Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

14.0.0.4592 3.87%
14.0.0.4330 0.89%
14.0.0.4253 1.49%
14.0.0.4158 6.85%
14.0.0.4134 2.38%
14.0.0.4114 1.49%
13.0.0.3463 1.49%
13.0.0.3420 1.49%
13.0.0.3401 3.27%
13.0.0.3382 1.49%
13.0.0.3333 11.01%
13.0.0.3267 4.17%
13.0.0.2883 44.05%
13.0.0.2792 14.88%
13.0.0.2740 0.30%
12.0.0.2213 0.30%
12.0.0.2190 0.30%
10.0.0.1365 0.30%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExA, OpenProcessToken, GetTokenInformation, AdjustTokenPrivileges, RegCloseKey, RegOpenKeyExA, LookupPrivilegeValueW, CreateProcessAsUserW, DuplicateTokenEx
avgntopensslx.dll
PKCS7_digest_from_attributes, ASN1_BIT_STRING_it, ASN1_INTEGER_free, EVP_VerifyFinal, ASN1_INTEGER_it, ASN1_BIT_STRING_free, EVP_DigestInit_ex, OBJ_find_sigid_algs, X509_NAME_free, X509_NAME_it, ASN1_INTEGER_get, BIO_s_mem, X509_digest, BIO_new, X509_get_serialNumber, BIO_printf, X509_NAME_print_ex, X509_PUBKEY_get, X509_PUBKEY_free, X509_PUBKEY_it, X509_ALGOR_it, X509_ALGOR_free, X509_SIG_it, ASN1_STRING_free, ASN1_STRING_type_new, OBJ_obj2nid, X509_get_issuer_name, sk_value, d2i_X509, sk_num, X509_free, X509_get_subject_name, PKCS7_get_attribute, ASN1_UTCTIME_free, PKCS7_free, X509_STORE_CTX_new, CONF_modules_unload, EVP_add_digest, BIO_free, X509_STORE_set_flags, EVP_sha1, X509_STORE_CTX_init, EVP_get_digestbyname, RSA_free, EVP_DigestInit, EVP_MD_CTX_init, EVP_PKEY_get1_RSA, PKCS7_ATTR_VERIFY_it, X509_NAME_cmp, EVP_DigestUpdate, EVP_DigestFinal, CRYPTO_set_mem_functions, ASN1_INTEGER_cmp, OPENSSL_add_all_algorithms_noconf, ASN1_item_d2i_bio, ASN1_item_i2d, BIO_new_mem_buf, EVP_sha256, RSA_size, PKCS7_SIGNER_INFO_it, CRYPTO_cleanup_all_ex_data, X509_ALGORS_it, PKCS7_get_signed_attribute, X509_STORE_free, ERR_free_strings, X509_SIG_free, X509_STORE_new, X509_it, X509_STORE_add_cert, CRYPTO_free, X509_STORE_CTX_set_time, EVP_MD_CTX_cleanup, PKCS7_SIGNER_INFO_free, ERR_remove_state, d2i_PKCS7_bio, X509_get_pubkey, X509_STORE_CTX_free, EVP_cleanup, EVP_PKEY_free, CRYPTO_malloc, EVP_md2, EVP_md5, OBJ_nid2sn, RSA_public_encrypt, sk_free, sk_push, X509_get_pubkey_parameters, sk_new_null, X509_verify, CRYPTO_add_lock, X509_cmp_time
avgsysx.dll
DllMain
comctl32.dll
_TrackMouseEvent, ImageList_Draw, ImageList_GetImageInfo, InitCommonControlsEx, ImageList_AddMasked, ImageList_Copy, ImageList_GetImageCount, ImageList_GetIcon, ImageList_ReplaceIcon
comdlg32.dll
GetSaveFileNameW, GetOpenFileNameW, CommDlgExtendedError
gdi32.dll
ExtTextOutW, DeleteDC, DPtoLP, GetStockObject, PtInRegion, BitBlt, CreateRoundRectRgn, StartDocW, AbortDoc, EndDoc, StartPage, EndPage, AddFontMemResourceEx, AddFontResourceExW, RemoveFontResourceExW, CreateEllipticRgnIndirect, GetBkColor, CreateEllipticRgn, OffsetRgn, ExtSelectClipRgn, CreateFontIndirectW, IntersectClipRect, SetTextJustification, SetBkMode, SetTextColor, MoveToEx, LineTo, TextOutW, GetDIBits, SetDIBits, GetClipRgn, SelectClipRgn, CreatePen, SetBkColor, GetTextExtentPoint32W, CreateDIBSection, SetPixel, GetTextMetricsW, CreateCompatibleBitmap, GetDeviceCaps, Ellipse, StretchBlt, SetDCPenColor, CreateFontW, GetClipBox, GetDCOrgEx, GetCurrentObject, DeleteObject, CreateRectRgn, SetBitmapBits, Rectangle, GetBitmapBits, GetObjectW, Polygon, CreateBitmap, CreateCompatibleDC, SelectObject, FrameRgn, ExcludeClipRect, CreateSolidBrush, Chord, GetPixel
gdiplus.dll
GdiplusShutdown, GdiplusStartup, GdipGetImageEncoders, GdipGetImageEncodersSize, GdipCreateBitmapFromHBITMAP, GdipCreateBitmapFromScan0, GdipSaveImageToStream, GdipCloneImage, GdipDisposeImage, GdipFree, GdipAlloc
kernel32.dll
WaitForMultipleObjects, CreateFileW, GetOverlappedResult, GetCurrentProcessId, SetUnhandledExceptionFilter, GetTempFileNameW, DeviceIoControl, CancelIo, FindVolumeClose, GetModuleHandleW, FindNextVolumeW, GetVolumePathNamesForVolumeNameW, FindFirstVolumeW, ExpandEnvironmentStringsW, WaitForMultipleObjectsEx, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, FindFirstFileW, FindNextFileW, FindClose, FileTimeToLocalFileTime, FileTimeToSystemTime, GetLocaleInfoW, GetDateFormatW, GetTimeFormatW, lstrlenW, SystemTimeToFileTime, LocalFileTimeToFileTime, GetVersion, GetDriveTypeW, GetVolumeInformationW, GetFileAttributesW, GetShortPathNameW, SetLastError, DeactivateActCtx, ActivateActCtx, GlobalFree, GetModuleFileNameW, GetLogicalDrives, FindFirstChangeNotificationW, FindNextChangeNotification, FindCloseChangeNotification, VirtualAlloc, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, VirtualFree, GetVersionExA, MultiByteToWideChar, FormatMessageW, FreeResource, IsProcessorFeaturePresent, EnterCriticalSection, LeaveCriticalSection, InterlockedExchange, ExpandEnvironmentStringsA, LoadLibraryA, InterlockedCompareExchange, HeapSetInformation, GetStartupInfoW, EncodePointer, DecodePointer, QueryPerformanceCounter, GetSystemTimeAsFileTime, CreateProcessW, GetTempPathW, GetCurrentThreadId, GetUserDefaultLangID, LocalFree, InterlockedDecrement, HeapFree, GetProcessHeap, HeapAlloc, VirtualAllocEx, GetProcAddress, lstrcpynW, ReadProcessMemory, LoadLibraryW, VirtualFreeEx, OpenProcess, GetTickCount, FreeLibrary, GetExitCodeThread, ReleaseMutex, SetProcessWorkingSetSize, GetCurrentProcess, GetLastError, CreateEventW, CloseHandle, SetEvent, SetThreadPriority, ResumeThread, WaitForSingleObject, Sleep, GetComputerNameW, MulDiv, CreateMutexW, GlobalAlloc, GlobalLock, GlobalUnlock, LCMapStringW, SetVolumeLabelW
mfc100u.dll
DllMain
mfc110u.dll
DllMain
mpr.dll
WNetCloseEnum, WNetEnumResourceW, WNetOpenEnumW, WNetGetUniversalNameW
msimg32.dll
TransparentBlt, AlphaBlend
msvcp100.dll
DllMain
msvcp110.dll
DllMain
msvcr100.dll
DllMain
msvcr110.dll
DllMain
ntdll.dll
RtlFreeUnicodeString, ZwSetEvent, ZwWaitForSingleObject, LdrLoadDll, ZwFsControlFile, ZwReadFile, ZwMapViewOfSection, ZwFlushVirtualMemory, ZwQuerySystemInformation, ZwSetInformationFile, ZwUnmapViewOfSection, ZwFlushBuffersFile, ZwCreateSection, ZwQueryInformationFile, ZwWriteFile, ZwTerminateProcess, LdrGetDllHandle, LdrGetProcedureAddress, RtlInitAnsiString, LdrUnloadDll, ZwQueryInformationProcess, ZwOpenProcess, RtlNtStatusToDosError, ZwShutdownSystem, NtClose, RtlOpenCurrentUser, ZwQueryVirtualMemory, ZwCreateFile, ZwResumeThread, RtlCreateUserProcess, ZwCreateEvent, RtlInitUnicodeString, ZwClose, ZwDuplicateObject, ZwWaitForMultipleObjects, RtlRemoveVectoredExceptionHandler, ZwFreeVirtualMemory, ZwAllocateVirtualMemory, RtlAcquirePebLock, RtlReleasePebLock, ZwReadVirtualMemory, RtlAllocateHeap, RtlReAllocateHeap, RtlFreeHeap, RtlAddVectoredExceptionHandler, ZwOpenFile, RtlUpcaseUnicodeChar, ZwQueryVolumeInformationFile, ZwDeviceIoControlFile, ZwCancelIoFile, ZwOpenDirectoryObject, RtlGetFullPathName_U, ZwOpenSymbolicLinkObject, ZwQuerySymbolicLinkObject, RtlEqualUnicodeString
ole32.dll
CoInitializeEx, StringFromGUID2, CoGetObject, CoCreateInstance, OleRun, CoUninitialize, CoTaskMemAlloc, CreateStreamOnHGlobal, PropVariantClear, CoTaskMemFree
shell32.dll
SHBrowseForFolderW, SHGetMalloc, SHGetFolderPathW, SHGetPathFromIDListW, SHGetSpecialFolderLocation, ExtractIconExW, SHGetFileInfoW, DragQueryFileW, DragAcceptFiles, ShellExecuteW, Shell_NotifyIconW, ShellExecuteExW, SHChangeNotify, SHGetDiskFreeSpaceExW, SHGetFolderLocation
shlwapi.dll
SHStrDupW
user32.dll
DllMain
uxtheme.dll
SetWindowTheme, IsAppThemed
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
winmm.dll
PlaySoundW

AVGUI.exe

AVG Internet Security by AVG Technologies (Signed)

Remove AVGUI.exe
Version:   13.0.0.2792
MD5:   1d2b51e5291448da123644a41250f6d6
SHA1:   a611063b37808d597d94265a1639d276989abb24
SHA256:   dc426ab556dcfb8fbfb477f0be05b07fcc90f761c52a66bfc47050b5476b9e5b

What is AVGUI.exe?

AVG User Interface - Antivirus and Antispyware protection, plus the full AVG LinkScanner safe search and surf technology.

About AVGUI.exe (from AVG Technologies)

New and improved AVG Internet Security 2010 offers real-time protection when surfing, shopping, banking and social networking. You'll also enjoy worry-free downloading, an enhanced firewall, and one o

DetailsDetails

File name:avgui.exe
Publisher:AVG Technologies CZ, s.r.o.
Product name:AVG Internet Security
Description:AVG User Interface
Typical file path:C:\Program Files\avg\avg10\avgui.exe
File version:13.0.0.2792
Size:3 MB (3,143,800 bytes)
Certificate
Issued to:AVG Technologies
Authority (CA):VeriSign
Effective date:Tuesday, February 16, 2010
Expiration date:Monday, March 5, 2012
Digital DNA
PE subsystem:Windows GUI
Entropy:6.355015
File packed:No
Code language:Microsoft Visual C++ 10.0
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'AVG_UI' → "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
Scheduled tasks
  • The job '{41B790C0-69C1-4DD9-AEBF-39C90542802A}' runs on registration in the path '\{41B790C0-69C1-4DD9-AEBF-39C90542802A}'
Network connections
  • [TCP] 117.18.237.191:443
  • [UDP] listens on port 1042
  • [UDP] listens on port 64657
  • [UDP] listens on port 58578
  • [UDP] listens on port 50345
  • [UDP] listens on port 61234

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.01414539%
    0.028634%
    Kernel CPU:0.00722657%
    0.013761%
    User CPU:0.00691882%
    0.014873%
    Kernel CPU time:1,429,813 ms/min
    100,923,805ms/min
    CPU cycles:1,439,814/sec
    17,470,203/sec
    Context switches:5/sec
    284/sec
    Memory
    Private memory:14.46 MB
    21.59 MB
    Private (maximum):25.15 MB
    Private (minimum):12.43 MB
    Non-paged memory:14.46 MB
    21.59 MB
    Virtual memory:184.83 MB
    140.96 MB
    Virtual memory (peak):201.53 MB
    169.69 MB
    Working set:21.07 MB
    18.61 MB
    Working set (peak):31.58 MB
    37.95 MB
    Page faults:72,885/min
    2,039/min
    I/O
    I/O read transfer:8.5 KB/sec
    1.02 MB/min
    I/O read operations:31/sec
    343/min
    I/O write transfer:2.48 KB/sec
    274.99 KB/min
    I/O write operations:16/sec
    227/min
    I/O other transfer:845 Bytes/sec
    448.09 KB/min
    I/O other operations:56/sec
    1,671/min
    Resource allocations
    Threads:24
    12
    Handles:570
    600
    GUI GDI count:162
    103
    GUI GDI peak:252
    142
    GUI USER count:73
    49
    GUI USER peak:122
    71

    BehaviorsProcess properties

    Integrety level:Medium
    Platform:64-bit
    Command lines:
    • "C:\Program Files\avg\avg2013\avgui.exe" /trayonly
    • "C:\program\avg\avg2013\avgui.exe" /trayonly
    Owner:User
    Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

    ResourcesThreads

    Averages
     
    mshtml.dll (Windows Internet Explorer by Microsoft)
    Total CPU:0.01477760%
    0.272967%
    Kernel CPU:0.00000000%
    0.107585%
    User CPU:0.01477760%
    0.165382%
    Context switches:1/sec
    79/sec
    Memory:5.75 MB
    1.16 MB
    avgsysx.dll (AVG Internet Security by AVG Technologies CZ, s.r.o)
    Total CPU:0.00325498%
    Kernel CPU:0.00161080%
    User CPU:0.00164418%
    CPU cycles:71,281/sec
    Memory:796 KB
    MSVCR100.dll
    Total CPU:0.00248789%
    Kernel CPU:0.00118998%
    User CPU:0.00129791%
    CPU cycles:27,490/sec
    Memory:764 KB
    avgui.exe (main module)
    Total CPU:0.00218209%
    Kernel CPU:0.00123460%
    User CPU:0.00094750%
    CPU cycles:103,998/sec
    Context switches:1/sec
    Memory:3.03 MB
    ntdll.dll
    Total CPU:0.00068218%
    Kernel CPU:0.00032351%
    User CPU:0.00035867%
    Memory:712 KB
    WININET.dll
    Total CPU:0.00008439%
    Kernel CPU:0.00004923%
    User CPU:0.00003516%
    Memory:920 KB
    wow64.dll
    Total CPU:0.00005999%
    Kernel CPU:0.00005999%
    User CPU:0.00000000%
    CPU cycles:2,831/sec
    Memory:252 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 33.09%
    Microsoft Windows XP 20.59%
    Windows 7 Ultimate 12.50%
    Windows 8 8.09%
    Windows 7 Professional 5.88%
    Windows 8 Single Language 5.15%
    Windows Vista Home Basic 5.15%
    Windows Vista Home Premium 2.21%
    Windows 8.1 Single Language 1.47%
    Windows 8 Pro with Media Center 1.47%
    Windows Vista Business 1.47%
    Windows 8.1 0.74%
    Windows Vista Ultimate 0.74%
    Windows 8 Pro 0.74%
    Windows XP Professional 0.74%

    Distribution by countryDistribution by country

    United States installs about 53.38% of AVG Internet Security.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 31.52%
    Acer 13.04%
    Sony 11.96%
    ASUS 10.87%
    Hewlett-Packard 7.61%
    Lenovo 7.61%
    Intel 5.43%
    American Megatrends 2.72%
    Toshiba 2.17%
    Medion 2.17%
    GIGABYTE 1.63%
    Samsung 1.63%
    Sahara 1.09%
    Alienware 0.54%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE