1.akamai.net/iavs9x/offertool_ais-8aa.vpx
hxxp://a1639.g1.akamai.net/iavs9x/selfdefense_x64_ais-8aa.vpx
hxxp://a1639.g1.akamai.net/iavs9x/selfdefense_x86_ais-8aa.vpx
hxxp://a1639.g1.akamai.net/iavs9x/setgui_ais-8a0-89e.vpx
hxxp://a1639.g1.akamai.net/iavs9x/setgui_ais-8a6-8a0.vpx
hxxp://a1639.g1.akamai.net/iavs9x/setgui_ais-8a7-8a6.vpx
hxxp://a1639.g1.akamai.net/iavs9x/setgui_ais-8aa-8a7.vpx
hxxp://shepherd.ff.avast.com/ 5.45.59.110
hxxp://www-google-analytics.l.google.com/__utm.gif?utmn=41&utmac=MO-1405551-23&utmwv=4.4sh&utmp=view/fa-2015/en/intro&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=-
hxxp://www-google-analytics.l.google.com/__utm.gif?utmn=18467&utmac=MO-1405551-23&utmwv=4.4sh&utmp=click/fa-2015/en/intro/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=-
hxxp://www-google-analytics.l.google.com/__utm.gif?utmn=6334&utmac=MO-1405551-23&utmwv=4.4sh&utmp=view/fa-2015/en/privacy/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=-
hxxp://www-google-analytics.l.google.com/__utm.gif?utmn=26500&utmac=MO-1405551-23&utmwv=4.4sh&utmp=click/fa-2015/en/privacy/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=-
hxxp://www-google-analytics.l.google.com/__utm.gif?utmn=19169&utmac=MO-1405551-23&utmwv=4.4sh&utmp=view/fa-2015/en/progress/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=-
hxxp://a1639.g1.akamai.net/ivps9x/iplugins-4.vpx
hxxp://a1639.g1.akamai.net/ivps9x/jrog2-d50.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_cmp_bpc-7e5.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_cmp_grimefighter-7eb.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_cmp_rescuedisk-7f5.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_cmp_secureline-7ce.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_cmp_secureline_x64-7cf.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_cmp_swhealth-7f5.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_cmp_webrep-7ed.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_core-7f5.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_dll_eng-7f5.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_gen_crt_x64-7e4.vpx
hxxp://www-google-analytics.l.google.com/__utm.gif?utmn=15724&utmac=MO-1405551-23&utmwv=4.4sh&utmp=click/fa-2015/en/progress/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=-
hxxp://a1639.g1.akamai.net/iavs9x/ais_gen_crt_x86-7e3.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_gen_gui-7d5.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_gen_gui_cef-7ce.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_gen_openssl-7d4.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_gen_streamfilter-7f5.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_gen_streamfilter_x64-7f5.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_gen_tools-7e2.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_gen_tools_x64-7e2.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_res-7f5.vpx
hxxp://a1639.g1.akamai.net/iavs9x/ais_x64-7f5.vpx
hxxp://a1639.g1.akamai.net/ivps9x/vps_32-1000.vpx
hxxp://a1639.g1.akamai.net/ivps9x/vps_win32-100f.vpx
hxxp://a1639.g1.akamai.net/ivps9x/vps_win64-ca0.vpx
hxxp://tools.l.google.com/dl/toolbar/t7/data/7.5.6227.252/googletoolbarinstaller_en_signed.exe
hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8375aa7c3aaffcf1
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c=
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CECkSxwyaK4o+9vYHRmLWi40=
hxxp://clients.l.google.com/tools/swg2/update?type=c&as=swg&os=win&osv=6.1.7601&hl=en&ie=10.0.9200.16521&ds=0&pds=0&su=0&hpi=-1&brand=AVNH&pa=9&cl=1&tbv=&id=7a84db8082774391b17b4432f8f57454eb587e9488&from=&to=5.10.11023.1534
hxxp://clients.l.google.com/tools/pso/ping?as=tbin&gu=pi&mode=3&sin=1&ein=0&version=7.5.6227.252&brand=AVNH&hl=en&tbiv=7.5.6227.252&time=1429869682&fitime=1429869682&browser=9.10.9200.16521&osver=6.1&ossp=1.0&osarch=64&ext=EXE&id=94394E1F1F38CEBAA4CC598C9A5F7962A4932kYVRG
hxxp://e3442.g.akamaiedge.net/files/emupdate/patches.ini
hxxp://e3442.g.akamaiedge.net/files/emupdate/20150112.exe
hxxp://www-google-analytics.l.google.com/collect?v=1&tid=UA-45708355-2&t=event&cid=1b9818a2-3789-4442-9fc3-714a6e217daf&ec=20150112&ea=started&el=&ev=0
hxxp://analytics.ff.avast.com/receive
hxxp://www-google-analytics.l.google.com/collect?v=1&tid=UA-45708355-2&t=event&cid=1b9818a2-3789-4442-9fc3-714a6e217daf&ec=20150112&ea=finished&el=&ev=0
hxxp://e3442.g.akamaiedge.net/files/emupdate/updates.xml
hxxp://v7.stats.avast.com/cgi-bin/iavs4stats.cgi 173.193.242.228
hxxp://su.ff.avast.com/R/A1cKIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://vl.ff.avast.com/F/AAEbmBiiN4lEQp_DcUpuIX2v 77.234.40.59
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDQn98xMgoIBBDQn98xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDFod8xMgoIBBDFod8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC3o98xMgoIBBC3o98xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDQpd8xMgoIBBDQpd8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://ai.ff.avast.com/F/AP8bmBiiN4lEQp_DcUpuIX2v 5.45.62.63
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDIp98xMgoIBBDIp98xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC9qd8xMgoIBBC9qd8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCkrd8xMgoIBBCkrd8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTEemCaVgs8Tuh2B9fGVE0pKKNyzgQUTF+nNhcF4oZhIkk5jLmo40rgOBoCEC6utoKGY/7ZdVX4/iTzOxo=
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCTr98xMgoIBBCTr98xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCdsd8xMgoIBBCdsd8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDktd8xMgoIBBDktd8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDyt98xMgoIBBDyt98xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCDut8xMgoIBBCDut8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCYvN8xMgoIBBCYvN8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDbvt8xMgoIBBDbvt8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDnwN8xMgoIBBDnwN8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDXwt8xMgoIBBDXwt8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRODEXefhs/UZFum2o8YfzOFwceMwQUkz5j3yJ0BOBkhDHd2yOfDq+2TZMCEA89qsgV9niZmSI6gIO0S/U=
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDJxN8xMgoIBBDJxN8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC7xt8xMgoIBBC7xt8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCwyN8xMgoIBBCwyN8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDEyt8xMgoIBBDEyt8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDkzN8xMgoIBBDkzN8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD2zt8xMgoIBBD2zt8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://a1639.g1.akamai.net/msdownload/update/v3/static/trustedr/en/authrootstl.cab?88a24d8325e2cdd0
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDV2d8xMgoIBBDV2d8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDO298xMgoIBBDO298xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDO3d8xMgoIBBDO3d8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDI398xMgoIBBDI398xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD_4d8xMgoIBBD_4d8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCF5N8xMgoIBBCF5N8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCO5t8xMgoIBBCO5t8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCG6t8xMgoIBBCG6t8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCP7N8xMgoIBBCP7N8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCN7t8xMgoIBBCN7t8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCb8N8xMgoIBBCb8N8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCb8t8xMgoIBBCb8t8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCP9N8xMgoIBBCP9N8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCM9t8xMgoIBBCM9t8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCJ-N8xMgoIBBCJ-N8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCL-t8xMgoIBBCL-t8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDk_N8xMgoIBBDk_N8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDz_t8xMgoIBBDz_t8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDzgOAxMgoIBBDzgOAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDlguAxMgoIBBDlguAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDphOAxMgoIBBDphOAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://a1621.g.akamai.net/pki/crl/products/WinPCA.crl
hxxp://a1621.g.akamai.net/pki/crl/products/MicrosoftTimeStampPCA.crl
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDxhuAxMgoIBBDxhuAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCLieAxMgoIBBCLieAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCCi-AxMgoIBBCCi-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD6jOAxMgoIBBD6jOAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD9juAxMgoIBBD9juAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD5kOAxMgoIBBD5kOAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCYk-AxMgoIBBCYk-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCYleAxMgoIBBCYleAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC1l-AxMgoIBBC1l-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCxmeAxMgoIBBCxmeAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCom-AxMgoIBBCom-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDCneAxMgoIBBDCneAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDun-AxMgoIBBDun-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD9oeAxMgoIBBD9oeAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD-o-AxMgoIBBD-o-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD7peAxMgoIBBD7peAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD7p-AxMgoIBBD7p-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD2qeAxMgoIBBD2qeAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD_q-AxMgoIBBD_q-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD3reAxMgoIBBD3reAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDur-AxMgoIBBDur-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDVseAxMgoIBBDVseAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDCs-AxMgoIBBDCs-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDtteAxMgoIBBDtteAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD1uOAxMgoIBBD1uOAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDsuuAxMgoIBBDsuuAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD3vOAxMgoIBBD3vOAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDuvuAxMgoIBBDuvuAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD-wOAxMgoIBBD-wOAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCHw-AxMgoIBBCHw-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCPxeAxMgoIBBCPxeAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCkx-AxMgoIBBCkx-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCyyeAxMgoIBBCyyeAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://a1621.g.akamai.net/pki/crl/products/microsoftrootcert.crl
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCyy-AxMgoIBBCyy-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCozeAxMgoIBBCozeAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCez-AxMgoIBBCez-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC-0eAxMgoIBBC-0eAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDC0-AxMgoIBBDC0-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDh1eAxMgoIBBDh1eAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDH2OAxMgoIBBDH2OAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD22uAxMgoIBBD22uAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDz3OAxMgoIBBDz3OAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCT3-AxMgoIBBCT3-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCj4eAxMgoIBBCj4eAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC24-AxMgoIBBC24-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCU5uAxMgoIBBCU5uAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w=
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI=
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCW6OAxMgoIBBCW6OAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEALa8SdwQh28+NjkQGqVhx8=
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDQ6uAxMgoIBBDQ6uAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEGO+CyDUoFQBjrKVo87pCRc=
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD87OAxMgoIBBD87OAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD_7uAxMgoIBBD_7uAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD98OAxMgoIBBD98OAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD48uAxMgoIBBD48uAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD09OAxMgoIBBD09OAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDz9uAxMgoIBBDz9uAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCf-eAxMgoIBBCf-eAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://a1639.g1.akamai.net/pki/crl/products/MicCodSigPCA_08-31-2010.crl
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDf--AxMgoIBBDf--AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8=
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCI_uAxMgoIBBCI_uAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://cs9.wac.phicdn.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEALE0eWKSmgMVo2jBH5+TV8=
hxxp://cs9.wac.phicdn.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRm/rYSaqNr0YBIv29H4pMHhv2XmQQUl0gD6xUIa7myWCPMlC7xxmXSZI4CEA717Ke9Mc/Dp/jmJZtCM1k=
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCGgeExMgoIBBCGgeExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCRg-ExMgoIBBCRg-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCMheExMgoIBBCMheExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCLh-ExMgoIBBCLh-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCFieExMgoIBBCFieExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCDi-ExMgoIBBCDi-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDyjuExMgoIBBDyjuExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCPkeExMgoIBBCPkeExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDyk-ExMgoIBBDyk-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD1leExMgoIBBD1leExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD8l-ExMgoIBBD8l-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC0muExMgoIBBC0muExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC8nOExMgoIBBC8nOExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDCnuExMgoIBBDCnuExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDPoOExMgoIBBDPoOExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDtouExMgoIBBDtouExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD4pOExMgoIBBD4pOExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCCp-ExMgoIBBCCp-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCOqeExMgoIBBCOqeExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCTq-ExMgoIBBCTq-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC5reExMgoIBBC5reExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDBr-ExMgoIBBDBr-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDMseExMgoIBBDMseExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDds-ExMgoIBBDds-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAKQll6RM0DNpmNM7zH3/Qc=
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDiteExMgoIBBDiteExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDgt-ExMgoIBBDgt-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDdueExMgoIBBDdueExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDzvOExMgoIBBDzvOExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDyvuExMgoIBBDyvuExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD0wOExMgoIBBD0wOExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD4wuExMgoIBBD4wuExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCVxeExMgoIBBCVxeExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCkx-ExMgoIBBCkx-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDLyeExMgoIBBDLyeExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDJy-ExMgoIBBDJy-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD5zeExMgoIBBD5zeExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD6z-ExMgoIBBD6z-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCp0uExMgoIBBCp0uExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCx1OExMgoIBBCx1OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCs1uExMgoIBBCs1uExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC02OExMgoIBBC02OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCy2uExMgoIBBCy2uExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC63OExMgoIBBC63OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC33uExMgoIBBC33uExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDJ4OExMgoIBBDJ4OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDV4uExMgoIBBDV4uExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDh5OExMgoIBBDh5OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDl5uExMgoIBBDl5uExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDv6OExMgoIBBDv6OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCK6-ExMgoIBBCK6-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDQ7eExMgoIBBDQ7eExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDl7-ExMgoIBBDl7-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDl8eExMgoIBBDl8eExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDj8-ExMgoIBBDj8-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://ip-info.ff.avast.com/v1/info 77.234.42.102
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD99eExMgoIBBD99eExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCS-OExMgoIBBCS-OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDf_OExMgoIBBDf_OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCx_-ExMgoIBBCx_-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCkg-IxMgoIBBCkg-IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCvheIxMgoIBBCvheIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD-ieIxMgoIBBD-ieIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCYjOIxMgoIBBCYjOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCojuIxMgoIBBCojuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCwkOIxMgoIBBCwkOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC8kuIxMgoIBBC8kuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDGlOIxMgoIBBDGlOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDQluIxMgoIBBDQluIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDUmOIxMgoIBBDUmOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDSmuIxMgoIBBDSmuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDdnOIxMgoIBBDdnOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDjnuIxMgoIBBDjnuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDmoOIxMgoIBBDmoOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD9ouIxMgoIBBD9ouIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCopeIxMgoIBBCopeIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCGquIxMgoIBBCGquIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC0ruIxMgoIBBC0ruIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDFsOIxMgoIBBDFsOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDUsuIxMgoIBBDUsuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCKteIxMgoIBBCKteIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC6t-IxMgoIBBC6t-IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDcueIxMgoIBBDcueIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCfvOIxMgoIBBCfvOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDfvuIxMgoIBBDfvuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCGweIxMgoIBBCGweIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDpw-IxMgoIBBDpw-IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD4xeIxMgoIBBD4xeIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC-yOIxMgoIBBC-yOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDayuIxMgoIBBDayuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC3zuIxMgoIBBC3zuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCK0-IxMgoIBBCK0-IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDA1eIxMgoIBBDA1eIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDm1-IxMgoIBBDm1-IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCw2uIxMgoIBBCw2uIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC33OIxMgoIBBC33OIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC73uIxMgoIBBC73uIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDF4OIxMgoIBBDF4OIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDZ4uIxMgoIBBDZ4uIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCK6-IxMgoIBBCK6-IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCD7-IxMgoIBBCD7-IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDQ9OIxMgoIBBDQ9OIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDh9uIxMgoIBBDh9uIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD3-OIxMgoIBBD3-OIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCR--IxMgoIBBCR--IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD__eIxMgoIBBD__eIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCyg-MxMgoIBBCyg-MxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDKheMxMgoIBBDKheMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD3h-MxMgoIBBD3h-MxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCGiuMxMgoIBBCGiuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCejOMxMgoIBBCejOMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDGjuMxMgoIBBDGjuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDQkOMxMgoIBBDQkOMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDdkuMxMgoIBBDdkuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDnleMxMgoIBBDnleMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDzl-MxMgoIBBDzl-MxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCHmuMxMgoIBBCHmuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBClnOMxMgoIBBClnOMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDcnuMxMgoIBBDcnuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDmoOMxMgoIBBDmoOMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD6ouMxMgoIBBD6ouMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCnpeMxMgoIBBCnpeMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD9quMxMgoIBBD9quMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCRreMxMgoIBBCRreMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCdr-MxMgoIBBCdr-MxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCtseMxMgoIBBCtseMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDZs-MxMgoIBBDZs-MxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDsteMxMgoIBBDsteMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCAuOMxMgoIBBCAuOMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCmuuMxMgoIBBCmuuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC_vOMxMgoIBBC_vOMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDWvuMxMgoIBBDWvuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDPx-MxMgoIBBDPx-MxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDqyeMxMgoIBBDqyeMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCozOMxMgoIBBCozOMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDJzuMxMgoIBBDJzuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC70eMxMgoIBBC70eMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://su.ff.avast.com/R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDU0-MxMgoIBBDU0-MxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= 77.234.44.64
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/ngiodriver_x86_ais-8aa-8a7.vpx 87.245.221.98
hxxp://dl.google.com/dl/toolbar/t7/data/7.5.6227.252/googletoolbarinstaller_en_signed.exe 173.194.44.38
hxxp://www.google-analytics.com/__utm.gif?utmn=6334&utmac=MO-1405551-23&utmwv=4.4sh&utmp=view/fa-2015/en/privacy/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=- 216.58.211.46
hxxp://v4142311.iavs9x.u.avast.com/iavs9x/part-prg_ais-8aa.vpx 87.245.221.97
hxxp://emupdate.avast.com/files/emupdate/patches.ini 23.64.222.13
hxxp://www.google-analytics.com/__utm.gif?utmn=19169&utmac=MO-1405551-23&utmwv=4.4sh&utmp=view/fa-2015/en/progress/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=- 216.58.211.46
hxxp://cdn.mypcbackup.com/MyPCBackup_Setup.exe 94.31.29.238
hxxp://t5416173.ivps9x.u.avast.com/ivps9x/part-jrog2-d50.vpx 87.245.221.97
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_gen_crt_x86-7e3.vpx 87.245.221.97
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/selfdefense_x64_ais-8aa.vpx 87.245.221.98
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_cmp_rescuedisk-7f5.vpx 87.245.221.97
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEGO+CyDUoFQBjrKVo87pCRc= 23.43.139.27
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c= 23.43.139.27
hxxp://5.45.59.110/
hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?88a24d8325e2cdd0 195.12.232.185
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/ngiodriver_x64_ais-8a7-8a6.vpx 87.245.221.98
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_gen_gui-7d5.vpx 87.245.221.97
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/ngiodriver_x86_ais-8a7-8a6.vpx 87.245.221.98
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= 23.43.139.27
hxxp://h6627484.iavs9x.u.avast.com/iavs9x/prod-ais.vpx 87.245.221.97
hxxp://b0905751.ivps9x.u.avast.com/ivps9x/jrog2-d50.vpx 87.245.221.98
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/selfdefense_x86_ais-8aa.vpx 87.245.221.98
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/setgui_ais-8a7-8a6.vpx 87.245.221.98
hxxp://www.google-analytics.com/__utm.gif?utmn=18467&utmac=MO-1405551-23&utmwv=4.4sh&utmp=click/fa-2015/en/intro/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=- 216.58.211.46
hxxp://aff-software.s3-website-us-east-1.amazonaws.com/09053f748038e4cb59688a657cb25688/Cloud_Backup_Setup.exe 54.231.13.20
hxxp://v4142311.iavs9x.u.avast.com/iavs9x/part-setup_ais-8aa.vpx 87.245.221.97
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/instup_ais-8a6-8a0.vpx 87.245.221.98
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/offertool_ais-8aa.vpx 87.245.221.98
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/avbugreport_ais-8a6-8a0.vpx 87.245.221.98
hxxp://crl.microsoft.com/pki/crl/products/WinPCA.crl 87.245.221.107
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTEemCaVgs8Tuh2B9fGVE0pKKNyzgQUTF+nNhcF4oZhIkk5jLmo40rgOBoCEC6utoKGY/7ZdVX4/iTzOxo= 23.43.139.27
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/ngiodriver_x86_ais-8a6-8a0.vpx 87.245.221.98
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_gen_gui_cef-7ce.vpx 87.245.221.97
hxxp://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl 87.245.221.107
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/setgui_ais-8a6-8a0.vpx 87.245.221.98
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= 23.43.139.27
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/instup_ais-8a0-89e.vpx 87.245.221.98
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_x64-7f5.vpx 87.245.221.97
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_cmp_bpc-7e5.vpx 87.245.221.97
hxxp://www.google-analytics.com/__utm.gif?utmn=41&utmac=MO-1405551-23&utmwv=4.4sh&utmp=view/fa-2015/en/intro&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=- 216.58.211.46
hxxp://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEALE0eWKSmgMVo2jBH5+TV8= 93.184.220.29
hxxp://j5108348.ivps9x.u.avast.com/ivps9x/part-vps_win32-15042301.vpx 87.245.221.97
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_gen_streamfilter_x64-7f5.vpx 87.245.221.97
hxxp://eu20150112.aa.avast.com/receive 5.45.58.148
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/avbugreport_ais-8a0-89e.vpx 87.245.221.98
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CECkSxwyaK4o+9vYHRmLWi40= 23.43.139.27
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_cmp_grimefighter-7eb.vpx 87.245.221.97
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_gen_crt_x64-7e4.vpx 87.245.221.97
hxxp://emupdate.avast.com/files/emupdate/updates.xml 23.64.222.13
hxxp://clients1.google.com/tools/pso/ping?as=tbin&gu=pi&mode=3&sin=1&ein=0&version=7.5.6227.252&brand=AVNH&hl=en&tbiv=7.5.6227.252&time=1429869682&fitime=1429869682&browser=9.10.9200.16521&osver=6.1&ossp=1.0&osarch=64&ext=EXE&id=94394E1F1F38CEBAA4CC598C9A5F7962A4932kYVRG 216.58.211.14
hxxp://l3362258.ivps9x.u.avast.com/ivps9x/vps_win32-100f.vpx 87.245.221.97
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/instcont_ais-8aa-8a7.vpx 87.245.221.98
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= 23.43.139.27
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/avbugreport_ais-8a7-8a6.vpx 87.245.221.98
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/ngiodriver_x86_ais-8a0-89e.vpx 87.245.221.98
hxxp://setupini.avast.com/vers/setup_config.ini 23.64.222.13
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEALa8SdwQh28+NjkQGqVhx8= 23.43.139.27
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_cmp_secureline_x64-7cf.vpx 87.245.221.97
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_core-7f5.vpx 87.245.221.97
hxxp://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl 87.245.221.107
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRODEXefhs/UZFum2o8YfzOFwceMwQUkz5j3yJ0BOBkhDHd2yOfDq+2TZMCEA89qsgV9niZmSI6gIO0S/U= 23.43.139.27
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/instcont_ais-8a6-8a0.vpx 87.245.221.98
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_cmp_webrep-7ed.vpx 87.245.221.97
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/avbugreport_ais-8aa-8a7.vpx 87.245.221.98
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_gen_openssl-7d4.vpx 87.245.221.97
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_cmp_secureline-7ce.vpx 87.245.221.97
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/setgui_ais-8aa-8a7.vpx 87.245.221.98
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/ngiodriver_x64_ais-8a0-89e.vpx 87.245.221.98
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/ngiodriver_x64_ais-8aa-8a7.vpx 87.245.221.98
hxxp://www.google-analytics.com/__utm.gif?utmn=26500&utmac=MO-1405551-23&utmwv=4.4sh&utmp=click/fa-2015/en/privacy/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=- 216.58.211.46
hxxp://c8884169.ivps9x.u.avast.com/ivps9x/part-iex-4.vpx 87.245.221.98
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/instcont_ais-8a0-89e.vpx 87.245.221.98
hxxp://l3362258.ivps9x.u.avast.com/ivps9x/vps_32-1000.vpx 87.245.221.97
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_gen_tools_x64-7e2.vpx 87.245.221.97
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/instup_ais-8aa-8a7.vpx 87.245.221.98
hxxp://g8873876.iavs9x.u.avast.com/iavs9x/servers.def.vpx 87.245.221.98
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/instcont_ais-8a7-8a6.vpx 87.245.221.98
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/ngiodriver_x64_ais-8a6-8a0.vpx 87.245.221.98
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_dll_eng-7f5.vpx 87.245.221.97
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_gen_streamfilter-7f5.vpx 87.245.221.97
hxxp://f5401358.ivps9x.u.avast.com/ivps9x/iplugins-4.vpx 87.245.221.97
hxxp://clients1.google.com/tools/swg2/update?type=c&as=swg&os=win&osv=6.1.7601&hl=en&ie=10.0.9200.16521&ds=0&pds=0&su=0&hpi=-1&brand=AVNH&pa=9&cl=1&tbv=&id=7a84db8082774391b17b4432f8f57454eb587e9488&from=&to=5.10.11023.1534 216.58.211.14
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAKQll6RM0DNpmNM7zH3/Qc= 23.43.139.27
hxxp://www.google-analytics.com/collect?v=1&tid=UA-45708355-2&t=event&cid=1b9818a2-3789-4442-9fc3-714a6e217daf&ec=20150112&ea=finished&el=&ev=0 216.58.211.46
hxxp://www.google-analytics.com/collect?v=1&tid=UA-45708355-2&t=event&cid=1b9818a2-3789-4442-9fc3-714a6e217daf&ec=20150112&ea=started&el=&ev=0 216.58.211.46
hxxp://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRm/rYSaqNr0YBIv29H4pMHhv2XmQQUl0gD6xUIa7myWCPMlC7xxmXSZI4CEA717Ke9Mc/Dp/jmJZtCM1k= 93.184.220.29
hxxp://www.google-analytics.com/__utm.gif?utmn=15724&utmac=MO-1405551-23&utmwv=4.4sh&utmp=click/fa-2015/en/progress/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=- 216.58.211.46
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/instup_ais-8a7-8a6.vpx 87.245.221.98
hxxp://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl 87.245.221.107
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_cmp_swhealth-7f5.vpx 87.245.221.97
hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8375aa7c3aaffcf1 195.12.232.185
hxxp://g4449219.iavs9x.u.avast.com/iavs9x/setgui_ais-8a0-89e.vpx 87.245.221.98
hxxp://emupdate.avast.com/files/emupdate/20150112.exe 23.64.222.13
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_res-7f5.vpx 87.245.221.97
hxxp://t9920830.ivps9x.u.avast.com/ivps9x/prod-vps.vpx 87.245.221.97
hxxp://l3362258.ivps9x.u.avast.com/ivps9x/vps_win64-ca0.vpx 87.245.221.97
hxxp://l7658080.iavs9x.u.avast.com/iavs9x/ais_gen_tools-7e2.vpx 87.245.221.97
ipmcdn.avast.com 23.64.222.13
slcw.ff.avast.com 77.234.43.77
ping.avast.com 23.64.222.13
pool.ntp.org 178.213.0.190
ipm-provider.ff.avast.com 5.45.62.79
auth.ff.avast.com 77.234.42.94
tools.google.com 173.194.44.38
ssl.google-analytics.com 216.58.211.40
su2.ff.avast.com


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

SURICATA UDPv4 invalid checksum
SURICATA IPv4 invalid checksum
ET POLICY Executable served from Amazon S3
ET TROJAN VMProtect Packed Binary Inbound via HTTP - Likely Hostile
ET MALWARE Possible Windows executable sent when remote host claims to send html content

Traffic

GET /iavs9x/instup_ais-8a6-8a0.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 1255151
Last-Modified: Tue, 31 Mar 2015 10:57:46 GMT
ETag: "551a7daa-1326ef"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:32 GMT
Connection: keep-alive
ASWsetupDPkgFil2...s..........&............s..........)..j&..x...eP]M.
.....;....;.g...Npww6.....]..{ ....Su........<Ow...Ybj..RR...K!...4
....DY.........6......`.!...O9.....E...C...g...gh.x.m.W..B....@Z.....T
.8D.@..(........2..<.l........t........j#......l..?....7..?.'L @..O
A.........t....2....../.....?.....V.A........T.....@.........8...ii./.
.........@.:.b........r......o.......'...s..........S....-5......0'...
...-.....)=..Li...:I..]X.....M..#....w...........<:u.....Xt..`QD...
.... C..E`..XH. @.....@.`.....6..............@.BPvGC.&..... .]E...../.
w..sA.<.9.?a..........,$.$.......!vV.=E<.y r...d.pd..U.<..a.f
...s...:..6....t..q.y=..p....;.S....m.......9..M.v..........[.s.....&l
t;<.....M5...q.zy..mW.)q.....;y....;-4..m..y..K.9..a...y.kJ.s.B.>
;..n...#...R]&b.K..b.]n...;....'.......Xi...'..T ..%;...@.S...w.U.."..
E.X.X.r.**.R.h.J....D.z.Pf.VcT-..)....W.6].jS...-...%.6.5.1..r...UY;..
....66....&..Q..E..Y;.6..N.d].Ir..<...h6.W.I;.Z...I[... .d.tm.8...6
.6......d[&..h.......t.,4@..[.F........e....eq.H.". o.....T.Wvp.Fp..T.
...h..o..fC.).x.......,......H,..G.....A....R...... .rW...(.*...^.*...
..CM.#.....'....T.........X/.......$Q...$e.)..r$).>9.....V..$......
.!............R.Y..W...Z!.ZAAjA.b.G....J.)V.........S..#..(.......,...
..l...<.e...|....S.R.w]@..\L)L.5@AA!..>t....S..../.......'..5 ..
.X?@`..B.....s.U\.-.m....D.4].A:)G`..Q7c.._....WB..b...xk..c....@..B.'
V..*..&..K..2...3e...... 9...w..........C(....:R.VV..Q.e.8....E.K.. .R
...I.......*........'...-......^..0.N......R..)\..0.l.....u)..v.o.

<<< skipped >>>

GET /iavs9x/ais_gen_tools_x64-7e2.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 288137
Last-Modified: Tue, 21 Apr 2015 16:32:27 GMT
ETag: "55367b9b-46589"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:31 GMT
Connection: keep-alive
ASWsetupFPkgFil3.8..)e..].....$..................~...7.iAp!..a...&&.v.
...b.$W.*........?..z.RM........,...d.i...8.....-,=..ThK.M./.zG....@..
.I.Mw...R...v...`.@J<.v.#.e..K\(P..g"H.<.........&eq...z<.fd.
..k:_X.s..Q.&...E.X.....XT.-.g......8.Q.....d.:_Z..j.R....7.......sm..
0....w!..@.{...!.,..`]..........D......L...g.....K<."..w.....S.....
C....T.|].\..N=7..H<c......$.{.]..._....]....6..k.. ..........Q\.._
Y.o.......nR~......B.W....V.(.Hq1.s.^..K.$...."...._~.s...j..#.x......
.0:...^.......F.M.ka........G........... .T.FR....y<..f..BK1m.yT..
F..u... .../,......,R5s.....K~a..rX.`8....Q.I..3&E.4K..Fj.W.'8^.......
4......:......1...u....!}'...D..dt.T ........!]$..=8!.........t.d.[...
y.=........n^x..G.1^0R[....W..l.OC@vBi....4...*m...g.,...<...Hs.GU.
.@#_?V...o:..$f.B..R.h..]Q-.b...&......-.VB.......BW...i......oA5o.<
;..g.u....~.y]]'X.y..E...u........N......U.4...8C.X.}...@.8l8!\.=D8.4.
3........!..Hc.z.............g..b.Ek.A...D.C..V..2Q:..^....(9...i.EV..
....`....U..O....R..s..).............. ..4=r...g.G....|-\...z.,D-.....
.....rM.i...."s..?..j2.q..P......5.Yuj{.1u....{.....YuYn....A...-a...8
.-v~\p............*sq..t4u@.).........R..._..L..h-".z!WL...dm'9P}TG...
l....I}....I.<@M.....R.4a....T..L."..4<4..{_..==....^..U..Z....D
.W-...W..N.W.....;-....?u".:A....HY0...... .9.g.=x.U..U ]b.....Q.0.~.i
.E>...t...qn.<.@.]..N..B b...v...Z.................A....M.. a...
-....\.z.......L`...09.S.2.ihi...h........ p.)[;..S."......V....&..G.t
.h7.h._v...>..m..(l."n.;...@...0.^...U|....9.....>_...[q...s

<<< skipped >>>

GET /iavs9x/ais_cmp_swhealth-7f5.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 488776
Last-Modified: Tue, 21 Apr 2015 16:30:29 GMT
ETag: "55367b25-77548"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:14 GMT
Connection: keep-alive
ASWsetupFPkgFil3.....t..].....$....U...{.Ky........W..W/.. ...l.......
..c....O..........B....w^j..E.......n.{...3..,..D8N.K...QE....lA....S.
........".A...Nn.P!u...&~..SN._.BJ......(....\.-.4?4......\...!....D&g
t;.....xbxeA.....L[c {... i..)..:.................R.v..G.ON.....z..E..
Z.e.....N....Y9..?.a...e..Dh.)......T..}..y.7.8...v..e..v..L~.{... .=.
.8..XN...(.^...~..~S..p) Nk.!\..m."......!.....uVw..^.y..#.d...x......
]..qB(..Iq6y..|..-..&....iD.@y.{.S.Bi.....J....{.R_.^.{n....."...h.Ir.
.Y5d8/.........F....$u.].c...~.F...cQ..^y...a.S.s..o.L.2.HZ{j...QW..u.
.Xo.`-.[.`...t7..........b....e)..q.....3..o.u8\#..g...<bp.B..j[.o.
..%E. ......VQ.dn.D&..r..xy...J..!.x....#..~.jQ.SL.J].....P.I6Y-.>.
."...V.!.../.c...W*J.....&....<b.S...C...3..6Zl..v...E.2...|..?..&l
t;.g.......,".^..p...B.f....H3G.8Mob.@......Q......!> ......(..88.\
.<.....#.,....3.k.....X...j.P...,.\..#a.^.HN[(...S....>...2...~&
gt;...S6........_.1_...R.8tJ...D..!r...(2.M.Q2.$...Mm.F.5......<].&
"..x<&x..u|$...*..PR%...m.w.%sT....d...Z.....W5....P*.....c........
Z............!...4M..%...........N8.}.........P....S..Y...f.. qF}.".cn
X.....m..'..A.Y.pm...Lu.I...6.h>4U..4s.gJ.YS... .DJ..=..~B..eR.u...
.t...!. ...J.a}....ur.n_......3..}... C....v!1..J.......V7"[....Y...;.
,e.>....R..8...#P....Mt..Y....<.MM}.....y\FLU........G.yB....6.U
r..KyNX.PI7..@..S....2>.......G. f...K.......~F....a{}x_C..[.M.....
...x.o...n?...:...Xd.AX6.W........,..t.q.....|r@o|.V....m.=........".F
.}.S.*...a...../..5.CHM..]..z..m.....%w..A.......k.UM@.yaQ?.......

<<< skipped >>>

GET /piwik.php?idsite=1&rec=1&action_name=WARNING/PAIS/fr/US&url=http://wizinstall.com/WARNING/PAIS/fr/US HTTP/1.0
Host: stats.zemobile.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
Date: Fri, 24 Apr 2015 09:59:10 GMT
Server: Apache/2.4.7 (Ubuntu)
X-Powered-By: PHP/5.5.9-1ubuntu4.7
Content-Length: 43
Connection: close
Content-Type: image/gif
GIF89a.............!.......,...........D..;..


GET /ivps9x/jrog2-d50.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: b0905751.ivps9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 1780329
Last-Modified: Thu, 23 Apr 2015 17:33:46 GMT
ETag: "55392cfa-1b2a69"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:09 GMT
Connection: keep-alive
ASWsetupFPkgFil3..:..*..].....L?..P...GU.^....N...,..2^'...2...t.~.)..
Q5g...6`..N#)p.0.......o.......... .. _G.#.>.H.T\WvL...B..Qs..L.N2P
0...0)X..3.AE...C..L@.u~.......m.....U@:..........6.&a.b.v.5.....%....
I....U....G50........(X>..8.we....C....olXh......D.i"DcW......%K...
......%.yR.u.h..2._...6.!..p.G...S..1.......U...I$....&/4o........:.}.
}.....Z....(..L.T...f%.....n.gJ..)..*....v...Eu.......$....w..........
.1.....}.3t6.....u.....te.c...N..."..I3g...7...kL...w....?.....:#.k..Y
.[.J.-:.L.8i |}H.#.....iI.....{.....|p.tO.Ql.].....[s?p>.c..w..y...
..@I..b~r..XY..._;.~j04.n\ .>z4....9j...ui...........Wu..xah=Q.Tb..
....g..A.6....~....<..m....'...a.Vi.. Qe.......d.......=.83.<...
..........'..2./.u<M..1XR...c..).....*d.M@...{..WCi.....v..eK..[.gp
dy2."..s:pcd.'..a.I...K.S......u...'8....e......(:X_M....../.V..H.r...
..\.>W;.P%..U..!...s..&f.G..B..LsX......A..$P.).....|.........=.CIe
....;."7.ndP_........\....g..X..J.q!.Vk....l ....VtC....V.6.G...D6....
..~..37..X....S..F....1.W=..>.....g.z#<X.NL.@...:4..!...d...EC..
...B...c..A......W..n......w}T.J`6.)..o.t..#...c.....o..U..9.".. ....\
K...G.. .Y?....>z^P......A.|...}.....t....!...b...L}.}z.&<v..X.
.V...!*\.....)2....'.n.*w....Z....F.j [.?.\.`....f..c..w#..U.....ov..S
<B.r....XW.y..E.Db..U........kY...k.f.....!..i.(....u.!...sd...k..L
5..Oo.rq......:.i'.<j...,.#....G...FD/.s.....F({k.m.V8....N:.[u. 6.
xM'?....y.p5.G~D?R1...z..Xsa..{.......S..9...j o.c.R...^.{-.2.m...N.e.
...a....i.1..N..IH......c..Pi..K..u,...@g.4Z...=.....a...@.......8

<<< skipped >>>

GET /iavs9x/part-setup_ais-8aa.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: v4142311.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 80540
Last-Modified: Tue, 21 Apr 2015 16:34:24 GMT
ETag: "55367c10-13a9c"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:24 GMT
Connection: keep-alive
ASWsetupFPkgFile....<:..x..].\...'..Q..El....s.nOU,....P.I(J3.`...v
......?.......^.sw.......}.{..f.3..3...{.Ry..vvvA.v...i.%.hu1.$.......
.7...T..."[e...p.J..=........d..^.g.t2.k)..4z........VeoT.......`.q...
.......U.2$4...d......[..!......Vk;....j...<..x..=t..........}....g
F.;.....lgw.>....]...........;..........N.Tc.g|....b......K...l]...
.$..p!...._...7=d.}....:..s..O.......12e......EW......].\#...H....!5.;
.Bj..N.R..~N.F.......p%5.....H..Jj...Dj.YP....3..]..R..&...S.......$..
.j..;]...|......T...L..I. ..q.kf7xw...........=....".......=;...b...SS
..z8.I.5 ..TKz....5.I.t...Z...H...t .2..'...kO...Lu..1.R-..Z?....lR..&
gt;.b.....4....V[&..q..S....}3./.%.......o7m....n.p.......n=..duh^.[..
.....{].D.ta.N.f.L...S!4..D. .Ai6..2.0....t...xs.....v..0.p....W.^..}=
.6.....6;.4.........]..f......5.... .v...=...Ik...?.!%je...3%.....D..P
m.....-&Rm.....o.9.m.....].A..D.u...O.4r5..Mr...4...ZN...{.....y..mS.
<...........]...t......>yS...*.7....r.~....R..1.).....o .Sk.N..P
:MdR.}z.5...S...I'...@.2.tNA.T.d?.....Xh.YOf...K.;G.......u3E3'.=..1t/
;......O...O9.{P...^y.{9...,- t...MdMz..1.......5....~..Q...d?EzWK..p.
.#3|............/..w>...Q?[.e.q.3.ZHg.xp..._..*.....s}.....?.Ky'.F.
v...-.(...)....D.(..}.r..'eR..SE5z..T.......T...6.......i.j..]rL.NoLNN
0W..`A.pLx.....q...vm..~[.Z........]^...Q...{L.tJ...\..M...u..W.l....&
lt;.s.Z..$..|..DUM...b.J.6PJ.j. .Z.. ..<....r$...D)..L)..4:Z..`.4..
@.;............r,..},..G.#.C...%o.....h....,."....8.<..(MbJ.!.or...
.U..........P.....].G&...d.3......C.a....a.jG.&.D..H.....&Z.`.c..C

<<< skipped >>>

GET /ivps9x/vps_win64-ca0.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l3362258.ivps9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 2551506
Last-Modified: Thu, 23 Apr 2015 17:27:30 GMT
ETag: "55392b82-26eed2"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 10:00:55 GMT
Connection: keep-alive
ASWsetupFPkgFil3..e.r.&.].....$.....g;E.N\"..m..I.#,,....G.nU{&..*....
E.Io.H.D......5.....3..dA.A.Q......ONi..`.>.\..L../Yx.w......*.L.'J
&iu.b.....T....R....").....gJ0~.......[OS..)..Kp..IG..s8....j..M:q.ZG.
...J....N2S.?&...B7.$..a`.#.fW..dJ.....&.."J..........f.....r[g.......
.....{.W.U.mG-.$.&N4>Y...f?...o.f..e..G..y.=(....c.(]..*.k...}YD.D&
gt;.K....6.~.2o>............. ...6.\...;..13..Y...)k....I.-p...).;y
..AN...}0..Z.... .=.R ......ir5../..._.m.5.TV...sq\.` ...w@qr.p.f.....
....iOB....@..p...W!x@....`a....k>I....J.."...So6!g....L8Z..vOSa..g
9...-3A.3... ...'=F...w>..8 at?.Uq........P.H.cO._CX....,....:...P;
..|V.kG..&.....u|..Ov......u..........[.fz.&...aW..Yy.y"U.ci.;M...@5..
..Y..A..3.......I...R ..........V.L]gC`....>...=..h..../N....(..2.T
.?9......^..TM...b.............T..pl/H._.|.?.>.{Vg{......]X.&H.F..d
,..L......v..3...(A.....\.O......6..I....~...C.%zS*..3x......{..q ..A.
<...'&...=..O...i..w.?.. ..z..J.'.....h8J...AN....-..v...'../a..#[:
.7(..G..f.V.....Y.{. .;..B.2.6.L..,?\z.O8x....LV..c./.18gt_.i.&tftj{..
..vI.$..w.6,..........-...)).y.;..;......2t&r%.A-..{..4.x...D...|.....
..U=......(..do....S..VM.z.c$...(.U{Y#%..J7Z).......j..kuh.)......Z...
....L......0......\E(<.a..'~|.E.nq.t.!>.7.G........:1..N..(.#9j,
.b....x....7A....L...R...E...@9t.......s......O.%O..... ...W..s..?...i
...u..%.R.?.#.p.'.?.V.....e@~..eQ..OfA..M.qH...2.. .:..Tt..X....;....|
1@u#.(.J...K.w[...(I.SJ5..."..%p.B3O.... .6.....'.n......;.$...I.4. R.
x.../_ .#.]ko.....P%..)...................,....n..Kk#"...,........

<<< skipped >>>

GET /iavs9x/setgui_ais-8aa-8a7.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 1352
Last-Modified: Tue, 21 Apr 2015 16:34:10 GMT
ETag: "55367c02-548"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:41 GMT
Connection: keep-alive
ASWsetupDPkgFil2..e0..e0..................e0......e0.........x....G.BS
DIFF405................e0.....BZh91AY&SY...w.....x...@..... .!.=F ..T.
.w..rE8P....wBZh91AY&SY...........p.. .8.r $2...":.....(1.............
......444h44dz.G.i.4.*A.......h....4.t.!...F..$.(.. .HE.@..I..Z..*.n..
v..5.(.q..........C.H..j..|.%s...".............E..nK....t..s=6..4idQEU
]f '=%..@..I#...).....GPBZh91AY&SY.A....R.............................
........@..'.i...F#...M1..C..M.......yG.4....A..h...`.=&j<..6.OQ...
<...).ze..x..(y5='...I..L.1=G.1#j...4.Q....4zM.....i.`..h..........
...`................&.i.lW..!...{...O.......#..@.y0..7..M....K...$..{.
.1DZ........U...e.B>...M;..CW(........:q@17..iY...zI. >.I>y..
.,\.7..^N#.@...6c..-.'....i(..%.*)..?..eu....^.*...=5..)C-........~..(
.....E...8.{o.MH..^...T.1k.<..C....b.J(f.:..V..7...3...C...."K...}w
i.r.6...zq7"&(D..%........d..?.....l.i...AJJ..}(........B... g2..0i(/0
......QU.F.;".8.b.j....c.....=...U.TPC.`L.^.D.O$<|.K.........X.6...
.M....8.y.;...4.........Y%..Ev.......f.&Dt!.C....I..R..N....J..=.'..=0
...Go.3:-.'....`.,e6..;L .4y...M8..#........J.........=.W..K.h~...t...
.....O....<{S...}.k.R. ..L..(.a3.R.....9Bg.....-..;C...4........3R.
.....j...k....pxO..&\....~$..".?.j.. _..Ei.#....M.l.B..j...../]..*8...
..x.....,.`......=@.U.P.VF.a...rE8P..A..........Q.0...........ck.A....
3y..Qf..!#O...W.R.~.C........X...,...~ASWSig2B..

<<< skipped >>>

GET /iavs9x/ngiodriver_x86_ais-8aa-8a7.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 1470
Last-Modified: Tue, 21 Apr 2015 16:34:01 GMT
ETag: "55367bf9-5be"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:37 GMT
Connection: keep-alive
ASWsetupDPkgFil2.(F..(F......U...........(F......(F......9...x......BS
DIFF400.......W.......(F......BZh91AY&SYL..A.....X.!... .1....jDD. <
;]...BA3V..BZh91AY&SY.>.9.......Yf.h*.....v....m.}"..#..O. ......#(
i.......z..4........L..M..4...............@i...z...............,......
b\#6..D..H.4...@PBK@..k.-.&.........C...dB.y...........(...Jz.XA...[..
..Y..{'T.l..\..N .f$x..A...a6..S.."^......_eIJ.-qCO...ZI...S.c..,..C .
..'R..$........S..?.A.P......iy.n......5.$..D......W.F...~...B.W....rE
8P..>.9BZh91AY&SY......Q......................~...............@.)..
y......z.h..0&....4...M..1.i..L...M2..a.....z.Q.dmO$i.OS...h...=G..O&.
......&...I....z&.i....2......................... ....A!... @@..x9.D..
.R. .a..fT.....y.0.Q...dF%.|.a...F2.m0R.!...F..#@...W>2. .$....O...
.iI.....K...:.Q..s.~.._A4.@xf..S..m..^.......d../......w...`.K..n.V3`x
.....&...J...k)..IS...V.`.)...<S.0 .(:..y....2.U..............Gt..T
.mj...B...11|cR...7.}..|............I......w.T..e..5.j.@.|.....WuRL.vZ
..;gLt..j...o}..m../.,....a...I..A.b"...*. .]..a.U?Q..xp...W2.l.K.2.#.
{.t...5.~|...(g....J.....gQKw_g.B...9<9d...o9{....X.@=.yf.....Gc...
.E. ..y........."A."K. ....O%.".?\.:W....pJ1..^.2"&..S....].P...).?.}R
!sL.M....S.Q.E.......js._.y..j....p.L..m..}...j,.ZZ.YZRV..02...vC.....
.`.s.R.M..o...0..8..J.@a'r.LS.{.]......../Y.M%.7.r.A....[....c .N...uJ
~x"s..4...1 ...DY........H.zfJS<..UD.o.........K.d...$............X
.xWOT]...BC.G..s.T.a....E..'.......6...#_C~|..@.m.f|......hq.m..c|....
,.......O...0ASWSig2B..

<<< skipped >>>

GET /iavs9x/ngiodriver_x64_ais-8aa-8a7.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 1491
Last-Modified: Tue, 21 Apr 2015 16:34:01 GMT
ETag: "55367bf9-5d3"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:35 GMT
Connection: keep-alive
ASWsetupDPkgFil2.(D..(D......j...........(D......(D..C...N...x..C...BS
DIFF400.......[.......(D......BZh91AY&SY@M.......X.!. . .1....jDD. <
;]...BA.7..BZh91AY&SY0............;..(".?...............^.T.mr....Jz..
...i.@..4z...h=@.hz...M.....=@7...mA...............@.........ps..G..%i
..Xy.@B0 ....l..@R."*.`@.Xpe ..k....G.v.....76.7.D....b~~.*.SsAp..(.-.
.Ej .......~.........A... .2^L.<.fI.........S....;.;p.....J.i...7^.
6@...[..cIb.'[.=(.d v...9...f.}.u...G]......F...".......df.NX.b..:P...
....p. `!..BZh91AY&SYE................................w..........H..H.
..#.z.Sjz.Hz..4h=&.......yC..<...m4.<.........Q.Sj.Q......hzi...
OD4<D.2.<..P..T.L.2O.=5=5=M...............i.i...Q.....M.0.h.4...
....4..4..!C.&O....$ ..wX\`i...4.s.X2..6p..........dh_(~:..;-.-.....{2
..0....M.E.E[.HB.[....#...,.!f...L...3..<c..xY. ...p......F.*......
.<.M....DW...........",..H...x...x.^...x...z.2..R..a.<g.1...F...
.....D..../5.L..,j.t..='y...@....j.....$.'#....\5.uP..8.Q.U...^....O.~
.kJ...9AXA2...&..b...V.....d.....{j.x5....HDk...yk..8...JU.%...x...}|.
...)".Gi..D....&.....js..)A..i ... j..'.L....*A......)...TJ.....Y\`...
..u$Aw.....p..|..Z.....R t5.....].SjE.....#A........#t...-...0v._G.p%.
.i(q...;...AY..T.Xp..g..G:8..PH.;>{..R.WK...p....BX.y..o...nS....)
.b...Mw.T.[..,.......T.R.4..;|...t...;k#.xj(]3.FZu`3_......I.1...u...&
gt;...4.Q..F].. 'j....g~1?...Sr.S..17){Y^..u..N.....]*./.'.....5....{.
.|.\L.._.....J...`../.T9P...bJ..w.:n....).........h_N..........i.n...Y
.*\) p;=L..O....x.../F*.@.6...>6.kN......f..|.ASWSig2B..

<<< skipped >>>

GET /iavs9x/ngiodriver_x86_ais-8a6-8a0.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 3432
Last-Modified: Tue, 31 Mar 2015 10:59:23 GMT
ETag: "551a7e0b-d68"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:36 GMT
Connection: keep-alive
ASWsetupDPkgFil2..>..(F...................>......(F..........x.m
.y<....7....B...b....1G.h.Q./..r..1.7*....a.#W...9.;..Q*...x.....^.
.................Gk,......V...F.d.$.I....C5...Q.....~#Fm..(..$.a...%..
...iD......R:q..@.S....B.d.mB....hd..jw.xt/...........U.?...$..C...-..
c...z....8=.kH....l'./..cD5x...'....X0..Q..7...5........-........X)u..
.jn17*X....a..8.c..<.1..92$.L..1...).G...#.....V.......?3.l........
...-..A..`........ ....c..{..X.5.....$...c.F...... a.M[....b......2O:q
.s...N....}B0[ ....x..d...2J&..'D.....2...F.8ey.........~.`;.(.].....j
......r.........$m....p.$r..=Yd)..E...LT....VN.qd..28yM.vF.`.#.}.-..Zj
.[t'...T.....!..0!.y:....E..1.... z.G...N..a...28.n......x.F.K....\..$
.,..:.?.......6W.u..T...k.8Q...E....i..._.#1<....A. .g...N..S......
......#SR.!r..K|.UR.9..d.Y.kK.|...._./8..@E......-{Y.G./.xH;...Gh"....
.C..1..?Jk&...............gb.....c]C.R/.W|..Y..L.iF..pP{...(..u.P..L7.
7..vj....f...........EY..cPs.....>...rd]a.......[..........O....i..
..Gq..#..;.'..0...|..!j. .GZ...%-np.h..GY..."......Y.........v.....5..
Oa..w:iUG....~.O.9.GK....1js..>.......e<.=..1[.F@1oEqzg=\1..N..9
;....7O}...... I=.wn..W3._ UV.s.5.k... ...l|...1.Y..9.....I...).|....T
_.D<....fY....|.M..9.YQ.?.K Bg......D.J.A......=..9....sUAJ.M..&&.E
,(. ......l..Kd.[.`P..bZ....F_....E...0...Q6.r.I..t..2....z....r-r....
....i...h...#.*.mVhWK@....{3&.]....i./1i...%O...!v.Y]....b......._i.5.
..Eg....lc.W..........G........Lg..Vm....UZ.....h.. K.#..^F...0.X{}.U.
...L.......,...(.k.....A$.~...<.o..!..&(......9..V.\..5...N...W

<<< skipped >>>

GET /iavs9x/instup_ais-8a0-89e.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 336841
Last-Modified: Tue, 31 Mar 2015 10:57:55 GMT
ETag: "551a7db3-523c9"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:31 GMT
Connection: keep-alive
ASWsetupDPkgFil2...s...s.....`#............s.......s.M$..D#..x..W.z&..
k;.m......m.|k..m..m......N..*.*..*.K...0R....WQ...~.N.SAMsN&..r%.Q..c
.v....>.L.4H*..2~.0.#jP...EYR6......!A.SF.'$%P.oRO.7...hV ..B..)[[
...).B..g......W..T......`.&...1d.`...j.f..o.&....$.i.G:..eQx.....e...
.....(.1.e<..............B......H.C.x.....b...(!6.h..%.f..(?.0....$
.#.....'.4.!'....-..H.(h..G....UZ...m.._).E..h.5...v.D.9y..0.._..L....
..9........CV..B.......e..D.."~...."..lV.9..t&.o9.'.....hV...b>I.$/
E..!.g.s.e........:.}.s..V..$....B..h.E..g........u..tV...b.,.....|.y/
.z....J.......mH..HP...%.........X.5. . Cs1..........D\..%.}.s... {:.k
.t..D.}........*...H.8GD>B..M..P......]*G.......j..H>...x....h..
.............v.*,.. ..J....ak^.....2...Va...P......(:..qP^.Kqu....*.F.
.N.>0.`.H...A..0......e..a.~.H......(..0"...0.....T.K7';....{H.V...
Q..%.7. G.TH.. @.........{0..z...6B.b....!.......S.X.C.707_.Z..o.t....
..W.E..e3.6...Z....}:U{.%..y..O....l./..>r.c|f....c.. .V{...M..{E..
...W.-3....u.47#?.&..G.yX.....Z.........v..."V.E.Jf..aDP.......F$.....
. ~K.X.1'6.....D.L.,{........(...Yn...li#?A8.;*.w....X...Rn.7.5.m\i.:.
2...".>.........l.>k..S-.-......E....z....*k.m....,.I..yV.w.`.G.
.....:....3A] ......#m..\F...0!...e..1.......q$...J..Mui.....{F^.]..fC
...S6y.E.uw...`Z.;z...oZ...`}1...>.C........(K........if..X....H..!
...m..../..z......s...a.p%....."..E..f.H.m't............[0.m{b.*.W...=
...M.]x..PHA-..4.D..............h.Zc.........T2{#...I...X..p....ke....
....c.........r.D..?....&.M..[Oo..&.q..................3} .mp....4

<<< skipped >>>

GET /iavs9x/ais_cmp_secureline-7ce.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 261613
Last-Modified: Tue, 21 Apr 2015 16:30:26 GMT
ETag: "55367b22-3fded"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:13 GMT
Connection: keep-alive
ASWsetupFPkgFil3........].....$.....y....\"..m..h..s[.......q|.f......
.".I...9J.z.. A..|._..F..'..].L.s...7k$cf.X..h......'-Ev....p#..1:...!
.Q.5V#.6..P!4g.x.~. .....V.....@@......I........B...VK|t.f.D.......bV.
.U...$...PH^........J..NB'.D.#s9~].............>.F.O.u\=....k~.....
#n..............S...sv.....ADGk...<..a]9"..sO.r....a..I.JQ{}..X.7.h
.?....JG.T...S..e....jA .OW....p#.....Bab.%.\.....M.>.c.-(..l.n#...
..r.<.d.)....8....y...-c.g...Q .._|B....#..?..V....e.....g3...Q...9
z..3Q........L7......<....k.....x...X.t.%.......W`I...7.Y.}X.}D....
|..M.B.`.j|2..*J(@....5IO...T}N...L..')%%.k..'....u....c27.G.p .....|f
h9...QtXm....7w2..U45..D.Q.[..2&.j..uL"1...5..^l....!,.g*...z..B.u..Um
.h..@?X5....i_...().....C.Y)nN.~....\. .=.#Q.8e........`....lH...C..21
.. .....j....|....M..P~.......B..X.>p.... ...K^F..^2K1...n..../....
....4^...DZa.>.B8VPT..i9..*yd.g..42l...0b...S..U...n[....G..$O.4...
x.].....|..s..z...5............O...*S..5.x..!.H*.G.^T.l.W_QYx(.......N
..^..0UE.a)q....<)c...^B...x.]oO.(...k.....JrLx".Hq....$K....kj...R
^..W.....nH|Ox>.y..R..j. O!s>5..M.L.o..t....1..0..t.t:"..I.....R
.\...1{...L.}.u...1..Z....J8*....s..t.U....l...A...j7.i...Zh..Q3..f.e*
!>Z...h*p...N['(...V..G.K1.x.....EH...Ho.o.[B ..iLX..tys..J...9..$&
.....d....Y.B...d..~.).O"X..u..H..m.Z/r=:...daQmqOL.&D...5.....H?.i...
r..J.w............".K.C..R..QS.|..Z....~Ej...../>"~%nm.7....B ...."
5p....FA..1...........G.....Ub..mQ...#.......*.>.9U......:Lodb..Lb.
............T.>F..t......G#d..........*e....=.d. l.|.....5.k=..

<<< skipped >>>

GET /iavs9x/setgui_ais-8a0-89e.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 124150
Last-Modified: Tue, 31 Mar 2015 11:00:37 GMT
ETag: "551a7e55-1e4f6"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:39 GMT
Connection: keep-alive
ASWsetupDPkgFil2..]0..]0..................]0......]0.....q...x...c..L.
-......m....m.....m...>m.<..o~.;.If%U{'...?.....Q....`c.@..... .
.#...'.h[r3.kQ.h......^....a........ZJ.b.U.../.......D...-..X../..$...
I.. ......%-..,-.XEy.R_...$?.&..T.. .*....x..?(=../...Y....@..,.O....z
..p$.W.I.?X>P.X).....).$/.W..U..eZ...U....P<.-.K&....W\cS}.Z.M..
..z..:.......o../.-.kN.......R......}.L.7.\.F.A.)F...E......7..).Z....
.x...p.|i....C......S.....".w^e.(..PQ.,.......&.4..a..5.t]..z....T....
7t7 .....H.....Y.s.*.Ee....Z.........;C...@@7....SO....x.&.b.(*6.{.<
;2..R..$4<.O.............Z..?.....V...K..W.Md4..iV..u3%...}C3p.....
4..o....`..V.mX....s...A8.9..S<.1.Z.|o.....N.GC....ij2....S.A@.....
.^.....LLRr.^H{...jA.M.e]....$U...uZY/.g.zK3..0}.n....d:.[....d..>?
W...tX..h.d8....D.<wi.....b.q.....l.d.n.J}..O.d{..?..Y..v;~..UT..@.
...>...:..E....C.\.(r..i..X~...].t..^<G...~......96.. A.g;.j....
.....T.Ik...3N..,.b..y.Q8.a=.X...K....E*..C..k>~......(..m|...|....
H.l3m..,$.L...M.k...........a..aQ..,..y......:..!.1i..U.g..........`..
.z............^.....L3j<...i.r.f..d...2....D........2.L..^.a...<
....4V........{..$.......:......D4D6B...^~..$NXC;..c..........`...i.?0
n.f.E...`S.]q..7be....>..!.I...(.....{.h...R..a.....u./.!....;.Z&|.
.#..8......l...../x.I..R9T62...q...p.Wa...U...?S..gB..4[&l..fe...c..o.
.}..Ji5.d.i..._.....o..m}.|..,O<..:..{5.hH.q.s}a.,L..c.<.}pI...'
....E`.0..j7..(...KJ.*.x7.*.fk.....N............U...........{Z...e1...
...),:.....&k.VNi/SP../|X.$......U...Di....G.$....p.],.fiAl.4k.y..

<<< skipped >>>

GET /iavs9x/ais_gen_gui_cef-7ce.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 17657571
Last-Modified: Tue, 21 Apr 2015 16:31:54 GMT
ETag: "55367b7a-10d6ee3"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:23 GMT
Connection: keep-alive
ASWsetupFPkgFil3..T..n..].....$.....<..oOT..r@0.>D.....Q._.#.;..
._.&_}..6...........H..1^....V>..*...$..^.KD.....UH...\..c...#,..Z.
'..Q>....8..dQ%..)./.PU0..M..XFy.i..M.»q.@~q..hY.H5....kZ..T.....
W.ZeK.s..N.........;ZX.8I:5.C... A.............\.G.Td8...&P.Q..rf...w}
.@C..LA.....u2.....Cy.;..r....{.I........2.*90I...?....a;t>..m2..==
.m...9..Ri.....].y{.....}x.z.....S......T<.-5...:.....k...I..I7<
.............e..d7tX. .u....h.>....@.4.....#../.^....3.V..Z/.w._@S.
.m....1..tk^..p........0L.A...O....0...;b.....g|.T....s.).u..F..?.,..m
CN....Qi.{....Y.9...3@>.."..E.A.&f.......%.n..~.2.#.(J......[w.s7..
.@.d...dO<5..?..2...P8.y`?..e.....%..Ok...<...e..P.....E...2},js
.2z.*.j....X... 5.....^:O0=>c....%w.....m..Z.....@. Pf"..~......Z.N
.'..u..X .2...q.d.Q..o..G....9S.....3........]....!..7.]..CJT`!!...v..
...Q.I/..u....;.mx>.S0.=.p.[.,(iv7.....".h-...%:..I%.m.....*....d?.
...J......73...{.7^kr....\|...;...x...uyL...I......^).....#..`......@.
YPR.;Zggq.iH..Z.?. Q.L.C.%.]..y.3k-..@.........V.......2.....2.}../...
...-ZaR.j....c..E0..;=...b.AV6`.4.QH...Q.*...9X. .z.?z.v:/.....8:..Xi.
..9..Y2?6.....T..n..Y. .....\$..}.{..Q.pe.T....O;.]...y)z.*w.......x..
......|.z.n.G7.,..T4.k<..xY.V....ZV.........b......I.yr.._..d.,.._W
G.Tr..c.y..{..<.......yN..C-^...hz.. }...w.}...la:..........uW.8XY.
.....$.d`.b&....Z.q...^d&3c...v.X.[gDV.0.....5.?..|....L'U.,...T.S.T..
...3.x.H@...._.7....Y.}>..1.D&...7.......?..SW]..T..ku.[i.r.,.),..:
.9.....,.....w..L....$.{.q.{..xa)P....1.u..F.......!8(..I..J......

<<< skipped >>>

GET /__utm.gif?utmn=6334&utmac=MO-1405551-23&utmwv=4.4sh&utmp=view/fa-2015/en/privacy/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=- HTTP/1.1
User-Agent: avast! Antivirus
Host: VVV.google-analytics.com
Accept: */*


HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 19 Apr 2000 11:43:00 GMT
Last-Modified: Wed, 21 Jan 2004 19:51:30 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Wed, 15 Apr 2015 19:43:29 GMT
Server: Golfe2
Content-Length: 35
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Age: 742526
Alternate-Protocol: 80:quic,p=1
GIF89a.............,...........D..;..


GET /__utm.gif?utmn=19169&utmac=MO-1405551-23&utmwv=4.4sh&utmp=view/fa-2015/en/progress/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=- HTTP/1.1
User-Agent: avast! Antivirus
Host: VVV.google-analytics.com
Accept: */*


HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 19 Apr 2000 11:43:00 GMT
Last-Modified: Wed, 21 Jan 2004 19:51:30 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Wed, 15 Apr 2015 19:43:29 GMT
Server: Golfe2
Content-Length: 35
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Age: 742539
Alternate-Protocol: 80:quic,p=1
GIF89a.............,...........D..;..


GET /R/A1cKIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1
Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..d7.....ASU!VPSz.".
.,...t...w...x...uQ.g``p.0.N..,@\.h........Sfdt`..p.t..Q.%S.G0cI.C4C.C
,C.G.cI5#K3#.~.<c."..$.f-![f=&..O..........9....U.....,L@..g....*..
.C..&1<w.#......}E...^M.>.....`.\U.............z...h..=PASWSig2B
..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDQn98xMgoIBBDQn98xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..8a.....ASU!VPSz.".
.-...'...$...x...uQ.a``.p5.........6f..ua`xY.w/..Fe.F...L....3.=..G.^.
l]..n..j..E.P....zf.z.5...x....!...Ea..7.....hASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDFod8xMgoIBBDFod8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..ce.....ASU!VPSz.".
.....k...s...x...uQ.f``p.0.Nf..h V.ZvO..Q..l.........F;.3..C.P>..A.
....J.A.Ak.....!.6..$.$'!.</..x&......Y3..............KA1..Hh.^..wM
.C....Fk?4i...g.2Y9.=..n].L..N....v...s..P....j.[>ASWSig2B..0..nt>....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC3o98xMgoIBBC3o98xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1b8f....7ASU!VPSz."../...,....
...x..Y.P.].>{..t.t.4H....R.............V.A@.. .......wfg....=...S{
u..2'......K.......p..a...`... >.PY........._..Z!...3Y.r..._..{..3.
.. `8.....$..._.m?.Z.=.}..\.`.H.C.l....^..X.f.gKt..?......&.. .....}..
^.^o`.fJ....>F..D.2..q%?.=.~...Mu9....0...g...'....#..'G..;.p.Vb...
..P..&j....x\..i.....{.T.^...",/.d<m..S........8.si....W...3Z7...j7
..P.......)y.6.v...!.r.?..8..xGq.....7.T....J.SU..Nr.......I.[?G...e&g
t;s.*[gxX,..`}7...9.....p.L~...v.o6@.@.'z..S..C....K._.>6..(0....:
.-.^.O..V a............K....;7...L?n.....k.1J.A@.......Y.pE...q&N\8vV.
..g..>Q5^[N.....r3....f..r..b.%1..."........~g(Y........I..6..,:...
N.....p..% .("HZ...O....9........-.....5./...UB....P8..-.... ...C.u.5.
4c....T.OK..Z_.....OKQ..g...l.....T^.c.R.....*.2....n..!fc........E...
k(...L.Y.bY.v!lj....G..7.wkJ..,.C...iU....S;..&..`.;..@!'...M&.YZ..r..
.%.D.=...De.)6.<d.cv..\jo...C......p..R2(V....p...{m._....*.e_eK'.T
.G...|....c]^...U.`PrSm15.?,..}K...-g....h.a....4..x..Q......$...H..a.
(.0....=..g......*......f."..a..'......X.U/.=!..?..h.2...}.&.........T
Z...R..N=......4...L.g.... ....*.. .i.H.(z..D...@Af....cmF"E.Vv...Q&..
m.;K.7...(d}.S....N?..<.}.)3.c.&..DV.6!N.CM%G..........q..l{<.,.
..4.{b.j...YA..K.V.;q.....wN....#q5...}._....h.g.N0tVS.gf(P.S6.9Z2._..
..3...A".6...57.'..t..>.......;$b%..R....oZ.Zg....)..'.y....l.L....
..w..3............S.3.K....~...$l.......}...I1..k...;......u..x..&.c.y
j...f.R..'......`w.sO.....'.............".`cN.1...A.;F.......v...\

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDQpd8xMgoIBBDQpd8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..128.....ASU!VPSz."
..0...........x...uQ>.....`.....6..1..{.....[.'3.`..f\..<....Y.Q
.).E/%.$.11.!....A.....[.J....2..C..^QqQ*cr%.@.C.#c-#.n....d.#.....b..
.n.....dq``p....H,N..K..........J.h...h.I........'380..3.0;L..t..k..|.
.......i.k..`.............,.....7......t.T..]C...GB.t0.....TC.a.j,..z.
.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDIp98xMgoIBBDIp98xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..105.....ASU!VPSz."
..1...........x...uQ......`.=.H..qih.i7...Z.O..Q.A.A.......!.Y/.).....
.Jn..`...2.&......d..F}a............8-..'= r.z^.4)..Ihe.3.;.....,.V..*
.I....~.)1h110Z33l`.K;x.H....Y,.......}h=..........,....Z...1......P}.
..M..Z..8.zu.....Z..|]e.".m..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC9qd8xMgoIBBC9qd8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..86.....ASU!VPSz.".
.2...#... ...x...uQ.```.w2...............7_.an..p.e.Qg.. R.x....m...Q4
....x.....a.....[..m.SU.w.KU..e...P(B.....ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCkrd8xMgoIBBCkrd8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..14c.....ASU!VPSz."
..3...........x...uQ......j. ......$.M...`..........C...[.rL..@.W...1.
?..LN....S.J...k....u...b33...t.%.-G...D"g]r6..n.......$=v:.}.. .2...
.a...d.9.A....D .....$.J..#>............Z\..)32.31(X0X28M...$.Z..!.
..C....D!.........'#m ....K.[.U!.QE\....x ..U.`..s...1.Q.....f..;.....
...r.,.....r.z%..7.K_.G!st^7.~..j.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCTr98xMgoIBBCTr98xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1da5....;ASU!VPSz."..4...B....
...x.%.eX......A.;DPJ...n.%.;.A...n.....NA...[J.;..{...........{.{.kJ.
WQ..F.................g=`.....(....F'.n..~.....y.g.(%'....O...... .J.0
...n..3r..k7.......7...z..z..;...(a...)..}.;.~....H...jS...>...Jf..
4.......DVHq.W4..%8rz.@T......../!c. ....bSo5E_?..=v....k..e.rkq.h#gR.
.y.,(g...=....Q....|.4..!.c>...@M....t.5.....;?..VoI4......a....z.2
....v....l.g....Yz.....1.... ......[....)..)......#eo:.....al.}.8b.. .
...E.Q;....3Qs.5...&.....!........a....>......}.......N.8^...?..{x.
.^.m.0u......$..\h.".c...J...FJjV.P......M...a...}...X.=.r.l........W*
$$.........U...>.dU).].*...`.0?...E.e...\B`...8RA.RC..4M.G.q..aD...
...J..AE.......g.y..-n..!.z\6I...ixMN..v.UJ.-.1..\.....J.0..../...aX..
V...3..cw.T.Z..18w.)ce...o~X.....0.L..9C1".h.L..B..g.j..........y..4"D
.H8m.-.=,..........0....%.}....l...r<....HO...*..SK.[.<5...Uj.1.
.-...V=}....ATZ..m.....x.....1 .v..!..aA]..vG.........._..on.:5.9....
..G|.....C.#......|>R.w5....%{....T........Ykn...{.......@..g2...\g
.......;.@k9....! ....DI$`..n3....J`...?.._.3?}X....v.A.X\..$7UP....(Y
.?.qr.?...p.~UYE...}p. .....!U .....^...u...&*.;.m.,.....?:...?.Y.cTX.
.....0.. 9.2.........w_D4.6.!..R...1..(Z[.;....cs# ..z...[.}!........c
.Z.. ...K..].k..{....&.....R4U.>cv..S.....g....". a.x....4F/X](.!..
j...F>Q_.... .....%...._......^!Tf..%..E....B.<.........k...>
W..z.....&$...C.D........~.k.3..:F.L...V..}..,....I..?...o. 0...uZ..$.
.p..........qm...G.\}..T.a.....K1.9]O_....Z.......f..0}?.S.....=Y.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCdsd8xMgoIBBCdsd8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..86.....ASU!VPSz.".
.....#... ...x...uQ.```.w2.......e.u='..[.fw0...[.x...3..-$.. R.>..
.)...%q..#*....B...P..^4..<z.>.0...2.uC.x...=ASWSig2B..0..>....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDktd8xMgoIBBDktd8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..f8.....ASU!VPSz.".
.............x...uQ......j. ..........{|......#[...].L... ....v.SfdTb
Pe0....d$.(.d2.a...0.&F.I...B...L.L...60Z.3^`L..... ....8i.h.P.|:HG:HG
..^IjE.cI.#c..Cc......k.l...b...GV"PK........&.O9m.8P.k..mPivQ..[.....
.q.........U..R.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDyt98xMgoIBBDyt98xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..b6.....ASU!VPSz.".
.....S...W...x...uQ.g``p.0.vg..{ ...uO..Q~b...B..m.=&.....I..&..^L..L.
..YmY.X..........**.ZX8....K..@....R6.....-.w.s...p....y7.?i.v..M{.}RB
..;..t..6u.. G.]w..cASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCDut8xMgoIBBCDut8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..95c.....ASU!VPSz."............
..x.M.y .[............PI!.2Q.5K.VQ..B"J...2..W....,i".f..R.,.0t.P.....
...o..y..;.{..<...T#..li..sH.\......1>\..5v.......F.U....UP.A...
0V.1........v4..1K...f.R..G|iL}A...;....n.......L...V..]x`...{...\...B
...o..,......%........E...8M......w..W%b.....W..Dq. .p..DU/7....AA9...
...olp.G......|<.Q.....[Rx.)NE......mf.z...s.i....e.G..t...O...1~..
../.....O.U.3..W...k-.zx.....=.e9tN..Efc.((j.......X.....x...YG>..2
D.~...^.O.Q...5y..W.)*..nXM7............0...I.....z..........U..n.b...
.X.f.V.`j.@._.1.l.i>b`.=l<...z.....)ed.Qf..4.T .$..DK&.......9.b
..n...G..|.j...cH.?....y.W.e.[...?..1.1.MZ........e...T..P.l_.e!.X...)
.g.%7.]...X..(..L........>......h....\.V...#..v.M'.C`DW.V..8b{.....
..2`U........-..y...........F..Y..r....:9N\...m]gl....i...g&...1H.$...
a~...q...l....x!n.7...H.b..B.i.........3..oc..}I`.E..t....U...R.......
...lT9.&....^M.)S*..t.j...u.....J3.k.....k.(...`...:.....&...xn@....&l
t;]..E:3..K..P.s;.. ..%.Y..lm......A~....fW|O.....d..?._.X..b1EU.t.*."
..H.MZ..d..!...........nt-&.@moSs86%.....q......y.).....R=b...R....*..
.~.)...n.l......{..U.!M..M....o$..`=F._......}.....zl..I.&........k.Gs
.c2...w.-..@...B-....$-@`.`8b.N*w3......|..%zPw@.'.....{.Ig:.s.B......
/.T,...m..I..P[.5..4.....1......Y.,.O/8*//..n.9w...g\.}......2.z5a1.QG
.._.........Gy0e.Z..7...h.GE..W..X.pU..Z.-.....Ta....a...Z.9.YOy..Q.C
..*.b.8...(6.......*2...;q....1.....2xI .YY_2.@w.%).R..Wy4.)`...E.M. .
...o...-]..oZ...4.6A..yR......)hb..../Rk=....'...O^>....a=T'z..

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCYvN8xMgoIBBCYvN8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..183e....0ASU!VPSz."..........4
...x.%.w<..........d..G:(....P.T.l..D2.=....ee&...(;#2.w?~..x....s.
..\...z^..).K...PCR..............LG#s..17.I.....g]u..m...F...\$.,^k...
.........d?..m.=.".a.......E^.E2..q).Sh..6.J......^.s.s[.....`......-.
...3......nU)...........7...-(...........Z..n.u......c....N.o..]A.%-q.
".w....8.].5....%......I^.=.UXL..V..Q.$...q."...N.G(0.%8"..........^.b
....Q....Sc24........U..[...1H..8.!.1nq..ui'...S....N.....u.:z.%TtF.h.
.7.=.z.....T.......>......m|......=)B.....iy.W........?...=..R.....
...._.j.Z..(s..v.\l..%...n.....W.&..1..M....^1.....d...`..3.....{.....
.N`.zz...O....T..zA.0..\.u.8.......K...}pug.^.]D...!.....?..k..FJk.C..
.P....0...7....\..........k...lm..\.q0M..".V..... .1.G`8.......7.....Q
P..Z.^..3.......Z.....:..R....%..K....cM?.Aq?a..2m......q.d...Z.."..B.
...p.G..Pi..{.......G:u9H.b.|.,...J.=......25;7.....3.R.z....<..7.@
.0..;...IK..o[p"....C...u....8*.U.._~d....XS.....!...2..#....v........
.C...lt?...w.q..w.1.m.9.-H...Y..........k..6.p.1.t..m ........=..;9..'
.e......O./...Z..<..N......23O.6..)f.A.......!........6.YP.D.....9.
k.y\.-...vB..VE.*....`..[.0,-....Sx..%A..Jl....&H.`....ah..;....b.c.G.
...j..7Z.PS.3!b...P.r$..s..._.....`k..I..Y&.i.[8.s.....vQ..q......15.!
..~.w.}..<......G.A..].n._US...c.V.eA.7f...r......u|.......LD..#...
.....=..RD................V.........;.&......g...Sf\.z.`.w/X=...,....=
.I....).....t..An.....\./.W...y.......K.'.s.w.-..x....B*P3.n...|J..L.P
. ......(Q.06X.?....t..[[.)..........{.*...D.,..\,.&.V...g.P......

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDbvt8xMgoIBBDbvt8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..c1.....ASU!VPSz.".
.....^...^...x...uQ.c``p.0....,@\..........SfdT.tBRA.1...A.iR......;..
.....H......L......'3.0&.360.p..$.M..`.}..@.Bi........#A..Zl6\.....22X
N..................#...O...,J..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDnwN8xMgoIBBDnwN8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..d8.....ASU!VPSz.".
.....u...v...x...uQ.c``.p5.........M.w\7NdX......"?4.X[.(...e0........
...w2.6.2jV.E..N....B.#&5../....h|.P....l.p.........8..<t4..D../5..
k....'..xZb..*EX.(..r......q..m..i.......-.u]._.Zk...y..lASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDXwt8xMgoIBBDXwt8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..c1.....ASU!VPSz.".
.....^...b...x...uQ.b``p.0..b../ V...O..Q....A...A..E...A)..S5#K.C##.Z
.".:.).C.=..H6..!.E...(.19n.CC.......=....=$.`...YS...X.tt..z..M.=...M
5$!..q..o.&q....o.?.lL.....W#n-ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDJxN8xMgoIBBDJxN8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..ef.....ASU!VPSz.".
.............x...uQ.```p.0..`... V.:xO..Q.A..G....!...!n2C.c.0...JF..&
.V.*uF....,l....l..2.....;M..u.J.ue..bq.wq.f.`..LI.d*I.a....d.-....Z..
.x )..`d..;..U.mdF...'F&w5.h.H..l.R......F.3.B.....[6....-(.5..jz.b...
Q..5.r.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC7xt8xMgoIBBC7xt8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..ba.....ASU!VPSz.".
.....W...[...x...uQ.f``p.0..f..g v.:|O..Q..G.A.2....0c.......d.3Fsa.SL
...>0..3n`......'...1.$. ..c..@/..\!.t...S..p...M....R.3..'.&OP~.C}
/...[0.5..0\.~U0....q.Cm.R.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCwyN8xMgoIBBCwyN8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..193b....2ASU!VPSz."..........*
...x.%.w8Wo..?....."d.-dD.....Udeg..Q......H!d.....?{<.y.s].:......
?.~.?..u...8....UE........^..D.....w...t.(...Y...*....(.Z........1wg..
..\/z../Q.8..f}-QU.b..g.4R.#.......;.R_S.]|.=...V3.t.X..........%..n.{
....m.@..Oh........b........^.....O.......,...X.Y.I.$zr*........B8...L
.S.\..m.!R...9"7...;..7.i....Y.=*...S`.-Sc..........c.n..S;.7..L...#..
.....r..^}1{...~w>.............}..l...L...i4-J.y.lPE...>.L^...zz
...]...C...k..H.....h.8T.x....OH.)...=.$.[...._ ........R.......O.....
".\n*fg......yU.....d'g8B^?.>...d......-...6u.......?2C....z..>.
.J. _..0J}.I@..6.....W...ku.....Qjf`..=.v.....)/..4...(v...._...{ePE..
3....Dbq.@....l.d .....s/.....!..Ltdc...y.B...z7......}..\a.^.V.\Y..H.
..Al.y)...!@... ..k....{..#4....4...D........3.....5.?...'.)........C.
V^..........Q......j..u...7...<...]T......5..e..\.b.s..K...8......^
9.....i'e..B...SE....|.Gd.. .C.....].g...d...........v..O.l.~.[.{,.$U.
.}...H.[.@..Jbe.-..o....%Zxv....:.......la...c...U.)... .4...A.......y
JE4X...T.!.i.r]o3.A.T...."..........wz...|A.5U....S..%x.):K&.@.7$.....
...p....& .B.Ka.hg~..N.@@.....K.v............X..@RD...=.......v:..v..j
........z..k.H/[..ti..'.5(1N...e..Y......(.. .......E..^>..........
&.8!6..w..`..@.m......l.J...e.8.y.......C.W...s.R..<#..O..9.v?.....
...zW...e.9...'.<.R.|.#..|..,c..........]~...{-..r%.I....6.]..XF..-
I.#....a../..._.Ao,.........,.......Q.zi.:.K..^da.c..T.e..=.....x.$8.w
..l,G....[..,.;.w.7.....tqR.K.....-...Q..v.7?3j]....-.x...~......:

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDEyt8xMgoIBBDEyt8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..fc.....ASU!VPSz.".
.............x...uQ......j........f.8.g.`b..__bom..$6..r..u!...m..?...
.`......@..u..2#.....Fe.[f..v;f.........T...&..R&.....*............H..
.....X...xf......2 nda.....Q.FD....}...........]='.%...).<'[..\...&
lt;h}n)y..s...96zD.^.`C%jMASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDkzN8xMgoIBBDkzN8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..bb.....ASU!VPSz.".
.....X...Z...x...uQ.b``p.0..b..' v.:~O..Qa.H..P.;m..........8.'1...1.y
.800..`. *..dL...`..'...Y.".4..S&.=8..C..7...:f...WY..j...=....fV...[j
4...... ..O....f.P....*.SASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD2zt8xMgoIBBD2zt8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..459.....ASU!VPSz."
..........P...x.uTml.U.>.... .n}.W5...(..:...&v[;.....8D."....,e...
)b.A..%D..f"..&.0@..E..A......P.."B.e.....e.......=.<.y.m.......P..
6....}..;.~'.........Dt.........(.....;%."Z.VY..7..".. .q.}LD=_..D....
._.....?....I..v.c."....&<.v.h..W..T..&.7.l............. 8.CDGz...]
.>%.hz...}.~$&..e_.{....5......'.t.n.|.9..1.......Vb..B..=.....h.T?
-S...Vy........[..u.[>r....|.....].!wb........R.|..D"..R.......B.7'
..._.'.....%7.|pA......~..X.C..k.cO ..n.o-f....l.1t$..2..O1.2....!....
...uv...{..i.mP.e..%.c..FKf..*[..x.jA....U.>L$.5......`.......6i...
`.xA..m.E&.&9.h*.7.|.9usi..1.........Ah......U c...#nCV.4e....Uj.!...
Rs.s. .T..V....z.2H.U.........pR.l....tW..]v|.........JS....'?w.P..5.3
.P.o..-..#.... Pk.cuT...5.0.4hxYY.ZMV.3.kx...p.....>@..1[X.....L.ZU
.1....f}!.. ...t.@..K....V..."&2.1....O......-...y.d.I.g........b.mV?0
.......a......D.....R.^xR..s.m.........^K..`....N.......6...Kr..rQ'.g.
..... .....aq.>t.M.d.M.|..3w(.1~ 6..G.T...".i.,A7..~kL........zn.6j
...l....)..]...!M!...VK.`\$..0z..Y...'...s.....q.K..rl'.>...N._...|
......q..v=.....bkK=..R9s..]..3.<.s.wP../......FI.Q[#@. ......a..|t
..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDV2d8xMgoIBBDV2d8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..115.....ASU!VPSz."............
..x...uQ......j. ......../.t....;..........j...X.X44T..H.r=......`....
...?.#.E...(.1...A..........&-a....0...&d(..!d.b..X..2.....'q.210U3.j.
5(1q..1X..pf~.....W.Z..X.....X.......t..?..!8.avu.&.r.[...._.9..E.j|.m
....u....c.;*~..O..aj...j...h.=..8ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDO298xMgoIBBDO298xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..b6.....ASU!VPSz.".
.....S...U...x...uQ.e``.p5........s..w..00L.......!..SmM..P.b.........
..WbZ.....................I..2..YD...J........E.........)g*&......p..?
...."......U..H.wz.%ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDO3d8xMgoIBBDO3d8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..26dd....MASU!VPSz."......z&...
'..x.%.eX.........i.;....i.............G7..(...t#...x?..........<..
~E.....k..h.....O9.j...#..R..........rs.-./.La!q..JM...i.d......Q..../
.&.g..."4.k...nI...:=....O$.d./M/....s..t..).&.....).H....R..L&.=^.5..
3&.....Q.\......E.../U....kP....A...E...m....%...#4....y.....w.t......
..\Lr......lx.....8.0C.H.I .O_........2Zy...a....S.z...w..m.0......KB0
O...cH.b..~l..,.`.G.Y.J..U.....^.....y......da....g........pxf.N.....a
<L..".:..[.....4..p...`.x..&,j..wf.g)...TW,.MX. .dw.c.q.'....0j$.Z.
..P%... 0...x...2..6....#..;.d......X*.F......:....#..p..........%}..f
..Iqj..M...9....'\..........O~..D..%.7.@.....g2gy...QJ.N6g'.F..0t.....
7...y=A.An..b...*.?..=...].sv,."d.$|.m.G.............{.= Z.hbm[o}.>
x....~'......ef.oP2.{*.$-...`.D..@..O.{......ND..p.......}.......1.L..
...[=.,...)>.&l.zF."1..8..g.=.......8......U..P#U.*....GzYi@....B..
F. n........v.idB.....-..]fZE.blc....q.....x...p%......c....".......O0
..r@.uX..)...C2.x.L.......e.O.3i.x.z(..4..L.G.'....p83......NS../.i/..
..U.j...."....... i.._."...g......$.)d....3t.(.1.g.[[CR........wB^x.s.
.....Rsb.....;7R.z5......}...O.S.\.]....;Tj.=...1y.S.h.8E*...P....S...
..(.{g.....'$..sT.@.C05..u....h...&.....q.O.D.S...U.&.....OF..n..<.
U...KF.B-A..&.....m...^.....0.xM ...[..l.Zs..P..;f..m...:].~..3.H..a..
|9?..H)......g....$_=..0Y.E.._.1..0#...o.~..HBNu.H......'...F...g.._..
..mN*P......r.....a....I.n.4...p.#.zG....._...'..4.....{r..{....P&Ryv0
.r.... ...|.n>....9...p...r.............m....8.O.N.u[.[f),>.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDI398xMgoIBBDI398xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1bab....7ASU!VPSz."......H....
...x.%YuP...>K %.".-.%....)..%]. ...%.%-..iD....A.....3;..3{..g?O..
....F...E^6.......|[....|.....K{ ......E...h).Br*!.....:....A.g..:...T
.g.r.!.[....t-dN................DR..e.sK K...y....B1.P.yq.F...d Y.../#
Y.;4.._.....V-.p|(o.N.K...Q.~....zt..l~....B9.5..G...~....etc......j.T
j.k.m\......0..NH.J....&.:.......K}. ~v.C.....LH..QOxz6..-.*...;a`t.P.
...h..j<....HRr...G.C.d............d .Y.......&>..#..R.z~.@$;i.A
...@.57..^.-.t?a..b#.W........n....7.A...4.0.{P..Y'...@tj..1..\v......
..5.0........a. J.........un.T............e....e....s..(.;.a.....j.YW
..M.%......Ky.7. .)._.\I.S#1F.$......H....rB1a8...xX...e.a!>..S.{#.
r:..Xy#...=..^........3K..O./.|.&..o..o}?8..}"......q..)...&..:].Q..8.
.....k...n.....,.C...!........c..Z9....L.KKv....0...../}..iEw...e.:L..
...%3....D_..`u....._&..Z.*. &b#O[.......=....tQ.k..z.;cJ.T...x.....f.
..y.r.../|;...9v.,...%.......w.Jn.g..^...E.....>......&....T.p... A
J."..%O.....v.p5...,4.n.%v]..0B.C..d..6#C..wX:......e.Py~M.D....*....s
/...J.......Z0-.&........P.~...D........@T....... ;...7...]L...}Y...}.
.......X.q[-."P.....Z.F..NQ....H<..B....A@...u..76........T.w..H.#.
.e4...9.t..B.SJ\.M,...#...y.7....,.......PS9.....g..x%q.y.R....K...i..
..sPxB .1..if9.G..........r.U....:.........._d.........<..wz...k..M
.E..z.J......e.Yv.F.k......D.......*[L.....2...... ....0.....L.{....~.
O.R..W...)[..{.:*}.E..@.[.o..q...'.q....=v..TA...@X.....X{>..b27*..
.........Q...<).`..'D..a[..|......=.p..g.r.p{.S.<.&...$2..L.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD_4d8xMgoIBBD_4d8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..e3.....ASU!VPSz.".
.............x...uQ.a``p.0..a... ..z}O..Q.A..d../F.....VL..6....mD..z.
.X....2&3<....Le,...U)MP.dR.."...;AW......$..G.?".@.1....L.....R3E.
........6..H_h....h..uDwh.G0.[..N...X........B5...z.......[*........AS
WSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCF5N8xMgoIBBCF5N8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..c8.....ASU!VPSz.".
.....e...h...x...uQN```.p5........{k.'...3.....p..,..Sm...0.bc........
.'.....gp.$..(...........>...S.0...fF...N.........t0...Aq....h..`..
.....9ji.Y.M.f........2...`EG!*...a0.L/..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCO5t8xMgoIBBCO5t8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..35f.....ASU!VPSz."
..........X...x.%.},.q.........v.(Q.MB...p.]...#cm.9Okyj&..C,..#S:.a..
...N..y.....C...VhW....w..>......`.r(...Y C.H.dFk......../%Q.>hT
#)....D.i...B(....'H..h. CP...v..z..m.J...r..}. =C ..7.^Q......^W @..
.....r...-d1..`8.3.7i..&`.............Mh.|Z..".......#.h.~IL<w..w}.
...ZH. ....7hm.v...ZG..B..)..g..s2]D...z....~.P$E....8...3 .BV..4 .M/.
}.....}1.\tr.M..>O.....".Z.Uh.~.%...d.u.m.r1Z>..U.tt...N..:....&
gt;.1...c..`......}R.A.A.r.V..:...q..f.....}D..~U...NY...Ne9...>..`
.. .dM4..3...V`...-m.%s...3..\^...........3/.?2#jZ...i.v.RU....yg....6
?.!M.........h......\....6.}...:;.IP...".....&......~W7...LC...7`..4V*
...H.&G]...yK..k....`r'.|F.......%u'x....=..6.....4.e.x...<[{.F\<
;.SQ.-......{......r..u.....SO=Z......Pj..h...C ..-.wL...S...l.ie....h
....J...*...%H........c.#D......... .l.q..%.>. ..i........{:....i._
3m[P..)hK.._13"....,..v....J.~.{ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCG6t8xMgoIBBCG6t8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1abe....5ASU!VPSz."......[....
!..x.-.w .]....u.}.D.).P$#.52";B.D*...r..$d$2...$2# #.2...T(.V.s......
.9...s~.ZX.n#..`F.#.D.....]L.y...`OM}.....P[...F.~l...0....5;..T.cN.f.
......j."m....p.T...I.=P..|.........'.]....E..TA..#'u.r./B.H...t...`.6
n.q.....jtJ...v...\.~.jo...S....v....:.56..p.<.w>;...m..5zs.h...
v..........M.......K.....1.8H)y.`..44.*....._6%@..s..8.c...|..E...T...
...~ ..%?.T....O..WL...v5.\..*....y.N....=...[.(..........JF......y2..
.|...q.U.{.n..h(...}EW.[..l...a........S'.RX.k......&.Y..>...2.....
....s...............G;.'...h....z.j._..Zo.........'0{.y)......'.c...*/
h...C..D....XSqL.R....!.....[.{...h.$B.......t`a&...........>.l.. )
...;..V.P.B......p.^9...Yb..5..r.....&.....|..3.D{...V;..I..T}.|..5$..
..\J..&....|.......='}......Q{...M.A..)HM........L...U3[.S*.@..ZIg_..j
.,c.dlnU.....m8...r..xM.X......L.j.,vD...q.....z..... ......y}g.......
......gW..V.j........gV.1.h.!..g......qzi....5w....q...E.......`v.b"..
pY.X..a...1.h#.{..;%....@...I)....m....;...c..j.@..^....z".a....n.....
...{n.9.. .....3.a.C...=v..........!..#...........c?~......_..I... ...
c*.\y.F...P:,23...A-...............n..>.?W.L.x....N...J..........GP
.#...s...}........\.I......#.r.^..$i.w..i8...BX.o...*.....)..-..~..n.M
.:...uS....j.q..{)5..CS;.K.A.r.7?.J)'./Y&...."p..I.......o|..g...S.P.1
...!G.Y...S....,Q...\w/.......[/.....[.7!j...x........g.........[[.m.
./NrbF.bm.J...&....Bt..p..O.f:..\%.o...(.b'.....C...V...p..(...;.i....
X........*x...#..$..0.......r.b]6#D.B.........uHG|2...X..Y....^...

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCP7N8xMgoIBBCP7N8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1201....#ASU!VPSz."...........
...x.%.y<......x.K.L.....,.KI.!Z....Y."..5..3"k.RZ~H.%.....P...Z#K.
~.........>.....9.1......0am..C. .!..7....x.Q...7.."..[.....H.~t...
..Iq.M......v.:..#..rX.1p......A,.._...........lD.f?...G...?6,..*<.
...;..E..V.]..1...cD.*t..1...f ..P.V;#...m'...~.XX....\..m!.Q.."fP`:.C
2N.._.k.......k.A.|"..T,..?.....q.4..x.~.Elo.'.K.........t......f.Af..
...V........4..0..Bg......u...t^._......S....9...8.w".n".1.4......Z.=.
)7b.c^....(.....=..8N.x1...w.....Cu.....`VQa[.....#.....wk.W.\..`.....
...b...%.u33..&.g.T.E?..>.K.....4.7C}.b.....k4...P.q...1q...D...J.p
){....2./.......o.....X(..f..`.....[....-...... z..@e.K..,}.C..BD..t.e
..b./'.`O...9...;..9...%.X`.C....hk.<.'x,......M.).".&...e@.......5
v ..LP..N..B.?..;7!.%....a.....nT\.A.W.U.5O.g....{..#&)......o.Q......
.....(.<~.`V.....[H-..M...R....(}B..?...../.Ot|`)...C..'.`."....h..
....t..#~..w<..X...slIn(..j:...!..rF....k!/..F.1.U&m.x......O.;!f*.
...D.,.k.q..8O..x.W~.A3..>k....E..=.\......".........K>.PK.h.wv@
,Vb.....v. .7....6........C....#..... ...%{..[..!F]/c....>...C8b...
..J....EG%...........e..f.v...._v...\^........y...0........#.E...`...R
...w...nd..j_..l.....u..../.uM....".X....9...........b.7^..v;gna......
..= .gT-.9c.Yt..3J..............b"*...2.gL...N%."....Rf.@p..b..2c.V...
q...w..op.;..Ju...sT.i....w.. ......<@oM}*..,.X..l8....A.]Q...^....
I.m,.{.c...b.[E5....i.<T....XG..14Wr../fX.?.f..wO...?.#.....A\.....
..w&(9....,K.W.._.J..uE/..g....D6I)...v`..W.....JFk...kb........l.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCN7t8xMgoIBBCN7t8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..109d....!ASU!VPSz."......:....
...x....8.o...wQ".....d..efd...?{u....B....!#.......2.....%...s.....}.
>.9.=.52Q.....W...B.............1.f.WZ...1I...8....)=.a!..S..XZ2.g.
....u!.!a...(.../..\.#!.=....|.>......j"....c9.T..../D..LA....=..N.
.Y..|".:.?....:)..>.6.DFb..=.....,..f.....n..=|C.....W.0#2..tW.4...
.D.%)W.........`.......Dd.......~9...x..m\..6..d.].C\..F..,.r..@...6&g
t;I.Xs"c.h.e......*.s. ...Q.,.A...#.....k_.......x.....?.R....2.;U...8
*".k...i..V.U.i..?......u...!WJ.o.....[.TH.z".%9....3!...q...03bF.,wQ5
.h[OC.....U"c.g..<. .U...3.ib(!h.....p......r,.x,.f."K..%.L.Z.p....
..jA"...$0qeQ.(g.".9c.e.r"....q}.Q6...4..@. ......0]...Y...5.K.y....".
....7.......y....C/..39(J@.xb.10...uz...0.....[.>.9.4.]...........v
B._..S?z....9...=2...2..*F8..8r. g........=7.C../ .V;....)....t.3.o?..
..cZ..6.8..-..m.0...I...m].].k.....I.._m7...r1i.PP.....]G...h..{.4=.BQ
...-{..C..uB./.....T"..g_.k..ZHcWYV.F.e...tT..W...=8.UbH.i....g.C{..E.
v.3......,....Y.....L..Y.O(*..J}.. k.,.o...K.M......_.`......H.c..}..1
.?....<...x,$..=.L.W.w}[._....=.3.. FO"..uE \.<f8EDW.....')...k.
...y.h..e..<."..~.X.j...K).2v......'.1.'.........3.,...$.mX........
...9S.0......4<...k.f^n.)/h,-..P.l):..EG>........Z.....V....DE..
.....R=...j..x.j...H........m.S.>..H.:......6?.N...G/....X.m..=._.^
.....2..^6.U.o...O.)e\..^...F..........te.......*....I.........i.;....
..a...U.._H..E.../................Xy....Z........XO..~.... .......Q...
^.....=._.........7J.o.........=.(.. ^.pW.V......bk...T.a.ig.....J

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCb8N8xMgoIBBCb8N8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..366.....ASU!VPSz."
..........V...x.%..0Ta...s....lo.(.5..........A[h.K5S".&E.Gh.......`.L
F.6c.X..M..U....e.e.G..?s.....9....2a<....... .........ow.x.*. ..v.
E..$w...m"...Ej...YP.tN.....h.f.....p.R...=..he.sY.;.....u.W*.|.J.m..P
&...._E.p.......g\6.\.... L.J...g.q..z.,........#S.".Ua.>wX.}k.....
..5.=8.......bK...hy[..t.!.....72...m.V.i2.G..&... ..'.Tj...z.u.!..-p_
....d..Z.epL3.V..^.6..T..V.Fg..H...U..}.r...Sh-Y.%,.,....#....>....
S...3.7r...D=.....5j#..ez..J..=.~.....M.......")......6....^..s..?....
..M^..A.&.q.@....oh.......? ....E..^...-....D....h.-D....Iq.{..hw_.=..
g.d.O>............%.o...LB........R .6.............:...:c...62XKAI.
....(.I......vq...Z.L.:d..u.....;. l.....K..7.z)?..!.\B`.....3F...$P.g
..{..{...GS.1.0Ad.D...........l....`..t!!.....F..q$H2)... ..../......U
3.......N.6.h].T..F._......i..m...\B..2....%.@..c(7.^.x.tsSY.].V.....5
7.Ia5~1.;f?.......X.JASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCb8t8xMgoIBBCb8t8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..2ca.....ASU!VPSz."
......g.......x...uQ.ab`.p5......D.W...C9..nN..x.......?..:....'!O[,..
$.&Qi....azQ...... .i..|....r.4...........gZ..p...w...> .,g. GO.2.*
...T.V.....?T.......G...Ab....W.b...M:evS.$.....z..A.Jv..... 1.Dk.....
....>.... .U.....`d.8...'...AbU...]e``.....Sx.9...b.w.....'. ......
{]>.A4..!...qQl[.H.....Q}&.....N.i...i............|n.. ...).M.ap..Q
.....$.?..VQ c...........;.F..h.....VC7K...#.3..X....7.l....{.]Y....i.
.;a... ...l.Y..0.>..i...gAbm.B.Mu.../...r......n.................n;
.............\.L... ......SfdTa0d.d.bb.pb.X..<.a......I...B..!,zE)
..L%..Ur...zL.,..IHd*.Lbq..g.Pk&K..h...j@.._c{5..s#.c. .X....d.q..y!..
...............V.....O..k?O..e..........y.5... N...^.&..v.. ...I...y..
gP...eD1ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCP9N8xMgoIBBCP9N8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..230.....ASU!VPSz."
..............x...uQ~.....j.[....a..>..e..Q.\.(..F.....m..02.[k....
}...p........'..>..5`.^......r.........y..h75`eh.3Q...I..M.........
..D..h3.......SY.Bn.......$fS.3.........7......N.........WdV..# 1...&N
.d`X).Pj.{..$.........3FS.f.$......|S......|.d... 1....L.b..oU........
....5G.}F)..../..U...5m`a`..x.(......5B ....>.r._.Hl.ci/..L..u.....
...]~~..5..!@..D.......~.......3.....i.].L... @..u.~.Sfd.c.`.b.`.gb.`.
. .4I..IH.'.E...(.1....].n]y...K....|........g...\.r...Zb.....\.....H.
.w9......w...l....Q....n{.DH*...Q$=....MP.V..............MASWSig2B..0.
.
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCM9t8xMgoIBBCM9t8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..31a.....ASU!VPSz."
..............x.-.mHSQ.......;.d.:S.en.eN..Z....%.K..J.$.L.j..R.aD*..f
X..>.A.C.!..m$f..d...V*lh..Q.@p.9..9.....r.s..V.KQ...e...S......j..
}..R.........*>...l^A......{.k......j.....J&r#..F..)...].........lc
..n...#y..`.T..o.......{...Wo.8.3...05..!.K. .....6.(.l|......cK.a.c..
....}K.k..v....`f{d~U...l..s..k...t.|........{....W...b..;.."..*.... {
....Q.4s.....6..Pl.}..........X....1I............|.....08..?j.s......n
.....s.}".Z..P.... ..Zj.v....6F......sV.P....x.b..H.(...-I4.....XI..ZC
....f..6..d.)y..7...L....i..%$..M.{3\B(."...K....v....%P..x*.u...HG..E
...F.........z..H..$....Hn....S.d.T..4..d....QE...<.F**.O....d*...r
1Z.....d.0K..@..."....f....d.9.(fH8...(..e.p.........)..:.B:..........
N...z%.N=...\.....T..m...T'...{...?.*...#...9Ab..cND...Y...~D|.m.F>
.l..~..B...\...ASWSig2B..0..22... ......2.......1... .....)(.....)..31
a.....ASU!VPSz."..............x.-.mHSQ.......;.d.:S.en.eN..Z....%.K..J
.$.L.j..R.aD*..fX..>.A.C.!..m$f..d...V*lh..Q.@p.9..9.....r.s..V.KQ.
..e...S......j..}..R.........*>...l^A......{.k......j.....J&r#..F..
)...].........lc..n...#y..`.T..o.......{...Wo.8.3...05..!.K. .....6.(.
l|......cK.a.c......}K.k..v....`f{d~U...l..s..k...t.|........{....W...
b..;.."..*.... {....Q.4s.....6..Pl.}..........X....1I............|....
.08..?j.s......n.....s.}".Z..P.... ..Zj.v....6F......sV.P....x.b..

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCJ-N8xMgoIBBCJ-N8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1d70....:ASU!VPSz."...........
...x.M.e\TM..g....V.CB).....n.KJD.;..n....i......VJ.sx....7....s.5....
........sy.....o....~A...._...Saf.i.'s..$.....z.0C.......9.....a=...5.
..........K.0.`.3C..@.uR..^b.fGRa....j."..vk......L..o`NW..f.. ..y..x.
..r.tR......0..}^..K.y.3:./6....2{.`..^%..-.......$].2........tFY`....
....fu.......p....mw.Y...6)...I.$.go_....I.......S..J.a.... H..~W....]
e.....d.7...>..5.30..S..?..m=?.L....([|.F..<....R......~./(.....
.X_-..&...H.....q.k.M>.3"3.U......u]'..P..r0m& P.....;.......y....L
\...&.r%j;/.8.'Z!:d>.Ci......hG....#^.....Ph.g1^..j..x.P....)..N.j!
...0..N..g.,...Y[..f........ .j....l.1..,vek.=..K ?.@.Q...#...^...#...
...p@.W.s.uU...P0qp..rW.&.(...'.n?..wa%.3gT...E.D.c....o...-.%..- d...
._z.}...:..(.V.w^..j.f........1R..Po.3...dmT..H.>.......o5..O2.o...
UD.d.l.@..P. -y9.q.}!.^......0../.^0">.."@....4.....2y..?A.R....5^.
0.....k~,QAVC..;.....&C..)x...=.t..<na...<W5c.. .3C..g..X.Y..8.
....Y.*\.9....m.s...l.^u..)....\..8.`.#0.2...h.....!.0...>jx(@.p.N.
L..fdb...C..X/.P..k.0..V..Z =k..S.w.9;.E[0D.Nvk..x....._............e.
7...BJ$.w.....s.qm..<........U.|7.....W...".o.ME.....]..6vv.....>
;.#.C...K."...0...%\..Y..-; c.7}.N .*.....> ......OZ5#...P.X.N.e.F.
..q.e...y'e......8....!.P..a.I4..3..R|D..`UI..k........~^...l6sz..}0o.
....1....}.-..2.]... ;...5.(%$3~?-"...P@n....Y..H~.h.E,...~....1k3*.H.
(.?.Z..n`..............d>....}p.3q.~.qZ.......`.......:.......{..oz
.../.=...s.......".....B.....-._..D...K...{B.Vj...`...)_.Rvf....Se

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCL-t8xMgoIBBCL-t8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..95a.....ASU!VPSz."..........^.
..x.%..8......;3..3.,..]E."Me.R.!*.Wh!7.Q.p......&....%7.R...P..H.r..e
.$....<.<.gf.y.9..;.......p.5Y.M...b..?I.f.......(..LMUh!.a.z...
..pkd.j.l....e.Y..R...E......M.5u.K"..,.j.....4VY.../2....n#..:i.,9.T.
l...........7...G.k....=.s/.q%.......&.sy......._..P..!...jr...;. ...
Z.F.....3..LdM./...........9..u...z.T.S..g.....~....F....Z..2,.N.73...
.~.K.Jdn..7...?.FVD....... ...&...IBg.#.H..BcX.$.M.<.F..z..`.@..^..
....=N...g.."eM@V,..Y.^..4...k.oM.-Dv....B.0...-.i......q..2....;....}
\y...K...0....O..U/.o.ul.'Z.>T[L.U.."W.N.<...P.6.?..~....Gux3..x
L....j...fwp.q...&.\.......Jhv..7.1... .l..p.h0...........K .N8..UB...
U..{....9.....j.>..._.2w...^.D,.~.2.w..b..$.9i......x".....r.?/[e..
.L..J....\66r..LG..?...Tp.].]C9.H.}Q.}:...._.J.k...^.%...c....aP...o..
|..#......B....y.2......c.--R..{..Y.s.6.8I.C._....".f.....x0...q...X..
..S....8_.x...1k.R@....L...v.........>.5..q%..k.@...e.)....9.....$.
....='.s.....:..........m.......L..l..2..s'..s.P8.5j.u...y][..>..M.
5.Y...&.O.@k.......6>...s1.%[R>.2.../....n..:..-...n...F..7~F..-
.;..7....,.R.X!.7..D.......R....M...G.H7..h...#.h1G.....p..M...Y.O)^J.
.........#SZw5...q.*kJ....Dk}.oB..N......=hk0...2@.h.n...kM..........k
S5.C...m.E*..X./8}.......\#.,K.;4.A./9...!....pv.[.s.8^.O..8<......
.%3.{VE......B........*l.0.`..W^.Ff.*...;D....3.W..L{...0....u.&....}.
...BT......u..3.,^.*...U.....Cv5.h.V...,. .N.....3..5....|Fl.%.d....pb
....cn..n#........./.../I!.....q.Q.[>..q..Z4.?O.}Pla@..k...;4..

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDk_N8xMgoIBBDk_N8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..190a....2ASU!VPSz."..........1
...x..X.P.k......n.;... .. -H..t7.. H.tw.."... %!..7sgv..../N....= )..
.|.Ep.@..7X.T.<H@....}BZ..k%.........:u.#....y.E..@N...w...G.......
.Y.)'...h....@..(....\...4..?U.u$i...{..;.j........".D.b.f-t.GLPGj.p..
.#......<b.F..H....p...4...s.E.T"...5.U:z2.1SG.e.7.4.<=.Wx...}.
.G.z.F..k....G...k...D ....d....=..g'.......K.Q..............I...#....
/.......T.z..1........Q. Q..z......x.x.........E...#}...h..NO[..._c.9.
..}..V.....6....X...f......JO......j,.q./.x.Y) ...|..".....3........U-
m.Y...T(DJ..w3.kA...-Sx....=Lr..q....c.;"....:......].........O.......
E...\n... ...@vm..,.....@\..RIoJ.#R.'.8U.8;XIn..O....1......R.x3ot.h..
..@...8.3....R.eV...._.5..(..Z.x.f3lGr8.g...WM.f&{E...@e.wLg...OO._E..
N................&s.......z..M).....,Y.c....G...~... .4.n......_.x..w.
>.!;;t\.B"..K!c...Kr...^D]... ...nn9i...k..u.0..`..mr..B...S....IiV
..b.H..e...9..=-..p..}./..@......$...7.K...o.>...<g...].T\.z....
S..j........B...'...qZ.-u.o.u.~:.N...........'&...Z.#...v. ...@=%.o$Ob
.6K.....c.#(.....).j..@aW..G.....%g...k.l.....9..^..?-{.5.N9~..<...
.. .....2.G_...D9...U...6HQ; ....)....L6*s^.ta.=....y..A.-m.kC.....Y..
..v.]8.Mh....h..E.~.}l.......37..b....$].\ju..a...$...i.|.......t.{...
.....n".a.B..s...........g.....K{....\V....D3.>.i.g?..........y..J.
..1...Ka............4..S.$.....Mi......... ..d.'y..)/" ....OJ...[.}L..
..)U....iX7....q......d.y1.i.$..[hXg.....EM7.._.:..ze.P..C-.J..vb..3#t
r.v$...5.>.....;U.:.<r....x.1..>./...Pg..............q.fv

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDz_t8xMgoIBBDz_t8xGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..35f.....ASU!VPSz."
.. .......J...x.%.},.q.....w.....[...kI....<.....ql.V.'J..T.E?.5.Q.
.H.......#.C..v....SJf....{}....k...........}..a.B.#....3..4..@.e....H
.l...(9.2......j..:.*P].E....3..\b....#.....V5..D-A..X........y$O..C&`
.....t]E....J....Fu.y~...lN...A..3.=..<d...W..........#....X.....9p
...52.|.BT....s.......g...f............K....z.Np.Ad..~f.........dd....
R. .....x...o...gW......bd..*.......m(!..j..Q2....dE.\.!...K.R{:....5w
.~d...i"..d....X.5d?.6.?....6?m.....].'P.G@)n)/i$..1....`.<.U.-.<
;g.wX.8.2.2h............u..7=....%....nHZ.4..2.6........=..7....UY{...
KG..9.zQu.`..T9..c! ...1H.....R..Xds...SV.0c..O.?.A.S.^C.._.I..0.0w...
P......iOu...|6&..F.\?..W..B........`......L.K..F.k2.o...S..F:...:B...
.g..f.a.8..p......>e.v>.I{..4K_.X.3.....]...k.....`7....,k......
bw!Oi9........EV Q.).604..}.Rr.$.g.h.......o.. ...b..6.T..sr$.........
.\bPk........I.'CC..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDzgOAxMgoIBBDzgOAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..341.....ASU!VPSz."
..!.......&...x.%.{H.Q....=....Xi.k..cS..|.N.Lzh..a.;.S.$D.|-.S..4,-a.
..hYfP(..Zn.iF.JI...=...N^..s~....{...Bg. N./....@....Uq..0\..S...A...
~b.J...........W.7s..v..A.e..X...".;..u..h.>W...........h.LQ.3LB.M.
..5...f.7=.......G...h Q5...N}."?F......0..b...H2.2.*...06<..^.Hy..
D MQnS1........j4q&].....^t..i.B..M%1..Z.V.....GK 9..;........@4M.P..G
C..w1..NB4.z.."[.....Bmu...N....0~i..,....u../...`.....O...X..C....{e.
E...........d...h....L..X...`..3.;.3....MMdW.{....6u6..q.%..g.m`~.....
...>s.....X..7qA.,u%:.S.&\..Wd.@w.4W..7......=.....a.A.........R)..
B.........g.S.\hFq......w......x..WsH..K..n...c. ......Y..0......!.di.
..........VKG...h. ...F.#.f.H;...ZZp. ..8....0......(......"v......YE.
........J$.Z.j.[O.I..sff..|M>.....j.5....H6X...{.X........%.."U,"%.
..Q|.N........4.4..=Mu.......~DZ.}...o[[...*..T7...M$.ASWSig2B..0..ont>....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDlguAxMgoIBBDlguAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..c8f.....ASU!VPSz.".."...,.....
..x.%..4._....ocd.TH*I.&.X....-dg,..f.."L...%!..%#.'|.P.....B....=..{.
.....}v.3..x..C..2.(.dE.....b..$F.u.......#.6FH.XhV....3a..s.T...~...i
l.....&....4..;&aEg....i>GA...Zn...:.;..C....;.o?..................
(.3..k<...Ax.[..Nv.......9d.....z,Hg....Tv..U1.....t..h...........G
........P..jE..=.Ng.x.wfO...6|m.z0..y..... ...1z.....Jf.C..."..y.....|
...0A..?#...&....yD(..fo.@....v.....C../.).....3.....!&.. ....:......
0../.I..V......M........@2....ec...z2.\.J...I.....|.A.UL..= ..`..'.K.
.i...Cb]nj6.:[z2.I..cA.rw...s.yi......dO...rN.._..Q..zq....@Lb.@q{....
.....c.............8.T.4.*.?.l...{....$L.5..P..c..}a.2.x..K....F3&.a."
i.y.kK.:8.%(..s.....v._E^......4W..U...^...........}.[.R<Q...Yx..S.
...^7{7..`....J.m..O.K. .......y.x............;.6jou.X.7E..mm....O....
M>w...]d...o..D...#...8...O.k..8GW.z~(...xA...<8.c..&....._..]..
...%TH[A_m......g.".C.M...[}............&.Sg..2N......lR......v.`....&
lt;a...*.L.>9...~.mv..L.y.......s....../.....^|~..7...&^~.3. v...n.
.w.G..... ..#4.x.... ^Ey.I[N..).zB.9.Wlg...@7W.....[..E.....p.DtI..a..
\m..C.. .[./T.Y.z).(UWT..Z...J%...c.y.j#I..q..... :....%..A\.{... .rZb
..z..-......Y'...z1q.........,...Z.#.....O.../0.eM~U.....v.bs..X...b..
..:!..\o....../1....h....5...!..4<..r/..X4L.....ki..{..P$Z.~..^|...
....&...b#....6c.....l;...Ao&...~...|t.kM..A..@....b......Qn...'.v....
<.O.UV..\.1.....i.._.......0.....Nyd2..mI=>D.. .....F/......;...
7.,..K...5..f.."'..;N8;.....L..Ss ..\...>R..........z.....^'u..

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDphOAxMgoIBBDphOAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..26d.....ASU!VPSz."
..#.......>...x...uQ6cb`.p5.=....D.....L...2M.LUh.>.$v......j.mN
.3.-./..Y.>^'............ .]...L.b....v......I..35`eH....|s.N.....7
;DT./.w......._lz..!eC....G...v;O.......#.t............../.Y~_.d&Hl..
.?....\2aW..T........r.........Ab.../M.00$.*..X...$&S}n..-V..]O7......
~.......-(aa.....}... .q..}.R.4HLob.[...mW.z....$.v.<_.:M..;]."....
:.t>.r..]...1.'H...5B.@.......7........4.....n;m........qr..K....{&
gt;~.``.=.#..q..$6....i. .i.......t.0..`... ..j......<C....A.......
.$..g!.5Q...iL.,.L...,@W0..............o.{.1.k`<...G.;....v .......
'5.y6.on.m.P.!O.....<....&..E........O..P.....5P8..9....X..... .ASW
Sig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDxhuAxMgoIBBDxhuAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..22b.....ASU!VPSz."
..$...........x...uQ~.....j...H.QC,....j7....}.v.F.$&)6...>..[...E.
....M.[kM........N.q.$.@.h..{..7.'....k......hz.....e.......j?yIS....3
....._..c..m.*.....N.....Ab....SU....I.......{[....wJ.B...U.@b..O~4.``
.qd..6oe...._K['23.T......~ .'S.....aH.._..... 1...oJ...j.8.?..c..;...
....._.,M..r}....#_M....3^MnZ...S...T.2F.".? v...........>..k..};Q.
............$.-.9.Vw.B0.^...IK.....>^.uz*....#...>........i.....
z...M..Ab..j;...2<.."R`.......R@;Omd?.S|..........e...[l...YW.0...=
.I...%` .3=.@.-...2Y.a.{1f....1U..~.G(..V\Rx"|#...L.bV.....ASWSig2B..0
..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCLieAxMgoIBBCLieAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..286.....ASU!VPSz."
..%...#...S...x...uQ.fb`.p5......d6..(*.*00\{.{.........-..MI6.*jx....
.....Ee...~X...*Zh.F.2\}j.9q.bY...... ...JE.R=S@bn.E.@b}.......-H....E
.y ...:y..Y...P.$V.....Io.%.4....*...=..,0-..7H,5.........WwLo\....ny~
..@'.........@b..~...#.p_......,6........j......S..]..gf.t......q.....
OQ..........<[..$vw........i..v.j...MX..gz..a_..7E.%.08.~.[S.V.....
.k.}.....u......../o..}...K..[U....J.,Sm... z.5..V..Y.>sq....|.....
^v...9.$..3."......g8.7....4.....d`x.a..'............V.}........zL...
......4..2$Nb(H.b<.9.x.S.0..........~]E....".-.o0...........G.2~.8.
...1.]....8f.3..k...#0.......p....Ov.m..i.E.G_Y........s..t....c1...K.
.f!.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCCi-AxMgoIBBCCi-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..16b.....ASU!VPSz."
..&...........x...uQ.`d`.p5.Na``.2.......20...9...B.$.7[.oj?...#...~[.
.....f.tf.. 6U.*......7.-......8EL5.-.$......E...z7.r.....`......@...~
_..Q.Aa..[.........(3)..-cRg.p.,0_.A..C.y."-g![}..........X.....f01..3
.3.5.T.M..........`...`<....X.q...$..3a...^,.....L...,|@.........{.
.8P.......3..wV[5..;2..K<..>.....=;.x...B..W.\..l.. ..&.$..P..,.
.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD6jOAxMgoIBBD6jOAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..d8.....ASU!VPSz.".
.'...u...w...x...uQ.g``p.0.Ng..x .......h.`.`7.....0.......t......X...
..21.T1.0..T.0.3..(00$x3.......2.'..Y.E.....W<f..>..............
f......`......}......3O8.~....*j..$.K...U..:-3.4........_2e4ASWSig2B..
0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD9juAxMgoIBBD9juAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..c6.....ASU!VPSz.".
.(...c...j...x...uQNb``p.0..b.. V......h..`f.. ...A......@<..X.C=.
.c##.v...<S...$.,.a."6.I.<.B.<....f@A3..=..T.'..B3..t)....O..
...Ek[q.9.b....h..S...CBb.UT?.l).g*.<{V...l..e.vASWSig2B..0..>....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD5kOAxMgoIBBD5kOAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..43c.....ASU!VPSz."
..)...........x....-.SUD#....UR3-..............H.......WH2 ....WH2LZ..
.....Cp^...%yk.LvE^O.(L. ...Z..91....P..A#.....`f.A..G..#..e.....UF...
.@..C.b....d ......n.`..#....Z..A.....,.A.F]..9:,...n.....,.....0(.7.8
W...4..m.<#u.T......N.......F}28.a.........3@TO.S..z^.$..P.....9..H
.....W}..$.m.B.:#...ZK...%.....\..N.].o.....w4.n.8......ct..l7..Z../ol
...iv#.....-.x..RY5k....'.i..X.<.......|..V.........).9...g....S9~.
...t.QIB..... V.p...........(...'sPY}a..........X..d..?.j..w:U....7.:.
......*.@D......Yc..............?..7.J......A...!..j........(....O.r.
......J.^........%.r...}.7.}.....g,......M*.O.u.X.i.9.,............9.p
e......^............m....>.....d.xGNQ...W.;..|e....P..%) ....8.O...
_.......6F. C~tG|......b..d#.........O/B.......H{.......;4...z&..s0q5c
..\..<...........t..N....#......M.E[......y...(.5.<.m{f%...^?...
..m..KD..W*.......\b..eu....D......z...Z.P..............Z..}....]..N..
...I. ....&..o...........G..(.:t..WH2S.....-..4... .....Q.`.!u..OB2 .
..8|v\y..xd..*.Na......bOt..2.....&.X..r.DY....V. $.(..R"....H..D7.aj.
......-.JwO.....L...t2.\!2..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCYk-AxMgoIBBCYk-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..f7.....ASU!VPSz.".
.*...........x...uQ......d.-......d.u]H...s ..5.T....r......2#.2..$.F-
.T&.I.......z.800.....1,zE.E...U....5..&U........X.R.K...#X....#..JS2S
b..K..'1...1.T04..... n./^"H.qb...e.ls..-........?I .F,.`g.l,...N..{Xj
t.v.........tU.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCYleAxMgoIBBCYleAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..159.....ASU!VPSz."
.. ...........x...uQf`d`.p5..a`.1.r.q.b....~s...'=..r.w.r>r.5..8.._
..x7E3......k0....V..]e...)y:l.....XJ.....$..._./.zv.8.S.D.X...R"...~`
d....V..o.Ab...n].`d.....=#.1H.@U..V!&..9,Gz.-x...^.x........|.....%..
./.M...1...9/w..... ..df.."...Q..$v....S}....4N...}..I..._......t..?0P
........?.~%...S.'`@.....M..r.u.%(nX...6.m....NASWSig2B..0..
...
.



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC1l-AxMgoIBBC1l-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..1af.....ASU!VPSz."
..,...L...g...x...uQ.gd`.p5....@..S.Sn....r.y...;.Ab...n.*p1d...n.J...
[b......0w..m....@b..O.[...$yV.=..... .T.7U``..)%.g....K..=.$...=...=.
^....G7.3h-rz..x..$V\Y<.U..!..K&...u...I..L/03....K#>y.H,pj.....
....ZK.....26.^e.,......s&..L@............b.*.v..)&..A.. ...#.........
J.........s..``8}...|.@..X.c.:Q...%.'...t..5.T..?..o.[...._.Zcf......c
......vuo&1*R.`;........i....^....1...Za.!.1..[HY.e.blk.......)..SASWS
ig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCxmeAxMgoIBBCxmeAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..220.....ASU!VPSz."
..-...........x...uQ~.....j.......P.H.4...g...3/.....-U.M...*..J......
s...15`e(r..........9........EF.*..@b.....702....zg.._....g..SX.~....s
.8.......d...ff.{..........c=t.qdx..H.i..6......7^.....;...S.f........
.0...W..)..3ay.}..q..W...B....A....a6.``.]^...|..H,zw.........V.'.....
..6..`.C....R...Abe.{.L.bd8.zY...{. ...w]6U`e.x...V...$...1.P(e...K...
.5.T;.......k.}eFFeF.3&.&W&..O.....q..8D....D.@.4. .(.. S..`.`....l.`.
..`X.(P....2.h......#|.)...[\ ..*.0....].m..>"... y3.e.r.Z....5..p?
.... ......k.8*/n..%...F.3S.].Q....PASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCom-AxMgoIBBCom-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..4c9.....ASU!VPSz."
......f.......x.%.{4[w...o".p.He.(J......M..6[.4.6..s:..hf.1.eL.<.&
lt;.P..C5[...*d:VCqj .=F=.I....:..q..s..~....{..xX...x.Gz..`.J..s.cX..
..>....'..)...t...s&{.M........s.....k.,2... .#...6$..-A.....x. 7.|
...\.Y......x:F.a.^.A6...6N...r.7..:....GM.fu Pj.*.....><..c....
&"V.g"2f.h(-..f.....q(...........&hK....d...w...|........mbX.\}.jvhNe!
..'d<..``....o.2M.1.#. ...a...Kd.7..i...C5...........?.kn..?..V!k}
.Z.a.....n...5d..fda-Y`:..W..5!s\.V...Uf_{*3P_..h..%.le.E........g*..t
|Ub..u....R...J...P.p....fe....u.H.H.x6.P..%A.~16.,..I....>=...&M..
........J!..[... .MD......e...$....W7..u...|,E0AB&... ...r...*..sd....
.L....x..uS.*.8.0_...;.......z....%....DS....b....$.?...Y~......F...t.
..\ .YEV}&1....e..~....F..g ....r..N1....wj.Y2.....<V./........a...
......s.;....bs[...2d...R.K....5E...L.)u..Z..T.g.Ga...(.....g.m'......
c.P...r...}C>>/.....?..Ky..qj?.3?..JL..;..Y.w....L-ID.....o...g.
....{D......$7|..$.........-;W?.g(?. ...D.9..N...Z......<..U|wlp...
r'..........9.......N.p......y.n.-.P...)..F.Yz.l...S.c.E.....K..-....X
t..IO.....].yCB...D..R.US........?.........</......A!r...FF]..i.5.
o.5......r....p.Qfn_~...c.M.`|.(s..TEj.N..^QT..4.H;.e...K..!....ep.!.]
2..C.*wq.............V}..O.......Y=L&=.>..N-....x.ASWSig2B..0..nt>....

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDCneAxMgoIBBDCneAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1238....$ASU!VPSz."../.......6
...x.%X.T...}.A.AJi...%$...i..F.i....).i...$~...-.(...(.-.o..3g....y.y
...z........B<.....Oj..X...b"LT........)T.g.=C:=1....z......w...\b.
4.q...f.&..3./.6..lQ.{hB....e..)..aE........i.\b..../...K..jX/^bF>)
7"..^.1..`c.^bG....a...n.2..3...s......g.......%.[<.VD........?.K.{
.3..;6$?k&l........."..!..L.....K.{=A.[S.F.9...w._b..I......x..p......
|..)......G......?a...oL{\.]...1.3.D.)6dS....gh....V!.@ZuB.UoGc..7].5.
....1....8.p......_..>...Y........~..v...... ..y2....[8Izs.Fd<..
... a..c../]7..j.............DyK.uo....f9.^t.l?krc. (.F..I8....E.....Y
..S7..C;....c.o'..E.".y.......j.<.;&..o ..*.0J....Q.h..E.......6...
...26.U..?{........Q..1....$qm.P..p._.....Ip...[J...uE)P....?1C7......
P).......d.|uP.&.\......h...s.5.U.. 2.3#..pk.m.`..*...b.bV.W....aG. ..
.<.f[.h{...%.-....e....S.-.....^..!...."....H.B..f......3#..)N.p...
<t..R.......|n.e.e6X.?.....h...>.?..j._.g..$t.6...#.-]..n...s...
T....}.T.-.H...R..U..... 6.`......^X........P..9.0M....J....)N ..j,q.L
0Q..`.....N.k...w.....oA.sV...1P.....-...=...0.....\..@/....H......NO.
.'[."..1...C.l...j.z%W\/&.R......w..7...;......o.x%.t.(.k}Q......po.`}
.,.........Pz...$..V&..4...O:...?.K.........q.....9Cu..]c.._s.r.J..r,.
.^.t...<..TT.A)u......TV..1..2...CR$.;....b..........c5zi|gt..{.p.L
.b<...q.PI..r.. .H....2Yo.7....L..q. ksenH.D..]..._?.i..4fDi..6..&g
t;.g..DW......).U]..P..X...7..b..:yj.%...`...N.H.................t.`b.
.."i1...'..,!J.K........3...UQ'...VQ.U...S.....H./|.k....l}:0iK.=.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDun-AxMgoIBBDun-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..1d2.....ASU!VPSz."
..0...o.......x...uQnfd`.p5.e..@.p.I..T......s*x}...N..^gz..!.?...'..
....U....?o...o}x/H....O....O}.._Q...$. ......!...../..........e.....p
..H....t..}}.'X........r.z.g.X.m....U....K............K...-.;d......B.
.S.. 1.."q.L..=......\..%}:....:.6A......b9.m'..00(.....#O.5.T;.......
k.}eFF-...].c..f..A..%r,...J,.,....!,zE)..L%....rUr.....Z.72'.qf..s.01
..04.....4_..Hw.P.......9.W.}..y/..J\X.x=....nj....6F:.[......[.r..-..
/.~.@0..Y....[%..........ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD9oeAxMgoIBBD9oeAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..29d.....ASU!VPSz."
..1...:...^...x...uQ.cb`.p5.5.......Y.}tmdb..?o.o... ./..oL...<x..r
.o.................6!.$."..sT:....$..9..Ab.r.e..X.T.MY6...r.....xk.3..
..qR......).=k.........s..@bw....j....fgK.#.. 1c....O.3.8ly2.p..H,!...
..&........?...L.......T.4.).....Z...X..3\.[.....V...z.4..F.I .....>
;.$f....4....v.|.... .....X........y...$...mH(......v.......[.2...4.B.
M...~u...,y.nz....X.]I...@b.V..3].. ."..r..b...U{..^`a..w.]....$vu..d.
KL.z5JuM.ZRAb./_..R.5m..d.y.@b.77..r31.Jjl.m......ib..J...?.}...@b5...
M...$o...jl..$v.cg.Va.....E.u.....~..55``.%(..V?..$6...LS......W..vc.k
......3Y.....{.9[X..>.:otL..0.,k.`......[F........\.......=v..P.M..
|..`....i..:<.8.Q.g...@..eTASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD-o-AxMgoIBBD-o-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..2af.....ASU!VPSz."
..2...L.......x...uQ.bb`.p5.=....D...~..V 1<.....a...3..}i......bcf
H.7H,\...Vo....0.....@biZ.-Gc.....-.?wA.H....6H.G.~..b[{Ab..?7.^`a0.-^
.....$..O^..n.}.f.../@b[3...*.0..U.s.....k/.z........... .....\....\..
mW......j..Z..0...}...&.....w..k2....W-`...{7y...@......B....)L.t..;..
~.`.l. 3H.....M'01..........!g.........N...$D...v:...O.f.Y~.aU.....~..
.1(h.1hf.p...8\..h.3...3..V.......}.....Z^D.H.....[......C.\..6......}
.....D...FI.y.?.p..`b8.%...I... cm9...f.`.3..I..>.I.......:7^D..v.0
..F".8...........:...z......X.JR ..K.X........&380..3.0&Lf.......@..".
...@#uy.FM;........u.e>.NF..@...mN.T.{..1..a.6..,yS...#..M..f......
...q..4..dUumV1p..eV....t.z..T6.g.@.........0ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD7peAxMgoIBBD7peAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..2be.....ASU!VPSz."
..3...[.......x...mHSQ....9.:...wf..Mm..6.kK3..e...3.d..i..eJ9.):...[.
...``...QB...%.PQ....D""..Y.....w....s.i...@..0.H.vz.]..l.....A..(. ..
.8..).K..N?._g...C"4s..,..jn.\G.e.8R8q.....n..J....X.Mk.p..6o.3....o,.
5.my..."f.....].wp..=.....4.b...}n..qV'.....i.....n....\"...g^. (.vb.%
&.4.v.......J...........E[`?..o....$..)}.u..gn...T....i.-C.c..5rn.....
N..2..K.....Sx31I#............j.....G....$.TB..`.......m.....ub~..~..]
D.F..H.9.t..[S61*...8..8..I..q..1.....1...v.eJ.i2.d...R.:..7.'. ..B.A.
........@i.`&....*.sy\7aq5...S.. Q.....@O]...).Z.d ?I.&...........;^..
.J.....l....<..\..$7PL.<s.....v......B.t..7.rc$!.|.J.....(W.'7..
..D\r...E...`.Y'B......Z.C.,.a..r..3.../......6$.. :,6..UASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD7p-AxMgoIBBD7p-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..18b0....1ASU!VPSz."..4...M....
...x.%..XT]...... . ..tI# .KHH.() .J.J......R......4..%%(]~......{.w.=
sf..g...*.....&F.w.......... E...F.x.gt0s%P...G.~.S..M.>.U....a..|.
.....A.......$(..._p;..Y=.y..;...8.Wbs..2..P^..CpJ.)6.r...y.H ...../..
C..X.>'....._.'lKBaff.:.,..d...u..c.9X.F.|...2.....l0..Qc......0&.O
...M........L ..0..k.2....w.......,;*._d..*.(...I...7..E..@.....:.3.).
hm.Cs.....:.E.,.Q........3.:.*.............<..:0..L.L....-z.^...f..
v..f.D.iK...].>q.,Z.-......3.N..t.......K{.3......v?..P,5...$.w....
..D......Jd..3.g.?......Q.@...<ym...r`..=..lF.Qv.hG..M...L}.,E...R.
...5.<?...`.....\s...._i...,....G1Q.a..L...E.{.^F..jY1.....}......3
.*.mt......n.y......=..f`y{.UP..#.hX.OtY....=..9... f...#\k..%9m....b.
.k=.TH.Q.....bq."5CN..b6.V8...w....g^..k-.....S.....!B....3 q...\.0z.m
S.Q-r......!..O .....].L&EZ..W......k.0K..X.......=...!.......xx m...7
=Vw!.~(......ipi.B..S./.WUHB........E.a...`.~......$..../....`vE.z....
$_<~3.Et.:"..Q.....T.......H.F2.3?2j .&.V0k7.....'..St.8......^..5.
-.u.b.......#.,i.kM..eFr.dPku..........0[0.]... ..x..&..3g.?M....y...O
.`6i.)....E9.x.../w...|4........N............1G.h.p....|.`9..3Mp......
.6....i><.j...\.."/......R..U..,.9.<.&.L.....5.`..r.Ip#9....'
....3..J.-....R...e^...._[....h.l6g>...9@.....*#....j9...t.........
..G..X.?.Wz..G.7..Z....W.....\7...z'Ed.j`...?.*.h <.\q....P*.._.(..
].ov`pe..>....k.!.....Z........-......u...... ...m......~..y.......
p.HY.L(S-.f..W.6.....;8...].MR.....$<..o.Ui.YYR.......S.M..y...

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD2qeAxMgoIBBD2qeAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..1da.....ASU!VPSz."
..5...w.......x...uQ.gd`.p5....@.`!x..*3...*.-....Ab.BjoM/.2....EK. .$
&)6...8..|i......Ab.lXxM.X...6..T0...e8..4U``.pSn.c..wAb...b 16.. 5..i
..j?yIS...g].g...p.$..\x..(.@!...7).......Gk......n.... .....@.....e..
.9H.q~.nk6.....a.&....3Z...R..%....s7.....7.@1[...S.5. 1..a.@.......l.
.$.y...V."......~N.......p.0.....=......<>qr.rj2..g<u9l.C....
.iG.32....x>A;.5.TW...a..........Z..2..1.f..6}...n.,.2.a.B.8Q...P&l
t;.gQ....b..KCY...7..9r).....;G..B.!L.e..3...V..ASWSig2B..0..
..
..



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD_q-AxMgoIBBD_q-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..2dc.....ASU!VPSz."
..6...y.......x...kH.Q...s...-*ec.....Y.f.'M1...1........ ...4mn.$..b.
........-...Y..H....,cE.T...^..w.=..{.........u;.`.z.x... .M7.Y..k.mb.
..Rj...Ir.gv..-]..#.b>....s4h..M.....{.V.'n...Z...(....St}/A.=j....
!J...`.p..2.....8..<f.e.....JhV@...CS.u.h9&.... ...O\.O....Y.A..~m.
...9.B.F..z.I.s.1......*|...fM[.b....e/..BTI`w.}..vopT.f....hn..-z...5
.../.w. G ...`......W\.../uM..............(..ncn............X.^G.....2
...-5^)......F..l=....Dl....e..l...... .Iv.mK...47,.II..p[...jg.."2...
..;.,.........2..$..rq..k....%0.s.{.Z........B.D$.) ..Q8.BAc...@A^%.&.
&.D.l{.....H.T...bR.F0....."..$%.......pv.)m....`.&<O......7..q.7`M
.w.u.....g=d.!...xH..Y......j...`..=.:....b.E...HH............z[X.Bv.P
....#..&Ll2(........ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD3reAxMgoIBBD3reAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..280.....ASU!VPSz."
..7...........x...uQ.ab`.p5.ead`....._?X....H....L...m...hZ.... ..#.G.
Ab....M.X..7.>....d.X.\-..J....=b.3d.@b.6.._.......o..Y] .-.e.M.01H
7.L.~(j....7R...3.../6..~..$&|qk...B.....6O..v....k........@..n.....K[
#..jc...Wlp..E.........Q...U..@bno...^`a8g.....a......3A.BT8...r~v.0..
.Jp..JCCMECCE..|y........4.L...........l.......YT.....\..."X...."....j
.....8rX.JR r.K..@...<9...`..@..&HU.3.h0.L..fq..y5.. )#..5...-P.H..
..j..Re.e.cb`...fj=.?.L..P...#..Y.C$C.C,C:3...,.V.... = .A...O.d..-Y..
...H...\.m....,b }.@[A:-.\. .......A.........0.00..V.....? .....T...!.
...E.1.$.A.....8..../.]....4qB...(....m...[.D.:I.CFu0...Z.......rASWSi
g2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDur-AxMgoIBBDur-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..25e.....ASU!VPSz."
..8.......%...x...uQ.eb`.p5..ad`...I..6..x..g./..;/...(..T(3........:.
..d.4..~de...}.ag.n..A.......A...{.e]...cw..4.....G....& 1...G]_p0....
.u9m?Hlr&..P C.....g..Ab...,e5``X...w........Ow@v.........H.......A...
V5.-;u@b...?.J..~.......H.i..1....2...w:..k<.Rg............ ..w,zL.
.......;.h.H,...._......Z.i...$... ....[.-,..gN..=.. /*..p............
gFGS..N$.=ue[......r.._.....F.7.>..`..........j......@........&L.r.
L.Va,z).%...1....L..)....9....%...U..j..L.J ..,..............;t.....L.
.8.....8...K*...YX.........5.\.f.....W_..5.?..hY_.F...=U?.k..c..<..
Z.S...8...-...k.....W......N....7zASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDVseAxMgoIBBDVseAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..111.....ASU!VPSz."
..9...........x...uQ......j........6...d=..........Y@b..v..*00L.3....
.....x.$&p.W....`..W%S...f\...,...k.........!........6.P.6dfTg.e0bb.e.
. `......|e;c..^JbI(K"P...]. .qO...-.N.7l.9.....tV......Q*.....x&.....
rs.`....g.i..ZO....1..~.......l..F.0k..#F.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDCs-AxMgoIBBDCs-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..20f2....AASU!VPSz."..:.... ..n
#..x.%..<.o....k.....de].D.H232...k..............Gd.de...........}.
.9.9.sN&........$...........J....n.^....3...ET)1p..U.........z4'3...~.
l...35.d.4... &.?..t.,..%........?..?..... .....V..#.0h}.p......@..@..
}~.......l......8..K.n......!...;....\..f.X..H......n.v..l.G.w........
...av..e2...:.^D...1.L.......~).n....f.x.1h.....E......q.p.....K...aX.
....zL.Z........C.sFB.r....C.*v...0 %<H@...C.<.,~..f.Dz.hI....P.
<..0. ..GgS..v./.\....1i....1...#[....37..m..6.......V.9.E.b.mZ`..g
.S...3Q.^QS>.p.lK6......M..Z..W.9%..Z/.M3I..H!....E....aVr...e.@vf.
&.y.o.........0.PLAm?..(v...............%..rD..pP;......l...xt...'..._
.{`..!-...sA...q....Hyq.`f...;.v$.."6.f..>.qi.Q..R.M7^Z.d.b.&WM...&
lt;...}.[.V..=.....Kk...q.....u...%.bFvi....*..q.....vG.....1.<....
_.......:....B4`..?..z.........e0K..=AO`..?.]yo..a.PT....pv......_a&#F
.LS......?p..`6*.x..C.......a..8........M..W\..0K..LF.!.A..#.......O..
.H l..!.y@.3....... ~O.?.O$D..)....C>.H....b.......y.......*Ea.U..E
B~.MY6n....''.[". !.|:...K.k...B.....z.."Y...V.J...)..).F(...si.....0`
.\Z5..n.~...VW.l.#.....C......J......Da.Z.%......JdE..p. .M.l...w.#...
R.-.5.........U/.T.n..|.L..7.\../.....'yYK.S..4.Ui.@yN...-..0[....#w..
l.^.....Y.AM..t4W..Z.tmk.).a?EvB......c)f.qFT.....L.....qn....U" ....3
b..u...Y@....&..|..u..w.g.^....W.\...M?.k$.........:.S.,N::.....Y..B.$
.t-y.i..`.o.r@.l.fu...>.f....:..`..........'.o.].....zO............
.(5...y....K....6'}iu.rl..o........u86........ =.(.......^...^.z^.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDtteAxMgoIBBDtteAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..137.....ASU!VPSz."
..;...........x...uQ......j.........8&...00.n|.|9...$V.s..u*?CF......_
..._:..*...x.~..E;&..Boge.*00.......y- ...SV.. 1.......5.T;.....X.k.}e
FFy...I.}.B.....Y....$.$00<.bhfdnad...cfh`vb.X...w.c.KI,.gL.gb0)eb`
.bhda....B.D....X../..)PT...T.&5I.9.:[.KH..Gg.Y...Zze.s..9.i[.u..$q.cY
...g.t.....C.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD1uOAxMgoIBBD1uOAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..1a5.....ASU!VPSz."
..<...B...Y...x...uQ.dd`.p5..a``.2..1....de.Y....b..$&.1..4..!^....
.k...$......a.c9......H,..,.T..a..lt....@bl.......V;.........Lu>...
..Zg......@bI.J..*20.;{....z<4.X[..&f......;..l..29..A"....O..P....
.jW1@@...r......0.!NA.q....:......M..Z./h.mdtgq``8...... ~..K..c].$...
...I.<.@:...%sR.R..o.......\..:.z&~..&..FF.fF...v..@.....k.{x6....C
..<..=.3.8q/.m...T66.\.../...`.lt.?.uro.u. .d.<..s6![..x.o5.d.AS
WSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDsuuAxMgoIBBDsuuAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..168.....ASU!VPSz."
..=.......&...x...uQ.cd`.p5......d6.f.;.z..Ap..t..I..@19..E.....od..6s
.@xG..-8=..Bxs.U.md...2.........D~./....i.....AS.....S..8D...........:
..{... ....l.@K..|.=.....?.vV.H...Z...KL.....h.... <y..w...Y......p
........._j"\.L... @....v.WfdT`z.....`..Pe...b.`..P... ...........e...
.|..`*.h.......n.BID<..Y....G......~._V..U.iv....8.!..`...Vc_3ASWSi
g2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD3vOAxMgoIBBD3vOAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..171.....ASU!VPSz."
..>...........x...uQ.ed`.p5.Ma``.2..p.9f.....n%.._.s@b73...*00...m.
Oag.H............;...]...9.b.W..A ..<..I...........^.Z\..5.T....Z..
.k.}eFF%.U...>ZB.L....8.9z.....$.2.$.Mf...'.8.5~2..c.0...fFf.*c..I.
..B..6...l....1.2....K.jOI,.eLL..S\...,Q....`.`...... P..^..r..M..@.._
.v...;..).f..u4..7:xu.r..S....H/..\mg.6....!...'z....4<G.vVkgj. ..(
.k....&...ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDuvuAxMgoIBBDuvuAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..2453....HASU!VPSz."..?....#...
&..x.M.w ......^{...U..d^[v.ed.....^!%...GvfFY. #e." .>.....?|^.9.s
..<...dh.......Z......@..^... .U..)...90;Q........V....:..y.~..@.J.
J)L..0.H..Fu....2..)..X.......@.I{-;..L..>D..T....g.O.W..9;..3.2..
...B...%..4. 0....@...z.z...b$.<...m...H......n....^..n\......l.Zt.
..Y..W........2...7.U' .}.a..z...........!..s..}t8.h:L.Je.......5...j.
....y`.3.<U?....i.*...`.M..B..@h.#.g...f..Wq.....IRz.._>.Q...G.c
......x.]03%.d....k.......f...v......"...w.3..;-=...=..}... ....8....5
.....Y.I..*L......D..d.f.....2....8$.H:.L.f..U....6.E.........U...4...
...0#./.b...;.M..WIu`.G....C... ...|..}a.x.%......q...0.d.............
.0kb..B_....Bt[.|z`........~i}.lF.&..8...8..........M.].X;.85 2......k
7.......Ue.Ht..L.K ?.......9........k......o?.ml.Isk.....n.~.0.q!..qol
....~....eh..R..O...`H2......0..;...E.....VZ..1.".u......xhn....,N.?..
.ex...NV...^.>.@@.c)p......fJ...p..0n4..%..,T|.)e....6.s,.?..P.A1..
.p..Q..WI.Y...%...4.....3..,P...U...1#.U..11...iF-.......H..f...C..X..
Y.&...9."./.{.........5..C%.U.>.H...y.g.J..)0q.4..o.;........^.S..j
%.V..X.H.....j%...Lu.....N...J....Uu.C...:vZpeR[..bij".^VHP|....;.....
u...QI.#.L .]U...n..{..<........C.[<....>..-....c..b..I.b.3em
C..\..{uh..8.1.M.&.....\...!vFa..C.....X.'-..9V.:.....@..g..b?'.`.\.0u
....W*pi.)%.....9Z....J.:...a6..D.>...B.if..K.F..E...`.|...._......
t].p..4'^.=.Y.m.....P...Q.6...nS.R...H.....6.`.e.^... .sd.OX.S.h.ZY...
. ....1b......tr(........0c..N..@.....W..E`&|/m......N~=........ =

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD-wOAxMgoIBBD-wOAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..19cb....3ASU!VPSz."..@...h...E
...x.M.w@.....s..I........Q......J.2.Je.4...:..D)>.AH..P...........
}......G.u......uggo.Vo...SC...(.Qk...0T.v.r.&..> V..*I.......v).0.
&R...El...|....2b....0$.L.KX.. ...n....\k..i.=.t.z..)..Cl.......Cc..na
,U..qh..c..tr.......J8..6........8P.......E.Z..}.{.y..4W..]...W.E._..A
.J;`.P%@n....gY.bb..3..4h..#..).El...h"..{.9...}jF.w...}..Y....E.<G
.o...<k......2.M..6..Tx...Pj.`1b.K.m..4..{...@...m)..K......&......
...D...w...I..X...H..`!;.y..s.b=|.g..4.Yb7:..E...>.D.....Y.~..c....
......or{...~.I.k.3.)....lt....y..Zh.........F.'..ofp)PE.Z...!. .(}...
.....c.OO ./H...\....I.R...j. 2....s.....^@lQ......6vE. .d..X...rb#'.-
^x..q...z.vA......hV...BlN.....#.......u.#..:.....d..#.g?.DQV....7....
.a./Q.~.=....Z{...T..t......&.s.;."..Ni...D...H>.....".......))8.=.
.1=..I.<..^..2.s..E...r....(....W.c.........e..93....f.3...o..Lda..
J.6....../.m.. |sU[5..2.....Y ..f...ZM2.......o..;&..O...#}...K.bu.vl.
.........vA..W..7...f}jK....d.5..X..!....U..V#.(...&...)...(..{..0....
.',...$.X.:.gt].b..*.W.."vIf..v^...../r8.wLC......l}...t..1[Y.(B..<
..nd..) .'..........X_....|x&...;w.'.h.v#vq.....2.g.o.........y..4.Z.8
.[..G........(1....o...Q.....h@.U9.s!..1..M.zo.....I.....,.B7..~.....x
.b~*..Pv..Eo........0.u.`L~V....^Sy....-.$..J9.(=....Yd......'.{..D...
.Df7..4.z.gv..... j'.y.@Oz...#.@.o*."..2.~..`.C..!.....^2>.oz..#.O.
.Pa.R.-.,.......R(.:...^.,.....!.....~-.[(.3....d....~...^B...\.B..h..
.....1..., l..^...].z.. ..*...,.~s.MA.././..(.........k...K......T

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCHw-AxMgoIBBCHw-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..14c.....ASU!VPSz."
..A...........x...uQ......j.[.........L5U``.3..J..."H...e...b ....j.n.
..........`.Y....X..) Ab.~-.W\...-x.2.$.. .".<..H,...iSO.2......g..
k..v..~. ........\G. 32j0X01.80eD9Ofp`t.fL`.a.e.cb(K.h`bh..R..$..a....
....W....T....pA...A........h&..]f .....f....e}x.;H}..|]2.!.z:@.b.s..V
.I$..p1..J.....8.....p._.x...t.k..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCPxeAxMgoIBBCPxeAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..1d5.....ASU!VPSz."
..B...r.......x...uQ......j.......l.e..p.......e..?..V..u.....R...xQ..
$v.`g*HlO.........nf$^..u ..L.I...{..&v|.!C.=.3..N...=.....[4%,.e..e..
....@...:...R-;H..r....Y....... .!HLsw......m.:.oO`........5p........m
.u?yQc.#HW...{X...J*..T{..].L...>f....P.. ..u..2#.&......I...BL.v..
..L..2........................... ....*M.S ....#~2...xa...D. ..J..0!].
qA..^IjE...N.;t.....J..NJ.d|..K....;.T.V..Z..yg.......1...M.i.1.h...7.
*u..i......@|@. ...U0.....7[./>ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCkx-AxMgoIBBCkx-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..127.....ASU!VPSz."
..C...........x...uQ>.....j...H3204.3??.z..a.[o.....@br...L...b:...
.........x.T..a......:. <....=]..@......:00l9..Xt.f:Hl...........=.
...@b./Z...Mg.H..^...(..z; .d....1..G_Bx......3<..=..U...z.k......G
g)...]i..,&.....{...b.<.e.......T0..].`$..{k..P....E...Vj.k;..|W...
......ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCyyeAxMgoIBBCyyeAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..189.....ASU!VPSz."
..D...&...5...x...uQ.ed`.p5..```.2..8&...00..^U....4H...5B....6.......
........;!}.i..[...........R.-.......j.b..]@..u..2#...C.-...w.B.......
...L...@.D ...Re.`.. ..<c............H...L&.....&...*y...I?...XY.'3
.0..3.`4..`.h....c..8y..c.p.=O.d...ta.....v..........-..*U.Li.*....L..
..n0...h*..T..p..E..r.Ot.......j..m0....V...Gd ..c.5.9H.'x.-..kC.A..Gs
3.z.w...>..U'.|>zNDH...c.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCyy-AxMgoIBBCyy-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..160.....ASU!VPSz."
..E...........x...uQ.dd`.p5.Ma``.2..p.9f.dwXK==&.3.$.aU.h...0.~.....j.
....j..v3T...^.[ .$.z; ...]|...v'v.....3A.].L.s...;..S.V....b........&
3.y(.3..S.....,...I.A.!~2C.s.0...D. ..*ab..bP.RdPb2.6af.b.d.gp....,.h.
.....WT\...,W..`.`...........XV..P..........]. .q.b.7.s..)..7.|.......
.J..w.P.../Ny......-o..].2$9Y8....m./{.~r.t..-.....ASWSig2B..0..>....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCozeAxMgoIBBCozeAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..429.....ASU!VPSz."
..F.......:...x.%..P.u...g...F..c8..!.:.../Q*.6....B@p.cJ!3o].j;.G.pp.
&...]..n.a.6.Rd.H2E......NO.c....}..}...s...I...,r.H.Gn..............P
..\3..-..|...............=.H....\...N......)..........&.....n..s.. .-9
h.U..&o0.?..g6"H...H.[..P..........j.d....u<4.....O...Nx...).RY.U..
.1......jVe....W..'.2......q..B.2.......5....../..qQ..6.. ).{......y..
,.E4.wo3.8........dP[5..........I.../X....Tq.N..TR..Z...[.n4......KMDt
...J..!..z.{.O9.uy.P.B.;49.p.a...,>">e...x)I.V.vq..`...IC..F.<
;..i..5.>/8c.......\.... ...X..Z.l.....c...`.z.V...C >..O)......
}..C.$..I...,d..mq.....-p..).U..'.......-.~..X..u...ES*kb.X_(..W.....M
.q..G........t....:.....Ly...5...V.b.....5.E~.v.i..^B...j..,K....uq..^
..dm...*.h%..1...........].e..[....@..2..G~......mv........."..^.7D..[
>..m..ch....\...Z..3.8HT0.KY^.Nhse.."5..............}........p.s.Mp
...".....7..V..Ro....&@.....O....-.".A..e..V.<..1.f ..p.n.n.LI\oi~W
5.....f.Ue!.L....0.udX.H.....Q..f.Zc../....^o.L.[.8..K....L(-..u.z8..W
..dr3.z.....5E?.4..................`A.....M..Fb.?...#a"`(E.......h..0.
i._f..(z9].q..-...ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCez-AxMgoIBBCez-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..21a.....ASU!VPSz."
..............x...uQ~.....j.{.H.QC......,.n..=...{.H.O........w.7le..@
b...%M......}o<!..$.:.M......w^z.o~.............O.b...mo|}...#..~CK
...# ...G........^ ?..$..)I.d......4J.Abfm.......7 { .N.H.n.....F.eM..
.^....>........\.....@b.....zM.......... ...,. u..l8..KZ...nz\...G.
.[.oL. 1.-..A..z....YK.$....!s....c.d}......o9k..C.j....N02..Boge....Z
.q.....MN)}.ZQe.....'....w....wO.H...}. u.}...... ....f.o^1..k....G.{2
.(^h.&...5.TW....o|.....> ...1.U...l...~'E.f/....n..$.@....i:......
cR..C...uYt.~B.. v.,..I$k..6..8?p.S=ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC-0eAxMgoIBBC-0eAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..308.....ASU!VPSz."
..............x...uQ......j...H3204<f.$h... ^.?..H..$f....*P..6....
..@b..8....0.=.(8m......R......4.2........U...200D.........SVO.1=.. ..
h..%..Ab..M&.:...._..l....m...fz.......r_......|....0S.`P..k. 1.......
.|E7}?....$.....T..![.<../}S...j?yI.....E....@.....g5>....Bx.*._
_.C_.....|...k....~?.O..#.])...f{..o.K..<&.T. E.p....b....,........
W|...*0.f.....j....E...l.^l....y.O...v...3..^M... .^..e^&.........6'..
9.....z.......[...T4AbI...........k.s.a2.{..l>.......mh...._.u.3.j.
............L.X.....O....H.{..RW%...G..~|.v.$..*t.(...t_Zc...$.d.VNP(.
..j..#.#8.w.D.......=.]......t\g...a. ).....@bl7.O..1....}B..Aba.....0
0...H>....(..~......`..L...@.....?.VL....`. .L]....Z.x...;.[...V...
VX"..}...h...Fv.&a............../E]..O)..H....={u\.6.29_/..=..A.r...5[
l..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDC0-AxMgoIBBDC0-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..26bc....MASU!VPSz."......Y&..%
'..x.%Z.TT....;......iiT.%.D.....)i........F@.......8..3w.....gWKG....
.u9^vb...3..%..?..e..F.........k.4.`...-.J\._..9Z."...`.a...-...$.....
.9.....d..........@|.IC.~...5_.F.d.........$..h..{....E........j.nn..N
......KE...5.x,)~j.....\;'c...%m.......}.dMP..5.<.f.....93.25...VS.
^....u..a.r...j"M?..Md...e...v..5..8q..$.f?.M'/.TO..5....S.9..2x8.0..^
5.>s9....L.1.*...B.Y...2...F&..E'.3....._.,a(p.x..yJ. ...U..7./#&..
h......!fZ.Pb.tni.I~..v..@...<S...G...\N.i.y7.~]Fm.zhf.p.H...02M.oU
....I.]..Hc^F...&.p.X0....)..6J....U........5.S..Q...I..L.=...:.8...*.
7.#.^e..c..\.".....])a?vrZY.T&.L..:...|....G.|s....d.... ._@.@.?m.pv.D
^.b.I.H.e....~ivAIUN..5/.jJ..f........M.n..v...`....R.(6..S../.D..i..2
H.@....$...S7...rl.o7FTv.........;.....d}<.#./.....#....A.J....q.%.
@......L"*........L...'.....L....z...8.W...].y..@.%...0/n52.%......$?.
u:..M8;...o9.Kom..<.\X.a.... e4.h"7^..(k...l"P....W.a..m~R..#Q.....
..1K`.. ~.....)B.k...=.>..r~....._..u.!.m..B..v..n..B.n...y.....\..
3.WH.C:..)....}S....._w..yX....7I.'...v......3.Zu.((.^...0m....W/..u.o
...|..G.3.p..d.~...'.dU......oy....K.)i.....Y...\f}*<.r.....|U<.
Z......x...@i\.\.....!9....#...%.._..$(.<.E22.....db...)TB..Z?.i}u.
........TC...n....K..p.p;,..{.....`d....L..;....L".8<}...?.G... .s.
7...]*..j......R.G0k....N|k.E~.v^...}.y.......b.~E.....[..Q..<a.(..
s....|/.".QAa.hG..j$!..8.0.n....F..p.e.....3..}......nI..[...RV...B...
O...}...(..].....!..N..7Z...0q.Y..h...............M.9........!$>

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDh1eAxMgoIBBDh1eAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..584.....ASU!VPSz."......!.....
..x.-..4Ty.....q..d.c'.a(%%f()..&E....dE.-.B.a4..c..n..........j.AG.I.
MS-.XQ......s.......|......a...M\g....yf...K...F.O.P.{...-?...0o0N....
.2...{8.8Po.).....,.n.AN..v.d..]I."sZ....S,x..e....Dv...(...$..~w..Edz
....&...... ..8iW.-..{7)1>....??.....N]..v....p......&..)...i{E.8..
..Z..Z.l.q....]....y......r......... ..Ev.J}.....7.........u 8...k..&.
.r6....;T..U.%...E ....p.qx~...r.i...I.GT_.m.vs.F..i...;...t..........
..L.......*......72>;.-.....CqAj@.2...w.......X^Q..mtc.I o..kD.b...
.qy...*$.BJ.&\.#......(.3..QE.~ ............jxGv...o ..t.....-......w.
.p..o..2.....r.g.........:,dm'C.$..B.|7saP.9.U.....0h.g'.N7.C.^0.....P
6...j....9...*.d.m.}......"."..a.}..,x......f.............1.I..@...M.*
....o.......x.W.......a%.pxi......D.L}.. ..k.^.!x2;......r.otu..=.7[_.
....S.>..8P.\LGV<.L~b..c.9aO...P.'{..@..9d..#...7q...'/.'.....PA
.e...GZ....$..aA.......:u...........;[........j}./X.. bL. . fq....W.;t
.Z.e......G..%.....t......)...u].y.b...y.J......7m.F...Hg....6k.. /36.
Z./5.......n...az.M.5.\.k....2w.]..i.y..k...[.....d._.q.z.9y.....X..g.
.5n.^.<Fl....~%[:..p>i.|M.z...Oa......6..1R.....'.tR,l.}.U/z.P._
:s..>.S{[S....EX..R...<39.t*s.X......v....9.S.{\f..O.k5......r.6
..Wb...{>.......[..M....|$..B..?X..,|...?......"..<B..<...(F.
c.y*...:... V.....8.S...ea..X.I..Q..........u.....k.e.I.QXd...f.p0$.H.
......kk(y...'V...",....kv.sS4...iP...A...2]....V%$Rq.[E.....D^.g...z.
...&...f....ASWSig2B..0..
....

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDH2OAxMgoIBBDH2OAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..351.....ASU!VPSz."
..........8...x.%.{H.A.......&smAL...j.FZ..K.s61.0V.Q.=HE..1M.%Je.mj..
e.e..E..):....F>.U.e.*)..l.<.;...}......Q.Q....$.....u....|-.PX.
.3.m..F.t.d=.#....G....j.....q.....h.|......G.%qI....<z\...5h/n^ZlE
.........Y4...B......i...d[/....m.b-.^P7Y9......s.B4.....[%.l.|.w..5.'
Gam.2G..E.l)..n...h^...|...y..0....b......R..m...#xOm9c.A.!1G.....Q...
...H.[;.6..m~..~....T..ABK4...X.......ie.G....a.o..v.1.:..).i|..tE..h-
A..N=c.$...*.S..h......j.l.....M.4....N....3V..L.........W..h...c1....
......dGPS....s-....!.....f.....=.....Tc..Z..X.m..1S.....z...a......C.
h.S.R....}....*....T...~3..........4.q...O....}..b|Kay\tN..... .B..l..
|..5.v.u..j...\.......[..>.A.....rPQ`..A..:AB\....y..5.....K.......
u...D.30.6...y..!..[..9....d.X......W...^]v...Z.{v.m....P/v6..V<.;.
,T...(S..fB.h...$m..#V'..Q.!c..'.K....b..WRzJ..t..H..:.2.O._.U...g_.fc
-..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD22uAxMgoIBBD22uAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..3bc.....ASU!VPSz."
......Y.......x.%.{PLq...so.Z.[......d..nl....!.....<...&.B........
.Ge.......T.c.ULMC..H4.R......;.....w.....Q{.t..._*U...@f$.<.$8.=.K
w..O".#Y..z.....yPb..%(..........y&...W=.6....;.w.%..BT.j...._C/.>.
/D[..5..n]...{l.[..!j..n....a-S...uk..... N .....h.........t<p..K..
..*...Y..b..uh/.n.......ey.........H...5;bKe.....Sh..\...6Fm5..eh..|..
.k._.e..].^PL.&!.G.xl4C...|X...M..^......_....%.,XQ~|..... .o.S$.|e...
..\...VW.....7Z....X'M.,.. ?.....=...u......U.6.=f1...]9...m..M.>.q
.....9.V.T.....7...I......@.....Y..,.5.....J?.....>....Q..h..*o1..d
..Y%...h.aO...3.......^....Eb>.(s..?....T..]z.g.kT.B..KR.b....3...@
P.W.%.m&q.B.O...Y..... ...aQ....3....Hy..^.4....6.9...YQ.q5.n.L.1^:..v
=...$.`...l.NNKq..B.Kt.E....mA..6...u.......|}x4...jx.s.O.H..P...7AH@.
.%.E.i..h...Y.@M%..........G.QC.).%.w..'...N.....X.J.TJ..T.BW.....ns..
..]..]..2=.$....#IB....\...w......*Q...4:f.G.j...N.?'_.R.M..t8&N%X.l..
...J;.j.......{.#..G*"..i4R..F.W......<\....[.ASWSig2B..0..
.
...



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDz3OAxMgoIBBDz3OAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..240.....ASU!VPSz."
..............x...uQ......j.;.H.Q...WeV.....s*........f\3=....U.x....A
b.t.>?... ..-|..1'HL.~.s..,.m.4.3M.~......iz..a..{..B......>R45`
e.?x.^....@b...%M....}^..Yn...c..|[...........$...^........Y...0HL.PE.
...A.<..W..C ...U.......Q...g..$6.v..U&......I......O.33U``X.......
* ...O...``8.x..s].#...........*...gW...9/.6....A.xY.... .. /o.....e.
~..!.. .i....n`d..K.j..!....z..k.<...V.S.ekAb9.m'.;00..z$.,.1.5.T..
..4.X...}eFF....*..........L.L..Y..3.M}..Y@...u..t.D......-`.^...1...V
..,....6.....ZA2J....V..t.A.$...xA8.1.m^j..9.I.a...9...0M$.eAt[fjE...d
.....8.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCT3-AxMgoIBBCT3-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..149c....)ASU!VPSz."......9....
...x.%W.T..........i.z4H..RJ(. J.C.......tI.t......z....y..f..g.......
.}........h)..v...n.....OV...,.Z...Cc>....Z..W0.2..^BcX......@..k.#
|......!.%.P...y..a.....n.......SAF"4.)...... G.......1-...83.^.B7..d=
....b.\.....J0..e....cT..|K...H.._...........zY.v.9-.s0;nE...%.M..'...
,M......MM..7. t(B........S.9_4V...L.......O..*4..f...`..;....l..X@.6.
z..B8.W.B0..Oq...b.Q..3.#.b4..m7.w`..>Z..@.h4.3..?...`..9..9......u
....S......'&.....@.....6....=..@....t....O..G..p...:B.........l......
.~....]....6&.......*.6.4.....WM.!..6......C..n..?..5......n../..h...X
0..m...rk.....*..g......1....^.qG....].9...... .....K.......w.......P.
....L...I#K}.#.CG3.yC3..ut$......CQ....#............D.HG.........Gl..D
q.O..9`z.#.eeMQ...8.g.z...b....(~".s{.. b.b.F....*;..... ....Qc..... ,
*%2..*..u.vPd.Ki..I.....5 _#QI.tZ.....O....yv2.l.,(........n....%....N
1w..i.....>...jN....S...3.n..KEa...$$[./0..Lg..eX.....^(..f.....76x
.......q|6....Z......k. ......i..}.k....[..z.b.2X..a@..N....k...(...7.
...;.............@&w`J. ...................&4{%wu...T../.M.0...q..,...
..%....;7......d..n.G.9..z.26..|....kG.....i<#..;f.AX.6.k|P.MxC2.O]
..zt}....Z93.SE.7u^5.H..X{.SOJ..*..}.J).hP .=.M..6f.L2..-....... .|..)
..d..0..LWE.....8..{,...m.`Q...p.[....b-.q.V............m...k.n..-...g
.......'..t..q.~.1?.....yg.....T.k..e. 8.#..:9..)X.....t-:...=....r...
@.1........O<....f....K.A...4B.....3b.nN..`..&....4...Y.#n...Z...a(
?..<.90o.2.8v..|8......0........^...w"ioH&eH....ku......9BV..x.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCj4eAxMgoIBBCj4eAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..27f.....ASU!VPSz."
..........\...x...uQ.ab`.p5............M.00...d...*... $=7....o.yx....
.C...A...tnkr.3.....J6............ .GFk|@...._..d....N.O.L/.2d.V.....
8H....WQ^...pS[...`.l.........7(n..|.....x.T..a..p'.... 1....Q........
.d........5..!_....3....../.o......`tw..U@/7..H..2OG.?V........j...`..
....r..IwK>...}P].(.j...P.7\,^s.H...Y.i.....#.O.N.....]w...\...h|..
H,i.m*(....x={..#.....@...N..S...HLkU................[.iM... ......5.l
@b../...00.....#.3.$.e...).U.&..0..z..c9s..4.....R..=l.`.<Z..r.....
.|....9..O.d^I...~.#=.^......m..t]....r.f.-.e.n}v.0....t.)...r...t?%..
.Y.{Z.J8..S..5.........8..T...|.h.,J.<.u.-].......F..Zf.v.$...a.ASW
Sig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC24-AxMgoIBBC24-AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..38b.....ASU!VPSz."
......(.......x.%..,Tq....{wo8nND....Hw'.....\...]*..&w.....Ne..._N)..
o...D..ZW.-.u.Mi...E.Q.{.........{.xE..... _.4A.....^{.H.vT..>..y3.
......sx .Fx.L.I..t.......h>..../@.......P.Q............e}h...<H
.........jC3......Y.e(..&..E=%X...^.gS.,.cI..IX.....%.....d.... ...:#.
....w.!..,......}.CI.U...\...@e.u4s..;.(..6:).s....|.......@[_.*y...5.
QWB..ZM..@..........i4SF.#....WyL.....]..z.zgqZR.............%.Z...]h.
.._...C....w..].;.&.(8#....l.G...7._4.>.e.0@...W..!..<{...$&....
...so...<...M..Z..E...~z8...yg.,....[...S...3.'}\.tQ..,S....e..Y...
...g......7....S..9Q5v.h.~.E.....k....)Li*...2x.].n.....E..0....P.)q..
.1s........'k3.mg....(........y......g.QI...~O.hC./.1..(.L/C.\..m..P.X
;H..96o......N'].y6..s4.Vy,....K.>.g..GQ.@...;i.D.....1..@Y.}NJWJ..
O.. wEf..tn&..V.Z...z....Z.<.)R....b:.tL.]...r.u..j.....u.yOqEy...g
......&..V.n....o......".......lW.....vb.G..0.m..."{ 9.h.i.b.....y3.l.
ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCU5uAxMgoIBBCU5uAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..2a4.....ASU!VPSz."
......A...w...x...uQ.gb`.p5.........$...n`a...Loo... .W.........t.....
. .H.u.[.30$...VL6q....y)n....F...LquF`.......^7.j...?% .....L.X......
-.....D~.oz..awE..M.]. ....2....|5Wp..v................M|..=...u.z..E.
S ]z...CY...,..q.........h.....zF..8.,.Xo.F.....x.-3..E.Ab}u..M....J..
...j....s...V........ 1.y'..V11<>0.??k.8H..q.N..K...p[...$v.....
.,..%...Qx-..A........j...." ./.ua.7&..t....6......`....a .u....N.eP[.
......$..p....L..~00..g.....p/....CK.....";.X.w.I.@_..rL.Q*..$...p..7.
..O..b.c.@b....4e``....r...*..Sm-..P.bE..........n.j1.31|.`.g.df0`l`..
......7{...).4^,1.]4..QE..E{..m.U.?......XXYX'...0.k..."V.....8.y...u.
.....CP.?...#...S..IXc..4;.j...ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCW6OAxMgoIBBCW6OAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..480.....ASU!VPSz."
..............x.%..LSW....^z......1 ...!.R...FZ......C.c.3K..0^.C.e5H.
...<......&.....Sy..XD.......?......s...s....eYG...........G0......
....eg4.#...G.b..k.L..hG.enT.aP..L......5.M...@p[....d.v.xg.....R.....
..N..~).......$..H.3..;.y&../*.\^.D..t....L0.....9BC..h...$.\../...E.s
]..i......i..hK../..,...w.pV=....&....[2...&|.&./..x........h....T....
..{..M..GA.....~$O..... L.x.....ZeHok.9....(.w]....W5.u$.L..X....q....
..2.....{.m......I.UG.w. --..5..8....K.....R.4.|.HE........7.......:N\
.e..4>@;t#i.ZH....m.. O.........Nslj..n*Zz..Z!....1.......jEm.....^
............... {}$-)...g.9;...y.[*....)>.........?..;s.E_...Ko.(..
.h.=..M..........#h{....f..../~a....;.......Hl.\...Z.lb._...bv..-v.l\Z
.sB.>..\.$yh......sQ..3k....73.S./a....X....m........(.}%.D.SM....`
..yq.....v7L0..j..|..BS;..8..l..OJS...?...>..6bz...2.......&.%5..j.
....|..Xs.{v...*.....qTw...Bs.9.df...2.h..}\.....B..>ZS.....8..g...
....tF.....~u...2.B.[.........F.....97..*...:KJK...[..8C>.....'....
!...b.n.m.'..z...E.K...M...E.f...../..x}.Iz...Oj.....,..3.0=...(...D..
V.it7M.......g.Cd1MG..& ;|.V..5?.7.G..n.i..$.C..%......c.0r1C.3^W(..v.
.....}....tu.n.....T.O..........ASWSig2B..0..
....

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDQ6uAxMgoIBBDQ6uAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1128...."ASU!VPSz.".........."
...x..W.4...=..<?Cf..9s<..L)2.B(!s......!I"....Le.Tx..e..D....o.
....]..s.9{_k.}AN&...Eim......D.nv#..........vKv..f7..&.....zu.M...SZG
`....X&...6...U.#.L.......#.....,z...X.]..q.%.r.*=.@.h?'..{......A.8..
...'.v......F...f...k........&3......Ma..GXe....6..D.J..H..F.l..4...B~
}n3..#L......82A6.K.NG..*...8.w..........*..Y.......q.a6_...Q.......z.
..%....{e....[.<.JAr....O..cH.kHEr..*.f.$Zdq.....*.F.&.....k%..v.d.
&.?k................G...2.MB_4-U.....s.11.....(/..k.S.x.9_:(.`p....h..
...o...E.z39A./...|.....1n..Z..,..B.d?.{r.,.>.\....h.0.o...m9.1..J1
.\A....g.9.1& ... ....F..@.........>.&...|%)_L......mF2S...f..[b2..
2m.%..IQG..K..>Y...Gs.ja...l4.XD.#@;...s......p.PVU...._\....o...'
....M.2..Z'.)..Wqt.o..~..~.m.t.<.....7.....k%..l.sn.f<h..:.@....
.bi...9..v:.......[.z>Lm.GL...../..R...I`<..8&53).....p.TB.r.K..
..G...N.hbC.........T..|4..)J.s.....$%....mQ...2.Lv.=...(.....m.......
G...r....H...._=...l...c..rC..V.....f.2...m.kh.4F.I;..n....O.S>..1h
.....`..YA<...X.(.i....M..sj.>.p..)0....p..p.j.x..2...h...W..=.&
.....93P.?qi.U..w..l.USe{....._./...0?3>7"...7NMS]...".=...r....wRu
..)....vB.....9.....,..S.......NndF....w]...........l...r..|....c..._.
V.O...b....=.y..P....S.I...?..*....n........I.~.......$...H<.2.P.`.
......}..1..w}...?.....2E..3.x..`A....?.W...$..........s..6.... J[...&
...........:..].9.s..O....`r...:.A`.X.}b...i4xb..C.....[.y..........:.
._..\..M.....N.......s.1s.S."PL... .......>.*.........j.;sZc.z.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD87OAxMgoIBBD87OAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..372.....ASU!VPSz."
..........X...x.%..HSa....{..y...W`.I.....fj..H........$0..f.>.f.hR
..K.....GJ...R...%..B..i.o....~.....BE..!.@..d..../S...j....;.?*..jd..
...!.k.3....Id.}.?X....._ea0.SfnR.N......NcR....wN.d..G...u..yG......b
.V.:R.lNP.$..@:...d1J$........kM.j:..... .I...A..&eS..RB.;.n:....t..]F
6...#UtpX.......L..lCza.=...5..Bv%.h.......e{C..2yjU,..0t.x\..n22.....
....f..... .%L.|..........b3....@.O~.Ff..,9.........P?..t.v)g./...6..
O{....Sc.6.U.!........&..T.eQ......jJ....R..N...............MU.;nnm...
x..DN..._.~.6..:.......u}9..O(j...LP.....mhE.J$...Pu....K;..2..r.....P
.u...DV*)].. ..=.}..hI..B.*..`I....z>.._...,..H..vPxL....o....H..Sj
...B..5d..E@N.............b.....?...'$..T...b.D.tj...Oq0..|.hi..@.y.[.
b...A.$...!1.&.O.....|d`.........GpHs..P@.f...c...d/..cr...8.y....`bB\
\.%...5..T....T>......lQ./|.jQ`..w.......<......;...9..mEc..oe{.
.>-U.8...m....*..b..E(.i.t.s$.H..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD_7uAxMgoIBBD_7uAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..2d5.....ASU!VPSz."
......r.......x...uQ.gb`..2..b```b`..7.}y.sv./ .3..X7.(.D.AB...@A.....
.....|..o...2..M;#..i..S.V.0......V.`... ..z....00<\...e0..$.....TG
....ugw~......i.6..[(..7.=f3H.-.#..(....WmN.xq.$&.........^......@b.e.
nW..Y0M]....'@b....n..d.......9.Ab..>.65`e..W.3.I..H,p..OWmV.l...t.
....J..2..`bH........$.pe.0.g^.........6/.........}..w.[3..V>..6...
._b..S...Ab,_.D\_lg.z..m.... 1.o.2M/00$..[..o?..`.}...v..$.......LV.*.
........U...,ZU.........X......... ..aE..^IjE.cI5#[.#c .f.....CB..^fJb
4SIb.3..c.d...xaF>...KY..j.....{.&.0aT..ud.d....IKH....z2....0c....
.$.$'.N..O...../..Qf ...*..jYX....DW.H.]"|g:.... &0.(9.....&.J........
...J",9/~..o....................}......5...c.....%......i.7..W\.. ..6.
..].X......P.6..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD98OAxMgoIBBD98OAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..1f0.....ASU!VPSz."
..............x...uQ^.....j. ....ARl...2..........Ab7.8.L.01\....w....
X...t......kr.........}.5.........6....d.......Zte..m?Hl[...Q.v.....D'
M..k...m...C...Y..}`.~..^ez..a..}.%..|...-wRd5.b8%.T..(`..;.......C.GD
e.3Uq....7...00,v..:....H...p).....\f.wq.{...n....xy...KS>.$.......
......2[..].L... .......WfdTb0d0b.ab.............!.....A.J.A....a.3...
.;K!P..!.!..A...h..*....G.q....z=......pu.....O.s....| ....,a...DN]..
...c(.*.A..q.r.g..H..r......Z,..q.cE...a-.3.0J_.....~.AQ._ASWSig2B..0.
.
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD48uAxMgoIBBD48uAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..310.....ASU!VPSz."
..............x...uQ~.....j.{.......8&...00.0>xm.... ...Z.B.....~..
z..U..[$G..E&.z..o.%E.@b........n......t.H,8^..5..a...r.... ...`.cy...
..N.js........&.3..q.}.sy.tV.........o....eV....%.-3....HWwN..cq..R.i.
..|.AbZ./........w~-H...I..@.."o^t....$.>.t....[. E f...m?.........
...SAb.'..<...j.......>..("y`.,.nG.*.... ....KM...Vw..B...X.vV..
.%..>...y.HL.YH... C........Ab...:A.*..3.y_X......3...!.M..z.R ...o
:...l.......R*..............n.f..........r.yM.@s..... .....s.:....!Y.h
.....Ab...S..``8k..G...:(.}..k........*......,>S9.D..ky......P....M
..v...=.)V`..9.yp..............:\.. 32.M..j.d......i.7.'.....2....d\..
..>.3.3.W)03..Sc0dfh.4af.P.ef00wabp.`q``8...p...h.....m..W^.j..-},.
.W.4..9....j{.7..a...u.q.XQ..3BG....~Y......2.:L#.p.....b..T.[#..E%,..
n.Q.....m...rnASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD09OAxMgoIBBD09OAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..23c.....ASU!VPSz."
..............x...uQ......j.......X.|9kB....Z.sSS......`d-.d8....;.Y4H
..J..(..."S.y..=....n8.....Cf.c...~. ..~.. ...}q.......GH....d...`.u.z
..[...h.......TL.'.$.Y~..........Ij.. ..s6..^``..Q.....Y ...~......%|.
..yj....z......*.m.|..0....sg..``8.......2..S.5.K....nZ,..i"H..t.... .
..f....j.X.....K...[.=).z7.$..>.....C].......AbQ.-....2l.....yV.@b9
.m'.200x....1..Fh..v.....q.I.r^;....29...A..z..5....$...n...e..[.!qn..
.B........aGAlU.....N..b{=..<...?...`. .d,lc...............j&2w..2.
....M....Q.g.^.8..N3@..6a.....>H..1.=.w....=....\.=.sL.-\.]....5...
ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDz9uAxMgoIBBDz9uAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1844....0ASU!VPSz."..........u
...x.%X.T._.}K.tIw...4,%"!H..tw#.4..(-H#H.tw....t.|......9......{..i&l
t;g.#.@Y......... .P.......... *..B4..>..h......T.c....|.H.......*.
=&!...w......Y$7..X.A.>_.....nJs ....e..=..........B=.f....O<..c
.G...<......&{[....s...o.....).\.T...=.7uy.......3...{L...ER *.!.i.
.}.x..|..........V...XR.d.=6. u..A.........wGt.f.?.r...,.....P.zO.....
.......:#R5....;G.b.8.2.O%..`cO..c..MGgP..9O..">..c.W.=$4..........
c.w.)$..h.^.a."gj.>es&...*`AW..E..3..Y..."...y.g..m_........w.5.D.2
.....0.Gg%...E..p..#v\...d.9WYY.t.......Je...9.....zs..A.BA.i..e>..
..V|....u...@I.<...$.3.z.VRm...&...]...|#....`..o.......}...3..^e..
..n$.Q.z.xR.....#..~...6...Rm..^W..J.1N..-.....v...%J~,. .AX....M..._.
.....n.D.O...w<.CW;q....t]Q k\......@.q.6.^...$..oA..4..m.V...l....
*1.m.E.=.n.p.......Cq.......)...<........Lj,...W..K.g.......0..=\xd
1d.......m...y9.d7...r.....E..........x%...3.h..v..p.....&B8.6...k..m.
..HO"UR......%Z.%.`....(....!R.4..NZ.H.pIU#w.cOs........d..,....z.Q..g
..Cc...!/..........~.........%.oe.C._k......wM>.&.G..K...9.oZ.#.~\.
.h#......T.Z...05....63q.....)...v.q.....<.i..9.b...c.ImQ...;;Q[g.9
#...O8z....>-M..O..x5cU...u9e ..4..Lt$.......(.....8U.:...q.4..1..\
.......>},....3..<..{k...4Q5...d<DO..50...>.@......J7~S..U
.......UQ.... W...k...Ib#\.....b'....P<.}....T...$...o0!,...-!.<
>.x......y...bl=zP..@C%.Q..h6r.W...$...2..2.....W.X..g.$..LC.......
........ ......U.]...*.:...D.I.<....7..-.m.Go....E....Z.....wE.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCf-eAxMgoIBBCf-eAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..17fd..../ASU!VPSz."..........3
...x.%X.X...}....!.H..t...tH7H.HJH.H.t...4. ]R..H !.........{g...y..s.
]m]yF...4....`.@...x........#l.....02.u.^I|.....A .x.).:.O...T5......;
..!.x.:>..BHR>....X9.f..P@............Z... Q..g............ ....
.......h3.....%_...P......Sp...%#.Z...w?...S.|.&?.o#..Q.0.....d.@3...i
.e.....u....m<..G.W=w... M.q.H%.....$..9{......h..=0....]...I... n.
.......x[.......[..Y..0...Z.qT@.sA.*.nx.. Z..{7..z...D.w.Q............
wj.0....A7T ..&s.L...........2v.).... ..F|j...i......{^.[.#ww..K2.7..p
L..|....rx...v...U_.._Um.e.."P LM.<..:..r.%M.....E.U.......GEZLo.`
.E....f.....X!.p......].P......].BL...FP.Fq_....9.c...(tL.P...r]E..;c.
..7........(.5.......f.K.C.....R..5..iNF.j.e..?...U..8Yu..F..`.~.....C
'.c..O...5.d.d........J^L...1LeTN..YQa..C..... ...D:....2i.g......../d
P]E..Z...8...Ms.P.=T....o.mI.g\.*k.UCiI.tsR.....T...........jR)?.g(...
..0.....f.u.w.R.5.2.<u..W..b...%0.$.X.lW...W....k.......h..;.....Ou
.....ti..C.P...if...DC..S......E..G.....X<...'.s.L.^..{>xH.....
...5#ou.m|....P...g*g....F,1..0...T.,.'.c.u...%.G.........J]..Qo...u..
I......;..........}.i9..i.. ...........C./p...t.C/.y.b%[hNT.a.S ...j.5
......8.. ..l.a.......$.5.e.\<.O.....@.q)....-..{.I....d.... (..7.I
.........km.p...<.jT...e9%1.i...^Q&N"B*....(.....AJ.L8bFs..n.....7.
..m;...........zp.t.hG^.#.FY.@.......7.j..../.._\o....C.d.L;g.........
..I........M.3..y.p......?S......._.(...;ao.|.P..S.k..F....F..|".c...'
.ou...3V.YH....|..4nb<.{...#.o.../.....j..........I{...q..{^H.,

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDf--AxMgoIBBDf--AxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..918.....ASU!VPSz."............
..x...y4.m.....,a,..d.V..O.Be.(.<-...%....5);.4d..%.....%O)E.4.,.JH
....9.>.:.s.q_.9........>.. .......'.|.{......DA.g......*.......
mna..\&...........%oB...4V..0|@ ....j........]~8l...k<F...3...H...x
..M.e....;.....%G..j7.l.~..........q...3.7......).:...........`]a....S
{.,o~v.p...H;t].#.p...H..q...Hy........k"....ks*ER....68....Pu3.^...qY
.....s.0..P."..u.....v..:....W..oL;.w..hR.C....}...2.e.....F.uE..n....
.....0.`..]..v.......e.N.g3/}..4.l!Ul..8..`..-..`j|[....../.)>..%.C
.u.&..l.............X.]MK.&.W.[........A..f......{.....}y0QOy.a..@..0.
.Ji)iA]...#.P?eX.-8...\|.?...7.\.Q.p.....,p......(2.|......W\......u9.
.......6'..^=.U...*...{...P.5Q]e0..C0......l".|.....n...%.....U.Y..t..
......2.6..'D...'.S.i{.C|\...........Y....ai.......n.(q.p.HX..x.8E..1.
..w_.....m. r..b....v3.,1......f..*...d...5.@..E.#..E.....\15...Ed..J.
.........oF.g..T.......t.y.....n.T.D..=RW...../....d.-...^j.R.6.z...d.
......H.{.&......m.h{y..:.=m.\...\:....6....W7....x....,.T....r...x...
.-.......oM...S........_..........S|%...^.xgR.6.u.}....O._u...%.....D`
J4.".l#..0~<5.....W..`sZ.L..........l../....).d.2.q<@.;[......Rl
....7../..&..N.SE%.....y...J.&.L.].....<..4.;.@.x...?%.Z>.t.l.Ih
..j.?.q.(..Ni...W.^^]x..H5OHoj...p..3m\Rb..g..{P~.FW...X.2.|0.....U.5(
Tj......~v2......=....a..8b.. ..J...k....... i..e....O&.....qLT.^.a...
..).5]...%..J..,.s..S{. ..[C.c.K.j..cL.du..t......no.|....s.):.,L..Bw.
u.A..4...5G..............Bv\z.Dd. .N.'. .!...=.b.!....=.m).....Y..

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCI_uAxMgoIBBCI_uAxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..f6.....ASU!VPSz.".
.............x...uQ.f``p.0.n..,@\.h.[......Wfd..X!/4.Qa.....Dgf.I..6..
...&14..3..;N.cv......W....T......X...... P...]......`...%.#..$.....).
.!5'.)?9.#...............W.R.#...b)P.w5..H.=`.8nA.c.]!j.;.....WNc..N..
...../..F3:.=.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCGgeExMgoIBBCGgeExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..175.....ASU!VPSz."
..........o...x...uQNgd`.p5..b``.2..Ew.f...pt..e!.|7.P,..2..........N.
.-Sd<....s.V...$.....S...3.38.pA...h.6.....1.....6.T..mr...k%^S....
.Xv...!..^...?.#>....-.[.12X....p.D.5.Ty..D.......n.&1...%..%1.%1.!
.b...Y .0..."..V..f Jb.3.!....0...iHb.j`.., Y6..l.i&.f...`s@...43. &..
EL@w.2.....2....g.R...|.^..PS.t.8.....=..y6).^,...}...|4........pi...
Z....../ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCRg-ExMgoIBBCRg-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..117.....ASU!VPSz."
..............x...uQ......`...............zL.,.L.Z.L=9Q,z.)..L%.),zE.E
...9@...\...z...fF&.*5.M.m...@]6NL.......$.3>..bQ``H.edU.R.*2bf....
T.....W.Z..X........Ze...d.`..pA.........tG&5I/.....*..3.n....x.\?..J.
.D..5.H.... ..y.."/....v....J.....U....`/F..:..{...ASWSig2B..0..>....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCMheExMgoIBBCMheExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..e4.....ASU!VPSz.".
.............x...uQ.g``p.0..g..| V..}_..Q...C....!...re...j.Y..Y....L.
...'3,P..f<...................U....`<.X....|....0..F.In.NB.Z.L..
-.l., ./..W3.....Lp..wGee..f..G...YL...&......,.ak.j..}......W....\$L
y.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCLh-ExMgoIBBCLh-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..7b...yASU!VPSz."..
............x...uQ.c``p.0.e..wV .....mpg.y@W....2t.n.?.0..X ......u^.&
gt;Z.....&.]........9......}...vV;ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCFieExMgoIBBCFieExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..187.....ASU!VPSz."
......$...>...x...uQ6cd`.p5..a``.2........3...........oXt.q2?.C....
..1........6.......!...WP3...6.J21.~d..........;.*..m....4.. ..j_..v10
L.e.^....HL..xA.K....v..s7f2..|..k.....=\.y..Cx=.Jq>...@.8...3l`d(=
......|.......Nb`(_qn...).Ab...,B..."....R....i>...^.. ..s..s1R ..'
....p1.z.".]..&HL...{..L....l_T......u.;...[1.."......!&.\n...........
o2.........X..@Hl.P.F;:.....zASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCDi-ExMgoIBBCDi-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..9bc.....ASU!VPSz."......Y...Z.
..x.%.i8........,a.dd...r......Q"...,.^c.. 2.lc7.R.%...%...d.&.,q.1w..
..yq^...y>.{~Xk4.......`..j"...Xs....o..Rny......4.J".h` H.|1w)d..l
`{."qC.0......>.i......2.F#...V.......(Q..N.....(.>H.]...!.q!.v.
.8.[?....s..4.....u].j.......m.]...^.>...^.........d...tl.\...j...]
..S..=...j.]....U......~. Ge<XX.@....2.......Y...3...xVN.`.I.?E..."
D8.h......A..{..f;*P.~.....i.)di...`.i...'.;..:..F.......^..tS.#..H.9.
...^L.<.i.7_{.{h..o$..J.p......:..(Mm..5)....3....P......a....t.@O.
/......)..!z9.WN;..p.A..p..(......E.2..9#.}.'...4.e..../p....\K8C`O...
A!.....Ei..4:O..8"....$.|.k...v.........*B.o..L....Kj.^..f.x.&..}.z}.H
K..=^..w2%...5.w..r.P.... _2X..5...kav........_......j.J.....8G0.B.P.-
...JH.Q.'.Y..;?..3y........0Y~.........,...D.W.V....D|..93..O.\.....L:
..R....9.Z.s(..x.=.M.R...`...9n...Z.....R.......Tw..'.....*.Y. ..M..bC
...f..@...5..g.....0..5V.pMl...@....I...y?.}i.OGlt.E........n....Ywd..
m...J..OD}.........u~...).;.}z.........o........![.....Z.6..u.@.M.....
.(}.....G.C...bF7@..E.k...Fm.......~.d<.Y...Z.b9..._...s1....P...^.
e.,b.[.e..~.(....g.....@..@.*....c..."}_s......N\b.......F...1-..A..,i
..w...(-Wt.l.W=h.. !_Q.p..-z......<.lr.....y......B..I.C.Z.#.[7....
.n.X.X...BN..7..k..#LaO.9D<n.1..e.G..1.c.[....c2. Y....'V...n.w..h.
v.Fqo..........{..wG K# .h....Q........E/....J...9...".....s=u(_1.C_2.
.o.`r.. .2V(.q..1....]*.K1#.I.......f.'..:.....Jp.8..._.........1QVT..
2.~r..pa.~./.|..M...X#.#...co.>)3.M..fh..(.C4....)....X.......;

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDyjuExMgoIBBDyjuExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..11a.....ASU!VPSz."
..............x...uQ......j...........Q>... .g......$.Ho......:.E..
............1.Z33,.....:..$.c ........J.....3..|..k........C.........S
......t...$...#W..7.v..=|)5.......y.^.NL 1.w..X...:T........y...c.vj..
..^-.....I;Q>!.R.&...#5.[.>....*..v1.......1.....?6.UHASWSig2B..
0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCPkeExMgoIBBCPkeExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..e7.....ASU!VPSz.".
.............x...uQnb``p.0..e..T V..w_..Q.A.!.%..!).E/<.9.)1......e
"[..@ .M.".!3....d..l....8.'i.;.qr:M..v...u.d..,\k..2)M.EHQ.u....#.R]V
}..r.....SI.`...................T...$.........m...<Nn....W.A.4.6$.
Z..IGASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDyk-ExMgoIBBDyk-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..1bf.....ASU!VPSz."
......\...u...x...uQ.ed`.p5..```.2..E.X:N.gH.1./<.K.$.>.t.H..F..
J..?....@...,.?.......W&..8.$Vi~L....a.BH...l. 1_ ..B c......5. ..D...
......l.:......^..z..AxO.....<`7...3-``xV}x..37..z.U..J00.l^gt!^. H
....z..F.SD..{O?wp.0..e..V ..jx.....(....... .?...}aF.F;...........[..
#..'.p....)L..P...dTd.d0eb`1...e&..d..o=.!..Z.q...d....a..,v..>...3
..&.800..bI``H.edifa.:..r....5..2.g0...3.d.............sZ.<.dgZ....
.qbgW..XL...X...*...XASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD1leExMgoIBBD1leExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..138.....ASU!VPSz."
.. ...........x...uQ......`.}.H..q....! ....@..Q.A........ ...1.1.!...
...Q...I.J.A...`...........9..C.$..L!N.z&&F.*y&[.M....I...B..Q,zE.E...
q..XD....D..R.@.ZF..*....JL?$..y....x2x1.p.2.'.0.TY01D...HI.g*I.gb.Hbq
``p...`b.........H.U.......e.....i...V..%.._E.[.Yi.....?.,.UMsa.3.e..?
.w.nSM..=..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD8l-ExMgoIBBD8l-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1268....$ASU!VPSz."..!.......0
...x.%.w8............&{.YY.=.e.Q({........U*...l.d~..........u.q..u..9
^..yc...s_...&...._.c*..:/.k...}...V...]C..58....$..p...z..........2..
..`..'7E.f........lN...5-....q.....i".....b-.h....|#P.2.J.u......Q.X.w
r...!..1.Vb....^2.S./....J.'pr..I....P..YJ..OEZ.4C.G.1...WC.Y....GANb.
.*M.a.0......$6..z:....a^A....R....9....iY..(...o....B.9BZ........."..
....:O......Ic.%....v..8.B.%.....Y..8......T........k.#~].3..$$6..qr..
.k...e.j....$`g.........8@v....F............u.......!...Rs.{.6.(...g.n
jkl.H}.1.<..k.....F...Y..&..w.......]bV...;.j...<>k6.[.c...u.
......K.....>K.;M....@tP...l...:.A.....L.g...k.....mp...hWm.U2..L_*
,8rO.,....:.g.....wuU.z....".....Q.X71...=...S...eJ..R.@....'.M.-....9
......[.....)..o3.'..e.Dku%n..)~..e..(...&.J.3]%W..U.x._..qp....Y...w.
..3....|..weZ....g..........,..gx.h[a1.y..T..H.*$...1tR{.%{g3.=.P..`..
(..x...)......7._.?....u.~.....7m.N|./~.q^7Az\.......$=Y.R.qi7k......M
r.".$..Y...o..{....G.F....X.. .f...3.2....:d..4.7...H.H.b..o.z...4&..*
..,.}.X.......%*tw..4.....T.j....=.6.Q.....J....3...Ia..VL.((e|..b.w..
D$[.....H*b..j.......9....M.?.H...kL......).4.;.'.....[x..i..Ow...h,c.
..Q..#LF..G...4J.........y.z...v._aB..kF..sg._....hr.Q\(..p..(.s.%..5)
Q..E]Z.w.l......%......'p..y..r.w&u..[e'.....t.U.......Wi.,H...R^..W..
9uT:.pIG..~.....k......jw.q.t,...P*j..~H....w.-AU...s..~.....V.1.i.im.
.k)<..........X(..r.P....I.. .cl~.....B.'.l.....?.....V`F....p^]...
......N....=.S.n..6]....s..._.c]I.G..2...c.....!..O...<7....#..

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC0muExMgoIBBC0muExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..c4.....ASU!VPSz.".
."...a...b...x...uQ.b``p.0....,@,..*...U...(32j1...f.e.d.af(....a. JI.
e*I.cdT.2f0af."......................4..n...z..w..k..z.._....]Sw....(.
X.U..E-g.<.[X....V..5...7n...R..B.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC8nOExMgoIBBC8nOExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..1a4.....ASU!VPSz."
..#...A...X...x...uQ.`d`.p5..```.2....-?......5R...)H..a.q........=!.&
lt;...%.!......*...7iU....B ...sn.....kU.Z.*2.$.k%^S.dp..U..X.......[.
.#.6..7..>. ...K.G......2.:...$....w#/.....%M.._ ...S.Z/10XL|#3.G{.
H.t.....L.b.....3...9../g5fbx.B.gZye.HlJ...Gu.........9.$......[...GvW
...E......{T.... ...... ...&.....oy....*........z..!..s..=2s.r.*....Z.
.s...~%/T..H....;p..![h..7&.....}.... .pE<8.A...}(.....ASWSig2B..0.
.
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDCnuExMgoIBBDCnuExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..98.....ASU!VPSz.".
.$...5...8...x...uQ6```p.0..`... ...|........`.`.....Y.P.............k
..h.bR.*....%.:FY...K.#.5...xAF..v.$...0>..[J..)...~-#.....%ASWSig2
B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDPoOExMgoIBBDPoOExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..13e.....ASU!VPSz."
..%...........x...uQ~.....`...H..q....5 ....@..Q.........!.E.(5'.)?9s.
I.c...F.z&&..&.V.*M..I1.ZB..a,z).%............Of``N.f4`...e,.gbflfd..R
.k.f0fp.....A...3B=T.^....d...6.....&..q;.........p......T..FFV.r.*9.5
...s&..0.p....ZF.V.#...2.gT8.d. ..<..d.o..\.`.^..E 4...cj.......c.~
....lD..U...%.g..]4@ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDtouExMgoIBBDtouExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..a8.....ASU!VPSz.".
.&...E...K...x...uQvf``p.0..f..c 6......(?QC^.R.A..A......H{.800.HgbH(
......[X..Z.r|.................TT{..P.A.~..y...4s.r..R....$o..U8\...g.
#xYCI.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD4pOExMgoIBBD4pOExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1217....$ASU!VPSz."..'........
...x.%W.8.........ke.d..=S..."$D.v.Y..({.=.%."Ef.....|...{...u=....y.y
..|....c|...!...:V...P.....<.?...1.R....b.r)<o.h........t...5x_.
...c....O.O.....o<i .(W.}.6.. ...h...,s......~.G4f=....4d.......hgL
....\.$...........#......D...)..-9.h..>M.p.b..)V..#..`.sR.....O1...
.%..x...v.O..b....$.P....Z`....b3.<.Yq.$.I;...q......`..X;..|.=.>
;..............wV}f...!..H.s.i..NP...|..3nF-.(..Q.X.RO...X.\..........
..4.{..ij....ct......Z...b..w..e.m......A...i..v...8.........J.I.....Y
v ...<..]|...'].....0.\=.....R..C"g.l.{.1..a,."Ov..p#....9N.4CS..5.
.G*...J.dp....&...G\on...hk.QX....lRTz..Vu.v.5..j.h.T..gm...z.W....*3.
.#.~..`......5:..h.YFR...fB#_..N.?....c,....?.Se....fK.Q.Z.NY...rYQI5.
H.%......t.....T7...,,.toR<'...f3.a.CA..........g.%.1....c.d......0
,.%....y.....7b,.h:.....7.R.......x...|S..\..j......Q..x...b.6.~.k....
8...'.....gz_G.m.......'m#9.y....l9.Gv.n..=....}.L.AA.G.[.~....T....A.
_4...s...A.\..iG..^.....y.)\...-.w%-..{[H.".......=.?..o/.>.i......
[..HW>..i.b>.....7....qe...../...u.. .."a.h.......N..x....D..a.:
7n..E.....e....d...y.[Q.S.\...'..2..!...V<.%{..e~qj.w..BI.g$a-..J.'
...K...).qL...H .........K%.9.2'..$..P.7(.<_............T..~N.@j3..
...6.^oS\..y.?.BB......$......)..R_...4Mv.p.3.....P......9..A..sI.M...
&..=.ri...e..{.W...Z.-.......z.T7I.[.aE.;......=&..O........4.E_Z...^.
.n..{....g|N.8.J....O.2....g...o.Q.........A).q..>.o...........W|M.
J3.ri)u..1.@..W...y.fu........hu..Cs..c.;..{..Y... ."..e..j.R~T.M.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCCp-ExMgoIBBCCp-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..11e.....ASU!VPSz."
..(...........x...uQ......j........V...zU..a.'.EK........V}..........=
.\.L... .....&>PfdT..$....t....A.v2..I[a..Rv@...0..i........J...U..
...(.o..Qc.f.afX .....S.(......\..d!.2....!...'q...1..11..........I..S
...fM...L....$....gx.>._|...u.l...q..%..I.....h>......s/0.ASWSig
2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCOqeExMgoIBBCOqeExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..2e5.....ASU!VPSz."
..)...........x...uQ^.....j.[.......p.Um.1=~... ....;..Z.u..&.3,......
u.Ab.u5.Y_J00.....w.2H....lm......|.9.<.$..l....@...*.......|7.{0..
!....R..{@....!.[.?z....Po. 7J..G.....;.A..3z..o..r....G..:00.......9.
$.k%^S.d..\^.. .=HL!aA.....docg_'......s.M....K..Z?....%d..f.ba0..\...
\.$.1...k...t....... 1.2...VF...?.1....$..u.A`'#..YE{.kH...V.....Qh.2}
~..M ..E..Z.114...:....H...W...8x;qC..\.%.......,....L..|... 1..m.D..X
qi...;....>|^..u.'.....F._....j.c..c@..5..2#.:...-3...7C..CY.3...D.
..iL.,jU...L.g.&Y,t.......H.$..Da...R&..jF.ZF..* &..[&...&m.......P...
0.....p..x....t3#.N...!..$..G!^^.....p....H.....dX....K...1(U.01(.....
.. ...........P.........t.... ..ND>.8.,..p.....bb...ZAR.2....8.. K
. ...W..RJ..-..M#W..Y........ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCTq-ExMgoIBBCTq-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..174.....ASU!VPSz."
..*.......%...x....J.P.....fQ.JC]....`#!..V..REqS......D)T.5..J...IV..
......7..Y....s.9.l.....{NYk^.Z....M.t.TV.....5n.Jw.4.8..(.....v...M*.
..-lc.W.......t.a...o.r.Z..7_.......RD...<6.....T...a6.sh..1.Q/,.&^
..g.%Od.X...... .0...~../q.O..[l.srA......_ ..U..V-..z...5'...Q$..#...
....F.2..?.H *Er..[..\..YA\.R..'.A.%...<M..-I..D...H..H.'.>.$...
I...6.I...ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC5reExMgoIBBC5reExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..9c.....ASU!VPSz.".
. ...9...<...x...uQ6a``p.0..a... V...@..Q..CD.A.....%C.....C...@5..
P..a[...P.Z..>..5...$ .....-%..qC1"u..#.............Q...?$...(..B..
ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDBr-ExMgoIBBDBr-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..26ab....MASU!VPSz."..,...H&...
'..x.%..P.].......D...n...[R...A@Z.[%.S:..%%.%.....0w...w.........~N..
...7[7.....f..h.j.RE9Jr....._B..x....("...pgQ.I.......d.....7.)h.jp.*D
..>r ..5.......C..........F&.[....v.2(.9.[..x'...@.v?......kW..q.=.
o.~..s....@]....T........[......Z.(..k.e..<...=.......4{.`..B...Xf.
7.....Y)..=...s.1.r..:..T.}.....X'.......8..~3zZ......h..g"..).....8..
......2../....tya.p.\.O.>..}..FlC.....uqM,.@sp.<~...6.|...I...}.
..3..... ..oZ.se..N.K..fJ.......l.p4S0./6.MZ.Ai..~F2.S..q.=..^oQ..#.,.
.....o......I>..v..o.y..U..H..F...Uho..i.y..J.%.-...}Jg1...#..._.Br
-.`<.....%'L&C.ZZ.....e....U...%?..e4...<...*..s. 1tvr.l....0.k~
..JX.,..^..%{.9.....d.......w.>P.....$.1....p{0.&..%.D....`..G.>
.=..O{..z...&ou#.~..`.......Lc.F..Z.......\..\....p...,.g..v...c".....
.D.A.. ...<.l.........`.....`..%..0S.q.....b&Sk-!..V.......#_..#.0.
.u...X... .R...5.....O.9....V........c.kUlCB>.......6.........".pEH
....Ll..&..B...v....y..b..($4F...........G......2*{...R.y.bvY......t.@
..8...q....<3..>...y.N.B.....<.jMk...c4.|...er..4..#x8..t....
YP...........`.8..G.'..l3N./_...:I.2..9.....s..U..s."..v{fh...!c.,[...
.....ni...Q........&k.......! ...ueW.yH.:.....9.....p^..M..7....L....
......./.Z.....ou......6.v..Z..#.}......p....W.2.p....n....M.....j....
....O...6...m..?.....Nw|.y%Ek......CZ%k... 6b_.. .VX.?...W..s=....8O.4
.|....^_I...%M..;^..i.j.k...NVJ..s....:.Jc.........es.....Q..i....c.G.
......t.U......D..`.............y..TDx..*....qbM.....sU1;6...t...Y

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDMseExMgoIBBDMseExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..1d8.....ASU!VPSz."
..-...u.......x...uQ.dd`.p5......d6.Z.....Gg.7..Y...r3j6U``.-.....g. 1
.. ......J...{?....*.t.....]Cc)c... .?.=&..<.'.N...Qj)H.......<.
['..3..R..=...........?.jLO..V.g.je-c.:.9.R....U.....E...Y.~..H,...F.y
|B....N....s...L..?....Y...5.T{...L.bC......-.l...l.......<X....$.H
..I...B?.sX.JR r.K......T.T.......,.......y..T&..FF......I.F.B.mF..n0.
.3.`2...e*...8.A.Q.1!.E/%.$.11..A..Q.......V..t...Yqy$%...u.>..;...
.Z1....wI..I. 3............a~..:....F..o.y.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDds-ExMgoIBBDds-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..97.....ASU!VPSz.".
.....4...6...x...uQ.c``p.0.Vc..9 ..Z.@..Q............A`B.C=.?#...'!..N
...LF..5...".].Q.....!.j {.o...........h....D.T^P.....i6..!ASWSig2B..0
..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDiteExMgoIBBDiteExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..228.....ASU!VPSz."
../...........x...uQ......j.k....d6|^...m2?.g..<..A~ ..W%SJ...t.E-*
}..%H....k....6...X.q..h...F..f....|..^...$... HL.&.x.YI...=s......<
;l.32.01D.j4.......s..!j........... 1i.0..@.-.c(;sB.&H,...0.$.........
. ...'..B,..g.....r.Hlm....5.CR.m]!Q.W .......L..w.....(....5.p5d`.Y)}
ez.h%H.N.,.VF........<g...LR.c.....(.?........[O..f`0....x.VE.....w
..`fx._.4...6.....=....f...^....$.x...G.33,(.{..............a...t..I.
.-7..Z....L...u.i2H....KS6...@.....3.....a.... ~X.n.4. .S.=....t...Ms.
xL.....d.......5#.........o..j.Z..]6:...7TVt......ASWSig2B..0..

....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDgt-ExMgoIBBDgt-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..9e.....ASU!VPSz.".
.0...;...@...x...uQ.```p.0.6`... V.Z.@..Q.A..C..A....S.3...tf...e@.r..
Z.h..........."..5 ...j..%..M.V..$..2S.....m.)..?./...1...6Iy(.=x.ASWS
ig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDdueExMgoIBBDdueExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..186a....0ASU!VPSz."..1.......`
...x.%.eX.....!D.)9. . .....]".....n.;.$.....=tK.tw.;...p..af....^..^.
....I....`"..U..Z...a0.K....k.P%.;.B..&K.`.....2>.^...a.EA\2....%e.
.P...I...6......_...Z._... -i...a...L.n.o..)..S>.M.......b.'wi...:.
R..7I.#k.....~.*..Ka....JT`......9..L.V...!....!.....1.C...).P...5.m}.
.......M...k07...i..X....a.G.k...j...;..?.t.0aUK..R..%....,[Uk.>.Y.
....K...s,...X...p^?..A.....o.}db........>q5..N..D......h.A..-.N..Y
.O.Y.tc...W...a.).9j.b.6...p...f...0E.}Z...a..v:uu.d..R.Z*k.@.I.S.jT..
s...).Ac..,.!s..8c<.Z...V......[.WD....N........x..h......s........
.....A..D..n..i.!..iV....<...?...wN..Ia....G]56U(.`...s.....e.>,
Yg.?.~..1&.00....p.9....E.....A.. .k.... x..u..L.8w...F...rQ!.....(.*.
.9R.5..T.(.v8.S..........`.......I..e....S$..y.[....].R.e..Ms.t..M.E..
..W.......D>$...Bxr...1.z&.`....;ZP..0N..:..!.R....rEH3....h.Y..:a.
.....@....._i>.<3s.$Q..i.=O.B...9.p0.K...."x.ZV..z _'E.X....$.E.
........6J......V6.L......=.H..g.F.3.........:.\L.....:P....Ti./.C?...
..t'.&X....a.......&.O........LL...Tv.i..r......d{...}.b./&.....1.P...
..2.^....4`..o.)B..%.....e......../.J0*....L.n........\.U.....X..x].vx
..Xb7..xc/]...1<......\....0..4..o.L...Q.e#.'!..d.....`... ..r..G..
.$..Q..E...>..@_z;.=....I....-.=.}.]..Q..........h.5..s.fg.....$.Sn
E .R.w...dr...l......y....3K..V....Z.W`\...u......S...#^H.....q.......
...[. ^.m.0...........e.5.X..V}.....a...E..d.p..X=l..&4....R..C_......
...$.QV7A.....U......_..?....D.Y'...HD[.?....`.W.p.-.V"0%.....v...

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDzvOExMgoIBBDzvOExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..29f.....ASU!VPSz."
..2...<...p...x...uQ.`b`.p5..````d`hhH:.w,...Z..G.d.. .....n....*..
...f..%.*.R....;q.4...{ ....eA...%-.?....\m.&.....-E.vpt.G-.........s.
" C.2.#.... 1_ ..B C<Gd.Yu..H..my<.......2......}.-..u``...1A...
~.....c.....V../.o...........a.o.....z......W..d|/u..,...3...?.....;..
=_7...n.v..621...aX.T...{.^.]T...).....E. .....[....K..?|...$.%..{C!.C
......y.@b...~..egH.oL.....$........S~2..p..)H,.Sa_(............];%..5
..AC.<k.&.9 ....Q.@...L8....l.. . ...........v.X........v....l5....
..z..2..........Ab...?1L.e...!\..p:HL..:..k..2..]R..]........)V.2;..v.
.p\........K.I....Ab'.,.wuda.P~.-|.j}.R1..i1j..../6.....6|.uK.;.....a.
M&..M"..K#J....2.<6&....1p%t..XZASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDyvuExMgoIBBDyvuExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..78...vASU!VPSz."..
3...........x...uQ.f``p.0.e....*..[_...y....9jq.Y.B8....oB...lW..p<
.......]D.%.,o.m....x.eM.|o.kn.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD0wOExMgoIBBD0wOExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..ad.....ASU!VPSz.".
.4...J...L...x...uQva``p.0..a... 6.Z.@.....A...a... C..^IjE0cI.d.V.Da.
v..I.U.BJU.,.....$.w..dr@...Q......N..VV..M...*.n%...5......2....<.
..l_.%?..6o...ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD4wuExMgoIBBD4wuExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..221.....ASU!VPSz."
..5...........x...uQ......j.k....d6.f.p...?..C?.L..-....{"}0.....U..3[
N...o.....?.{..]..j;.fhO`..1..T.";.....<....Ab..X...00t.]b.|.......
.).2n...5.Zv.$...U........o:o....)E.(neb`P..yXTz.....>.....^-x..w.{
2H.Fj.qk..C.......[...6..4....R^.[~..H...|..;...>..V.......K.5U``..
...y...$...3.....cH.....6...'.[x..*.lXD..~...{<..~.......3...Z....s
0..h^..6E.... 1.U..]...\.W...\............$M..t{..p..<z..h....Z.\..
...n..0....[.(......{.<.X...T....~h..k.*..`........7...`c.4c..U.6.
..J...,..RHz....)...|.......J...".......S..."!. .?"uASWSig2B..0..t>....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCVxeExMgoIBBCVxeExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..a4.....ASU!VPSz.".
.6...A...C...x...uQ.f``p.0.6f..m ..Z.@..Q...Q.A.A..a..%..3...3...(....
.h..d....W1.).gI.g....j.zU.D....6]$.p@.V\..6*....O..:g... .....IU..pg.
..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCkx-ExMgoIBBCkx-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..10a2....!ASU!VPSz."..7...?...k
...x..Ww<.........(.s...2..#3..r...d${|....D![..T4.=...YBv.........
..............:1.XjK..L..Q....V.H.PY.....a...b.E=.b....J...U.o.4...X_.
......H....WG..).v..R..z2tz...n.^...G.)zo.n.[.....u.d-.7.mS.RWM.o.1..1
.}...)..klJ..)G.1..f}.(......q..sk..(._..*%g.|s...6.....h..<.G0....
^........s..>.4...Vs..r).....O.>1'...,.X..G....{1.fV.,m...~.t...
.....k:.....^...].Gh.%.o.....[.5I.......d..(...g...!.._. ..t.:...Fv.k*
..<....vHV.".........`..).......Z5S}...>.^....w.=.w..r...LM..i..
.sS.....p]....$.M....6.\N..|...)..u^.....X.S...|..&>Z...H.XrG..g..z
..............X.........?...1^^..t.5w;...yQ...{s....U.......I..vF`$.*.
q.q.V..zHM......K5q..L.....b.......Z......._'.$...f.w.L.c.%..R...Vy{6.
.....[. 9..}\..k%.:Cd^Q=..._-s.l.m..(Pd=6.Rj7...7..@h..s....t.....}e..
......G`T[Z\I.....Lu....o.p.......#}q.1..p...>...(..|b~..X.jH6....L
[7S..TX.7....Q..J.H........H..`..P......H..(.Z=..?..!R....f....H.`>
,V...~.@.iuL.f.i......P./.r%-:.........Z9.AF.O|..;./.......q....I.;.'.
'W....|.\ ..li..Lqm.=f.u..vAgn...U...N...?.....$.wK..g...>..T.....6
>?..f......_...rkVHj....j..[.WJ..?`..D..[.=.'f.#...hFh...b.^.x.@.9.
v.z..'.b.H...5m....Ca.8..t...\......9..t....{..i...Dc=....#7...J}...P9
o.0d.....a*4......DO%`...*...D.][....n5..cj.v..Jx,.9.... 6VX_..U.~.F.$
_>....%@O.?....t..T.....JT..=)...............\...D{.V..i....[a...R.
P.gG..:.(.3..'.................M{..e.._::.U4*F.........Zh.0C.Q;J0....&
gt;c.....T...O|gD.33.{.{.X<.6.?..cR.j^..~. .VO.,..`.......RU..Y

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDLyeExMgoIBBDLyeExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..c4.....ASU!VPSz.".
.8...a...e...x...uQ.e``.p5........7V.=.W``.34]...B.5.T........k..eFFU.
uF.].K&.D......!,zE)..L%.Q@VqQ4cr............;\'I...i..k.~.Jk...w .r.$
.PJ......|R..P..fx.V .(.B:..1.K.cKASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDJy-ExMgoIBBDJy-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..1ea.....ASU!VPSz."
..9...........x...uQ......j......d6.....8..........,....4m..P...!.u.Cn
....E..............@b!.Yd.....R...Q.m......17..Q.....oj..YF.R..K..C..8
.4...Nns.....n..j......a..5. .$.Cy.........^_;.l.........J...*6.....XZ
0A..........f...'..1<``.(..20J2.$V3ce1.qF....V2A[.n.]..m.y..^S.El_7
........z...c..eo.....d.-..p.....s.....@bRWr...p1.........$.....F[F...
.;..=....~........~.....Ab7?.8r.....Q.yl..t..S]6`\.]Pf;...(..........L
f..{R...g..n.I.f.P............S"y...tP..~)*$....".o.ASWSig2B..0..t>....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD5zeExMgoIBBD5zeExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..b1.....ASU!VPSz.".
.:...N...Q...x...uQ.d``p.0.vd..K ..Z.@..Q.A..x...ca..F.I.......l'1\..b
..0.l.....w...../....d......`-.>..M.....v..j.T..h.X...|TW....5.....
j.............u..XASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD6z-ExMgoIBBD6z-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1027.... ASU!VPSz."..;........
...x.%.w8........d...,.c.A...(........."...E...DFV..(#;.l.~.u....\..&g
t;...........7G.pC[J4...n4z...#1.M...^...h.....0.ND..v*....,v...T.a..B
|a..... j.F:..*J?Z.............2..Q.dU..i.........%..._.2.p...........
...1..S.^.~....'.b..J...I. U..T.Y.........?._.6$..e.3.......yL @_..)..
6Uq..n.....|.;T|v...S...8h2..=.J....."G.......!Hc....mq...............
W..i....-,,x.?...'...H...LM\.sg..e.....v....>..}...>6....zV.ANP.
...K..x...}...PF..E.Y(... ..fuc..~*..O........Un..A..[...n..0.\Z(:=I.P
.....7Xy;._.. ......qz .*.......>..)........MZ....I.5SR....n.0.....
...K..d.t..q14....)\.....%..!...o......S=...bn...D.....v............w.
.'..._.8.n..o...^b........smi..E@....3..G.,....P.v....H......Y........
.].......w.O@.Vr....0u..........c..S......xb....6.....o.0.9..2W...r..&
gt;!....^.t.Q..<...:..H...'7..|..?8;..,...ZaR.........QL_&.Q..&`.dD
..~...i).......A..i.6...V....=.o>3..P.<;...5.P.....-P]...;.^BDt.
..ID.5r.0..d...q-@....K.....7.1B.cv.?.I}P...3Y..I.2...Z......Uf.k...0.
b..fyc...".K.....>.XD..Z.5H6..-#O...5...LV.....#@r.K.c.......J."...
.z*.....n5..5..E.7.....h.<.u..E..C..e(.....p...-..sH.D.}.&KFL.f.kj.
E.M.zs...z..r.,........GR....Q,~.UL/ .c.B.#nF)1<...:.o.E.`....#....
d..*..3...E...*.LIC?5.........a.Z~....,..l/.T8...N.tP.*.k{..oH_..Q1..0
..{.....,...s... ...o^9X$....?..h[X.,$U|.z....".]....i. h..c.iq...5H.L
$......gV..Z.h..k.....L9.2;N....#,`pk.`...v..\.>....%..]I,.J....\..
.YX..'u.9$"..$...;.i...o...z..xn.c0..;.....u.y.L&.t".k....hO...WHX

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCp0uExMgoIBBCp0uExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..157.....ASU!VPSz."
..<...........x...uQf`d`.p5..a`.1.......11...r.Z...H...){...3....K.
`..$6...i....g......1.h.v.......S_02._...eq.a.X....S...M........$...v.
A....K.R../.......7.02T0...\rW.$...9.a. C.....z......[.YU...eZcf*(....
j.0@...ks.{.......`..`a..`... s...L...9,......., ..R...k*..|.....q?Ky.
!h.....;...v.sBE..2.......I...|?.6..m.....w..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCx1OExMgoIBBCx1OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..d1.....ASU!VPSz.".
.=...n...o...x...uQNg``p.0..g..p 6.Z.@..Q.A.A..r....0#...$sfG.....J...
N.z.$00<.../......X....`:.!.T.....A..... C...K..C#.....p!.q._$.l...
x.mF).U%Y.D.*L6'f.N3."knR.w.J...n..... ...7.."....ASWSig2B..0..

....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCs1uExMgoIBBCs1uExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..b6.....ASU!VPSz.".
.>...S...U...x...uQ.e``p.0.ve..[ ....@...t2..FSa.S...}.q8...sF.....
E2&'Lf`.H.f|`Z..X..Z.........C.B-..Z.VXz.<........aO.O..Bw..H5.5.#|
.....5.DF.....)...B.:..7.#ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC02OExMgoIBBC02OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..159.....ASU!VPSz."
..?...........x...uQf`d`.p5..a`.1.4O.{y0..a.V..|.}i@9.;P.b..C.y.....|.
V...$...p.....@.X..7.. 1............G.....*=v2...0.>.gk..j.H.......
L.*..>......$g~se='...`...-..$..`NH.>#....xS..% ...u.......z.x..
...=Yk;...#..Cm{..6|..3.u...GF..y..V.z~..e.>..A..a........._]..\...
.;..2F.=M#1.N.Ks^q...jl.Q....<./.....}$.b...H.Z.;.0..;y.ASWSig2B..0
..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCy2uExMgoIBBCy2uExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..d0.....ASU!VPSz.".
.@...m...o...x...uQNg``p.0..g..p ....@..Q.A..a..0...a..>p;.]..c. *.
.gL.b.f.gbP.edQ.Rc.cb`.gfx...t ..%.! !..`3[#.@.#S ...X.B.....o...){..F
..bTN.O.F$....qM_gW..@O&Z...].F..?.D08#..m.R..9..ASWSig2B..0..
.
...



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC63OExMgoIBBC63OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1416....(ASU!VPSz."..A........
...x.%.w4...._o......ee.$#{f..3...W..."3## B.eG"....~.s~..{........x=
...r.........._U...>.. .m....lY..n...S...3.A.z. .x..MZ.......\."..-
...*9.08.............F.......2C..F.b.r..{G.v..p.</.&..(.v.....d6...
....z..v.......]o2.s...P.3.."...p.5......;.'..mo.5.f...a3S..\_.N._`;8.
...{g....iY....67B....>s....a...G<.e..v.....~.~...oQ}..E-...$.$
..?....c.........'u`'..TL.]... }....l_..V...}.9.............Q...p..L-.
.........:...B.......C.a......0..,)..F..@......v./.Q..o.8.C..<..)wI
."?.;.-n.......(.......((..5.c.<(K.v.a.?....@H;..)....|..Kwx..M...B
f{.O1.4L..b.^..O....k%...&d.X.o1.............[.....\..Y.b......D].W...
...b.5..X.N2...]e>.0.Z.(.y;.R.#.....x..m..T..5.Vp.o.9........sX....
.E.O..&f......g.S..L.........-...|.....`..1.v-t..Jr...Te....n,&..R.<
;..y..I.9..DO[G..i...e.:.9..-.J.t.....4k..p..P..j..A@..Q....Ljk...<
..&...CE...........!...].2.....G....(......v.....N&)...6..`..."#.1..&g
t;....,N.....j(.YM.@.N...t1]..3.......E...<'D.M_In... c.Y..|smR.!.I
.._..~).. ...-...E....q.s......f.@\..4....1.8..? ....5....)....m..&.2.
/...@...s.`..O.j..2.....'U.... .>....m.J.....{}...:...\?.k.....W...
.j(0Hu\>.}(...."._...'~.Z!..q9&.,....o..z...-.. ....zW....M.%F$=. .
..t....h...k..tI..X.B...Q"....d.....%7.?.?.{n.xc..a.......6..'d.....('
..~.GH............a..8.V.W.oFt"J.....Q..v.&_E;....C.g..C....U..c.k...*
....x..[.x.......8F]....*r..X]-...1..;. .]).......'...7<....?."..x.
.........._.6..|,.U..&..g.@..c...f_.[U..3..3m.... &.....0( .r..F..

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC33uExMgoIBBC33uExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..14b.....ASU!VPSz."
..B...........x...uQ......j.k......f.=[b.....}......Ab.......g(.......
1H..k.4.3|.Yo._>.[..4C..jF...g.....D.)...... tu.1..[b..l.Ey6H.G....
...o..i'S..@b..x....z."=..&.$va.P..Bf.J...S..5...|:......~.$..........
......\..(32j2.114Y2.01<.epeHcb`ida.*..;@.."X8.ST3....C.a.........'
i..J6..@.:....>....3...P...M9.V9~..BASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDJ4OExMgoIBBDJ4OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..ac.....ASU!VPSz.".
.C...I...J...x...uQvb``p.0..b..# 6...@..Q.A~..y..JL'..&3,...f< b..2
.B.Eh.g%.@.C=..#...(.s.^J.;;..Y.P:....E..u........Gb.[f.I.'~.^:.w....(
.......U..L.7ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDV4uExMgoIBBDV4uExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..e0.....ASU!VPSz.".
.D...}.......x...uQ.g``p.0..g..t v...@..Q~........D..AOM..I.lZB.lv...,
...78;L.c/. ..S:n2..R.0..f<...j.*.6.>3...!....'.7.......}C..T.L.
....R...^........,...........)....E(..........f....Jj.K.G.....a~/.N.AS
WSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDh5OExMgoIBBDh5OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..bb.....ASU!VPSz.".
.E...X...Z...x...uQ.b``p.0..b..' V...@..Q.Q...A......)G6.!.!.E..!..A.J
.A.A.........!s...L..;.05.0.M..U.'..p..6gq>..j..L.....,.h#.<AMr(
....@.&.......<|...d.d..qU..VGASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDl5uExMgoIBBDl5uExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..1f0.....ASU!VPSz."
..F...........x...uQ......j. ....d6.T...M.gH....~ ..(...*7E..q..F..'..
;..^..c..]|.......T.... ...B ..30..;S.=.._.XN.G#.0... .4.4......$.1.20
X.[...4...n7..s............ ......G..tyEjM.....5l..2U``...hV.... 1..j.
.X... .g...?......Oh(#....=?.=......}2.`f..$`... %.X..o....!n._.....].
L... ......<Pfd.gf(`tb...a.eHd...ed.ch`hfd...cf`..g.addRg0bb.`.. `.
.......`^....`9.R...z.C..... .....`......Lq..~....B3.b..02...l..2....p
A..rd..TS..U.x....h.$...G.C..4QPU.#;\..iW.iw..c`L...B.x.p.ASWSig2B..0.
.
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDv6OExMgoIBBDv6OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com



22... ......2.......1... .....)(.....)..128b....%ASU!VPSz."..G...(...a
...x...w<......m..YY..=..=.W....Q2C..J.J........!.cf....w...?......
.:.y...\..*..T...".k..[....-.......ZV..,..J....w.Q../C...bD..jnGJW|...
S0z......#......g`...n&....x..K..J.1$...#..K........$... `.K. ..b}&.=\
.vy.M.UJ...0.8=...su..GZ-.1.m..'r...J..,)....oy.9`wQ...y...kV..pp.Lt..
.....l..`..8.....3.....?b,g#.By.E..z|/1..{D....S....u...D.B.t..S..j9{.
...P~rv.7..}.AE..h).$...:.lE....v.X.j...K.C.^fc.....7....>..|.ct...
....7....;...rO..>.x.._mHu.r.n-......&\.[..d...y..?...p.!..h./...V
.W...FA...]..K....d.8.x./G..wS.....R}z}J.....OuI;....Q`.\@....e}.m.8@.
.h..............&O=...N...5.G.H......z...V.....5.^..b#.T._.f.y]L.j^..9
3.V...,........F?B...rF.........*.#:B.......~?..;.{.X.. .....<B.n..
.h..7.Q$..{L.P{.q..(E..R4\...x..Zq._...i..pj..k....... .........@rw...
|a.c.....A..I;.i.........E..?.F.......a.%.q..N%..3{.4...Cw.zv.Y<"~w
....q..Q..W[...H...4...qJ"QA...6.......[w0....?.W..1....SO...&..U|..5b
..-.J.... ..\.7..n...vN...i7.r.2x..xG<.4......?..X...E._.......%...
..w..d......L .Q..X.G,emW5#..B.v4...^.4.Z..@.4C..%..xzV..l...O..?....R
...d%\.Z&.....,........ ...=Y>$....}.Iu.#.Z...8.\.|..]o..."-.....r.
m).2...B.M..\.w...9.......^E.6....4...0.S..5=.Z.iRt......(.@<J.?".l
.`...f.X=.r...........?..>.)o...$...S\...z...k....#..o.....ta..$.5^
@.J.Q.a.Q.y.....'x...%.....4....JY&EV...[.'Tm....|*............{.:.."]
h.......6..T.Z....;..._.....Q.m.".[..F1%...........w.........U..KH.#oa
e.J.3...K..C ...T..pZD....L.'Oh....9...V....d.....C.=...DUo..4..._

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCK6-ExMgoIBBCK6-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..9d.....ASU!VPSz.".
.H...:...>...x...uQ6c``p.0..c..5 V.:.@...............!.!.!.$P..R...
.....)..2.X......2.)...(."..b.`.'.W.l.dYK.=!r.....\.....t.T}..z..?..AS
WSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDQ7eExMgoIBBDQ7eExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..138.....ASU!VPSz."
..I...........x...uQ......`.}.H..qih..> -.u..2#...=.3...7./.....ZF.
FF..Fn.*e....I.].B.?.....&3D...3N.N..p.8A.Q...(^.(`X..`6...L...a..Y...
.....:...O.... ....T......eq..u.Nf.`5.f.c5....d"......v2C...0c....$Mg.
..LQ,zE.9.L...,.@.......%D....:._..X......[F....."..\LfW._.........s.&
.G....j.B@. ..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDl7-ExMgoIBBDl7-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..ca.....ASU!VPSz.".
.J...g...l...x...uQNa``p.0..a... 6.:.@..Q..d........$W...%2N..y......(
00$.....$.3.$.11..1.T.3.P`...`.d.e0cb..IT............s.9.;..>......
}....wAaN..4..'.S...tb.8c..!..S..r........tASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDl8eExMgoIBBDl8eExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..200.....ASU!VPSz."
..K...........x...uQ^.....j......d6t..|<.........o.. ...z.l_..r....
].......Y..d~.,.....l. 1..[/...g..2...... ......*00...'...i;.PL...umfL
.V3T*..r*.[w...a....,..B.k.%.!..b7.fpa`(....nQ.#............W..~`...}.
..`.cgX.......7H.P....c.......G.|...E.n>Z....../...'........Y...{..
..?.$.2m.Tw.V..._.0..?..u..I.*....z...23"Ab....dmg`...zv..i.H......[Y.
.z;....B.X.m....,....?}*ck@b.O..^....~g....}. 1.OiK.t..|......X.... ..
......./.}.{.S.l.......,i....U..X..s...[-....5...|(}..*........;.kZ}..
..pl.Z.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDj8-ExMgoIBBDj8-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..fbd.....ASU!VPSz."..L...Z.....
..x.%Ww8Vo.....<...=v..["J.. ;d6...[..Q6..BFd..l.2..Y........:....3
..."...@O...........`.`g.?<..>>t.I............!.e{.u.....$...
.J...x... .\jW...D..0......i.$.G.A./......^'v..........7..X....&Z.....
.w.....1.D=x.\......M?....P7.....l;...H...... .S.......rF.,.....e!...#
.}t..d..0....W..G.&..M..J..7...........m...@P..dF.u.F.[........&.5.. .
.$........\.;...;j..dx..L.=..*e.n..../.l..E.-...".y..D..a.{..w...mCX..
(.E....3......q.k.....RW...:$..M1d.....,D......e..0.g."p..L...........
...N.......wf.P.-tf~. Bj......r......>P.Rc'd....W.7.,..Y.qa.`D<
.............5...I..."....i2'.[....-..&.....^......4.C..d.......$.....
.2.P....}....#.w.3fo._T9.38..,...%$.........2....s.n....`x~4.B...c....
.............G.;.,..7..k.. .G.............v...,7c.\.a..I..k...-..o.6}2
ra.....f...S......0.l.Y....... .S.-z`[...:/?...J.......B....)i?.2!....
\..U.........s..m~..E.1D.R....^_.J4.T.z......:....ry,W.^y..;..DG.S.$.{
..8.._&..'Y..9..l.9.E.sY...8.;..~8.*:e'4.4....6&.v?...(.J....Z=M..jP.U
H&V.......\Y....H.=./HM.j....a"T..T<.[..Km5.91.{..2S.v.4..F..Z.l...
/.....1&.9...'D.=W....;.z.(u..U...98*=L.E`...(..E?..{H.~.....&...7..aC
.K.'q;..T..?;..R.......g.H&...v..j......4P.NP..p.^Iz_.....5..x.....C..
n:#...(.c.)i@...0...sW.......L.nr.E........gq..K<...m..i]..9...~MK:
.-..c[~...}.....7p\.<.^K...M..^.......}.........:.T;/.0Y.4.. .{#...
.c0..h.U.....;.RO./.y..IL...W...6.p.!...r....IG..i...W......n.(..JaPn.
...v...|....D.XK|..N#...::D}t?.8.A.i.......v}..."....!....i.......

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD99eExMgoIBBD99eExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..2c7.....ASU!VPSz."
..M...d.......x...uQneb`.p5.]........f.Y.j...0.....W..b..k..32dO4m}|..
:H.!Y..Q=~.....b*/.......i...pz......7Aby.3?3ndb....z.7..H...g.....B..
wM.f..$v.RH...F......32.....Jgm<.....^.@....N..F.;7H.].Z..P-.B...k.
.&.Wl....v.fV.[9..$..)=..7...m.r.W}h.......................;X.s0.;;.L
....H.u.t...L.............=...31....w....H.mi..q...].....H..W.v.......
]...iZ.....]6....x.76.I.. ...=.Xg.2......y$.$f0...TE..._CwFx4...ak....
...y.j...Y@b7w?{31..aF....n..Ab.....]...j.qu.;.M .... .330x..x.....$..
T....3C......V....^>(dy..`v....7.. ........2.n.x.....5.T;..VX..44..
.H.p.z...(. ?.F^0...A.z...k!..v....N.|t..6.:3mat.H.$ .(.S$...........h
..Dz^.yu..s....R.1...eQAA%X....4..a..o.k...........Jj.*.....L.....ASWS
ig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCS-OExMgoIBBCS-OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..17e.....ASU!VPSz."
..N.......0...x...uQ.`d`.p5..a``.2.j.M;...3ty..1P....5WI.9.......{..r.
...z.<....O3\..]...h.....w.......0..d.U'.$...(}.pM.d(:x..C";.$v^.!C
T..........m..I.......0.qyT.G.. .=%.........k.U.E....Mg....pw....%k.@b
/gl8.2OR..o'=..`.3.t..``8-.=.f.R.Hl.r9..........Zvd)H,jW6.Q3Y....<.
.5......[c...2uQ...............!. .4.......[\&.g..qI...#....}.........
...mD..C.5.C.g...ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDf_OExMgoIBBDf_OExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..e67.....ASU!VPSz."..O....... .
..x.%.w<.....ceE...}.9..Q.Gf8...{.#[...R.,.H.I.;3d..wf}.........u?.
.z^.....f*...I....j...x`...X.?..0Z...^.Vl.^..DA.......=![V.u.*...`....
...!......YR.g.......v.ci....pTz......a......j...LK..m...gnq.c..#..k..
.1.w..Q`b.F.)P.k.._"...[a. !..X.(..=.x..O..M....M......82.M&.R...|y...
1...@...$v;.......d...T.....Is...!0.....~..b........D.....R.R..@.8.Z.3
......*..J..8..CBw....4i.==^.b...5.R. .7......H:.....q....|...."^....&
lt;.\..^.....~.8.?..6..K.E......[....].2t.J.1.[H.~N.......6..=S.!v.?..
iY...V.....c..'~...=o.;...A....";pu.fdu.r..-.....F....Ao.....%.aM.....
.L|M..~Il.\...H..c....0?...s...q........G.... J........UK..WA.G.....?
..6c.,>....w.[.).ee.P4[..WJ..........:[_[.h.~.\$7.^}=...)..!z..'V.`
.[ .P.......~r.$Q...............L...=..>....~.W...}..!.C.>~...f&
gt;.....r..08.....(.......6...O.A.9 Kb.k9...@I.!.k...u...il3...vW..f..
Y........7c....t7.X.\......y_...f.....]...d...9.-......Y.Y..Rb..... ..
.M.&.!>.1.l*F1...|'[..>]}.F...#...A....8.%....r.....\J.^F....b&g
t;|....w.....j..zK.4.]..b.Z.cq..q.W.9~.R....0..x.5....f=.&.G.....W..N2
....|h.dr.....$.....L..].....*S..Qy.W..l.>}oU.zY....{(]........J../
h.........P..T.X.4_b...P..A/.kVW."z...Ta.4.j............!....-.u......
..{.....<Ir...5.....;..6^..9Lb5..cl..]....X.ij.0....Z3...qbR..(.S.Z
7..../\dQs.O5a..p..KJ.B.`....\..#>.p...-.....i>.\(.;..q\..EM.a&l
t;W....../........u...BV.3dR<)..b>u...#../u2.Jo2....Z.s.......1:
........@a...-.dqs,E..ov..`..)..ACJ.p...e........,.]O..Y.)...8'?k.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCx_-ExMgoIBBCx_-ExGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..a0.....ASU!VPSz.".
.P...=...@...x...uQ.```p.0.6`... V.:.@..Q..a. ..C.C,C...K.$...B..k..ZX
8....DT..)...{Vo.. ..%.#g......!..Ws(JR..r...a.;....b<..1=.&X./..Z.
.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCkg-IxMgoIBBCkg-IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..f8.....ASU!VPSz.".
.Q...........x...uQ.c``p.0.n..,@,&%(P.....<PfdTf....IKH..t.C..0....
$.%3!../....GiL.,....0..3..,gha......b /4..z2C...0.....KL,..UwY8N2..(,
.......7.a.m..T...\.:....7.....bK...*>.l]=.[B..t.Q.T.....g..)!.o_..
..[J.V..u...v.$k.._X.hASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCvheIxMgoIBBCvheIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..15a.....ASU!VPSz."
..R...........x...uQf`d`.p5..``.1.|.T...``HRc.......[.........?c'..e.A
b[...=........Av.*Hl....n....;..n).u...^.5w.\....N. ..Y..............P
....?2a7Hl].e.VI....Lo..]....(.....5....c.._...6O.\7....K.l.._a.H.y..#
k....3..?.....u<...u.'.o..;..5Y..d.......01.l......Y.8kri...4.....C
...I.G.../.....SK.Mc"...9?...P[......=.H....u..UASWSig2B..0..
..
..



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD-ieIxMgoIBBD-ieIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1041.... ASU!VPSz."..S........
...x..W.4........~d..2.Bv.x.F..=.dV..%#.......7.H6.BF(RH.....s.s...{..
...|>.^.MU....C...4....d.5...0.v]4. ..9).B,.q.../3..x9D1..Y3..3.1..
.................?.e..}..FG:...h. ...X.~...Zo...D%.3..G......y.S=(/...
.*l.R.0.........6.\.....zZ..P.L...A...{..L......r.....7fL....w...4..RW
..J....j.,.5oP....OG..SM...!O..x.C.J.............3..L>..w...z....p.
....@........?.T.b.............OO10..s..............9...|...........u.
....C.\..1...0. |3.......<^.M.<.......0fA.,s..P.....;...~M.....t
.{U,....U.G.16...,........U....Q.......b)`...s".R...{.[R..A....k.;.._.
.....<............U....|..=. E.....w..n...l.0/....W.B...;.._;......
%......k.....Snr.t......K.$d..o...... $.vAm.....l.f.$....s0.."@?&.b...
...6./..{.........:...J...N.Y).......-..@........... /]T.&.......?&..m
7...p..$3..$..K..7......d.......j.I.%*...|l..R......-..._.)j....$.o...
\_.>...wK.6Q....PM1[.!'.m.M.".......*.....l.E.|.B.v.:..@<I,.0..7
.f..G4....7..5A...U$.-..-e^....|.7.....).."r?9..4..kWv.i..5....o......
.c~.0.e.......cRcY.[[. v.].9T....y[.Q..g.Yu...X...|yr..`......i..=.(l.
...O.W..W.tn.j.:z$W..z3owD.......e........Kz.p...Y..!.B{.b...8...$.V..
"...... ...J.......g.l9n/o.m{o.^[.p.mS$...6.._!7..b.o.Q>...|;v.8...
..sL'.l...).o....._.s.7.....#.HS...;mtZ.......j../.$ W.t....nJs.;x;."1
:C.P.......]..8fGf.......uJp.....V...x....o...,..6..."?....)....zx4.&v
.lj.`'...kJ.:.......H..B....p.....a"..(.R...;3..7.:.....s...... %.-V.!
.._N.v..7.F.x.I..hc......Z2.......2..Nj)..Y/.. odM....vP...aB.....

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCYjOIxMgoIBBCYjOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..a3.....ASU!VPSz.".
.T...@...B...x...uQ.b``p.0.6b..- ....@.............!!....;...*...'..A
..'....A.....C..`...E.o...h..-...6..[..B.f.2SC#;......S:%.;....3..q.#u
>ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCojuIxMgoIBBCojuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..c6.....ASU!VPSz.".
.U...c...i...x...uQNd``p.0..d..@ V...@..Q.A.A..!...!...A..9".)...A`...
.v.<....2...9.k.. `..P.<....Y...K"..(.d1..PkA..^ 1DS....1vo.....
..... ..!R~(9.J-.q....E......P<:Br...=....ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCwkOIxMgoIBBCwkOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..d7.....ASU!VPSz.".
.V...t...z...x...uQ.b``p.0..b..$ V...@..Q..A........!.!.!...bQd`Hp....
Ofp`..f|.f0.a.....c....d..&saF..0.....p......l.......jX@...i....N..}.|
..c..A...nR..I<B.....a..!....}......N& ......\...d.6.ASWSig2B..0..<
/font>....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC8kuIxMgoIBBC8kuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..185.....ASU!VPSz."
..W..."...7...x...uQ.gd`.p5..a``.2.....|5....../....Abw}6...12L..\.b..
"HLx_...0.C......~..4C..j.#..s.cF..3.W........h..^a`Xs8...... .`}.....
..S.".6......R:....aE.\..W=.Ab...5L.`f..z'..... ..E..L......U.....$..a
V......qsNI..?t.0..g..w ....@..Q.A.A.A.......i.W.C4C.C,.z..d.EF.....j.
:....L.,.,@...X.........x...D.O. .z..`.....C.....pn.....o#.|d.m..U...n
.T."V.'...F^BD..pkASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDGlOIxMgoIBBDGlOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..ecc.....ASU!VPSz."..X...i.....
..x.%Ww8.o.......W.>vdf....HDV....>2.=".....e...JB...IV....}....
...z......y>.....O(=..-.a....Yt.t5.H.....~..[UD.(..S;.;...M.b..s...
fA..W....i.gg......B}~..8q...k..%...i3....OP..=R._3..6.S.u..4...F...~.
....76N..=........n.F.C.....[Y...!.}Z..:....//...t.....?..q.O.l.....1.
..K..i..;.4...gBg....N..T...*..~.D\j..<p.\..d.UEa...Pi`M.#f. .)..v.
.yB.1..^.;.d>.....2....xk.p.....0U..09.G.%......C{.-#?|.7..Y.....&g
t;...s.2^;U./..!.V...h.P....\..."..V.I..W.....5..3@.d&X`!....k.D8.M...
.*....fk?...>......y........@.{?...qS]..f...[.D..2..S.e...Nr6._....
...#...^...#..[.#....H.Z.(i@......&.Z..u{.[...1M;7d....d..U7I..].6....
...|.S.*1.e*..}.....e.'..C.V7..6H{E.]..I.....S.b.(..Qx..L..5.....,..E.
7...H.]..k....d...;7....!0.H...8...l.j.m}...tp'...`..Vp.e..Y.f........
.....@T...<..q....[.1.H...a....g..1.$....l...t;O?^.T..C...t.......'
...R..T.&..c.?._..].p.>..'F.r..w.v'...W.x..K.....n....F.=,.:W.6w.`.
?QF.h........e *ug....S!p~~T>h4..w2;..Xg.,'Gt....@....^ 2;.E?"0c./!
w.......HETL.=.<i..F.h..]Ns...>N.....^........b... ...4\5....j..
.7.......%[......^..yx....]l..a.Q.W.bc....7G...FkIY.y=...'.!...;W..|1.
..N..4......Z.<.S....j.G..H.6O.=[..ao......?...*.B...qu.V.g~0.g[M..
>.......(.4.u..........S"...#,.y....W.._..I,..qt]nb...tR.!...L.5...
. }.^..M....U .&r..(..%".... >..l.a.......J..m....j.:..............
...?.ld.......5$.\.c...Al...'._T s.-e....nw:y..V........Sx.B..N[De.MS.
.Gs..>....&U........9...F.-Xz..../......=g...N.B......r.....Ef?

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDQluIxMgoIBBDQluIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..e0.....ASU!VPSz.".
.Y...}.......x...uQ.a``p.0..a... 6...@..Q.A..n2...;a..Y...>d..3>
..bq``x....HV3..0rZU.Of..1.f..1af...........8.K....zO...1,zE)..L%.5..,
L@......5..l.sy..0....:.?> .j...|!..."...M..`=}.b......D.2]......%.
uASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDUmOIxMgoIBBDUmOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..30c.....ASU!VPSz."
..Z...........x.%.yH.a....7...S....V..........L..W..m.....if../I...k..
...I!..AD.......Bb]...W.......yx.....-.....$.aB....o...b..p...3..|Kn3Y
...,.4..&{.)Pr22".M.....9.P..Z..L..%.02..L...h.^.3@.z.........W.9S....
........q..$...!.:..#..(..GW.De..lW..F....1S7..l=de.``P]Q.....!..jb.q.
.A.R...Ed.|.,A.......-..L.K.|_..e..0y.@V$......:5>.......*........J
.L.A.'.@Y.;@..w..S.'..G....i0V...I...........'....yc22%1...A..3.-Z.9.l
..]......O.u..,d~m..|....^..]."...N......Np..`{_..YA(.<.....Q.Y7]^.
...........,MwH......R....7..a..?....\...?.....=.K.Eb`.Z\5.,b...^..wbR
....@.2.i4._..\..... 2o...8...D..^.#..#....`...'%..m.?f/..^..P...^7..n
.\.x..%n. .{...{..,...r......T"......D.@.9S..q)@...*...xH.cv`b........
.|V..x.W?;....b.8...z.bs...b..H..e_NT...A"..............y.A..5*9\ASWSi
g2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDSmuIxMgoIBBDSmuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..9f.....ASU!VPSz.".
.[...<...@...x...uQ.```p.0.6`... V...@........$.N'.NNW.=.iL.,5...,u
.., ..:/3..*...v.p..?.....X~"...^3.~..q|..TL..%Ox.....Xn..u8..E.....(.
ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDdnOIxMgoIBBDdnOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..ee.....ASU!VPSz.".
.\...........x...uQnc``p.0..c..2 v...@..Qi...&.2......&..#.%....NG..2F
.I..NB...X..Rs....#.".2'=..)......A@.J.....3...%.3..#G.PqqQ$cr.C,C.d.D
.0c.S........*...u1@....6.......p/......(.W...p...m...q....R......n...
.uH.kDASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDjnuIxMgoIBBDjnuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..481.....ASU!VPSz."
..]...........x.%.}4.W....}.w.4;bTU..X[....0.:}9..5.f>..H...#Ci...N
...........2.:-#....XiL.J...........;.}.s.}.@.a.J*........ .........7^
a.}....i'.V.`A{Aojaf.Nd.....O...{b.....d^.W......2.I5r..eoP....(......
.$..sN....=.U.....~a...R.......UO,.UX]Efn....j(Z.]s.sd.....t..X._.....
,x.`.?..%....7...X..9.2...d\.3.@...RK...t...........9.C.....M.)E.>q
.! .,...k.\..Av.s.V.........|d..2...RA...d.u...wI#?. 2i..! =...^..Bc.R
......Td.>.Q......`.#..@v.D..b/.tw.....i..B..v..'8D.:b...L..C.S.i..
\.2.12...........j.1kdA..).x7l..KZ.I%..3..F[(`....q.XEf.....e.f:8V...F
.<...<..O.<.^...........,7i...2.L!.@..0.2....." .0Q ......2.T
.,..Y#..C...ks........2>..fF.i.....].2d..V...;...._.%>:2. .m..r
G..,..G......1.).,C6t...L..w.;.....,.j.A...8l#<.o.C...(T~...|.=G...
YaM..Q.....J...S.4..........Q..;.=....<:,.......9Co..-...1*.g6...2A
..s....y.5/..Rd.]9..1.N%..[.s...*....84.g.6.N4.7[ys.H..XD5..... |..#$.
....*7KZ...(..p.@.F..Y.OE&......C0.1.`&/.Y....n:...]..-.p......\......
.5l...E?.2.@.3.002..........."\|.a.!X."&Z.nT9d..$5.....2.>.........
..`......pa<{f.a.j}..p`.S.....r.Ei.Xr..C...1..J......D/.. .:...k...
!.0.l<X......p..aI..0b...2..F...$...?...W.p...R.ASWSig2B..0..>....

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDmoOIxMgoIBBDmoOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..206b....@ASU!VPSz."..^.... ...
..x.%.uPU]....SJ$..[.EJ.;.C..K.n....n.A.S.E.....wg..?..s..k=..<s.4
$.#(....b...U...2...6......N...,.5w....a.R..a....7..V.KbB:y^........*.
.'...bD.=JH.!...V.M:..r~R.......;..~...6I.C$......!L.g9...d...~...=.$.
.. .& .V.]j.!-.YT..[6..P....~....{u..f..!AO..>...u.Y...y.E..?...Q6q
.#..a7......W...dg.M.........u.}R.~....."........*S.F..h;..w......D...
J....i.........h.... .dY.|;. ".G_....b.._ ..9.eT..e......X............
L.....)..XQY.."%^.....q ...o.....wM....F.NZ...t.=...I....S.:....QDU...
...xr.h....~.[..J.Nv......2;....7e..C.....U({.>.Z.?.......H..)m...P
..S..x>..m.....`.9..y.V.2..k7J..%G.n.......,X2i.*.)..q..T.i..N$....
.K......CNCyF.BF`..N......I8. C.>5|.!9.u]g$.......P;..w{...6Td^...
.Kz.}Q...7..................v..{<...m.]..A.._6.....o..%.... \....G.
...".x-.....a9..P..O.(...b..Q.$v.._w.-.8........i......8...0..........
..<!.'...N@i..f......9/..SI..,..8....Q...b..D..{.XI5~.W..J..v......
.).. .......<]..xW.h.t....V.9.p..~.._.^...5.u.......R.,...M.G.X.c5J
g=....}...1$..4.T..q...k..*...j,..e.'...>....^..k1.!"6..u.....'....
`..G../w.}V.(T.....^...O..Y.*..g...7n...e...V.v../..G.Cv.?U.PpMhm...@.
?.U..:..l.......-.........D'.. ...%R..>..o[..u.6}.|x.)..i{.S.zW..48
.Yd.Z$.tb...j....A.u.......f..k....}.H....|5...]#".s.2."..v.....w...U.
..=mI....m...kY...F.n.h2d..b.0."pap...h.... 5D..4QLzI..@....>.?c..Z
...JT.J......pYe..F....D.......X..f(...^Ktw..P.vm.Jr.q.....ILE.......$
rfR.^J...,.....c...1...O..B.2.....=......K'..jw<.....3Yt.......

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD9ouIxMgoIBBD9ouIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..30f.....ASU!VPSz."
.._...........x.%.},.q.....ww.m.*.<s.<tN.V.0... :.j...Di.."....N
.e...VG..5...9ZTSK.5[a..C...g....w..g..8r..4..1..a.( g..<....;3.={.
.-.]LJ<.'2..].qv.WF.Wo-78....^.^1}ZEL..z2......Ii...r...F.>x.li.
1Y..AA.kb..g..8`..>}.....Q.G!..@.0-r......M..L6..V$../.%Vj?....>
?._.k.q.....q....]6uS.@......n..F_.M..Wb...j....6....J.i...F.W2.b..y..
XMDLJ..n.....*4..}...a.. ...S.i..cb.<...t...jy.D,(.%........b...9.y
K..:.x....;..U....S.u...g.G........8.k...]..3..Fs.@[...lA%$&S..(<.h
C.m...m.u6..8Y@....~.........\@u{.<XjQL...{5.....(....51U..y.......
.....H.8y..i..~I..X.V.W...."_....O.Y.Lt...8...$....X.L..S.....\=8.x...
^.....RE.D50D...@C./.......S&..Y.....g.EkOQVp...b.F...D&....cy....-.!.
.....A4rB..@@...h..)..9.....0...>....R..d]..I.J...:.;.....8xlo...#k
.r.... ..'.@SL.WZ.....".PASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCopeIxMgoIBBCopeIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..111.....ASU!VPSz."
..`...........x...uQ......j.k.............gx ..j.... ..r.=.....vf.D...
........d~...wK..X..fh.@.....,.....wS...I.$6.....%..SM_jM\....KZ.d.Z..
pb.da...'@b....Z......N.....$v..N.Q.!...........N.f...6....x.nP1....@.
.Y.hg..Jp<bs...z.x.${O..IC.)..fg..5@F..:..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCGquIxMgoIBBCGquIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..10b6....!ASU!VPSz."..a...S...r
...x.%.w<......G"%..dgg.d.l..........."."#|Jfe....EvFF8............
~]..y........9.......WM.d.Y.D..P.n./r..r>.(...[..)..........q`*:.."
...Fr.. ._............;.F..R..Z.....o.;.qs....f.$...E.G.......#....e\D
..MFY.....Z>p..z....G<..d/....?.zl.le.>..k.&.m ...b.B.#A.....
D_X.`.T............y5.b.'.../......#=m..D..3.......U...Tp^".|..C....F5
..>vYc.i...$..Z.G[y.3S..!..^n..$..#.(V..(b3(;.=....#..`[kY[..D...B.
.l.m._.Q......Q.y..i....r.w?3.y..Yao..y..)n.0.....k._.....qy....[.4...
<A=...2D...18..i.-......Q..-..J9.........{n....3<...L`..r.......
.y......O...r..7.......^..g.n..a&I#...z...~.4.h_U.&.s?.mvQ.X. .....6'c
{g.@......& ...'.@R...G,...-.[...)t<..... ..>*...h.....gs6......
.=....4....m|a.d.......D .E..E..er..a..2...~V.(..\d.#k...........`..n.
...)..u-....e....L..{...=.l..e....jF...%$:.x...W..2.....y.z..`U.'L:.`K
.Q.y>....U...".......{>.J,..........zFr....q..H..W..oxQ]........
y....;G0M}.....k}..W......S......M.;.1..`3%.......XkR..yRz{..L.grQ.@'.
.......c..M.b$.[_.....&.`.E.wJu..x...]..gav_..8q....g_.C...........g.D
...eB...........j.A...o.....U...j.K....x....@>.....p.O......![)...@
.NX1Y...MA..).M....[`.[_.Lh.*[b.lR3.....O..Q..J..Q...R..E.N@.C...w^.p.
W...CAx..r..... %...c5..g.7...>..ZW..}Z}<.0.G...JIq.D..,...h...
fp..n^g."..Y.9..8..`.BV.tK...}...U.....S.[.X...........}4.0..d$.....A.
......Nn..^.gQF........i...L.........{^..).].Z.p.e.x`wzo..${..$.Y...`.
...A.....Luoh...t.......tD.."~.....T/.$.u....E..U.....Uu3...c..u.4

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC0ruIxMgoIBBC0ruIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..124.....ASU!VPSz."
..b...........x...uQ>.....j.k......Zj.....g.....S..H.X....c~..G...c
.'.....<..6....v.|...c@3. .f.H.6nm`b0.~.S...k....W%Z.10..n...p..H.m
o..Vg.....G.w.....]Z{.........%.'.@bso.k..ecx....U.y.$....oG..2.b..._.
0..k..".'.............b..Z.J..21.x.1..u.Y....ux.......f.q8]2,......ASW
Sig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDFsOIxMgoIBBDFsOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..9d.....ASU!VPSz.".
.c...:...=...x...uQ6e``p.0..e..U V.z.@..Q...*.......>3..f;f..,..,.,
L@E.[.s....*L.8..6@K.'X......d...u1...J....zyf......Z\.;.wI...rh.:..AS
WSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDUsuIxMgoIBBDUsuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..464.....ASU!VPSz."
..d.......{...x.5..0.w....M....M..q....t.hY.T.W.5=..."F7.....&VJ.u.:..
U.O...Tv3.L.p4ti...oM..zg.E.'...~w....>..y.oT...\.@,.o........?S.J@
.:-....u..>...J......Qh...hp.LW.....g3.F.......s.} ?3.....d.5.W.P..
r.XN.@.9..d&...@.....Gh....u=...J....%.mJY[{ ....kq....h[T.^...|....:R
/D....Th.....:(.:.60}46.G..*#.i..I.=.../z........2'....b.*{3 ..-dM....
....8..{k....U2.pX.v...N...B...=.l.F..5..=.N...sc....pS/R).<Ej..z..
..w.....Xo'.t{.S4.@R)`.T..>?iM..... ...p...........s..8...]k..)6..L
..m.2... {7...m_d.R..8[..>].....].F...z.hg..c..]...|..&.#.....@ .mM
..Y.)..r....M.08....._Tq..O..%.O..........w.Fr..z.$.D...U.<C...|H..
..v._.6.r.~..e....!........P...7/.6u.5J.hc....l....v.\.i.7.=..&(..!Li.
,D.W.YP.....}.q...D./.(&...n;z_gea.k....2.......:...n.6.l&g^.m./A.o./.
l..7O.......u....Y.N%.c..........y_...u7.k.y...:.j/i.>.r?Z......ik.
.8......:...`.?.Ks3t..B...[J...D.3.R"......<.r...._[../sK..=..o....
.qh..1.eL6....kCG#Z.B...`.}V........5.......-=.Om.....^..X......s'.o.e
.k.q.......ef..&... K=.I...4."we.-.....B....X..._..N......."<......
:.$L..t.`)......7..\.5v.5..T......j."...8..m{I..n....({...P.^..Ff.%...
..Qx..C..0ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCKteIxMgoIBBCKteIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..a0.....ASU!VPSz.".
.e...=...@...x...uQ.```p.0.6`... V.z.@..Q.A.A.A..`2....a.W,......L.Lu,
.@u.8...b...g....A....T.u...s......c;T..q..y....4 ......t....F.t.a..AS
WSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC6t-IxMgoIBBC6t-IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..107c.... ASU!VPSz."..f.......E
...x...w ......HVf..-{g.=..!..dg..............2/.Y..EYY........y..y..y
.[......f...{)...m.....x-Z.n.Q(kk.,.W....t.....%...|.b.D.n./z......y..
...6......~.Y.h.......E..!..s....%..1]y.}.. ..`fyd.@y6.pw...iuNzk.^.D.
6Y..A...991#wS...[....j.....U.....~$.z.U#.A..........Z....z0.....W7c].
..w....._#:.n....N..]...b.|..g.(tm.O).s...*.[ .i.bT....pR..z^R..RU...X
r........Q2...M....o.W3..f{D.;.C...t...^}-....._.\n3...9fdV5bo.rl....]
.&..u..3.q....&eS._$;.K.2jf.>.w.'...<.h..f.@-.....q1.=...v.[*d.}
._v;.v.=.C.... rt.w.<..$.VE.Fk`0.U..._.....#..]...V.wp.[......;. .T
..OB.`(.{............Y...* ...Q.....o...$y...X5.P.......%z.. ...M....q
p......:...e.....i....D....a.Uo.7....C-........h.g......[&=MM.F3.#.~..
.......-.yC.t....0.. .>..?.D...,....~.;.D.9...t..............u<.
BW....H}.:.F"E..~$...%.TU.......1l..E.M. .c.OL..HCo......h.J..@.q...@$
l.......kF.Z......H...,.Hl}08...X".:..@..!VN.....R....N......Z..M.J~K.
!0..\.h{.@wJ......d...`.W2.....e.O..zX.;3.G.n....ZW!.....3.U..........
...0...@r)W...J...|.... .l.C.~....ui........y..$o,..AuR{...... ....v..
U.sc...........b7z.a..(.h)}....iU.H.Y......S.J]..`V....@l.....4*....-.
..........j...X....tZ_..BA.A.(W.z...Q.Tz..g..mYF.\wO..[.{....[.Ph.X`..
..n.Kd.D.......sY........9.-.....h.i.D..]..9.:.R..]l.{.....J..........
.0s.`_.Ce....0.&\.?......'...p:]......S...N.........o.r...O.w...... I-
....c..5#.wv...._....rP.9J#..c....E....].O._..z_.....k..R_....h.......
..p.3. @..g.....$L.8..=XG.iO..^.6b.........*...zVX.w.P8.......r.Y.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDcueIxMgoIBBDcueIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com



22... ......2.......1... .....)(.....)..b5e.....ASU!VPSz."..g.........
..x.5..4Tm......;.-$K.$i..&.d4&E.j^.B.h......y.....I%*......U...-..VJ.
,...>O.s.s....Y..............3.... l;S.........F.....V..3].@uS...,.
6}.o..".....\j.E.v..OT[(@.@..I...jw.........x...M....g.!.#^v......y...
.Jd..6{...7.D.O../d,Z.G....[.{{..oD..........F4......$.W...A.D.e......
C.../..{.RI.,Y.;..!.....A|.7...V.'O..8.p.!We.2W....i.er.q.....U.s.....
r..Z..{......d.R.u..1...B.@...4V...9.a.....4......N..n........1q.`.I..
.F..2#..U..W..@.:}.-27-F#...v<sL..=....m1.L.7z.a......k..B..0...z..
.jd.t.....@ .....]id...Q.....^....Sd...N.....?k.,...-7....J...%n].Y...
......:..:Q#...gi{.I........~...............0.. .2.o...<U..u8. ^{S.
O..4x..`........5.,)....J.v.x....v.?......4{..`.j..,]...?J.C..B&.~|...
3iZ..Xg5d".Foa<.R....v...$.m'`&.......iz.ll..D:t.^.u....!d.m....2`.
.....Y.l..>W..............;'...0q..PAM.......4.E..6..|y..... ......
.....ou.o.L........y..p|.......:-zc.{.o.7.B>...O........#...w....;.
.md.N.......>...h7..}G...0.mO...?.p.~.._...E.>si..zd..gSQ.|.....
=Fx..]3...I...c..&.8Mp.ZK...h^w........o.....1S.}&.F^.V..(.Zq.T...Xrq{
....9L8h............qV..0iy.}.Ld...}UZt.!~..\......e.0....X..F.d..3.X@
..I. .M..M..xM..(]).,0j..d.=....t`.*.z.l....O....X... ..:.,.@.Af....E.
.....1.(;."....7.?o..YD@.6....^.\.1..G6.?..|B....<...k........6....
^K...~.......fK.......sE.....GYF....#[......8.0W9lCU..-..jd...T..g~.Nd
...[.O.p....g.=..).....&....?.....&O.Xq..0.k..dU...'C.3M.....$.....L&g
t;#.N.P...c...K.......b-...l..l.o.#...l..=/.......DG56...(.>.Q.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCfvOIxMgoIBBCfvOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..102.....ASU!VPSz."
..h...........x...uQ......`.....Q@.....2#......J.j.A,.......L.L.....-.
<.U....p..3zq.3.1$.x......X...........2.'722.Ldj........7..`dfbea.f
................I*..r0na..x.. ......?lp..~9L...5...}....N......F..35.Z
....P.Q........1.p......0W....ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDfvuIxMgoIBBDfvuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..2db.....ASU!VPSz."
..i...x.......x.%.kH.a......k...Y)I.4s..&j3f...$......l.*.Li.hy......T
.Z^.f"..d`.F....l.RK..........~.....S...p.d.....'..X.D.1.........0Z...
..L..}.E...j4.F...b..J..)_.g.^o.\.k........ch..I..P..].B..-6.5..j....~
...K..Z...... ..U..LM'.^P9Kg...>.mvu1..HT.Ow.(-[.*....6.....:.).f.N
.*Bk.7&...4..~J".G -TT....].X$..B.U.nF....<<c..R..%U-....?...>
;~.Zfm..f;...vs......#.5.D....TgO6.u.3O...t.../.X./?.S^...P..'-Jz>.
e.H0....g0m...Y......*.Z9..FM._.\..6...}.H....T..%..@V.f:B.<....uQ'
..N...&.3.bLC. ....!.H..4...Ox.&.......h.......Z. ...........@..;.;/..
-.lj....r......T..;.......0g. $..^.u.e.yD...8.!.>9..f.A0..#.*.@.(xD
.....1*..1....).z..|..q...f\".9.&b...r8.E....w..ci....rl...i.~^......v
W..:.8.q......%.W.....x6._...EhASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCGweIxMgoIBBCGweIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..9c.....ASU!VPSz.".
.j...9...>...x...uQ6c``p.0..c..5 V...@..Q.A....A...].*'.0V..2W3.4..
T..[s.. .... I.......N.5...I..........}6.y.hk..........-....v.emf..ASW
Sig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDpw-IxMgoIBBDpw-IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..ff.....ASU!VPSz.".
.k...........x...uQ......j. ..........X...>.NV.~.`.k..v...$........
.r.VL......Xl...X...&..br.....8.......N.\...T.b.b........^q.13..;2;.a.
b. J..f.ONbq``p.`.b....Q..Ho....b.%.A ......@....w..=.........fW...Q..
#..{..p..k:`..P.....&L..7ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD4xeIxMgoIBBD4xeIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..e5d.....ASU!VPSz."..l.........
..x.%Ww<.o.?..........YBJ.]{$.w...{$..(.y....Jf......!!......^.....
s...>.G...7...HEL`....F/1..E.N."p...G[.".e..o.>.m...;&._Z.@>m
..y.C...!;..E.@u$..o.-'g..Y*.......<j...UiLY.2..3L6@8%v.'.C.#/b.@._
..ur...S...rN].%. ss.H.............^..&..E..w.........x....x........0.
.B.$rC.:...v[...n....mK.....@}&....s$xq..Qh..m.4".$ .0x..L....IW......
......i..hg.D.0.$......n.......>.. ...>Ez.m...5..=-v. .xA.....7.
.Ct.s..b.f.]3..L... @...s.i.~.M.....E.[S.*.._.0..dd.b...)..[|k..../...
17>.P...4.~..dJx..B....#.....u.......}..........5.N..|{.".K..8S(.t.
Gq..M...?/."..]....k:IA.....x.........."kvP..Tkj.z....5.}.......>lW
j...z...TZ.j"..=..[......:....r..SAh...N5..........'..[v.x.........e.!
.77$.W..-g..%...iX.\M.{....]l.N..\/.......z.........}&.e.\....KIFI|..O
0w..u.t.1.X|AuR....:.g_.w....y.p....w......Z:/.?=k.....1..8..{.....FY.
{V.d...S.l0".....[.=R..I..)Z19....d'...y*...=.$.s..!....<.........W
^y%...[.O..w,V......D`..s.@............$_.........]]`t.{.zJ.......NK..
&...|I..C..P.7.y..Z.........H.6....[>l`Am7...t.d.qV..H..u....k..&..
..5*<.>...j..."....K.lx_t )G.)..5._.@...E.:-.Wt.!!R.g.2z.....@.2
..S.) ..JW...^.8.W5Wk...hVf.P.....r./x.D6!...#.@8E...3].AmOU.....s..=l
....$J.)B...X.S......(.[........%.Z....})M..*.nP...7..V.T.......3..x&_
..`.....B.t..r.M..i.F.=...y..;.Id|....../z..W.....r.#$f...............
Ti]...Z?.......T.....b.|..\..L..[.$?...q.:~....&.v.We.?2aN.......x.t.O
.H....k.....K.i&......;....>!=Vn...=..]....X..`z.e.nj]C..r..u..

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC-yOIxMgoIBBC-yOIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..8a.....ASU!VPSz.".
.m...'...$...x...uQ.a``.p5............YSY.^.J........7G.5$...~..z...{.
I....".....y..h.....-..v.?..Sq.....<.u..h.m..yASWSig2B..0..
.
...



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDayuIxMgoIBBDayuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..78...vASU!VPSz."..
n...........x...uQ.f``p.0.e.... .....".*I.<2.D.J.........sV...q{..B
m.....$...;.P.K,.%O.6..5l...._.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC3zuIxMgoIBBC3zuIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..156b....*ASU!VPSz."..o........
...x.-.w W_...gfo.!.";....B.J..?.....e|.HJ..23..d.D..(RB......s.=.....
.....x.9....)...A..$P.x.......:q.}P......y..%@...$.9...X....@...2.y.%.
...{...BPI.4...(2<...............l..7.......W..-...N.)?. [...B..F._
N....s:...s.!.v.6...i..IV.c#Gc.T<....r.j_.5$....4*Anc.......6X2...X
....A.y.^9.c...[...7.u..U.D....J.o..og.*%.......M...{Ny...W.UL1..6m.#.
...bD.l.1......c.......3m~T.p...b^.ET.....i.*.F..3..T.I...9..m)gHZ....
$z....AF{A.2.D.)g...B....[^...=M'.J..z..x.l,................p.S..bP...
...:n...K.{U.<R...*....=.>.....G..t@r........D..2VQ.tc..... .Rf.
..CR.s..&M.....T..H>....m.(.n....l... I..<....'.MC.....q.aYG7@m.
.6-#./......}%.-s..4GB..m........p..yG...*K.....4.mi...R....>.....F
.....0.d0..P4..5.LP2.B..I....>.....L?...yC...O.<n.<.?.v..#Z.(
.P...?..R...p.o......>....()../....|.....@..RH.=.m... .D}-.i/...u.%
$..m..A. ...}.T..k..s.!.9j.."$.'.Ji.P.>r.Z..|13...:...6...%..rg....
{..A..q..l...Rq....... .....$v.P..)....U..(.;.........xU.f. ...".$ ...
c....t..A)..bI.$zP)xST\s...r...KhK.....~...Y..* ..e._...:i>.;$<~
..;o.)?../.....<*.S.]b.o.....w...u..T.o.fCe._.Z.N.Q..,...4;6.9....}
N...{s.......p...K.D63w!.3pV.f..>..I.^......1y...M.".f../..J. .../.
.XR..i...}|..W.X;d.g...9.2. .q...s1;lmXX_._.. 6.5.. ..N....F....G.#...
S4#.y....X.$H.V....T.>..8..6.......M.M....i.;.M.P.......>#H.k..`
A...aA...WQ,h,V.o.S81hP..o5.h...d..oG,..d......;.kf..z.....r..........
..Z@)...H...Z...;Hr.(.vYm...,.Q..Y....6.M.~..r&%....J9 ...I~.V"PIi

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCK0-IxMgoIBBCK0-IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1e3c....<ASU!VPSz."..p.....
...!..x.5.w<.....cd....&.1...Q*.%.]...d...egddo2.e..Q.H..y......g.{
>w.s.cj.........`.).(.....9e...Q..j.......z(J!...2..Qb.,D.M.P..Q.v&
gt;Y.h...Y....6,N.X0.&....A.dB...N~..Y41P~.}.~D....( .....=..)%.q;...K
K?y....tg.1..................>.....1H....PZ....18.. ...z..!.;.MM...
.....4..w.Z.........(...?K@ky.....V...Y$..^...2.W.'..CH.E.]........q..
K.{.A.E0..U..V_..H....oMO.@...n...S..K.;.......j.h&.t.Xd.... <-.s..
.#....[.1G..DWB.z......g/!.XO....Y..V....>....X.!. ...kq;...N.1.`..
..9D......I5.....I..2.....p...9LSq.P...2.Oh.... 5.......Og~.......R...
...d....L.c..X ..-s......3>..u..>.ul\.y...=...8..2..^BK..1..5...
.j.S.q.Y...2F..P.'........P..Q.ji..:.C..@.mxI.........z.....Z...h.N./
.sm.@.R....R.4.o.......iK..:$...WI$..!....:.Z.A".zlw..C..A.........YV%
9u..I.....].bS.A...#wH..>CRt.w..>..G. d..U...u.%:^..r)..|4......
$.yro..a.h.;.....]......q.*3$......1.H.}..W.....r....H ...A..P...P.QE.
q..W.R...(.....$2...8..C..-...N.. .[a;^8...$.W......!...'K..n.~T..)...
k..$..`.V....9.....r.#H<,.2...,.....ZW.@..2....I...l.......X...9.s.
._v.Ic.w.8.!.......&..q".X....e....&[.W!...u..........K...R.gR?.5.....
N?U....)E.sA\.........'...|..o..p.........Fg8.4........u4y...)c.B.....
S....L.R`..sj......`.@...._&;....7E..0c0.k.....ad.J.y.. ..6..%).H.UD.0
23.#..[o. U.>..x......G.bd..........Y.. .FFt.....W"H.x..[=Y.... ...
lD.01f.US.z.E....b...3F.........%#YY....*5....NX.bx...V....<.\J.1..
.*c.u.{X.......-.X...d......._..P#......9.^s..........zj..........

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDA1eIxMgoIBBDA1eIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..148a....)ASU!VPSz."..q...'....
...x.U.w<V....c..v...S6.Y..$3$e...!.M...2...B*dEv...$3[!...{....y..
......9...o..... .j..O...!.}k.Q.in....RP,...k..E.`m....G>..`m.4n.X.
...T'.....m$..%.l.Rn$R2.V..Z9R.......?.....s....JD......1.7 s.B.-...bu
.JNt.SP..?y..5D).....V..!.4y.|=.6h..C,f<...Dl.).5......w8SsA.....m9
5h.V."..4.RM7.....C.$...X>F......6.(.-..z{......I..O....}.!D..J/...
...q....,..!....8$.....f?#*3j.gi.^qQ.:{.#5B.>.9Mq..........Lh.....6
5.a.Q.Co1.o..y.VZ.>B...... ..bu..VT.......I...P.Q#.Q...M..QQ. c....
g..u... ....B.n..c..".....F.&...."....yB,>...h...~A.......h..g#....
FwI......kx! .......Q....2K..P7..2...f.tH.....8.l?3..I...,Z|3....>.
.&..:.p8y.O.Z._.1*.[y7.S..M .3'..}OZ...5P..%F.... 7w.C_L..v..P...`.bs.
....................a.=./..w2&ri7...)r7!f.\v.... .....zTV "4K....h....
]..4...H.O...M.%..o..M^..A<.o..nK...P..H.N Z...f0.y...... K1.<c'
..d.0k...<...Yh...^.~v..............:o.C.{(]......q....y..F..[4.p.
l.2...ME".^...9L.......J.....c.(K.........W-mz...@A=.6J...`....7..u.B&
.6p U/..2...[*.F... l.vW.|<..3....|...6!.....y....c..S&...s.qV...$.
...[...%...M.b....O......Za...\.#....:~^=P.w.%(.rE..1.....`...H..}.#..
.c...J.^.0.../....#../.C...~....# ..y.Yj.G..m..bN.MK..YK...vm...L...4.
......|.C.R....o........Q....*y.UN?6..D....U.....Z.|vp.t.,.@q..p..Q..:
........B.O.Cp*.yyE...*.q.. ...#.b.l,q{...:`.Rj....A....x..@..}/sH..O.
G&Q..v.a...........~j........l....GwA[B..W..]`wK{L..8..!....v.;.p.yf9m
..s .v..._..=....v.a.$.s.h...z4.Tz~...K...''.......Da.1p..T.$.....

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDm1-IxMgoIBBDm1-IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..ce.....ASU!VPSz.".
.r...k...m...x...uQNe``p.0..e..P ....@..Q~....P)...e........f..1.2bbXb
>...\.....a.H....~o...........X...4&..,.....j.....I.D....v...Fe...$
...7..A[....s%.4.|...S..[....q.#.:.%q.......$..ASWSig2B..0..
...
.



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCw2uIxMgoIBBCw2uIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com



22... ......2.......1... .....)(.....)..203a....@ASU!VPSz."..s........
%..x.%Z.8Tm.>3..w..K..d)..Uc..4R.R.....R#!.FB..I...H..J)S!B".H.H...
.yz..;s.....y.....s...*.[. .r.....(5......9..2z.4.....E....:......0^..
..\D....CC......v.3.LOzG...)E......>!`.......EX...........?.x.....#
.H^.._vHek........H..1....F<..:5V-._.;...u....<..S.%....s.4..m..
.....a...t../.....P:k.Eb....#nQ`.....@z.......a.m#.....TR@..[...O.....
...cm.~...&]..V..!#...#,........v-5.h.......-....W.._....0.bV.C......`
....J.X........-.WC.VM0..O)P$....% w..&......[/?.{..:.Vp.O. ....}.JGc9
...q t._.z.,...J. ..J.<Y.. .......=..].VA.....=...\)...."il..$.N..j
2......I......W.M....hi.5......*..].k..g>.p;V....B.P..|..N...W.#...
,.wk.......1.{..0.1.=|.....%ioUl...........8.A..c...'. E._.......zk..
..M....B.*Xr.....O.kn:....G.v..e7...=f.e."..(......>.01.{...v.'.'oj
.M LK.V0...N.~.-.. ...G.7sq.p. .m.Wx....9@.....a.............,....{w..
B.....:.-..s.p.s.)...8d.....3u....U......n{..U.C2...=...@...c-.J\..6*6
..b@....>=..;.f....S.0.Ap.tj&..$N. ... ..v.0v@...{..$....9..}Q.3..=
..l.9F..OK...%C...y.u.mG.SE...JZ.2f.`.s....ro.uH...3.....Ux.'.ao$.h%..
'..63.1D..3...M....[f{.?.......E..92.:O.21..X=q*.;/..:O....!.UM..."OCX
.....X*.O$...tmG..)....?|.(_.@?).a&.sa.d...=./%.........2.......T.3P..
.;.$.\..r.v<}#..d/.......F.../..ir..fe....[?%..Z....c.s....1..|....
..r..D.\e\.Y..0....:...L..z.r.........7l'..Bey......I......\2.@X.b..B.
.)..UcA.0w$ .f..r...g,.....J.C...XGd{..s\.CbR..g8r.F.[R..$....... ..w.
..S..<..6...&.E..{;.J.......a6~...J..#?....2Io...U-....l..7).m.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC33OIxMgoIBBC33OIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..4d4.....ASU!VPSz."
..t...q.......x.%.yPSW.......HEe.uj0P.J. .@...U....Q.P*.%...,R.)..F...
.B\*b..5(h..E..L.Q*B:q.....H.y...f.{.~..^L .F.Dr.......)wZ.....,..7...
E.1yv....rF...g}...%.....O.v.[..C[.....G.\%...=..h4[..vC.j..oS...m....
w&@.K......hV..|2..........h...#....N..{.:..F]2.............J|....hp._
..$.....OY...?]A...Z......T ......ho....l.d)..]|.9h...D.h....].V[J....
.....7}e.Q.P..:`jL..`.J......U.....6..... /..F.<....34..}>......
Kp..L.x.-...E.(4.$gC.....{.y..I4.7!/Hk.,...y.N9.....H6@Op.|..y.....M.a
...^.Jg.T~.Y.6.G.tj.l..47..f=W)$.G...".i...s...wz.&....i....0.c.. .uM.
..w..f.%A.._. ...;.....RnO....x .t...............k. .....zq.l...^..E5.
..!..bm...W...4o.....j-....3c..i..Y.....!.$q......mN..Z....."s...;m.:x
.h...\.......u.Z...\\.P....C../...h.M..cZ...?......jwK. w.0d..u.......
.&.ip.......... .........R.C7Z.5pr.....o..$.......L.6m...9.Y....Y.*.L.
d.d~.o.C.e..[..m_C_z.X..A..;..93=..U~..h...m...r%...]..Q.....3?....}f.
...^....@..8)..l'Z............~F V..$4..} ..H...h[.Nj..&p....FM`.Z...~
B....-..?..6.vX._.. [............;...c......m....(#:.8.D._...vOUV..i..
7[y@...h..b{...M..>.c..._....Z.."$..]...miv.v.......sc.*.....=.2h..
(..a..%-......5..@S.....}..-3......W.*..tD....A4%F.-...ho..u....J...;}
.^6.....hU{./..4.&.8..^..W..oE`1YvASWSig2B..0..
....

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC73uIxMgoIBBC73uIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1033.... ASU!VPSz."..u........
...x.%Ww8.o.>..df.|.=.2..l...d..=#;J...........JfVVVde...}......\.u
...}....<..)...0...G57L..fB...'...p.?*.<.....)...b..\.in.y...../
.......^...G...D%.....m.....3..`..y.m.36r...y.....q...>.....I.....9
Yu.=.G.Hr.s.JDl.../..x..b&.*..i;..93-5...5.n&...CJ;>...5...''....a.
.l.%...o..H.N...y.l........Q. q?.T.....Hw>7..SlwX.. ;NFj.0&s...s...
..t.p^.......U}..{6....B.{.....=4.........TQ....#.h...F~..........>
.[c3.........d(9t.pjN.@M....c..DS5D*.]7mb...X.f.........N...'.:g.....Z
.2..3/..<7...a.~.j.A}..@...S^.r v.M...:.S..._...Pm..T....9Y_.k...`r
..M....u..&j...\..P.W.....E...&#.....xl.......pUtSN7.......$.M.G...o..
.H%D...r.G.......C.#.$k\!.|.."..=.?r....|.I....Xtv. ...3...U..3.....L.
...J>......o.N......k8.H..;...\s6LLz..zTP......p.j..]..6...&]......
!...4#.o.J.....8..x.7t.[......]D.sR...|>S...;........@n.....Wj>i
JO.i]..p..E?......!........B.zg2i...S..I..T...u....(~.~...s..tWI.. ..K
..!..~.Vp.T.<!.C.B.F.@m.o.. F..qkg;...#I...Q........m..6..3...gI...
.6.W.(YjH.mw.%r.......U'..@`..A.b.....n....1....*...8.C.D...[Q....Y...
i..M.eX.....;.w.....9.\..D...8,.S\.G....L@"[.3..e.I.w-....4.. ).N..]..
A7..'.d.uy..... .....t..k...3y.*.qr .0#.3.y....*..P.>l$.4nH)]%T.RC.
.?&.F.....NQU\.Tu..ge.....7y.b....5.h.(...t<....{...3..Wy...|.....6
>u.....&.mX.Z......F.Fm>......9H....@........#.=i:....am.....}.!
.......%].&5....]....o#.C.E?.-...?H.....g......Q>d......\y.._4.Di"M
....g.R.......l...g.&..mST...4>S....L?....w.^g).......p_=1.|...

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDF4OIxMgoIBBDF4OIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..bb.....ASU!VPSz.".
.v...X..._...x...uQ.g``p.0..g..w v...@..Q~R......&..d._.....,...&3l.w.
fT...........!.$....bI....0....&..5....Z{.....lY.... uq.z.l...j..{....
....Fq.........)..B...GWeASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDZ4uIxMgoIBBDZ4uIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..ee2.....ASU!VPSz."..w.........
..x.%Ww<...?.P..#;.u..]FfBF."...)Y...'.l.>2"....>V....H%D....
......:..:.elzC(...L[.r..W..R.p....~...m.U..Jv...b..."...!b....u&...z.
A3...0....;.>d....^.[b.5..T......p.`..&{...3..%.0h..&6...M.?..ILR..
L...e......n....#J..O..i.....{q.a......|.......D..]A./o,{.-.O.....7d..
.NO.....i..sOa.A.o....TL..%6G/}.x5.....).......}...X=..uJ^W.3.`..;.0..
..m......Y.....?.....5......8.=....,-r$.....o...L...:RL...M..#..a.CRP.
r....&.p.Z..1....e...c\."m.[...?.......s.xz.;7yX.......mK...IX..s;%..?
.....R..3.,veX....(.6.2.....LM.c.3...{.K.......G4.iQD........~....@...
.....WM.-e....R2..GV........L...RC.["...K7......./....4mDx.....j.....&
lt;...D-)$.M.We.=e.D<...4........%.... bl......,IA.J.&.tU.D......l.
_.y....zG.kX.@ ^Q$....4.,5..9....rg..<..&..9 .I.oJQ..3......*.X..n2
.pj..O..G,_.....[..o......>..,/......q.M.......U..1.n...,=.......d.
H..c.....3;......w0R......#t.#PN.,.......m'v...6.Ul2.%G...J._Q. ......
c.e....f.z..J;..../.{..'s....:$..;..........rJ..r..D....=..X.n9*.h.,..
.".m%k..._%.t..........kt.....Nn..k..0..w....W\.x...L...l.....=0..G`&l
t;MZ)..N...w.....u.W3...M ...C.Ynj........n.)....5..r ....&.....v...I6
&\y8#.@L...w.j.=T.A.."..!..f..9...-ieU.[. ........G....;.....t[...._d.
..m.{.[..*]... ..7.............g...2.4...=o9.~\Z.H....#.Yu........Q..N
.{...t.q......0.0......mj.(..}..<........{Q..*.........nlqpg~.....:
.V#y....B....c.. .O......Z......[.*...1..S....(C.......mA..R..........
.G......&q*..c?.lrp.w..!.......x..W....9.-H......`.;.....x.*.d,..|

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCK6-IxMgoIBBCK6-IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..be.....ASU!VPSz.".
.x...[...^...x...uQ.c``p.0....,@...:..H.s.{.......... ....`.`.$....&.3
(V.0X21092i.:3-......aqq.q.eHc.....v7..<!,..0.<.....v$l.!.0....r
L.FY.!?7.Mx).U.k.pW....kS.....l"..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCD7-IxMgoIBBCD7-IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..9f.....ASU!VPSz.".
.y...<...C...x...uQ.f``p.0.6f..m ..jx...(.t.K..A...A.......(w .(...
.d..r.>}.....F..|.=.....X....C......f,.q.`Q|.T....=O.....w.nx..t...
..)ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDQ9OIxMgoIBBDQ9OIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..86.....ASU!VPSz.".
.z...#... ...x...uQ.```.w2......-.....l-.Y.$H...`?....(obK.{.......J..
..~K......b....K ....z...0. ....Q.i4..#.J>ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDh9uIxMgoIBBDh9uIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..f6a.....ASU!VPSz."..{.......(.
..x.%Ww8.o..|...MV6.{' .5......................*.!{ee.c..........z.x..
.\.}.>.}?.Vg....l..$'..7......'(Kf. ..8.~\.}..w"V.......c.i}....X^.
l...X.....!`..Eu=....mU/...gb......:.t......~.>~.X.Vx...5.qX.. .[..
.'s<.. ....~..v.CW....R_..v.YV. ......:.Q..4." .....'....2..x.....n
........%.e.q.........d............>..7...<...J4.%..b...9.~&....
.f......Ar..d.E1..`(...*~s.t.3...\ 63.0..'cb\.O`..4.....z?.m..V.4..),.
|>....N......qi.U..../..L..:kc;..c.=..{..8"....0{..6.J..2......P..[
.hZ.pp..8..f.... >.....Z....;...U...4.r-3[.>VS."?.i.D.3.F... ...
.B.(T.....1.......u.X6E*.b.._.S....X&f....._8......l.;..)GiQ CM.. <
..d....WN.s....e.k...|.E`:IO...{..Z2x$.. ..3."...-..x.be.X](.\.....{.
Mk.B`...8...:.>.....H..lF..z....8..|..:3S...{..(=.9.....#..S......5
............ V@Ez..(....^....K4.O0./.7ey;(=..d.....T....g.....! ...h.1
^A|...he<.$..G.c2....Bi...W74*..EC..g..;6M.....r&[..hq...n../wNb}..
/...gU..m..7.5.C.U6..'...?.0..z..f....H.9}...D... ......^p......B.i...
.>.FL.@.........u..^..^.P..].......-...... .S5..dQb...y).....4..L..
..Z.0..y...\..2...b...8..~..ir..{DVzqeT...HQ.q......r.....%#..r.\.@...
qq[...zAL.7.Ze...Z..c.od......~.\.>.%.kr......2....sX2..y9K.Bk...L.
.0..d.|F...j....e`~.......U.Tp. .e....{..uHs....{.B)..3....H..w.,Q>
......q..7!.....?....KO....~>.n (#..C...@8..F.H..1{......V..vb..<
;....-............8..O...B..P......x....:[.k.#@..`...R...'....~YkW:..@
I.~..8@..U..d..%............U....h.q.%Z.....S..g")..*.u..`...Q5..n

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD3-OIxMgoIBBD3-OIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..da.....ASU!VPSz.".
.|...w...z...x...uQ.b``p.0....,@\.h........*32*O:..,.....d.......)....
....vg.V.7.......\...*.I..ZB......p..3vpY11..% .........X.....xD.C.)J.
..O..x..*U.=..%...fP.U?D?..?'Z.Qg{?..;..m..4O...^....{P.ASWSig2B..0..<
/font>....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCR--IxMgoIBBCR--IxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..c9.....ASU!VPSz.".
.}...f...h...x...uQN```p.0..`... ..jy...(...5I.YK...z2C...0..F....L...
...&i.:.k..Kbq``pHa. *.JeL.a. I..e,.fdma......K...._F....S.<.?V....
.jL......NM._f7...(.,.._.!F. ....X.6.CA0.@ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD__eIxMgoIBBD__eIxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com



22... ......2.......1... .....)(.....)..1061.... ASU!VPSz."..~.......$
...x.%.w<.............]rK.....=.J6q3".fF.L..DF.H...."...........y..
..:..:..)......\.d....$.k8..DvU.....Y9~....nx7.5@......z......k...1<
;q...2.....1..]`O..h..M.n....9<.D.=...M!oGCL.|l..r/..2.e..f(...."..
....w... F..h.F`.;.<(..o......o..K..v-.......v.T.Jvd....u..h..g.Q.7
....T...rq.`.lv.......c.zN2.m.l]qS....M5&o.W.K.Q...T.....Dw.h.]:....[.
....(V........oi..&_|*]....p.....y..CF......u..d\.........0.~..-KcS.xf
.8>...sx..@.9...<..w.4...a .F".......}.V.>.w......HA.)...../"
.U.{.C.B......$U.D....f..P...E&}..././.Z.&.JmS]...@ G..;.......2._..KT
.j?lJ.F.G....{.6j.....Dcl.}Vr8........c....~..e..gY..Y j..B...,G$4v.G.
o..#..mY.J.$.....">....d~=<...uY.TV.K...t.`.VUy.2v......:..b....
.Su...U.....^A.U*?@M-...`O.. ...F.<..0.w..}.) ..........2..X....2..
.0..%9.....K..>G.w....D.C..]T.Cy...%V...4.o...3.-.g..m~.)w.x.,#r. .
gb.............k{.5V."\.......R.....7...m..(...z....<|..Gw....V...Q
0..,..q.xe...9...........n......U*.(..Zi...w..:..|...../Q.v.E....j....
......3.d..n-~...a0.b..........@.f.A..^w...9.....N...2b.&......,..0._.
....)..0..%.@K.S.LAy..r.0..Xv8.t..i.C@....W....J.7_.....~......@6.E..|
...4_@....%...m.....p..[H..../i...*g...pq..@..,5mt. ..o.....X...V.....
.}..g.M..g...$>.?.n..."....JS._...fH....0L.1...\7@...}..........G.6
G?..T..#.j.I../........Q...?...&...d...t.../&.e......1F..U.b:..r..V...
o....[.#,.!.}.`v..D.=w.D...n."..O/L..6..|....,W~.Lc......k.o,....H.$..
7.........`\...|....@r... ..5%.....|J..k..@....TL...$..4^.......q.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCyg-MxMgoIBBCyg-MxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..a1.....ASU!VPSz.".
.....>...@...x...uQ.```p.0.6`... V.j{...(...`4.....0.=.o..f...D.W|.
..,L.....Y:0ko..DR..`PZAz...Z^...R*.v..zs...!............~...|q.r.....
8.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDKheMxMgoIBBDKheMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..2055....@ASU!VPSz."...........
%..x.%..<Uo...{.c.\...TVe..r3.r..Z(J...Y.$$.F.......\#.....JQQ.R...
......v.=.y.g..s.0.T......Z{......h..` ..S.Q!.....t.r.u....R.../...r.J
..$........_ ...bD.N1....)...A........O..K...3!..a.6w.}..>}....7..r
.-Cl..w.XG....3n.]......2.)`jt7..k...Om...C.i"d.q.y....=vj.........zj.
.J.-!...{&..<..@.5-..x/.......f../!............... .4...0.|..c.d.b.
..Rv.@dn.&}g.'b...>p9T.]...qbA..dN.....)...2_7.....S...4gDq....4o.b
b.....M.....K.{7...`..9Y0xW3b...~`e.....ec......y.3r......ey..b..-s...
.......U...or.s........M............~..... &.(.Kd....xrSky...P." `..o.
.s.....w.V..F....q._6.#&,..@D....../.2M....x.\@.......:..i..].....Uv..
Q...]..(#.......,v&..@.X......;......p.G................ey.@..QY<.A
..ND.W...X].-...~".C4./{>......,W......2..xjVD.....X...-z..:.....{x
.Y...1*.`x'6;em.Y.6H.T...L.M...o......Cl*...>... c.1....1..;.....y.
n.....) v.;.....1/i.`..?...iV.%.!.K....0@.E._...H.w..E.o.D.#..Rl6#."..
..B........f....83....^f.....1.....y....].y.|...\g/.I........yp...i`[.
..hk.7.w)....q...@..T'~~........A......$.............X.e....T.........
X...?G.BE. Y.&...%.^.......u..Ou.OU.EG.3Wz.I..q..7..../.\.bWq........C
X=b.J.....4......o...t .I..p.&..~.D.ha\.c-/..r..... ....iF......*.H.A.
.......v:.zY....b.....J..'..Z...E.@yG.S.`.o..h..8w.).}%^.A..."......V.
.........9..A>.U......X ....Bt.EE2.aK..G.............d..R.E.y[...a.
R!P.. .4.C.e.4.b..C..:.'_.h!...............z.....#L..d. ....@LN..r.'.,
..3.Gp0...jc..y...oiZ....]^.Yq..`...^..e..{...(.W.....{..rP..U.}..

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD3h-MxMgoIBBD3h-MxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..2044....@ASU!VPSz."...........
%..x.-..<.....3<.5M..%.Q....l.bH..e...J.QR.2"..."!.D...L.R......
.....?......3s.{..;.r`.[...`..]z../..".B.%B.o- .~._]...........%..74"v
....J.Q.*G....D................b!...D)... 8...\..<.z-iL.....]. .h.c
....b..;...;,t.,..O....J.JGO..)|.....z........h.JXv.D.?...'-..V...u.$@
.R.i.p.;b%d.".O@.......y.9.(v.R .zq.Zf...bL....i...........\.#G.c..k..
....$.................Q..;...0..;d...FlB...7..}.P...V?...\.e...H..w...
4..'.|..G...e=.rc..b.....h...}^.r?.!6_..G.<..].Y.6...;".{3....._?..
..BlHts..5..V..=..2........v.....].........kN'...{p.1#qk9v @E..z...k.u
...3..`r..%..^|.U....g..^..}.>.BL]...w>..b...Jj...H.F..Y...i..5.
FlJ.s#w..Oy...'jj.<...2.d.Q....KS..s..XE.....RN.3...ris...E`~..x...
U..H........G.o.j?..........}..we.,..f...W.B......W..>..k.M......}.
z.Clt.v..h...Ze.B...|e.....&.M|)..,....i....z.........l.... m.v.......
.....L..d{'L*n.!.i...d.....s..._@......B@$......3..Px... ....<..Q.)
Z|.7.du..~;~..1oE.......C.V..mG,X.........1G.^.G..bm.3.....2ra.C....o
...H..X.kLL.G...)."..v5........|....@..3.<.V.En........:.svaBu.....
w...[..[.U.rQ..XF.|..p.X.........Vn...2.....3..F....=U ......(..8..[.z
=E,PU.>I.HWrg...u8.L.^.b.................=.;R..Q......;61..........
.{....<.@A...l.t.b.j.=..9./.~...A....9..0..t...?c.3WW.....%.F..Kve#
...e.....d.n."c.bI............)@LA.....@....7wf.!....G.D...gS...k..[kh
g.R;.z.I'.>'I;.e....FU.F..?.P.f..0N/.'e..3....d..).....^."V.....F..
.........jv.s.h...e....O.[....v).. .d...7 ..m............oF,M.....

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCGiuMxMgoIBBCGiuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
..s.?.u ,@.w.a....I.dx...o......N;....."LQ.G...@.vB....g...qR..D......
..2.. ..D.4._{....}...W.~$...8...u.>.AX.*%Mb........%..vV..&z....z.
We1..k..D..%../_...AFKo s9.^.tTs%]T...u~.u...:S..&...[.Z.O...-.mt. ...
V..1)q.`Ij..l=N........t8. ...i.d..\.........Ovp._.Fe.o4.]n.Kf.<..-
a.................K...s./.6.B.....H35.[..l..z.W..a...A....A..a....e.iM
....^6{U>.*...#...a..f..J8.T.F.1..!...v..z.\Q..s.a...._.jB...*..a..
..[Eu3..^G.....M>...w...4V....).A)t..m.....R\....2..C.........S3\.'
2C..;.B.g..;j.....t....{e.{'...D..W..N.IS..Wg..5.3.u...9..QM..J&OV....
_......\...}#.u..p.....2.S....4...^......a.&...0..Y.nME....._k...N..C.
..p....|.....O..Q..U...2jk.....:?.~.u.v.....!5.....:?j..-P(q.........Z
.t~.<..@.1...#...._.W...n...E.........U..~0S.....a6& o}.cq..qG.....
2./WWb._....:.FV].../...:n...'........y.s.cO.Q.~.z...^.'..fc...i...2fn
..6.~.....7?..<...#L........IO.s..{..d./e.r..L}.*......x...$.......
............-G,.. >I..j/........)...Z..uO..@pQ...../..XtZ...|.>h
^..h.0U.4e]3........X/.....xJ...kG..v......Jv.@EX.......fa.......Q.^..
.....V....\.T...{k..........:..*.H8.B.. .f...].w.../w#.x.*E*QA(...V.o.
.y.=.\~J?_..1....s.&.'...&.......X/m..#.S..7.Y....w.f.3b...5lj.<$..
..uz.y...y#..*...Vg}....P....8Z.....].......N..u.G....D....5..aN......
..Q..y...fDA.......=].1.q..I.1.v.<lJI...... b.O..........B....8....
P}.).* ...5.z..].T..u..[...?\7.}w.C.`uUq..d........\xU..i.._.aC.?.....
..~.... .....f!*N..*....#l=..&f,....^e./....Ev....?...{..c..Yy.......g
..F. ...X.}....K:... ....r.M...eB.b.8.C..|D...Hn.:..=.a;wF...^...7

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCejOMxMgoIBBCejOMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..2314....FASU!VPSz."......."...
&..x.%.w<V.......M)...l.....Y...eF.W.BFV..)Y....!"{.D..........o.&g
t;.{..............W..gy......I..qe8(.4"f=...e.H..Y IAo.4.~.....I6...p.
m.'..xS.e.$...#....|.R.cF. .Ai...d.\.....B._RwEq...."....;(.$k...A...~
..*.%....t./.....pY3..ew..x....... ..!'Q....e.......=&.F..Sl.._...gR_.
...(....#dP...6?.7gWP.u@...w..,UL)..~b.r_.O..............D>E..^..k.
..9.J....&........xK..........&......P.G.D......X).j.6.l..t..q......b.
o.,.....I!*...T...^w...>/......Z.>.2O..O.s$..{.....*......A.d.Bw
..m-.L.]........3.s..P..`.K.=.$0L.?..&..C..Tx$.....i;..Q.q$.......3w?X
...........F~.{.$.o.........|/)..G~.A...1[|..........(.r.....@o.x..EJ.
..r...;....<.Te...fny7.....OO?Y/.CY......`3..gZ...e..N.:...._.hS..P
V.}.......C....=(.=.!.x...&..<LBb......xR2`.2...NYG..I.].qa...v.c..
.2...!....U8,.....{. ...d6md....pD....8....U..7........_.........V.Y.V
.l...ET...jg.X...9.D..s.QJ..T...<[$@<...c.4.....2~...8......)vF.
.?..1..#{L../,.C....K.>..1.l.V.....hJ_..re.\........=..E.&_[..>.
ak...j'$S.k........;.e...o{.c^BU.!.2iA...c8.)......A.....^.......u....
...B.2A...%T..e..y..E..ct2\.....I...M.88:H...k4.2...SM..aL..\...;./b7f
.2.....u.;.../....;..7C .2y........@>k......e'%.J.|H....F.[......V.
3.Z..."...a.&m%E."....U....6.K..' ;S.T..:[...I.5W. .o...G...zS....w..~
........,Rf{.`#..E..o~.`u."s..)....x.U,.1.(..M......>Re.e.%......8.
3.Y.u..l@.~....q.....6.......`FQPrR... J....>.|.HL..yl}._g...L<.
|.....g..n......I.'W..".Gi........q.3.=rU....H.....u.`.j.._.......

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDGjuMxMgoIBBDGjuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..17f.....ASU!VPSz."
........../...x...uQVgd`.p5......d6\..w.U....>.....]Ab..':L...~X.,.
..o....X.f.....%,.w....................%.../NVl.cbP..U.l.V.$&<...5.
.a...w...W....]Qg] ..|b..^_......F...da(x.}<..n.H,.............N...
..y........LN.I. .{.Y?.Neg.!o...eY.k...5......W.CeFF.....3....O.91U.:O
z..,....(..(.?..%^.qC-..P..v...M..h.p%5......a.X.e.]..n6...].[.Y4./...
...]?....Kba73...u...ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDQkOMxMgoIBBDQkOMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..a1.....ASU!VPSz.".
.....>...B...x...uQ.b``p.0.6b..- ...~..........j.`.. .0....A.......
..........F....;..<..EI...Iv.C..t.....7kEm7.....y...p......h...>
....J.:.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDdkuMxMgoIBBDdkuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..86.....ASU!VPSz.".
.....#... ...x...uQ.```.w2.....-J5 ..7l>.>].....4OK.r..O...._...
...q&..]&Mm.T...,...o.^.d...U|.. .U.2.@..M..A(..ASWSig2B..0..
..
..



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDnleMxMgoIBBDnleMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..e5.....ASU!VPSz.".
.............x...uQnd``p.0..d..B ...y...(...`.....P.. P.. 0...E.......
.a.C.....7..........@.t.H.#.^.2....f6G..&'&.Lg.."1,z.)..L%.I@=.N.L.j5,
K..!.$.....H....:..v.47.....S..@..YRI...=.L.....N.[...}.$.."..:...ASW
Sig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDzl-MxMgoIBBDzl-MxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..227d....DASU!VPSz."......."...
&..x.5.w<V........B.J.x.Q..Y.$ .)!.....J...d.22..$......;..;.x....z
;.>...u...u..B. .!..-9./r..@x%.H ........XN&..iM-n......Fo..=......
|......z..D...g..4.......~..2K..].D&.4......<.*.*.m=.p:.[........}J
RC.3....K...e....8.&..y.F.W.!..u?...2...nM3..*.}3>2.>7\ ..w....S
..,.........Z......6....[........(......\.:...."...\...gRo....v.. ._.I
p..@.=/.e....=.YiQD.yo....}....?...,.{.r.#.H..r..eS@...B...c...e.'....
.H.:?.......lC.{.a.6.....r.~..GY\xN;z........Y.}.G:...2.p.Q~V.8.t....u
.Oi.....o.y...}.....|7^V..?.S..=..5....m...6W...S&p(....De.e..O...k.0.
.....2..ok(.U...........{.s...$..y=P..b....#..q8.......r.[-....,.P.:..
..*.3m...H3._Z.:.el.6Z....g.h,.kEQ..3Gw.Y.H:.5.>......Q... ...5"..:
...L^pG.e...V..i..............Y.>........Q.qD....e_....z6...k......
. &.z:.`.........~t._...'..K.EW...{.X.`....M..`{..z...............HAr.
.....N...#...#.y.....(..^..8......^.....wg..?...........(..y..........
Qe.2...8.J.........*..%;I~8...:....eS$......4;..e..'.l.......'1.7%...e
.(.%.w......Pu..okN.?.Cr..B..7((.?..D9...*....w).|.g..8.~Y....?.Ri....
..g.`.B. ...Z.km.BW...!...e....xU..J....)......<x....c..........@p
.......Y-...M...W.I Wix....9..MR.......U...........t.....4.(S.`..."..r
S...d.X.p.t&.....m........../.../']0:.....O7 ....'kb.~..L......@..i...
.*...=.dO.p.p..^P........D.%.n&....A....j..n..~.M*G......,.0r(l.....lF
.(.xE.....?y..X....a....9..-.p..... .....=.'.m.1e=.E.w......%..b.2y`$.
..p.......7.].H.#...<..O.d.......-.....'TG.5a.....3......0...(S

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCHmuMxMgoIBBCHmuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1dae....;ASU!VPSz."......K....
"..x.-..<T.....qmY..Y.dK...2.e.P.(K.."LLI....I.6K!)d...e.".R*J)....
......y{.....s..<....nV....82t5n....$...c.;.....qo..&.6..f...G...B.
.(b.p.Id...4..LA.......k\...'.....#.G.......Vi.R...".@....J.%.Z^..O.G.
.m=#C. %..I.ix../.b G.....fY..$.\y....(...v....0bK.l.2......W./.. V..R
.J....$6...y"..O.....vu.t.....8..|.....8.8A.j.b.......a..ECb...=....z.
.AR.G'_.P*b.B......#.[.d.....7Y......gt.7z#.R../.H.z.5...|K.[/........
..y..x^.D<jY......H.........W....o-q....Tt\.X..&3..o..c...m......@.
....)#.G.........7o."..............\..X.X.m..E.~...p>k?.g..o.O.....
8Q?.5.3.//.....om..J..b........>.c...^#bB...3.|...Q.bU{0b..Ly"]....
. .=..........z..b.E/...X..!...O....,..bK..nr6.....coQa..'.W........r.
....J...H..5.=.j.._.....I(.h....y.^GLT..c.q....t...-...2#G8......~...6
b.d.....<..<.W{8...2...t.KE&...:..{&{....(.7..`q.y.^...u.O......
..Y....ewI.l.a ..z......'b.n........X................3Q....O.7.J.m.g..
.SQ.2....Bg...T........*@...y.!.3.)*.......do.z...F.\%.....x.[.%.<.
Hz/..t%.D}....F...i_.O-.{Ii.....>(o.Y\P;.....3..yp..D@.........A{..
.g...l..)*...K..D.-%..,.........Wv3..T..F..B.w.O.p#m........... .....^
...U.#.eA.t*:D..^nc.!.n......[icD\......'...l..dt...../.#.##. ..W.h..u
d.4...L.7..5_..,.8..R.^\^.b.be..v2....s...U....&..J..sk...7.? .h.3.R@.
dB,rC .iB.......4...#......V{.>v.~1...? ....&..2.(....2.UW3y../>
..<".z..w.%M."QF..>.S*..{p....'2.^fWTuge\..Ik.*...Z_...gy..~.E..
3'..x.....}...f...<pq...T.,......g.....W.3M:.......[.\.........

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBClnOMxMgoIBBClnOMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..d62.....ASU!VPSz."..........Z.
..x.M.y<T....;...!......4."K#*e..."........_....d_...O.J%..B.../!.{
....z..5...s.Y..y...]..@......... .Mr@.....#...;O'#....'}...O.ZYpq..`.
/O...`p>p.m.2v../...O{ ..QEC..38..q..zZ..o.}4$..<#9..QP.......\.
.%..1.l.0.E...,.5...Gl-u..*...J...Ik.0..r<....c...VT vET..%..x..}..
.t....*n......#...a!&'n.....n..........)u-.8...H.W=.....i.{P.Z.~....3b
.......F>6*:F3_.3..6.&......X......?..e.^.....l........*.......Z&b.
...8..Y.....2E.......#..Qw.<b.b.{.d.Z........T.x..U..q.0h....x.....
,...%M._Dn....=.U..l..c..|({kT9.1E./.8W.8..<3.u..........[.ge.fB..n
................,..p_.pI......Cl.....Z.*k...*b.!.....7..4..?.0j.......
H....0H...DL^K7......&....N(..Y.,.Wn...U............EQ.r..]~..Jq.....[
.kf].C.<...N{.\..#Vs..>@.2cY......f.Ys.0x'/.|..k9...d.c.}o0.....
.!.S.}9.OQc.}........y..!0......BF-..8.R.@..@*.......D:....aI..}r...;f
*....2..\...GLyM.'.....k..A.<.....|U.6.g...K].......?......\\O..g..
..s.D......b.k{..j.........|....*c....j4...}N.`.......A.}...pR...N....
kaf.b.!....}t...>..'0Z$......$....*......7*8.X.pYi..y.u?..%....1...
4lX4v8.B..Q:.R ....6...'.....n.)8..b....a.A..a..Qt.2a.c%.i."J<.v...
.4r..~H.!........e..u!....k....&Z.;....k.$^..7a....^..\...].Y[..6..8].
..^Yv1:z.[j...~.@....t.]...[.{l"4. ..u.. =q.]q!^...0"g.K.#..xp....^E.&
gt;MQ..C..'...s..9!.s...F.......I.x.s... u^...G8]..@&c.Z..8.&.OP.|.`K.
.._........@.#%*..J.Z.[.9#...V.^.'...]v...f...w..~K.t.2...@..t.V^h..vt
..<F.8.......{8...o)..7!oB..r.W....m.-..Io.....v.Z..%Na...y]...

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDcnuMxMgoIBBDcnuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..cf.....ASU!VPSz.".
.....l...n...x...uQNc``p.0..c..0 ....P..Q.A.A...`2C...0....."^.....8.'
~w.2ew....$....!.E.8%1..$1.....).E..!...A.......h*....H.7.QZ.......k..
."..1..."....9.x..o..9&(...)1wW,W.....fJ....-ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDmoOMxMgoIBBDmoOMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
.....1i!p.].Q..nS..=TA......... .p.o....iX.......f.G......]!....AG....
...%3/............_.E...K._..K./J[../..2......b}r....'#.;..@8...eC.$.&
A..2.fC...=...b.x.m.wIOI..Fy/.:^......Y.p...63.h....C.O...\...S...,..!
9.p....q....r.Pw.%#.....6k.W.a.#..1G...ok.:..... ..).....,.:..\#......
).D.R..G.}?..pdUd..3.Pn....D.....<.Z...Bc.U.:..z.p.3....d....h..9O.
k..y[Z.`..[...Qx...By[......S`.H..{o:T_......m.....r...J|.M...a..>W
.#..<.....n....R..&. .a.q....6.D.Cj1Xis...>.^.=V..?.C.].8..P./..
............8...... ......u...v.rx..L..f..f..#'c.O.I..j.d...z.`.GK.>
;oZ..[_...!.a.....e.*X!....2.G.(..,t....E.8.T...kp..d...o0....O...a...
.\W?.z...X....g....cs0.p..r...g(.K...~.,...o..t3.....?2-..G.)[.i..x$.
L..]\[;e..O?...{b.N.{....K.......Z.....=54|.j.#.L...x4.f...\.?.IX1)C..
..(._k.d9V..o......an....]......B..h.4...............|v...2.i.....C..X
<.........M...].v.$.0....p.../...4.~.u.!..2.0.uk6......O.O..H......
......J.......-.}.`.......%!;.<L../K!lh..g...W...=b...g..H'.....#..
...}.BHn..k"l6.?r.b.N..}..#u..n.A3.%R:......a~pgL..F_..g....F8.p.:.bQ.
Q...Q{.....o..kk_..{....P..O...".)j....T...h........S.l...^N..\....X.w
....].w...=...8.J.b.y.{~...R.2..t...t....B'....pM........g..q.K.W....C
!.M...!..N..O....v...W8.....8N.GV"..;Y..}..Tp....e.......p...S........
.x.R..q,.#....e.{...e........ G.R;..:)..y.`.*...$.....y.}..T.R.......z
.yC............O...Q.W....!..wn*C.W. q..?).O.....u........~.[.-.A.)W..
LxbU.....w.....>........](....9v~...F>..^dC.Z....r..y[-a......TX
`).....:<...^S....n........<..Q..:.....2...G...)4...`.......

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD6ouMxMgoIBBD6ouMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..1084....!ASU!VPSz."......!...y
...x.-W.4....<D$..J2z..^..k...&2..V.(;{KV6.#{..YDHFJeDD".?~..s.s.s.
s..>.u_..s.z.J.n....E.....xp.......t.r...o..a...Y.. ...En......=.mS
.S.....z...G..A5......`.H..%.......".)&.....2...G..fy9}.@.....&.]..s.q
..L.l..].....P;.\T&].D......Ik...f......./D.Y.'...aW.G..h.."OM......Zo
.`/........u9.........^.0....#..w...r ...c....} .s...!....?u.n.#l!.>
;...hS..4.C.....x.m.G.{...g.....3...&yK(,.^.?.K.\..y1X{4..G..W...oC\.P
Fc......:e.p.B=.%V......|..........@.HM.......:...{g.....kq.?.H..F$..X
. :.Te..w.=....R......!.."...@.f?i..?6a..i...et...1........d.O.qX.`w.#
.N:.B.....Q.........%Yv.BN.._Xe..c..p..|.$>..v).z..............'...
}b.7..}.W..Fn...3..`$.Y.f...LK.."?....fn...Lx.O%G..>]?<!.9..$.k&
ACI...8...;'.:{..{OZw...P...=..B6:.}.....O.q.........P#.q....^..[.]...
j#&C.w2i\.....Ih31.>..9.k\<o...L.._.V8z.R*l.......F.?.N...Z.....
......k.}..jI.....\....~,.6.$l<..i.K.N...%.L.IT.|E...U.E-.....'....
..jV.....c0.<s.[6...[/...jn... ....)..iHn..5..f...(..w.....g...G...
....[...]......g..b....,......&..Z..g...i....|...~.........U.....W...;
`...7l."3.........^..x.W.46.>..z.....s.N.....#.rJG.h.z......v......
v.....=I......t...DiI.~WwL...B....kv.AY.........L......`l.L.r..z/.V%..
..3}....".?.c..E;....5."..c.y...k.?.....g.....V..r.>?.h~.$p.$.9...*
..m.:.z.j.4.^Kk.pe:......k.(.....|..T.9.j....@.F..)..........L.-.G....
....B........d...Q..N~_B.`J.F...X....K<..A.<.S.d..!.F.M.....Ka.|
..*<_.L^.U...'.....k.)F....W<.un...?^.(.^....UX.}M..../.5...

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCnpeMxMgoIBBCnpeMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..21b.....ASU!VPSz."
..............x...uQ......j......d6.*U?:.J.a..G5.:......./q..gp....5 .
.H.kI......o.........K(.q=.....b...I.. ........gm]\0q.$... ......../YU
.*.l....w.t..X.w.:.....&m F...X...:32.O.^.4.h.HLY6c.....5.M^|..8@b_T..
4L`dxu.i.tJs.H...YaS......NSM*g..........!.%...... ....|.>10...]c..
.l...M.XO.2l.py.%.#A 1....R......N..8v.$.*..{.v....{K.z....5T..mpd`.V.
.....f.....v.........<.|.......r.._?.5......;...t6.../. .f.2..Boge.
..|...]c|.. <....U.|A.l>48...cX);Y....A.Cl.V..$.3..tQ.*.?...T>
;N.C.oOu"..{...V.:_.s..e.W0|.. ....q...NYSjASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBD9quMxMgoIBBD9quMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..db.....ASU!VPSz.".
.....x...~...x...uQ.c``p.0..c..4 ....P..Q..|2....0....$...!F.0.....p..
x.@<P a2....a...U.5..ZU*........M.....X.JR ..K......2....Y.....*..%
G!.f.H.... Qm.....39..V.I.*.U^."U..a(...:!.....R.g../.*..KeQASWSig2B..
0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCRreMxMgoIBBCRreMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..fa.....ASU!VPSz.".
.............x...uQ......`......@l.5..2#...".2....C.C,C.$..8!F..I...B.
...C....J.....YZ&.....N.i.Lw.R`b.S....,43F....A..a..?..a..,..J.....z.8
00..a. JI.e*IL.j.g.kd`.."....D.r.o...}..3..~..|.Zp....W.muj.."I.5...F.
.L/...'Rm..c.i....ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCdr-MxMgoIBBCdr-MxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..e32.....ASU!VPSz."............
..x.%Ww8.....(.........T.f. ...".....)... ;#3[.HV.J\.K~f..}...<.y.?
.<.}?.{>...]...9.p. '....^0....Pu.......1..@"y...r.....U)tj....&
(}n.....S...|....F......q'....l.g........V...3.....m$.;.e...&....~..^.
N.P.W....?V....e.! ..M.Yo....z.N._.Pq}.P........../..~{.1p....n.......
..e...L..FaJ......?\w..r. ..?v.J...{....D!u._...^~Qh.l"lJ...S.\;.....i
.G.?Z<.@y.,..]}?>...I.bf.dE.........r ...g..<mt...4... .U...7
...I....[?....~T/...'.`......8)....g5P.PHO.$... '%#......c...X'.w.uU.'
]..w.........?..9[...k.D.7.P.. B.s.. ./,...a./..y....8....../.V.Fd.=.6
..^.)L.....M....>h.............R....%.F.p.......>VqL....*h..8..\
V.........8K9..(.......g..$aOe.ow}.}@..9x.c..@...dkF........M...[T.{.$
..7id.r.......d..S.).O=Z..P..&.R.M...o....I<...zl....L......}W..u..
c..yI...z.@WQ&W1....u....G..X....M....:;..>...&.5\....:..........)&
gt;[l.f....K>cU.b........3...X......v....6=..3...(...{...v..._....x
...Qt.-.UF......,&...........G.d.Y...s.[.E.Cy...}........m".$..l.q!.3.
.s.}.aY..;.$RLk..2.O.x..yd.c/......2......"<.*1...[3.o.\.z.|....$_.
.......2.y....f..C.:......($IO.....n<H......'..W..e...jv'..[..'....
..KR...o..M....wL........b..b.p......8=SR....g..gxs.g.K.Q..].*.!....y.
..tm...9gz.>..~.*G..3Y.Sq>...J.}.1......wz.h..3....v.;(..S..(.T$
.5....t...O...e.V/..-...c.....71~9.^.K.lkp.y.....n..yGB2....J>')^..
vxr{>...)*.g...B....n"D.[..'.W..~F9..r.....h...cn....O...F..m...%..
C.....RU1....'....ZZ..s..v.............E.n...y...k...~.....S..W...

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCtseMxMgoIBBCtseMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..a8.....ASU!VPSz.".
.....E...J...x...uQvb``p.0..b..# 6...P..Q..........5.....5.!.E/3%1..$1
.(..T.......f.F%u...G..50.h..Tpvr......=NY....m....a..Y....}..c..tg..`
..1r..ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDZs-MxMgoIBBDZs-MxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..a5.....ASU!VPSz.".
.....B...F...x...uQ.c``p.0.6c..= ....P.........i...'..&...,....<A.S
.3C.s.......#.F..F.p`...;r\.9Ym;..1`.._..9.j<...]....E..Gx....#a...
. O..R...ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDsteMxMgoIBBDsteMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..373.....ASU!VPSz."
..........e...x.%..L.a......#r......:.....S .*.t.S..Z..3.t^..K.[.....%
fjjd.-/.....JM2...e....g{..>{..^.=..p...@\.......<.uO....G....1.
.2.T..,.E..F..I"....V..gQn.=&....l.w.I.F.O.?k..I.dEKzJ.g.;.......YWd.R
...yHx.q...d/w....".o......Q.}..?.;&..nl...!=d7....c0.EY.VSB..g..U,\..
.OK....x......[...o....RS..m..zj.#`.^.q...B...].U./....g..F.;..[|.._s.
...r...k.....e..oQ...6....a......m}..9.{........W.H.$.Wt.....t.k~..o!.
$|.'hsC.V..........[........W....]N.t..V.s..M. ..Mw...8s.Wch.%"k*p..s.
...Sd...#..*...44.xT|K.I...\MK" ......U.....>....< .V.\....a..F
.O..S...d.K.r..8..c..I.....&.k....Ks..z;.....\.=6/N...Z.DVeJ,.....Ue..
...doLl..}2... ..(h&s...... ....... Kh.8..r.bXX^"~<:..k...0...Yt].d
._*...".......|.h.....$.C8...|......|.s.I.........rA7`.*...~..q~^r._..
-.W...0^.A..(5..*Ib..y...B6... .O..d..B....J.....0...0(.u..<u..)f.?
:_/?i.3.....3i9jk-.(.<_.n._L...#B..w...VASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCAuOMxMgoIBBCAuOMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..d5.....ASU!VPSz.".
.....r...v...x...uQ.c``.p5............\-Y.&..:].....`.m....@l.5..2#.)3
.9&sf..F'....L%KBX..R.C.J.....xsX.JR r.KJY.......2....'..1...>.3.j.
e..UL....'C..n.a.i.p$f2 -LGV(...........".......}.....ASWSig2B..0..ont>....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCmuuMxMgoIBBCmuuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..e5f.....ASU!VPSz."............
..x..W.4....nV..$...".!#B..Z.!BH.....M.!.Zq.l..gd%%.6TJ$.]R....=.}.s.s
..>..<..5..<...`.uV...P..f.)J....yPp..G?\.=s....TC<R/x.AG.
....N%...oa...n...`..Cq.A.$...v...T...K.u..n.A4.?SF6..|t j..(....W0...
kGh..U.../X\..t.[.a...z....E;."..^{...z0`.mw]dg.....aZ.......-....~Q.H
........HGY)Z.6.4N....Z..I.)..t..1......~1.$sQ..ZZe.8....~..u.j.0^S.(.
{.......?.....9.~.[M*Ou.wD.,.yH.J..5..{.S....7F.--J. ...R.d.w(`6.F..&l
t;......)...U..".W.D....C.ZE...K@b3.w...{o...@[......./.......-..^...[
...i.pd._.`...f....~..oeC..l..9"-7.8,.V..e..*U.c..QQ....a-..eC.....>
;x.ncfg.....{..,..kW.....~.....e....h.J...n..oe&V.W..Ycy...e..........
:\\I.W...tO.....`E..Wf ....{D.h.n G...)>...0.....q..k.P'i..~..F...D
.E......-...........998.z.H...f8..F.....G......,...D...8....%.Xa..6O&l
t;ND.......Zcl......CY.s.^..\.K...`!?.p...%q...K^...T....o.....q.;....
.6.x....?.-I.........~.R.Tlmi5L......u....e-...>..X.?rWL..Vk....Y.J
U..S....)!./........)[;(...u...)...(.G...>...._cG....^..a.E...Y#..\
...Rz..1...F......h?Lw[W......M4I.H..).mX...:..K....I@..V. ,.=s.r<.
th.i.c..!P^.wIr'2Q.....f........=...~,..G..A{9.....&O1......J.{.....b.
k.k....VT/wnDL......!..l!?U...%.7=.i.u..#...>.@X_....u.............
."/.......ht....V.....<.6.r.x2#..#i..O^.xE.Nk...M..m,r.t..(..jL....
..ZJ.HW ..4..\...3.tz.n..}hq...hq..]Y.4..../*....T...x%|v..I.$$<.Fz
....s.<nv.g8.........@%. ...P=...y......lL.%<....Z...u....*.I.-.
..-.g....e".y......h.../.N@......o~..v..E.0jV..Z...0...j...^....j.

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC_vOMxMgoIBBC_vOMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..de.....ASU!VPSz.".
.....{.......x...uQ.d``p.0..d..@ V.Z.P..Q.A...Q..A.......O(.E...(.19.!
.A.J....!.......b........P....".h.X.....4...H[.H.-*......=4...{...V..,
.(<Tx~RSrb...:s.....V..AX..o....,5V....&H.........#|:..{....ASWSig2
B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDWvuMxMgoIBBDWvuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..b7b.....ASU!VPSz."..........*.
..x.%Vw<....N"{...B..:e.".D..$.....3.Et.....:.D6.:. ......H%.......
.y...a~...6....r..O#^df..b..$..w\\...hNb..............g.@.\........_..
K..F'.....F~?k.>!F...?..n..8..D..|..6./L5H>....>...9...S..Z5.
[aG..V[...iX.:.......Y.5............L.4;...`Y...'.p_.u..2.O$.}.g.....L
.d....&b...3 .o.<...F.Q`......_$'.?.1..]9..;....@`r....R..r..1U...1
.%......xF0...q...=...*...............g). ....NR]....>....E...0.=.x
.>N......A.....ZC....k...|.*..SJFP?...@].q...6.......7.....KN.1..s.
@|..=Z.$..._>..q.'.'j.@..A:..%........U...i).....wL....6P62>F.n.
.....'.....n....u.=..GX..)zW..../..<.]eP.3....#a..!.X9]L.......j_..
r.3.~.t.y%Cq..&......b ..%k.Z.....2...,.}......4../......f.(0..P.....l
..GK#.?."Gf...6..[No%.....%.AK.....}xh?\..J#..;.<.....z...Z..-u..F.
.I....z.....>1].rq.....O&.........8...H,a...i.k.[..B..*.4D..R......
~..'.:...T.V....h.....O{...w._^.<>.1e.....V^._..n,g.Kf...8.;...
.t..`\..iA.#..E?.. .t]..M...?...q.;<...).&......T...k....2....w..##
~...e..*.qP..<..:.0W....dM;O...........l..S.*o.._......{.|.......d.
w.Y.^.?.,...Sd. ..T....,..l.z.4a.)..9.............l*.h.i)...4.S...m.6.
.8.a..e.']...... .~...N..Pp.y.......V...r.........8D...x......M.LN.M.Z
......!.~fx3...BE.r-.F....NK......j...&....4....PKj.!......N..2}'T....
|@.....W...7...9@.}X..~. k.).......u?....v..).-..-..yE.......6.......n
.?T.$F......~y..d..9...e...B..j.3.hB&a.....Y...g.......4....-.*.:uG...
..C).,.-.2u5..}..~.VJ.....;..............q.Tr.s.v.</..y..1.)6..

<<< skipped >>>

GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDPx-MxMgoIBBDPx-MxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..9a.....ASU!VPSz.".
.....7...9...x...uQ6d``p.0..d..E V.Z.P.....A.......!....!.!.!.......G.
N.z...jkt..C..D@>...G.....G.0.fQM.........(...Y.....2....N6...ASWSi
g2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDqyeMxMgoIBBDqyeMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..a3.....ASU!VPSz.".
.....@...B...x...uQ.b``p.0.6b..- ..Z.P..Q.A.1E.A........%...A..^IjE0cI
=..#...'.1..o(#.y.l..Ep..YaQ..H....m...YSl.B.Fn.r.nk.;./...6../LY....8
.ASWSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBCozOMxMgoIBBCozOMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..2c6.....ASU!VPSz."
......c.......x...kHS....s.^......h...V..f*...|..oW.S..\..JS...G..51..
..64..G.#.r.JJ%EMY.d..>ha.mG..?..y....#...H^.....x...O...pF..@..;..
.x...D...I...n..^.../.mU'.(Qj#.~...;0..v..&...q,.e........L... .2<.
..~......U..D.h:. MM....i....hi^....w..R..z.l;Z..d.!. ....7.jA[;\....7
4...J.P%..;......6*lQ8\2.f....G.G....v. Z..1...t..bT.E|4[Lf...@..w....
..&.r). ......s.m/..\.. uL.......s...$....MH.....;9yUc.T/Vq...mh#..Fa.
....b...C.*/fXX...-.7c{..e.^...|..W.<.v.....4...e.].W|.E3u..6....gc
.L/nB..cMRB..?.....[hJc..&...........%...j.|@....~.S................F?
}.o..._^H.....zf.f.3u........./..p....U.....K.v.........p......,".....
.2..PQ....N_.,....%F.S*Y&.^h.-...l..R.Y..]Z#..]....O)......C.1..4..rAS
WSig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBDJzuMxMgoIBBDJzuMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
HTTP/1.1 200 OK..Content-Type: application/octet-stream..Pragma: no-ca
che..Cache-control: no-cache..Connection: keep-alive..Transfer-Encodin
g: chunked..22... ......2.......1... .....)(.....)..9c.....ASU!VPSz.".
.....9...<...x...uQ6a``p.0..a... V.Z.P..Q...).......93C..=..C5#K3..
P....g..u.h.,i......F......V.V.4.._)J&..D...1..|{\..I.i..hkWR1..e2.ASW
Sig2B..0..
....



GET /R/A28KIDFiOTgxOGEyMzc4OTQ0NDI5ZmMzNzE0YTZlMjE3ZGFmEgQBIwQVGKwCIgH-KgcIBBC70eMxMgoIBBC70eMxGIAKOKqRiFBCIAAAAAAAAAAAAAAAAAAAAADRt2NBVVUWwYrJVKOQyFlrSICDmAg= HTTP/1.1

Accept: */*
Content-Type: application/octet-stream
Pragma: no-cache
Connection: keep-alive
Host: su.ff.avast.com


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Pragma: no-cache
Cache-control: no-cache
Connection: keep-alive
Transfer-Encoding: chunked
22... ......2.......1... .....)(.....)..ae3.....ASU!VPSz."............
..x.%Vy<._.>../Y.U..!.".K1bze.ED..f.$..$.d.RdK.h.%$[b.Q(Ke......
.........{.}..<...j........z....H,..K..5a..|...e.:&.....R....Az....
.O.&E..1la.^.............;........V`O...a..D.F.....\.U)v...;...F.X.t.I
..(...z............-~..w..d2z!.w.....#...........W...|S...G.-wP.9.....
...B..Tc..3T..,Q.....] ....0.....js.M.........z.8...v:.p.W.x\.....s..z
.G.C7.Y..x....V.*G..%..uM............R.K..e..&>W.:..'.U. ......'..
..k...VGT.B.Y.Q.V{..2.R..4....8....6.....x..X.g..l.....la...........|d
..(V.[.1.u7o.2%..X......."].SZBj..R~*wc.gh......1.-.ZE..(..- :[.......
...Q.....c.........?.....'....Z.y!.Wc.F.:..K..[.....`5.......:.kk...mN
r....}...NV...%W~RX.Y.$RU.l...aO....3z.G}xD...x....p4.U......T. r}G...
..........l........H...G..J......o......v...i..u....U.d^e...d....]0L..
..^7x...=.."R.e...p.Z1.$n4Y.8...A.. ........%z\..].Hi@.f['..r....C..&g
t;.3`.g....#5.X..uX.....x..1c.C..."'..-o..=.,.....!.`./G6..2..X.......
_.a.@..V......?O...4jG.Vn3e;.................M...y...R:..4....%.>.Z
F-.%......i..}.`?V. ..............N../O#....5..=...F..9.....}.!CK.@6..
..r..|.TX.3..@.Ik..f&.g..S.'.U..b.O..g~6qU.a....uS.#_N....{...6.f.....
x4@...wB.}...v.Y..]....u..$..}............%.r'....R..&j......9...../.5
".O<..B...?.. .g=..........'....k......e_..0.%..z.\....z...ph...<
;..Z.Z>.[H#.l..-u...`~...V ,.z......[.x....p.A.....i..3s:BL........
r.....}...M*,X...F.......ny..G.;l.#.s...?..$..].q.6.l.....?....4R*dLb
....#s/....<..A.s...)....S.@...Y....43fJ....Mj.2w.........(.NC.

<<< skipped >>>

GET /files/emupdate/patches.ini HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: avast! Emergency Update Agent
Host: emupdate.avast.com


HTTP/1.1 200 OK
Server: nginx
Last-Modified: Thu, 23 Apr 2015 13:00:37 GMT
ETag: "5538ecf5-11b5"
Content-Type: text/html
Content-Length: 4533
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 10:01:25 GMT
Connection: keep-alive
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
[Patches].229=hXXp://emupdate.avast.com/files/emupdate/20150112.exe..[
Patches_dll]..[1451].105=hXXp://emupdate.avast.com/files/emupdate/2012
1107.exe.110=hXXp://emupdate.avast.com/files/emupdate/20130515.exe.120
=hXXp://emupdate.avast.com/files/emupdate/20130604.exe..[1456].105=htt
p://emupdate.avast.com/files/emupdate/20121107.exe.110=hXXp://emupdate
.avast.com/files/emupdate/20130515.exe.120=hXXp://emupdate.avast.com/f
iles/emupdate/20130604.exe..[1466].105=hXXp://emupdate.avast.com/files
/emupdate/20121107.exe.110=hXXp://emupdate.avast.com/files/emupdate/20
130515.exe.120=hXXp://emupdate.avast.com/files/emupdate/20130604.exe..
[1473].105=hXXp://emupdate.avast.com/files/emupdate/20121107.exe.110=h
ttp://emupdate.avast.com/files/emupdate/20130515.exe.120=hXXp://emupda
te.avast.com/files/emupdate/20130604.exe..[1474].105=hXXp://emupdate.a
vast.com/files/emupdate/20121107.exe.110=hXXp://emupdate.avast.com/fil
es/emupdate/20130515.exe.120=hXXp://emupdate.avast.com/files/emupdate/
20130604.exe.246=hXXp://emupdate.avast.com/files/emupdate/20150106.exe
.249=hXXp://emupdate.avast.com/files/emupdate/20150107.exe..[1482].107
=hXXp://emupdate.avast.com/files/emupdate/20130304.exe.108=hXXp://emup
date.avast.com/files/emupdate/20130419.exe.110=hXXp://emupdate.avast.c
om/files/emupdate/20130515.exe.120=hXXp://emupdate.avast.com/files/emu
pdate/20130604.exe..[1483].110=hXXp://emupdate.avast.com/files/emupdat
e/20130515.exe.120=hXXp://emupdate.avast.com/files/emupdate/20130604.e
xe..[1488].110=hXXp://emupdate.avast.com/files/emupdate/20130515.e

<<< skipped >>>

GET /files/emupdate/20150112.exe HTTP/1.1

Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: avast! Emergency Update Agent
Host: emupdate.avast.com


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 118336
Last-Modified: Fri, 23 Jan 2015 08:53:13 GMT
ETag: "54c20bf9-1ce40"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 10:01:25 GMT
Connection: keep-alive
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$........19..PW..PW.
.PW.f....PW..(...PW..(..nPW..(...PW..PV.BPW..(...PW..(...PW......PW..(
...PW.Rich.PW.........................PE..L...u..T....................
......................@.......................................@.......
..................................................x....'..............
................................H.....................................
......UPX0....................................UPX1....................
............@....rsrc...............................@.................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
.......3.91.UPX!....8G.....s.l..........&..2....j.h...;d..PQ...x3.P.D$
.d.....'.N4..~$4..u;j..............F....K..t..@......k..#.@....3.C...F
$.......P...@..u..N$ .PW..%,.L.......kY.....?.....N ..~.u/j83.....P.X\
........R...L...pjl.JsA....3!.. u,.I..I....`..P....N..j...".=)...b....
..d.........d...h)...".?.PI..8..`.....=.....?..)@.d..H.J.......d...@.d
...0..) _...E?.V..V.... .$..J.}......A.}....^.F;.u.AQ..*..............
....H.@...4G.....40\.T.....rQ.4....3.....t.;.H..H........j.b.J~.%,_. J
....l..?...-..$d.SUVW@.Ph...?....j..c...h...t$0..M.^. 0.*....$....

<<< skipped >>>

GET /files/emupdate/updates.xml HTTP/1.1

Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: avast! Emergency Update Agent
Host: emupdate.avast.com


HTTP/1.1 200 OK
Server: nginx
Last-Modified: Fri, 17 Apr 2015 12:16:13 GMT
ETag: "5530f98d-2c4f"
Content-Type: text/xml
Content-Length: 11343
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 10:01:27 GMT
Connection: keep-alive
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
<?xml version="1.0" encoding="UTF-8"?>..<aswmicroupdates vers
ion="1">...<condition version_c="(=)2000">....<update url=
"hXXp://uupdate.avast.com/files/emupdate/avast9_0_beta1_update_1.cab"
mversion="1" info_url="hXXp://VVV.avast.com" />...</condition>
;...<condition version_c="(=)2001">....<update url="hXXp://uu
pdate.avast.com/files/emupdate/avast9_0_beta2_update_3.cab" mversion="
3" info_url="hXXp://VVV.avast.com" />...</condition>...<co
ndition version_c="(=)2006">....<condition mversion_c="(-)8">
.....<update url="hXXp://uupdate.avast.com/files/emupdate/avast_9_0
_r1_8.cab" mversion="8" info_url="hXXp://VVV.avast.com" />.....<
condition mversion_c="(-)4">......<condition os_c="64">......
.<update url="hXXp://uupdate.avast.com/files/emupdate/avast9_0_r1_6
4_4.cab" mversion="4" info_url="hXXp://VVV.avast.com" />......</
condition>......<condition os_c="32">.......<update url="h
ttp://uupdate.avast.com/files/emupdate/avast9_0_r1_86_4.cab" mversion=
"4" info_url="hXXp://VVV.avast.com" />......</condition>.....
.<condition mversion_c="(-)3">.......<update url="hXXp://uupd
ate.avast.com/files/emupdate/avast9_0_r1_update_3.cab" mv.....</con
dition>......</condition>.....</condition>....</cond
ition>...</condition>...<condition version_c="(=)2011">
....<condition mversion_c="(-)23">.....<condition os_c="( =)6
.1">.......<update url="hXXp://uupdate.avast.com/files/emupd

<<< skipped >>>

GET /__utm.gif?utmn=41&utmac=MO-1405551-23&utmwv=4.4sh&utmp=view/fa-2015/en/intro&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=- HTTP/1.1
User-Agent: avast! Antivirus
Host: VVV.google-analytics.com
Accept: */*


HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 19 Apr 2000 11:43:00 GMT
Last-Modified: Wed, 21 Jan 2004 19:51:30 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Wed, 15 Apr 2015 19:43:29 GMT
Server: Golfe2
Content-Length: 35
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Age: 742513
Alternate-Protocol: 80:quic,p=1
GIF89a.............,...........D..;..


GET /iavs9x/ais_cmp_grimefighter-7eb.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 2660370
Last-Modified: Tue, 21 Apr 2015 16:27:30 GMT
ETag: "55367a72-289812"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:11 GMT
Connection: keep-alive
ASWsetupFPkgFil3q.g...(.].....$.....*o........`....z.....zHg.O.Y..,..n
.>....S...}.X.OB.-.Z...#B6..s...^..<....H...J<......Y..@\..I.
....lR~..w....>#i...?.G..]...D....m...j..$W8...@.;.Tz...~G..P<.-
1i..u..l'...,.....:..c-sM.........k@.c.A....{..,.[n7V^.......!V .,Ng;.
....F.\v..._......u.j..{b\DP.....mF.x..N:..Z.....d3!=.j..#...I........
...P...H.US.. 28.............(.s.S.RV.3.8.c.y..*x...{.g.hAZ.....E....,
.)6f}.16. .(.o_...q.........m.7.p....Y..Y.Vd....1C=,.U.Nq.Y...4.x..7s.
.J.B....vtR..[b.R...$....EY.#....Y.m4.c.......m..A./:...B....i.XV.C...
.8...LI-..t.....pR............jJ-._..S...NB.tt.<.}....!.X...x...}..
...{..%,....q.....o...5..A...|..."m..F2.....VlZ...p..E.m...5....~IO..0
s.V.O..Q.y..^.. ..Z>..... O.v.7.I.... ..v...%\.A.hS.E.h....'.0.Z%.
Q.........s..........0...B.....U^DoS..8.?......$....?. ...M.:..k...v..
..9./d..QL. ...9.?....U...<.aB...&f*.Q..~.......j....K...H..6u....-
.z...>..D.s...(xB.uU.P`b..L....7..2...'-.....b|.h.:.j....y..u$To.mO
.P....i...BYY..A..yw...q.*.[(.........jKr....1..F[.&..qn...XQ....6...N
y.I.m.>....<c.7..H.4..o./.YP.....x.T.q.........'....3#.g.......t
!...o...U... B].mw...$%K..c.[Nus...... ..k........h)....t...]8..."7pj.
Q.|e.P= .....'...w..2l.=...f..)....n.%O.F...P*........n....q.8c...m..@
... ..{S_...e]L........6..d....P$,.w._..x4e..>.akcz.D...!.......%..
./x.....\.y..-.1.....\...*.j..@a.'..a.Lj...;j..b.....=.w.....R........
K..D....rS.C..l.........e.&.....[.Y...W. ...9="...n@m...*.Z..=...E...R
...J......U..3)...N.....dlh,.<Vo....VP]z...}.........3......bd.

<<< skipped >>>

GET /iavs9x/ais_cmp_bpc-7e5.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 653563
Last-Modified: Tue, 21 Apr 2015 16:27:22 GMT
ETag: "55367a6a-9f8fb"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:10 GMT
Connection: keep-alive
ASWsetupFPkgFil3.0!.....].....$.....`*.{.Ky...........W/.. .....iX..j_
.x..G...5....=.;.K.....#...H....G.^.B......]...!p.j.....#...n.34AC.a..
V.A...........n..DD..uB.....XJ..tw3.v...f...'@<PiX.^.X...]f._....p.
4.TG^ ..Ta.i_.3.f=[.^D..#...JZ.:.G...~........0..c}.4..o.../m.y.'.z...
.I...=.d.f.......8[.._..k...5......h..K(.j..}.~8H.d..Z...........&...:
.Nd....t..vl.^Mh.i.n...Ji.o.3.)5_.Be-.....W...=.nE.....8"=...=..-T...)
^..br.fAX.,v...6fM..(A...]{m!...LtsZ;...l8P.K,.?\...6.........%i...%6.
....1iF.Sx........?...Mt.;....s..Fq...]r.....8fx....h._!...w..;.Q=...i
.Y0=./3a..9=X..Y)h.k.g.........\.xOS#&....Ts.F5..l...f-.C.J.......l..B
...o.Z...R.|..s...g..@k......%....<.iQ...Ayr...K.F......9.N.. .a.B.
."..v.0L[.....Y..}F...b;.@.....*.....X...%...Rv..(Z........M"5........
.#..=@.....g....._<.{'-.........:c*.]W.. .....=...P..^..".......X&l
t;l...D..2t.........n.B..=........#-.....>..O@.=......r....on.... x
/Q.....a......mX.(.._./......l\...I..I...LT2.E......#.%..D..:.$.../...
J....M.P..kA.........%0#.f;.L..f....7.......... .vu^EH..c... ..0&.v...
.W.].mx..eR....>H]wP*[..}..U.{aI!.5.....gBK....._4..#NNQQ..3ka8....
.Lm.nqai}.S>.:eUm...<....g.....c....q$.t.....9l:...C.....8l.v.R.
...bgk.R._..?.| ..jZr.....Jp;.....".v.t.h....C.cH..n..H..2...U.O:....x
....56|pR..t.... 6.O.K.D..}Z.7.....H=..!..C.....J...I..(m. g.etd.....p
.( P...,.M.p.....3R....m......-.}a..F...=...u.b.D...>.{x..^......Z.
h..%.>.P.H.....6........;pqy....v0L...i.....-.............v.b....&g
t;..4(.........cx....a=r`~hQ....Y.........H.S.x.........O.....'.'e

<<< skipped >>>

POST /F/AAEbmBiiN4lEQp_DcUpuIX2v HTTP/1.1
Accept: */*
Content-Type: application/x-enc
Host: vl.ff.avast.com
Content-Length: 81

.n.%.....M.[....B...k..,.%.#.Z..jc..M.....m...,...bB.. ..E....65.g.-.a%..p.WS...]
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 26
............( .....)0.8.Hd..


GET /iavs9x/ais_gen_streamfilter-7f5.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 209502
Last-Modified: Tue, 21 Apr 2015 16:32:24 GMT
ETag: "55367b98-3325e"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:29 GMT
Connection: keep-alive
ASWsetupFPkgFil3._...1..].....$......2...........~...7.iAp!....[.y./o.
........s...'nY......~...m.J..LP.t..../.....$....;..b.5.....]H.x.m....
..Tj...........8[.!D.e....?.}./...K..a...X.P~.; N..QQ4....%<.s{.6#h
L~^.w.'6..v{...q:=#..eA........T..c....V.i..`..F..:..D....&...5T......
...9LQ..em.=....t..l.n........l.d...<%..Yy..T....:......L...mb....s
.4:...GVWC;..jd6cmLG...._X...E.v..[{...g...k{.....f...~D. :&.'....<
t.d.K.......0......D..U.T.l.....!t.L<.`U..wN..O=As.-..d.3..v.iR..Ug
.e.x.; .:.../.-.F...`I5.....H..t=1S.LE.........h.Z..'>8.....].Hn.v.
.e..w.j[!.70....._zQ./..L......@..*.iC...$.Y.V.3...g..p3.j...lt.......
W..%.....O.<.5....z`........Z/s...`..6..4......o.....u..F.M..*v9.c.
QCe......b......w.7_.T.....u.p.V.|..z..(..0].7.1I...X./.|......EWVL.k0
y..w...|?7zl.H.......j..;{:XyQ....fh...?..3................'.S[T......
..J......_.....>}.=F....jCh.2.T-...g.......C.m.....}..#.X.D^`-..O@9
A..&..'..c.IS....<..Q..fF\...r...Z..Y...KE..k.L..|..k.....X.J...2m.
u`.[v....V.>...x...o....&.{...;. 7......y...}U.........=$.-....x.a.
A./5.....nW....4..........4.F...u..=W.<...5.6w..1.....f..p( .....=O
%.J.O.'Hq!..h...........0.gA..J(zf_[{....).>..Z[......../.X..f..0w.
....^.........~......._k.[...9g.S......t8 >&..<..k..o...'...gU!.
..o.H34.@.T...Jk...(.n......Z.JR...........V......H....M..V...v......M
.:{....t}l.\....j.-...&$....3 ^....s...`......u&..,...D....t..@.Gg..[*
P..q..s.....vrr.Z.......>.`....*...C. ....@v...q.'......8F. .....M.
AS..m......]....L...............O.Q...1........VI...*. ...I<.Z.

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEALE0eWKSmgMVo2jBH5+TV8= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.digicert.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=516297
Content-Type: application/ocsp-response
Date: Fri, 24 Apr 2015 10:03:05 GMT
Etag: "5539dd2b-1d7"
Expires: Thu, 30 Apr 2015 22:03:05 GMT
Last-Modified: Fri, 24 Apr 2015 06:05:31 GMT
Server: ECS (frf/87D9)
X-Cache: HIT
Content-Length: 471
0..........0..... .....0......0...0.......>.i...G...&....cd ...2015
0423200000Z0s0q0I0... ............(..A...B..G@B.X....>.i...G...&...
.cd ........Jh.V...~~M_....20150423200000Z....20150430200000Z0...*.H..
...........I.u.or2......]...z..z..&.w....:...@.a..."U..._).YGqx...k...
.zd]F<Fe&].....:Z...Nn....3........>..Z. #...%j:.n..Mm..X..m.p.$
;..T...../..9...F..b.,4....r......8_.=T~'.E.qw...N A.~...;..|.l.g..Y.D
mO .......b,..;y.-......&.S.p..{..y.............u$.s...toJ[....

....



GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRm/rYSaqNr0YBIv29H4pMHhv2XmQQUl0gD6xUIa7myWCPMlC7xxmXSZI4CEA717Ke9Mc/Dp/jmJZtCM1k= HTTP/1.1

Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.digicert.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=507591
Content-Type: application/ocsp-response
Date: Fri, 24 Apr 2015 10:03:05 GMT
Etag: "5539be32-1d7"
Expires: Thu, 30 Apr 2015 22:03:05 GMT
Last-Modified: Fri, 24 Apr 2015 03:53:22 GMT
Server: ECS (frf/87C6)
X-Cache: HIT
Content-Length: 471
0..........0..... .....0......0...0.......H....k..X#.....e.d...2015042
4033800Z0s0q0I0... ........f...j.k..H.oG..........H....k..X#.....e.d..
......1.....%.B3Y....20150424033800Z....20150501035300Z0...*.H........
.....MN.r.J.a.......9......ePk7jp.......n....a.5.<..f.uj~u.V.H{...M
..T......[..O...B..o..q/.....[@..A.`..N@...6.0..`.{g.>.....x..V}R$.
o.:.......w..X..}..............[u.U.m..*\H/(q...x.9..8..w....y_.....O-
......^l(F7....f.6kk......x.%.j....l. .J........[&[..Q.o...


GET /iavs9x/ngiodriver_x86_ais-8a7-8a6.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 256
Last-Modified: Tue, 31 Mar 2015 10:59:23 GMT
ETag: "551a7e0b-100"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:36 GMT
Connection: keep-alive
ASWsetupDPkgFil2.(F..(F..................(F......(F......{...x.s.v.ts3
10`..=(......2,..#..#....30.^qH.`p`dp`P`P.0kfhk|e.{R.....W.3..k.B.....
1.``...........7.>....rr]Hu,.../r.......4l"....%"u..o..............
]us%.....>......eL..:l.....i.',.....[....ASWSig2B..


GET /iavs9x/instcont_ais-8a7-8a6.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 1610
Last-Modified: Tue, 31 Mar 2015 10:56:56 GMT
ETag: "551a7d78-64a"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:30 GMT
Connection: keep-alive
ASWsetupDPkgFil2.@...@...................@.......@...........x.e.i<
.....3...6c..sL..c..{.[F.....16..uN...>J.1(:D.L.J.k......J.rm.].O/.
...|......y..M,..@Uu.;S..j(..M.N.j..\..]V.vo...*.&.........R.F...{..Z.
....../.?......$8...S..m.]...fr.v/p.C...}.VU.].>..)....S*. .;B(..y"
@x.1!.Z.^Lfe........F..X.!g^N.Rw..!....../.t..zT. ..A..%..j.y.X..f....
....8.#..k.e..x`...*A.0...e.9C.^..?..U..-=#.S......o.75...7..j}7......
B.4V...t(!^v.A.....kM........g......e9:.."...'.C..l....{6.7..{m..99...
z...8;.o/...<........l$.. .......Y..y.}=......Q..7..0G..N..F!..Az.l
.......2...r..>..c..K0...<3..<dS2L...~..mkHg...a....$..]....]
..6..s.=*-.....o..6.s..>.DK|.pk.8...\.'{0/..U.N...n.K.x....|....9..
.._l...`L.........."..6.lU......eS.... ..F.<"Vb....f.....7.=...g...
..%..c...9......}5#l....G.....Mz.t[.Pa.....v..6.I.7f.. .#fT.Y)#.k.....
C...."......U.:=... I_....}.=../...K..3@.0'....Tdr..>..a2.N...K..=.
...x......... .T.-..U"E...i.I.. .r.......\{.......d_&*...g....l..Z....
......Q.....H.x.. Ij.s..q.sh.XCp.^......_..%%.0U.....,3..`._;.".J..?.O
_d....$.....o..O.dl..fF[.%.0.J.8!...~=,e.r.c.....Ay"%/.>..........)
3.......;.$.Z#..v....o..:..|..u.....S.yp...jl.._.......l...`C.....jJ..
/ouQ`E.....8...\ja .J.Kf...%5mRdo._p./.....Cs...!.~G...Qr........F....
.|...z.Nz.`qo....l.k.F.5......5..8..^b.(#.../.i.".\3B.a. ..VB...&X%.n.
E..3..W..<.G...<..2......&y7S.?..bH.}.....C.{*U..#....kv...;.g,.
8.......K....u...B..B....9. ....p...b;......MQ.M....u.........2......F
.....d....c...H......g.M.F..1&L.JS.......4....OH>.z....Ez....P.

<<< skipped >>>

GET /ivps9x/part-iex-4.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: c8884169.ivps9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 232
Last-Modified: Thu, 23 Apr 2015 17:33:47 GMT
ETag: "55392cfb-e8"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:25 GMT
Connection: keep-alive
ASWsetupFPkgFile........x..pt..```.s.u.....9...y....n.@..i....?...6.=.
i.i.Z.......-3.....M.b..k........p.w.......7....I.....s........7......
' f..o....P>.......GD....^>DCb40....um.. ........~?...!.d.4.P...
. ..m.F/..Q.........ASWSig2B..


GET /iavs9x/ais_cmp_webrep-7ed.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 1776375
Last-Modified: Tue, 21 Apr 2015 16:30:31 GMT
ETag: "55367b27-1b1af7"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:15 GMT
Connection: keep-alive
ASWsetupFPkgFil3..j.....].....$......S...........m)hj.\%..wvE...&.j..S
..~.}.T.V.R....i.2......T.....YB3..*.|ez..Z..3.}..:..=.<.,3.ZPOJ.e.
..,.EcB. ..c,..~W...T...(..?...o|.zz$..[bb..4ott{y.....?(..].qM.P...(i
`.8..:nx.3.L.H........$'...<...].xv,4.]..E..'..........=?\.>.. .
.{.. ....dp.y%.0.A]h.Vq"uBA[...;..].......g7....$.o..c..a...TO.m..W.*R
..7s..S...n.1.{r...oo6...>....`-.......{$O<..Fp.........!.I'.*.L
Go.`...o.........(L\.m..%?/%.<.ZM....Wr.....G.!a.{..*...).....<2
..[...1..pJ...|..!d......B...{..y)8.@NR.....Q.%..>C....... .L.-....
o.:"#...rr..]\...}.Nk.....4oG../.Pc)A...fQ...X..B/...5.......5...].^ e
?..?AZ|b.!...\{Y...C..zz............Y.K_...?F.j.. ..Nu4P.@..s.......WB
8ej..[.!........G...."4.wtV.......t(..:.%...$.nG&..;...3.H"n..r.......
`^......h...)......MZ#.S.....I...^......*F.i.,.o....}..j....H.....D..;
I7#4.B........j.........`w1.o.Fy........_....7...;,......x.=..t,..xm1}
=G.4@.2.a.....<,..H...Uf.m.....o.T....%...Kt[...MK.C..'DO......b8.1
@#%X..B.<..*. .....E..bE...'./...VV..........ts....zk...}c14*.P....
T.....7.......u?4..vf....._h7)@..k.8$..H.G^......Jj.03....D..>.9.4.
Ka.........f.....h....B..L..;S....YX.........R.S.k.a..).....pm...}f)..
..36.A.zZr....\?%..1.\%\.hv..KvHtY........3.....#....t./.G}.4..m`.].o.
.......(..4&...9.W.......`..u.3a:.....{.....e...V.9Du.;)$..g..... >
.]eL...M.H.H..Lxt.....K.K.H..5.]N...gFz.......,|N[.(O#J.zn....*.f0F...
M.. ...8..<-P..pB....8.{4.....'Mn..D^.k.G..$).'..].....&..........1
d.|^3....t.....#,zP..%..i.Y....G..zoY$.......$....|~.L.....1z.6.:.

<<< skipped >>>

GET /pki/crl/products/WinPCA.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com


HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Sat, 07 Mar 2015 06:01:44 GMT
Accept-Ranges: bytes
ETag: "dde36a309c58d01:0"
Server: Microsoft-IIS/8.0
VTag: 43879645100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 561
Cache-Control: max-age=900
Date: Fri, 24 Apr 2015 10:02:04 GMT
Connection: keep-alive
0..-0......0...*.H........0..1.0...U....US1.0...U....Washington1.0...U
....Redmond1.0...U....Microsoft Corporation1 0)..U..."Microsoft Window
s Verification PCA..150306223202Z..150605105201Z._0]0...U.#..0.......p
............<.J0... .....7.......0...U......40... .....7......15060
4224201Z0...*.H.............4......n[.t........'....Dx.P3R.!3.|D.6vL..
"k..9'....L..k......e.4......._..N..TJ......N.fP...H.....8...TJA...fGA
.e...^"{../...H?..E.Y.U....h..0/.......d...6..K..V?QM...{..h.....{.3..
.v.....\~.7n..5..'..k.Ia.YL..LP.b....._7.V..%......z*$q..Y..f.b..L8<
;~..v.w
....



GET /pki/crl/products/MicrosoftTimeStampPCA.crl HTTP/1.1

Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com


HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Thu, 05 Mar 2015 06:01:35 GMT
Accept-Ranges: bytes
ETag: "cf2633d6957d01:0"
Server: Microsoft-IIS/8.0
VTag: 43853244400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 550
Cache-Control: max-age=900
Date: Fri, 24 Apr 2015 10:02:04 GMT
Connection: keep-alive
0.."0......0...*.H........0w1.0...U....US1.0...U....Washington1.0...U.
...Redmond1.0...U....Microsoft Corporation1!0...U....Microsoft Time-St
amp PCA..150304221607Z..150603103607Z._0]0...U.#..0...#4..RFp..@.v.. .
.5..0... .....7.......0...U......20... .....7......150602222607Z0...*.
H.............Y..}y`....T.Z..`B<..I.N..O... E:....7......a..)......
...._|W5laoqi(..>t~.."...&`.._.7J...:..{bO_Kyi...R...!...B.s..I.c&j
...(I\.S{._;@B...[i.e.[."...R` \...........M^k.=q[.V...9y..G.1o#k3<
.W.......H.$>}...U...2qyd2|b.fB.....r....H.P...;....Q...b......5%.P
.#..


GET /iavs9x/part-prg_ais-8aa.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: v4142311.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 11528
Last-Modified: Tue, 21 Apr 2015 16:34:24 GMT
ETag: "55367c10-2d08"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:24 GMT
Connection: keep-alive
ASWsetupFPkgFile.G...,..x...w<.m../...&[.lQ....Y.{..%....(R$ $..!#e
.D.."....].y......q....<..u|.}...{.t.H..P(.5..t....d...o......b..(o
.s@K..o..g4Y...G/........\......4J.....X...(.....E....;r"..[..b...=?..
.R...76.F...1.uO...G.OD(.G..D.)..B.w.y....ENK.._!...........CNv2....|.
JN.%.....W......aCI.....Xs.'w)..eh3.Vq.... .W.e.rIGf..c.5O..i!..U..'..
.y..r1.&"......D... '...ZD.a*.j.9.IEP3.y...j.9U..Pc.YxM. ......N...(J
~3...............J_...9M..a.<..................-.c...H.c!..BI...Sx.
y...L2...Z..v...;..}:....N*....t...OL...=.......U......;..HM....]..G..
.x.. B._"8{{.y{.o.p.d.(........-..A...'.8.....G....D..7....'j".b..6_.E
......L{....L...`..N.@.....N...rR#.[...E4.q......<...W.h.B...A...x.
n.<-....E'.p..p....9=s.;..xG..7..)`...!..Oz.|.......EN..{..x.es..G|
..?.r....^.U!;M``Cu...[g...nd.*....!.... .\.B.].=|]6$.1y..i*.i.....t.S
..;..v.:d?..]OL6.8_.Id......&9.....oK.eG..`..... F..!F..5`...0Z....O..
;.L.'..^..V..'.P6...F..|..._>f..q...Q.....7Q..04%..*....6....$!..Iw
.*....P...B.w'..E.......0....B..y...b T.n.aC%F..........@..?...).o3.5x
..P...k...."..|............Pr..K.].......VH.I...{y.j..m..%. .. .H.....
"qC..z...".A.V... .....R9DZ...2 .....\.6C....k...&M., &u.E<!....<
;Y...";.R.mC...w&.3.......8.]x[.Nx6..J .U......@..H&....@..H?O..k.I.Z.
."...H....!DJ..H7 .5N.r...- ..e'..e...*c.U...........6Dl..(....D.3...#
B...B.6.R?.....".hc.o.;1X........^lf.@.y...D..%..c..D..R>:.S.......
.6D...>{,A.W_he.1KF...y,..'\.#.i2j......w.3~(.S.N..}N....e.'.e.....
z.\....a5...4...h..,..>~..y[...I...@."..4...h....|. .<.C....

<<< skipped >>>

GET /iavs9x/ngiodriver_x64_ais-8a0-89e.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 2132
Last-Modified: Tue, 31 Mar 2015 10:59:23 GMT
ETag: "551a7e0b-854"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:35 GMT
Connection: keep-alive
ASWsetupDPkgFil2..:...:...................:.......:..........x.E.{8...
....IN[E}1.6.|.L....13......^..a.DNM..r..g..W.o....Jd.(.xK**..a_W}....
......s].Cd.R.d.....,..u..2qO...K...P......H.........l5.a.|0..........
iG. .Y.z....r...O~.#.cY..W.P...ee..._..NR..).3.k..kh..%*).....r.L.S.Y.
.H}...*.....$..|(...#./.1.!.QLy".|.s.$'......l7....3...45I..x.*...f..g
M...Y.*Q...{-..i,.#..5...0In..D.6.....4.......} ../...,...U.q}.V..(@..
6..\i.........Xf.")..i.U....R....|.rN.I...F...Fj...>......1.44.j..N
..`..#7.!BKR.&.P.......yu..%.Ep....M...".k2...~N.....Tcri.>...q<
..JzO.# .......k...,q5...%qm.)4...9TdPfmm..#.50$..:..P.]..5.V....f..E.
..">._.7......&...\.....TQg.....lp...x..6..8..d...5L.....K...Z..;..
.V?l..H?[('..=...\.-.p(..........Z...CQ..J._....^......n.4F.uGv3.k..9.
..^-?.....G..emiI....K.o..~./..?.i......:/k.!$=..gQ.m.......sSr'8r....
.h.*"..v_.B.:Vw.....Ll\..A.7..6 i.....6_s....;.o....._..&.*.p...*_..W.
X.4a..F7V}.p..q.........;Co)......f.qEr-.WK.n...V.n.%.Dq{.KC|.n].i...w
E[o_....2<M>[.k5...o.........H..i...<.Cf.d....4(2.cB.Z.....2.
.y.....v~.p..<X_q.F.c.R...,:u..G?*Y.#.......h......9..A.%....(K^...
.6..>..QP.<!......?T\.0..>...V. ....>?..$..=3.F......]...7
.....K.g...$R..R.3t.A..U....d.WDg..J.?.......;...[...* ...O.._..;V.;..
.....8.rY.......')p.r.....("w...M...Kmm.}........).c.Ht.^./t.{......-.
N.....4.HL..m../..x.`.Q/...t6X........p....0.:...I_.:.........o..EJ.&l
t;...k.w.c...`i.s.r..m...-3.V_v].WQ...%...*>.u. ....{a..%.G/v..[A..
...[...............v..tgN.A..x..[;......Won....~.o.O.].;T.....L^..

<<< skipped >>>

GET /iavs9x/avbugreport_ais-8aa-8a7.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 173721
Last-Modified: Tue, 21 Apr 2015 16:33:44 GMT
ETag: "55367be8-2a699"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:28 GMT
Connection: keep-alive
ASWsetupDPkgFil2..L...n......0............L.......n..........x..TSs&..
.m..m....m.O..m.n..m..y...'7..$.IDT..%$...D....G..q.=..XD...YX.BU...E.
H3...E?.'(\9..V?(..........8..p.h..8z.5L ...$.3.HqG.......].z.......H.
.........:5.R...h.#.T..e..U......J)2.....E.,fVfl8l8..L...L.......)..&.
....(.".C.q2sQ).......Ll..hr..H%.S&.. .......K.....$gE.X:.c..6...5....
.*..W....h.Q@.i.-_he}a..H.$$$.cb%..e.....j.......tq.*7#?..[.i.......u.
..t.'...?V&."......2..q.."..7.,SF...\.3."...T._uY.H.Ku.U*..,...m#..[^.
....bH..,..h0.,..:t@Q.. 6.yQu....,.t..j....../\....j]..D..../..fp....f
...M.%6..N.4.xDB?s.d.#c.D.......PoE7.....h....TI]......f..&>IK%L...
.p....D,.L.v......"^.}.....T.$.}pu.LR..Y.,.A..V..&^.^9G.XS....>2<
;.E3O^@c.J...r..0:....$.@/3.x.i.5ZI..t.H5.........#......,.6>,.....
..lc...F.,..H..dD.L..G...........~E.,....{m.%j...W..U.<..N.m-..v<
;..I...".d?.. {vQT.`W2M.[=..*...n..].......O. ./H..V!{....8p....x....`
(..\...4.}...q.:d..-..ln..X.. .g.$t...g>.. .........F.4..YT....y...
.Z.\>..2....A...D......`er.:._4..B..........(E......c.....2Dq...?l\
q.E..'...e.b.............U.....:........0. ..E.....$..>3\qN.....5v,
Ua..o.7.v.E0...k.8..i.;..>I5,p..o*.)F...U(.P........I..,2..au..t-.'
,.@...../Mo.O.k...G!ROx.........E?...6.M..N..r.2.,.&.A..h4...8....].7.
.....2...b..*4:......'\*....... BI5Eb...AS.U.j..YF.T....p.......G<f
-.......1.W...cz.vk..2...<.;..F.y.H.5.m....M.@v.Xu..&I.....&......F
.)..Sz..i.W.*.U..7(@...>.ZK.......G5y%...9}..I..s...Q......"...1..L
..:...GBP....M..Q....f.Q..N.6.:......R..za)k..s.j..2S...@..k0[.o..

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1762
content-transfer-encoding: binary
Cache-Control: max-age=382189, public, no-transform, must-revalidate
Last-Modified: Tue, 21 Apr 2015 20:09:58 GMT
Expires: Tue, 28 Apr 2015 20:09:58 GMT
Date: Fri, 24 Apr 2015 10:01:19 GMT
Connection: keep-alive
0..........0..... .....0......0...0......;O}a.!..u...au..eUNp..2015042
1200958Z0s0q0I0... ...................B.>.I.$&.....e......0..C9...3
13..R...%V.......K3.....20150421200958Z....20150428200958Z0...*.H.....
........ M......-....d3c....k..y7^...=.....Y.........8.....M.rQ..C.9w.
.../.Q...{......@.......p.....a'c..&.[...;..<.....b......R..'.).E@D
n.Z)._b]..e.... 69. ....3.."f.p..l..k..../.qy..;.E.-.`e..y.r..{7.`..*[
.......1E.#^~U....6|C....u....vw...a..U.$...CP...M....L......0...0...0
...........2...'U.BM...g.B0...*.H........0..1.0...U....US1.0...U....Ve
riSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1(c) 2006 VeriS
ign, Inc. - For authorized use only1E0C..U...<VeriSign Class 3 Publ
ic Primary Certification Authority - G50...141202000000Z..151216235959
Z0..1.0...U....US1.0...U....Symantec Corporation1.0...U....Symantec Tr
ust Network1?0=..U...6Symantec Class 3 PCA - G5 OCSP Responder Certifi
cate 30.."0...*.H.............0...............2&..PL...,..2....:..tH..
.`JG.%..*...s.c%...?t..J..0.q....~..k@X.l.i....0..kk..h.9"1.5?..s.....
3[...u......]...R0..Z}....l..I.Y.....j\H.q...#.uw.4qz.#.J.....@2$"..$l
.B.......D.ye..(..2.........@...... ...."... E..0M,..b{.^..s'....f.6.p
r4.J........'j..........0...0...U.......0.0l..U. .e0c0a..`.H...E....0R
0&.. .........hXXp://VVV.symauth.com/cps0(.. .......0...hXXp://VVV.sym
auth.com/rpa0...U.%..0... .......0...U...........0... .....0......0!..
U....0...0.1.0...U....TGV-B-2760...U......;O}a.!..u...au..eUNp0...U.#.
.0.....e......0..C9...3130...*.H.............(.&..Dgr.Ve..#...5.N.

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CECkSxwyaK4o+9vYHRmLWi40= HTTP/1.1

Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1725
content-transfer-encoding: binary
Cache-Control: max-age=527846, public, no-transform, must-revalidate
Last-Modified: Thu, 23 Apr 2015 12:35:16 GMT
Expires: Thu, 30 Apr 2015 12:35:16 GMT
Date: Fri, 24 Apr 2015 10:01:19 GMT
Connection: keep-alive
0..........0..... .....0......0...0......N$p...v....1.;..vn....2015042
3123516Z0s0q0I0... ...................F....0.yV......{&.K......&......
.).... .>...Fb.......20150423123516Z....20150430123516Z0...*.H.....
..........N...p...e...#\....02Y..........V.$y7..........Q]..*E..e..k..
|.X..2...-........Y..5.....y..W.%.~.J_.1...i...'K..U`..7..E.V. .{,...I
/$7EE..T<%r[...J..C.w.DX.!..K..G<R:?"..Dc ..^(x................n
F..U@........mQ`.w^.UK.{... ?].......&.%e #q...`......w........0...0.
..0............F...I]A(M..s@.0...*.H........0..1.0...U....US1.0...U...
.VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of us
e at hXXps://VVV.verisign.com/rpa (c)101.0,..U...%VeriSign Class 3 Cod
e Signing 2010 CA0...150225000000Z..150526235959Z0..1.0...U....US1.0..
.U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1VeriSi
gn Class 3 Code Signing 2010 OCSP Responder0.."0...*.H.............0..
.......q<...A...#......A...u..Lz.............o..D.vQ%..s.......f...
.e../jI.d.W.....|K;.j5...#.B%.]..~S.... .|;S.&.....N..`...5.....!D.p..
..M/.. ..;j...q..`6...2.Ck..BnLHvCZn%....,.w.Ooi..z'...\.Yx......b..L.
..5.o..o..{..}.........%e.....N..._i........*Bc....:yQg.........0...0.
..U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.ve
risign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS in
corp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U
........0... .....0......0"..U....0...0.1.0...U....TGV-B-31830...*.H..
............-..^.........f.P`...s.....8.....V.......... .... B.(@-

<<< skipped >>>

GET /__utm.gif?utmn=18467&utmac=MO-1405551-23&utmwv=4.4sh&utmp=click/fa-2015/en/intro/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=- HTTP/1.1
User-Agent: avast! Antivirus
Host: VVV.google-analytics.com
Accept: */*


HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 19 Apr 2000 11:43:00 GMT
Last-Modified: Wed, 21 Jan 2004 19:51:30 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Wed, 15 Apr 2015 19:43:29 GMT
Server: Golfe2
Content-Length: 35
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Age: 742526
Alternate-Protocol: 80:quic,p=1
GIF89a.............,...........D..;..


GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEALa8SdwQh28+NjkQGqVhx8= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1725
content-transfer-encoding: binary
Cache-Control: max-age=582116, public, no-transform, must-revalidate
Last-Modified: Fri, 24 Apr 2015 03:44:53 GMT
Expires: Fri, 1 May 2015 03:44:53 GMT
Date: Fri, 24 Apr 2015 10:02:57 GMT
Connection: keep-alive
0..........0..... .....0......0...0......N$p...v....1.;..vn....2015042
4034453Z0s0q0I0... ...................F....0.yV......{&.K......&......
....'pB.....@j.......20150424034453Z....20150501034453Z0...*.H........
.....$S....KNR".3....>E..y..c.C.=......{Z..=bOT....f...5...eE......
...<....I..:..'....T.JI.;..&:p...'TQ.9J.zg/B...Y ...}X9.K.>..R..
./Z.o].3"..l....}..;.%.."D.tm..B...7UKV.......D...r..o|..e......&.....
......6...../xV.*p..T.._......!x..G...C...d....l...yIaQCi.......0...0.
..0............F...I]A(M..s@.0...*.H........0..1.0...U....US1.0...U...
.VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of us
e at hXXps://VVV.verisign.com/rpa (c)101.0,..U...%VeriSign Class 3 Cod
e Signing 2010 CA0...150225000000Z..150526235959Z0..1.0...U....US1.0..
.U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1VeriSi
gn Class 3 Code Signing 2010 OCSP Responder0.."0...*.H.............0..
.......q<...A...#......A...u..Lz.............o..D.vQ%..s.......f...
.e../jI.d.W.....|K;.j5...#.B%.]..~S.... .|;S.&.....N..`...5.....!D.p..
..M/.. ..;j...q..`6...2.Ck..BnLHvCZn%....,.w.Ooi..z'...\.Yx......b..L.
..5.o..o..{..}.........%e.....N..._i........*Bc....:yQg.........0...0.
..U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.ve
risign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS in
corp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U
........0... .....0......0"..U....0...0.1.0...U....TGV-B-31830...*.H..
............-..^.........f.P`...s.....8.....V.......... .... B.(@-

<<< skipped >>>

GET /iavs9x/ais_cmp_secureline_x64-7cf.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 55204
Last-Modified: Tue, 21 Apr 2015 16:30:26 GMT
ETag: "55367b22-d7a4"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:14 GMT
Connection: keep-alive
ASWsetupFPkgFil3....D...].....$.....qb~oOT.....;yH....!..M.....N. ..-.
1.H..........:..Z@.,.KK.........nJmC\r......1.nt....6_.l.?..........._
...@.....lf......3.......U....Z..%......p......Smog.0G..2.S.......0T.^
.G...pW.s.. l...<.?....>`=[...>y.-.P.......7...]..1Q..J......
......9..s...)......ys....V..C}*5..b........F....=..NS..|c'.~_..X~v0M.
Y...W...s.*G]....OVYn.I...l.3S.L.n.,F[...v..'C41..y({......d..v. ....:
.F,a.."/..V7e..c..E.5.....>eC..*..\.^e..8..u..H..I..mX.I-....r.....
n.*..{.)^.GA.v.5>8..z.LuF.D ,..d.] h.%Xv.......,@..5..!.........u*[
.x.n..vYhVn6..0)..,...9=...4]0...Bp.. ...P..p.Xv..r4..Dd.l-..s..K.$f..
.t..W..\..q..c..0....JZ........F*.9..Czta.......eTf......oj..Sl]...<
;X.<b_........#...vN...Z.M5[.<aU. c..t....I.|K.q.,.^jw....._.|..
.L....~...>0e..\...f..}.^,v.~...\..,..q.d*.$..".l5.$...j..r...z....
.M!....k.|..~........m...W.........?.........^.........0.a7......F..'.
.A..8_ab.`y....Rn....R"...`...TN..i. 3Ds...Z[..9..........!......(...c
.1T.N..Y..../...qn...6.c....cW`M.#j..m'Vm.......E...tQ.7Y..S......C..f
4^...V.K... ..y......5r..n.......Ez@........o. [Qp.q.y..5..1..8}.Nm.3.
.x......s...D.O.}2XX.Q...\..?A5..8...bx.S.=N.!_....F#.h..j.........B..
d.|We].z...$.$..vqEy.....tA..>./.j.GvH.rq...K..."......vs.,99.."...
......a...(..&.0.I.\.....W....... ..Z.Hz=LO.iY[=....... V=...].UX i.j.
.<....9.-.....8~..2...v4......(; >....!..R2.s&.0...>..N.h...h
..._...`....^.........&...:....#?.(....u....Q.%..z.K)....T....6......,
o.r.z>a..-n.!.f...tn........oz.?x...}`....h;^GK....!}.5.2...i..

<<< skipped >>>

POST / HTTP/1.1
Connection: Keep-Alive
Content-Type: application/x-www-form-urlencoded
User-Agent: Avast SimpleHttp/3.0
X-AVAST-SeqNum: 130743431216039146
X-AVAST-KeyId: 00936B625208F6A80000014D14104C3D62373236343431340000014BB65D8A13
Content-Length: 68
Host: 5.45.59.110

rI......8..1E.ng..8.Ha.^..Y,........d...zP.Nbe.:Q.&...V....Qs...eL..
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 4404
TTL-Spread: 21600
TTL: 86400
Config-Name: default
Config-Version: 1
~...s...rO...s.Y....."a...$.RF...C$...rt5.:.w.......1.....I.~sV..Z=O.t
P..s uL./...V.@@...q.D...q<#j;.ME.....d.........A..]b..D..`.L.....*
..ja^.e...4q......\.*.;.X<P..#r.R....L.....? ..78q..<.}.b!...b.g
..R(.......'a..O&..e.h..T.vF*u^@.r.....t<.'..R....M...8....#l......
5.)..E~..............}.[.|x|o..znN..WI.. .7..........[.?]t.'p...f...w.
v4......;6...4&P.K4 ..d5....Bd..VF..U.....Qk.m.U..R....l..W..4,EG.={..
.....s..y.N_>.P..Z..i...^.(c..5...^`q@S3A..=._KWB.v..Q.W .".h....i.
.%c.U.dZ...m6..U....@.Z...R.C5..h............e..Y.t...[).9.U..}.Z.d.C.
.\iGa..............w.B...\r...a.yqG..c.oyfm..Y.....~/c..*.V.kbM..>.
..x5.H.Y.&#..}.r.... .-.....c.\7._.........e.N......Fd...!...n...f..nO
..`...y........8...]1...(. ..r..y..8!!....!.u.'y...m}.r...Z.Tu....K...
.~-1......c[I.._......BT...3l.>....;........&|.F E.....,>.....0.
.....{...8....'W...:..[...X.....Q..0.5...]....e>%.n.Z'.&W.O._*.TB.S
F.....5?...AM$0.x...d.....0).......,v.6o.9..."O......?~........Gt....^
;.F~1..Tv.,.h..R..-.{...W..1h.....~../.V$..1.....3X...BlK....Z........
.....-.z N.[..oq.la..7.d./.u.....S.....BLB..Y.8....E.?......S.:....o..
.h.,k.N.(../o..R[......t~b%..j..R.\.E.0..PLH........JX.....|P..|...Y'.
.....l..^.m.>j1....R....<k..u..A...S9.V..*C..po..h.Zj*./T>1.Z
......{.......m.........,.>...Kd.......g.[......GH......`....$...3.
.......#.i#.cnI.P!...@...U.......n...-.m...`.....@... ..s..../.l.....S
Pt....~......=......A<.C.".T...}zU..u.XX.FE.5..R3 ..x..?.z.:Q.VaG'.
.........]...5....Va.b..U..O.i/H.]..xL%l......FM.e......f.cO.-8.%j

<<< skipped >>>

GET /iavs9x/ais_cmp_rescuedisk-7f5.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 258818
Last-Modified: Tue, 21 Apr 2015 16:30:25 GMT
ETag: "55367b21-3f302"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:12 GMT
Connection: keep-alive
ASWsetupFPkgFil3........].....$....8.pO...7w......W.m.......g......v..
.X.b..3.2...vWp..4.....&.3.yl#Bm......X..G.......9.1.?WQ....._.y...­
........V...W.}...YL.B.....X;l..$c.t`..%.R.z....K1...7...O.h=.!...Dyb.
i...$&C&.Gy#...Ue...W....]....S.uD0I"TM7.y[..5.I..=Cw<.......>.'
8.0........<M..U..&o(.x[......h/?.\..Abb....\\..<.AB.-.Y..sk.R..
.d..........."....G?.....P....m........>...8.....Z....n./<..n...
....VF:....Y.0...">._..G...._..........FM.t.iVg..x.A...1.ul..KH;..r
e)0o.%.. ` Q|...IG.[m...d3..3..=d. ...D.B.h.g}.X.....<Y.Rk....X.k..
.......=....... .@. .|F..Q...{MY.49=3....#"...w..&....'.F`.S]......)..
.....F.....f.?..O.....Z...v..6}..`..@UcF.......A*..5~.u..N..(.2.p.....
2.e.TR9w.tQ.}.xvy....e.1.o......O..K..E&....4.lmuN...N...$l-...../.S.\
....,D.|-.T..{<Z9....t..... ....j.....o.(.."..2..{..Y......V...h..0
...K.....{.^..J(.......uY..n.h..He..G..)?%YDF.C....5G P.AQ...|......s.
.76.E....*..-..(]1c.<s..|.zJ.:.ZRmz^.....Z.......u(._..p.........A.
53..._..(....@..'......#z...(.....M?..?]..j..yY....u8uK. TTs.G....y7,&
.z...}D.....~q.....4I.....8./......\(i..q*_...Y<......Gx.....X..g.F
.7..T.#..........Y.............L(.9.....e..8...7...T-... DTa.k.]U..E..
.<.y..By..e.T2.'..7.Q..S..~n..O..`.Cp...........7x..8A..sX...u....0
._.j.$.1.Ps#....n.....g..,......{.-..'.*....C.a.....*u..EH............
.y.u......hu....F.y..T..f..dD....m0..'/%]G..m..)A=.,..M/...D.. ......P
K.GsfM..........FE...... ..C}.....A...Cd..E/.Rl9.:.0.E.Y.....8..Kr5`.2
ff....sM..dYg.....g.!.CB.($..1J..Lz........eE...&.....d-..blt...$.

<<< skipped >>>

GET /vers/setup_config.ini HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: setupini.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Last-Modified: Thu, 13 Nov 2014 09:54:16 GMT
ETag: "54647fc8-2f6"
Content-Type: text/html
Content-Length: 758
Accept-Ranges: bytes
Cache-Control: max-age=446
Expires: Fri, 24 Apr 2015 10:05:49 GMT
Date: Fri, 24 Apr 2015 09:58:23 GMT
Connection: keep-alive
[Offers.GoogleChrome]..ShowInIntro=1..ShowInPost=1..ShowInComplete=1..
ShowInPaidConsumer=0..ShowInPaidBusiness=1..UseTryOffer=1..DefaultStat
e=2..[Offers.GoogleToolbar]..ShowInIntro=1..ShowInPost=1..ShowInComple
te=1..ShowInPaidConsumer=0..ShowInPaidBusiness=1..DefaultState=1..[Off
ers.GoogleDrive]..ShowInIntro=0..ShowInPost=0..ShowInComplete=0..ShowI
nPaidConsumer=0..ShowInPaidBusiness=0..DefaultState=0..[Offers.Dropbox
]..ShowInIntro=1..ShowInPost=1..ShowInComplete=1..ShowInPaidConsumer=0
..ShowInPaidBusiness=0..DefaultState=1..[Diag]..SendUrl=..SendLog=0..S
endBrokenFiles=0..[PushPin]..ShowType=3..[Signature]..ASWSig2A3FB407D5
23B933CC1189ECDF133B7F356EDF4936A772B7557DAFB34AD6F0BBC72E853BD8933B3E
3D342E2F692CAAB5DBABA688D90533D3E2A2EEEEACFAEACBACASWSig2A..


GET /iavs9x/ais_gen_streamfilter_x64-7f5.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 53218
Last-Modified: Tue, 21 Apr 2015 16:32:24 GMT
ETag: "55367b98-cfe2"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:29 GMT
Connection: keep-alive
ASWsetupFPkgFil39.......].....$....Q|o........`...-z...~..?.y.......z.
.{qd..Z.w......MJ......>B|..kd...o....../..U.m.p......,..}>.. ;.
..h`..(.d..F...C.@.9@....i.>K.,.>..7.5o.4....I...._......LLA...W
..`..?.K..^.d...7...qH`..@.N[..\ ...C..C..6F.......c.=/..}.].J..r.A...
=hy...pIX......6..!,.>..6...PY........w.T.&..Y..J.s..Q..k.O.i.F T[.
........[.~.AK:....w..0..&......8....*..)/.8..........=.....Py....E}R.
^......V....T(.n........"....w....]&)sK....&...T..J'...k.`...G.k.^C4P.
i.. ..QM@..}..l...j.CW.,p.fK.6.q....Jh.]|S..R...B........-.}i.;.[I=Z..
Wq>d...Xb....X.C...f..f....~...pD.]...a...?...r...........8.?....#
...^F9,..Z..N.X}\C@.O..."..k.....yj.5Z]..h~...u..$.eH..P..c..'G.....C/
..p..0.1G...H....6..:..e.@..B.....).w.......{..b..S..6....J....J....@.
w.....7..Y...-L...(v.m...3qxX.VmTs..K.GU.F.*..7..c..w.U.f.L..m..^.*!..
.......h./t...b@..I...6H...E...5......XTsh....`"A.]..u...'..7...p..BU.
x!Yr........l......4.....4..... .#n.2.8'.&t..6k5:.HEO...D......d8.(U.3
..0.:mq[].!<..@.....a.....X..J*..Sc....9..d.LCY......|@.>VQ. ...
.)......@...i..`.}.X4\...k..>....Ni....G.#.8.....(.....q...."...16.
Vp.._.0<......4"4 ..X[z.l.{..[.....s....d.D`.(cs.Am..\.V.-.C.....8M
.......*....E.Tm.Lj.....WF .D....i.T....!z..iv5D......Y.~3]<..|.mz.
.o6F.Nc?.f.6.'.......2.k......)OR#..!...*..r.09....-...s..0d.5%.F..m#2
.k.2cL..r`G-qQ0$..O.c.....7..A&..Qh....v,c..4.EvYPb.F,U/U6;.O>.....
..n.k... 4.H.&,/E..N...)..C.1.........$.G..1.)G....E.q9/!.z..`....&<
;.......QM<...y.$...xC..=x..X.|..B......m.d.xmkS.;.8.!Z..t...s[

<<< skipped >>>

GET /iavs9x/ais_gen_tools-7e2.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 325835
Last-Modified: Tue, 21 Apr 2015 16:32:26 GMT
ETag: "55367b9a-4f8cb"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:30 GMT
Connection: keep-alive
ASWsetupFPkgFil3HX..k...].....$.....[*.{.Ky...........W/.. ...l....k..
..".4 ..U.X.:............*.SI.dO....@......)*tRoXyQ)@9..P.........t...
f.-.V;....a.g.rbh...Br.}....NU.O8n..9..Z]"..../hz;q$%.u[. .va.....c.'.
....F.q....o=/...7[<..{s..9.3....(..X.&......lA.7k.4..."....&../.A.
.)....T...Q...Ou..4...#.TCX.....f..j|..3._...Q.....B....p|...u.......k
.{h../2..Le6a..1v....K..tv..H........s.......H..z@..Pd..zJ.<ER.....
/E....eH..B2I...6.jF.[..~.n..|7....5n9.tve.L..,..:..#l|./..t...A...-..
Kw|.z0"..V..-_......Rm2j.!=..........FO.2....p48t....M7...3Z.........x
V.&.o.~q.....9>.D.....0&..(6...C...{..v.....dH...I.haa. .=.....~C..
....O....$'b.)c..E.4./..^....r..XVJ..s.).9.We=..V.}.ug.:J.o...-.......
I.p.CL..z.O..i#,n.q.5.a..6a_4....H..5E...]....6.5n.c...J..`....<...
..P]...eF*.{.B...3O........9j.f....(.....2...kl...G.z..........7..=...
. p.7..].v...=..........wq..1.#....4"]...(NK.m... ...c.H..u'P../h2...G
/.!..:c{*....>.Y_....s. .}.I.X[._.....>\.....W|....].2......er.!
.V.}.*...e..p....bY..f.}fc ...^Y....Yj.....0KI.:....3F.a.u.(../...;..L
....a.A..WAW_....Dh.............9....o^....es.I.z.3.L....>^.../....
.......z....&RY.RP.*}...j..o..V.}..g.$...a..J?.......f.).8EP..=...ySWQ
..p.Z.E1........]g.`|..N.3.L......GY.?......r......{oC..Wc..Rk..DR ...
._._*...(....Ku.....6|....../....&%^.WY...K..N..m..&......x...O.....c.
..]...5.QC.t...n'4.j.&....8B.:..>.......o....Sr..r..@..^.tM.Fv..lje
...^...r.lR...w.....*.69.CyBx.2..^V.....f....~..k..!.t...<...R..l..
..........D..Hh.....:7..s...>.....T=51..|...T^ ....lh.xj....`$.

<<< skipped >>>

GET /iavs9x/instcont_ais-8a0-89e.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 2191
Last-Modified: Tue, 31 Mar 2015 10:56:59 GMT
ETag: "551a7d7b-88f"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:29 GMT
Connection: keep-alive
ASWsetupDPkgFil2.h ..h ......&...........h ......h ..........x.].{<
......L..e,.Z35.t...2.1.a)#.Jr.b.M4..0.2...)..S.....(K..n.=H..2;=.<
.s......}}......Z..D....W...m.$..m..oj@...4..v..d>...`....&........
....*..Q!j..yX........g...W"n[.....M$......V..*\.....p1./.......T..l..
7...Z..'...C...L..Y..4.g......._J)...e01.L..."..X.R..".gX..h..........
....g.fSI4..~&g..yvH:............4d.B".3.kG:.....uj.$.em...,.s7.$...]}
,...H......T#8.......>.{...SUc..iO....q\l.:...~3..`. W=..$..V...Q6.
...wh.....0...\....\T0.....O.2Q.xG..)H....^iAoSpa.`..V.#..)..YlW]wk.u.
*.i?.......7..af..j..7.Q...:YM3.....X)gM..".. ....V.Ho..L....i........
.d?......e....6.0"Q......M.yBW.YZ..4W.i(....-...c....s6.1..q~uT.%.....
.m.5WV]..xk..1..w..../A? .../g.f...6.......&....N..K..Y|...f/2. Lc....
S.U..pR...$.y....ez..Z.H(.h>.K.nN...........r..X.........7...b.5..0
..o.U......vx.#}.P........]..?n...s........N.....8.2|.m.E'.vc....:K._P
.....K._..z>...T..g..."*......?ZR. ......"/..h.!#.`_. .Ln..;._.d<
;.5.-...1.q<...Fwe.P..pG<%.....P....;.D..=.EQ...a9.~W.}..$\<.
Q.V.j'J.z..!j..<....Z..d......../...._-u.,....jl..:.$..a.....<..
.`pk......W..n..m.o.......i....CK.?..C....#<x..w..0...Q.af.R.,t&mWX
Oi.2........v.Yg.S....c.3%..>.|FS.2.x=.....nn..4He?Sh$...4h...F....
51.........Pmf.t&]..FM...l....".K....6Q.hsB...fq....[<........p.0[T
..3.Bu.F`.W .....A.y..a"..Gs.....Y_.-....P.?.;s(...Y.37...1.0......%..
......T...j....7.b.....2Y.. ..........I..c:e.......I....$.....#.......
.O>...w..J...L.........n:w..W1!..d...}.O..HD..S...L.)..xw....3n

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEGO+CyDUoFQBjrKVo87pCRc= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1725
content-transfer-encoding: binary
Cache-Control: max-age=339796, public, no-transform, must-revalidate
Last-Modified: Tue, 21 Apr 2015 08:25:34 GMT
Expires: Tue, 28 Apr 2015 08:25:34 GMT
Date: Fri, 24 Apr 2015 10:02:59 GMT
Connection: keep-alive
0..........0..... .....0......0...0......N$p...v....1.;..vn....2015042
1082534Z0s0q0I0... ...................F....0.yV......{&.K......&......
.c.. ..T.............20150421082534Z....20150428082534Z0...*.H........
........~.[6....c>.{...J..|P.U3..e.Y..'.#........>O...X0._......
J.a:.H..S.....3..cX.O..3.6..?I...,$..6-..XY08.0.m..,`...3.Gk3G........
.........P.FB2.&N..@}.`...K.....?...e......(,..I@.4....T...tRby...*Bb.
.P ......nS.!....7....v.ud1.fF..'../.k...W.A*.f/\o.....|e....0...0...0
............F...I]A(M..s@.0...*.H........0..1.0...U....US1.0...U....Ve
riSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use a
t hXXps://VVV.verisign.com/rpa (c)101.0,..U...%VeriSign Class 3 Code S
igning 2010 CA0...150225000000Z..150526235959Z0..1.0...U....US1.0...U.
...VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1VeriSign
Class 3 Code Signing 2010 OCSP Responder0.."0...*.H.............0.....
....q<...A...#......A...u..Lz.............o..D.vQ%..s.......f....e.
./jI.d.W.....|K;.j5...#.B%.]..~S.... .|;S.&.....N..`...5.....!D.p....M
/.. ..;j...q..`6...2.Ck..BnLHvCZn%....,.w.Ooi..z'...\.Yx......b..L...5
.o..o..{..}.........%e.....N..._i........*Bc....:yQg.........0...0...U
....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.veris
ign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS incor
p. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U...
.....0... .....0......0"..U....0...0.1.0...U....TGV-B-31830...*.H.....
.........-..^.........f.P`...s.....8.....V.......... .... B.(@-)6.

<<< skipped >>>

GET /setup-free/avast.exe HTTP/1.1
Host: s3-eu-west-1.amazonaws.com
Connection: close
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
x-amz-id-2: H 3u6/NMdkJaNbVl6 5ONtJkjvbCjREXadXKoLVDLaNgQBYnFdUIKPaL5W8rb03djvkBiTOt4UI=
x-amz-request-id: 1A314CE1180F36E8
Date: Fri, 24 Apr 2015 09:58:20 GMT
Last-Modified: Wed, 10 Dec 2014 01:33:13 GMT
ETag: "73a0c739e3c73d4888c89a1672198bd6"
Accept-Ranges: bytes
Content-Type: application/octet-stream
Content-Length: 5004328
Server: AmazonS3
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$..............C...C
...CQ..C...C...C...C...C...C...C...C...CW..C...C...C...C...C...C...C..
.C...C...C...CRich...C........................PE..L...$9FT..........".
.....|........................@.......................................
@..................................j..........\K..........@$L..7...0..
`L......................................@....................g..@.....
...............text....{.......|.................. ..`.rdata..<....
.......................@..@.data...|W.......$...p..............@....rs
rc...\K.......L..................@..@.reloc..|u...0...v...............
...@..B...............................................................
......................................................................
......................................................................
......................................................................
...............................................U..j.h..I.h..D.d.....P.
..SVW...I.1E.3.P.E.d......e.3.f.E..E......E......m..}..tf.M..U.....U..
.tV.E..x..u..M..9.u..C.}..u*..U..E..M..I....f.U.f...f.U..E..M..H..M...
.U.....U..E....M....E..............e..E......}..t..U..E...f.E..M.d....
..Y_^[..]..............U.........E..E..}..u.......M.Q......Rj:j......f
.E...E...u..j3.f........f......f...f...............M.;.}6.............
..u..#........M..Q.9......u..E...........3...i.....].......U....(.E...
...E.....j.j.j.j.j.h....h .G.....G..E..}..u.....G..E..|3..E..E..E.

<<< skipped >>>

GET /iavs9x/ais_core-7f5.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 6516372
Last-Modified: Tue, 21 Apr 2015 16:30:49 GMT
ETag: "55367b39-636e94"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:16 GMT
Connection: keep-alive
ASWsetupFPkgFil3..Q.4nc.].....$.....f.....6j...<o.O.q...&H.....)..&
gt;...Zl.x.@cp.B;......~..%..%.Y.....4..c.%...=.]Lt,..`....b^`f...A...
.6?..OY>.h8.....g....R\.x_.(.s...D..v..F......-8.@.......F>}T...
.Xc...'...P.Q...6{....L....*J'>6.$..^f..Do..F.nue.q.....?.@..|..(..
7\..'gE.....H...t.O..E*...."@...q#..,....k.m..5>....Qc.CB.Z.&......
..)..f."$..v.o..D..n..K...X...w.z$...&............?..7 '....J.m....r.Q
.)|.V6.s.O...$..{...4..B..o.1j....k.=......*......b.......gl....6.ljQ.
.6b} .y,....t...5...<.A...h.....wEb....7..c....Q..2....".......R.W.
.:.eK8A......9...J.......D`. .1..In.90.ntl....1.]hS..!0)3....Tf._..R..
.........C.Y..PF.|....L....C|...w......3...@..LW......f`.S....YS.r.S.~
.n........z^l.J....G...g.......P. ...)p.7..c...84F2t..vw4>V...Zs..c
.....e.*.4G....v...9...=.c.......A..A...1..C.u..(.......q...M[.Z.g.r^.
c..@h".W..4 .P. .....h?{.KzG4.W...d~*..$...V=..t..>.{y&a .~.C.a..."
;..(.........7... .y=...D.>e{...b...K..<x.N......EQ... ..-.J..".
....$.u....(T[yo..i..T..f..kW....@[4....>....I.......q....2w.j....b
....d.....E....s....1..f(.\y..o6C.C$k%..~=OO........3.......4..e..M...
;..y...#.8'<.2.2.....SWC.'.rbLI..$bR!...j.7.g.......h94...,H...P..-
.EN.J'..Y..,...A..Yf.........M_]S.u....D........ .G..G.gn...S13.b7....
j.O.....}./.#.../..lN.....%....3_.J...cr..e.{...>....Bv.!Xxd.sq.s..
.W3k......E]..On.W3u..e... mp..I- .....-..FN.......gG.......t.=>/.b
#%I..s.....2./kr.........[...8...c.L.~...t:.s....()i._$.lQ;...S..%|...
..h...F...t.3.[l....Y`.....h.e....s)......p....rF.Y..'1].*.....h.)

<<< skipped >>>

GET /iavs9x/offertool_ais-8aa.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 1387335
Last-Modified: Tue, 21 Apr 2015 16:34:07 GMT
ETag: "55367bff-152b47"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:37 GMT
Connection: keep-alive
ASWsetupFPkgFil3 .4..*..].....&..p.........../D.N..tF..s.....}.....<
;...*........:.>..#s..\.b...bi..@.^..gw`.e...........(.T.$.v...W.r.
.?..9h.....A...N.:.m..w..?.......gW...r..s.>'e.. p...h\.|,....;.D.
..C...(.%2)F.._.G......(.pLO......9*U...&.. ....Gy...b...uc.....LiY...
..(.......((..:oa.....$G.V....-........R..Lb.....i....x..#T.....w`s!..
=.X.D./...0.g[.*9...`.@...[.=.Y...zx....i...f.......s...&. 6i....y#...
..].j..T..!.m</N.%C..v...z`.Z.@...'...g!.I<...W.*...,..e.Wh.. ..
E..#.2....1...*.".@.Q,{.}.V.g.....66K......*<.]....\..=.@...^..yf.J
..p.lB.. ...y....2...@.M.../.Jc(..k$....g..[...R.........P.J0`q|.2-D..
a..b..2.b../.i.^B..]...K..F.]....c....5.....&...z./.(.R..=q.Ci.%.sJ.G.
.o.7....G.Vi........k8b,4vmJ..,?P.0!.w.&#V..JG?..[...w..c ...5.k..77..
..F..H. SS4.!....X.. .7.......4(.9.=..J:.y.3 ..Y.J...0P..2H./.%.*.]{B.
....'.,}.{...>\-..k.......T.TuO..\..Y.Z.b..`c......nx....._^....If.
...5{&.......".l.gm&I3...."ksz"..>.z.;.R..2:..k.[.Z......2..W.(..0.
..X..jp.5.W.By{}...^f~.C.i....cy..x..._.q08?..ez}.@Ibc,L...eK..M. ..mD
.;.p|..o,.....$..kd.u....F.....1......{........r.....d..Bs.?w.$..m.U&.
B.b.i..?..H(...n.Cg:._....18...5*.....9........1.5.7.........^.}4...."
..k.....@<%.j.........._7...nZ...K3.*~9..A...@....~..-_.....{...T..
-&.2z.6dUm(G-.o. mu...p.P.F.......W....B..-..L.zh....zD......kV...._..
.F....j1<1.....V.....Z.w.....Dy..\$.".../...(...8Ru"...).^.A....0=.
Z....a..1.q7^.....Fg...x.`w.h...s.e...u 2...!."..........m.......TW^..
....!z..F.x.....6.I...o....L.i.3..x...!..~8./d.o..?...L.R^...;....

<<< skipped >>>

GET /iavs9x/ais_x64-7f5.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 1617179
Last-Modified: Tue, 21 Apr 2015 16:33:41 GMT
ETag: "55367be5-18ad1b"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:32 GMT
Connection: keep-alive
ASWsetupFPkgFil3..h.....].....$...........j......PHZ..s..35.-u...`H1]a
..=....}.E.....j.`......J`...N.........&)...K.P2..14..{..z.a.."..v....
1Z.....y.~..v.Z...Tg..@..!.....Q........~m.*"......d..rx.3\....}05,g..
N....S}e.N.?..p....j..$z..7.rh...o 7.-.Sa^<R`.&..[.j..8.....,..e...
d..|"....<.......W.^......m.2.K.hcL..z./ph?.,<.....'......."..='
.....Dp.4.....t*..~..V.....RQ.d...........).......f%....gX.QM. .%.~...
x...&...X.._...k..S.O0.Z.Z.K....0.S.......m...3...5K....T..a9...%..kc.
.x.Iqo.@|}...c.. ..........Q.|6\.f:......B..p/.C.....7.%[..r@.B...._..
.a....E/.E.r..4.......DW..<..&!.........'..|...4....<..M......UP
-?...O...Q.b...(:.c.1..P..w.......8..._.5pE..B=.N.~.8bf...)?.........W
.=...J.W......\..e..............^r_i48...q.^......'...=......j'.#..x..
\.....R.;7.gu....\'.U2..E...;..l.....aUkb8NI.<.....8........N...L..
)...Q.f..8.&.Q..)d...q....qK..........x....,..m1......J..."n...>/Ub
..!.PD.g.=......He.q...nRDQ..)..P...w...t.M.`....;.7De=38x.r.]e...F...
...'C.k.#~........R(.r.OE..D.:.VJx...|............H\Z&....>;.$_....
.7...<..nK..He..o..>....e.fI...q.C....6_.P-HO......\...n..T.<
...L<%rN....'.O.PA...E3.O........s...I.d.G1jr.-..:._."u....r..).._}
..8.....c...._....(..TJ-eS.W;.M.7.....Js.. ............w.^x.q_..RAI...
..[..'g...L ...}..9....3. .........3U..4....../..#...]3HhnE...2......V
..O.q.P.._....E.}`.\"z.3~.RC.{.R.q....dKt.......A3.... ..1....'...!f..
..HM..t....M.......V.;`..W...?5$.../..=....}M....h(..N...[../....>
.{vN;.?P...'.'.F.}T.5..h..$..J..bw:.......b.&.^..i.>...x...J.{t

<<< skipped >>>

GET /ivps9x/vps_32-1000.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l3362258.ivps9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 54983757
Last-Modified: Thu, 23 Apr 2015 17:27:19 GMT
ETag: "55392b77-346fc4d"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:34 GMT
Connection: keep-alive
ASWsetupFPkgFil3w.....F.].....$.....`.t...D..z*...[...%...>........
'.mox....I..F.a.. tt.C..*.4 ZRtT...w........,.yU....@..........8.T.0.b
f.@.:K.R.H.k0.g<.0....T....B...n{H}..2:.k..\...4.(..A.j......5.jx..
Z.'..2..n.]{|..W.^..8.....*x.....X.}.....4k4.g..%.d.p......}..`S..Kr..
.n..W.Y.?C.Y~....1.........7Vn....}..R.........r/7...:.j.L(3.../..o..W
...c9... .>-#.....i.~.,..!\AY.A[..Y?#.n.~...~*..o.....x.....{..:..
...t.O...Z...ZDU....|...............sz.D..5]...}...=..s.wZ...,...WF \R
........g...rjmz....b.........kf...G........N...L.......Oa.z.:..xc\..`
6'......'..F3....M:-.B..pg.a9.7.p.G.q....R\.....S;:*..6..Nc.._..G.....
'....U.E_MB...B..).....M..q.;.......1..{.......k......".9..1w....^.O..
.R.........|....6Ev d..cS..7.a(.o]p........5k..0..4o.!o........?b..d..
..P....^..f[..K.P.....A.N...]k!.]~.o...W.7.....m.q........F..O.._.k...
...h.u..........h.....y%\..%..d.....-......wkc./.i..G.;,Ax..~f...r.\..
............w.....!..v3...$a[p\.k0............b....%......Qu..Gs.L.W..
Q...].....W8..`0~.hf...>..y.........t..{.. .6.. ......G(b0.!i...z..
..O.b.?Ta...$t_ .aCn...-....i*......W.....E`........Z...[GRkM.....Q...
tV...z.......F.....{.&.....I?....;..e:.;F........N..-2..U[.1.A.6.Y.?U.
p...........S.F.v..x.....S.a.PI..\...OP..Nv.t%m.D}H..!..V.C......1<
AU.....`..n..d.......&.....s.zX.}....-E0h.;*. BA...m,:g.y...........A
E...).Q...E....j%e..........i....zh .:...t....z...B=..>...A....D..w
m....w....>.U.F)..*Ee.....c.z.4...;.....F.h..g4V6.BG.....c.S.y.....
/.......@..rt...tN....@jF....|.<.g.....@`2........N....lU....~.

<<< skipped >>>

POST /F/AP8bmBiiN4lEQp_DcUpuIX2v HTTP/1.1
Accept: */*
Content-Type: application/x-enc
Host: ai.ff.avast.com
Content-Length: 533

.nm.^q...J..#..<.9CDh5...L....E............2...|.....~...(....a:.1.p.P...;..b..B<.(.&F '.f.Nz......\{..d`k..m>...u..S...?c.
.._....J{z,...I...s....r4.@..LII. \... |.M....@..}.....l.i..9T.~...8.G.R.U{i..5p....@....fy..CFe../d.;..qq.o...gn.@..vt..ckk..4..
..e7.-.;.....[.W....
?...(E..?.(.S..e..L=...T.W[.[...B.q...#.D#...m...N_
..P...Y.vX....B..%...K_nxN.9....u.V..j.z...Z.A..&....Hw\s..A=...Q.....1Z......[.Gk...K.f~.....&^t...yC..>..R@..(...k.s~..yt;...m3..c2.E=-{.O3.X3.b..o.....u.y..h3....0S.- Lra..0.....^....IK..7.P$.2_..U...
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 2
OK..


POST /F/AAEbmBiiN4lEQp_DcUpuIX2v HTTP/1.1
Accept: */*
Content-Type: application/x-enc
Host: vl.ff.avast.com
Content-Length: 96

.n..^o
...........%.?..c..q....Eg...M.y...a..!,...rX..9..j.....m.^.*.....k..'..X8P(... 5.O.Mz..\
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 27
......"......& .....)0.8.Hd..


GET /piwik.php?idsite=1&rec=1&action_name=INICIO&url=http://wizinstall.com/INICIO&_cvar={"1":["PRODUCTO","Avast Antivirus"],"2":["TARGET0","fr-tele"],"3":["FORMA DE PAGO","v1-3"],"4":["DOMINIO","installfoox.com"],"5":["OFERTA","no"]} HTTP/1.0
Host: stats.zemobile.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
Date: Fri, 24 Apr 2015 09:59:10 GMT
Server: Apache/2.4.7 (Ubuntu)
X-Powered-By: PHP/5.5.9-1ubuntu4.7
Content-Length: 43
Connection: close
Content-Type: image/gif
GIF89a.............!.......,...........D..;..


GET /a2f8abf7/D0wnloads-English/MyPCBackup_Setup.exe HTTP/1.0
Host: track.mypcbackup.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 301 Moved Permanently
Date: Fri, 24 Apr 2015 09:58:17 GMT
Server: Apache
Set-Cookie: SESSID=ui88rofgjepr09buh87b30a064; path=/; domain=.mypcbackup.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: LC_CURRENCY=US; expires=Mon, 04-May-2015 09:58:17 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: ?uva6aT*=US; expires=Mon, 04-May-2015 09:58:17 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: LC_CURRENCY=US; expires=Mon, 04-May-2015 09:58:17 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: ?uva6aT*=US; expires=Mon, 04-May-2015 09:58:17 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: 748a7624422584634822bd3a2bf604ae=543bc9d3ade384672208d078359f50e3; expires=Sat, 22-Aug-2015 09:58:17 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: intc=1; expires=Sat, 25-Apr-2015 09:58:17 GMT; path=/; domain=.mypcbackup.com
P3P: CP="We do not have a P3P policy"
location: hXXp://cdn.mypcbackup.com/MyPCBackup_Setup.exe
Set-Cookie: aff_id=65635; expires=Mon, 25-May-2015 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: hop_name=INSTALLERSILENT; expires=Mon, 25-May-2015 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: hop_id=93949; expires=Mon, 25-May-2015 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: hash=e3e847182b7240ce2d6e2a6a5747fad1; expires=Mon, 25-May-2015 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: tid=D0wnloads-English; expires=Mon, 25-May-2015 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: a2f8abf7unique=true; expires=Thu, 23-Jul-2015 09:58:17 GMT; path=/; domain=mypcbackup.com
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8

<<< skipped >>>

POST /F/AAEbmBiiN4lEQp_DcUpuIX2v HTTP/1.1
Accept: */*
Content-Type: application/x-enc
Host: vl.ff.avast.com
Content-Length: 83

.n...1`..{..hNH.6@...b-.@...&..U....M.6...\...,...bB.. ..E....1>.i.-..y..m..2..~]PM
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 26
............( .....)0.8.Hd..


POST /F/AAEbmBiiN4lEQp_DcUpuIX2v HTTP/1.1
Accept: */*
Content-Type: application/x-enc
Host: vl.ff.avast.com
Content-Length: 90

.n2..#..Q]u..z...,CI.C...
....N....M.....i...,...rX..9..j....4h.^.'.$..,..4...2[?G-sLF.,
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 27
.............' .....)0.8.Hd..


GET /iavs9x/prod-ais.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: h6627484.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Last-Modified: Tue, 21 Apr 2015 16:34:24 GMT
ETag: "55367c10-164"
Content-Type: application/octet-stream
Content-Length: 356
Accept-Ranges: bytes
Cache-Control: max-age=42
Expires: Fri, 24 Apr 2015 09:59:06 GMT
Date: Fri, 24 Apr 2015 09:58:24 GMT
Connection: keep-alive
ASWsetupFPkgFileD.......x.s..r.```....p..o..m .....8.1(..(......2.....
%..9.B......a.A.,@.*...7.W?..C....tw...^7p.L......'c....6.m._...~m.[..
..~]......:..g...s...._.:....'..7.....x.....1.Ev. ..N-)-........9V.p.1
..=,.p........Q....md#9.'.X..h.ql........;.z.j.....%.N.0oP.........]..
nli./...U...|..G.po.2..c./0.j....~..R....V.o...|...yU....V]..b. ....AS
WSig2B..


GET /collect?v=1&tid=UA-45708355-2&t=event&cid=1b9818a2-3789-4442-9fc3-714a6e217daf&ec=20150112&ea=started&el=&ev=0 HTTP/1.1
UserAgent: Syncer/5.00 (unknown)
User-Agent: Syncer/5.00 (unknown)
Host: VVV.google-analytics.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Pragma: no-cache
Expires: Mon, 07 Aug 1995 23:30:00 GMT
Access-Control-Allow-Origin: *
Last-Modified: Sun, 17 May 1998 03:00:00 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Wed, 15 Apr 2015 19:48:39 GMT
Server: Golfe2
Content-Length: 35
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Age: 742366
Alternate-Protocol: 80:quic,p=1
GIF89a.............,...........D..;HTTP/1.1 200 OK..Pragma: no-cache..
Expires: Mon, 07 Aug 1995 23:30:00 GMT..Access-Control-Allow-Origin: *
..Last-Modified: Sun, 17 May 1998 03:00:00 GMT..X-Content-Type-Options
: nosniff..Content-Type: image/gif..Date: Wed, 15 Apr 2015 19:48:39 GM
T..Server: Golfe2..Content-Length: 35..Cache-Control: private, no-cach
e, no-cache=Set-Cookie, proxy-revalidate..Age: 742366..Alternate-Proto
col: 80:quic,p=1..GIF89a.............,...........D..;
....



GET /collect?v=1&tid=UA-45708355-2&t=event&cid=1b9818a2-3789-4442-9fc3-714a6e217daf&ec=20150112&ea=finished&el=&ev=0 HTTP/1.1

UserAgent: Syncer/5.00 (unknown)
User-Agent: Syncer/5.00 (unknown)
Host: VVV.google-analytics.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Pragma: no-cache
Expires: Mon, 07 Aug 1995 23:30:00 GMT
Access-Control-Allow-Origin: *
Last-Modified: Sun, 17 May 1998 03:00:00 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Wed, 15 Apr 2015 19:48:39 GMT
Server: Golfe2
Content-Length: 35
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Age: 742368
Alternate-Protocol: 80:quic,p=1
GIF89a.............,...........D..;..


POST /cgi-bin/iavs4stats.cgi HTTP/1.1
User-Agent: avast! Antivirus
Host: v7.stats.avast.com
Accept: */*
Content-MD5: DAgGZ2Ns57kVK6nwqpenPg==
Content-Type: iavs4/stats
Content-Length: 1935
Expect: 100-continue


HTTP/1.1 100 Continue
....



GCHBitmap=0.GChBrand=GGLS.GTBBitmap=0.GTBBrand=AVNH.Guid_created=14298
69521.HTTPhandler="%Program Files% (x86)\Opera\Opera.exe" "%1".Initia
lScanNOV=0.IsVirtual=1.NG=0.NoRegistration=0.OfferEvent=1.OfferReactiv
ation=0.OfferResult=1.OnlineInstaller_status=1.PersistentGuid=1b9818a2
-3789-4442-9fc3-714a6e217daf.PersistentGuid_created=1429869521.PostByt
es=0.PostBytesOK=0.PostFiles=0.PostFilesOK=0.PostTspan=0.PostTspanOK=0
.RetriedFiles=0.RetriesTotal=0.ScAsAvastReg=0.ScAsOtherList=Windows De
fender,.ScAsOtherReg=1.ScAvAvastReg=0.ScAvOtherReg=0.ScFwAvastReg=0.Sc
FwOtherReg=0.ShepherdConfigVersion=0.Silverlight=4.0.30319.SubmitRejec
ted=0.SubmitTime=0.TestID=.TriedServers=5.UpdatingTime=0.boot_time_sca
n_accepted=0.boot_time_scan_offered=0.brandCode=AVNH.bytes=105003698.b
ytesOK=105003698.chassis=desktop.community=1.cpu=I9,2;ntel,306c3.cpu_n
ame=Intel(R) Core(TM) i5-4440 CPU @ 3.10GHz,2.custom_scan_created=0.do
tNet2=2.0.50727.5420,2.dotNet3=3.0.30729.5420,2.dotNet3.5=3.5.30729.54
20,1.dotNet4=4.0.30319,0.edition=1.files=25.filesOK=25.firstInstall=1.
gui_like_clicked=0.gui_opened=0.gui_settings_altered=0.gui_settings_op
ened=0.guid=1b9818a2-3789-4442-9fc3-714a6e217daf.help_opened=0.idate_b
=06/02/2011.idate_w=1363796288.lan_addr=MAS_win7x64.lan_ip=192.168.139
.135.lang=0409.licExpDays=30.licExpirationDate=1432461667.licIssuedDat
e=1429869667.licType=Trial.licType2=999.mid=22C01CB0FA89DF1041E12D779C
965270.midex=00000000000000000000000000000000D1B76341555516C18AC954A39
0C8596B.offerInstReturn=0.offerReasons=0.offerType=3.on_demand_sca

<<< skipped >>>
HTTP/1.1 204

Server: nginx
Date: Fri, 24 Apr 2015 10:01:32 GMT
Content-Type: text/html
Connection: keep-alive


GET /tools/pso/ping?as=tbin&gu=pi&mode=3&sin=1&ein=0&version=7.5.6227.252&brand=AVNH&hl=en&tbiv=7.5.6227.252&time=1429869682&fitime=1429869682&browser=9.10.9200.16521&osver=6.1&ossp=1.0&osarch=64&ext=EXE&id=94394E1F1F38CEBAA4CC598C9A5F7962A4932kYVRG HTTP/1.1
User-Agent: Google Toolbar installer
Host: clients1.google.com


HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
Content-Length: 2
Date: Fri, 24 Apr 2015 10:01:23 GMT
Expires: Fri, 24 Apr 2015 10:01:23 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Alternate-Protocol: 80:quic,p=1
ok..


POST /F/AAEbmBiiN4lEQp_DcUpuIX2v HTTP/1.1
Accept: */*
Content-Type: application/x-enc
Host: vl.ff.avast.com
Content-Length: 95

.n..DU.ED.Y:..lj?..`.s....hx.|w..H..M......0.GU...uR..=..`....ji.u.-.8<..r.."...%M.!y.74..8Gr..
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 27
.............& .....)0.8.Hd..


GET /iavs9x/ais_dll_eng-7f5.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 415433
Last-Modified: Tue, 21 Apr 2015 16:30:58 GMT
ETag: "55367b42-656c9"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:18 GMT
Connection: keep-alive
ASWsetupFPkgFil3....iV..].....$......Y^{.KzKk......Z....0Z._a<.....
."...p.....-=:89.....fj...o.I8...z...3X....w(8.8.. (!...z^u...;..$.Sr.
"'......./@/1..J.......kg(.P......zlq.....U~O...>U.G3Te..wPR.....I.
x...=....`.b..cg.....i.......D.$.5u..)R.....|.'$.Mq.f.8.....z.....&/.a
..d'.|....,w7W.kImG.. .....h}.....,...3<.O......_.{{...J.\We.k.q.;.
|.-..Il..0H..tA&../.......C{g.0.....<....N.......P5s..L..(..K..<
m....G.a.8..C.oWy).8..,%...ejA....$_.&.w......c. .;......x...p.hC...4$
....f.dn.........[H.{..m.D6X"..*....../.)?...F0s...Q.}....a.1.Uw...E!\
.v.c..&Z..f....<"$....D p....=...z..D./F.Z.E@......^...$..0..]...Z'
.M..`...,.R2.9._YYoB.i#..XPE..S..uSw..C...Sd../..c8.q..Zb..".....5..".
..eVy.?..........h. h.)4...........X...,...]9.k...j....jtU.....U......
.Z..?m.........r...*Nq...ovo.E..A>..zi.R.[..F1..Wb(...9..a...l.U.&.
<....<XK..[.4.../K*.a.h}.`..gP....."...........#.Qe...CY..[D....
.... .xC..XV.^.=....ks.k/..H.O..N]...2_|.w.Vd.....uF.J5..G...w..3..)..
nb.......CA.nc...To..S.y[..~..h..DO......^.L...'Yr.O.o......4Z..U*..5s
.Y,{.5CDH....[..}q...~.SjhU...h."..S|..p..i).P.w......@...7.....X.[3.h
.WA}.P..W.z.Ia.d.H.1.4.*......g...$e...u..F6...<..X.G.."....$cFi...
..'p..=h...;...e......f.....0..tb.M...f....%......lt..M...BK4hg..6....
..^m.......'.8zlP..;..kI...k Y.}....p..< ..3O...."........Z.......(
`...=u.a{..w.R..D..D...........$A~...P...,.....H<.0^C1..O]U..Y.\.[d
.h. ....T..=......[;...Rs..c.'.s.%T..4:.`..`.b........<8./...e..R..
.{>{..._._E.=..SxvG.......3.. .t.#04.\g.j.s.2|!.....z..P....Xq.

<<< skipped >>>

GET /iavs9x/setgui_ais-8a6-8a0.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 242876
Last-Modified: Tue, 31 Mar 2015 11:00:34 GMT
ETag: "551a7e52-3b4bc"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:40 GMT
Connection: keep-alive
ASWsetupDPkgFil2..]0..e0.....S............]0......e0.v...7...x..w..(..
k..m..m..m..m..m...|....I&.j.$.DHYDRL...D... ....'.2....,8..5..5A$2...
q.......0.. ..5P).R....*......A.*....W..H..Wm.l.7W.......k-.U.JU..J)UQ
*..RP(U......P.P...QAU....11d2...YXX1.e.`Y.@...P..0..X.d..LL.*C......A
L.E.... .....CF.......`.;D.....C&.F,.y&L..d.2.YXFyY`e..O...Jy&...2....
*?..x...<".....X.K......y.I.Y.,@... ..XyY.`....QV.ae.."....%.d.C..W
)[..y,...0.2.K..J....d..T^.Kd../2 YJB.......b...2Y...,......e..I.d#..
dbX..%....Xb,Y.."K..$.......`..."....If...b.y..^.@.T.i..xJ0T..(..!j..V
..h.R....6..j..^..h#.,......BZ.....M6[S..Q...îD..qdL.%...<..5....
.,..1.u..R%...2.......Tmk.J.Qx..V/.T..B....!yx..9Y........&...`R.."...
..&.$....1........H88...P.....2....h ...C.i..}..f.h..Z].....l.......KN
..ZU....^...J.&}.....!6J..j..l..iI,.i9.=...h'3K......J0oUU.J.ru.v"k..I
). .@.9........u..K.$..8.. ....3..g....6....*.l..1...h..aYn#....Dyi.=.
.`.[...RUC.%.{......M..K^..>t.Y{_...p.Cz...aFJ.]@=..O..n.. kU..4:..
r.1#."9..........`P.D...j$..R.O.....T=.<..,X\.5..8.g.pIM...........
.7.-.d...Z.]Y.Z....F.G.9..s..S.l<..%.f....&p...L<.....5.h=y.C...
.....,0..X .....g.ho?1.Z........X..hU...J........"mv...;Y..,.~.0.S..{e
......6gD.&.M.hY.].T....R_.g]q.J....a........?0{......g../..9..#r..Oa.
.p...}.....Gf4........7.\....<=.<$..-F.C^.jH.X..y..c...O..oa....
........L.F.K.*..b\)WZ....S../~...l....C.i.h...n.}2.....4^._...f...-.z
.....H..U.....Z.R0..../*...^G....4..7G.......{....w ..QAYK.r.`.`.n<
....T...Q.N.at.D\..v.[......]%yf-.e45.\)..6E......I._k(mZ}.Ye.d...

<<< skipped >>>

GET /iavs9x/setgui_ais-8a7-8a6.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 1600
Last-Modified: Tue, 31 Mar 2015 11:00:28 GMT
ETag: "551a7e4c-640"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:40 GMT
Connection: keep-alive
ASWsetupDPkgFil2..e0..e0..................e0......e0.........x....O.BS
DIFF405................e0.....BZh91AY&SY...w.....x...@..... .!.=F ..T.
.w..rE8P....wBZh91AY&SY{.........p/_>K.=._~....[..:.^f{.4...{.....P
.2.....4.2......44h.1.4...L.M....h..H2i.OL..$..I='.......h.......@....
.......S.!9.z.Rq %.P....p..........B.....$.T... .".B...{..U?..*.N....F
,.G.0..._..H0.j.:_..~eF..Mx....g3S.T..P"KZ..)r.........4...A.t..'./W.(
.-M.<..C.1p...&.#...r#t....0..0I.u.........58..e.....5xt..m...{....
..$90..~..w.=,.-...Y\...(.o.=..)X....v..,..3. ..,j/U:?hg..:.....~. ...
.....*..6z...qe.......P.m.rPI..Pe..........g..........N.$....@BZh91AY&
SY9.g...0.....................................P(.(..A.z....4....I..26.
#i4...........6.A..1... ........6..<MOQ..x.OI.i.e.)....LS..M.Q.<
.&.$......24..6........@.....@........hC.$..H...b.8;<...Tg.:.=.%;.]
..2`.............\.1 B>@.;..).M...G.i..Rx...QC...Q....n{HP...A...1.
!..Z&...."$.....A..v.... s....v.0.BeP....2...4....s..c....2.j.u.k.c*.u
.1~...iI(y...).0*......g.,...,]..]Y.H.....F...K?..E.0..E.Z.7.X0..8\za.
. .T..xd-....q.J .....xl.Z\X:.K..[...._.....b....w.."..m.....h9...D.N$
:.s.^l.b3.....k.d.zO,;..d<.....N.k/7.o..14..w-|L.z'<2.......XhPj
q.H........jJ..........e..V._.#`.Ct."....n.L.I..........Q8.vY5..\..#o.
d.<:..}8. ....(.U(.VR...(......".[...........j,.]..A..q./.4..*.m".`
%..){.%|.o..T.:...S]dbJ...4....(...6.........j......m............)S$x.
......edR.f..."..-#..##.nM6!b......u.d\......R..[J.)x..7...w..G......k
Y6.s....S........(.c..&b...#.?........w............b .....'...6a.i

<<< skipped >>>

GET /iavs9x/avbugreport_ais-8a7-8a6.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 57409
Last-Modified: Tue, 31 Mar 2015 10:56:30 GMT
ETag: "551a7d5e-e041"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:28 GMT
Connection: keep-alive
ASWsetupDPkgFil2..L...L...................L.......L..R.......x.t.cp&`.
,............m....m....m'......{oW.L......_].BJ".bb@Fix...^...q...s.i.
s2.jP(idRoZ....~......../yy.......`......0..e.....Ig..E.".7-X....Q....
.,. ..%C.%J&..b9...rJr......r.i..%........eOl...9.D.r.....K.9....%.c..
@....8.}H....3.....`~I..a.gN~..p<C,P..9Pxi.0oq.Ii.-l.m.G8.,.E8O.Q..
9...P5......H.#H..5.l.<..W.9...1{.g..2..\y!iW...CE.)..5CW.{..|u....
....8....T..W...7\4...#i.heR....eu...}..B.?o.j..D.:......l..;a^.g.Lg.i
1.).qW..t.m........I..C*..K.U..K.3F.Y...;...LI.W...:.....f..t8.'._..)D
.(..T.0....n...bX... ...s.$l.L2.QKO.xu...........'.........z...kj...k.
.....h.5.....2.....2........&..e.^.g..C.Lp.].@..}|.bn.."=.!YB...!..8.n
%.ty...........O.u.;...5.~P...YVl....5..&\..hynb..d...Je}O{p.>...$.
1...@...Qw. >.....-x.'....../..@..9.....>8.V.m........3..f.pI:?&
lt;.'.........u._h.C.... o..{?.O.;c.>V..?q.V.YO...B...._.O.*.N1.m..
i.....j....#.V.K....~U..........4&...=^..x*.X}..c.2..7.QE}!.\.I.......
..-.o.?77.$.....j.;..y..~n.......I. ?%..5!...`u... \tFu.f..*M4...gL.}.
...H.*...)...B...YO%..l.......r.<.DTE...5cr]x.. . ..JX.8..J..t...#.
wW.U.b.h..'..1.K....h.D.H.E{..5HzF.G.W..Ek..k-%TYF..7..~....'.....p...
...~...)..l^..|v.....-.<h....wx6..fOPK....sz..a..{.[..QVQ'.br.U.$..
v......Cd..{er^....Lr.#..P.[...1.a}..Z.]w.. .S.......M.x.^.Z.....[S...
q....i.....v...c>.....C*-..swM,..N.G...o.. fm!...Z,.........h......
.V...").a..M..z..s..Et..Y#..(...6C>.....Y.>...1.......H...w.F..?
L.A..j....|O.....'...~....O..C{^..n].....QR...m...-OC...y.:...}.[$

<<< skipped >>>

GET /iavs9x/ngiodriver_x64_ais-8a7-8a6.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 257
Last-Modified: Tue, 31 Mar 2015 10:59:22 GMT
ETag: "551a7e0a-101"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:35 GMT
Connection: keep-alive
ASWsetupDPkgFil2.(D..(D..................(D......(D......|...x.s.v.ts3
10`..=(......2,..#..#.O_....z.!A......A.AQ.......I.I..NN..NG...WO.e`P&
lt;.p.....a....V.W..lrzO...*..W..../r.......u7".^/.n...2.........5C..8
~K.1|.!koJ..5.`....Z..5..$^6..............ASWSig2B..


GET /iavs9x/instcont_ais-8aa-8a7.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 32307
Last-Modified: Tue, 21 Apr 2015 16:33:45 GMT
ETag: "55367be9-7e33"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:30 GMT
Connection: keep-alive
ASWsetupDPkgFil2.@...@!.......}..........@.......@!...~...}..x.T.eT.0.
.;.....Sd....^.@q....X)^....3......)...>..~.;g'Y;k.g. wvv$...de.<
;.(......x.=.....T.WB.....eV.@s............. ...W...M.../m.?`.&..D....
"}m...%....S........B....u ..- ^.#WR..57d.oPv...N...6OM..|..4w...A-..:
i.#)...../.... `.9.....@.S......."....BC.dQ..(r.e.Y....s\..-.......D..
.n....n%#..!...w.....k.LX....q....v..u..t-B.....a.C.X? ...Ii.;.3..<
../.......7...*j........9.K.3.3.....j..4(B.;..f.?&.U.\.6?$.e...b.G..J.
.q..d'..`f........2.2.8~...~.K....%. .. k.r...Z.qgr.q8.........h.....b
.4z..".FW...4.\.2N;.&....jF:.:w=.,.>..y*........O......#9o.V.E..f.v
.8....V.vu........1.q6L1......n..%...S..!.......s....x.O^x.QS.p.~e(.?.
.V..8.&.{.~..|U!.M..UU-Q.}>....Q(M{.......t{...7....=...c.......L..
.....3..=..InAh.[.1Y.c...a.=.y4.l...A.../2!..d....8..UA..-.)..[R.uU...
..vW..C...V...3Z.].n......`7..f=D..QL...Z..N...}.2.[uW.[}......a.....E
.Bn..............v?-nA....}T.N.a..D#............|....M..D........y.#.1
....;>*F"..y...2`.:..4./.N..2.$.EK...cIK."...=T....P..%8.wnhi.1^F..
....[......p..........Mo..V ......."4..^...V.>.g2T-2m|...~.........
.Z.R.p..@;......S.H.@u[A...R.O=._Z.*.'.....)...XRu..2d....=."....~[e.a
.^twjX.#.|.(f..#......&_.i'..z.nO......`3.:s-.........v...T.kV"8./.T8.
.\..pJr...N......<..1.......$...&...]..M..R..'.*A...b%....q=.,.M...
.,.cl.V.ngGP..w.......2.a.....V......Q....&._Z.}... .Q..O.uC..ey.C/...
*GW...m..a(H.a...;..O......".......G.a..g...sDha.%H..;..y......?...#/.
^.N.#.}...j8N.#1...../fBc....C..."......TdBd.4...........L..AH....

<<< skipped >>>

HEAD /dl/toolbar/t7/data/7.5.6227.252/googletoolbarinstaller_en_signed.exe HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: dl.google.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Length: 5059928
Content-Type: application/x-msdos-program
Etag: "506e4"
Expires: Sat, 25 Apr 2015 03:01:15 PDT
Last-Modified: Fri, 27 Feb 2015 23:15:00 GMT
Server: downloads
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Fri, 24 Apr 2015 10:01:15 GMT
Alternate-Protocol: 80:quic,p=1
....



GET /dl/toolbar/t7/data/7.5.6227.252/googletoolbarinstaller_en_signed.exe HTTP/1.1

Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Fri, 27 Feb 2015 23:15:00 GMT
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: dl.google.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Length: 5059928
Content-Type: application/x-msdos-program
Etag: "506e4"
Expires: Sat, 25 Apr 2015 03:01:15 PDT
Last-Modified: Fri, 27 Feb 2015 23:15:00 GMT
Server: downloads
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Fri, 24 Apr 2015 10:01:15 GMT
Alternate-Protocol: 80:quic,p=1
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$........R.&.3eu.3eu
.3eu...u.3eu...u:3eu...u.3eu.3du.2eu...u.3eu...u.3eu.3eu.3eu...u.3euRi
ch.3eu........................PE..L...r..T.................z...8......
9u............@..........................P........M...@...............
..................| ..H....p................M.X....@..................
.....................................................................t
ext....`.......FL.....PEC2*O......`....rsrc........p.......JL.........
.... ....reloc.......@........M.............@.........................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
............................................7...l....7........{...@.k.
i..Y.. ....O}...X..Q>!L........f.l.Hs..s...5.*.O..{0=L...L..j2}.\b.
....s?P.........n......}M...^.......7..........5..).SF.f6..:.#.0...@|y
.a-h......5>b......Jb6......u?l.q..Iu..fI$M.ex..A..5.3.)......k..u.
.~....y...U:..[.B..cHD.X...Yn...c............@..........2.F....q.."%.'
..E.........).t.............{%...m.n............y.}.s.......a(..."....
.9.f...#."..l/....M..aA.3M.....B.k'.......]..z..w.8.B..2..S.z..l_....7
=..3I[.l(.V.I.......!.K."c...`..5.7......w. .........3A...`.~.....

<<< skipped >>>

GET /iavs9x/ngiodriver_x86_ais-8a0-89e.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 2124
Last-Modified: Tue, 31 Mar 2015 10:59:23 GMT
ETag: "551a7e0b-84c"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:36 GMT
Connection: keep-alive
ASWsetupDPkgFil2..>...>...................>.......>.......
...x.E.{8......6..e$.....k.X..;...I.1..-..2:....e~..3........J"..[..u.
vN........<.......9...Z....2........(......Cd.0G.@..L..............
.6.%U.8.I. ...h.~Qh^q...H.!.%..K...#.....)..{K....^....ja.#..`..Jp....
2.k..M..H.6..,b....$.]....)D....0..<.[qm]m...%mS."..G.5\........&.^
W.VA..S/`....K.I..w....D..mX.z.h..W..8..g.....aM.T..CrJe.......2....C.
vy.Mf.dP.|VS....)D..%.`j.,.$!nm...n..zUQ.D..:...Z.P::..4.C0.3.x..=.0.!
....~...C.O........R.....O.g..7U}.X.S{..j..1;u..f.a....?.G.....'.?2.b.
...$@uo=7..3..;.....N.N.sY.c.._..%~..d.z..>..A..G=*L&Z0l..A.z..lo."
.|W.Ku... }>....T6T.y...QK..e.....f..>...|.;\...o....u.$.Ei _.e.
f.P..ED......./.%..5.......M.....u..uB...G.jPR.|.._*..*.8......<...
w/.5].3j....?. M7.6^...sE.37R zAX.4.P....gn..F,......@.....}.L~t.m...9
.....;...u.7^./VCs...5t.........#..,.%..U.....o.R.......N.3....N..:.W(
.w..u....t5........eC\...O.=..6s.V&:..J.:bZ. .....fBw.=..Q..7....S.q.I
...a.9.iiT........H...[c-........q..|.T9.%.qh.. ......n...8c..v...#^..
... u.u...G.a.x......$....s.p.....t.(..i.1V..F.?..'yR.....#.uV..,]....
.....Vv.........^.X.b;.....t..QB.....&.`..W.=W..%Py.g..f..p..b....N...
....M.........D....}.....}.......O......U..x..AA1Z....<.p'.Z|..O...
..@.G.C..4.Pb.....U.^...^...........-....]k.h.4.c..%<L.]..}>;..m
0O.OU._ ..z.Z...QKp...oa!.......,..I. ......e..r......J......\* .%0v.;
F7.T. ..y.D.$...........bG2._J].f..Yk..."..x.. ..<....b. (.....c...
=..z...^.......u..I........>.....M0.....d.....>b.O....#..!g.

<<< skipped >>>

GET /iavs9x/ngiodriver_x64_ais-8a6-8a0.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 3971
Last-Modified: Tue, 31 Mar 2015 10:59:22 GMT
ETag: "551a7e0a-f83"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:35 GMT
Connection: keep-alive
ASWsetupDPkgFil2..:..(D...................:......(D..........x.e.w4...
....."Q.ZE4U.H..VC.{'T..=j 5.V.X..Q[...V.....Q....}~........s...{...|.
:JSWK..{...m.......h."...(...dm.pM)....r_XS..Kq...4.."..@........P..z5
...9p........`.1..q......8.I.....ad7...P..]...........U.O.$......{/.7.
...i`.....F.....(. G.....9.1..>DB$.W....u....{..1K8....`X..w...$P_.
....Y ..5C..>...h...@..U*$B... ....rm..H.%y.. w>....u.'(...A....
.........vz.....cq....z:..E@1.@"... ..,::.].y.RX..i.)O..'V..i..... ..w
...V.l..... A..Q..$.q..I86m...p...QW.0............<.2...(.].R.....L
.E. .....4.5.R.....q....J....1g..7.&mnN~.Q..05...O.......L>.hKb.(..
..G<e5.....f...I?........5.....~L..!.......1hN..X..h.#=4.r.}......M
6...&1..x...Y.GA:.$5kl..'{hY.q1p.3.....Y..5;P%...R|.K#xg.P......y..L.?
z..........X.....mR..~O.h.C.*.h.G."..].9/...........U..<mE...e~....
...hB...)......s.M...H...P.Z....B...K` .,D@...98.j:-.{.S[?x8:...l....y
?.A*.Kg0P..7.f..@.~..zp]Kf......sk...... .9.9E.S.Fl.#.nE.Clq.....1..&l
t;.b....V....?1....w.........K..ha......\Au4.. ..........n..7z.?.<~
.>..v..S...R<.].....uq0-.eH.....MQ../........ V....y.......v.0..
...kW...G..:...oy&0YJP..hX...-..u..b....z...>.XJ..D...W..._@....0..
..2.....t...Qi....nd.h.x..(.o$*......|3S/.LMCKT.0...........9..#...h(
...5=1..K1B...S`B.XbUp0.B.Y.<...e{PyvG.h.S.3.ax...9....t...n...\K..
...<.V...| ...J..99......H...P Fy......&L..'(. 5.4.......}Er..W....
.|..s..y.....5\.........W...6_.JF.{..jq.p.l.F|.>....C..U".Q........
W.......=...............J...I.....k .M6x...........(.7.ncjv#......

<<< skipped >>>

GET /iavs9x/avbugreport_ais-8a0-89e.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 71525
Last-Modified: Tue, 31 Mar 2015 10:56:39 GMT
ETag: "551a7d67-11765"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:27 GMT
Connection: keep-alive
ASWsetupDPkgFil2.PU..PW..................PU......PW..x.......x.tzc.%..
.mLOO..m..ms..m[.m...m..~ow_v.........JNr..E$..X......I]....1.'.iYp2.j
.)k......|~.?....&...?........5.D..|.......OR6J_ b.#..(....<7&..D.H
'^.Z.&..W.k...F.2.C.<3.Yl"".x.d...(.y...Y..".../(?.....dZ....'4.g..
...2....0..0b1Y.'....!#..[.3YL..d`...Yf.....x.i...w....HI.TU..O....a..
..s......x..UgD{.:....qn.OC.6.[...;....B.r..&....Y.R.o..@W.\...U<..
..qQE.]..6.....gl.E..* I.MU..8...V.Xa.&.Rj....w.RA....Z..^...|...$.{.X
..a... kVk...$......~*.. @%/..G.B....n.n=..hG%......l>.1...?.....x.
...Yj.M......\B.I_....,...ZiaA..%.BF.:..k......ZZE.|.......h..)n....*.
..A..z......mS.H..p...=...N.%..SJ1:.o8..F.N.....!.Z.....@."0..9\N.wA..
...gj.[.'.d...^..F...)h.......P........WkP...r6M.-tw.....\...r~.oY....
.......i.dds...f...J..3c.O...3.Z. ......\....j._r%..v&.{..Cv....Y#n...
..pI.y..`MW.=...,o.8....S..~k.y..Q..... .....5.....?..hHI\p..*. .:.Hp.
...s........<...P?....J.gH..V........e.............n..i.)^}!y..F:VL
....|6Q..T...`i.;..!Kj~NDo.....@.....lCGOQ.q.......&.(${J ....(...!..A
...m."..J.... hxb..v.b.I..z....%...s)3r.z.p..?s}2...0.No.f..I..^..{.o.
..[z..?.<...CS.7..A....._....)!..|{p...l...0#c.......%..V..{...Z~`(
L=.x.M 7V..k7..57-0..dD..M%yH.1.W.......s._V(.....`KI.G!.yac...;.....,
...~L.=HH.s]..(H...8.......V.vl..c...jh......C<>.Lu...V..w.._-K.
.E.M7...2g.(83.4.O.Qr.....#.{...&.E...U....H.8........6/....v}.y.d....
6.Q 0...!<.&O.2X ...a..^..\s# 5.J...Q..R.B...^]..-..4U..D..<--V.
.....R.:....g.2.f.%..o.~A......Q.....nN...%.Q..g.}...By....l$...]F

<<< skipped >>>

GET /pki/crl/products/MicCodSigPCA_08-31-2010.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com


HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Tue, 14 Apr 2015 05:02:07 GMT
Accept-Ranges: bytes
ETag: "2711f7277076d01:0"
Server: Microsoft-IIS/8.5
VTag: 279782516600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 554
Cache-Control: max-age=900
Date: Fri, 24 Apr 2015 10:03:04 GMT
Connection: keep-alive
0..&0......0...*.H........0y1.0...U....US1.0...U....Washington1.0...U.
...Redmond1.0...U....Microsoft Corporation1#0!..U....Microsoft Code Si
gning PCA..150413163223Z..150713045223Z.a0_0...U.#..0..........X..7.3.
..L...0... .....7.........0...U......Z0... .....7......150712164223Z0.
..*.H.............WK....e.\.-.n......./......."]..E!.. //=...[....w...
..........#...[.l.J..f|..... .s......w...J._.......3.[..#.z....ko.I..
Q{....e.nV......F..d}..rF\H.jlH]dQ.E....x......W............j....&L. 2
.$.?...X?.#.(.....pK.v.......y..r....t......=.AW......K.G.gJD.b...


GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTEemCaVgs8Tuh2B9fGVE0pKKNyzgQUTF+nNhcF4oZhIkk5jLmo40rgOBoCEC6utoKGY/7ZdVX4/iTzOxo= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1552
content-transfer-encoding: binary
Cache-Control: max-age=518558, public, no-transform, must-revalidate
Last-Modified: Thu, 23 Apr 2015 10:00:09 GMT
Expires: Thu, 30 Apr 2015 10:00:09 GMT
Date: Fri, 24 Apr 2015 10:01:40 GMT
Connection: keep-alive
0..........0..... .....0......0...0........C...4N...@..6...v...2015042
3100009Z0s0q0I0... .........z`.V.<N.v...TM)(.r...L_.6....a"I9....J.
8........c..uU..$.;.....20150423100009Z....20150430100009Z0...*.H.....
.........{...M...p.....?.T.}....;.. .....P...}....b.Q.)6.{....`;......
..23.P|9.S....C.......B.....?....k..N>........B..t6.$.o...(.@.x.=..
....P...I.lm.J.M.}[`.@...P..h.a.G3.o-#5.6si..M]...m.9....m.0.0..Tkf...
..t...hx...\...Q.#...YE.p....W. .4.7-.k...g..b..\.k..0.N....50..10..-0
..........y.P}~.EY....T]. 0...*.H........0..1.0...U....US1.0...U....Ve
riSign, Inc.1<0:..U...3Class 3 Public Primary Certification Authori
ty - G21:08..U...1(c) 1998 VeriSign, Inc. - For authorized use only1.0
...U....VeriSign Trust Network0...141202000000Z..151216235959Z0..1.0..
.U....US1.0...U....Symantec Corporation1.0...U....Symantec Trust Netwo
rk1?0=..U...6Symantec Class 3 PCA - G2 OCSP Responder Certificate 30..
"0...*.H.............0..........6..]......w';.r........I..c..4.... ...
......TyW......hd_.....!C.k......SE<?o.H.. .me.c..9N.&....e.^-..a..
...i\:..*."..u...|....".Nf3.~.L...QW...p.....-]UV8U...J&.<./.G.....
I...4.T....#I*.i.E0\..~q$.I.......X?G....f.t......v.l.U.Ld.I...B.....=
...Sf...H.s.........0..0...U....0.0l..U. .e0c0a..`.H...E....0R0&.. ...
......hXXp://VVV.symauth.com/cps0(.. .......0...hXXp://VVV.symauth.com
/rpa0...U.%..0... .......0...U........0... .....0......0!..U....0...0.
1.0...U....TGV-B-2740...*.H............1.`...i.....H.C.i.9~.i..Z.r.*$.
.(./.ag9.....J.Q.~.`.$?b..C....<.h.........d&....3.kV.....f...3

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRODEXefhs/UZFum2o8YfzOFwceMwQUkz5j3yJ0BOBkhDHd2yOfDq+2TZMCEA89qsgV9niZmSI6gIO0S/U= HTTP/1.1

Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1725
content-transfer-encoding: binary
Cache-Control: max-age=582494, public, no-transform, must-revalidate
Last-Modified: Fri, 24 Apr 2015 03:44:50 GMT
Expires: Fri, 1 May 2015 03:44:50 GMT
Date: Fri, 24 Apr 2015 10:01:45 GMT
Connection: keep-alive
0..........0..... .....0......0...0......%bn.$..5.......?'4....2015042
4034450Z0s0q0I0... ........N.E.~.?Q.n.j<a.....3...>c."t..d.1..#.
...M....=....x..":...K.....20150424034450Z....20150501034450Z0...*.H..
...........t........=..O...i...9....... .J.5.]... ...[r.$M.!.bD...z...
.o...30^.u..l...6.N!.K.C......S.,'2......4.....l.... ....I..2.}.&..x..
/C2..x?$n..`.....-l.2..'.>9@.V..iYp......$.x.....A.;....)U*R..r..i.
[]..T....5Q......t..R6..4.7u....3..`..c..xLk....i|.S....1.~.....0...0.
..0..........7.R.~|..r."....#0...*.H........0..1.0...U....US1.0...U...
.VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of us
e at hXXps://VVV.verisign.com/rpa (c)091.0,..U...%VeriSign Class 3 Cod
e Signing 2009 CA0...150401000000Z..150630235959Z0..1.0...U....US1.0..
.U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1VeriSi
gn Class 3 Code Signing 2009 OCSP Responder0.."0...*.H.............0..
........z..|..>.....5.Z ...2.C MWIH.5......M.\.... ...eW..`.B=..`:.
.R. ...Z.k.Y.....p@.(3.c....a.;..[E....J:'...`...B....M..&......{. (..
......%......^[v[....m....*.T.o&4..3.....3.........G...e)...'?.K..2s..
8=?..z.:..T..-.8R..8wv7*U.K..c...<s...]{.........6.?_...........0..
.0...U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://www
.verisign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS
incorp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0.
..U........0... .....0......0"..U....0...0.1.0...U....TGV-B-34920...*.
H.............,..-......q3a........z....t;B.z.h...]...#}.6.,..YU..

<<< skipped >>>

GET /iavs9x/ais_gen_gui-7d5.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 1750979
Last-Modified: Tue, 21 Apr 2015 16:31:30 GMT
ETag: "55367b62-1ab7c3"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:22 GMT
Connection: keep-alive
ASWsetupFPkgFil3GkY.c...].....$....8......7`.....~..u7.iAp!....r..^.Q'
.k4.H*.4E.s.."...x6.1es..:...DE.!......O.O<...Uc@d...{.......-.].d.
..O..0..(.R%?.U.tsp...D...%,..V...n.1...qi3 ..\..M2N..}u.z.O.8..5b.B#.
.Q.^..A.....f....$3.....E..u..Bx..-0&.....y...xB..J$..dA..$in.;..>.
.....TE.....1....qgs.p.. ..W.......!.F......{.=.U.. ec....H...p.....".
.=.a3-... .G....6B......Et.8....*..Q....(:.m8..K..^......~.^.4........
c.=.3b..mwK...M..._m....B..L.N......K...}.3......-..*..Z.k9c>.....2
.@.......U..V..v.............3....Z.emZ..j.7M....@..a.c...5WQ/.3..'..]
I.5...C-l../...[(arL..S)r.nll...5.D..3.Q1b..%.D......b..@kt.!...a.?Q&.
.7......*`..?Ft7..7..Ij.....64.].u.[....*@;W...S..'~F..>..S.BO,...|
. .....`D.r.S..t,....d.M..i D...}....x.T ../.Q.S.I.......... e^.......
.'.M.kL~..#......8...L.m`...........k....6..J..(...$..2..].X.-.....%v.
..........3.x..]C..G.......{R-i.V;"M&[.L..^.....^...Q._Q...^.rp..5...e
>c... .V.E...#.-?.T..B..?%..XP .......#YKHy.c...........-..V...3.99
U...|..9.<......AM...........W..RN....,.q.H...Z..U7.2..!.-....!S.j.
..Hnk..V.|...F....a.u.._..i....@.F1KZ.B..Lj.R...D.s7..X.Uh......!...5m
.p8.......I....../.S....L....1r{...FI....".....A.pb\f.i.......R.Z..7U.
#.Tl.@...o[;1E.^.o..A~a..}....,.4..`!.-.wx....Pf^"... .C.H...?.....I..
Cs9......!.3....".'...P...o... ...Ws.|@.D<4......J. ..YO..7=.*.,...
&.V..b2.g5...&Py....^'.y.Jr[...dc..Z..A0b.2y...)b.h~..#....A ..C..R.-|
...T.....yp..JL.7.r>.....J..)]}.#..j....-z....X.b..$O..xY........N.
...&......r..U..U..x.[...L...(...k....[.p...8.aP..-!.7j..L....r...

<<< skipped >>>

GET /iavs9x/ais_res-7f5.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 1591941
Last-Modified: Tue, 21 Apr 2015 16:32:33 GMT
ETag: "55367ba1-184a85"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:31 GMT
Connection: keep-alive
ASWsetupFPkgFil3..T.%J..].....$....QiJ..'.....w....;..3.....",X.......
v.'.5.2H...q7U.....p!...)6C..].........T.R?.D...d.....{>....?......
-UM....MAo~.j..ok.L6.D......f....9..".|..W...,..>.\H..%s.{...g..l..
N.OJkF).........@...[]...@9c..q!..Hbv4u@yQC.w.E.....*r...d.Q.(^,..qM..
.......c...M....G..4......y..._..mW.[..&.eC......D..:...&....(f..e....
.. .P5.._G@#..'.T..(.F....L........~...D.<.P_.....}.:.S=..u[E.....Q
`.Se5W?........z...{.%.t...@...s..........>.P.8. ..IR.!.)....I..^..
........8.....Q\....8.......}.g1..?.l.!1.=...$.........h4.%..B.oF.UU.s
....v..].i.4..4..!....._..F........%.%...%2.....9..|]n.Q|;..Q.H..$...
.XE.L.e.?....C.h.yh......~....5.5e..[.Y..'..{..0....RQ...FJ.s.<UH.L
..I.^...`...G .2e*]..X77.^....K.o!.Tw>.. s>.69....]...]....sc..x
......Ri.t.M*...[(X..m,...]..K..fJJ.s..0.L..\yO..q.*Tg5....u.......n..
w...XQ.%.kmdp...sD...X......w.o.j..Yu.K....l....%.o.....v.TxE......lX{
(.h$......i..q...6mU&T..H...S....qpD.#*.>jCg......`. ......3T..}xs.
[.s..9.......=....[/.f....9,.o;....20~-.... :.w^..We4y............B. .
....n.8..3.....).....E.q......K..^-.wt...@dE.:.~|..-E.04....q...;,.v..
..........-....?....'TH"..6......m8g. ..../.}.>.:s.,B.f...bm.&...@&
gt;#....R.......5xn..k...`O...4n..4.9.S.....K....#.V......s.l..Yv..1.N
.$.7....h.$.......d]C;.}{ D.v*-t..A.....[..Bb..".....n_.)z..o.%Y....V-
......[.....N........U../...q#...E..5....v.'.96CI..$.aI..I...C........
).Q....O...e1...........%.A ..5.Xu..{...R....ZmB}D.8.Y..e..7.......X..
q%K?`.|.QV~...$.....vM..%.h.!.7.(d......"S....._.).'.D...7.3.>9

<<< skipped >>>

GET /msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8375aa7c3aaffcf1 HTTP/1.1
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Tue, 24 Mar 2015 16:17:41 GMT
If-None-Match: "804047d4e66d01:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: ctldl.windowsupdate.com


HTTP/1.1 304 Not Modified
Content-Type: application/octet-stream
Last-Modified: Tue, 24 Mar 2015 16:17:41 GMT
ETag: "804047d4e66d01:0"
Cache-Control: max-age=86400
Date: Fri, 24 Apr 2015 10:01:18 GMT
Connection: keep-alive
HTTP/1.1 304 Not Modified..Content-Type: application/octet-stream..Las
t-Modified: Tue, 24 Mar 2015 16:17:41 GMT..ETag: "804047d4e66d01:0"..C
ache-Control: max-age=86400..Date: Fri, 24 Apr 2015 10:01:18 GMT..Conn
ection: keep-alive..


GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1453
content-transfer-encoding: binary
Cache-Control: max-age=583543, public, no-transform, must-revalidate
Last-Modified: Fri, 24 Apr 2015 04:05:12 GMT
Expires: Fri, 1 May 2015 04:05:12 GMT
Date: Fri, 24 Apr 2015 10:02:56 GMT
Connection: keep-alive
0..........0..... .....0......0...0......T3t.%..O.E..~..F.=....2015042
4040512Z0s0q0I0... ........H.dI.....3..^B...d6Q....ZL%."..1.m..._)..a.
.eR&.....Y.)..".\....20150424040512Z....20150501040512Z0...*.H........
........UJN.z...%sp.&.Wp..WX.W..D.R..Y..`.*A..4%....|,.8z.8.R.,....@..
OJ.....zMp.$!..a..L......~^.y.. YB h..L.",.......7....3|......3L..M.F.
........C. a.!{.&.T.....5..E.!vc.%j.....*)..01...fd..........67.....|.
0w* ..9."...........b[..C.........m..K......v..........0...0...0..3...
..../...b.v..-....l}0...*.H........0_1.0...U....US1.0...U....VeriSign,
Inc.1705..U....Class 3 Public Primary Certification Authority0...1412
02000000Z..151216235959Z0..1.0...U....US1.0...U....Symantec Corporatio
n1.0...U....Symantec Trust Network1?0=..U...6Symantec Class 3 PCA - G1
OCSP Responder Certificate 30.."0...*.H.............0..........'.....
.Y..x.3B1.7..Q..`..d.. ....s..t.$a.....j2R.{ ,*..c{.3.....H..3-; )....
.0._...*..9M..V...... ...{m...-.......)..tR..{D....~...M...T..pS.p..^|
o....S..v.).).....r.v.qo$......C.V!....@.h#qh...u1T.].G0.]E...=._.....
. ........TE...Sa.s4........r...3.............0..0...U....0.0l..U. .e0
c0a..`.H...E....0R0&.. .........hXXp://VVV.symauth.com/cps0(.. .......
0...hXXp://VVV.symauth.com/rpa0...U.%..0... .......0...U........0... .
....0......0!..U....0...0.1.0...U....TGV-B-2730...*.H.............$..H
......oU....Y!.z{*.V.M..u.._z..3>.. 0....3..m.....e.......a..D.....
......e..F6:.y.....di.......<y.Z.......x}..q.2....UZ1 :,
....

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= HTTP/1.1

Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1790
content-transfer-encoding: binary
Cache-Control: max-age=387944, public, no-transform, must-revalidate
Last-Modified: Tue, 21 Apr 2015 21:45:16 GMT
Expires: Tue, 28 Apr 2015 21:45:16 GMT
Date: Fri, 24 Apr 2015 10:02:56 GMT
Connection: keep-alive
0..........0..... .....0......0...0......'.V.8.F.V....H....JW..2015042
1214516Z0s0q0I0... ..........!7h....O.d...AG&h.....k.&p..?...-.5......
..M.s.Q~...@?j.......20150421214516Z....20150428214516Z0...*.H........
........ @H.L.D.Um......v9...Q..Xijo.....;&..W.....q...0..(`I.e.H7..:.
..ENLn.pM..........i.`w.&2*..6]`!P._ .zj3..'6.fS...W8W...X.uV./P...\.j
r......lo....G.&#...;Xb.....D.D.......q!.t..dB.H....yB../..^.U..Hm.0@k
P\X|...........Lu9..s.....?.VeC.kdmd...j..h..k..C4<...#0...0...0...
.......r..?.*......y"..0...*.H........0..1.0...U....US1.0...U....VeriS
ign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at h
ttps://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3 Code Sign
ing 2009-2 CA0...150226000000Z..150527235959Z0..1.0...U....US1.0...U..
..VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of u
se at hXXps://VVV.verisign.com/rpa (c)091<0:..U...3VeriSign Class 3
Code Signing 2009-2 OCSP Responder0.."0...*.H.............0..........
...m5*R........2....>...yU4..L.. ...........u..Hez..Pn.....d...nz(.
..V7.}^...d!RX...bl..[..a...L.. .~..Ij......%..%p.-...u..:..i..F*]...*
....{NH..|0...gHX.Q.r....S..........._.9.(w...suC...N..s.....&."...:.C
.Q.i~rl..<..krS..8.B..o].y..L.4...iB@..s.....mw.........0...0...U..
..0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.verisig
n.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS incorp.
by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U.....
...0... .....0......0"..U....0...0.1.0...U....TGV-B-32010...*.H...

<<< skipped >>>

GET /iavs9x/instup_ais-8aa-8a7.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 625225
Last-Modified: Tue, 21 Apr 2015 16:33:58 GMT
ETag: "55367bf6-98a49"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:33 GMT
Connection: keep-alive
ASWsetupDPkgFil2......_..........................._..........x...C.0..
....m..m..m..m..m....;S3..6.*.dq.&.T....e..j../.....y......9.........Z
0 ...........C..`.....p....... @..^...2....FB$.Z*W. ... S..C._..WV...S
.H......#.....@g...45T.. K.S.'. ..........M...fa.k...5.....9..VQ.P.[J.
..O7V7....j..R.W.p._.....b.64.ViXQ....v....ni......l$...$..n......TA..
&...Gq%/n.(L.j....\.'G./....8..Hb.@A.C. ...f*(...*. .XY O.2...3.....I.
.9..T.2P.....?=...y!x.|...y.....,...,"..,xx../O'......d...............
.(.L.6_6^.V..g^(....O.(..W.[......g.@........@................/.q.Jb..
.|..rB.e.v.KJK.KJ............................1.r.$|.e.....yI..2.d.2..b
...Y....J.E...Y"...,<...g.6...d.....6..7J.6r ....................I.
|..%..b.`qA....h.B/..o.l>>o.Lj.@.X.O:.XQ.,.. m.N*.......%......
-. .. .z.@.......Y.2.......:.uG2.......G...V.Dr...Ln...e.`)Q.HA.x.=...
Qj..h> ..)E1..%z..d.0&.........m9R....0m.....[./..A...Q..-.12.o.B/.
K...ENy...J ........=.L..D...N3...)BS......Ca...a...z..B....A...o.^:..
.&...Pl..G.j......'x.Q..\=.`...rE..%...).../..d......0..z....S.D....hA
3N/.l?.d&..,xh&.....|.8.F".^'.....Q=. ..e..L.[.<...C2=..x.g........
..~R.1.]..syN*IUE.f{].`.-....tM*._P.o.k...BT..!m..l..!.n.Z.U..Y.b.8.Bm
6(..J.JY.i.......Al.Y.0jL......L.CQz.b.......Ni.-U{..xo.YIi.....6l..P.
..; L..ua.0..z>0..2..@.]Y=.U.o..^...o...C.!...|..Gd........*.A..PU.
%xT.....Z.&..fY}..VrP......X.L.)DJ.J.e....>..~...=.{EEcz.PD!.....B.
.A|B.QK..c.}.k.Ix5....L.X#...X... ....8..V.@..`.!.2..........V.V....#.
.5.@..6..e!......Hta.w..vF:.....M......fg......]..j..t.......Kh.p.

<<< skipped >>>

GET /iavs9x/servers.def.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g8873876.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Last-Modified: Wed, 22 Apr 2015 15:46:10 GMT
ETag: "5537c242-963"
Content-Type: application/octet-stream
Content-Length: 2403
Accept-Ranges: bytes
Cache-Control: max-age=38
Expires: Fri, 24 Apr 2015 09:59:01 GMT
Date: Fri, 24 Apr 2015 09:58:23 GMT
Connection: keep-alive
ASWsetupFPkgFile.D......x...[s.8...S...............Lg'.q......J.,..``.
'... ..8..4../KW.c.st$}.......,/.yz......{zr...(.y..............0R.W."
JXQ...d.jY.eq..%.=.4..,c.Lt.ID*u...v..eR.*.k.>..z........e[..>..
W....z.<.E9....I......w.&!....>/<......x4.>....v.gCp<.&
lt;..e.3..c.cIy.z.........g;..........e......7...8.^. .Ns.....m....9.Z
.......2]..y...$2......;Po.,..[..C!}..U.F ...&...f.l....9.....?.u....O
. .2\.@.."...:..^.OV]......9....H.............,..y<A.=D.(....08G.9.
....HiKI.$RZRb)..PJY...AY...AY...AY.....<..B).......9.....D.K.|^i..
..g...oePWAH,%..J..t.p......'[.G..uj...AI.,...mP.%...~...X...v|F.i....
2..>.g|..gY.......QX..zh?.f.....K..I.x.b.y...r.I..".F....:....(...u
..$.C.h....I.U.`.^qwiRny.U...j.....!7..K.rL].!v!..{.........5dHw.@1T..
).kL.....TT...RQ.ZXB.!.....l..v...Z..u.....xg\........rXP!..o...g.*...
..-.l...bRz..N.<...h..>>..z[>#.~y.YO.4....pY...K>......
W.|..[]j.QP.;=........ x.Y..o...RQ.i.n.j..#T.e..*.......%.....-/.<.
.........i^U.(d.........4^.b.^g.. x....*...oS..qqu..,....{~. ..kq..f..
...yQ.....9Z..f^.._.q....^..`....@...p.-j..V.`.....{. ..@......%u~....
'.....'....#....L...e1...~..K....g?.......,.~cg?..;...t..;v......&.Yg.
`...2k=..>.'..T}.IW...O.._...6k..(]. .:-..O.[~....y.....fQx.=A..Xx.
.s..&ves[..>'...9....Oi..a=..<..Ws.M..}..9.XZ.N.k...g.`tt9.UI..5
YF1.H.0H.Y....'.fX...To..A.jU0xGe.W.V.......JxS.\.*...0...)[_...B..bv.
..o.'.X..&.Y.......~o.w6..._.5..kh...W.yq...b......./...=.K...>...N
..Jk.....m....:..x..y..'....j.w.............I....7..S......I......

<<< skipped >>>

GET /__utm.gif?utmn=15724&utmac=MO-1405551-23&utmwv=4.4sh&utmp=click/fa-2015/en/progress/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=- HTTP/1.1
User-Agent: avast! Antivirus
Host: VVV.google-analytics.com
Accept: */*


HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 19 Apr 2000 11:43:00 GMT
Last-Modified: Wed, 21 Jan 2004 19:51:30 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Wed, 15 Apr 2015 19:43:29 GMT
Server: Golfe2
Content-Length: 35
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Age: 742551
Alternate-Protocol: 80:quic,p=1
GIF89a.............,...........D..;..


GET /ivps9x/part-jrog2-d50.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: t5416173.ivps9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 903
Last-Modified: Thu, 23 Apr 2015 17:33:47 GMT
ETag: "55392cfb-387"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:26 GMT
Connection: keep-alive
ASWsetupFPkgFile....'...x.-.{L.a......~.N..S(..P)..9%.4...[6.......k./
.\&3..l.1.(GH.KR.]..TT.......x.9.....<..{..NI..q.Y.....n....9.....y
uE.y..5......[.*..0..x.y.........S'.-..........>.iG.}ak@....]..xZ..
......v.)0.."..C2.v.Y..~"..b'....E.a%q&.....*..<..t4D.....s.....|..
. ...<O......E..?L$......$2[....gq..~.^.t..#....>.7..L..|..M..V.
.H..#.....).L....."..x..1?.........W.w...w.....A....."..|.....H.n.m...
...9..9...G.{.>Yo....@...4.o.......b?..Hj./.>........5.k....K?.O
..'.z..D....0..5.I=.8.Ud.6..3....^.|.U~b't..G.?...|_..<Ol.]|o.....7
B..........?..~C.....L..j..6......GS#6.....|....q'..p;.}.`.....e/..o..
!o... F.......W...N.H.....Ws..q).>a-..0..#.%n......I|.l..=&..;\....
..{....Z...f{./q../.Y..4c.u=W.y......b....#.9.%.>.4......y.....t.|.
..?.....U.....s..l...4.....U.....|K.w...j...5..........>...zr..OlQ.
.=..U...~..8.q.QL.......cQxp.....2@.T.N........!b..l*}N..............~
N...)..R@0.r..$...ASWSig2B..


GET /piwik.php?idsite=1&rec=1&action_name=WARNING/IDIOMA/1036/1033&url=http://wizinstall.com/WARNING/IDIOMA/1036/1033 HTTP/1.0
Host: stats.zemobile.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
Date: Fri, 24 Apr 2015 09:59:10 GMT
Server: Apache/2.4.7 (Ubuntu)
X-Powered-By: PHP/5.5.9-1ubuntu4.7
Content-Length: 43
Connection: close
Content-Type: image/gif
GIF89a.............!.......,...........D..;..


GET /ivps9x/vps_win32-100f.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l3362258.ivps9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 3908745
Last-Modified: Thu, 23 Apr 2015 17:27:26 GMT
ETag: "55392b7e-3ba489"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 10:00:53 GMT
Connection: keep-alive
ASWsetupFPkgFil3vp..).;.].....$.....f%..N\#5....I.....yL..Z....d.F....
.l...j3.T'..Zn..~@Sp..T.Q.:..(i...%...,/.~H2d.x5...^<.- .T.W8 ...=\
V.|..!.w.......L........s`M~.y.\...0.Kn ee? ..qGR....z.B.Z......-V0.rm
..G.x[#.X.....L..n.s..#.Pd..F...e2..m..F..........T.g.qg.XC.[.........
.u.........!.j ..:.9.'.*..D.d,A/...|.".......#%2.......1.b...8[..R.c.|
|.5`.7uNQi.0m...K...:...(..........J.o.y.5...LG..2SM..t./.....H4<..
|....e7...'....v~.u...^=mPOL P...~e...S..T.$/..Y.x...5...(4:...L\.N/..
...T..`..~.b$SP..W#i..7w....!.<..S..{7...179..m.....h.dC..G........
.)-(...w..P.....K.@..S.D............u....g.D.xt...}h.,7.R.s.T3........
d.b.#aCC..L....mR..Imp.r$v.....*...8s.....%.9...m.8...p.......k,..=&..
#q.iI..^.......`S.;f.X.t..!........Y.#......hF.E.....]...9.........[..
d....Q..........k.....".l...V.c.=F...:d.F...N......t.k....L.....}.A (.
..*.^.P.{.. d..t...~m..t..A 'G...../.........^m.n..t......@.%._...\.t'
A[..j..nHoJ.A.}.....3C.....E....t..[.|..O.*.......).<..H.'ZW)G.r.y.
&.. }.t`o...p0{(...vo../..`!2Y.....Nl...{..m_...5..ln. u.g...@....Y...
...-\../..BOj..&.)...t:H.q...w.v..x.~k(..t.t.\p...^....>......0.w.&
lt;W.p....G /..9.n.{.....fz...6.........>...>..6b.H`...'.....q..
..N....hX._.K:F.......V.'.....`.......G8v.p.tT{.G..b..3...W.5...d...'O
Q[{.=..o...wx...S .i9K$.]%.0..... ...M..l.W.R!. .(..7.Gh.:..;;.m..>
..%.z.....8....@.P.<...W...:.\....H....|...}5..Q~..o.,.h.4j..j0....
b/.W....<.y..\..n@.H....5$.&.....k.r.......s"...5.N...j.-%....w$..M
^..{TR.0.7.K.il,......3.K.xF.._..Z.\ 9.y3...2F9i..{.)...H..9d.....

<<< skipped >>>

GET /piwik.php?idsite=1&rec=1&action_name=FIN&url=http://wizinstall.com/FIN HTTP/1.0
Host: stats.zemobile.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
Date: Fri, 24 Apr 2015 09:59:40 GMT
Server: Apache/2.4.7 (Ubuntu)
X-Powered-By: PHP/5.5.9-1ubuntu4.7
Content-Length: 43
Connection: close
Content-Type: image/gif
GIF89a.............!.......,...........D..;..


POST / HTTP/1.1
Connection: Keep-Alive
Content-Type: application/x-www-form-urlencoded
User-Agent: Avast SimpleHttp/3.0
X-AVAST-SeqNum: 130743433576044157
X-AVAST-KeyId: 000ED2015208F6A80000014D1413E62262373236343431340000014BB65FAE6E
Content-Length: 52
Host: 5.45.59.110

.Z..#.>y..Z...R....z..l.....8?.U.I....>..1.......C.v
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 4404
TTL-Spread: 21600
TTL: 86400
Config-Name: default
Config-Version: 1
A.....#.......s..O.:..)e.;V.uv.....'Ch........S.....F!....vN.V;4.Pvm..
Q...:u._.z...=.o..1.Lj.........jmYyx[eY..e.m.hR.../Z."....m.........f.
X5u.1...(V..s.`....,iM.p~.J...*}..O......(.........:.g.-./......Pf3.&g
t;.x8..y.......2.Ej.!'u.p....!.....g.*....V.....mL....&.<.K.XV..=..
.`v.$.8....9..(.h......._Y...7`.....>.......\D..I..AG.....m..).Q8=.
}.w.TAGv......Tz1......(}o..[}.*1... ...~.}......h.....0..............
.t*v...pa.ni...g...u./....l s.d.!k.....zam..........%~. ... .H.......e
U.U.......Q...&Wo....[..l. .O....C....Q.... ).a..e$..V?..[....@.B...~.
UH\i..t........[...D.\...,......3uO0....9W.- .c...<...Fr>.\./...
...............k.>Q...]<. .c-...H..A.u.E.......k..5u.2/...L. .|.
...`'v....2.|.x.2..va0T.....g'........w..h..).....R....$:...,.a.i...$a
5.y.Sa.l.x..z.h.";0..K ....5P...#.m..zNW.....H....3......(B..&...U.0..
..E.....L..P....v6.............M..@!.A7r.......X..1!. ..........J<w
rhJ..~B...Z..n......f.w....!)[.x ...u&.......#..A9.....k...p.j.b=M....
......5..=..k.a`yFhIJ2ZS<..X...8..h.)..Q..bn3.......xS. .i....)Ne.8
....5....gZl......8.'.. R......1.k...8I.....#.;..qf...... ..V.i.^B|...
..qiA..z....k............`.Z.K..Q...pb.a....j%..&..8. @K.R....."..o...
.....'.^...h..;...-......E.?...u.@..rn.&.w.t".....;...n...>..u... .
..O.9m*x.$aqA....,.....cy.F:...$.....A.3".F.eme....zW.......;42{.'....
;l..F`.)..R..1....v.".W...D.Yz..u}.....~.Hd).. m.....3{.M..B`:7..k..s.
...#..m...:r..rO^un.....i..\.}...{/.6tRdh.rZ. ..^.....g.[.J...M.a.....
.%A.y.(c.....~...........P....S....%...b.......Mf4..yg>.Q\.1...

<<< skipped >>>

GET /pki/crl/products/microsoftrootcert.crl HTTP/1.1
Cache-Control: max-age = 900
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Tue, 24 Mar 2015 05:02:25 GMT
If-None-Match: "a1132b8ef65d01:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com


HTTP/1.1 304 Not Modified
Content-Type: application/pkix-crl
Last-Modified: Tue, 24 Mar 2015 05:02:25 GMT
ETag: "a1132b8ef65d01:0"
Cache-Control: max-age=900
Date: Fri, 24 Apr 2015 10:02:34 GMT
Connection: keep-alive
HTTP/1.1 304 Not Modified..Content-Type: application/pkix-crl..Last-Mo
dified: Tue, 24 Mar 2015 05:02:25 GMT..ETag: "a1132b8ef65d01:0"..Cache
-Control: max-age=900..Date: Fri, 24 Apr 2015 10:02:34 GMT..Connection
: keep-alive..


GET /iavs9x/selfdefense_x86_ais-8aa.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 185595
Last-Modified: Tue, 21 Apr 2015 16:34:08 GMT
ETag: "55367c00-2d4fb"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:39 GMT
Connection: keep-alive
ASWsetupFPkgFil3........].....&..p.........../D.N....L......o..i....4r
.3.....5X6hvF.)......$...j$:..Y.t..i..................2D4..y.V.{.A..x.
G......n...UAO.|9...l.j.}*X>z.....X.zj.....5......M9P.k..L.z...C..&
lt;... Fd_.. .....Q.@...,.e..W.J..Tl.>,..0l.........z.m/f...,......
E..M.8Q<.L!._=meN....<]....m...)q..5.%..46Vp.....'..W....C%.:...
..w...~...-..0.....S..\w.._m.!F.<[.>.F.C.i.......j..... .`...O!.
f0....F('u7.<....x.-:7.f..]..5.........!.f3.....6.N.M..R2..(~.t0.~.
U1e.R ........`>V9....{.d.xG|/.2..}.t..c...g...rj........`.^.d...;.
Mh.. j0..KN...................wh.Q NG...8.K.{X..I..@....*.h....F.....w
...?.H.....P5....s..2D...HL.S{q.....7.e.>%k......|.........#..=....
......JYq.~...t.....$..{Jb..t&.......e..._.....xk....N'ei..79#S....~e.
.^u.. 1.G...,n$n.._....b..B..G.~.0.Y.gvz.....5>......."...R........
.Z..6...#.b..'...C....;;....]#w;..../...-.U.?.....<...7".Q....}..`!
T\....1o...b.%._} 3u..4.@.B1..x.Y'...B$.O.]>....k...*...a.Xu.\....?
.7.Z.x..vK..Q..;..0%..6.K......$.J....."..D .|..N.i4..4./.as.D44..M:..
...-.^r..o......Q...HJ.xQ3e........N\.k.4*z!.s......:.)..._.....*.|...
....i..D.{.c>...e...'..*..7........H....._.\.IZr.|q.8u..o...n:w....
...).....W-x....f_3| .3...?/.D.......#0..}.......*O..B...|....o5F..B..
V.G...}...Nf..P).i.!..O..h....6.....x...|.=.:M.~......X...U..Pm...1_`.
L.M....SH.f........y..t]..a...N =m...|9.....E..*..r7I..C......M. grn..
.g~:Q...B.b.........a`Vj.@....Ms9.......2....7..$..K..3S.V...9#..vsn.U
..?...>?*<.D....O...4,.1k..H.[0..2..:............vm.....X.G.

<<< skipped >>>

GET /tools/swg2/update?type=c&as=swg&os=win&osv=6.1.7601&hl=en&ie=10.0.9200.16521&ds=0&pds=0&su=0&hpi=-1&brand=AVNH&pa=9&cl=1&tbv=&id=7a84db8082774391b17b4432f8f57454eb587e9488&from=&to=5.10.11023.1534 HTTP/1.1
Accept: */*
User-Agent: SearchWithGoogle
Host: clients1.google.com


HTTP/1.1 200 OK
Content-Type: text/plain
Transfer-Encoding: chunked
Date: Fri, 24 Apr 2015 10:01:22 GMT
Expires: Fri, 24 Apr 2015 10:01:22 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Alternate-Protocol: 80:quic,p=1
16..rlz: 1R______enUA637..0..


GET /iavs9x/ais_gen_openssl-7d4.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 568758
Last-Modified: Tue, 21 Apr 2015 16:32:23 GMT
ETag: "55367b97-8adb6"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:28 GMT
Connection: keep-alive
ASWsetupFPkgFil3x...V...].....$.....V............~...7.iAp!....y...J..
^.s^2J...*.bO......?...9....?=...Yb.....6.0s.k._.l.<...8.Xg-..q.cs.
.8...g.h.......bZFf.....].>.>....g...M&...MO;.....q.-..Q>8\?.
|...b....g......#.'..L.$R...d...d-r`.H.....?..4Xj;.=..c..m.Fwg .. ....
.N...Uw........k..Bo.._.7c.s.L.)...E{i.aH.!R.X...!. 1....E8..|..LH5.u.
.4.K&..j|.x.W}....................d.rV..).5...\.6..t..H#..g.@".C...I..
............Z{...q.....MBR...z.B-.`.m.-).d.i..Re.r..{12[D...M3.6:`....
.Q..T..w...KF..j....].......#...:.$..5 tt..2.7 K.d?.#0.05..u;.....!...
....2.W'.H..Y.......k.oi.....>....g.8..Q%.n....La.l?...le ......`..
.6T%.k.c.Kc..C....sK.C....j..(]Y.4*.n..gV..p.9..l.../i.-V.p:s.\...!."
..)...ZF..I..&S....wh....0(.`f#...&.U...y..v..=%...g.e*|CJ...]....Q..$
.x;..Qu...`...kJ&?Fr......`bS.9"n[.6.R.}Y...y:0.F..IW.~..l...........8
.K..D.L.pP$....S.f.g.........2..s.a.^{.3g....j.%o@.'.|...;....2..gL..B
..;=n.zB!...:0E.....-.9..r>..g1...E...Q;.G......z.j..........h....R
.$..5&..i...zk.....E......6.M^"y.;z..R..L.|....G :...... ..J.........&
lt;4SGP.ju..kR.....}...k.H.kE........W...t..w...9..."...l"/..y$OD&!l..
..j.......l%.u..D..:...L.....E[.Z..D...05...A3.".%...S..~1.....'!..u.K
......L$..4<.=?..X."L....s4,.{.e3W....&H.^....p....m....g{q/W-..\..
..LV...4...9.,'H7.0V.../7..a...ae...J....Iz.Y....c..uo...~<......D{
.......W..?.......g.s3..Y...&..............-2...i...hq;.G>w.6..)1-
oU.m....zR[r.7...@{.......i. .....B..' ..d_.e?C.k....oJ....d9.........
......<....!...6..>...M.o.B8..m7Z.s.....4..7...UP..,@...~...

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTEemCaVgs8Tuh2B9fGVE0pKKNyzgQUTF+nNhcF4oZhIkk5jLmo40rgOBoCEC6utoKGY/7ZdVX4/iTzOxo= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1552
content-transfer-encoding: binary
Cache-Control: max-age=518287, public, no-transform, must-revalidate
Last-Modified: Thu, 23 Apr 2015 10:00:09 GMT
Expires: Thu, 30 Apr 2015 10:00:09 GMT
Date: Fri, 24 Apr 2015 10:03:21 GMT
Connection: keep-alive
0..........0..... .....0......0...0........C...4N...@..6...v...2015042
3100009Z0s0q0I0... .........z`.V.<N.v...TM)(.r...L_.6....a"I9....J.
8........c..uU..$.;.....20150423100009Z....20150430100009Z0...*.H.....
.........{...M...p.....?.T.}....;.. .....P...}....b.Q.)6.{....`;......
..23.P|9.S....C.......B.....?....k..N>........B..t6.$.o...(.@.x.=..
....P...I.lm.J.M.}[`.@...P..h.a.G3.o-#5.6si..M]...m.9....m.0.0..Tkf...
..t...hx...\...Q.#...YE.p....W. .4.7-.k...g..b..\.k..0.N....50..10..-0
..........y.P}~.EY....T]. 0...*.H........0..1.0...U....US1.0...U....Ve
riSign, Inc.1<0:..U...3Class 3 Public Primary Certification Authori
ty - G21:08..U...1(c) 1998 VeriSign, Inc. - For authorized use only1.0
...U....VeriSign Trust Network0...141202000000Z..151216235959Z0..1.0..
.U....US1.0...U....Symantec Corporation1.0...U....Symantec Trust Netwo
rk1?0=..U...6Symantec Class 3 PCA - G2 OCSP Responder Certificate 30..
"0...*.H.............0..........6..]......w';.r........I..c..4.... ...
......TyW......hd_.....!C.k......SE<?o.H.. .me.c..9N.&....e.^-..a..
...i\:..*."..u...|....".Nf3.~.L...QW...p.....-]UV8U...J&.<./.G.....
I...4.T....#I*.i.E0\..~q$.I.......X?G....f.t......v.l.U.Ld.I...B.....=
...Sf...H.s.........0..0...U....0.0l..U. .e0c0a..`.H...E....0R0&.. ...
......hXXp://VVV.symauth.com/cps0(.. .......0...hXXp://VVV.symauth.com
/rpa0...U.%..0... .......0...U........0... .....0......0!..U....0...0.
1.0...U....TGV-B-2740...*.H............1.`...i.....H.C.i.9~.i..Z.r.*$.
.(./.ag9.....J.Q.~.`.$?b..C....<.h.........d&....3.kV.....f...3

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRODEXefhs/UZFum2o8YfzOFwceMwQUkz5j3yJ0BOBkhDHd2yOfDq+2TZMCEA89qsgV9niZmSI6gIO0S/U= HTTP/1.1

Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1725
content-transfer-encoding: binary
Cache-Control: max-age=582238, public, no-transform, must-revalidate
Last-Modified: Fri, 24 Apr 2015 03:44:50 GMT
Expires: Fri, 1 May 2015 03:44:50 GMT
Date: Fri, 24 Apr 2015 10:03:21 GMT
Connection: keep-alive
0..........0..... .....0......0...0......%bn.$..5.......?'4....2015042
4034450Z0s0q0I0... ........N.E.~.?Q.n.j<a.....3...>c."t..d.1..#.
...M....=....x..":...K.....20150424034450Z....20150501034450Z0...*.H..
...........t........=..O...i...9....... .J.5.]... ...[r.$M.!.bD...z...
.o...30^.u..l...6.N!.K.C......S.,'2......4.....l.... ....I..2.}.&..x..
/C2..x?$n..`.....-l.2..'.>9@.V..iYp......$.x.....A.;....)U*R..r..i.
[]..T....5Q......t..R6..4.7u....3..`..c..xLk....i|.S....1.~.....0...0.
..0..........7.R.~|..r."....#0...*.H........0..1.0...U....US1.0...U...
.VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of us
e at hXXps://VVV.verisign.com/rpa (c)091.0,..U...%VeriSign Class 3 Cod
e Signing 2009 CA0...150401000000Z..150630235959Z0..1.0...U....US1.0..
.U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1VeriSi
gn Class 3 Code Signing 2009 OCSP Responder0.."0...*.H.............0..
........z..|..>.....5.Z ...2.C MWIH.5......M.\.... ...eW..`.B=..`:.
.R. ...Z.k.Y.....p@.(3.c....a.;..[E....J:'...`...B....M..&......{. (..
......%......^[v[....m....*.T.o&4..3.....3.........G...e)...'?.K..2s..
8=?..z.:..T..-.8R..8wv7*U.K..c...<s...]{.........6.?_...........0..
.0...U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://www
.verisign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS
incorp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0.
..U........0... .....0......0"..U....0...0.1.0...U....TGV-B-34920...*.
H.............,..-......q3a........z....t;B.z.h...]...#}.6.,..YU..

<<< skipped >>>

GET /09053f748038e4cb59688a657cb25688/Cloud_Backup_Setup.exe HTTP/1.1
Host: aff-software.s3-website-us-east-1.amazonaws.com
Connection: close
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
x-amz-id-2: cu3Pmi6taCx4Chlo5s5C0gUH6A9n0jqzw98lGxLOLbL7fINNy8v/Dc8lL7hdOBXyl58YKF1O7/Y=
x-amz-request-id: 8C683EFF6AD32C91
Date: Fri, 24 Apr 2015 09:58:17 GMT
Last-Modified: Tue, 08 Jul 2014 14:20:57 GMT
ETag: "42c2ac94749aae293ed08951a6974d96"
Content-Type: application/octet-stream
Content-Length: 73856
Server: AmazonS3
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......1..:u..iu..i
u..i...iw..iu..i...i...id..i!..i...i...it..iRichu..i..................
......PE..L......K.................^...........0.......p....@.........
.................................................................t....
......0m..............p...............................................
.............p...............................text...L\.......^........
.......... ..`.rdata.......p.......b..............@..@.data...X\......
.....v..............@....ndata...................................rsrc.
..0m.......n...z..............@..@....................................
......................................................................
......................................................................
......................................................................
......................................................................
............................................U....\.}..t .}.F.E.u..H...
.h.B..H.P.u..u..u...Hr@..B...SV.5p.B..E.WP.u...Lr@..e...E..E.P.u...Pr@
..}..e....Dp@........FR..VV..U... M.......M....3.....FQ.....NU..M.....
.....VT..U.....FP..E...............E.P.M...Hp@..E...E.P.E.P.u...Tr@..u
....E..9}...w....~X.te.v4..Lp@....E.tU.}.j.W.E......E.......Pp@..vXW..
Tp@..u..5Xp@.W...E..E.h ...Pj.h`.B.W..Xr@..u.W...u....E.P.u...\r@._^3.
[.....L$....B...Si.....VW.T.....tO.q.3.;5..B.sB..i......D.......t.G...
..t...O..t .....u...3....3...F.....;5..B.r._^[...U..QQ.U.SV..i....

<<< skipped >>>

GET /iavs9x/selfdefense_x64_ais-8aa.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 187514
Last-Modified: Tue, 21 Apr 2015 16:34:08 GMT
ETag: "55367c00-2dc7a"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:38 GMT
Connection: keep-alive
ASWsetupFPkgFil3........].....&..p.........../D.N..iO...T..w{...]..s..
.R..}.;W.^..HN.g..2.3........t..#Ft.4..2.5...............d.j..N.....aO
.#..........Kr.u.e../..v1...y......m..K..2'...%).......^l.....N!R.....
.c...TiLC.i.}.......]}....$.xB.\..*.....=.%......c\G..\...cB... ..vzK.
.".G...I.l...... S_............J...m../.I..eK7n3,.._..G......ss.3..S..
...eD.h|i..'X....J...~#......|.u7.P.t@0{.....%;h.|z..z...2$..'N..~....
.Me.....V'..b...S.Zf._.............Q6..lZj.7*.F..!.V.^.*...y...G....c.
.qz.9/..d.y?.9.c..]...R.CO...H%.>2'.Qb'#..kso..r.8.._...A..(..p....
-Q.r..&*M<...?..H..<.<.....i.-..2Wd..../....C...i....`.9.o...
...iUj.u?..L..9..k.T.rGm..\.%....n>.4...3.....` ..4..X..h30.9.=.bx.
e./....c.P.M..W....mb.5..q....7.603>).....M...y.<L.f...#-.N.P0z.
..Wf..c.n..X.......r....Z8......}..A.#.)g.._ws4.Q#.ym....7@v.......Gqb
.f..lO...&^..?..Wg.'...... ..Br.)r.]H....*G.......u........8.^.OT.....
sc.TU}.....m..x....2.[:......W.K.."B..B..>...0.....8GJrN..Ds.Z.3.D.
dZ....)........V..g..... i......-.2.T.........6LaY........D..9......$.
;..:.a ....g^..E$E.%..a6k....VZ{P.k"ux.2{.Vs.5.e._.A.)....k..8..G%....
.9.~..x.......8.....F.L..\o..G.|."H._.9_.\..bM...=......c:..}..5....%.
....cSlEEH9L"./.v.o.5...u.Uh~..._m...A}......2..m...s".kQNi..OW.[.....
.*u.&.J.H.c...7.Vo.Q....|81.............E...r.M.....g|<..V....7..Z.
'.l....L^9b..P.$..p......:..o.."G..&.I.......&.#7.n.J9....5T..D$.n....
)..........i..{..KW. ......1].!r......%..t.....]...l.h.Y8.R...._L...].
....e..'.D.w.8...F.....#.X...e.F4.B.........BA|C....Z.."...i......

<<< skipped >>>

GET /ivps9x/prod-vps.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: t9920830.ivps9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Last-Modified: Thu, 23 Apr 2015 17:33:49 GMT
ETag: "55392cfd-1c2"
Content-Type: application/octet-stream
Content-Length: 450
Accept-Ranges: bytes
Cache-Control: max-age=20
Expires: Fri, 24 Apr 2015 09:58:45 GMT
Date: Fri, 24 Apr 2015 09:58:25 GMT
Connection: keep-alive
ASWsetupFPkgFile....b...x.s..r.```....p..o..m .....8.1(..(.......3S ..
}a.0..`. ...|\.@...;....H.0~].1...9..@h.U....o...,..Gl..:{..%..R..,.h.
.vX..m.^7..Y.....<i.?.Mn!.. 3..X..\..u. ..*.O7......&....vf.k.. .Vw
......a...r....7.OSL. ..U.'.......&.~...iJ.....4...9.. .mW9x{;.k:.....
...N.3.<3....Fe.Q.{|8...../.NNg......7...r...I8..1.._(}.'.w...wK...
q.T..c...........9n..ZV.s._.{.p....b.......w.j..P1yM1....k_.[.@...AQn.
.K...I^b.....E.\.....0....R.ASWSig2B..


GET /ivps9x/part-vps_win32-15042301.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: j5108348.ivps9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 2380
Last-Modified: Thu, 23 Apr 2015 17:33:49 GMT
ETag: "55392cfd-94c"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:26 GMT
Connection: keep-alive
ASWsetupFPkgFile`.......x.m.y\Ue....=.npY]pI4s\.5..0sCQ.$0.0.K..@..7DE
E...}.)s....%s..e.P....P3Ss..=....3........<.r~....GD........ m|...
.b.......'.1..Gl.N......v..J..V./nl.o....\.M./9.?....O.u5...^..<gbZ
T...E..%....=`.@~@..^f./.x..O..z6<....<...-xD.6..!.u....f...i.b.
...W........]...;tJ..n..........w.g....V..~.-RM...nYp...g....n....Y...
w..U....~..6.PAw....p;;...U.\........d......'.g..?J?./~......M.5pQ..4q
..|.D.=.....k..s......|.......(...m.w..E.,-i........-.Re.7..h._.....W.
*..3...._........../....SR../...&.8A.Gz.8..j.1....G...6|!. ...M.j.s..i
G1....a.........E.._.8H....'M...gt~...2~# .../X..Z..Q@o....t.l;.A.....
.4..>..a.^..eb..GG.v.|...Em...I/}n..9/.Vl.u.n..4...mt.......w.C.J..
.....[..'.>....".F..L3.X..&nt`#m0....N..X/.&..:Z...Z._f`..=..j...'.
......6.:.O..3..Z....6...2Zt..Ki..&....L,....b1m8..Er.VX.K...a!.....y^
...e}.....S..G.4..\.N.'....v![..N......Y."..Y4v........zz...i|!0..8.D&
.K. C..;&....f..Z#..t....&....I4t.SI.-.c"..K..w{.).......g,.@s[X0..^..
d.s......V...y..cd_F.`...K.....lH..y..H.7..h.c.MG.M.II........w..m[.q^
ah...C......w..rKj...."...>{.r.....]%)..a.."...3Vu...(w....e@.|..&g
t;4.mo.K..'uQ.|...6..t...NZ.m....].....:l[.O[..M}..>.c.".5.[<e(.
.8h...&.K0.s$..Q.f.G...J0.....`nL%...]...~...E...o....|........].m.h..
..E...J..W..../..G .s......wY?...Z.,........:..Z.%.O...^.:...yU...o..Z
.A.Z..D..N...~h....j.......".h.m.h.o.h...~..Nk....w...6.%..p_Oh...x...
/..?........R.h;......u.C...^........"..........E................N.%.o
....I.'......u.........%..9?..'...~.M.#...k..Y..U.%.|....f..Y.Q.9.

<<< skipped >>>

GET /ivps9x/iplugins-4.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: f5401358.ivps9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 13272
Last-Modified: Thu, 23 Apr 2015 17:33:44 GMT
ETag: "55392cf8-33d8"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:08 GMT
Connection: keep-alive
ASWsetupFPkgFil3!o..x3..].....$......o........`..8W...9.....y...O.. ..
.._h.{..99..=.d.......]>..m.2m.....f./...!..l..M<.-&.w.....4..SH
U....D.CFu...'...D.C-...{... .....Pw%...,....E...C^u.......u.Nzg]O<
.K.N.xN.j.....S.[g.A_.&....n.P.r....c....#....... ........c.......8{G.
......w[........~....J.pH..x..%2.../...7../..,^5.y...W..WV.8[........Q
x..J:2......).3...1,p........D.Vq.....Q...Btv...y..gp.mUg.`.o...-kS}..
...O....4C. .@E..1.->IP>.xoju.".[.18l.^...{~.L...y..2(.7.9.!.P.&
lt;.|lfGF..Q....e.ID..`...NY.....~..e.....RXdRn.X.1..2@..T.9....>..
b0.D.... .......aQ-.......\B. ..8.rJ.U..m..L.}k@n..e.?..17.W....S.....
w....y7Y.l.....&./6.....$_...r=.e?W.S......o#8M....s.<-._J.\.._K..L
..k....l./.<O..P.........e...x....(W...?..P.......u.../...%...5?..F
.....4.X"..o[....a..).7..0. },.@...N4.!..M..I...|.Z....).l.V...[.R^. .
.(..A.bq(..Z....)..{).1|...............J(....JA..~..n{.....c..i...9...
...".:..O&}.FZ.. ....Z)......g.l.....:.XpECB...Q..z...~...j].F.....d8e
.I...w..G|/g....|......#....W.....G..Q.........x`...{:..;...U.[.`...4M
.f.v..C....>:..Q....3.?7.&.b_w...:..........A..MS.....@x...u..g<
.M...`.. t..._.....C..mR...P..Sr/.:....l...M!..............@ ....R..DV
.....j..$..O....&W...ma..z0...L}`@.X.z5...BQ..........7..6.\...l....{.
P.?.$..%1.a.f~mu.-a., ,..K...x...c.e8.j.~pR.....Q.?r..^AL\R...Ly]..{Zw
^..g.....~.......s.p...T~.....#...4...G4.x....Z.... L...TQ...&"./..R.C
.?.....x..j........%...:..Tu..'..>5Xzf..A......r.Z..M.L...i.$.b.'..
....`L.ve.Hd'fz...jK......\..X&8..y7B...B..d....6.......x...Q.q...

<<< skipped >>>

GET /iavs9x/instcont_ais-8a6-8a0.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 198599
Last-Modified: Tue, 31 Mar 2015 10:56:59 GMT
ETag: "551a7d7b-307c7"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:29 GMT
Connection: keep-alive
ASWsetupDPkgFil2.h ..@.......^...........h ......@.......B...x...S./..
...m..m...m..m...m..m.{...d.wO=...z....'."*%...DE..?.V._.$.......f..P.
.N.vV......_* {..K22..#4 .$5.. .B5A .`AI.......!.............a.....
.A.Y..d........A.d...f..%[Y.B.Y..K>.q...XJ.P.e...X.W~...<P.7.E^.
-...,..Q...=A7...l.....I\.....Q..W..Uy,....K......<...<d......jR
...\.{.\:w..^.l.{ ..s..........T.u.....>f...z.DNA$.^.$...Wg[L?....Q
N.....4.J/.s....}..>r...-...r.^;....vm.%.I.......z..-MQN..q...g.[..
.w..2.W...L.jg.3vC.0...j...p.n5.....s...].n...l.d..ss....X....<kzL.
..k...4. ...d......A...<.f..|..E..U'e.8A...)..FT*.?...AB~..L.f.....
B6.....M..c=..0.^~q].U...f.....:..E.V.5.e.g....86..'h.........S.....0e
...{/.Z.64>h..M.P.N._[..U...X.A..=..M..`.r..~h.mB}...iL.,..>,.f.
.d....}.s........MzU............op..guPA..3~.-(.<.e..........f4."..
.dSH2...H3.t.TP.......|..H.,e.L5;..,..6Zs71..<.8..d.^.Y....F'.Y0$FL
.&.)...J.....e:..P.a...(.....[&.J:.....e.|:..'A.<....b(.,...8Yk....
..y.L.....\.......f.T.[.X.&...:.C..&......m<...8..<.|!.........t
..m....=.05....9Y..%...&q.j.BC.....7@.....z.\.K3.....W.h7u......#z.`Z.
..K...f.....uCE%m..;..r$M.q..n.e.et........z...B..... ...-.Z3....'....
..@%. .".[.......x&/B;..V.Q~.e..H.".l. ......#7..e}D..#9 .._..U..0k.6.
.j...`:.f.......^.q.a....m...K/.y..;U.A...{.G ....!A.. 1.b...8Y.."J..x
....]Yg...=...m.....?.2..&^2.o`...n...3...,n.CH:..r.....rB.'%......L3.
.....J.T.DN%.....7...X..t. 0"...!....V]E.,9R.J.jBV....H...Y.n....6....
lL<.......1.p](..HmD... U...YWo..B/.-.i ..?...0.....[...yD.....

<<< skipped >>>

POST /receive HTTP/1.1
UserAgent: Syncer/5.00 (unknown)
Content-Type: application/x-www-form-urlencoded
Content-Length: 5507
User-Agent: Syncer/5.00 (unknown)
Host: eu20150112.aa.avast.com
Connection: Keep-Alive
Cache-Control: no-cache

.
&J$1b9818a2-3789-4442-9fc3-714a6e217daf
........
"...*.
.EmUpdate20150112..10.2.%%Program Files%\AVAST Software\Avast"#C:\ProgramData\AVAST Software\Avast*$1b9818a2-3789-4442-9fc3-714a6e217daf2.1:
Aavm4h.dll..2Cv.d.I.=2...zk..
10.2.2218.942 ...
:
AavmRpch.dll...............|.<.
10.2.2218.942 ...
:
.AavmRpch64.dll......, ..../......
10.2.2218.942 ...
:
AhAScr.dll......U.3.c.T...8..
10.2.2218.942 ...
:
AhResMai.dll..h.......W....O(..
10.2.2218.942 ...
:
AhResStd.dll.....@tQ..1...j ...
10.2.2218.942 ...
:
.AhResWS.dll.......Z....dnB....
10.2.2218.942 ...
:
AhResWS2.dll..../.." .3R.2lle..
10.2.2218.942 ...
:
.ashBase.dll..A#P..z.fKe.!...g.
10.2.2218.942 ...
:
ashMaiSv.dll......-.q......B`..
10.2.2218.942 ...
:
ashQuick.exe......~did.9...{h..
10.2.2218.942 ...
:
.ashServ.dll...T6.a...I".^.)..
10.2.2218.942 ...
:
ashShA64.dll..%W.j9]Zb...N..jJ.
10.2.2218.942 ...
:
ashShell.dll..L#TU..k.C...wf...
10.2.2218.942 ...
:
.ashTask.dll...W.........J..R..
10.2.2218.942 ...
:
ashTaskEx.dll........#..v.......
10.2.2218.942 ...
:
ashUpd.exe...H..c.....(.. .$.
10.2.2218.942 ...
:
ashWebSv.dll............*...z$.
10.2.2218.942 ...
:
ashWsFtr.dll...l.<.. .)&,..P ~.
10.2.2218.942 ...
:
asOutExt.dll...."a(L..c.;..I...
10.2.22
HTTP/1.1 200 OK
Server: nginx/1.7.6
Date: Fri, 24 Apr 2015 10:01:27 GMT
Content-Type: application/octet-stream
Content-Length: 0
Connection: keep-alive


GET /iavs9x/avbugreport_ais-8a6-8a0.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 269946
Last-Modified: Tue, 31 Mar 2015 10:56:37 GMT
ETag: "551a7d65-41e7a"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:27 GMT
Connection: keep-alive
ASWsetupDPkgFil2.PW...L..................PW.......L..> ......x..wC.
&....vO..m..m..mM..m..mL....}......:dd.).H...0.....=!@...2X..BZ.....d.
..\..@8C.._...._-.-.x...n`....#U....(.A.d..U.HUuJ>U...(.T.\.... ..R
Q(.....k.d................/......|._...]9...J.....ZS....Z..S......X.p.
..sw.3.:....V..v....-......v6Rg...Lkw6.T.l[Gs..*..nk.j.q)...:......0..
.[........<..r%(X$\.G./p.B../.dX$.!`.,..l.......21.21.d@......d..X`
2.X&.1....c...f.,.$....H^.Q.#..X...*..b..@&#....?Za.p.Y.....FV.K.-C.!'
.......R^..*....d..%..@.-.-....2....LL8.dVF&Fy...@y).,..L^.e/.l..<.
..l...IcY..... .,...,d..E/a.R"HD%/...61D^..r.0Y....y.......p..b..,.,..
..8...L....."PbA.X`i..... .RJ!1..<^.T.\...2....b..,..2......`a...."
&..o..,...c....$....X,.d.0..e..X..,.-#.-..,X.@.$..M.dV..,`...bp,2@I&..
p.y2.D..4...g%....r...*..L....v".....4..$g..k..h.B.j.9...."...9.;I}.K.
,.K2.=..p..}...Y.-..&.Z'....A...U.f.4..8..ne........5.... ....($Q.81.=
9.j K;.CL..@p.y..h.D..!.)!..P.0..#sq.Khv........L8..-A..ke..[.).55.A.I
...<..C.....d.{.x..-.....o.=..d..e.:r/..u.n.d....D.:y#....0...U.J..
.p....f.MZ.G.^h$[9....H[....4.s.x&N..X............*..uFU`.Z.&....(T.=L
ut..k&.ds.,........5.gb.v.\tb....ZZ..X&F.@.....'...In.h..c.f......m.f.
...ccf/..f.l.6.....(q..L.C-|;.N....%i4/..FT.nX.@.1$.U.x..M~.)......8..
.d.).F.K4...#..v.<...s..OG.iw..Q...m:.un..j.......D..1.utd........[
....}Ec....6.........9{s..........(0uh.dr.....PX.(.yY..*G......L.[.y5m
.%m.....R$....R.uZ..I...K ...,%.D.x...X.%Sl8r.Y.t[.&XrEOi$c..x.k.9..v.
..|.X..I.....dSZ.V.J.....lQ.......c...Y.......s.u..:fzo...,....u..

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAKQll6RM0DNpmNM7zH3/Qc= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1790
content-transfer-encoding: binary
Cache-Control: max-age=513349, public, no-transform, must-revalidate
Last-Modified: Thu, 23 Apr 2015 08:35:12 GMT
Expires: Thu, 30 Apr 2015 08:35:12 GMT
Date: Fri, 24 Apr 2015 10:03:20 GMT
Connection: keep-alive
0..........0..... .....0......0...0......'.V.8.F.V....H....JW..2015042
3083512Z0s0q0I0... ..........!7h....O.d...AG&h.....k.&p..?...-.5......
....^.3@..cL.1.......20150423083512Z....20150430083512Z0...*.H........
......_J.r.R......~..^'r...w..H-C3.].Y....1.X.j .........Dd..........z
.*.B/...V....WB.q..9....mY.<.$...]........r.D'.....mm.....lHp......
.@..............nQ.w>.......R..'.!.........i..^......h...AB.....IJI
.......).8~...dC*7*.?....l.....C.'Lb...,...N....;../W.......#0...0...0
..........r..?.*......y"..0...*.H........0..1.0...U....US1.0...U....Ve
riSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use a
t hXXps://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3 Code S
igning 2009-2 CA0...150226000000Z..150527235959Z0..1.0...U....US1.0...
U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms o
f use at hXXps://VVV.verisign.com/rpa (c)091<0:..U...3VeriSign Clas
s 3 Code Signing 2009-2 OCSP Responder0.."0...*.H.............0.......
......m5*R........2....>...yU4..L.. ...........u..Hez..Pn.....d...n
z(...V7.}^...d!RX...bl..[..a...L.. .~..Ij......%..%p.-...u..:..i..F*].
..*....{NH..|0...gHX.Q.r....S..........._.9.(w...suC...N..s.....&."...
:.C.Q.i~rl..<..krS..8.B..o].y..L.4...iB@..s.....mw.........0...0...
U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.veri
sign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS inco
rp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U..
......0... .....0......0"..U....0...0.1.0...U....TGV-B-32010...*.H

<<< skipped >>>

GET /iavs9x/instup_ais-8a7-8a6.vpx HTTP/1.1
User-Agent: Syncer/8.00 (unknown)
Host: g4449219.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 512547
Last-Modified: Tue, 31 Mar 2015 10:57:15 GMT
ETag: "551a7d8b-7d223"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:58:33 GMT
Connection: keep-alive
ASWsetupDPkgFil2.....................................k.......x...Cw&..
.c.c...tl..m..m..m....y....S..5..\kmaeQIqqVF{...i;...~0..?....b..$W...
2G.4.......v..O.PEE.....0.`%..p.J....L%%u@...m.......E..,..06`.!bffg..
6.....T.F..e.....6.M.,S...U..-...M-.TURU.J....".Q.,P..T).._......j.R.u
...*..*....x.f.x.< 6996..9U...8. D.. ..2RbY.L.y&.!..D...... .Yd.E..
.-.L.....QY....P..6...0...P!........b....eT~....iYF...U..H..|e.,.Kp.T.
.....U&C..DF<.:.u![..ha d ...".^yd......(#[.:2`.\...5.."A.......22)
?..2b..By.o...9tY.^e...x.7..0R.e.._._eVl.Q^.G..,E..Gyd.e,EQf.2E..V....
..I^yP.J^($}........Q.....\N.:.#_..... c...1.[.Xk..L<d&.,....,.....
...z...%N...d..p.$....Z.?.N...&.U.;.C..c^..{....?T...l..."FYN..MK.PSU.
.k.-.....5.&.4T..7...7.k%p6.z.44.N..`.b.0E'..b{.......,...@.*.#!(N*...
..C.w@.IZ/0i..C.......8.....l..b...K..Fe.:....Q........[9\.M2..Z.AHEYK
U....$..,(....Tl..&k.D....IGZzCgMA.....R..HWmH(Ha..(E.......h..C...7..
R.@.O.."....{.....!..vS`'...hoOl.OS.R..,...li..J..=...E.m...@.&0.2..0'
....V...apg..4....M]H.Ps.U.j..?..}}.....U.4d(.V.G.M.4J!...h.*.........
.Vv/.....F$.^..H.U.......[<...y...o`.|\.# ..V..H.T.T.....qh...."...
..h!.A.k..O...'v{.&.....cO6.w|.........es..Y...y........E.m{.aG......4
.....Zt.........n*5......\.v.D??.KB...J....mI.....`EE.....:.vK.K.T....
GJ..G...x-f.....6j..hs.@O....w`......c...)70.f....W,....i....u.~..UA..
............U.y...?.D.....y....UGv.....m..#/.......v..I../rX2.....,.b.
.....qt.{....n].WY............;.u..~..z;..*..z....;.2.1.m.... .v.....'
..p..~...Fo..;.*...l...!....7...Y.l.`|b.4..'w}......v.....f..z.W..

<<< skipped >>>

POST /F/AAEbmBiiN4lEQp_DcUpuIX2v HTTP/1.1
Accept: */*
Content-Type: application/x-enc
Host: vl.ff.avast.com
Content-Length: 107

.n.=..,0...N.....,n..k..v...JXo.....M.....;..4,...iY../.._....ys.:.a..*..^..4...4F.Or.0).@.
..Y.V.6....a3.
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 26
............& .....)0.8.Hd..


GET /MyPCBackup_Setup.exe HTTP/1.0
Host: cdn.mypcbackup.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
Date: Fri, 24 Apr 2015 09:57:56 GMT
Content-Type: application/octet-stream
Content-Length: 1120195
Connection: close
x-amz-id-2: X2uLtZuT4nQVGUCB2LGuFiIZB/0o0uSmhvZeRZtRuQoqZ/AWNWe yCAY rYRlsvEuPT1h /h8VA=
x-amz-request-id: 4A5351227DE99DB5
Last-Modified: Fri, 24 Apr 2015 08:59:55 GMT
ETag: "062670ff6d10750af99bf774f7d10eeb"
Server: NetDNA-cache/2.2
X-Cache: HIT
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......1p.:u..iu..i
u..i...iw..iu..i...i...id..i!2.i...i...it..iRichu..i........PE..L...^.
.K.................b...........6............@.........................
.P.......................................................p............
......................................................................
.............................text....a.......b.................. ..`.r
data...............f..............@..@.data................x..........
....@....ndata.......p...........................rsrc........p........
..............@..@....................................................
......................................................................
......................................................................
......................................................................
......................................................................
............................................U....\.}..t .}.F.E.u..H...
..cB..H.P.u..u..u...T.@..B...SV.5.cB..E.WP.u...X.@..e...E..E.P.u...\.@
..}..e....D.@........FR..VV..U... M.......M....3.....FQ.....NU..M.....
.....VT..U.....FP..E...............E.P.M...H.@..E...E.P.E.P.u...`.@..u
....E..9}...w....~X.te.v4..L.@....E.tU.}.j.W.E......E.......P.@..vXW..
T.@..u..5X.@.W...E..E.h ...Pj.h.[B.W..d.@..u.W...u....E.P.u...h.@._^3.
[.....L$..(cB...Si.....VW.T.....tO.q.3.;5,cB.sB..i......D.......t.G...
..t...O..t .....u...3....3...F.....;5,cB.r._^[...U..QQ.U.SV..i....

<<< skipped >>>

GET /__utm.gif?utmn=26500&utmac=MO-1405551-23&utmwv=4.4sh&utmp=click/fa-2015/en/privacy/express/toolbar-yes-AVNH&utmcc=__utma=999.999.999.999.999.1;&utmvid=0x14712e76ae25dc4c&utmr=- HTTP/1.1
User-Agent: avast! Antivirus
Host: VVV.google-analytics.com
Accept: */*


HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 19 Apr 2000 11:43:00 GMT
Last-Modified: Wed, 21 Jan 2004 19:51:30 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Wed, 15 Apr 2015 19:43:29 GMT
Server: Golfe2
Content-Length: 35
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Age: 742538
Alternate-Protocol: 80:quic,p=1
GIF89a.............,...........D..;..


GET /piwik.php?idsite=1&rec=1&action_name=Mostrar oferta/MYPCBACKUP&url=http://wizinstall.com/Mostrar oferta/MYPCBACKUP HTTP/1.0
Host: stats.zemobile.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
Date: Fri, 24 Apr 2015 09:59:21 GMT
Server: Apache/2.4.7 (Ubuntu)
X-Powered-By: PHP/5.5.9-1ubuntu4.7
Content-Length: 43
Connection: close
Content-Type: image/gif
GIF89a.............!.......,...........D..;..


POST /F/AAEbmBiiN4lEQp_DcUpuIX2v HTTP/1.1
Accept: */*
Content-Type: application/x-enc
Host: vl.ff.avast.com
Content-Length: 86

.nC.!...s...!.d.....z/..Bz..~G......M.........,...rX..9..J.....m.^.%.J...0..>...g*E$oq
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 27
......#......& .....)0.8.Hd..


GET /v1/info HTTP/1.1
User-Agent: avast! Antivirus
Host: ip-info.ff.avast.com
Accept: */*


HTTP/1.1 200 OK
Content-Length: 135
Content-Type: application/json
{"ip": "193.138.244.231", "continent": "Europe", "country": "UA", "sub
divisions": ["63"], "city": "Kharkiv", "timezone": "Europe/Kiev"}..


POST /F/AP8bmBiiN4lEQp_DcUpuIX2v HTTP/1.1
Accept: */*
Content-Type: application/x-enc
Host: ai.ff.avast.com
Content-Length: 499

.nT.gH.9.s........z}Q"..u....|............2.6k.B;.t..,..(....nc.6.|.]-..5.Y0..Dl.)Eq;2Nl<:Wr..t.{.L.3..`[..mn...w..R...<a....E....Jyz,...U...u....b7.F...SY. \... |......F........|.)..9>....q!......"(
tUpn..m..
 g...C.....d.inWN#.mz.....4......Z........e....q..0..t..O".N....)...aR..0.%._......C(....)ev.....F.A...9.IsBF.(..QR
...(...O$*yd..fc..%.}.3?x_r......BH.....u.)6.mh.. ....,}~L..;..sfih.D..I)..MJ.....9...K.%X."...!Eo...".U.g......w..q>.&<..*! .Z.)e.^>"o.cx.I.=4.[7.g..j.......p.*.0....5Z._
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 2
OK..


GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab?88a24d8325e2cdd0 HTTP/1.1
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Tue, 24 Feb 2015 00:37:01 GMT
If-None-Match: "80b4d90ca4fd01:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: ctldl.windowsupdate.com


HTTP/1.1 304 Not Modified
Content-Type: application/octet-stream
Last-Modified: Tue, 24 Feb 2015 00:37:01 GMT
ETag: "80b4d90ca4fd01:0"
Cache-Control: max-age=604800
Date: Fri, 24 Apr 2015 10:01:50 GMT
Connection: keep-alive
HTTP/1.1 304 Not Modified..Content-Type: application/octet-stream..Las
t-Modified: Tue, 24 Feb 2015 00:37:01 GMT..ETag: "80b4d90ca4fd01:0"..C
ache-Control: max-age=604800..Date: Fri, 24 Apr 2015 10:01:50 GMT..Con
nection: keep-alive..


GET /iavs9x/ais_gen_crt_x64-7e4.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 2361099
Last-Modified: Tue, 21 Apr 2015 16:31:21 GMT
ETag: "55367b59-24070b"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:19 GMT
Connection: keep-alive
ASWsetupFPkgFil3..p...$.].....$.......E..\"..M..I.GT/.K$....%.... .a.9
..#T..,...U7.a.q...y/.`..(.....h.....G....[O..;.pzH.P.....cN.7B$.....p
j..H~q.^.@......G..........p.v...(....e.1......&..5[;u.;...G.....lXn..
wP...'8....".......4..=.........L...."..>.....(...C.6.pUvGJ\p..u{..
x....k./d..k..qC..k.......(.@#c~..y......V[..E6.cO......S(.c4L46..p.3.
...s.....f......_BF..'......k..1"M..<..3).Q...7.W........W...A..v.v
u..B_..5jVH.c..W..V...!....T...3.....J.{.~.=U6?4.J.....h...C5......-..
.........E.|....I__....4F.M.7..Q.Is..>...lU.{...$.(.......'p.....[.
.o.T...-..le..t..\5.K,z73k.....|...S.......S..i.^g.3.B..H1.I ...%.K.a.
.,...U..bhw)..g.../..qUQ.......L.IQ.Y....%...m...R.e..........;..Y....
.P.. 6...&...!......NN?.3.(..(H........wU.5Q;.....Wts....Zv.../....O(.
....6...."..8.z..~..F>7.....;.|."\..I..Z.nB...wA...a.....WA.."..}v.
....Y3.7..tw......}....`.S......M../..S.3<.u.4<..G8}..tk:..|...r
.|9V.\.....}..M.%.%.G......C7I.fN..rR...u......;1....[...... Z.,.eA:.&
lt;...q.=fD.............@t.F....=.\.....B.^....2|..SDx{2*...B]0G......
.....uL..E.....a..,L0.....Mj~...L<...nc.c..S....v.8.t.z.m;B.B%.....
.6iR.h...9.n.j.K.K...(]..I.].1.l2k....m...S7...S.s...!0F...."...c.....
.......#..s:=9...5...@Q...y........._8.^.....h.[.C.$.r.....ak4..R.r._.
`r8[."H....<r..%..........K...lhv%......!.-...A%.k.G.8...B}@P.d.3f1
.}P.H.y.ed&.".."._..8...O..2.....k9....K....Z.Ijh..K8...;.O.....N.]...
%<t.>a..b-.9........<..A.=..d0.....T[2..f..'s.H....5...^I..".
.My3Q..H..$....bl.x....&.....Xh..N......<..8..\a{.S.V-lQ..n=_~-

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1790
content-transfer-encoding: binary
Cache-Control: max-age=520905, public, no-transform, must-revalidate
Last-Modified: Thu, 23 Apr 2015 10:40:21 GMT
Expires: Thu, 30 Apr 2015 10:40:21 GMT
Date: Fri, 24 Apr 2015 10:03:05 GMT
Connection: keep-alive
0..........0..... .....0......0...0......'.V.8.F.V....H....JW..2015042
3104021Z0s0q0I0... ..........!7h....O.d...AG&h.....k.&p..?...-.5......
.A..2.....:...:......20150423104021Z....20150430104021Z0...*.H........
..........o.}"^O8.[....i...8..o4.....|..aJ.J...U..E[.../...\ .%.o..;.,
r~.0....xgZ...8..K..V.CQ..U...F1..D1..VwQ....<h~.*#........ .R@.s..
.-.6Y,Be...l*?.e@g.........u......*.0.`U.U4...?_......>r..H.......q
...f..0.BD.w.m..-.f.@.%...LH.7..{........AV5......E.%.c.....#0...0...0
..........r..?.*......y"..0...*.H........0..1.0...U....US1.0...U....Ve
riSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use a
t hXXps://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3 Code S
igning 2009-2 CA0...150226000000Z..150527235959Z0..1.0...U....US1.0...
U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms o
f use at hXXps://VVV.verisign.com/rpa (c)091<0:..U...3VeriSign Clas
s 3 Code Signing 2009-2 OCSP Responder0.."0...*.H.............0.......
......m5*R........2....>...yU4..L.. ...........u..Hez..Pn.....d...n
z(...V7.}^...d!RX...bl..[..a...L.. .~..Ij......%..%p.-...u..:..i..F*].
..*....{NH..|0...gHX.Q.r....S..........._.9.(w...suC...N..s.....&."...
:.C.Q.i~rl..<..krS..8.B..o].y..L.4...iB@..s.....mw.........0...0...
U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.veri
sign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS inco
rp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U..
......0... .....0......0"..U....0...0.1.0...U....TGV-B-32010...*.H

<<< skipped >>>

GET /iavs9x/ais_gen_crt_x86-7e3.vpx HTTP/1.1
User-Agent: avast! Antivirus
Host: l7658080.iavs9x.u.avast.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/octet-stream
Content-Length: 2255346
Last-Modified: Tue, 21 Apr 2015 16:31:23 GMT
ETag: "55367b5b-2269f2"
Accept-Ranges: bytes
Date: Fri, 24 Apr 2015 09:59:20 GMT
Connection: keep-alive
ASWsetupFPkgFil3.8]..i".].....$.......E..\"..M..I.GT/.K$....%.... .a.@
.[..P.,...U7.a.q...y/.`..(.....h.....G....ld..L..PM.Y.-.*..d.L....=)..
.......mE@...[l......dgT....%........z.V;.I.`*.Y..#..l5..J(.c.BQ.h...
h$o\W....d.y...d.9\/._...c;YTQ...ck.......Q...$.mX&...L.9.w.5<@...7
$0?2.f;....[...|.;n3......'.(o.r..8.a......K.e{A.......D......... .=."
=G...d9.T...../..#Y.....G..G.x@..E=v,o7......4.(o.jW.5.........10....C
.e.K(!..K.....zb.|...w..sI..H..0...4.6.........T.5. aJMl,.-..rcUCMl...
xe.T.. ..Q...T.|^...E.......j..s@.....N.....u}.."..M). W..-_...i....F.
..;.r.,K...d'..{)..&.).x.mN.k/H6B...\UW.O....PoE...fN..QU....... ...ry
..2.4J....e..U...>W.[.........9........U.Z.0g.j.....!.9.M.....J..w.
I`.....0..z...y.....5.T...sl\.Z!.#..E"....E2.... ..4.j.....wqt......~.
....I....#.KV......B.......B.......h.W..=..h."....o....5.Y.s.U}.i.`.6J
.h.b...G.zI...A..'.Y*.....j...e../.(.k..6.n".V=t..4F.k.?...l5/.....S.@
z.W.T.H%.g..U..8.e.UuH^|!.............}....2/..4.X..O#......j......L.A
7......{.G.q.*..,Y....m..3v..*......2....Ab.....n.n.6Q.G.B !.l.P.t.T.A
7I.V...... c...d.?.a.L....Y.nT.}uo..K............>;.w.`P.....d..M/S
`0......c.5p..:.3B.a..G=...pw..z.g...z......0..]..?.(_h..O$..a....Ss.u
.x..`.......`..ia...`h.m.t......j.q.......#oE.7...Zu!Hn..j.5....R.D...
..%vs.^..3. ......`.. H..|,v..M.s.\<...l.:...O}X.0..M...'.*.....&D[
#....B.*.8..6w.......j......=...b.3.H~[Te.LJ.d.iv.? .4....*B..%..v{.!6
.];.F..6..:/...d...kY.9..*.M.sx.;..._.%&Q.T......C....Q1...{...5.{?...
2`...7>.k3.B.J.N..Ir.........n.........(.~h...8..Iz... 93.b3. .

<<< skipped >>>

The Trojan connects to the servers at the folowing location(s):

setup___.exe_1816:

.text
`.rdata
@.data
.rsrc
@.reloc
CMDL
CMDP
QSSSSh
RSSSSSSh
vSSSh
tGHt.Ht&
FTPjK
FtPj;
C.PjRV
kernel32.dll
GetNamedPipeServerProcessId
GetNamedPipeClientProcessId
?456789:;<=
!"#$%&'()* ,-./0123
Visual C   CRT: Not enough memory to complete call to strerror.
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
portuguese-brazilian
Broken pipe
Inappropriate I/O control operation
Operation not permitted
operator
GetProcessWindowStation
gdiplus.dll
deflate 1.2.8 Copyright 1995-2013 Jean-loup Gailly and Mark Adler
inflate 1.2.8 Copyright 1995-2013 Mark Adler
RegDeleteKeyExW
12:44:19
%s %d %d
%d:%d:%d
NtRenameKey
XMLLITE.DLL
WWANAPI.DLL
WUDFPLATFORM.DLL
WUAPP.EXE
WTSAPI32.DLL
WSMAUTO.DLL
WSHTCPIP.DLL
WSHIP6.DLL
WS2_32.DLL
WS2HELP.DLL
WOW64WIN.DLL
WOW64CPU.DLL
WOW64.DLL
WOW32.DLL
WMVXENCD.DLL
WMSGAPI.DLL
WMPCM.DLL
WLDAP32.DLL
WLANMM.DLL
WLANCONN.DLL
WKSCLI.DLL
WINTRUST.DLL
WINSTA.DLL
WINSRV.DLL
WINSRPC.DLL
WINSPOOL.DRV
WINRNR.DLL
WINNSI.DLL
WINMM.DLL
WINLOGON.EXE
WINLOAD.EXE
WININIT.EXE
WININET.DLL
WINHTTP.DLL
WINDOWSCODECSEXT.DLL
WINDOWSCODECS.DLL
WINBRAND.DLL
WINBIO.DLL
WIN32K.SYS
WEVTAPI.DLL
WBIOSRVC.DLL
WBEMSVC.DLL
WBEMPROX.DLL
WBEMCOMN.DLL
WBADMIN.EXE
W32TM.EXE
VWIFIBUS.SYS
VOLMGR.SYS
VERSION.DLL
VAULTSVC.DLL
VAULTCLI.DLL
UXTHEME.DLL
UXINIT.DLL
UTILDLL.DLL
USP10.DLL
USERINIT.EXE
USERENV.DLL
USER32.DLL
URLMON.DLL
UMPO.DLL
UMPNPMGR.DLL
UBPM.DLL
TZRES.DLL
TSDDD.DLL
TPMCOMPC.DLL
TOOLHELP.DLL
TIMER.DRV
THEMEUI.DLL
TERMDD.SYS
TCPMONUI.DLL
TCPIP.SYS
TCMSETUP.EXE
TASKSCHDPS.DLL
SYSNTFY.DLL
SXSSTORE.DLL
SXSSRV.DLL
SXS.DLL
SXPROXY.DLL
SVCHOST.EXE
STORPORT.SYS
STI_CI.DLL
SSPISRV.DLL
SSPICLI.DLL
SSDPSRV.DLL
SRVCLI.DLL
SPPWMI.DLL
SPPOBJS.DLL
SPPC.DLL
SMSS.EXE
SLC.DLL
SHLWAPI.DLL
SHFOLDER.DLL
SHELL32.DLL
SFC_OS.DLL
SFC.DLL
SETUPAPI.DLL
SERVICES.EXE
SECUR32.DLL
SECHOST.DLL
SCSIPORT.SYS
SCHANNEL.DLL
SCEXT.DLL
SCESRV.DLL
SCARDDLG.DLL
SAMSRV.DLL
SAMLIB.DLL
SAMCLI.DLL
RUNONCE.EXE
RUNDLL32.EXE
RTUTILS.DLL
RSHX32.DLL
RSAENH.DLL
RPCSS.DLL
RPCRTREMOTE.DLL
RPCRT4.DLL
RPCEPMAP.DLL
RNR20.DLL
RDPREFDRVAPI.DLL
RDPDD.DLL
RDPCLIP.EXE
RDBSS.SYS
RASPPP.DLL
RASMBMGR.DLL
RASMAN.DLL
RASGCW.DLL
RASERVER.EXE
RASAUTO.DLL
RASAPI32.DLL
RASADHLP.DLL
PSISDECD.DLL
PSAPI.DLL
PROPSYS.DLL
PROFSVC.DLL
PROFAPI.DLL
PROCINST.DLL
PRNNTFY.DLL
PRINTFILTERPIPELINEPRXY.DLL
PRESENTATIONHOST.EXE
PRESENTATIONCFFRASTERIZERNATIVE_V0300.DLL
PPCSNAP.DLL
POWRPROF.DLL
PORTABLEDEVICEWMDRM.DLL
PNRPSVC.DLL
PNRPNSP.DLL
PNPUNATTEND.EXE
PEERDISTSVC.DLL
PCWUM.DLL
PCIIDE.SYS
PCI.SYS
PCAUI.DLL
PACER.SYS
ONEXUI.DLL
OLEAUT32.DLL
OLEACC.DLL
OLE32.DLL
OLE2DISP.DLL
ODBCCU32.DLL
ODBCCP32.DLL
NTSHRUI.DLL
NTOSKRNL.EXE
NTMARTA.DLL
NTKRNLPA.EXE
NTFS.SYS
NTDLL.DLL
NSISVC.DLL
NSI.DLL
NORMALIZ.DLL
NLAAPI.DLL
NETUTILS.DLL
NETAPI32.DLL
NDISUIO.SYS
NDISTAPI.SYS
NDIS.SYS
NCRYPT.DLL
NCOBJAPI.DLL
NAPINSP.DLL
MSWSOCK.DLL
MSVCRT.DLL
MSV1_0.DLL
MSPRIVS.DLL
MSIMG32.DLL
MSIEXEC.EXE
MSHTML.DLL
MSFTEDIT.DLL
MSCTF.DLL
MSCORIES.DLL
MSCOREE.DLL
MSCMS.DLL
MSASN1.DLL
MPR.DLL
MOUNTMGR.SYS
MOUHID.SYS
LSM.EXE
LSASS.EXE
LSASRV.DLL
LPK.DLL
LOGONUI.EXE
LLTDIO.SYS
KERNELBASE.DLL
KERNEL32.DLL
KBDYCL.DLL
KBDYCC.DLL
KBDYBA.DLL
KBDYAK.DLL
KBDWOL.DLL
KBDVNTC.DLL
KBDUZB.DLL
KBDUSX.DLL
KBDUSR.DLL
KBDUSL.DLL
KBDUSA.DLL
KBDUS.DLL
KBDURDU.DLL
KBDUR1.DLL
KBDUR.DLL
KBDUKX.DLL
KBDUK.DLL
KBDUGHR1.DLL
KBDUGHR.DLL
KBDTURME.DLL
KBDTUQ.DLL
KBDTUF.DLL
KBDTIPRC.DLL
KBDTH3.DLL
KBDTH2.DLL
KBDTH1.DLL
KBDTH0.DLL
KBDTAT.DLL
KBDTAJIK.DLL
KBDSYR2.DLL
KBDSYR1.DLL
KBDSW09.DLL
KBDSW.DLL
KBDSP.DLL
KBDSORST.DLL
KBDSORS1.DLL
KBDSOREX.DLL
KBDSN1.DLL
KBDSMSNO.DLL
KBDSMSFI.DLL
KBDSL1.DLL
KBDSL.DLL
KBDSG.DLL
KBDSF.DLL
KBDRU1.DLL
KBDRU.DLL
KBDROST.DLL
KBDROPR.DLL
KBDRO.DLL
KBDPO.DLL
KBDPL1.DLL
KBDPL.DLL
KBDPASH.DLL
KBDNSO.DLL
KBDNO1.DLL
KBDNO.DLL
KBDNEPR.DLL
KBDNECNT.DLL
KBDNECAT.DLL
KBDNEC95.DLL
KBDNEC.DLL
KBDNE.DLL
KBDMONMO.DLL
KBDMON.DLL
KBDMLT48.DLL
KBDMLT47.DLL
KBDMAORI.DLL
KBDMACST.DLL
KBDMAC.DLL
KBDLV1.DLL
KBDLV.DLL
KBDLT2.DLL
KBDLT1.DLL
KBDLT.DLL
KBDLK41A.DLL
KBDLAO.DLL
KBDLA.DLL
KBDKYR.DLL
KBDKOR.DLL
KBDKHMR.DLL
KBDKAZ.DLL
KBDJPN.DLL
KBDIULAT.DLL
KBDIT142.DLL
KBDIT.DLL
KBDIR.DLL
KBDINUK2.DLL
KBDINTEL.DLL
KBDINTAM.DLL
KBDINPUN.DLL
KBDINORI.DLL
KBDINMAR.DLL
KBDINMAL.DLL
KBDINKAN.DLL
KBDINHIN.DLL
KBDINGUJ.DLL
KBDINDEV.DLL
KBDINBEN.DLL
KBDINBE2.DLL
KBDINBE1.DLL
KBDINASA.DLL
KBDIC.DLL
KBDIBO.DLL
KBDIBM02.DLL
KBDHU1.DLL
KBDHU.DLL
KBDHID.SYS
KBDHEPT.DLL
KBDHELA3.DLL
KBDHELA2.DLL
KBDHEB.DLL
KBDHE319.DLL
KBDHE220.DLL
KBDHE.DLL
KBDHAU.DLL
KBDGRLND.DLL
KBDGR1.DLL
KBDGR.DLL
KBDGKL.DLL
KBDGEOQW.DLL
KBDGEOER.DLL
KBDGEO.DLL
KBDGAE.DLL
KBDFR.DLL
KBDFO.DLL
KBDFI1.DLL
KBDFI.DLL
KBDFC.DLL
KBDFA.DLL
KBDEST.DLL
KBDES.DLL
KBDDV.DLL
KBDDIV2.DLL
KBDDIV1.DLL
KBDDA.DLL
KBDCZ2.DLL
KBDCZ1.DLL
KBDCZ.DLL
KBDCR.DLL
KBDCLASS.SYS
KBDCAN.DLL
KBDCA.DLL
KBDBULG.DLL
KBDBU.DLL
KBDBR.DLL
KBDBLR.DLL
KBDBHC.DLL
KBDBGPH1.DLL
KBDBGPH.DLL
KBDBENE.DLL
KBDBE.DLL
KBDBASH.DLL
KBDAZEL.DLL
KBDAZE.DLL
KBDAX2.DLL
KBDARMW.DLL
KBDARME.DLL
KBDAL.DLL
KBDA3.DLL
KBDA2.DLL
KBDA1.DLL
KBD106N.DLL
KBD106.DLL
KBD103.DLL
KBD101C.DLL
KBD101B.DLL
KBD101A.DLL
KBD101.DLL
IPSEC.SYS
IPHLPAPI.DLL
INTELIDE.SYS
IMM32.DLL
IMAGERES.DLL
IERTUTIL.DLL
I8042PRT.SYS
HIDSERV.DLL
HID.DLL
GPAPI.DLL
GDI32.DLL
FWPUCLNT.DLL
FLTMGR.SYS
FLTLIB.DLL
FLPYDISK.SYS
FIREWALLAPI.DLL
FILEINFO.SYS
FECLIENT.DLL
FDC.SYS
FASTFAT.SYS
EXPLORERFRAME.DLL
EXPLORER.EXE
ESENT.DLL
ELXSTOR.SYS
DXG.SYS
DXAPI.SYS
DWMAPI.DLL
DUSER.DLL
DUI70.DLL
DNSRSLVR.DLL
DNSAPI.DLL
DLLHOST.EXE
DISK.SYS
DHCPCSVC6.DLL
DHCPCSVC.DLL
DHCPCORE6.DLL
DHCPCORE.DLL
DEVRTL.DLL
DEVOBJ.DLL
DEVMGR.DLL
CSRSS.EXE
CSRSRV.DLL
CRYPTUI.DLL
CRYPTSP.DLL
CRYPTEXT.DLL
CRYPTDLL.DLL
CRYPTBASE.DLL
CRYPT32.DLL
CREDUI.DLL
CREDSSP.DLL
CRASHDMP.SYS
CONHOST.EXE
COMDLG32.DLL
COMCTL32.DLL
CLBCATQ.DLL
CFGMGR32.DLL
CDROM.SYS
BROWSEUI.DLL
BCRYPTPRIMITIVES.DLL
BCRYPT.DLL
BASESRV.DLL
AUTHZ.DLL
AUTHUI.DLL
AUDIOSRV.DLL
ATL.DLL
ATAPI.SYS
APPHELP.DLL
APISETSCHEMA.DLL
API-MS-WIN-SERVICE-WINSVC-L1-1-0.DLL
API-MS-WIN-SERVICE-MANAGEMENT-L2-1-0.DLL
API-MS-WIN-SERVICE-MANAGEMENT-L1-1-0.DLL
API-MS-WIN-SERVICE-CORE-L1-1-0.DLL
API-MS-WIN-SECURITY-SDDL-L1-1-0.DLL
API-MS-WIN-SECURITY-LSALOOKUP-L1-1-0.DLL
API-MS-WIN-SECURITY-BASE-L1-1-0.DLL
API-MS-WIN-DOWNLEVEL-VERSION-L1-1-0.DLL
API-MS-WIN-DOWNLEVEL-USER32-L1-1-0.DLL
API-MS-WIN-DOWNLEVEL-SHLWAPI-L2-1-0.DLL
API-MS-WIN-DOWNLEVEL-SHLWAPI-L1-1-0.DLL
API-MS-WIN-DOWNLEVEL-SHELL32-L1-1-0.DLL
API-MS-WIN-DOWNLEVEL-OLE32-L1-1-0.DLL
API-MS-WIN-DOWNLEVEL-NORMALIZ-L1-1-0.DLL
API-MS-WIN-DOWNLEVEL-ADVAPI32-L2-1-0.DLL
API-MS-WIN-DOWNLEVEL-ADVAPI32-L1-1-0.DLL
API-MS-WIN-CORE-XSTATE-L1-1-0.DLL
API-MS-WIN-CORE-UTIL-L1-1-0.DLL
API-MS-WIN-CORE-UMS-L1-1-0.DLL
API-MS-WIN-CORE-THREADPOOL-L1-1-0.DLL
API-MS-WIN-CORE-SYSINFO-L1-1-0.DLL
API-MS-WIN-CORE-SYNCH-L1-1-0.DLL
API-MS-WIN-CORE-STRING-L1-1-0.DLL
API-MS-WIN-CORE-RTLSUPPORT-L1-1-0.DLL
API-MS-WIN-CORE-PROFILE-L1-1-0.DLL
API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL
API-MS-WIN-CORE-PROCESSENVIRONMENT-L1-1-0.DLL
API-MS-WIN-CORE-NAMEDPIPE-L1-1-0.DLL
API-MS-WIN-CORE-MISC-L1-1-0.DLL
API-MS-WIN-CORE-MEMORY-L1-1-0.DLL
API-MS-WIN-CORE-LOCALREGISTRY-L1-1-0.DLL
API-MS-WIN-CORE-LOCALIZATION-L1-1-0.DLL
API-MS-WIN-CORE-LIBRARYLOADER-L1-1-0.DLL
API-MS-WIN-CORE-IO-L1-1-0.DLL
API-MS-WIN-CORE-INTERLOCKED-L1-1-0.DLL
API-MS-WIN-CORE-HEAP-L1-1-0.DLL
API-MS-WIN-CORE-HANDLE-L1-1-0.DLL
API-MS-WIN-CORE-FILE-L1-1-0.DLL
API-MS-WIN-CORE-FIBERS-L1-1-0.DLL
API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL
API-MS-WIN-CORE-DELAYLOAD-L1-1-0.DLL
API-MS-WIN-CORE-DEBUG-L1-1-0.DLL
API-MS-WIN-CORE-DATETIME-L1-1-0.DLL
API-MS-WIN-CORE-CONSOLE-L1-1-0.DLL
ALG.EXE
AFD.SYS
ADVAPI32.DLL
ACPI.SYS
d:\Avast900\src\BUILDS\Release\x86\SfxInstFree.pdb
GdiplusShutdown
GetWindowsDirectoryW
KERNEL32.dll
USER32.dll
GDI32.dll
RegOpenKeyExW
RegCloseKey
RegCreateKeyExW
RegEnumKeyW
RegDeleteKeyW
ADVAPI32.dll
SHELL32.dll
ole32.dll
GetProcessHeap
GetCPInfo
GetConsoleOutputCP
RegEnumKeyExW
zcÁ
$"$$&$,*,,.,4244:<<:<<><DBDDFDDFLLJLDNZLNTTRTTVTTV\\Z\\^\OXc\^dZcmdfddjlljllnlemwlrttrttvt|z||~|px
Paint.NET v3.5.100
$"$$&$,*,,.,424464<:<<><<BDDBDDFDDFLLJLLNLDNZTRTTV\\Z\\^\OXc\^dZcmdbddfddjlljllnlemwlrttrttvttz||z||~|px
$"$$&$,*,,.,4244644:<<:<<><<BDDBDDFDDFLLJLLNLDNZLNTTRTTV\\Z\OXc\^dZcmdbddfdljllnlemwlrttrttvttz||z||~|px
$&$,*,,.,4244644:<<:<<><<BDDBDDFDLJLDNZLNTTRTTVTTV\\Z\\^\OXc\^dZcmdbddfddjllnlemwlrttrttvt|z||~|px
$"$$&$,*,,.,4244:<<:<<><<BDDBDDFDDFLLJLLNLDNZLNTTRTTVTTV\\Z\\^\OXc\^dZcmdbddfddjllnlemwlrttrttvttz||z||~|px
$"$$&$,*,,.,4244644:<<:<<><<BDDBDDFDDFLLJLLNLDNZLNTTRTTVTTV\\Z\\^\OXc\^dZcmdbddfddjlljllnlemwlrttrttvttz||z||~|px
$"$$&$,*,,.,4244644:<<:<<><<BDDBDDFDLJLLNLDNZTRTTV\\Z\\^\OXc\^dZcmdbddfddjlljllnlemwlrttrttvttz||z||~|px
$"$$&$,*,,.,4244644:<<><<BDDBDDFDLJLLNLDNZLNTTRTTVTTV\\Z\\^\OXcZcmdbddfddjlljllnlemwlrttrttvttz||z||~|px
$"$,*,,.,4244644:<<:<<BDDBDDFDDFLLJLLNLDNZLNTTRTTVTTV\\Z\\^\OXc\^dZcmdbddjlljllnlemwlrttrttvt|z||~|px
,.FLw
Pg%U=m7
$"$,*,,.,424464<:<<><<BDDBDDFDDFLLJLLNLDNZLNTTRTTVTTV\\Z\OXc\^dZcmdbddfddjlljllnlemwlrttrttvttz||z||~|px
$"$$&$,*,,.,424464<:<<><<BDDBDDFDDFLLJLLNLDNZTRTTVTTV\\Z\\^\OXc\^dZcmdbddfdljllnlemwlrttrttvttz||~|px
3$CYO%u
$"$$&$,*,,.,4244644:<<:<<><<BDDBDDFDLJLDNZTRTTVTTV\\Z\\^\OXc\^dZcmdbddfddjlljllnlemwlrttrttvttz||z||~|px
PLTE'07,2<,6<,:<4634:D4<C4>D<BD<BL<FLB=0OC,]J)jQ%xW"DJLBIPDJTDNTLRTLR\MV\TZ\T^d\^d\bd]ci\fldfldjldntjpulrttv|tz|t~
PLTE'07,2<,6<,:<4634:D4<C4>D<BD<BL<FLB=0OC,]J)jQ%xW"DJLBIPDJTDNTLRTLR\MV\TZ\T^d\^d\bd]ci\fldjldntlntjpulrtlv|tv|tz|t~
PLTE'07,2<,6<,:<4634:D4<C4>D<BD<BL<FLB=0OC,]J)jQ%xW"DJLBIPDJTDNTLRTLR\MV\TZ\T^d\^d\bd]ci\fldfldjldntlntjpulrtlv|tv|tz|t~
!3 3 3 3 3 3 3 3 3 3 3 3 3
Q.oG|
PLTE'07,2<,6<,:<4634:D4<C4>D<BD<BL<FLB=0OC,]J)jQ%xW"DJLBIPDJTDNTLRTLR\MV\TZ\T^d\^d\bd]ci\fldfldjldntlntjpulrtlv|tv|tz|x}
n7.AdI
PLTE'07,2<,6<,:<4634:D4<C4>D<BD<BL<FLB=0OC,]J)jQ%xW"DJLBIPDJTDNTLRTLR\MV\TZ\T^d\^d\bd]ci\fldfldjllntjpulrtlv|tv|tz|t~
PLTE'07,2<,6<,:<4634:D4<C4>D<BD<BL<FLB=0OC,]J)jQ%xW"DJLBIPDJTDNTLRTLR\LV\TZ\T^d\^d\bd]ci\fldfldjldntlntjpulrtlv|tv|tz|t~
aÎQ
.um)F_
l%sz~
tÂ@
d%d@q~
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity type="win32" name="Avast.Instup.SfxInst.exe" version="9.0.0.0"></assemblyIdentity><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS>
3)4;4[4}6
: :':.:5:
8 8Œ8^8t8
2%3X3
< <$<(<,<0<4<
1%1u1B2_2<3
3 3$3@3`3
8 8<8@8`8
HKEY_USERS
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
\\.\%s
Windows NT\CurrentVersion\ProfileList
Windows\CurrentVersion
\\?\UNC
%s\Oem\%s
aswCmnOS.dll
avast5.ini
KeyFolder
ReportFolder
report
CertificateFile
%SystemRoot%
user32.dll
\LIB\NVDAHELPERREMOTE.DLL
X86\JHOOK.DLL
JHOOK.DLL
\MSCTF.DLL
\UXTHEME.DLL
avResMai64.mtx
avResSPM64.mtx
avResE2K64.mtx
avResWss64.mtx
AswProxy.evt
AswProxyCfgChg.evt
Avast5.XLayer.AavmMutex
vpsUpdat.sig
vpsNew.sig
AvWsTrm.evt
AvWsCfgChg.evt
Avast5.ChestMutex
aswUpdateNow.evt
AswMailSvc.Evt
aswLogDebug.mtx
aswArPotTest.evt
aswAavmUp.evt
asw.script_blocking.conf_data_protect
asw.script_blocking.conf_data
aavmSema.apc
aavmRefr.now
aavmGlob.mtx
aavmGlob.cnt
d\\.\aswSP_Handler
mscoree.dll
\\.\ASWSP_Open
\\.\ASWSP
MiniDump.dmp
Failed to get a handle to kernel32.dll with error 0xlx!
dbghelp.dll
Software\Microsoft\Windows\CurrentVersion\SharedDLLs
OpOnReboot: MoveFileEx('%s') successfully performed.
OpOnReboot: MoveFileEx('%s') failed, code %s
OpOnReboot: Direct delete of file '%s' successfully performed.
OpOnReboot: Cannot directly delete file '%s', code %s
%d (0xX)
00:00:00
[%s] [%-7s] [%-15s] [%5lu:%5lu] %s
Failed to open the log file "%s" with error 0xlx!
Cannot create registry key: %s, code %s
Advapi32.dll
WDeleteBranchImpl: %s deleted
DeleteBranchImpl: %s not deleted, code %s
CustomInstallation.ini
Failed to get a handle to kernel32.dll with error 0xlx
Cannot get signature of archive '%s' (code 0x%x)
Error in signature of archive '%s' (code 0x%x)
Unknown signature type of archive '%s'
Error opening archive '%s'
Incorrect content length of archive '%s'
Archive '%s' is too small
Incorrect magic of archive '%s'
Cannot load map block of archive '%s'
Error loading map of archive '%s' (code 0x%x)
Error in unpacked map data of archive '%s'
SFX archive '%s' sucessfully loaded.
Unpacking %s
Error saving %s to a file '%s', code %d (0x%X)
license.avastlic
bcc.cfg.tmp
Avast for business public key
bcpub.key.tmp
rid.bin
Error saving embedded recommendation ID to a file '%s', code %d (0x%X)
Error extracting file '%s' (code 0x%x)
Error extracting module '%s' (code 0x%x)
C:\TEMP
"%s" %s
Cannot get exit code of process '%s' (code 0x%x)
Error creating process '%s' (code 0x%x)
Reboot: Restarting windows...
Reboot: InitiateSystemShutdownEx returned 0xX
GdiPlus.dll
\\.\aswSP_Open
\\.\aswSP
ntdll.dll
bpubkey
Reboot.txt
Instup.dll
instup.exe
\Logs\Setup.log
Running SFX '%s'
We are sorry but avast! Antivirus %d requires Windows XP SP2 or higher. Please, consider update or download avast! Antivirus 8.
avast! installer cannot continue because OS is too old. Version: %u.%u.%u
The installer has detected corrupted avast! Antivirus installation on this computer (service '%s' is running), thus this installer cannot continue. Use the 'avastclear.exe' utility to fix the problem or contact the avast! support team.
Avast was not detected but service '%s' is running. There is a corrupted avast installation, thus this installer cannot continue.
The installer cannot open the SFX archive '%s'. (code 0x%x)
Cannot open the SFX archive '%s' (code 0x%x)
_av_iup.tm~
~aswOfferTool.exe
GuiCust.dll
The installer cannot extract VPS files to '%s' (code 0x%x)
Cannot extract VPS files to '%s' (code 0x%x)
The installer cannot extract installer/updater executable to '%s'. (code 0x%x)
Cannot extract installer/updater executable to '%s' (code 0x%x)
setup.ovr
avast.setup
Starting installer/updater executable '%s'
The stub cannot run installer/updater executable '%s' (code 0x%x)
Installer/updater executable '%s' finished (process return code 0x%x)
Leaving Avast SFX stub guarded code section (return code 0x%x)
hu/hu/hu hu:hu:hu START: Avast SFX stub executable
hu/hu/hu hu:hu:hu END: Avast SFX stub executable, return code %d (0xlx)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup___.exe
10.0.2206.692
SfxInst.exe

instup.exe_2812:

.text
`.rdata
@.data
.rsrc
@.reloc
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
Visual C   CRT: Not enough memory to complete call to strerror.
Operation not permitted
Inappropriate I/O control operation
Broken pipe
GetProcessWindowStation
operator
GetNamedPipeClientProcessId
GetNamedPipeServerProcessId
d:\Avast900\src\BUILDS\Release\x86\InstCont.pdb
KERNEL32.dll
USER32.dll
RegCloseKey
RegOpenKeyExW
ADVAPI32.dll
SHELL32.dll
Instup.dll
SHLWAPI.dll
GetCPInfo
GetProcessHeap
zcÁ
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity type="win32" processorArchitecture="x86" name="Avast.Instup.Instup.exe" version="9.0.0.0"></assemblyIdentity><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS></application></compatibility></assembly>
0C1k1y1<3\3c3k3p3t3x3
= =<=\=*?
6&626[6}7
4(4-434:4
6%6s6
2 2$2(24282<2
0 0$0(0,00040
.mscoree.dll
- CRT not initialized
- Attempt to initialize the CRT more than once.
- floating point support not loaded
USER32.DLL
\\.\ASWSP_Open
\\.\ASWSP
avast! Self-Defense trust was not acquired. Code %s
Cannot initialize Instup, return code %s
Error returned by Instup, return code %s
Error in Instup cleanup, return code %s
avBugReport.exe
hu/hu/hu hu:hu:hu END: Avast installer/updater, return code %s
dbghelp.dll
crash.log
unp%u%u.mdmp
ERROR: GenerateCrashReport failed.
Warning: Multiple calls to GenerateExceptionReport! Ignoring additional calls.
* No exception info provided for GenerateCrashReport.
rKernel32.dll
The operation completed successfully
Operation was cancelled
Proxy login needed
HTTP error
Retrying operation
%d (0xX)
ais_shl_web
alc_shl_web
ais_cmp_webrep
alc_cmp_webrep
ntdll.dll
k\\.\aswSP_Handler
kernel32.dll
daavmGlob.cnt
aavmGlob.mtx
aavmRefr.now
aavmSema.apc
asw.script_blocking.conf_data
asw.script_blocking.conf_data_protect
aswAavmUp.evt
aswArPotTest.evt
aswLogDebug.mtx
AswMailSvc.Evt
aswUpdateNow.evt
Avast5.ChestMutex
AvWsCfgChg.evt
AvWsTrm.evt
vpsNew.sig
vpsUpdat.sig
Avast5.XLayer.AavmMutex
AswProxyCfgChg.evt
AswProxy.evt
avResWss64.mtx
avResE2K64.mtx
avResSPM64.mtx
avResMai64.mtx
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup.exe
10.0.2206.692
Instup.exe

instup.exe_1544:

.text
`.rdata
@.data
.rsrc
@.reloc
j.Yf;
_tcPVj@
.PjRW
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
%b %d %H : %M : %S %Y
%m / %d / %y
%I : %M : %S %p
%d / %m / %y
0123456789-
Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flag
Visual C   CRT: Not enough memory to complete call to strerror.
Operation not permitted
Inappropriate I/O control operation
Broken pipe
GetProcessWindowStation
operator
avBugReport.exe
r:\storage\sdk\vs 2012\boost\1.55.0\include\boost\exception\detail\exception_ptr.hpp
?456789:;<=
!"#$%&'()* ,-./0123
GetNamedPipeClientProcessId
GetNamedPipeServerProcessId
ACPI.SYS
ADVAPI32.DLL
AFD.SYS
ALG.EXE
API-MS-WIN-CORE-CONSOLE-L1-1-0.DLL
API-MS-WIN-CORE-DATETIME-L1-1-0.DLL
API-MS-WIN-CORE-DEBUG-L1-1-0.DLL
API-MS-WIN-CORE-DELAYLOAD-L1-1-0.DLL
API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL
API-MS-WIN-CORE-FIBERS-L1-1-0.DLL
API-MS-WIN-CORE-FILE-L1-1-0.DLL
API-MS-WIN-CORE-HANDLE-L1-1-0.DLL
API-MS-WIN-CORE-HEAP-L1-1-0.DLL
API-MS-WIN-CORE-INTERLOCKED-L1-1-0.DLL
API-MS-WIN-CORE-IO-L1-1-0.DLL
API-MS-WIN-CORE-LIBRARYLOADER-L1-1-0.DLL
API-MS-WIN-CORE-LOCALIZATION-L1-1-0.DLL
API-MS-WIN-CORE-LOCALREGISTRY-L1-1-0.DLL
API-MS-WIN-CORE-MEMORY-L1-1-0.DLL
API-MS-WIN-CORE-MISC-L1-1-0.DLL
API-MS-WIN-CORE-NAMEDPIPE-L1-1-0.DLL
API-MS-WIN-CORE-PROCESSENVIRONMENT-L1-1-0.DLL
API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL
API-MS-WIN-CORE-PROFILE-L1-1-0.DLL
API-MS-WIN-CORE-RTLSUPPORT-L1-1-0.DLL
API-MS-WIN-CORE-STRING-L1-1-0.DLL
API-MS-WIN-CORE-SYNCH-L1-1-0.DLL
API-MS-WIN-CORE-SYSINFO-L1-1-0.DLL
API-MS-WIN-CORE-THREADPOOL-L1-1-0.DLL
API-MS-WIN-CORE-UMS-L1-1-0.DLL
API-MS-WIN-CORE-UTIL-L1-1-0.DLL
API-MS-WIN-CORE-XSTATE-L1-1-0.DLL
API-MS-WIN-DOWNLEVEL-ADVAPI32-L1-1-0.DLL
API-MS-WIN-DOWNLEVEL-ADVAPI32-L2-1-0.DLL
API-MS-WIN-DOWNLEVEL-NORMALIZ-L1-1-0.DLL
API-MS-WIN-DOWNLEVEL-OLE32-L1-1-0.DLL
API-MS-WIN-DOWNLEVEL-SHELL32-L1-1-0.DLL
API-MS-WIN-DOWNLEVEL-SHLWAPI-L1-1-0.DLL
API-MS-WIN-DOWNLEVEL-SHLWAPI-L2-1-0.DLL
API-MS-WIN-DOWNLEVEL-USER32-L1-1-0.DLL
API-MS-WIN-DOWNLEVEL-VERSION-L1-1-0.DLL
API-MS-WIN-SECURITY-BASE-L1-1-0.DLL
API-MS-WIN-SECURITY-LSALOOKUP-L1-1-0.DLL
API-MS-WIN-SECURITY-SDDL-L1-1-0.DLL
API-MS-WIN-SERVICE-CORE-L1-1-0.DLL
API-MS-WIN-SERVICE-MANAGEMENT-L1-1-0.DLL
API-MS-WIN-SERVICE-MANAGEMENT-L2-1-0.DLL
API-MS-WIN-SERVICE-WINSVC-L1-1-0.DLL
APISETSCHEMA.DLL
APPHELP.DLL
ATAPI.SYS
ATL.DLL
AUDIOSRV.DLL
AUTHUI.DLL
AUTHZ.DLL
BASESRV.DLL
BCRYPT.DLL
BCRYPTPRIMITIVES.DLL
BROWSEUI.DLL
CDROM.SYS
CFGMGR32.DLL
CLBCATQ.DLL
COMCTL32.DLL
COMDLG32.DLL
CONHOST.EXE
CRASHDMP.SYS
CREDSSP.DLL
CREDUI.DLL
CRYPT32.DLL
CRYPTBASE.DLL
CRYPTDLL.DLL
CRYPTEXT.DLL
CRYPTSP.DLL
CRYPTUI.DLL
CSRSRV.DLL
CSRSS.EXE
DEVMGR.DLL
DEVOBJ.DLL
DEVRTL.DLL
DHCPCORE.DLL
DHCPCORE6.DLL
DHCPCSVC.DLL
DHCPCSVC6.DLL
DISK.SYS
DLLHOST.EXE
DNSAPI.DLL
DNSRSLVR.DLL
DUI70.DLL
DUSER.DLL
DWMAPI.DLL
DXAPI.SYS
DXG.SYS
ELXSTOR.SYS
ESENT.DLL
EXPLORER.EXE
EXPLORERFRAME.DLL
FASTFAT.SYS
FDC.SYS
FECLIENT.DLL
FILEINFO.SYS
FIREWALLAPI.DLL
FLPYDISK.SYS
FLTLIB.DLL
FLTMGR.SYS
FWPUCLNT.DLL
GDI32.DLL
GPAPI.DLL
HID.DLL
HIDSERV.DLL
I8042PRT.SYS
IERTUTIL.DLL
IMAGERES.DLL
IMM32.DLL
INTELIDE.SYS
IPHLPAPI.DLL
IPSEC.SYS
KBD101.DLL
KBD101A.DLL
KBD101B.DLL
KBD101C.DLL
KBD103.DLL
KBD106.DLL
KBD106N.DLL
KBDA1.DLL
KBDA2.DLL
KBDA3.DLL
KBDAL.DLL
KBDARME.DLL
KBDARMW.DLL
KBDAX2.DLL
KBDAZE.DLL
KBDAZEL.DLL
KBDBASH.DLL
KBDBE.DLL
KBDBENE.DLL
KBDBGPH.DLL
KBDBGPH1.DLL
KBDBHC.DLL
KBDBLR.DLL
KBDBR.DLL
KBDBU.DLL
KBDBULG.DLL
KBDCA.DLL
KBDCAN.DLL
KBDCLASS.SYS
KBDCR.DLL
KBDCZ.DLL
KBDCZ1.DLL
KBDCZ2.DLL
KBDDA.DLL
KBDDIV1.DLL
KBDDIV2.DLL
KBDDV.DLL
KBDES.DLL
KBDEST.DLL
KBDFA.DLL
KBDFC.DLL
KBDFI.DLL
KBDFI1.DLL
KBDFO.DLL
KBDFR.DLL
KBDGAE.DLL
KBDGEO.DLL
KBDGEOER.DLL
KBDGEOQW.DLL
KBDGKL.DLL
KBDGR.DLL
KBDGR1.DLL
KBDGRLND.DLL
KBDHAU.DLL
KBDHE.DLL
KBDHE220.DLL
KBDHE319.DLL
KBDHEB.DLL
KBDHELA2.DLL
KBDHELA3.DLL
KBDHEPT.DLL
KBDHID.SYS
KBDHU.DLL
KBDHU1.DLL
KBDIBM02.DLL
KBDIBO.DLL
KBDIC.DLL
KBDINASA.DLL
KBDINBE1.DLL
KBDINBE2.DLL
KBDINBEN.DLL
KBDINDEV.DLL
KBDINGUJ.DLL
KBDINHIN.DLL
KBDINKAN.DLL
KBDINMAL.DLL
KBDINMAR.DLL
KBDINORI.DLL
KBDINPUN.DLL
KBDINTAM.DLL
KBDINTEL.DLL
KBDINUK2.DLL
KBDIR.DLL
KBDIT.DLL
KBDIT142.DLL
KBDIULAT.DLL
KBDJPN.DLL
KBDKAZ.DLL
KBDKHMR.DLL
KBDKOR.DLL
KBDKYR.DLL
KBDLA.DLL
KBDLAO.DLL
KBDLK41A.DLL
KBDLT.DLL
KBDLT1.DLL
KBDLT2.DLL
KBDLV.DLL
KBDLV1.DLL
KBDMAC.DLL
KBDMACST.DLL
KBDMAORI.DLL
KBDMLT47.DLL
KBDMLT48.DLL
KBDMON.DLL
KBDMONMO.DLL
KBDNE.DLL
KBDNEC.DLL
KBDNEC95.DLL
KBDNECAT.DLL
KBDNECNT.DLL
KBDNEPR.DLL
KBDNO.DLL
KBDNO1.DLL
KBDNSO.DLL
KBDPASH.DLL
KBDPL.DLL
KBDPL1.DLL
KBDPO.DLL
KBDRO.DLL
KBDROPR.DLL
KBDROST.DLL
KBDRU.DLL
KBDRU1.DLL
KBDSF.DLL
KBDSG.DLL
KBDSL.DLL
KBDSL1.DLL
KBDSMSFI.DLL
KBDSMSNO.DLL
KBDSN1.DLL
KBDSOREX.DLL
KBDSORS1.DLL
KBDSORST.DLL
KBDSP.DLL
KBDSW.DLL
KBDSW09.DLL
KBDSYR1.DLL
KBDSYR2.DLL
KBDTAJIK.DLL
KBDTAT.DLL
KBDTH0.DLL
KBDTH1.DLL
KBDTH2.DLL
KBDTH3.DLL
KBDTIPRC.DLL
KBDTUF.DLL
KBDTUQ.DLL
KBDTURME.DLL
KBDUGHR.DLL
KBDUGHR1.DLL
KBDUK.DLL
KBDUKX.DLL
KBDUR.DLL
KBDUR1.DLL
KBDURDU.DLL
KBDUS.DLL
KBDUSA.DLL
KBDUSL.DLL
KBDUSR.DLL
KBDUSX.DLL
KBDUZB.DLL
KBDVNTC.DLL
KBDWOL.DLL
KBDYAK.DLL
KBDYBA.DLL
KBDYCC.DLL
KBDYCL.DLL
KERNEL32.DLL
KERNELBASE.DLL
LLTDIO.SYS
LOGONUI.EXE
LPK.DLL
LSASRV.DLL
LSASS.EXE
LSM.EXE
MOUHID.SYS
MOUNTMGR.SYS
MPR.DLL
MSASN1.DLL
MSCMS.DLL
MSCOREE.DLL
MSCORIES.DLL
MSCTF.DLL
MSFTEDIT.DLL
MSHTML.DLL
MSIEXEC.EXE
MSIMG32.DLL
MSPRIVS.DLL
MSV1_0.DLL
MSVCRT.DLL
MSWSOCK.DLL
NAPINSP.DLL
NCOBJAPI.DLL
NCRYPT.DLL
NDIS.SYS
NDISTAPI.SYS
NDISUIO.SYS
NETAPI32.DLL
NETUTILS.DLL
NLAAPI.DLL
NORMALIZ.DLL
NSI.DLL
NSISVC.DLL
NTDLL.DLL
NTFS.SYS
NTKRNLPA.EXE
NTMARTA.DLL
NTOSKRNL.EXE
NTSHRUI.DLL
ODBCCP32.DLL
ODBCCU32.DLL
OLE2DISP.DLL
OLE32.DLL
OLEACC.DLL
OLEAUT32.DLL
ONEXUI.DLL
PACER.SYS
PCAUI.DLL
PCI.SYS
PCIIDE.SYS
PCWUM.DLL
PEERDISTSVC.DLL
PNPUNATTEND.EXE
PNRPNSP.DLL
PNRPSVC.DLL
PORTABLEDEVICEWMDRM.DLL
POWRPROF.DLL
PPCSNAP.DLL
PRESENTATIONCFFRASTERIZERNATIVE_V0300.DLL
PRESENTATIONHOST.EXE
PRINTFILTERPIPELINEPRXY.DLL
PRNNTFY.DLL
PROCINST.DLL
PROFAPI.DLL
PROFSVC.DLL
PROPSYS.DLL
PSAPI.DLL
PSISDECD.DLL
RASADHLP.DLL
RASAPI32.DLL
RASAUTO.DLL
RASERVER.EXE
RASGCW.DLL
RASMAN.DLL
RASMBMGR.DLL
RASPPP.DLL
RDBSS.SYS
RDPCLIP.EXE
RDPDD.DLL
RDPREFDRVAPI.DLL
RNR20.DLL
RPCEPMAP.DLL
RPCRT4.DLL
RPCRTREMOTE.DLL
RPCSS.DLL
RSAENH.DLL
RSHX32.DLL
RTUTILS.DLL
RUNDLL32.EXE
RUNONCE.EXE
SAMCLI.DLL
SAMLIB.DLL
SAMSRV.DLL
SCARDDLG.DLL
SCESRV.DLL
SCEXT.DLL
SCHANNEL.DLL
SCSIPORT.SYS
SECHOST.DLL
SECUR32.DLL
SERVICES.EXE
SETUPAPI.DLL
SFC.DLL
SFC_OS.DLL
SHELL32.DLL
SHFOLDER.DLL
SHLWAPI.DLL
SLC.DLL
SMSS.EXE
SPPC.DLL
SPPOBJS.DLL
SPPWMI.DLL
SRVCLI.DLL
SSDPSRV.DLL
SSPICLI.DLL
SSPISRV.DLL
STI_CI.DLL
STORPORT.SYS
SVCHOST.EXE
SXPROXY.DLL
SXS.DLL
SXSSRV.DLL
SXSSTORE.DLL
SYSNTFY.DLL
TASKSCHDPS.DLL
TCMSETUP.EXE
TCPIP.SYS
TCPMONUI.DLL
TERMDD.SYS
THEMEUI.DLL
TIMER.DRV
TOOLHELP.DLL
TPMCOMPC.DLL
TSDDD.DLL
TZRES.DLL
UBPM.DLL
UMPNPMGR.DLL
UMPO.DLL
URLMON.DLL
USER32.DLL
USERENV.DLL
USERINIT.EXE
USP10.DLL
UTILDLL.DLL
UXINIT.DLL
UXTHEME.DLL
VAULTCLI.DLL
VAULTSVC.DLL
VERSION.DLL
VOLMGR.SYS
VWIFIBUS.SYS
W32TM.EXE
WBADMIN.EXE
WBEMCOMN.DLL
WBEMPROX.DLL
WBEMSVC.DLL
WBIOSRVC.DLL
WEVTAPI.DLL
WIN32K.SYS
WINBIO.DLL
WINBRAND.DLL
WINDOWSCODECS.DLL
WINDOWSCODECSEXT.DLL
WINHTTP.DLL
WININET.DLL
WININIT.EXE
WINLOAD.EXE
WINLOGON.EXE
WINMM.DLL
WINNSI.DLL
WINRNR.DLL
WINSPOOL.DRV
WINSRPC.DLL
WINSRV.DLL
WINSTA.DLL
WINTRUST.DLL
WKSCLI.DLL
WLANCONN.DLL
WLANMM.DLL
WLDAP32.DLL
WMPCM.DLL
WMSGAPI.DLL
WMVXENCD.DLL
WOW32.DLL
WOW64.DLL
WOW64CPU.DLL
WOW64WIN.DLL
WS2HELP.DLL
WS2_32.DLL
WSHIP6.DLL
WSHTCPIP.DLL
WSMAUTO.DLL
WTSAPI32.DLL
WUAPP.EXE
WUDFPLATFORM.DLL
WWANAPI.DLL
XMLLITE.DLL
d:\Avast900\src\BUILDS\Release\x86\InstCont.pdb
GetProcessHeap
KERNEL32.dll
USER32.dll
ADVAPI32.dll
SHELL32.dll
Instup.dll
SHLWAPI.dll
GetCPInfo
InstCont.exe
.?AVwindows_file_codecvt@@
zcÁ
.?AVIExportable@asw@@
.?AV?$Exportable@VILogger@log@asw@@@asw@@
.?AVExportedFromModule@asw@@
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS></application></compatibility></assembly>
9-999E9j9u9}9
4%4u4
> >$>(>,>0>4>8><>|>
5 5$5(5,5054585<5
<*<6<;<{<
9(:3:9:`:
2 21272=2
8"8'8,818:8
.mscoree.dll
- CRT not initialized
- Attempt to initialize the CRT more than once.
- floating point support not loaded
portuguese-brazilian
\\.\ASWSP_Open
avast! Self-Defense trust was not acquired. Code %s
Cannot initialize Instup, return code %s
Error returned by Instup, return code %s
Error in Instup cleanup, return code %s
hu/hu/hu hu:hu:hu END: Avast installer/updater, return code %s
The operation completed successfully
Operation was cancelled
Proxy login needed
HTTP error
Retrying operation
%d (0xX)
ais_shl_web
alc_shl_web
ais_cmp_webrep
alc_cmp_webrep
dbghelp.dll
ekernel32.dll
crash.log
unp%u%u.mdmp
Warning: Multiple calls to GenerateExceptionReport! Ignoring additional calls.
* No exception info provided for GenerateCrashReport.
rKernel32.dll
entdll.dll
0xx (%d)
\\.\aswSP_Handler
\\.\ASWSP
daavmGlob.cnt
aavmGlob.mtx
aavmRefr.now
aavmSema.apc
asw.script_blocking.conf_data
asw.script_blocking.conf_data_protect
aswAavmUp.evt
aswArPotTest.evt
aswLogDebug.mtx
AswMailSvc.Evt
aswUpdateNow.evt
Avast5.ChestMutex
AvWsCfgChg.evt
AvWsTrm.evt
vpsNew.sig
vpsUpdat.sig
Avast5.XLayer.AavmMutex
AswProxyCfgChg.evt
AswProxy.evt
avResWss64.mtx
avResE2K64.mtx
avResSPM64.mtx
avResMai64.mtx
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\instup.exe
10.2.2218.942
Instup.exe

werfault.exe_2576:

.text
`.data
.rsrc
@.reloc
ADVAPI32.dll
ntdll.DLL
KERNEL32.dll
USER32.dll
msvcrt.dll
ole32.dll
OLEAUT32.dll
SHLWAPI.dll
IMM32.dll
wer.dll
COMCTL32.dll
faultrep.dll
Starting kernel vertical - %S
rundll32.exe
NtQueryInformationProcess failed with status: 0x%x
Reporting never started for process id %u
StringCchPrintf failed with 0x%x
NtWow64QueryInformationProcess64 failed with 0x%x
NtWow64ReadVirtualMemory64 failed with 0x%x
NtQueryInformationProcess failed with status 0x%x
WerpNtWow64QueryInformationProcess64 failed with status 0x%x
StringCchCopy failed with 0x%x
Invalid arg in %s
wdi.dll
dbgeng.dll
dbghelp.dll
SETUPAPI.dll
SHELL32.dll
VERSION.dll
WTSAPI32.dll
WerFault.pdb
PSShD
tSSh,<
t.PSj6
t5SSh
SShx`
tsShxc
t.Ph0j
_amsg_exit
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegEnumKeyExW
RegQueryInfoKeyW
GetProcessHeap
GetWindowsDirectoryW
RegDeleteKeyW
ReportEventW
RegOpenKeyW
RegSetKeyValueW
GetProcessWindowStation
EnumWindows
NtAlpcSendWaitReceivePort
NtAlpcConnectPort
ShipAssert
ntdll.dll
RegisterErrorReportingDialog
WerReportSubmit
WerReportAddFile
WerReportCreate
WerReportCloseHandle
WerReportSetUIOption
WerpGetReportConsent
WerpSetIntegratorReportId
WerpReportCancel
WerpAddRegisteredDataToReport
WerReportAddDump
WerpCreateIntegratorReportId
WerpSetReportFlags
WerpGetReportFlags
WerpIsTransportAvailable
WerReportSetParameter
WerpInitiateCrashReporting
version="1.0.0.0"
name="Microsoft.Windows.Feedback.Watson"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<asmv3:windowsSettings xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">
</asmv3:windowsSettings>
<requestedExecutionLevel
ÝCD0
#$$$3355<
##$$$335566
% "#$$$3355666=
"#$$33555666
!.DQ$
.Py>o
Kÿg
.ib:?
T3%X_
a,M.cbd
KEYW8
KEYWH
? ?$?(?,?0?4?8?
1 2$2(2,20242
>,?0?4?8?<?@?
?%?5?:?|?
5'565^5{5
3#3(353_3
=#='= =/=3=7=;=?=
=#=(=>=]=
>!>&>3>}>
1!1&131[1
Microsoft\Windows\WindowsErrorReporting\WerFault
%s %s
Global\WerKernelVerticalReporting
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl
CrashDumpEnabled.Old
CrashDumpEnabled.New
%SystemRoot%\MEMORY.DMP
LiveKernelReports
Software\Microsoft\Windows\Windows Error Reporting\LiveKernelReports
LiveKernelReportsPath
BCCode=%x&BCP1=%p&BCP2=%p&BCP3=%p&BCP4=%p&OS Version=%u_%u_%u&Service Pack=%u_%u&Product=%u_%u
*WerKernelReporting
%SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
SOFTWARE\Microsoft\Windows\Windows Error Reporting\KernelFaults\Queue
sysdata.xml
%s -k -q
SOFTWARE\Microsoft\Windows NT\CurrentVersion
<OSVER>%u.%u.%u %u.%u</OSVER>
<OSLANGUAGE>%u</OSLANGUAGE>
<ARCHITECTURE>%u</ARCHITECTURE>
<PRODUCTTYPE>%u</PRODUCTTYPE>
<FILESIZE>%u</FILESIZE>
<CREATIONDATE>d-d-d d:d:d</CREATIONDATE>
<NAME>%s</NAME>
<DATA>%s</DATA>
<ERROR>Failed at Step: %s with error 0x%x</ERROR>
%sDrivers\%s.sys
</%s>
<%s>%s</%s>
%u.%u.%u.%u
*.mrk
WER-%u-%u.sysdata.xml
Software\Microsoft\Windows\CurrentVersion\CEIPRole\RolesInWER
SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability\MemoryDiagnostic
Web Server
Software\Microsoft\Windows\Windows Error Reporting\Debug
%SystemRoot%\Minidump
0xx (0xx, 0xx, 0xx, 0xx)
%s\%2.2d%2.2d%2.2d-%u-%2.2d.dmp
*.dmp
Software\Microsoft\Windows\Windows Error Reporting
Software\Policies\Microsoft\Windows\Windows Error Reporting
\KernelObjects\SystemErrorPortReady
%s\%s
Microsoft.Windows.Setup
\WindowsErrorReportingServicePort
(0x%x): %s
%u %s
WindowsNTVersion
%u.%u
ErrorPort
\StringFileInfo\xx\%s
HKEY_USERS\
HKEY_CURRENT_CONFIG\
HKEY_CLASSES_ROOT\
HKEY_LOCAL_MACHINE\
HKEY_CURRENT_USER\
%s="%s"
%s.%s
%s %d
Software\Microsoft\Windows\Windows Error Reporting\Hangs
_NT_EXECUTABLE_IMAGE_PATH
wxmu.dmp
wxhu.dmp
axmu.dmp
axhu.dmp
hu.kdmp
mu.kdmp
hu.dmp
mu.dmp
Software\Microsoft\.NETFramework
NOT_TCPIP
sos.dll
version.xml
.version.xml
%s.xml
memory.hdmp
minidump.mdmp
Local\WERReportingForProcess%d
atk.kdmp
Software\Microsoft\Windows\Windows Error Reporting\Hangs\NHRTimes
%i|%d|%d
xxxxxxxxxxxxxxxx
xx
%d.%d.%d.%d
D:P(A;;GA;;;BA)(A;;GA;;;SY)(A;;GA;;;%s)
D:P(A;;GA;;;BA)(A;;GA;;;SY)(A;;GA;;;%s)S:(ML;;NR;;;HI)
dc.noreflect
dc.xpmemdump
dc.xpdata
dc.CustomDump
dc.expmodmem
dc.expmoddata
dc.OnDemandKdmp
dc.xpmodmem
dc.xpmoddata
default=%s
memory=%s
module=%s
.dbgcfg.ini
ElevatedDataCollectionStatus.txt
Open process failed unexpectedly: 0X%X
Attempting to cross-proc reporting process!
Elevation:Administrator!new:%s
Reflection attempt failed: 0X%X
Attempting to reflect reporting process!
Could not collect dump for reflection cross process: 0x%x
Could not collect xproc for reflection: 0x%x
CollectFile for reflection failed: 0x%x
Could not collect dump for cross process: 0x%x
CollectReflectionDump failed with: 0x%x
0 processes found for xproc module: %s
Could not collect cross dump from module: 0x%x
CollectCrossProcessModuleDumps failed: 0x%x
CollectCrossProcessDumps failed: 0x%x
KernelDump failed: 0x%x
ProcessHandle
%s|%s
rpcrt4
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebugProtected\AutoExclusionList
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebug\AutoExclusionList
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebugProtected
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebug
sntdll.dll
WerDiagController.dll
Software\Microsoft\Windows\Windows Error Reporting\Plugins
Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Software\Microsoft\Windows\Windows Error Reporting\Plugins\FDR\CurrentSession
%s\%s\%u-%u.etl
%s\%s\%u-%u.etl_%d
Microsoft\Windows\FDR
%s-%d
Software\Microsoft\Windows\Windows Error Reporting\Plugins\DriverVerifier
Software\Microsoft\Windows\Windows Error Reporting\Plugins\AppRecorder
%d-AppRecorderEnabled
%s /stop
psr.exe
Software\Microsoft\Windows\Windows Error Reporting\RuntimeExceptionHelperModules
verifier.dll
nVerifier.dll
Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\%s
Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
lsvchost.exe
"%s" "%s" "%s"
%s\system32\cofire.exe
psapi.dll
sfc_os.dll
werfault.exe
%s\%s-(PID-%u)-%u
%s\%s-(PID-%u).dmp
%s\*-(PID-*)-*
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\%s
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit
kernel32.dll
kernelbase.dll
ReportingMode
WinShipAssert
WindowsMessageReportingB1
Windows
ws2_32.dll
Software\Microsoft\SQMClient\%s\AdaptiveSqm\ManifestInfo
%s\Sqm%d.bin
CorporateWerPortNumber
BypassDataThrottling
Software\Microsoft\Windows\Windows Error Reporting\Consent
Windows Problem Reporting
6.1.7600.16385 (win7_rtm.090713-1255)
WerFault.exe
Windows
Operating System
6.1.7600.16385
Microsoft-Windows-WER-Diag/Operational

AvastSvc.exe_832:

.text
`.rdata
@.data
.rsrc
@.reloc
advapi32.dll
ws2_32.dll
RegOpenKeyExA
vlsp.dll
nl_lsp.dll,imon.dll,xfire_lsp.dll,mslsp.dll,mssplsp.dll,cwhook.dll
HKEY_LOCAL_MACHINE
2d
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
, Key:
RegOpenKeyTransactedW
RegDeleteKeyExW
d:\Avast900\src\BUILDS\Release\x86\AvastSvc.pdb
log.dll
aswCmnBS.dll
KERNEL32.dll
RegOpenKeyExW
RegCreateKeyExW
RegDeleteKeyW
RegCloseKey
RegCreateKeyExA
RegEnumKeyExA
RegQueryInfoKeyA
RegDeleteKeyA
RegEnumKeyW
ADVAPI32.dll
SHELL32.dll
ashBase.dll
MSVCP110.dll
SHLWAPI.dll
WS2_32.dll
MSVCR110.dll
_crt_debugger_hook
__crtUnhandledException
__crtTerminateProcess
_calloc_crt
__crtGetShowWindowMode
_amsg_exit
_wcmdln
__crtSetUnhandledExceptionFilter
GetProcessHeap
AvastSvc.exe
.?AV?$Exportable@VIPropertyRpcConnector@rpc@settings@asw@@@asw@@
.?AVExportedFromModule@asw@@
.?AVIExportable@asw@@
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
<assemblyIdentity type='win32' processorArchitecture='x86' name='Avast.VC110.CRT' version='11.0.60610.1' publicKeyToken='2036b14a11e83e4a' />
< = =1=7===
0
0P0V0_0
: :%:7:<:
9Ÿ9X9
5_5x5
2 3%3[3`3
%0U0Z0
: :$:(:,:
r:\storage\sdk\vs 2012\boost\1.55.0\include\boost\thread\win32\basic_timed_mutex.hpp
%s\%s
\log\AvastSvc.log
Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastSvc.exe
Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastUI.exe
ashServ.dll
aswServ.dll
avast5.ini
r:\storage\sdk\vs 2012\boost\1.55.0\include\boost\token_iterator.hpp
ais_shl_web
alc_shl_web
ais_cmp_webrep
alc_cmp_webrep
servers.def
\avast5.ini
*AavmRpch.dll
config.def
Advapi32.dll
ntdll.dll
avastcfg://ExchangeShield/Exchange/ScanAtTransportLevel
Blocked_by_avast.txt
avastcfg://FileSystemShield/FileSystem/ScanOnExecute
avastcfg://FileSystemShield/FileSystem/ScanScriptsOnExecute
<RW>?:\PageFile.sys;<RW>*\System.da?;<RW>*\User.da?;<RW>*.fon;<RW>*.txt;<RW>*.log;<RW>*.ini;<RW>*\Bootstat.dat;<W>*\firefox\profiles\*sessionstore*.js
avastcfg://StreamFilter/Common/FilterTcp
avastcfg://StreamFilter/Common/FilterUdp
avastcfg://StreamFilter/Common/RecordTcp
avastcfg://StreamFilter/Common/RecordUdp
avastcfg://StreamFilter/TcpFilter/InnerDump
avastcfg://StreamFilter/TcpFilter/OuterDump
avastcfg://StreamFilter/TcpFilter/Http1x
avastcfg://StreamFilter/TcpFilter/Http2x
avastcfg://StreamFilter/TcpFilter/Spdy
avastcfg://StreamFilter/TcpFilter/Connect
avastcfg://StreamFilter/TcpFilter/Ssl
avastcfg://StreamFilter/TcpFilter/SslCertRep
avastcfg://StreamFilter/TcpFilter/SecureDns
avastcfg://StreamFilter/TcpFilter/DnsCache
avastcfg://StreamFilter/UdpFilter/SecureDns
avastcfg://StreamFilter/UdpFilter/DnsCache
avastcfg://StreamFilter/HttpPlugin/Scanner
avastcfg://StreamFilter/HttpPlugin/UrlBlocker
avastcfg://StreamFilter/HttpPlugin/LicenseDownloader
avastcfg://StreamFilter/HttpPlugin/AvastHeaders
avastcfg://StreamFilter/HttpPlugin/UrlPatternDetector
hXXps://ipm-provider.ff.avast.com/api/?action=2&p_elm=136
avastdef://config/WebShieldUrlCaptures/RedirectLicenseUrl
hXXps://ipm-provider.ff.avast.com/api/?action=2&p_elm=137
avastdef://config/WebShieldUrlCaptures/RedirectLicenseVpnUrl
avastdef://config/WebShieldUrlCaptures/RefreshLicenseUrl
hXXps://id.avast.com/inAvastium
avastdef://config/WebShieldUrlCaptures/RedirectMyAvastUrl
avastcfg://WebShield/SSL/BlockingDuration
avastcfg://WebShield/SSL/PassthruEV
avastcfg://WebShield/SSL/PassthruDuration
avastcfg://WebShield/SSL/QueryCert
avastcfg://WebShield/SSL/PassthruBank
avastcfg://WebShield/SSL/SupportNPN
avastcfg://WebShield/SSL/SupportALPN
avastcfg://WebShield/SSL/SupportSSL3
avastcfg://WebShield/SSL/CertCheckOnlineRevokeList
avastcfg://WebShield/SSL/CertOnlineCheckTimeout
avastcfg://NetworkShield/NetworkShield/SendBlockedUrlStats
avastcfg://P2PShield/P2P/eDonkey
avastcfg://P2PShield/P2P/OperaDCPP
*.DCTMP;*\__INCOMPLETE__*;*.TIGER;*TMP*.DAT;*\INCOMPLETE\*;*.SD;*.PART;*.PART.*;*\INCOMPLETE~*;*\___ARESTRA___*;*.BC!;*.!UT
*\COOKIES.TXT;*\MIRANDA.DAT
avastcfg://ScriptShield/Common/ExcludedURLs
avastcfg://ScriptShield/Common/ExcludedURLsList
avastcfg://ScriptShield/Common/MozillaFirefox
avastcfg://ScriptShield/Common/GoogleChrome
avastcfg://WebShield/General/UseStreamFilter
avastcfg://WebShield/WebScanner/WebScanning
avastcfg://WebShield/WebScanner/HttpsScanning
avastcfg://WebShield/WebScanner/HttpsScanOnlyBrowsers
avastcfg://WebShield/WebScanner/NetworkShield
avastcfg://WebShield/WebScanner/ScriptScaning
avastcfg://WebShield/WebScanner/SecureDns
avastcfg://WebShield/WebScanner/IntelligentStreamScanning
avastcfg://WebShield/WebScanner/DoNotScanTrustedSites
avastcfg://WebShield/WebScanner/HttpScanParamFlag
avastcfg://WebShield/WebScanner/HttpScanParamExtensions
avastcfg://WebShield/WebScanner/HttpScanParamExtensionsList
avastcfg://WebShield/WebScanner/HttpScanParamType
avastcfg://WebShield/WebScanner/HttpScanParamTypeList
avastcfg://WebShield/WebScanner/URLBlocking
avastcfg://WebShield/WebScanner/BlockedURLs
avastcfg://WebShield/WebScanner/ExcludedURLs
avastcfg://WebShield/WebScanner/ExcludedURLsList
avastcfg://WebShield/WebScanner/ExcludedTypes
avastcfg://WebShield/WebScanner/ExcludedTypesList
avastcfg://WebShield/WebScanner/IgnoreProcess
avastcfg://WebShield/WebScanner/MaxObjectSizeKB
avastcfg://WebShield/WebScanner/DisableScanner
avastcfg://EmailShield/EmailScanner/MarkSubjectForVirusMsg
avastcfg://EmailShield/EmailScanner/SubjectForVirusMsg
avastcfg://EmailShield/EmailScanner/MarkSubjectForSuspiciousMsg
avastcfg://EmailShield/EmailScanner/SubjectForSuspiciousMsg
avastcfg://EmailShield/EmailScanner/InsertNoteCleanMsgIn
avastcfg://EmailShield/EmailScanner/InsertNoteInfectedMsgIn
avastcfg://EmailShield/EmailScanner/InsertNoteCleanMsgOut
avastcfg://EmailShield/EmailScanner/InsertNoteInfectedMsgOut
avastcfg://AntiSpamShield/AntiSpam/SubjectForPhishMsg
avastcfg://AntiSpamShield/AntiSpam/SubjectForSpamMsg
avastcfg://AntiSpamShield/Exchange/DeleteSpamMsg
avastcfg://avast5/Communication/SMTPPort
avastcfg://avast5/Communication/SMTPServer
avastcfg://avast5/Communication/SMTPFrom
avastcfg://avast5/Communication/SMTPAuth
avastcfg://avast5/Communication/SMTPUserName
avastcfg://avast5/Communication/SMTPUserPassword
avastcfg://avast5/Common/DontUseChrome
avastcfg://avast5/Common/MAPIPassword
avastcfg://exclusions/Global/ExcludeUrls
avastcfg://avast5/Chest/CheckPassword
avastcfg://EmailShield/EmailScanner/PopRedirectPort
avastcfg://EmailShield/EmailScanner/SmtpRedirectPort
avastcfg://EmailShield/EmailScanner/ImapRedirectPort
avastcfg://EmailShield/EmailScanner/NntpRedirectPort
avastcfg://EmailShield/EmailScanner/PopRedirectPortSSL
avastcfg://EmailShield/EmailScanner/SmtpRedirectPortSSL
avastcfg://EmailShield/EmailScanner/ImapRedirectPortSSL
avastcfg://EmailShield/EmailScanner/NntpRedirectPortSSL
avastcfg://WebShield/WebScanner/HttpRedirectPort
avastcfg://WebShield/WebScanner/IgnoreAddress
avastcfg://WebShield/WebScanner/IgnoreLocalhost
avastcfg://WebShield/WebScanner/AutoRedirect
avastcfg://WebShield/WebScanner/Port
avastcfg://WebShield/WebScanner/ScanOnlyBrowsers
avastcfg://WebShield/WebScanner/WarnFileRep
avastcfg://WebShield/WebScanner/DontUnpackSignedArchives
avastcfg://avast5/Common/PropertyPowerbarWeb
avastcfg://avast5/Common/PasswordEnabled
avastcfg://avast5/Common/PasswordUI
avastcfg://avast5/Common/Password
avastcfg://avast5/Common/PasswordSettings
avastcfg://avast5/Common/PasswordProt
avastcfg://avast5/Common/PasswordProtSettings
avastcfg://avast5/Common/PasswordScan
avastcfg://avast5/Common/PasswordScanSettings
avastcfg://avast5/Common/PasswordUpdate
avastcfg://avast5/Common/PasswordChest
avastcfg://avast5/Common/PasswordImex
avastcfg://avast5/Common/PasswordFirewall
avastcfg://avast5/Common/ShowChrome
avastcfg://avast5/Common/SBCServerPort
avastcfg://avast5/Common/MonthlyReports
avastcfg://avast5/Common/LastMonthlyReport
avastcfg://avast5/Common/WebRepLogging
avastcfg://avast5/Common/WebRepAutoInstall
avastcfg://avast5/Common/WebRepControl
avastcfg://avast5/Common/WebRepPhishingFilter
avastcfg://avast5/Common/WebRepSafeZone
avastcfg://avast5/Common/WebRepNoPopups
avastcfg://avast5/Common/ShowChromeWebRepInstallOffer
avastcfg://avast5/Common/EncKey
avastcfg://avast5/Common/DailyReportSent
avastcfg://avast5/Common/ChromeInstallStarted
avastcfg://avast5/Common/ARCPasswordEnabled
avastcfg://avast5/Common/ARCPassword
avastcfg://avast5/Common/WinSatCPU
avastcfg://avast5/Common/ShowChromeToasterInstallOffer
avastcfg://avast5/Support/SystemInfo
avastcfg://avast5/Support/SystemLog
avastcfg://avast5/Support/Minidumps
avastcfg://avast5/Support/Fulldupms
avastcfg://avast5/Support/LatestPackage
avastcfg://avast5/Support/NextUploadBetaPackage
avastcfg://avast5/Support/BetaSupportLastUpload
avastcfg://avast5/Support/ArcBetaTest
avastcfg://avast5/Support/UsePassword
avastcfg://avast5/Shredder/ShredFilesNumpass
avastcfg://avast5/Shredder/ShredFreespaceNumpass
avastcfg://avast5/Shredder/ShredPartitionNumpass
EXE;WinExec;Streams;Drop
avastcfg://avast5/***TaskGUID***/Report
avastcfg://avast5/***TaskGUID***/ReportName
avastcfg://avast5/***TaskGUID***/ReportRecords
avastcfg://avast5/***TaskGUID***/OverwriteReport
windows
avastcfg://avast5/***TaskGUID***/Execution
avastcfg://AntiSpamShield/Common/Report
avastcfg://WebShield/Common/ScanPackers
avastcfg://WebShield/Common/VirusAction
avastcfg://WebShield/Common/SuspiciousAction
avastcfg://WebShield/Common/PUPAction
avastcfg://***ProviderINI***/Common/Report
avastcfg://***ProviderINI***/Common/ReportName
avastcfg://***ProviderINI***/Common/ReportRecords
avastcfg://***ProviderINI***/Common/OverwriteReport
avastcfg://avast5/AdnmSettings/SMTPServer
avastcfg://avast5/AdnmSettings/SMTPPort
avastcfg://avast5/AdnmSettings/SMTPFrom
avastcfg://avast5/AdnmSettings/SMTPAuth
avastcfg://avast5/AdnmSettings/SMTPUser
avastcfg://avast5/AdnmSettings/SMTPPassword
avastcfg://avast5/AdnmSettings/PasswordGeneral
avastcfg://avast5/AdnmSettings/PasswordSettings
avastcfg://avast5/AdnmSettings/PasswordProtectionControl
avastcfg://avast5/AdnmSettings/PasswordProtectionSettings
avastcfg://avast5/AdnmSettings/PasswordScanControl
avastcfg://avast5/AdnmSettings/PasswordScanSettings
avastcfg://avast5/AdnmSettings/PasswordUpdateControl
avastcfg://avast5/AdnmSettings/PasswordChestControl
avastcfg://avast5/Lan/WindowsDevices
avastcfg://avast5/RemoteAssistance/DontUseDNSFromKeys
rh.ara.avast.com
avastcfg://avast5/RemoteAssistance/RemotePort
127.0.0.1
avastcfg://avast5/RemoteAssistance/ConnectionPort
avastcfg://avast5/RemoteAssistance/DataPort
avastcfg://avast5/RemoteAssistance/ListenPort
certs
avastcfg://avast5/RemoteAssistance/CertDirPath
aralog.log
avastcfg://avast5/StreamBack/KeyId
avastcfg://avast5/StreamBack/Key
avastcfg://avast5/StreamBack/KeyExpiration
urnal.datinil
avast5.ini
nfig.def.new
Stats.iniv
Stats.inir
Stats.ini-
Stats.iniP
Stats.inig
Stats.inie
Stats.ini\
Stats.ini2
Stats.ini6
Stats.iniE
Stats.iniw
Stats.inin
Stats.ini
10.2.2218.942

AvastSvc.exe_832_rwx_01110000_00030000:

SfChannel09dc4dc8Cmd

AvastSvc.exe_832_rwx_01D50000_00070000:

mm.mode
dumper.channel
dumper.log
sys.lazyattach
apitrace.flags

AvastSvc.exe_832_rwx_0A0B0000_000B0000:

%Program Files%\AVAST Software\Avast\defs\15042301\Sf2.dll


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    GoogleUpdate.exe:1176
    GoogleUpdate.exe:2424
    GoogleUpdate.exe:2556
    GoogleUpdate.exe:1856
    GoogleUpdate.exe:1932
    GoogleUpdaterService_B33FC4DD36A473C6.exe:1412
    aswOfferTool.exe:1344
    aswOfferTool.exe:2944
    aswOfferTool.exe:304
    aswOfferTool.exe:2256
    aswOfferTool.exe:2784
    GoogleToolbarNotifier.exe:2468
    GoogleToolbarNotifier.exe:2728
    RegSvr32.exe:2432
    RegSvr32.exe:2468
    RegSvr32.exe:1368
    RegSvr32.exe:2916
    setup___.exe:1816
    GoogleUpdaterService.exe:2800
    GoogleUpdaterService.exe:1604
    OLBPre.exe:2252
    RegSvr64.exe:2964
    RegSvr64.exe:956
    RegSvr64.exe:1012
    RegSvr64.exe:1176
    googletoolbarinstaller_en_signed.exe:2660
    GoogleUpdateSetup_1.3.21.169.exe:580
    MPBSETUP.exe:1752
    gtoolbar_setup_14298696672256.exe:1760
    instup.exe:3916
    instup.exe:1544
    instup.exe:4084
    instup.exe:3784
    instup.exe:2812
    instup.exe:3376
    instup.exe:3756
    instup.exe:3584
    instup.exe:3708
    instup.exe:3412
    instup.exe:4012
    instup.exe:3368
    instup.exe:3296
    instup.exe:3176
    SearchWithGoogleUpdate_6F4EEAE8D7FCDAD8.exe:1368
    avBugReport.exe:836
    aswRunDll.exe:1760
    aswRunDll.exe:3820
    keytool.exe:3472
    regsvr32.exe:1636
    %original file name%.exe:1824
    BackupSetup.exe:536
    9fc49b8a-7b2d-463c-978b-474af67c44b7.exe:2792
    AvastEmUpdate.exe:2412
    GoogleToolbarManager_BA9226F4C70BECC2.exe:2636
    GoogleToolbarManager_BA9226F4C70BECC2.exe:2412
    GoogleToolbarManager_BA9226F4C70BECC2.exe:2064

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    %Program Files% (x86)\GUM1B3D.tmp\goopdate.dll (872 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_en.dll (864 bytes)
    %Program Files% (x86)\Google\Update\Install\{A7B6D392-0D13-454B-A517-CBD6C019C7CC}\googletoolbarinstaller_en_signed.exe (38780 bytes)
    C:\Windows\Temp\gui3EC4.tmp (15 bytes)
    %Program Files% (x86)\Google\Update\Download\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\0.0.0.0\googletoolbarinstaller_en_signed.exe (38295 bytes)
    %Program Files% (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe (390 bytes)
    C:\Users\Public\Documents\gcapi_14298695221344.dll (368 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\gcapi_14298695222944.dll (184 bytes)
    C:\Users\Public\Documents\aswOfferTool.exe (23811 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\gcapi_1429869522304.dll (368 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\gtoolbar_setup_14298696672256.exe (1635 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\gtapi_14298695222784.dll (146 bytes)
    %Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll (983 bytes)
    %Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\gtn.dll (147 bytes)
    C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log (484 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x64_ais-89e.vpx (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instcont_ais-89e.vpx (75 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-iex-1.vpx (217 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup.exe (412 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\servers.def (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x86_ais-89e.vpx (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-prg_ais-89e.vpx (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\prod-ais.vpx (354 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\prod-vps.vpx (452 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\setgui_ais-89e.vpx (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avbugreport_ais-89e.vpx (553 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-vps_win32-14102100.vpx (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\HTMLayout.dll (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-jrog2-bb9.vpx (676 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avBugReport.exe (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\Instup.dll (392 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\servers.def.vpx (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-setup_ais-89e.vpx (75 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup_ais-89e.vpx (2 bytes)
    %Program Files% (x86)\OLBPre\state.jdat (428 bytes)
    %Program Files% (x86)\OLBPre\aff.jdat (200 bytes)
    %Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarUser_32_52E818EF81C83A9B.exe (620 bytes)
    %Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbar_64_62C1B48EAF0FD125.dll (514 bytes)
    %Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_0A4439FF67F61065.dll (2 bytes)
    %Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_64_2AD99D2EA038D2F2.dll (489 bytes)
    C:\Windows\System32\config\SOFTWARE (99158 bytes)
    %Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_32_75A7C54F0BE42E8E.dll (149 bytes)
    %Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarUser_64_4D9709C1FA1422BA.exe (801 bytes)
    %Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbar.7.5.6227.252.manifest.xml (36 bytes)
    %Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe (50 bytes)
    %Program Files% (x86)\Google\Google Toolbar\Component\GoogleToolbar_32_3934E923EEC91A78.dll (390 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GoogleToolbarInstaller2.log (43867 bytes)
    %Program Files% (x86)\Google\Google Toolbar\Component\SearchWithGoogleUpdate_6F4EEAE8D7FCDAD8.exe (50 bytes)
    C:\$Directory (384 bytes)
    %Program Files% (x86)\Google\Google Toolbar\Component\GoogleUpdateSetup_5CC4B0F53D73AD88.exe (1480 bytes)
    %Program Files% (x86)\Google\Google Toolbar\Component\GoogleUpdaterService_B33FC4DD36A473C6.exe (390 bytes)
    C:\Windows\System32\config\SOFTWARE.LOG1 (94108 bytes)
    %Program Files% (x86)\Google\Google Toolbar\Component\GoogleCld_187F9D811452062B.dll (50 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_bn.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_ur.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_kn.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_gu.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_sl.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_mr.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_el.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_fil.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_ja.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_et.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_zh-CN.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_es-419.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_pt-BR.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_uk.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_hu.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\GoogleUpdateOnDemand.exe (59 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_da.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_fr.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_de.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_th.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\npGoogleUpdate3.dll (838 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_vi.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_bg.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_pt-PT.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_sv.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_lt.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_ko.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_sr.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_zh-TW.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_ar.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_tr.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_it.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_is.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_no.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_ro.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_en-GB.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\psuser.dll (163 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_hi.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_hr.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_fa.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\GoogleUpdate.exe (234 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_id.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\GoogleCrashHandler.exe (237 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_am.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_nl.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\GoogleUpdateSetup.exe (5873 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_cs.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_ca.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_ru.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_lv.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_fi.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_iw.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\GoogleUpdateHelper.msi (26 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_sw.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\psmachine.dll (163 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\GoogleCrashHandler64.exe (550 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\GoogleUpdateBroker.exe (59 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_ta.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_te.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_ml.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_ms.dll (1702 bytes)
    %Program Files% (x86)\GUT1B3E.tmp (63108 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_sk.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_pl.dll (1702 bytes)
    %Program Files% (x86)\GUM1B3D.tmp\goopdateres_es.dll (1702 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc7E15.tmp\NSISdl.dll (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aff.conf (111 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\BackupSetup.exe (72675 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GoogleUpdateSetup_1.3.21.169.exe (26262 bytes)
    C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log (10438 bytes)
    C:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\atl110.dll (164 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\sasF297.tmp (532 bytes)
    C:\Windows\System32\Tasks (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\zh_TW\mesF3A1.tmp (11 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\en\mesF40F.tmp (11 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\sasF61B.tmp (532 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_o7.map (163 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF553.tmp (159 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\mocks\gptF1CC.tmp (422 bytes)
    %Program Files%\AVAST Software\Avast\ffmFBEE.tmp (985 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\Chrome\AswF18F.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF53F.tmp (715 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\winbar\winF746.tmp (18 bytes)
    C:\Windows\Prefetch (672 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\indF053.tmp (3 bytes)
    %Program Files% (x86)\Google\Google Toolbar\GoogleToolbarHelperPatch_signed.msp (126 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F61D.tmp (566 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\iplugins-4.vpx.dld (423 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ur\mesF49C.tmp (15 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF01D.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\locales\hu.FEE5.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icoF5CC.tmp (7 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\zh_TW\mesF49F.tmp (11 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF030.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (4 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_EE3.tmp (66 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_C9A.tmp (18 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\fi\mesF424.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_E96.tmp (57 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF66D.tmp (557 bytes)
    %Program Files%\AVAST Software\Avast\Setup\Stats.txt (8 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_w6.map (13 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\ialF4DB.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs\jquF1A6.tmp (219 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF579.tmp (215 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_F85.tmp (12 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\butEFC1.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF58E.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\RescueDisk\waiF0BD.tmp (3 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\whiC66.tmp (2 bytes)
    C:\ProgramData\AVAST Software\Avast\sounds\1033\scaF812.tmp (37 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_gen_gui_cef-7ce.vpx (7815 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_C88.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\shoF6FE.tmp (582 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_js.map (6 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F61E.tmp (619 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\de\mesF300.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x64\AvaFA43.tmp (9 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF51F.tmp (736 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\da\mesF3FD.tmp (11 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\sv\mesF478.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF66E.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\resources\resFBBC.tmp (344 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFD9.tmp (1 bytes)
    C:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\mfc110u.dll (678 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ms\mesF360.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\AvaF84A.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\locales\en-FEB8.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\BroEF59.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_cmp_webrep-7ed.vpx (392 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_cmp_grimefighter-7eb.vpx.dld (225848 bytes)
    C:\Windows\System32\drivers\aswHwid.sys (29 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_E25.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\RescueDisk\aswF0BA.tmp (44 bytes)
    %Program Files%\AVAST Software\Avast\locales\kn.FEF8.tmp (30 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\hr\mesF428.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF646.tmp (812 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_crt_x64-7e4.vpx.dld (143341 bytes)
    C:\ProgramData\AVAST Software\Avast\sounds\fw_FA1C.tmp (24 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\sasF608.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\pt_BR\mesF374.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ca\mesF3CC.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\scrEF48.tmp (27 bytes)
    %Program Files%\AVAST Software\Avast\flash\ammap\ammF9BA.tmp (30 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF01E.tmp (1 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF006.tmp (1 bytes)
    %Program Files% (x86)\Google\Google Toolbar\GoogleToolbarHelper_signed.msi (28 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF576.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\fr\mesF327.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\it\mesF43B.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\setup\aswEEE4.tmp (23811 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_cmp_webrep-7ed.vpx.dld (110225 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F2AC.tmp (413 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF043.tmp (1 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF01F.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_CCC.tmp (5879 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFD8.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\he\mesF328.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\arrF4DC.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\locales\bn.FEA3.tmp (28 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_x64-7f5.vpx (392 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF505.tmp (227 bytes)
    %Program Files%\AVAST Software\Avast\locales\nb.FF0F.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\setup\iplugins\ISt9B5.tmp (28 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\aswFEE.tmp (463 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\pinF607.tmp (3 bytes)
    %Program Files%\AVAST Software\Avast\RescueDisk\uiLF0BC.tmp (294 bytes)
    %Program Files%\AVAST Software\Avast\1033\AvaF7EA.tmp (135 bytes)
    %Program Files%\AVAST Software\Avast\setup\setC65.tmp (5 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\de\mesF3FE.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\vi\mesF39F.tmp (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\bn\mesF3CB.tmp (19 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F630.tmp (413 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ur\mesF39E.tmp (15 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5A4.tmp (294 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\blocker\bloF4B5.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\asO64.tmp (456 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\swh1056.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF59F.tmp (450 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\maiF6AB.tmp (738 bytes)
    %Program Files%\AVAST Software\Avast\setup\instcont_ais-8aa.vpx (4185 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\seaF6E6.tmp (11 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ca\mesF2FD.tmp (12 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF007.tmp (1 bytes)
    C:\ProgramData\AVAST Software\Avast\log\PushPin0.log (157 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\jquF699.tmp (92 bytes)
    %Program Files%\AVAST Software\Avast\VisF8A0.tmp (254 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5B7.tmp (470 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\3.gEF99.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\sk\mesF475.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\locales\lv.FEFB.tmp (15 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x64\PolFA54.tmp (9 bytes)
    %Program Files%\AVAST Software\Avast\HTMEEE3.tmp (22575 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF551.tmp (343 bytes)
    %Program Files%\AVAST Software\Avast\aswF78A.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFFDA.tmp (442 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\he\mesF426.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\aswFDD.tmp (127 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF50A.tmp (724 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ko\mesF43D.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\setup\part-vps_win32-15042301.vpx (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F633.tmp (1 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\blaEFC0.tmp (43 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\aswFAA.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\AhR77.tmp (303 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\vps_win64-ca0.vpx.dld (166124 bytes)
    %Program Files%\AVAST Software\Avast\setup\Inf\x64\aswF11B.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\asw1098.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\safeshop (4 bytes)
    %Program Files%\AVAST Software\Avast\OpenVPN\driver\win64\ndis6\aswF0F4.tmp (6 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF209.tmp (357 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_gen_tools_x64-7e2.vpx (1 bytes)
    %Program Files%\AVAST Software\Avast\OpenVPN\driver\win64\ndis6\aswF0F3.tmp (10 bytes)
    %Program Files%\AVAST Software\Avast\ComF87F.tmp (3 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_core-7f5.vpx (3692 bytes)
    C:\Windows\System32\config\SYSTEM (15750 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFD6.tmp (793 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\fblF4DF.tmp (3 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_ECE.tmp (17 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_cmp_grimefighter-7eb.vpx (392 bytes)
    C:\ProgramData\AVAST Software\Avast\Fonts\OpeFA07.tmp (222 bytes)
    %Program Files%\AVAST Software\Avast\ashF8C1.tmp (104 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\conEF6C.tmp (184 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F631.tmp (481 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\credentials\creF4C8.tmp (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_cmp_rescuedisk-7f5.vpx.dld (18805 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF66F.tmp (679 bytes)
    C:\Windows\winsxs\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396\atl110.dll (192 bytes)
    %Program Files%\AVAST Software\Avast\aswF94F.tmp (102 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF032.tmp (1 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF003.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\logFA31.tmp (114 bytes)
    C:\ProgramData\AVAST Software\Avast\log\Instup.log (2840 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\settings\optF6E8.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icoF5CE.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\aswdefs.ini (32 bytes)
    %Program Files%\AVAST Software\Avast\locales\el.FEB7.tmp (24 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\avaF4DD.tmp (3 bytes)
    %Program Files%\AVAST Software\Avast\aswF14D.tmp (33 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\aswCmnOS.dll (131 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF58D.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\aswFDE.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\locales\sv.FF48.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\zh_CN\mesF49E.tmp (11 bytes)
    C:\Windows\avaFA30.tmp (43 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF259.tmp (260 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_ECD.tmp (8 bytes)
    C:\ProgramData\Google\Custom Buttons\toolbar.google.com_O8Y91YHB24Z6SR0SGYSK.XML (16 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\lv\mesF35F.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\ashF8B1.tmp (891 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\nonF01A.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\asw1002.tmp (167 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\temF1F4.tmp (20 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_elf.map (81 bytes)
    %Program Files%\AVAST Software\Avast\aswF068.tmp (78 bytes)
    %Program Files%\AVAST Software\Avast\snxF11A.tmp (336 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x86\AvaFB08.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_F0E.tmp (73 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFF0.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ja\mesF43C.tmp (14 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF008.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_EE7.tmp (59 bytes)
    %Program Files%\AVAST Software\Avast\avaF985.tmp (76 bytes)
    %Program Files%\AVAST Software\Avast\libFC4E.tmp (5879 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_E35.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\AvSF849.tmp (69 bytes)
    %Program Files%\AVAST Software\Avast\locales\gu.FEE1.tmp (26 bytes)
    %Program Files%\AVAST Software\Avast\locales\ar.FE91.tmp (21 bytes)
    %Program Files%\AVAST Software\Avast\OpenVPN\driver\win64\ndis6\delF105.tmp (154 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\sitecorrect\sitF730.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\locales\zh-FF6F.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\Certificates (4 bytes)
    %Program Files%\AVAST Software\Avast\locales\et.FECC.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\flaF4E0.tmp (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\aswOfferTool.exe (291 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\settings\setF6FA.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\mocks\ga.F4B0.tmp (439 bytes)
    %Program Files%\AVAST Software\Avast\flash\ammap\icons\pinF9E1.tmp (382 bytes)
    %Program Files%\AVAST Software\Avast\aswF971.tmp (406 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_F40.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_cmp_bpc-7e5.vpx (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_crt_x86-7e3.vpx.dld (108256 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\es\mesF411.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\queF1E4.tmp (31 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\id\mesF43A.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\License\EULFF94.tmp (15 bytes)
    %Program Files%\AVAST Software\Avast\setup\config.def (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\winbar\tesF743.tmp (11 bytes)
    %Program Files%\AVAST Software\Avast\OpenVPN\driver\win64\ndis6\aswF104.tmp (44 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF20C.tmp (463 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\bg\mesF2EB.tmp (14 bytes)
    C:\ProgramData\AVAST Software\Avast\Fonts\OpeFA08.tmp (217 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ru\mesF465.tmp (16 bytes)
    %Program Files%\AVAST Software\Avast\locales\th.FF5B.tmp (27 bytes)
    %Program Files%\AVAST Software\Avast\1033\aswF7EE.tmp (101 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\gadEFD4.tmp (11 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\ialF1E2.tmp (38 bytes)
    C:\Windows\System32\asw62C.tmp (2105 bytes)
    %Program Files%\AVAST Software\Avast\sslFF82.tmp (294 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_EFC.tmp (1 bytes)
    C:\ProgramData\AVAST Software\Avast\Fonts\OpeFA06.tmp (212 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData (676 bytes)
    %Program Files% (x86)\Google\Google Toolbar\GoogleToolbarUser_64.exe (401 bytes)
    %Program Files%\AVAST Software\Avast\ashFFA6.tmp (722 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x64\AvaFA44.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\settings\optF6E9.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_elfa.map (28 bytes)
    %Program Files%\AVAST Software\Avast\AavFF95.tmp (319 bytes)
    %Program Files%\AVAST Software\Avast\schF9F4.tmp (90 bytes)
    %Program Files%\AVAST Software\Avast\aswFFED.tmp (600 bytes)
    %Program Files%\AVAST Software\Avast\AhR43.tmp (93 bytes)
    %Program Files%\AVAST Software\Avast\asw8A.tmp (171 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\da\mesF2FF.tmp (11 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_ECF.tmp (28 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF031.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\setup\insEEC2.tmp (4185 bytes)
    %Program Files%\AVAST Software\Avast\locales\bg.FE92.tmp (23 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF51E.tmp (666 bytes)
    C:\ProgramData\AVAST Software\Avast\sounds\1033\welF816.tmp (20 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\jquF6A9.tmp (15 bytes)
    %Program Files%\AVAST Software\Avast\ashF8C2.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F62F.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_EE4.tmp (120 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFEC.tmp (1 bytes)
    C:\Users\Public\Desktop\Avast Free Antivirus.lnk (1 bytes)
    %Program Files%\AVAST Software\Avast\aswF079.tmp (392 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFD7.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_ECA.tmp (361 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF644.tmp (909 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\oveF3B4.tmp (23 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\algEA7.tmp (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_cmp_secureline-7ce.vpx.dld (18351 bytes)
    %Program Files%\AVAST Software\Avast\flash\ammap\empF9CC.tmp (11 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\sasF286.tmp (307 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x64\atlFA56.tmp (192 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF21D.tmp (343 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_swf.map (29 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\el\mesF40E.tmp (16 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\bn\mesF2EC.tmp (19 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\asw1000.tmp (457 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_cmp_secureline_x64-7cf.vpx (300 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\unsF01C.tmp (5 bytes)
    %Program Files%\AVAST Software\Avast\locales\ca.FEA4.tmp (15 bytes)
    %Program Files%\AVAST Software\Avast\Certificates\digF86D.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\aswF984.tmp (103 bytes)
    %Program Files%\AVAST Software\Avast\setup\part-prg_ais-8aa.vpx (11 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\sitecorrect\sitF731.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2C3.tmp (559 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF20D.tmp (470 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF232.tmp (2 bytes)
    C:\ProgramData\AVAST Software\Avast\sounds\thrFA1E.tmp (21 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\mocks\omnF1CD.tmp (770 bytes)
    %Program Files%\AVAST Software\Avast\AvaF067.tmp (143 bytes)
    %Program Files%\AVAST Software\Avast\locales\mr.FF0D.tmp (26 bytes)
    %Program Files%\AVAST Software\Avast\AhR87.tmp (72 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\credentials\creF4C9.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF671.tmp (653 bytes)
    %Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFFEB.tmp (272 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\shoF6FF.tmp (535 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5B9.tmp (470 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF58A.tmp (264 bytes)
    %Program Files%\AVAST Software\Avast\locales\fi.FECE.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_res-7f5.vpx (392 bytes)
    %Program Files%\AVAST Software\Avast\setup\servers.def.vpx (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\asw1001.tmp (408 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF58F.tmp (287 bytes)
    %Program Files%\AVAST Software\Avast\aswF93B.tmp (64 bytes)
    %Program Files%\AVAST Software\Avast\avaF986.tmp (428 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\it\mesF34C.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\aswF917.tmp (356 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF005.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F2AB.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_str.map (8 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\uk\mesF39D.tmp (16 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_gen_streamfilter-7f5.vpx (679 bytes)
    %Program Files%\AVAST Software\Avast\aswF77A.tmp (662 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs\q.jF1B9.tmp (58 bytes)
    %Program Files%\AVAST Software\Avast\aswF12D.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\setup\part-jrog2-d50.vpx (903 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\HTMLayout.dll (291 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF234.tmp (1 bytes)
    C:\Windows\winsxs\Manifests (4963 bytes)
    %Program Files%\AVAST Software\Avast\aswF.tmp (608 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_gen_openssl-7d4.vpx (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_sl.map (2 bytes)
    %Program Files%\AVAST Software\Avast\setup\prod-vps.vpx (450 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF004.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\zh_CN\mesF3A0.tmp (11 bytes)
    C:\ProgramData\AVAST Software\Avast\sounds\1033\pupF811.tmp (54 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_ECB.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\fa\mesF413.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\optF1E3.tmp (4 bytes)
    C:\Windows\System32\drivers\aswRvrt.sys (601 bytes)
    %Program Files% (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (311 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\cs\mesF2FE.tmp (12 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\secF01B.tmp (6 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF670.tmp (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GoogleToolbarInstaller1.log (8 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\safeshop\avaF6BF.tmp (256 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\15.EF94.tmp (2 bytes)
    C:\ProgramData\AVAST Software\Avast\sounds\scaFA1D.tmp (24 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\shoF700.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\1033\BooF7EC.tmp (24 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF574.tmp (646 bytes)
    %Program Files%\AVAST Software\Avast\aswF906.tmp (941 bytes)
    %Program Files%\AVAST Software\Avast\locales\cs.FEA5.tmp (14 bytes)
    C:\Windows\winsxs\Manifests\amd64_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_6aa8346920c8423b.manifest (612 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\aswFEF.tmp (624 bytes)
    %Program Files%\AVAST Software\Avast\AvaFB6D.tmp (392 bytes)
    %Program Files%\AVAST Software\Avast\locales\ru.FF24.tmp (21 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_tools_x64-7e2.vpx.dld (15807 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_mx4.map (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_cmp_secureline_x64-7cf.vpx.dld (3117 bytes)
    %Program Files%\AVAST Software\Avast\1033\aswF7ED.tmp (678 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\app745D.tmp (3073 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x86\AvaFB07.tmp (9 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\mocks\ga.F1CB.tmp (439 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F632.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFF93.tmp (93 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\avaF1CE.tmp (684 bytes)
    %Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFFD9.tmp (65 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\logF26F.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_cmp_rescuedisk-7f5.vpx (965 bytes)
    %Program Files%\AVAST Software\Avast\locales\sw.FF49.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\CrtCheck32.dll (57 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ms\mesF44E.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_dyna.map (272 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF58C.tmp (4 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF019.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF65C.tmp (556 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\chrF190.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F299.tmp (566 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\aswFCB.tmp (446 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5A1.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\aswF972.tmp (47 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\be\mesF3C9.tmp (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_gui-7d5.vpx.dld (98753 bytes)
    C:\Windows\winsxs\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.manifest (608 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\css\setF1F6.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\aswF939.tmp (648 bytes)
    %Program Files%\AVAST Software\Avast\pdfFF71.tmp (16 bytes)
    C:\ProgramData\AVAST Software\Avast\avast5.ini (4678 bytes)
    %Program Files%\AVAST Software\Avast\1033\BCUF827.tmp (27 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\css\extF1F5.tmp (60 bytes)
    %Program Files%\AVAST Software\Avast\locales\de.FEB6.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\sasF61C.tmp (836 bytes)
    %Program Files%\AVAST Software\Avast\locales\ko.FEF9.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\cerEC9.tmp (237 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_EDF.tmp (5 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\quiF6BE.tmp (110 bytes)
    %Program Files%\AVAST Software\Avast\locales\sk.FF25.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\tr\mesF38C.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF508.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF257.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_dll_eng-7f5.vpx (794 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\sasF285.tmp (580 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF21F.tmp (744 bytes)
    C:\Windows\System32\drivers\aswVmm.sys (1425 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF66C.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_EE6.tmp (9 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\asw10D9.tmp (551 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF4F4.tmp (665 bytes)
    %Program Files%\AVAST Software\Avast\dbgF987.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\be\mesF2EA.tmp (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_FB6BD2AF592BD59C48D4520A31AC1EA3 (4 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\14.EF93.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_gen_crt_x64-7e4.vpx (392 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\ext1033.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\asw9B.tmp (198 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\avaF1CF.tmp (74 bytes)
    %Program Files%\AVAST Software\Avast\AhA76.tmp (169 bytes)
    %Program Files%\AVAST Software\Avast\locales\nl.FF1F.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\uie1067.tmp (59 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\10.EF7F.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF575.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5A0.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF256.tmp (2 bytes)
    C:\Windows\winsxs\Manifests\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.cat (9 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\ArPFA8.tmp (52 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\9.gEFBE.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\locales\uk.FF5D.tmp (22 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x86\mfcFB0C.tmp (392 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\sl\mesF388.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x64\PolFA55.tmp (612 bytes)
    %Program Files%\AVAST Software\Avast\Set31.tmp (674 bytes)
    %Program Files%\AVAST Software\Avast\aswF94E.tmp (335 bytes)
    %Program Files%\AVAST Software\Avast\setup\HTMEEC3.tmp (22575 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\logF5F1.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\ash88.tmp (382 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF231.tmp (733 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\algo.dll (146 bytes)
    %Program Files%\AVAST Software\Avast\locales\te.FF5A.tmp (30 bytes)
    %Program Files%\AVAST Software\Avast\setup\ngiodriver_x64_ais-8aa.vpx (17 bytes)
    %Program Files%\AVAST Software\Avast\locales\es.FECB.tmp (15 bytes)
    %Program Files%\AVAST Software\Avast\1033\BasF7EB.tmp (63 bytes)
    C:\$ConvertToNonresident (16 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\sr\mesF477.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\pt_BR\mesF452.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\flash\amlF9B8.tmp (54 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\app745E.tmp (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\vps_32-1000.vpx.dld (9387949 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\config.def.new (196 bytes)
    %Program Files%\AVAST Software\Avast\flash\ammap\ammF9B9.tmp (51 bytes)
    %Program Files%\AVAST Software\Avast\1033\aswF800.tmp (442 bytes)
    %Program Files%\AVAST Software\Avast\locales\id.FEF5.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\aswF929.tmp (127 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_java.map (976 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\attEFBF.tmp (6 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ru\mesF377.tmp (16 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\xinF697.tmp (3 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_EE8.tmp (238 bytes)
    %Program Files%\AVAST Software\Avast\locales\tr.FF5C.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\safeshop\safF6D2.tmp (354 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_tools-7e2.vpx.dld (21843 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\winbar\winF747.tmp (45 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F29A.tmp (619 bytes)
    %Program Files%\AVAST Software\Avast\locales\pt-FF21.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\et\mesF315.tmp (11 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\8.gEFAE.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\flash\ammap\maps\worF9E3.tmp (127 bytes)
    %Program Files%\AVAST Software\Avast\ashF8F4.tmp (269 bytes)
    %Program Files%\AVAST Software\Avast\locales\lt.FEFA.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\sk\mesF378.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\alg1069.tmp (3 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_dex.map (1 bytes)
    %Program Files%\AVAST Software\Avast\aswF94D.tmp (281 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_EFB.tmp (79 bytes)
    %Program Files%\AVAST Software\Avast\setup\part-iex-4.vpx (232 bytes)
    C:\ProgramData\AVAST Software\Avast\Fonts\OpeF9F5.tmp (224 bytes)
    %Program Files%\AVAST Software\Avast\locales\fa.FECD.tmp (19 bytes)
    %Program Files%\AVAST Software\Avast\locales\sl.FF46.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\setup\SnxF119.tmp (59 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\safezone\safF6D4.tmp (948 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_cmp_bpc-7e5.vpx.dld (52103 bytes)
    C:\Windows\Prefetch\GOOGLEUPDATE.EXE-648FB068.pf (49 bytes)
    %Program Files%\AVAST Software\Avast\aswF759.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\ash89.tmp (126 bytes)
    %Program Files%\AVAST Software\Avast\setup\avBEEF5.tmp (11518 bytes)
    %Program Files%\AVAST Software\Avast\locales\filFECF.tmp (15 bytes)
    %Program Files%\AVAST Software\Avast\aswF748.tmp (565 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\defEC8.tmp (7 bytes)
    %Program Files%\AVAST Software\Avast\aswF960.tmp (47 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x64\mfcFA57.tmp (392 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\gooF4F1.tmp (3 bytes)
    %Program Files%\AVAST Software\Avast\setup\jrog2-d50.vpx (3 bytes)
    %Program Files%\AVAST Software\Avast\flash\ammap\icons\arrF9CD.tmp (76 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x86\PolFB09.tmp (9 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\pt_PT\mesF375.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\Sf21045.tmp (803 bytes)
    %Program Files%\AVAST Software\Avast\AavF828.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icoF26C.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\Sf.F87.tmp (532 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\hu\mesF429.tmp (13 bytes)
    C:\ProgramData\AVAST Software\Avast\sounds\1033\thrF814.tmp (31 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\winF02F.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\aswF93A.tmp (123 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\aswCmnBS.dll (446 bytes)
    %Program Files%\AVAST Software\Avast\aswFFEC.tmp (78 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_openssl-7d4.vpx.dld (32164 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\sasF284.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\sasF619.tmp (580 bytes)
    %Program Files%\AVAST Software\Avast\JsoF89F.tmp (81 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFED.tmp (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_x64-7f5.vpx.dld (108247 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icoF26B.tmp (989 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ro\mesF464.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\OpenVPN\driver\win64\ndis6\tapF106.tmp (88 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\tumF684.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\imgF5EF.tmp (17 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF21E.tmp (674 bytes)
    C:\Windows\winsxs\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396\msvcr110.dll (849 bytes)
    %Program Files%\AVAST Software\Avast\flash\ammap\icons\flaF9E0.tmp (378 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF235.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF577.tmp (5 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF233.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\locales\hr.FEE4.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\Chrome\AswF14E.tmp (642 bytes)
    %Program Files%\AVAST Software\Avast\setup\prod-ais.vpx (356 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\logF5F3.tmp (1 bytes)
    C:\Windows\System32\wdi (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\nl\mesF362.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\Setup\Stats.ini (1241 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\winbar\winF745.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\flash\ammap\ammF9CB.tmp (5 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\vklF696.tmp (3 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\indF064.tmp (3 bytes)
    C:\Windows\Installer\381d.msi (28 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\safezone\safF6E5.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\winbar\tesF744.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_EE2.tmp (16 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\optF3B3.tmp (422 bytes)
    %Program Files%\AVAST Software\Avast\setup\vps_win32-100f.vpx (1944 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\oveF3B5.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\avaF208.tmp (3 bytes)
    C:\Windows\winsxs\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.cat (9 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_cmp_secureline-7ce.vpx (771 bytes)
    %Program Files%\AVAST Software\Avast\ashF8F5.tmp (186 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoF002.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\locales\es-FECA.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_F10.tmp (788 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\tr\mesF47A.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_EFA.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\lv\mesF43E.tmp (12 bytes)
    C:\Windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d} (4 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_CCB.tmp (986 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_F84.tmp (23 bytes)
    %Program Files%\AVAST Software\Avast\1033\uiLF801.tmp (294 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\arrF1F7.tmp (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_FB6BD2AF592BD59C48D4520A31AC1EA3 (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\jrog2-d50.vpx.dld (104385 bytes)
    %Program Files%\AVAST Software\Avast\CrtFA42.tmp (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ar\mesF2E9.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\snxF107.tmp (277 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5A2.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F2AE.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFFC9.tmp (89 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\aswFCC.tmp (434 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF509.tmp (463 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\hovF2D9.tmp (802 bytes)
    %Program Files%\AVAST Software\Avast\ComF86E.tmp (575 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFEB.tmp (1 bytes)
    C:\Windows\winsxs\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396\msvcp110.dll (661 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\nb\mesF361.tmp (11 bytes)
    %Program Files%\AVAST Software\Avast\aswEF47.tmp (71 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF230.tmp (787 bytes)
    %Program Files%\AVAST Software\Avast\OpenVPN\opeF0E0.tmp (622 bytes)
    %Program Files%\AVAST Software\Avast\aswFFB6.tmp (375 bytes)
    %Program Files%\AVAST Software\Avast\locales\ro.FF23.tmp (15 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_EE5.tmp (524 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\~tmp_aswInstUpHttpGet (210 bytes)
    %Program Files%\AVAST Software\Avast\RegFFFF.tmp (577 bytes)
    C:\ProgramData\AVAST Software\Avast\snxF108.tmp (15 bytes)
    C:\Windows\System32\drivers\aswMonFlt.sys (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_gui_cef-7ce.vpx.dld (1618398 bytes)
    %Program Files%\AVAST Software\Avast\setup\part-setup_ais-8aa.vpx (601 bytes)
    %Program Files%\AVAST Software\Avast\1033\aswF7FF.tmp (629 bytes)
    C:\Windows\System32\drivers\aswRdr2.sys (601 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\et\mesF412.tmp (11 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs\lodF1B7.tmp (223 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\mocks\mapF4B2.tmp (605 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF258.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_mx95.map (9 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\gpbF1E1.tmp (23 bytes)
    C:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\msvcr110.dll (1751 bytes)
    %Program Files%\AVAST Software\Avast\locales\he.FEE2.tmp (16 bytes)
    %Program Files%\AVAST Software\Avast\flash\ammap\icons\croF9CF.tmp (234 bytes)
    C:\ProgramData\AVAST Software\Avast\HtmlData\ima9D.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\cefFBDD.tmp (427 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\aswFBB.tmp (508 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_F41.tmp (7 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5A3.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\extF2D8.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\locales\ja.FEF7.tmp (16 bytes)
    C:\Windows\winsxs\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.manifest (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_F42.tmp (149 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_C9B.tmp (392 bytes)
    C:\Users\"%CurrentUserName%"\Desktop (4 bytes)
    %Program Files%\AVAST Software\Avast\aswF94C.tmp (81 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\17.EF96.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\fr\mesF425.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F2AD.tmp (481 bytes)
    C:\Windows\winsxs\Manifests\amd64_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_6aa8346920c8423b.cat (9 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs\jquF1B6.tmp (15 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\id\mesF34B.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\cleF4C7.tmp (37 bytes)
    %Program Files%\AVAST Software\Avast\ashF8E3.tmp (392 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\sl\mesF476.tmp (12 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\16.EF95.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\th\mesF38B.tmp (19 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\nb\mesF44F.tmp (11 bytes)
    %Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFFC8.tmp (29 bytes)
    %Program Files%\AVAST Software\Avast\setup\InsEEC1.tmp (66235 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\aswEngin.dll (49 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\butEFC2.tmp (1 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\5.gEFAB.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\setup\vps_win64-ca0.vpx (392 bytes)
    %Program Files%\AVAST Software\Avast\Certificates\ARAEF25.tmp (8 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\mocks\gptF4B1.tmp (439 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_ECC.tmp (6 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\logF603.tmp (3 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\gadEFD5.tmp (16 bytes)
    %Program Files%\AVAST Software\Avast\aswF961.tmp (544 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs\proF1B8.tmp (60 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\tweF685.tmp (3 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\ReqF1A1.tmp (3 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\skin\oveF3B7.tmp (3 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\creF4CA.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF51B.tmp (875 bytes)
    %Program Files%\AVAST Software\Avast\Certificates\avaF86B.tmp (1 bytes)
    C:\ProgramData\AVAST Software\Avast\sounds\1033\susF813.tmp (45 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\utiF066.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\uk\mesF49B.tmp (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_core-7f5.vpx.dld (440486 bytes)
    %Program Files%\AVAST Software\Avast\aswF779.tmp (72 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_E46.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\asw10C8.tmp (488 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF25A.tmp (259 bytes)
    %Program Files%\AVAST Software\Avast\OpenVPN\driver\win64\ndis6\addF0F2.tmp (126 bytes)
    %Program Files%\AVAST Software\Avast\locales\am.FE90.tmp (19 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF564.tmp (367 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_E97.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF58B.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\fi\mesF326.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\phishing\phiF6BC.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\fwA1043.tmp (44 bytes)
    %Program Files%\AVAST Software\Avast\setup\setup.ini.tmp (9 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5B8.tmp (260 bytes)
    %Program Files%\AVAST Software\Avast\flash\amcF9B7.tmp (32 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\logF606.tmp (974 bytes)
    %Program Files%\AVAST Software\Avast\flash\ammap\icons\bubF9CE.tmp (217 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\se_F634.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_C89.tmp (21 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\cs\mesF3EC.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\BroEF6A.tmp (42 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ko\mesF34E.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\shoF720.tmp (322 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x86\msvFB6C.tmp (875 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\balF4B4.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2D5.tmp (557 bytes)
    %Program Files%\AVAST Software\Avast\logF9F3.tmp (104 bytes)
    %Program Files%\AVAST Software\Avast\Reg21.tmp (716 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_F20.tmp (392 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF550.tmp (726 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\abeF1A2.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\locales\it.FEF6.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\aswEF26.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_gen_gui-7d5.vpx (392 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF51C.tmp (144 bytes)
    %Program Files%\AVAST Software\Avast\locales\ml.FF0C.tmp (34 bytes)
    %Program Files%\AVAST Software\Avast\icuFBEF.tmp (780 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_cmp_swhealth-7f5.vpx.dld (24476 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x86\atlFB0B.tmp (164 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\blocker\bloF4C6.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\es\mesF314.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFFB7.tmp (364 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5CB.tmp (436 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF657.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\modules\UtiF3B2.tmp (8 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\pt_PT\mesF463.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\en_GB\mesF313.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_gen_crt_x86-7e3.vpx (392 bytes)
    %Program Files%\AVAST Software\Avast\locales\sr.FF47.tmp (21 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_EE1.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5B6.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\safeshop\cslF6C0.tmp (202 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\13.EF92.tmp (2 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameEF6E.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\hi\mesF427.tmp (18 bytes)
    %Program Files%\AVAST Software\Avast\setup\iplugins-4.vpx (28 bytes)
    C:\ProgramData\AVAST Software\Avast\HtmlData\Blo9C.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\flash\ammap\icons\zooF9E2.tmp (198 bytes)
    C:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\msvcp110.dll (1071 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2D6.tmp (679 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\2.gEF98.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icoF5CF.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\traF683.tmp (162 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFEE.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\vi\mesF49D.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\setup\setFA20.tmp (5 bytes)
    %Program Files%\AVAST Software\Avast\AvaF85B.tmp (343 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ja\mesF34D.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_F0D.tmp (221 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\logF5F2.tmp (801 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5CA.tmp (259 bytes)
    %Program Files%\AVAST Software\Avast\asO44.tmp (415 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFDA.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\aswFA9.tmp (221 bytes)
    %Program Files%\AVAST Software\Avast\setup\selfdefense_x86_ais-8aa.vpx (2321 bytes)
    %Program Files%\AVAST Software\Avast\locales\vi.FF6E.tmp (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_streamfilter_x64-7f5.vpx.dld (3610 bytes)
    %Program Files%\AVAST Software\Avast\OpenVPN\lzoF0DF.tmp (83 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\shoF6FD.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x86\msvFB5B.tmp (535 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_cmp_swhealth-7f5.vpx (1 bytes)
    %Program Files%\AVAST Software\Avast\setup\avbugreport_ais-8aa.vpx (11518 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\11.EF80.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_EE9.tmp (995 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\bs.F1A3.tmp (11 bytes)
    %Program Files%\AVAST Software\Avast\locales\pt-FF22.tmp (14 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFDB.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\setup\vps_32-1000.vpx (11077 bytes)
    %Program Files%\AVAST Software\Avast\setup\Inf\x64\aswFFFE.tmp (137 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F2BF.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\safeshop\safF6D1.tmp (15 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_E56.tmp (392 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF5B5.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\phishing\phiF6BD.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\aswScan.dll (167 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF20A.tmp (227 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\sv\mesF38A.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\OpenVPN\libF0DE.tmp (65 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\safeshop\safF6D3.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\hu\mesF32B.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF65B.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF246.tmp (287 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\lodF6AA.tmp (223 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\extF4CB.tmp (59 bytes)
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software\Avast Free Antivirus.lnk (1 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_gen_streamfilter_x64-7f5.vpx (137 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\sasF298.tmp (836 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_CCA.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\ashF8E2.tmp (645 bytes)
    C:\ProgramData\AVAST Software\Avast\SecureLine\secF0F1.tmp (10 bytes)
    C:\Windows\SoftwareDistribution\DataStore\Logs (4 bytes)
    C:\ProgramData\AVAST Software\Avast\sounds\virFA1F.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2D7.tmp (653 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\1.gEF7E.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\temF732.tmp (18 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\logF604.tmp (7 bytes)
    C:\ProgramData\AVAST Software\Avast\Fonts\RobFA09.tmp (141 bytes)
    C:\Windows\winsxs\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396\mfc110u.dll (920 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2D4.tmp (556 bytes)
    C:\Windows\System32\config\SYSTEM.LOG1 (18577 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\fa\mesF316.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\setup\setgui_ais-8aa.vpx (22575 bytes)
    %Program Files%\AVAST Software\Avast\setup\offertool_ais-8aa.vpx (23811 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 (4 bytes)
    C:\Windows\winsxs\Manifests\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.manifest (2 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\butEFC3.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\Pus1044.tmp (664 bytes)
    %Program Files%\AVAST Software\Avast\locales\ms.FF0E.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF659.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\mesF3A2.tmp (2 bytes)
    C:\Windows\Prefetch\REGSVR32.EXE-55A4EE79.pf (28 bytes)
    %Program Files%\AVAST Software\Avast\setup\instup_ais-8aa.vpx (66235 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\ar\mesF3C8.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\avH20.tmp (409 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x64\msvFAE6.tmp (849 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF51D.tmp (182 bytes)
    %Program Files%\AVAST Software\Avast\setup\selfdefense_x64_ais-8aa.vpx (2321 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\Instup.dll (1746 bytes)
    %Program Files%\AVAST Software\Avast\asuF12C.tmp (88 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2C0.tmp (909 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\logF281.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\CrtFAF6.tmp (54 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_C87.tmp (19 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\en\mesF302.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\logF26E.tmp (5 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\logF270.tmp (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (4 bytes)
    %Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\gth.dll (40 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2C1.tmp (812 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\logF283.tmp (503 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\Chrome\AswF18D.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x86\PolFB0A.tmp (608 bytes)
    C:\ProgramData\AVAST Software\Avast\sounds\1033\virF815.tmp (40 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\7.gEFAD.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icoF5CD.tmp (12 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFF1.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\flash\ammap\ammF9CA.tmp (3 bytes)
    C:\Windows\System32\drivers\aswSP.sys (2321 bytes)
    %Program Files%\AVAST Software\Avast\locales\fr.FEE0.tmp (15 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\lisF86.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\pl\mesF451.tmp (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_dll_eng-7f5.vpx.dld (25252 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\sr\mesF389.tmp (12 bytes)
    %Program Files% (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (258 bytes)
    %Program Files%\AVAST Software\Avast\RescueDisk\AvaF0A8.tmp (478 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\insF5F0.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\aswCmnIS.dll (438 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\shoF6FC.tmp (322 bytes)
    %Program Files%\AVAST Software\Avast\setup\CRT\x64\msvFAE5.tmp (661 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF506.tmp (358 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF578.tmp (5 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\scripts\balF1D0.tmp (94 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\gadEF6D.tmp (886 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\hi\mesF329.tmp (18 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\lis1068.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\en_GB\mesF410.tmp (11 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\BCU1013.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\RescueDisk\waiF0DD.tmp (3 bytes)
    C:\ProgramData\AVAST Software\Avast\avaFA1B.tmp (5 bytes)
    %Program Files%\AVAST Software\Avast\locales\ta.FF59.tmp (32 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF682.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\logF605.tmp (503 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\insF3B6.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\Certificates\digF86C.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\RescueDisk\BasF0B9.tmp (63 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_F53.tmp (1 bytes)
    C:\Windows\AppCompat\Programs\RecentFileCache.bcf (200 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\4.gEFAA.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\pl\mesF363.tmp (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_gen_streamfilter-7f5.vpx.dld (11832 bytes)
    %Program Files%\AVAST Software\Avast\locales\zh-FF70.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF507.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\setup\ais_gen_tools-7e2.vpx (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\shoF6FB.tmp (318 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\logF282.tmp (801 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_bhv.map (424 bytes)
    %Program Files%\AVAST Software\Avast\ash65.tmp (441 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\greF4F2.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\icnF20B.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\th\mesF479.tmp (19 bytes)
    %Program Files% (x86)\Google\GoogleToolbarNotifier\5.10.11023.1534\Readme.url (4 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF552.tmp (646 bytes)
    C:\Windows\System32\drivers\aswSnx.sys (7385 bytes)
    %Program Files%\AVAST Software\Avast\aswF7D9.tmp (85 bytes)
    %Program Files%\AVAST Software\Avast\cefFBCC.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF4F3.tmp (357 bytes)
    %Program Files%\AVAST Software\Avast\locales\da.FEB5.tmp (13 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\el\mesF301.tmp (16 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\Chrome\AswF18E.tmp (295 bytes)
    %Program Files%\AVAST Software\Avast\locales\hi.FEE3.tmp (26 bytes)
    %Program Files% (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (196 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\jquF698.tmp (93 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\ro\mesF376.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\avBEF05.tmp (11518 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_EE0.tmp (5 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\logF271.tmp (7 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_F54.tmp (392 bytes)
    %Program Files%\AVAST Software\Avast\aswF918.tmp (311 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\12.EF81.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\mocks\omnF4B3.tmp (770 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\avaEF6B.tmp (7 bytes)
    %Program Files%\AVAST Software\Avast\libFF72.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF645.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\locales\pl.FF20.tmp (14 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\6.gEFAC.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\sasF61A.tmp (307 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\seaF6E7.tmp (341 bytes)
    %Program Files%\AVAST Software\Avast\aswF973.tmp (22 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\se_F2BE.tmp (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\vps_win32-100f.vpx.dld (257579 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_F0F.tmp (20 bytes)
    %Program Files%\AVAST Software\Avast\AhR42.tmp (118 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs\eveF1A5.tmp (16 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\locale\hr\mesF32A.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\icnF51A.tmp (470 bytes)
    %Program Files%\AVAST Software\Avast\locales\en-FEB9.tmp (12 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\icoEFEF.tmp (1 bytes)
    %Program Files%\AVAST Software\Avast\RescueDisk\aswF0BB.tmp (76 bytes)
    %Program Files%\AVAST Software\Avast\setup\ngiodriver_x86_ais-8aa.vpx (17 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF658.tmp (862 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\bg\mesF3CA.tmp (14 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\safeshop\safF6D0.tmp (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ais_res-7f5.vpx.dld (71340 bytes)
    %Program Files%\AVAST Software\Avast\BCUEF49.tmp (643 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\swiF65A.tmp (559 bytes)
    C:\ProgramData\AVAST Software\Avast\Fonts\RobFA0A.tmp (140 bytes)
    C:\Windows\System32\drivers\aswStm.sys (673 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\libs\cslF1A4.tmp (202 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\images\ameba\18.EF97.tmp (2 bytes)
    %Program Files%\AVAST Software\Avast\aswF916.tmp (81 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\db_C76.tmp (233 bytes)
    %Program Files%\AVAST Software\Avast\cefFBDE.tmp (580 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\templates\img\avaF4DE.tmp (4 bytes)
    %Program Files%\AVAST Software\Avast\AavF838.tmp (291 bytes)
    %Program Files%\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\indF065.tmp (25 bytes)
    C:\Windows\winsxs\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.cat (9 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\IE\_locales\nl\mesF450.tmp (12 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\swiF2C2.tmp (862 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301\Sf1F88.tmp (96 bytes)
    %Program Files%\AVAST Software\Avast\WebRep\FF\content\common\skin\img\imgF26D.tmp (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x64_ais-8a7-8a6.vpx.dld (257 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\servers.def.vpx.dld (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instcont_ais-8aa-8a7.vpx.dld (1921 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\selfdefense_x86_ais-8aa.vpx (427 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instcont_ais-8a7-8a6.vpx.dld (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x64_ais-8a0-89e.vpx.dld (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avbugreport_ais-8a7-8a6.vpx.dld (3949 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instcont_ais-8aa.vpx (598 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup_ais-8a7-8a6.vpx.dld (25237 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\setgui_ais-8a6-8a0.vpx.dld (17620 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x86_ais-8aa-8a7.vpx.dld (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instcont_ais-8a6-8a0.vpx.dld (9216 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\avBugReport.exe (11518 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avbugreport_ais-8aa.vpx (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup_ais-8aa.vpx (780 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\prod-ais.vpx.dld (356 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\setgui_ais-8aa.vpx (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\New\instup.exe (4787 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\setgui_ais-8a7-8a6.vpx.dld (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x64_ais-8aa-8a7.vpx.dld (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-vps_win32-15042301.vpx.dld (214 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\selfdefense_x64_ais-8aa.vpx.dld (13107 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\aswSetupConfig.ini (758 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avbugreport_ais-8a0-89e.vpx.dld (3918 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avbugreport_ais-8a6-8a0.vpx.dld (16591 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\prod-vps.vpx.dld (450 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\setgui_ais-8aa-8a7.vpx.dld (214 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\setgui_ais-8a0-89e.vpx.dld (6233 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x86_ais-8a7-8a6.vpx.dld (256 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x86_ais-8a6-8a0.vpx.dld (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x86_ais-8aa.vpx (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\offertool_ais-8aa.vpx (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\selfdefense_x86_ais-8aa.vpx.dld (11031 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup_ais-8a0-89e.vpx.dld (12133 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup_ais-8a6-8a0.vpx.dld (52071 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x64_ais-8a6-8a0.vpx.dld (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-jrog2-d50.vpx.dld (903 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instup_ais-8aa-8a7.vpx.dld (26477 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-iex-4.vpx.dld (232 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-setup_ais-8aa.vpx.dld (3166 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x64_ais-8aa.vpx (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\servers.def.lkg (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\part-prg_ais-8aa.vpx.dld (1344 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\instcont_ais-8a0-89e.vpx.dld (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\ngiodriver_x86_ais-8a0-89e.vpx.dld (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\offertool_ais-8aa.vpx.dld (55822 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_av_iup.tm~a00688\avbugreport_ais-8aa-8a7.vpx.dld (10493 bytes)
    %Program Files% (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (79 bytes)
    %Program Files%\Google\GoogleToolbarNotifier\5.10.11023.1534\swg64.dll (298 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000085.bin (320 bytes)
    C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\45781A86D7D79A4E3FE6F4DF8CDF171D_E0B7CDE0B6AB7ABECB214E5A7A028B64 (1520 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000006e.bin (228 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000030.bin (275 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000014.bin (342 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000004.bin (9 bytes)
    C:\ProgramData\AVAST Software\Avast\log\StreamFilter.log (4230 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000007d.bin (315 bytes)
    C:\ProgramData\AVAST Software\Avast\wscert.der (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000098.bin (551 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000031.bin (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000002f.bin (6 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000033.bin (177 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000050.bin (615 bytes)
    C:\ProgramData\AVAST Software\Avast\URL.db (528641 bytes)
    C:\ProgramData\AVAST Software\Avast\log\softwarehealth.log (57 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg15042302000000a0.bin (177 bytes)
    C:\ProgramData\AVAST Software\Avast\report\WebShield.txt (138 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000052.bin (167 bytes)
    C:\Windows\TEMP\_avast_\ws09CDCBC8.dat (944 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000088.bin (164 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000051.bin (4 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000007a.bin (177 bytes)
    C:\ProgramData\AVAST Software\Avast\log\Grimefighter.log (1382 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000008c.bin (4 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000005d.bin (183 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg15042302000000a3.bin (164 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000087.bin (2 bytes)
    C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\edebdb5e5c006a3a2136a47fd2342bbe_c0322acd-5e5d-42f0-b163-c591ee6ff5b9 (102 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000005.bin (843 bytes)
    C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A92F33496848CFF4F115ED04BCDD933A_6C14F82F698E40985D569864739DB21B (1 bytes)
    C:\ProgramData\AVAST Software\Avast\snx_lconfig.xml (4814 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000001e.bin (5 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000009f.bin (264 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000026.bin (9 bytes)
    C:\snx_rhive{316f7b84-deb2-11e4-b648-005056210174}.TM.blf (2654 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000039.bin (155 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000025.bin (294 bytes)
    C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bb87d795d8de56e15dd2d7704498f1b8_c0322acd-5e5d-42f0-b163-c591ee6ff5b9 (102 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000016.bin (209 bytes)
    C:\ProgramData\AVAST Software\Avast\report\FileSystemShield.txt (138 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000093.bin (4 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000000e.bin (183 bytes)
    C:\snx_rhive{316f7b84-deb2-11e4-b648-005056210174}.TMContainer00000000000000000002.regtrans-ms (712 bytes)
    C:\ProgramData\AVAST Software\Avast\log\Mail.log (4429 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000078.bin (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000044.bin (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000006.bin (459 bytes)
    C:\ProgramData\AVAST Software\Avast\log\AvastSvc.log (31420 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000068.bin (272 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000006c.bin (198 bytes)
    C:\ProgramData\AVAST Software\Avast\log\SecureLine.log (1070 bytes)
    C:\snx_rhive{316f7b84-deb2-11e4-b648-005056210174}.TMContainer00000000000000000001.regtrans-ms (1224 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000003d.bin (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000055.bin (3 bytes)
    C:\Windows\TEMP\_avast_\ws0A47E810.dat (1111 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000057.bin (186 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000073.bin (3 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000004c.bin (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000072.bin (183 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000079.bin (130 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000009a.bin (189 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000049.bin (448 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000036.bin (924 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000011.bin (283 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000005b.bin (859 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000083.bin (6 bytes)
    C:\ProgramData\AVAST Software\Avast\SecureLine\client.ovpn (187 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000006f.bin (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000002e.bin (243 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000037.bin (169 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000002d.bin (347 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000010.bin (7 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000099.bin (6 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000096.bin (130 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000021.bin (203 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000006.bin (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000038.bin (3 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000008f.bin (8 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000007f.bin (222 bytes)
    C:\ProgramData\AVAST Software\Avast\Log.db (233646 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000007c.bin (153 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000043.bin (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000013.bin (166 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000003.bin (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000004f.bin (168 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000070.bin (158 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000028.bin (9 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000022.bin (9 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000006a.bin (3 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000004e.bin (241 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000003e.bin (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000001c.bin (479 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000047.bin (286 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000005a.bin (3 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000000.bin (155 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000002b.bin (5 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000086.bin (293 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000089.bin (8 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000097.bin (804 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000008.bin (6 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg15042302000000a2.bin (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000058.bin (581 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000065.bin (188 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000009b.bin (179 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000032.bin (312 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000067.bin (3 bytes)
    C:\ProgramData\AVAST Software\Avast\log\StreamingUpdate.log (125 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000095.bin (217 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000001.bin (375 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000004d.bin (604 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000054.bin (303 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000008b.bin (8 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000066.bin (747 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000009.bin (184 bytes)
    C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\45781A86D7D79A4E3FE6F4DF8CDF171D_E0B7CDE0B6AB7ABECB214E5A7A028B64 (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000077.bin (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000041.bin (1 bytes)
    C:\ProgramData\AVAST Software\Avast\spool\suspic\{5A3F9B39-FD0E-4314-AA1E-7F3588216579}.suspic (5222 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000001d.bin (9 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000027.bin (9 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000000c.bin (4 bytes)
    C:\ProgramData\AVAST Software\Avast\FileInfo2.db (2788 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000008.bin (161 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000001a.bin (6 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000040.bin (5 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000000a.bin (240 bytes)
    C:\ProgramData\AVAST Software\Avast\journal\journal13B15994 (125988 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000042.bin (897 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000000b.bin (142 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000076.bin (332 bytes)
    C:\ProgramData\AVAST Software\Avast\chest\index.xml (116 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000060.bin (217 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000007.bin (225 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000012.bin (309 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000009d.bin (215 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000059.bin (199 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000084.bin (226 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000005f.bin (207 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000003b.bin (840 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000003.bin (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000075.bin (594 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000069.bin (710 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000009e.bin (4 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000009.bin (131 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000002a.bin (9 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000056.bin (190 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000004.bin (9 bytes)
    C:\ProgramData\AVAST Software\Avast\log\Resident.log (41 bytes)
    C:\ProgramData\AVAST Software\Avast\db_storage.dat (16 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000034.bin (5 bytes)
    C:\ProgramData\AVAST Software\Avast\report\EmailShield.txt (138 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000090.bin (8 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000005e.bin (3 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000007e.bin (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000003f.bin (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000024.bin (654 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000007.bin (141 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000017.bin (283 bytes)
    C:\Windows\TEMP\_avast_\ws09CDC998.dat (319 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000000d.bin (233 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000000f.bin (280 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000094.bin (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000006b.bin (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg15042302000000a4.bin (337 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000018.bin (181 bytes)
    C:\ProgramData\AVAST Software\Avast\log\EventLog.log (992 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000008e.bin (234 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg15042302000000a1.bin (131 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000004a.bin (135 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000009c.bin (130 bytes)
    C:\ProgramData\AVAST Software\Avast\log\autosandbox.log (1496 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000035.bin (198 bytes)
    C:\Windows\TEMP\_avast_\ws09CDCAB0.dat (556 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000001b.bin (157 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000063.bin (5 bytes)
    C:\ProgramData\AVAST Software\Avast\spool\suspic\{B93E86A2-4ED7-45BD-8692-45349ACB8CE1}.suspic (4170 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000007b.bin (6 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000001.bin (4 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000053.bin (226 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000004b.bin (381 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000002.bin (8 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000001f.bin (7 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000062.bin (273 bytes)
    C:\Windows\TEMP\GeoInfo.tmp (135 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000003a.bin (308 bytes)
    C:\ProgramData\AVAST Software\Avast\log\Chest.log (34 bytes)
    C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4de477a8df4f16d076ef8dbe12e0bb46_c0322acd-5e5d-42f0-b163-c591ee6ff5b9 (102 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000003c.bin (3 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000046.bin (199 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000080.bin (271 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000019.bin (290 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000061.bin (766 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000074.bin (157 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000082.bin (3 bytes)
    C:\snx_rhive.LOG1 (1048 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000023.bin (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000005c.bin (204 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000064.bin (225 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000002c.bin (1 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000081.bin (240 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042301_stream\pkg1504230100000005.bin (1 bytes)
    C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A92F33496848CFF4F115ED04BCDD933A_6C14F82F698E40985D569864739DB21B (1520 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000020.bin (412 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000048.bin (3 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000002.bin (7 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000071.bin (921 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000006d.bin (461 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000092.bin (8 bytes)
    C:\ProgramData\AVAST Software\Avast\exclusions.ini (210 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000008d.bin (148 bytes)
    %Program Files%\AVAST Software\Avast\Setup\config.def.new (100 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000045.bin (931 bytes)
    C:\ProgramData\AVAST Software\Avast\log\CommChannel.Protocol.log (2 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000029.bin (3 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg150423020000008a.bin (8 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000015.bin (5 bytes)
    %Program Files%\AVAST Software\Avast\defs\15042302_stream\pkg1504230200000091.bin (8 bytes)
    C:\ProgramData\AVAST Software\Avast\log\BugReport.log (2 bytes)
    C:\PROGRAM FILES (X86)\Java\jre6\lib\security\cacerts (445925 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn935F.tmp (43 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup___.exe (356166 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\NSISdl14.dll (44 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\ButtonEvent.dll (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx485A.tmp (43 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\modern-wizard.bmp (26 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MPBSETUP.EXE (5597 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\NSISdl.dll (2202 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\logo.bmp (1568 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\System.dll (47 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsh190D.tmp (43 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\mypcbackup_image.bmp (1568 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss1BBD.tmp (43 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsm1CD6.tmp (43 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\ThreadTimer.dll (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc189F.tmp\nsDialogs.dll (23 bytes)
    %Program Files% (x86)\OLBPre\es_ES.mo (1856 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\nsExec.dll (14 bytes)
    %Program Files% (x86)\OLBPre\pt_PT.mo (1856 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\Desktop\MyPC Backup.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\AccessControl.dll (20 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\nsSCM.dll (13 bytes)
    %Program Files% (x86)\OLBPre\it_IT.mo (1856 bytes)
    %Program Files% (x86)\OLBPre\de_DE.mo (1856 bytes)
    %Program Files% (x86)\OLBPre\fr_FR.mo (1856 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\nsRandom.dll (808 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn8382.tmp (52076 bytes)
    %Program Files% (x86)\OLBPre\OLBPre.exe.config (203 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc8392.tmp\DotNetChecker.dll (1597 bytes)
    %Program Files% (x86)\OLBPre\brand.jdat (17848 bytes)
    %Program Files% (x86)\OLBPre\uninst.exe (1026 bytes)
    %Program Files% (x86)\OLBPre\LinqBridge.dll (1856 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aeu64AC.tmp.dld (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aeu5DF7.tmp.dld (35 bytes)
    %Program Files%\AVAST Software\Avast\setup\45db3fb7-4838-48e8-8387-b5bc4e296450.xml (11 bytes)
    C:\ProgramData\AVAST Software\Avast\AvastEmUpdate.ini (34 bytes)
    %Program Files%\AVAST Software\Avast\setup\f250f4e7-9d83-458a-8282-b8a5853969a0.ini (4 bytes)
    %Program Files%\AVAST Software\Avast\setup\9fc49b8a-7b2d-463c-978b-474af67c44b7.exe (1255 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "AvastUI.exe" = "%Program Files%\AVAST Software\Avast\AvastUI.exe /nogui"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

Average: 5 (1 vote)

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now