Gen.Trojan.Heur2.JP.zmLfaW4kDTnO (B)_11861f0e26
Gen:Trojan.Heur2.JP.zmLfaW4kDTnO (B) (Emsisoft), GenericRXFR-LR!8406CA7C5284 (McAfee), Gen:Trojan.Heur2.JP.zmLfaW4kDTnO (FSecure), mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Requires JavaScript enabled! |
---|
MD5: 11861f0e26a72aae6a994856dbe1f50b
SHA1: 7c02ba5af742a179953252b6859d92654aa99d43
SHA256: 0e2386992266e74c764046029d3561af541ef5a0c834499b664a7eaa172a59cd
SSDeep: 6144:cAceQ9R1nt/2TdeEoQaOUNmpNX uS1DOgbt/gJrXEnb9G2EgqzUtuACQpQk9muzj:cteent8dZ7UNmsDfdb7GzBAek9VJt
Size: 417864 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: PackerUPXCompresorGratuitowwwupxsourceforgenet, UPolyXv05_v6
Company: GOG Sp. z o.o.
Created at: 2018-05-23 15:25:01
Analyzed on: Windows7 SP1 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
GoogleUpdate.exe:3584
GoogleUpdate.exe:2592
GalaxyInstaller.exe:3832
%original file name%.exe:3412
GalaxySetup.tmp:744
wusa.exe:2440
vcredist_x86_2015.exe:568
vcredist_x86_2015.exe:1736
vs2015-redist-x64.exe:3528
GalaxySetup.exe:1872
The Trojan injects its code into the following process(es):
GoogleUpdate.exe:2716
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process GoogleUpdate.exe:3584 makes changes in the file system.
The Trojan deletes the following file(s):
%Program Files%\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\54.0.2840.59\54.0.2840.59_chrome_installer.exe (0 bytes)
The process GalaxyInstaller.exe:3832 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\ProgramData\GOG.com\Galaxy\logs\InstallerWebinstaller.log (751 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\GalaxySetup.exe (6362246 bytes)
The process %original file name%.exe:3412 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6 (434 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\69C6F6EC64E114822DF688DC12CDD86C (372 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6DB145CFEEC544B1582FED1ADA3370DD (320 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6DB145CFEEC544B1582FED1ADA3370DD (531 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\1.0[1].0 (729 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar255B.tmp (2712 bytes)
C:\ProgramData\GOG.com\Galaxy\logs\InstallerBootstrapper.log (5278 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6 (471 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab255A.tmp (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\GalaxyInstaller.exe (61 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\remoteconfig.json (729 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\69C6F6EC64E114822DF688DC12CDD86C (531 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\icon.ico (4210 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar255B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab255A.tmp (0 bytes)
The process GalaxySetup.tmp:744 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-RUC54.tmp (15 bytes)
%Program Files%\GOG Galaxy\is-VO01K.tmp (3073 bytes)
%Program Files%\GOG Galaxy\web\images\gwentBanner\is-9H0L2.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\js\is-R57NG.tmp (6841 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-8VM2P.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-M5FBM.tmp (9605 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\es-MX\is-RHEDD.tmp (56 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-1Q746.tmp (37 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-R7MT9.tmp (1425 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-DCPO9.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-8SLP8.tmp (44 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-78RP5.tmp (1281 bytes)
%Program Files%\GOG Galaxy\web\locales\es-ES\is-EQHNL.tmp (56 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-IRLCE.tmp (39 bytes)
%Program Files%\GOG Galaxy\unins000.dat (23634 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-D3CI0.tmp (3073 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-VOEAC.tmp (38 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\fr-FR\is-HIVD8.tmp (1 bytes)
%Program Files%\GOG Galaxy\is-S8PKF.tmp (1425 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-7UPVL.tmp (52 bytes)
%Program Files%\GOG Galaxy\web\is-H921P.tmp (909 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-OPJ8V.tmp (7971 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-IKVOP.tmp (13122 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-7NPH7.tmp (59 bytes)
%Program Files%\GOG Galaxy\web\locales\es-MX\is-EKUA6.tmp (56 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com\GOG Galaxy\GOG Galaxy.lnk (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\pt-BR\is-CQFO1.tmp (981 bytes)
%Program Files%\GOG Galaxy\platforms\is-4MMFU.tmp (7385 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-H7S3A.tmp (26 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-R4HAA.tmp (114989 bytes)
C:\Windows\Fonts\is-8JARL.tmp (4185 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-LBUP5.tmp\botva2.dll (64 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\pt-PT\is-8SJ09.tmp (54 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-ELDPT.tmp (61370 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\ja-JP\is-T0L5C.tmp (60 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-5FFO5.tmp (58 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-LTLKU.tmp (51 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-HTN8S.tmp (39 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-8JP2R.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\styles\client\is-S9BIL.tmp (20 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-KA6JD.tmp (7433 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-JFSGB.tmp (3 bytes)
%Program Files%\GOG Galaxy\web\images\gwentLogo\is-33D0R.tmp (21 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-P1OEL.tmp (1425 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-MFFVN.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-LM3RM.tmp (517726 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-RJOIS.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\js\is-4LNET.tmp (3073 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-IBVA5.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-6RPRH.tmp (59 bytes)
C:\Windows\Fonts\is-99NB0.tmp (4185 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-ETCND.tmp (13 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-9GC8E.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-33CHM.tmp (76782 bytes)
%Program Files%\GOG Galaxy\web\styles\client\is-ABOVH.tmp (48 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-6HR7S.tmp (2321 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-70LL1.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-VA64H.tmp (2 bytes)
%Program Files%\GOG Galaxy\web\audio\is-C71U3.tmp (4185 bytes)
%Program Files%\GOG Galaxy\is-C62G8.tmp (13122 bytes)
%Program Files%\GOG Galaxy\locales\is-G21KO.tmp (1281 bytes)
C:\Windows\Fonts\is-L4ASO.tmp (4185 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-RFQ3I.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-4OHVM.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-P9QC0.tmp (39 bytes)
%Program Files%\GOG Galaxy\is-0TDCO.tmp (2321 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-JT8IJ.tmp (176 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-S9DGI.tmp (1281 bytes)
%Program Files%\GOG Galaxy\is-HMC0O.tmp (2105 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-BVCMS.tmp (26 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-2M131.tmp (63 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-BKBMD.tmp (601 bytes)
%Program Files%\GOG Galaxy\is-L8MRA.tmp (33350 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-5CTK6.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\locales\fr-FR\is-C9MG6.tmp (59 bytes)
%Program Files%\GOG Galaxy\web\fonts\is-2U4IT.tmp (4185 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-AM0LM.tmp (46 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-VJIM1.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-FUNEP.tmp (4545 bytes)
%Program Files%\GOG Galaxy\is-QI6PF.tmp (30812 bytes)
%Program Files%\GOG Galaxy\locales\is-88PVE.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-MVD9G.tmp (40 bytes)
%Program Files%\GOG Galaxy\is-DE8HA.tmp (4545 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\it-IT\is-04644.tmp (55 bytes)
%Program Files%\GOG Galaxy\locales\is-M38SK.tmp (673 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\ru-RU\is-T52QN.tmp (1 bytes)
%Program Files%\GOG Galaxy\web\locales\en-US\is-KREOP.tmp (54 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-9L42N.tmp (2 bytes)
C:\Windows\Fonts\is-IFKS0.tmp (4185 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-C911P.tmp (13 bytes)
%Program Files%\GOG Galaxy\web\locales\pl-PL\is-7HKMB.tmp (57 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\fr-FR\is-KL4FN.tmp (59 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-12QAB.tmp (1281 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-CVD1T.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-84JFA.tmp (57 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-18\is-5TU2S.tmp (110924 bytes)
%Program Files%\GOG Galaxy\web\locales\ja-JP\is-VBIOB.tmp (924 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-FRT8U.tmp (9605 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-187O0.tmp (1281 bytes)
%Program Files%\GOG Galaxy\web\locales\es-MX\is-O8DJQ.tmp (916 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-P2KQM.tmp (50 bytes)
%Program Files%\GOG Galaxy\web\locales\zh-Hant\is-RIIPS.tmp (54 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\en-US\is-D3FMH.tmp (54 bytes)
%Program Files%\GOG Galaxy\web\fonts\is-2K8KR.tmp (4185 bytes)
%Program Files%\GOG Galaxy\is-UI57V.tmp (4545 bytes)
%Program Files%\GOG Galaxy\licences\Boost C Libraries\is-A65VS.tmp (1 bytes)
%Program Files%\GOG Galaxy\is-QV0JU.tmp (1425 bytes)
%Program Files%\GOG Galaxy\web\images\gogGalaxyLogo\is-NO04O.tmp (17 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-Q198Q.tmp (38 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-15\is-94UMK.tmp (82840 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\pl-PL\is-9E927.tmp (57 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-1UPTB.tmp (22 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-Q8PIR.tmp (41 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-R4G6L.tmp (26 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-9QBUT.tmp (37 bytes)
C:\Windows\Fonts\is-6JQML.tmp (4185 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-1K03T.tmp (1425 bytes)
%Program Files%\GOG Galaxy\is-CAMFS.tmp (7971 bytes)
%Program Files%\GOG Galaxy\web\is-S4DVE.tmp (1425 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-5CSC3.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\audio\is-U3BMB.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-HPCF6.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-TU2QD.tmp (10 bytes)
%Program Files%\GOG Galaxy\web\is-KHJLI.tmp (1 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-8GGV7.tmp (54 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-LBUP5.tmp\vcredist_x86_2015.exe (108599 bytes)
%Program Files%\GOG Galaxy\unins000.msg (654 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-QHNQP.tmp (2 bytes)
%Program Files%\GOG Galaxy\is-KSVHJ.tmp (4545 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-837K2.tmp (50 bytes)
%Program Files%\GOG Galaxy\web\is-CTNU2.tmp (14 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-BISQ7.tmp (59 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-GA1A1.tmp (3361 bytes)
%Program Files%\GOG Galaxy\is-Q7ODU.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-EEU5A.tmp (28 bytes)
%Program Files%\GOG Galaxy\is-3NUN2.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-QRO7U.tmp (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-LBUP5.tmp\innocallback.dll (65 bytes)
%Program Files%\GOG Galaxy\licences\LatoWeb Font\is-N7NF3.tmp (4 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-V5EGS.tmp (22575 bytes)
%Program Files%\GOG Galaxy\web\is-6K6QJ.tmp (37 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\pl-PL\is-7GTTF.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-71NS2.tmp (35 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-V1GEK.tmp (14 bytes)
%Program Files%\GOG Galaxy\web\locales\it-IT\is-JDQ5Q.tmp (55 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-A4TOQ.tmp (35 bytes)
%Program Files%\GOG Galaxy\web\images\gogGalaxyLogo\is-CLHSH.tmp (4 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-7C0AN.tmp (3073 bytes)
%Program Files%\GOG Galaxy\web\styles\client\is-G2S02.tmp (673 bytes)
%Program Files%\GOG Galaxy\locales\is-H3N24.tmp (1281 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-0Q7VI.tmp (2 bytes)
%Program Files%\GOG Galaxy\web\images\gogGalaxyLogo\is-F44CS.tmp (10 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-6I2E5.tmp (53 bytes)
%Program Files%\GOG Galaxy\is-01R46.tmp (38249 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-DAFTO.tmp (2321 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-020J9.tmp (21 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-LO0T4.tmp (49 bytes)
%Program Files%\GOG Galaxy\web\images\gwentBanner\is-0D1GB.tmp (673 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-KL6KQ.tmp (673 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\zh-Hans\is-7BRGN.tmp (54 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-CKCE2.tmp (2321 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-7SDPF.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-1K4L6.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-2II99.tmp (673 bytes)
%Program Files%\GOG Galaxy\locales\is-L7E4J.tmp (1281 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-76D1O.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-QT67A.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\locales\pl-PL\is-371IV.tmp (1 bytes)
%Program Files%\GOG Galaxy\is-IAQLK.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\styles\overlay\is-G2JG9.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-2D61S.tmp (23062 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-LBUP5.tmp\_isetup\_isdecmp.dll (48 bytes)
%Program Files%\GOG Galaxy\is-R6G78.tmp (34583 bytes)
%Program Files%\GOG Galaxy\is-ECG7S.tmp (5873 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\zh-Hant\is-FJQER.tmp (54 bytes)
%Program Files%\GOG Galaxy\web\images\gwentLogo\is-PMBFU.tmp (7 bytes)
%Program Files%\GOG Galaxy\is-PR68G.tmp (2321 bytes)
C:\Users\Public\Desktop\GOG Galaxy.lnk (999 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-JIJRT.tmp (673 bytes)
%Program Files%\GOG Galaxy\web\images\gogGalaxyLogo\is-8KOVQ.tmp (7 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\de-DE\is-6704P.tmp (57 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-76JCE.tmp (2 bytes)
%Program Files%\GOG Galaxy\web\is-AM1JJ.tmp (8 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-NSFB7.tmp (39 bytes)
%Program Files%\GOG Galaxy\locales\is-UI5LQ.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-K56D5.tmp (59 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-581M2.tmp (673 bytes)
%Program Files%\GOG Galaxy\is-EAF21.tmp (1425 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-E30BI.tmp (37 bytes)
%Program Files%\GOG Galaxy\web\locales\ru-RU\is-R1SQR.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-LH1DO.tmp (33350 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-07EDC.tmp (1281 bytes)
%Program Files%\GOG Galaxy\locales\is-UKBV9.tmp (1281 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-TOABH.tmp (13 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-FDHSF.tmp (5 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-N9CMU.tmp (35505 bytes)
%Program Files%\GOG Galaxy\is-TSJ6B.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\locales\ja-JP\is-H549C.tmp (60 bytes)
C:\Windows\Fonts\is-DP3Q8.tmp (4185 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-S14ET.tmp (38 bytes)
%Program Files%\GOG Galaxy\web\locales\en-US\is-47SLT.tmp (916 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-18\is-8U9UO.tmp (85228 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-3OCQN.tmp (4 bytes)
%Program Files%\GOG Galaxy\web\styles\client\is-7JINM.tmp (40 bytes)
C:\Windows\Fonts\is-LLC7F.tmp (4185 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-G7HB4.tmp (44 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-UASEI.tmp (13 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-JBAIQ.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\locales\pt-BR\is-LOMN8.tmp (57 bytes)
%Program Files%\GOG Galaxy\web\is-RJO8R.tmp (601 bytes)
%Program Files%\GOG Galaxy\is-E4SJN.tmp (3361 bytes)
%Program Files%\GOG Galaxy\web\locales\de-DE\is-234K0.tmp (57 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-OLC3A.tmp (15 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-5U3FD.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\locales\zh-Hans\is-GK4G7.tmp (54 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-SKS8N.tmp (10 bytes)
%Program Files%\GOG Galaxy\is-0MJIQ.tmp (7726 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-GCR0H.tmp (6841 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-ONLL3.tmp (4185 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-24KQ7.tmp (2321 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-68B77.tmp (8657 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-FV1PJ.tmp (59 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-5S66G.tmp (49 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-GM7VA.tmp (673 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-04DA8.tmp (57 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-UG91F.tmp (54 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-II4OA.tmp (11 bytes)
%Program Files%\GOG Galaxy\locales\is-3INNB.tmp (673 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-8UL9A.tmp (673 bytes)
%Program Files%\GOG Galaxy\licences\POCO C Libraries\is-22DK1.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\en-US\is-12NCS.tmp (916 bytes)
%Program Files%\GOG Galaxy\licences\Chromium Embedded Framework\is-RIUOI.tmp (1 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-G33H8.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-IRM9J.tmp (2321 bytes)
%Program Files%\GOG Galaxy\is-7JBNG.tmp (7433 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\pt-PT\is-9O0IP.tmp (916 bytes)
%Program Files%\GOG Galaxy\is-87DPG.tmp (9605 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\ru-RU\is-F6UTI.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\audio\is-TBIAK.tmp (2105 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-VEMCQ.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-B2K4C.tmp (47 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-BFNJA.tmp (51 bytes)
%Program Files%\GOG Galaxy\is-O8LJ4.tmp (15116 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-17\is-R32TV.tmp (86230 bytes)
%Program Files%\GOG Galaxy\web\images\gwentLogo\is-6E9II.tmp (20 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-IA5TI.tmp (59 bytes)
%Program Files%\GOG Galaxy\imageformats\is-BQOEB.tmp (1281 bytes)
%Program Files%\GOG Galaxy\is-5THVN.tmp (76782 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-GGHSO.tmp (2321 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\css\is-NAMA2.tmp (57 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-UO22F.tmp (40 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-R7ANV.tmp (60 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-BNL5P.tmp (4545 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-VB4ES.tmp (1281 bytes)
%Program Files%\GOG Galaxy\web\audio\is-UH8NR.tmp (2105 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-JD8TR.tmp (22 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-17\is-UMV3I.tmp (112480 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-15\is-O0K3S.tmp (125140 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-M7F32.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\images\gwentBanner\is-JBP07.tmp (1281 bytes)
%Program Files%\GOG Galaxy\is-28QJK.tmp (673 bytes)
%Program Files%\GOG Galaxy\web\locales\pt-BR\is-PFFMT.tmp (981 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-5R569.tmp (3 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-16\is-5L5P8.tmp (85696 bytes)
%Program Files%\GOG Galaxy\is-BBKCC.tmp (1425 bytes)
%Program Files%\GOG Galaxy\web\locales\pt-PT\is-CC18G.tmp (54 bytes)
%Program Files%\GOG Galaxy\licences\JsonCPP\is-44A19.tmp (2 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-P0HV4.tmp (13 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-H292O.tmp (42 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-BDTAI.tmp (45 bytes)
%Program Files%\GOG Galaxy\is-74VLL.tmp (9605 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-04JC7.tmp (58 bytes)
%Program Files%\GOG Galaxy\licences\Apache\is-JSFDC.tmp (9 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-0I73C.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-EGQJU.tmp (14 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-8HLL1.tmp (48 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\de-DE\is-J05GH.tmp (996 bytes)
%Program Files%\GOG Galaxy\licences\zlib\is-4V222.tmp (5 bytes)
%Program Files%\GOG Galaxy\web\styles\client\is-IF6H1.tmp (51 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-3C3I9.tmp (601 bytes)
%Program Files%\GOG Galaxy\licences\QT Libraries\is-R6C7Q.tmp (27 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-FG1IU.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-8A09T.tmp (7726 bytes)
%Program Files%\GOG Galaxy\web\styles\components\findFriendsWindow\is-Q3899.tmp (24 bytes)
%Program Files%\GOG Galaxy\is-GU4OV.tmp (51303 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-TJJPE.tmp (26096 bytes)
%Program Files%\GOG Galaxy\is-419DU.tmp (2321 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-N14J6.tmp (50 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-OOP2B.tmp (52 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-18AOQ.tmp (2321 bytes)
%Program Files%\GOG Galaxy\licences\libcurl\is-S2BVE.tmp (1 bytes)
%Program Files%\GOG Galaxy\is-GIQ01.tmp (517726 bytes)
%Program Files%\GOG Galaxy\web\styles\client\is-BOBIL.tmp (45 bytes)
%Program Files%\GOG Galaxy\licences\OpenSSL\is-VAH9A.tmp (6 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\it-IT\is-LHG6P.tmp (916 bytes)
%Program Files%\GOG Galaxy\web\fonts\is-LB5S1.tmp (4185 bytes)
%Program Files%\GOG Galaxy\web\fonts\is-PLKN9.tmp (4185 bytes)
%Program Files%\GOG Galaxy\web\is-DIKMK.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-HPKGF.tmp (22 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-JIHHI.tmp (2 bytes)
%Program Files%\GOG Galaxy\is-CAOMK.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-1AO3I.tmp (45 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-0K71S.tmp (14 bytes)
%Program Files%\GOG Galaxy\web\is-1UMI2.tmp (1 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-U554V.tmp (31 bytes)
%Program Files%\GOG Galaxy\web\locales\ru-RU\is-31C3R.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-R29GO.tmp (1425 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-NCO68.tmp (48 bytes)
%Program Files%\GOG Galaxy\web\locales\zh-Hans\is-G42A9.tmp (909 bytes)
%Program Files%\GOG Galaxy\is-19HQU.tmp (22575 bytes)
%Program Files%\GOG Galaxy\is-R20EK.tmp (31786 bytes)
%Program Files%\GOG Galaxy\web\locales\de-DE\is-KPB0D.tmp (996 bytes)
%Program Files%\GOG Galaxy\web\styles\common\is-MLA24.tmp (595 bytes)
%Program Files%\GOG Galaxy\web\images\gwentBanner\is-0E8HQ.tmp (26 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-PUGNQ.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-N96G6.tmp (45 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-AUGNL.tmp (14 bytes)
%Program Files%\GOG Galaxy\web\audio\is-S8V8J.tmp (1425 bytes)
%Program Files%\GOG Galaxy\is-T0L4B.tmp (3073 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\ko-KR\is-RF5FD.tmp (54 bytes)
%Program Files%\GOG Galaxy\web\locales\pt-PT\is-8B80M.tmp (916 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-I8JNT.tmp (2105 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-ER4V9.tmp (14 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-94LL9.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-OLD4B.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\ja-JP\is-84IKG.tmp (924 bytes)
%Program Files%\GOG Galaxy\is-5M57H.tmp (673 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-DSK9B.tmp (14 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\pt-BR\is-B6SO1.tmp (57 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-KEN5M.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-RGCD7.tmp (44 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-MBDI3.tmp (673 bytes)
%Program Files%\GOG Galaxy\web\images\gwentBanner\is-R6CSK.tmp (54 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-AB1LA.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-ANRT4.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\zh-Hans\is-UAOK1.tmp (909 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-SKJT2.tmp (39 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-KQENL.tmp (42 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-SCPVT.tmp (30812 bytes)
%Program Files%\GOG Galaxy\web\images\gwentLogo\is-71KTF.tmp (16 bytes)
%Program Files%\GOG Galaxy\web\locales\it-IT\is-U0KL1.tmp (916 bytes)
C:\Windows\Fonts\is-MM1CU.tmp (4185 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\es-MX\is-OT028.tmp (916 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-16\is-8A74G.tmp (114298 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-K8KJV.tmp (1 bytes)
%Program Files%\GOG Galaxy\locales\is-EDUMM.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-JLI41.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-UOTDF.tmp (13 bytes)
%Program Files%\GOG Galaxy\web\locales\es-ES\is-RMGHM.tmp (916 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-FR5S0.tmp (2 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-5VPA1.tmp (23 bytes)
%Program Files%\GOG Galaxy\web\locales\fr-FR\is-H3ORE.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-VEVDP.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-1UEPS.tmp (56 bytes)
%Program Files%\GOG Galaxy\is-MLSAT.tmp (6841 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Setup Log 2018-06-18 #001.txt (2865136 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-SIBMA.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\es-ES\is-D8DLO.tmp (56 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-BTM6O.tmp (2321 bytes)
%Program Files%\GOG Galaxy\is-QQT9A.tmp (26096 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-LDUAD.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-U63UE.tmp (59 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\es-ES\is-GLK0G.tmp (916 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-BEFOO.tmp (13 bytes)
%Program Files%\GOG Galaxy\web\locales\ko-KR\is-CD4HF.tmp (54 bytes)
%Program Files%\GOG Galaxy\is-IT07T.tmp (7547 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-AVTI7.tmp (2105 bytes)
The process wusa.exe:2440 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Windows\WindowsUpdate.log (13709 bytes)
C:\989f8654a2a9bdd87e\$dpx$.tmp\de0df680e990594d8bff4484efdf984b.tmp (468 bytes)
C:\989f8654a2a9bdd87e (4 bytes)
C:\989f8654a2a9bdd87e\$dpx$.tmp\27d9f57d6d77e84d879ace4bf2d00ce6.tmp (2552 bytes)
C:\Windows\Logs\DPX\setupact.log (3028 bytes)
C:\989f8654a2a9bdd87e\$dpx$.tmp\476e18042842f849bfd39dd8de4e7dc8.tmp (6722 bytes)
C:\989f8654a2a9bdd87e\$dpx$.tmp\a25f4146e9855344b6c4b2c88ab51598.tmp (444 bytes)
The Trojan deletes the following file(s):
C:\989f8654a2a9bdd87e\Windows6.1-KB2999226-x86.cab (0 bytes)
C:\989f8654a2a9bdd87e (0 bytes)
C:\989f8654a2a9bdd87e\WSUSSCAN.cab (0 bytes)
C:\989f8654a2a9bdd87e\Windows6.1-KB2999226-x86-pkgProperties.txt (0 bytes)
C:\989f8654a2a9bdd87e\Windows6.1-KB2999226-x86.xml (0 bytes)
C:\989f8654a2a9bdd87e\$dpx$.tmp (0 bytes)
The process vcredist_x86_2015.exe:568 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab91B3.tmp (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F90F18257CBB4D84216AC1E1F3BB2C76 (550 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar91B4.tmp (2712 bytes)
C:\ProgramData\Package Cache\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\state.rsm (1808 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\696F3DE637E6DE85B458996D49D759AD (732 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7396C420A8E1BC1DA97F1AF0D10BAD21 (554 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\dd_vcredist_x86_20180618173208_001_vcRuntimeAdditional_x86.log (127738 bytes)
C:\ProgramData\Package Cache\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\VC_redist.x86.exe (5873 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F90F18257CBB4D84216AC1E1F3BB2C76 (756 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\696F3DE637E6DE85B458996D49D759AD (781 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7396C420A8E1BC1DA97F1AF0D10BAD21 (912 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\dd_vcredist_x86_20180618173208_000_vcRuntimeMinimum_x86.log (126936 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab91B3.tmp (0 bytes)
C:\ProgramData\Package Cache\.unverified (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar91B4.tmp (0 bytes)
The process vcredist_x86_2015.exe:1736 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1029\license.rtf (3284 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\cab54A5CABBE7274D8A22EB58060AAB7623 (16944 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1055\license.rtf (2663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1046\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1041\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\thm.xml (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\vcRuntimeMinimum_x86 (1712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\license.rtf (2722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\2052\license.rtf (2591 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\2052\thm.wxl (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1042\license.rtf (7601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1028\thm.wxl (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1040\license.rtf (2201 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1031\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1040\thm.wxl (577 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\dd_vcredist_x86_20180618173208.log (51040 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1028\license.rtf (2682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1045\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\thm.wxl (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\BootstrapperApplicationData.xml (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\Windows7_MSU_x86 (10528 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1036\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\wixstdba.dll (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1 (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.be\VC_redist.x86.exe (106328 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1055\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1031\license.rtf (2050 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\3082\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1049\license.rtf (4025 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1029\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\3082\license.rtf (2303 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1042\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\vcRuntimeAdditional_x86 (2160 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1036\license.rtf (2922 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1045\license.rtf (2597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d} (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\logo.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1046\license.rtf (2124 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1041\license.rtf (3662 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\cabB3E1576D1FEFBB979E13B1A5379E0B16 (76515 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1049\thm.wxl (4 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1029\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1055\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1046\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1036 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1041\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1055 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\3082 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1031 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1045\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\2052\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\2052\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1042\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1028\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1040\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1031\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.be (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\wixstdba.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1040\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1028\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\BootstrapperApplicationData.xml (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1036\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1049 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1046 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1055\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1045 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1042 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1031\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1040 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1041 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1049\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1029\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\3082\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1042\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\3082\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1028 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1029 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1036\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1045\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\2052 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\logo.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1046\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1041\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\thm.xml (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1049\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.be\VC_redist.x86.exe (0 bytes)
The process vs2015-redist-x64.exe:3528 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1031\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1055\license.rtf (2263 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\wixstdba.dll (1890 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1055\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1031\license.rtf (1730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\logo.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1040\license.rtf (1881 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\thm.xml (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\thm.wxl (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\3082\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\2052\thm.wxl (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1040\thm.wxl (497 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1029\license.rtf (2804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\BootstrapperApplicationData.xml (817 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1042\license.rtf (7401 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1 (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1046\license.rtf (1804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1045\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1042\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1041\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1046\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1036\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1045\license.rtf (2197 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1029\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1049\thm.wxl (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\dd_vcredist_amd64_20180618173253.log (21751 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1036\license.rtf (2522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1028\license.rtf (2202 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1028\thm.wxl (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\2052\license.rtf (3031 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1049\license.rtf (3465 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\license.rtf (2322 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1041\license.rtf (4022 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\3082\license.rtf (1983 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1031\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1055\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\wixstdba.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1055\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1031\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1049\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1040\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\thm.xml (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\2052 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1049 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1040 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1041 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1042 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\2052\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1045 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1046 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1040\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1028 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1029 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1029\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\BootstrapperApplicationData.xml (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1042\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1046\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1045\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1042\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1041\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1046\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1036\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1045\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1029\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1036\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1028\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1028\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\logo.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\2052\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1055 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\3082 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\3082\thm.wxl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1049\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1041\license.rtf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1036 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1031 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\3082\license.rtf (0 bytes)
The process GalaxySetup.exe:1872 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-1D2BU.tmp\GalaxySetup.tmp (50 bytes)
Registry activity
The process GoogleUpdate.exe:3584 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}]
"RollCallDayStartSec" = "1529305202"
[HKLM\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"pv" = "54.0.2840.59"
[HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}\CurrentState]
"StateValue" = "3"
[HKLM\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"DayOfLastRollCall" = "4186"
[HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"UpdateAvailableSince" = "Type: REG_QWORD, Length: 8"
[HKCU\Software\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"dr" = "0"
[HKLM\SOFTWARE\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}]
"DayOfLastRollCall" = "4186"
[HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"UpdateAvailableCount" = "1"
[HKLM\SOFTWARE\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}]
"ActivePingDayStartSec" = "1529305202"
"DayOfLastActivity" = "4186"
[HKLM\SOFTWARE\Google\Update\PersistedPings\{B80DBE63-1990-4361-A107-DBCCD7DB78F5}]
"PersistedPingTime" = "131738057800188412"
[HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}\cohort]
"Hint" = ""
[HKCU\Software\Google\Update\proxy]
"source" = "IEWPAD"
[HKLM\SOFTWARE\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}\cohort]
"Hint" = ""
[HKLM\SOFTWARE\Google\Update\PersistedPings\{2A442A5D-09A1-4692-80B0-C7F94C36480D}]
"PersistedPingString" = "
[HKCU\Software\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}]
"dr" = "0"
[HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"DayOfLastRollCall" = "4186"
[HKLM\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"RollCallDayStartSec" = "1529305202"
"ping_freshness" = "{3BD54845-A658-48AF-83CF-F883F3DE0510}"
[HKLM\SOFTWARE\Google\Update]
"LastChecked" = "1529332180"
[HKLM\SOFTWARE\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}\cohort]
"(Default)" = "1:b8:"
[HKLM\SOFTWARE\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}]
"pv" = "54.0.2840.59"
[HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"pv" = "1.3.31.5"
[HKLM\SOFTWARE\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}\cohort]
"Name" = "Stable"
[HKLM\SOFTWARE\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}]
"ping_freshness" = "{046C7C6D-2F6E-4F61-9871-C4E81EB410C5}"
[HKLM\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"ActivePingDayStartSec" = "1529305202"
[HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}\cohort]
"Name" = "Everyone Else"
[HKLM\SOFTWARE\Google\Update\PersistedPings\{B80DBE63-1990-4361-A107-DBCCD7DB78F5}]
"PersistedPingString" = "
[HKLM\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"DayOfLastActivity" = "4186"
[HKLM\SOFTWARE\Google\Update\PersistedPings\{2A442A5D-09A1-4692-80B0-C7F94C36480D}]
"PersistedPingTime" = "131738057723748278"
[HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"ping_freshness" = "{D2786935-CF5E-4A7D-AB11-5F1B35C6D17D}"
[HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}\cohort]
"(Default)" = "1:9co:"
[HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}\CurrentState]
"DownloadProgressPercent" = "0"
"DownloadTimeRemainingMs" = "4294967295"
[HKLM\SOFTWARE\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}]
"LastCheckSuccess" = "1529332180"
[HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"RollCallDayStartSec" = "1529305202"
[HKCU\Software\Classes\Local Settings\MuiCache\63\52C64B7E]
"LanguageList" = "en-US, en"
The Trojan deletes the following registry key(s):
[HKLM\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState]
[HKLM\SOFTWARE\Google\Update\PersistedPings\{2A442A5D-09A1-4692-80B0-C7F94C36480D}]
[HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}\CurrentState]
[HKLM\SOFTWARE\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}\CurrentState]
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Google\Update]
"uid"
[HKLM\SOFTWARE\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}]
"UpdateAvailableCount"
"dr"
[HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"tttoken"
[HKLM\SOFTWARE\Google\Update]
"old-uid"
[HKLM\SOFTWARE\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}]
"tttoken"
[HKLM\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"dr"
[HKLM\SOFTWARE\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}]
"UpdateAvailableSince"
The process GalaxyInstaller.exe:3832 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASAPI32]
"ConsoleTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASMANCS]
"FileTracingMask" = "4294901760"
"FileDirectory" = "%windir%\tracing"
[HKLM\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASAPI32]
"EnableConsoleTracing" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASMANCS]
"MaxFileSize" = "1048576"
[HKLM\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASAPI32]
"FileDirectory" = "%windir%\tracing"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Classes\Local Settings\MuiCache\63\52C64B7E]
"LanguageList" = "en-US, en"
[HKLM\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASAPI32]
"EnableFileTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASMANCS]
"EnableFileTracing" = "0"
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASAPI32]
"FileTracingMask" = "4294901760"
"MaxFileSize" = "1048576"
[HKLM\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASMANCS]
"ConsoleTracingMask" = "4294901760"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process %original file name%.exe:3412 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Tracing\11861f0e26a72aae6a994856dbe1f50b_RASAPI32]
"MaxFileSize" = "1048576"
[HKLM\SOFTWARE\Microsoft\Tracing\11861f0e26a72aae6a994856dbe1f50b_RASMANCS]
"EnableConsoleTracing" = "0"
"ConsoleTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\11861f0e26a72aae6a994856dbe1f50b_RASAPI32]
"ConsoleTracingMask" = "4294901760"
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\11861f0e26a72aae6a994856dbe1f50b_RASMANCS]
"FileDirectory" = "%windir%\tracing"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 41 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\11861f0e26a72aae6a994856dbe1f50b_RASMANCS]
"MaxFileSize" = "1048576"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\11861f0e26a72aae6a994856dbe1f50b_RASAPI32]
"FileTracingMask" = "4294901760"
"EnableFileTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\11861f0e26a72aae6a994856dbe1f50b_RASMANCS]
"FileTracingMask" = "4294901760"
"EnableFileTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\11861f0e26a72aae6a994856dbe1f50b_RASAPI32]
"FileDirectory" = "%windir%\tracing"
[HKCU\Software\Classes\Local Settings\MuiCache\63\52C64B7E]
"LanguageList" = "en-US, en"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"
The process GalaxySetup.tmp:744 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\RestartManager\Session0000]
"RegFilesHash" = "F3 DB 30 60 0B CB 17 ED 2F EE 9E 95 4E 46 D5 8A"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7258BA11-600C-430E-A759-27E2C691A335}_is1]
"Inno Setup: Setup Version" = "5.5.9 (u)"
[HKCU\Software\Microsoft\RestartManager\Session0000]
"RegFiles0000" = "%Program Files%\GOG Galaxy\chrome_elf.dll, %Program Files%\GOG Galaxy\CrashReporter.exe, %Program Files%\GOG Galaxy\d3dcompiler_43.dll, %Program Files%\GOG Galaxy\d3dcompiler_47.dll, %Program Files%\GOG Galaxy\expat.dll, %Program Files%\GOG Galaxy\GalaxyClient Helper.exe, %Program Files%\GOG Galaxy\GalaxyClient.exe, %Program Files%\GOG Galaxy\GalaxyClientService.exe, %Program Files%\GOG Galaxy\GOG Galaxy Notifications Renderer.exe, %Program Files%\GOG Galaxy\libcef.dll, %Program Files%\GOG Galaxy\libeay32.dll, %Program Files%\GOG Galaxy\libEGL.dll, %Program Files%\GOG Galaxy\libGLESv2.dll, %Program Files%\GOG Galaxy\pcre.dll, %Program Files%\GOG Galaxy\PocoCrypto.dll, %Program Files%\GOG Galaxy\PocoData.dll, %Program Files%\GOG Galaxy\PocoDataSQLite.dll, %Program Files%\GOG Galaxy\PocoFoundation.dll, %Program Files%\GOG Galaxy\PocoJSON.dll, %Program Files%\GOG Galaxy\PocoNet.dll, %Program Files%\GOG Galaxy\PocoNetSSL.dll, %Program Files%\GOG Galaxy\PocoUtil.dll, %Program Files%\GOG Galaxy\PocoXml.dll, C:\Progá°£:"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts]
"Lato Bold" = "LatoWeb-Bold.ttf"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7258BA11-600C-430E-A759-27E2C691A335}_is1]
"URLUpdateInfo" = "http://www.gog.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7258BA11-600C-430E-A759-27E2C691A335}_is1]
"Inno Setup: User" = "%CurrentUserName%"
"InstallDate" = "20180618"
"EstimatedSize" = "399960"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts]
"Lato" = "LatoWeb-Regular.ttf"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7258BA11-600C-430E-A759-27E2C691A335}_is1]
"UninstallString" = "%Program Files%\GOG Galaxy\unins000.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts]
"Lato SemiboldItalic" = "LatoWeb-SemiboldItalic.ttf"
[HKCU\Software\Microsoft\RestartManager\Session0000]
"SessionHash" = "3D 92 6C E3 00 2B 8A C9 5E 90 BF 95 38 AA E0 8E"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts]
"Lato LightItalic" = "LatoWeb-LightItalic.ttf"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7258BA11-600C-430E-A759-27E2C691A335}_is1]
"NoRepair" = "1"
"DisplayName" = "GOG Galaxy"
"Publisher" = "GOG.com"
"InstallLocation" = "%Program Files%\GOG Galaxy\"
[HKLM\SOFTWARE\GOG.com\GalaxyClient]
"clientExecutable" = "GalaxyClient.exe"
"Version" = "1.2.44.30"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts]
"Lato Light" = "LatoWeb-Light.ttf"
"Lato Semibold" = "LatoWeb-Semibold.ttf"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7258BA11-600C-430E-A759-27E2C691A335}_is1]
"DisplayIcon" = "%Program Files%\GOG Galaxy\unins000.exe"
"Inno Setup: App Path" = "%Program Files%\GOG Galaxy"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts]
"Lato BoldItalic" = "LatoWeb-BoldItalic.ttf"
"Lato Italic" = "LatoWeb-Italic.ttf"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]
"GalaxyClient" = ""
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7258BA11-600C-430E-A759-27E2C691A335}_is1]
"HelpLink" = "http://www.gog.com/"
[HKCU\Software\Microsoft\RestartManager\Session0000]
"Sequence" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7258BA11-600C-430E-A759-27E2C691A335}_is1]
"Inno Setup: Language" = "English"
"Inno Setup: Icon Group" = "GOG.com"
"NoModify" = "1"
"QuietUninstallString" = "%Program Files%\GOG Galaxy\unins000.exe /SILENT"
[HKLM\SOFTWARE\GOG.com\GalaxyClient\paths]
"client" = "%Program Files%\GOG Galaxy"
[HKCU\Software\Microsoft\RestartManager\Session0000]
"Owner" = "E8 02 00 00 1D 5B 0D 1C 11 07 D4 01"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7258BA11-600C-430E-A759-27E2C691A335}_is1]
"URLInfoAbout" = "http://www.gog.com/"
"Inno Setup: Selected Tasks" = "desktopicon"
"Inno Setup: Deselected Tasks" = ""
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GalaxyClient" = ""
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process wusa.exe:2440 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WUSA]
"WUSACommandLine" = "/quiet"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WUSA]
"WUSACommandLine"
The process vcredist_x86_2015.exe:568 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}]
"Installed" = "1"
"UninstallString" = "C:\ProgramData\Package Cache\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\VC_redist.x86.exe /uninstall"
[HKCR\Installer\Dependencies\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}]
"Version" = "14.0.24212.0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}]
"NoElevateOnModify" = "1"
"DisplayName" = "Microsoft Visual C 2015 Redistributable (x86) - 14.0.24212;"
"QuietUninstallString" = "C:\ProgramData\Package Cache\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\VC_redist.x86.exe /uninstall /quiet"
"EstimatedSize" = "21246"
"BundleTag" = "Type: REG_SZ, Length: 0"
"Publisher" = "Microsoft Corporation"
[HKCR\Installer\Dependencies\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}]
"DisplayName" = "Microsoft Visual C 2015 Redistributable (x86) - 14.0.24212"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}]
"DisplayIcon" = "C:\ProgramData\Package Cache\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\VC_redist.x86.exe,0"
"BundleResumeCommandLine" = " /quiet /norestart /burn.log.append C:\Users\"%CurrentUserName%"\AppData\Local\Temp\dd_vcredist_x86_20180618173208.log /install"
"DisplayVersion" = "14.0.24212.0"
"ModifyPath" = "C:\ProgramData\Package Cache\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\VC_redist.x86.exe /modify"
"BundleAddonCode" = "Type: REG_MULTI_SZ, Length: 0"
"BundlePatchCode" = "Type: REG_MULTI_SZ, Length: 0"
"BundleVersion" = "14.0.24212.0"
"BundleUpgradeCode" = "{F899BAD3-98ED-308E-A905-56B5338963FF}"
"Resume" = "1"
"BundleDetectCode" = "Type: REG_MULTI_SZ, Length: 0"
[HKCR\Installer\Dependencies\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}]
"(Default)" = "{462f63a8-6347-4894-a1b3-dbfe3a4c981d}"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}]
"BundleProviderKey" = "{462f63a8-6347-4894-a1b3-dbfe3a4c981d}"
"EngineVersion" = "3.7.3813.0"
"BundleCachePath" = "C:\ProgramData\Package Cache\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\VC_redist.x86.exe"
[HKCU\Software\Classes\Local Settings\MuiCache\63\52C64B7E]
"LanguageList" = "en-US, en"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"{462f63a8-6347-4894-a1b3-dbfe3a4c981d}" = "C:\ProgramData\Package Cache\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\VC_redist.x86.exe /burn.runonce"
The Trojan deletes the following value(s) in system registry:
[HKCR\Installer\Dependencies\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\Dependents\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}]
"MinVersion"
[HKCR\Installer\Dependencies\Microsoft.VS.VC_RuntimeAdditionalVSU_x86,v14\Dependents\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}]
"MaxVersion"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}]
"BundleResumeCommandLine"
[HKCR\Installer\Dependencies\Microsoft.VS.VC_RuntimeMinimumVSU_x86,v14\Dependents\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}]
"MaxVersion"
[HKCR\Installer\Dependencies\Microsoft.VS.VC_RuntimeAdditionalVSU_x86,v14\Dependents\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}]
"MinVersion"
[HKCR\Installer\Dependencies\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\Dependents\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}]
"MaxVersion"
[HKCR\Installer\Dependencies\Microsoft.VS.VC_RuntimeMinimumVSU_x86,v14\Dependents\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}]
"MinVersion"
The Trojan disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"{462f63a8-6347-4894-a1b3-dbfe3a4c981d}"
Dropped PE files
MD5 | File path |
---|---|
051806a689df6f8a161ec49096f0645e | c:\Users\All Users\GOG.com\Galaxy\redists\GalaxyCommunication.exe |
e92bf16bbee171dfe52269d04b5c7b23 | c:\Users\All Users\GOG.com\Galaxy\redists\GalaxyUpdater.exe |
ec33d4e29d36b8260bc43395a0b7fcb9 | c:\Users\All Users\GOG.com\Galaxy\redists\PocoCrypto.dll |
eea146bd5b1bb3ca60d58d92d79c1137 | c:\Users\All Users\GOG.com\Galaxy\redists\PocoData.dll |
26aab4650091608fac3714196d2b1e92 | c:\Users\All Users\GOG.com\Galaxy\redists\PocoDataSQLite.dll |
e0d5538cc5a029e20a405189ee5d6519 | c:\Users\All Users\GOG.com\Galaxy\redists\PocoFoundation.dll |
a9fabd0b69f5db85d52ceed2964e6227 | c:\Users\All Users\GOG.com\Galaxy\redists\PocoJSON.dll |
6320aa1e39c2a6578eb25b17604cbb08 | c:\Users\All Users\GOG.com\Galaxy\redists\PocoNet.dll |
1f8695e069e24a4a333ca69943468d9d | c:\Users\All Users\GOG.com\Galaxy\redists\PocoNetSSL.dll |
b43ad746ad91ed76bee464adc457167c | c:\Users\All Users\GOG.com\Galaxy\redists\PocoUtil.dll |
a78d096c36623a0326b012afe93655bf | c:\Users\All Users\GOG.com\Galaxy\redists\PocoXml.dll |
6dc356a56c9ba8aff52a5176df8f506c | c:\Users\All Users\GOG.com\Galaxy\redists\PocoZip.dll |
cca9f43984cef5f8a1c08a6c6be44dae | c:\Users\All Users\GOG.com\Galaxy\redists\Qt5Core.dll |
05400007bb86287b242f4aa55d19f0ff | c:\Users\All Users\GOG.com\Galaxy\redists\expat.dll |
a653fd46758f67879ae3137f8d8d2fe9 | c:\Users\All Users\GOG.com\Galaxy\redists\libeay32.dll |
ffb526f1ad415dc13b282dc89194561d | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\GalaxyOverlay.exe |
faeecab8174eac86b4af6992bce41e58 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\chrome_elf.dll |
e16ca76a141de63a7ca661e489f91e7e | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\d3dcompiler_47.dll |
949773209f457203790d393226e89e64 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\overlay_injector_Win32_Release.exe |
8ed95787713af45327361ba675210b23 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\overlay_injector_Win32_ReleaseWithLogging.exe |
14a3ecbd11a49698af04b94866aec8a9 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\overlay_injector_x64_Release.exe |
2a1455e5397be47a3c887b3ec7d2649f | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\overlay_injector_x64_ReleaseWithLogging.exe |
6f05619c12d7d0a0966264d94f49f1db | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\overlay_mediator_Win32_Release.dll |
286a45a8fcaad2df0c61714a1fd2d8ab | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\overlay_mediator_Win32_ReleaseWithLogging.dll |
6448e8c9dec55345be9566100846dfe3 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\overlay_mediator_x64_Release.dll |
f6e77633ad1801e3e4a9c1308aca419d | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\overlay_mediator_x64_ReleaseWithLogging.dll |
217f4f0b90dde3ea11484572f59de1ea | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydinput_Win32_Release.dll |
d8d7941bba3d88f58afcb1780183c7c2 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydinput_Win32_ReleaseWithLogging.dll |
c4ceb9a1270fc8ea55a719d8ce94e47d | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydinput_x64_Release.dll |
78cff9188b14588ffd9d959ad3101ab5 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydinput_x64_ReleaseWithLogging.dll |
b8613e0c5cf98e7849db96f9d785e2df | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx10_Win32_Release.dll |
f0f46cca89ef7042db9e52da0c2fc8be | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx10_Win32_ReleaseWithLogging.dll |
41898dc21393fabb4c259f39ceb46640 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx10_x64_Release.dll |
69f4638c62b54683ce55d99c25c34b5f | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx10_x64_ReleaseWithLogging.dll |
38dedfe8ec885cdb6f659b2eb65b80fd | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx11_Win32_Release.dll |
5ba91501307ae9fcea1a98c6e2fddbb6 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx11_Win32_ReleaseWithLogging.dll |
1eb11a1ab97fd5918cd0551283476de0 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx11_x64_Release.dll |
e302381bdf36a9c058d1ac286547f2a9 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx11_x64_ReleaseWithLogging.dll |
b2d9b7275143d9f4bacb5dcdb5cfac7e | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx12_Win32_Release.dll |
c76ee77d33fffb6942a13158839fc863 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx12_Win32_ReleaseWithLogging.dll |
6aa3fd2ab55b918910f322667511597f | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx12_x64_Release.dll |
8e887995f228e5d397fd639a484f8de4 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx12_x64_ReleaseWithLogging.dll |
7b72d0c607fc5a273ecb88ad49e96b84 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx8_Win32_Release.dll |
bc8c28d7fdf52f62165fd24ea81b02a8 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx8_Win32_ReleaseWithLogging.dll |
9f63d5b30197f5dda5db302dd5e54e10 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx8_x64_Release.dll |
d702d2f1db723d51e8ae06f2df3c68f4 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx8_x64_ReleaseWithLogging.dll |
f9b588878314f7e56cddfaa9f6fc7ddf | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx9_Win32_Release.dll |
11a905a6663d2cc6c70343c0e6207033 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx9_Win32_ReleaseWithLogging.dll |
f498d9956e82c9aa36b7167b48feed9a | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx9_x64_Release.dll |
be3da3cd839344db66dc643531951b99 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxydx9_x64_ReleaseWithLogging.dll |
9cd2a6b6e1a424796f033bcaf9d5e5b1 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxyopengl_Win32_Release.dll |
910fb50346bc53b3096057b2cbe80f9c | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxyopengl_Win32_ReleaseWithLogging.dll |
248b0e44dacb8ee0f6489fcfca6a4dbe | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxyopengl_x64_Release.dll |
db640ace0363f90179e7c0e716d342a6 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxyopengl_x64_ReleaseWithLogging.dll |
2ac08087704a53b3114e82c23dbbae4b | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxyuser32_Win32_Release.dll |
0207af5e940da9d6b642f346120f2182 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxyuser32_Win32_ReleaseWithLogging.dll |
1e8abda59650b2c58569c4398b4e4871 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxyuser32_x64_Release.dll |
a006ed220f32c54e99d48840fbf16af4 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxyuser32_x64_ReleaseWithLogging.dll |
38eb58c7f0731f5ebe11654340ddfbe1 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxyxinput_Win32_Release.dll |
1a8366c4ceb26e100b4bc18c9367be17 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxyxinput_Win32_ReleaseWithLogging.dll |
2cd92d6e4588ff269f52fa1148315d96 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxyxinput_x64_Release.dll |
f2f35a735467084a6410bf1fc98483e4 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\proxyxinput_x64_ReleaseWithLogging.dll |
be70e941a4abf2bb1f5d050e403d0a44 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\swhx_injection_helper_Win32_Release.dll |
308bcf3641264591341678515ccbb96e | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\swhx_injection_helper_Win32_ReleaseWithLogging.dll |
69220755b059a597b085c72da29beb0c | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\swhx_injection_helper_x64_Release.dll |
f63d976876ff817dd84a8e3be57e9ffa | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\injected\swhx_injection_helper_x64_ReleaseWithLogging.dll |
2e276df2227b7797256084920c452294 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\libEGL.dll |
2e5057c98a48db72cd2df6c93f84c0e4 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\libGLESv2.dll |
fd11791338e5b6497a827dc3c2a25da0 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\libcef.dll |
2397cb0a7d4f611b521a23e8e3b22424 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\vs2015-redist-x64.exe |
3a1b6b38253f9641f7784197538f4215 | c:\Users\All Users\GOG.com\Galaxy\redists\overlay\widevinecdmadapter.dll |
f4012e091c491efe3e5115471429a25b | c:\Users\All Users\GOG.com\Galaxy\redists\pcre.dll |
7e031c397a146c911d0728ed2900c565 | c:\Users\All Users\GOG.com\Galaxy\redists\peer\msvc-15\GalaxyPeer.dll |
46e9f55d411b57a7b4a9bb411f52d3b1 | c:\Users\All Users\GOG.com\Galaxy\redists\peer\msvc-15\GalaxyPeer64.dll |
bf3c8cf98812d3a49ea0bf6d8c9f86a7 | c:\Users\All Users\GOG.com\Galaxy\redists\peer\msvc-16\GalaxyPeer.dll |
3e809d3a85772a63dfa07e841b014d37 | c:\Users\All Users\GOG.com\Galaxy\redists\peer\msvc-16\GalaxyPeer64.dll |
f7ab2e7854e804f31bc4be3b8107f792 | c:\Users\All Users\GOG.com\Galaxy\redists\peer\msvc-17\GalaxyPeer.dll |
0680f8f241d2b5db58e9563a8012ec85 | c:\Users\All Users\GOG.com\Galaxy\redists\sqlite.dll |
3652630987071d96781c1246ae4a2c10 | c:\Users\All Users\GOG.com\Galaxy\redists\ssleay32.dll |
ea21596b1b0f62ccd928d5ec0530ac83 | c:\Users\All Users\GOG.com\Galaxy\redists\zlib.dll |
2769fb47fb3bb36ef22c3b224b3ab36c | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\GalaxyInstaller.exe |
43a0bdf173d8feb193f4f2c07b0f3be1 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\GalaxySetup.exe |
5b6f4c585ce1796d5576fabbaf0e9310 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\de\GalaxyWebInstaller.resources.dll |
e75e8b1eb7d011b6bdba5d885373df6d | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\fr\GalaxyWebInstaller.resources.dll |
8bf0f7e679dfd24358d372918be4c217 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\pl\GalaxyWebInstaller.resources.dll |
c76fe7c5ab682f00cb295c9426c638e3 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\pt-BR\GalaxyWebInstaller.resources.dll |
8ac7be76606fa766827074dc87ecda87 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\ru\GalaxyWebInstaller.resources.dll |
564bfa844cf820ee3d14777503ac729d | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\zh\GalaxyWebInstaller.resources.dll |
f5988310ab7033ce16421f8223d62499 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-1D2BU.tmp\GalaxySetup.tmp |
77d6d961f71a8c558513bed6fd0ad6f1 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-LBUP5.tmp\_isetup\_isdecmp.dll |
295832fa6400cb3407cfe84b06785531 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-LBUP5.tmp\botva2.dll |
1c55ae5ef9980e3b1028447da6105c75 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-LBUP5.tmp\innocallback.dll |
1b3d24a3e9c99e63391a53b9e5be5356 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-LBUP5.tmp\vcredist_x86_2015.exe |
4d20a950a3571d11236482754b4a8e76 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\wixstdba.dll |
01361b8b05ceb9da8bcef07c110e5a6d | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.be\VC_redist.x86.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name: GOG Sp. z o.o.
Product Name: Real Myst Masterpiece Edition
Product Version: 1.0.0.0
Legal Copyright: (C) GOG Sp. z o.o. 2018
Legal Trademarks:
Original Filename: GalaxyWebinstaller.exe
Internal Name: GalaxyWebinstaller.exe
File Version: 1.0.0.0
File Description: Real Myst Masterpiece Edition
Comments:
Language: English (United Kingdom)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
UPX0 | 4096 | 585728 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
UPX1 | 589824 | 307200 | 306688 | 5.49814 | 8547d98d062b978b63bb7f20c82a7db4 |
.rsrc | 897024 | 106496 | 102912 | 5.46178 | 719511ef9529a9fee7d9657643ffc3e2 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
URL | IP |
---|---|
hxxp://cs9.wac.phicdn.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh/sBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o+tuynXIiEOLckvPvJE= | |
hxxp://tools.l.google.com/edgedl/release2/update2/LRsxN5n35Q8_1.3.33.17/GoogleUpdateSetup.exe | |
hxxp://r5.sn-q5u5bgv02-3c2z.gvt1.com/edgedl/release2/update2/LRsxN5n35Q8_1.3.33.17/GoogleUpdateSetup.exe?cms_redirect=yes&mip=77.222.144.250&mm=28&mn=sn-q5u5bgv02-3c2z&ms=nvh&mt=1529331714&mv=u&pcm2cms=yes&pl=24&shardbypass=yes | |
hxxp://cs9.wac.phicdn.net/DigiCertGlobalRootCA.crl | |
hxxp://rvip1.ue.cachefly.net/DigiCertGlobalRootCA.crl | |
hxxp://a1363.dscg.akamai.net/pki/crl/products/microsoftrootcert.crl | |
hxxp://a1363.dscg.akamai.net/pki/crl/products/MicCodSigPCA_08-31-2010.crl | |
hxxp://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl | 77.222.148.96 |
hxxp://crl3.digicert.com/DigiCertGlobalRootCA.crl | 93.184.220.29 |
hxxp://r5---sn-q5u5bgv02-3c2z.gvt1.com/edgedl/release2/update2/LRsxN5n35Q8_1.3.33.17/GoogleUpdateSetup.exe?cms_redirect=yes&mip=77.222.144.250&mm=28&mn=sn-q5u5bgv02-3c2z&ms=nvh&mt=1529331714&mv=u&pcm2cms=yes&pl=24&shardbypass=yes | 80.91.179.80 |
hxxp://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl | 77.222.148.96 |
hxxp://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh/sBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o+tuynXIiEOLckvPvJE= | 93.184.220.29 |
hxxp://crl4.digicert.com/DigiCertGlobalRootCA.crl | 66.225.197.197 |
hxxp://redirector.gvt1.com/edgedl/release2/update2/LRsxN5n35Q8_1.3.33.17/GoogleUpdateSetup.exe | 172.217.18.174 |
cdn.gog.com | 192.229.220.97 |
tools.google.com | 172.217.18.174 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET POLICY PE EXE or DLL Windows file download HTTP
Traffic
Web Traffic was not found.
The Trojan connects to the servers at the folowing location(s):
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
GoogleUpdate.exe:3584
GoogleUpdate.exe:2592
GalaxyInstaller.exe:3832
%original file name%.exe:3412
GalaxySetup.tmp:744
wusa.exe:2440
vcredist_x86_2015.exe:568
vcredist_x86_2015.exe:1736
vs2015-redist-x64.exe:3528
GalaxySetup.exe:1872 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
C:\ProgramData\GOG.com\Galaxy\logs\InstallerWebinstaller.log (751 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\GalaxySetup.exe (6362246 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6 (434 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\69C6F6EC64E114822DF688DC12CDD86C (372 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6DB145CFEEC544B1582FED1ADA3370DD (320 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6DB145CFEEC544B1582FED1ADA3370DD (531 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\1.0[1].0 (729 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar255B.tmp (2712 bytes)
C:\ProgramData\GOG.com\Galaxy\logs\InstallerBootstrapper.log (5278 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6 (471 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab255A.tmp (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\GalaxyInstaller.exe (61 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\remoteconfig.json (729 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\69C6F6EC64E114822DF688DC12CDD86C (531 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GalaxyInstaller\icon.ico (4210 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-RUC54.tmp (15 bytes)
%Program Files%\GOG Galaxy\is-VO01K.tmp (3073 bytes)
%Program Files%\GOG Galaxy\web\images\gwentBanner\is-9H0L2.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\js\is-R57NG.tmp (6841 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-8VM2P.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-M5FBM.tmp (9605 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\es-MX\is-RHEDD.tmp (56 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-1Q746.tmp (37 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-R7MT9.tmp (1425 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-DCPO9.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-8SLP8.tmp (44 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-78RP5.tmp (1281 bytes)
%Program Files%\GOG Galaxy\web\locales\es-ES\is-EQHNL.tmp (56 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-IRLCE.tmp (39 bytes)
%Program Files%\GOG Galaxy\unins000.dat (23634 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-D3CI0.tmp (3073 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-VOEAC.tmp (38 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\fr-FR\is-HIVD8.tmp (1 bytes)
%Program Files%\GOG Galaxy\is-S8PKF.tmp (1425 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-7UPVL.tmp (52 bytes)
%Program Files%\GOG Galaxy\web\is-H921P.tmp (909 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-OPJ8V.tmp (7971 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-IKVOP.tmp (13122 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-7NPH7.tmp (59 bytes)
%Program Files%\GOG Galaxy\web\locales\es-MX\is-EKUA6.tmp (56 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com\GOG Galaxy\GOG Galaxy.lnk (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\pt-BR\is-CQFO1.tmp (981 bytes)
%Program Files%\GOG Galaxy\platforms\is-4MMFU.tmp (7385 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-H7S3A.tmp (26 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-R4HAA.tmp (114989 bytes)
C:\Windows\Fonts\is-8JARL.tmp (4185 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-LBUP5.tmp\botva2.dll (64 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\pt-PT\is-8SJ09.tmp (54 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-ELDPT.tmp (61370 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\ja-JP\is-T0L5C.tmp (60 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-5FFO5.tmp (58 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-LTLKU.tmp (51 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-HTN8S.tmp (39 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-8JP2R.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\styles\client\is-S9BIL.tmp (20 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-KA6JD.tmp (7433 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-JFSGB.tmp (3 bytes)
%Program Files%\GOG Galaxy\web\images\gwentLogo\is-33D0R.tmp (21 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-P1OEL.tmp (1425 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-MFFVN.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-LM3RM.tmp (517726 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-RJOIS.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\js\is-4LNET.tmp (3073 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-IBVA5.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-6RPRH.tmp (59 bytes)
C:\Windows\Fonts\is-99NB0.tmp (4185 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-ETCND.tmp (13 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-9GC8E.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-33CHM.tmp (76782 bytes)
%Program Files%\GOG Galaxy\web\styles\client\is-ABOVH.tmp (48 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-6HR7S.tmp (2321 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-70LL1.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-VA64H.tmp (2 bytes)
%Program Files%\GOG Galaxy\web\audio\is-C71U3.tmp (4185 bytes)
%Program Files%\GOG Galaxy\is-C62G8.tmp (13122 bytes)
%Program Files%\GOG Galaxy\locales\is-G21KO.tmp (1281 bytes)
C:\Windows\Fonts\is-L4ASO.tmp (4185 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-RFQ3I.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-4OHVM.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-P9QC0.tmp (39 bytes)
%Program Files%\GOG Galaxy\is-0TDCO.tmp (2321 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-JT8IJ.tmp (176 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-S9DGI.tmp (1281 bytes)
%Program Files%\GOG Galaxy\is-HMC0O.tmp (2105 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-BVCMS.tmp (26 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-2M131.tmp (63 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-BKBMD.tmp (601 bytes)
%Program Files%\GOG Galaxy\is-L8MRA.tmp (33350 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-5CTK6.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\locales\fr-FR\is-C9MG6.tmp (59 bytes)
%Program Files%\GOG Galaxy\web\fonts\is-2U4IT.tmp (4185 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-AM0LM.tmp (46 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-VJIM1.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-FUNEP.tmp (4545 bytes)
%Program Files%\GOG Galaxy\is-QI6PF.tmp (30812 bytes)
%Program Files%\GOG Galaxy\locales\is-88PVE.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-MVD9G.tmp (40 bytes)
%Program Files%\GOG Galaxy\is-DE8HA.tmp (4545 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\it-IT\is-04644.tmp (55 bytes)
%Program Files%\GOG Galaxy\locales\is-M38SK.tmp (673 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\ru-RU\is-T52QN.tmp (1 bytes)
%Program Files%\GOG Galaxy\web\locales\en-US\is-KREOP.tmp (54 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-9L42N.tmp (2 bytes)
C:\Windows\Fonts\is-IFKS0.tmp (4185 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-C911P.tmp (13 bytes)
%Program Files%\GOG Galaxy\web\locales\pl-PL\is-7HKMB.tmp (57 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\fr-FR\is-KL4FN.tmp (59 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-12QAB.tmp (1281 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-CVD1T.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-84JFA.tmp (57 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-18\is-5TU2S.tmp (110924 bytes)
%Program Files%\GOG Galaxy\web\locales\ja-JP\is-VBIOB.tmp (924 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-FRT8U.tmp (9605 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-187O0.tmp (1281 bytes)
%Program Files%\GOG Galaxy\web\locales\es-MX\is-O8DJQ.tmp (916 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-P2KQM.tmp (50 bytes)
%Program Files%\GOG Galaxy\web\locales\zh-Hant\is-RIIPS.tmp (54 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\en-US\is-D3FMH.tmp (54 bytes)
%Program Files%\GOG Galaxy\web\fonts\is-2K8KR.tmp (4185 bytes)
%Program Files%\GOG Galaxy\is-UI57V.tmp (4545 bytes)
%Program Files%\GOG Galaxy\licences\Boost C Libraries\is-A65VS.tmp (1 bytes)
%Program Files%\GOG Galaxy\is-QV0JU.tmp (1425 bytes)
%Program Files%\GOG Galaxy\web\images\gogGalaxyLogo\is-NO04O.tmp (17 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-Q198Q.tmp (38 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-15\is-94UMK.tmp (82840 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\pl-PL\is-9E927.tmp (57 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-1UPTB.tmp (22 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-Q8PIR.tmp (41 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-R4G6L.tmp (26 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-9QBUT.tmp (37 bytes)
C:\Windows\Fonts\is-6JQML.tmp (4185 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-1K03T.tmp (1425 bytes)
%Program Files%\GOG Galaxy\is-CAMFS.tmp (7971 bytes)
%Program Files%\GOG Galaxy\web\is-S4DVE.tmp (1425 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-5CSC3.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\audio\is-U3BMB.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-HPCF6.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-TU2QD.tmp (10 bytes)
%Program Files%\GOG Galaxy\web\is-KHJLI.tmp (1 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-8GGV7.tmp (54 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-LBUP5.tmp\vcredist_x86_2015.exe (108599 bytes)
%Program Files%\GOG Galaxy\unins000.msg (654 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-QHNQP.tmp (2 bytes)
%Program Files%\GOG Galaxy\is-KSVHJ.tmp (4545 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-837K2.tmp (50 bytes)
%Program Files%\GOG Galaxy\web\is-CTNU2.tmp (14 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-BISQ7.tmp (59 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-GA1A1.tmp (3361 bytes)
%Program Files%\GOG Galaxy\is-Q7ODU.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-EEU5A.tmp (28 bytes)
%Program Files%\GOG Galaxy\is-3NUN2.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-QRO7U.tmp (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-LBUP5.tmp\innocallback.dll (65 bytes)
%Program Files%\GOG Galaxy\licences\LatoWeb Font\is-N7NF3.tmp (4 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-V5EGS.tmp (22575 bytes)
%Program Files%\GOG Galaxy\web\is-6K6QJ.tmp (37 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\pl-PL\is-7GTTF.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-71NS2.tmp (35 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-V1GEK.tmp (14 bytes)
%Program Files%\GOG Galaxy\web\locales\it-IT\is-JDQ5Q.tmp (55 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-A4TOQ.tmp (35 bytes)
%Program Files%\GOG Galaxy\web\images\gogGalaxyLogo\is-CLHSH.tmp (4 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-7C0AN.tmp (3073 bytes)
%Program Files%\GOG Galaxy\web\styles\client\is-G2S02.tmp (673 bytes)
%Program Files%\GOG Galaxy\locales\is-H3N24.tmp (1281 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-0Q7VI.tmp (2 bytes)
%Program Files%\GOG Galaxy\web\images\gogGalaxyLogo\is-F44CS.tmp (10 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-6I2E5.tmp (53 bytes)
%Program Files%\GOG Galaxy\is-01R46.tmp (38249 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-DAFTO.tmp (2321 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-020J9.tmp (21 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-LO0T4.tmp (49 bytes)
%Program Files%\GOG Galaxy\web\images\gwentBanner\is-0D1GB.tmp (673 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-KL6KQ.tmp (673 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\zh-Hans\is-7BRGN.tmp (54 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-CKCE2.tmp (2321 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-7SDPF.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-1K4L6.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-2II99.tmp (673 bytes)
%Program Files%\GOG Galaxy\locales\is-L7E4J.tmp (1281 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-76D1O.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-QT67A.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\locales\pl-PL\is-371IV.tmp (1 bytes)
%Program Files%\GOG Galaxy\is-IAQLK.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\styles\overlay\is-G2JG9.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-2D61S.tmp (23062 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-LBUP5.tmp\_isetup\_isdecmp.dll (48 bytes)
%Program Files%\GOG Galaxy\is-R6G78.tmp (34583 bytes)
%Program Files%\GOG Galaxy\is-ECG7S.tmp (5873 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\zh-Hant\is-FJQER.tmp (54 bytes)
%Program Files%\GOG Galaxy\web\images\gwentLogo\is-PMBFU.tmp (7 bytes)
%Program Files%\GOG Galaxy\is-PR68G.tmp (2321 bytes)
C:\Users\Public\Desktop\GOG Galaxy.lnk (999 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-JIJRT.tmp (673 bytes)
%Program Files%\GOG Galaxy\web\images\gogGalaxyLogo\is-8KOVQ.tmp (7 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\de-DE\is-6704P.tmp (57 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-76JCE.tmp (2 bytes)
%Program Files%\GOG Galaxy\web\is-AM1JJ.tmp (8 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-NSFB7.tmp (39 bytes)
%Program Files%\GOG Galaxy\locales\is-UI5LQ.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-K56D5.tmp (59 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-581M2.tmp (673 bytes)
%Program Files%\GOG Galaxy\is-EAF21.tmp (1425 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-E30BI.tmp (37 bytes)
%Program Files%\GOG Galaxy\web\locales\ru-RU\is-R1SQR.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-LH1DO.tmp (33350 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-07EDC.tmp (1281 bytes)
%Program Files%\GOG Galaxy\locales\is-UKBV9.tmp (1281 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-TOABH.tmp (13 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-FDHSF.tmp (5 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-N9CMU.tmp (35505 bytes)
%Program Files%\GOG Galaxy\is-TSJ6B.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\locales\ja-JP\is-H549C.tmp (60 bytes)
C:\Windows\Fonts\is-DP3Q8.tmp (4185 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-S14ET.tmp (38 bytes)
%Program Files%\GOG Galaxy\web\locales\en-US\is-47SLT.tmp (916 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-18\is-8U9UO.tmp (85228 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-3OCQN.tmp (4 bytes)
%Program Files%\GOG Galaxy\web\styles\client\is-7JINM.tmp (40 bytes)
C:\Windows\Fonts\is-LLC7F.tmp (4185 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-G7HB4.tmp (44 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-UASEI.tmp (13 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-JBAIQ.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\locales\pt-BR\is-LOMN8.tmp (57 bytes)
%Program Files%\GOG Galaxy\web\is-RJO8R.tmp (601 bytes)
%Program Files%\GOG Galaxy\is-E4SJN.tmp (3361 bytes)
%Program Files%\GOG Galaxy\web\locales\de-DE\is-234K0.tmp (57 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-OLC3A.tmp (15 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-5U3FD.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\locales\zh-Hans\is-GK4G7.tmp (54 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-SKS8N.tmp (10 bytes)
%Program Files%\GOG Galaxy\is-0MJIQ.tmp (7726 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-GCR0H.tmp (6841 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-ONLL3.tmp (4185 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-24KQ7.tmp (2321 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-68B77.tmp (8657 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-FV1PJ.tmp (59 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-5S66G.tmp (49 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-GM7VA.tmp (673 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-04DA8.tmp (57 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-UG91F.tmp (54 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-II4OA.tmp (11 bytes)
%Program Files%\GOG Galaxy\locales\is-3INNB.tmp (673 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-8UL9A.tmp (673 bytes)
%Program Files%\GOG Galaxy\licences\POCO C Libraries\is-22DK1.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\en-US\is-12NCS.tmp (916 bytes)
%Program Files%\GOG Galaxy\licences\Chromium Embedded Framework\is-RIUOI.tmp (1 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-G33H8.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-IRM9J.tmp (2321 bytes)
%Program Files%\GOG Galaxy\is-7JBNG.tmp (7433 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\pt-PT\is-9O0IP.tmp (916 bytes)
%Program Files%\GOG Galaxy\is-87DPG.tmp (9605 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\ru-RU\is-F6UTI.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\audio\is-TBIAK.tmp (2105 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-VEMCQ.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-B2K4C.tmp (47 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-BFNJA.tmp (51 bytes)
%Program Files%\GOG Galaxy\is-O8LJ4.tmp (15116 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-17\is-R32TV.tmp (86230 bytes)
%Program Files%\GOG Galaxy\web\images\gwentLogo\is-6E9II.tmp (20 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-IA5TI.tmp (59 bytes)
%Program Files%\GOG Galaxy\imageformats\is-BQOEB.tmp (1281 bytes)
%Program Files%\GOG Galaxy\is-5THVN.tmp (76782 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-GGHSO.tmp (2321 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\css\is-NAMA2.tmp (57 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-UO22F.tmp (40 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-R7ANV.tmp (60 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-BNL5P.tmp (4545 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-VB4ES.tmp (1281 bytes)
%Program Files%\GOG Galaxy\web\audio\is-UH8NR.tmp (2105 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-JD8TR.tmp (22 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-17\is-UMV3I.tmp (112480 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-15\is-O0K3S.tmp (125140 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-M7F32.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\images\gwentBanner\is-JBP07.tmp (1281 bytes)
%Program Files%\GOG Galaxy\is-28QJK.tmp (673 bytes)
%Program Files%\GOG Galaxy\web\locales\pt-BR\is-PFFMT.tmp (981 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-5R569.tmp (3 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-16\is-5L5P8.tmp (85696 bytes)
%Program Files%\GOG Galaxy\is-BBKCC.tmp (1425 bytes)
%Program Files%\GOG Galaxy\web\locales\pt-PT\is-CC18G.tmp (54 bytes)
%Program Files%\GOG Galaxy\licences\JsonCPP\is-44A19.tmp (2 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-P0HV4.tmp (13 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-H292O.tmp (42 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-BDTAI.tmp (45 bytes)
%Program Files%\GOG Galaxy\is-74VLL.tmp (9605 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-04JC7.tmp (58 bytes)
%Program Files%\GOG Galaxy\licences\Apache\is-JSFDC.tmp (9 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-0I73C.tmp (601 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-EGQJU.tmp (14 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-8HLL1.tmp (48 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\de-DE\is-J05GH.tmp (996 bytes)
%Program Files%\GOG Galaxy\licences\zlib\is-4V222.tmp (5 bytes)
%Program Files%\GOG Galaxy\web\styles\client\is-IF6H1.tmp (51 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-3C3I9.tmp (601 bytes)
%Program Files%\GOG Galaxy\licences\QT Libraries\is-R6C7Q.tmp (27 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-FG1IU.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-8A09T.tmp (7726 bytes)
%Program Files%\GOG Galaxy\web\styles\components\findFriendsWindow\is-Q3899.tmp (24 bytes)
%Program Files%\GOG Galaxy\is-GU4OV.tmp (51303 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-TJJPE.tmp (26096 bytes)
%Program Files%\GOG Galaxy\is-419DU.tmp (2321 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-N14J6.tmp (50 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-OOP2B.tmp (52 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-18AOQ.tmp (2321 bytes)
%Program Files%\GOG Galaxy\licences\libcurl\is-S2BVE.tmp (1 bytes)
%Program Files%\GOG Galaxy\is-GIQ01.tmp (517726 bytes)
%Program Files%\GOG Galaxy\web\styles\client\is-BOBIL.tmp (45 bytes)
%Program Files%\GOG Galaxy\licences\OpenSSL\is-VAH9A.tmp (6 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\it-IT\is-LHG6P.tmp (916 bytes)
%Program Files%\GOG Galaxy\web\fonts\is-LB5S1.tmp (4185 bytes)
%Program Files%\GOG Galaxy\web\fonts\is-PLKN9.tmp (4185 bytes)
%Program Files%\GOG Galaxy\web\is-DIKMK.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-HPKGF.tmp (22 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-JIHHI.tmp (2 bytes)
%Program Files%\GOG Galaxy\is-CAOMK.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-1AO3I.tmp (45 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-0K71S.tmp (14 bytes)
%Program Files%\GOG Galaxy\web\is-1UMI2.tmp (1 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-U554V.tmp (31 bytes)
%Program Files%\GOG Galaxy\web\locales\ru-RU\is-31C3R.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-R29GO.tmp (1425 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-NCO68.tmp (48 bytes)
%Program Files%\GOG Galaxy\web\locales\zh-Hans\is-G42A9.tmp (909 bytes)
%Program Files%\GOG Galaxy\is-19HQU.tmp (22575 bytes)
%Program Files%\GOG Galaxy\is-R20EK.tmp (31786 bytes)
%Program Files%\GOG Galaxy\web\locales\de-DE\is-KPB0D.tmp (996 bytes)
%Program Files%\GOG Galaxy\web\styles\common\is-MLA24.tmp (595 bytes)
%Program Files%\GOG Galaxy\web\images\gwentBanner\is-0E8HQ.tmp (26 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-PUGNQ.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-N96G6.tmp (45 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-AUGNL.tmp (14 bytes)
%Program Files%\GOG Galaxy\web\audio\is-S8V8J.tmp (1425 bytes)
%Program Files%\GOG Galaxy\is-T0L4B.tmp (3073 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\ko-KR\is-RF5FD.tmp (54 bytes)
%Program Files%\GOG Galaxy\web\locales\pt-PT\is-8B80M.tmp (916 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-I8JNT.tmp (2105 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-ER4V9.tmp (14 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-94LL9.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-OLD4B.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\ja-JP\is-84IKG.tmp (924 bytes)
%Program Files%\GOG Galaxy\is-5M57H.tmp (673 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-DSK9B.tmp (14 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\pt-BR\is-B6SO1.tmp (57 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-KEN5M.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-RGCD7.tmp (44 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\is-MBDI3.tmp (673 bytes)
%Program Files%\GOG Galaxy\web\images\gwentBanner\is-R6CSK.tmp (54 bytes)
%Program Files%\GOG Galaxy\web\angularLocales\is-AB1LA.tmp (2 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-ANRT4.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\zh-Hans\is-UAOK1.tmp (909 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-SKJT2.tmp (39 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-KQENL.tmp (42 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\is-SCPVT.tmp (30812 bytes)
%Program Files%\GOG Galaxy\web\images\gwentLogo\is-71KTF.tmp (16 bytes)
%Program Files%\GOG Galaxy\web\locales\it-IT\is-U0KL1.tmp (916 bytes)
C:\Windows\Fonts\is-MM1CU.tmp (4185 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\es-MX\is-OT028.tmp (916 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-16\is-8A74G.tmp (114298 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-K8KJV.tmp (1 bytes)
%Program Files%\GOG Galaxy\locales\is-EDUMM.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-JLI41.tmp (39 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-UOTDF.tmp (13 bytes)
%Program Files%\GOG Galaxy\web\locales\es-ES\is-RMGHM.tmp (916 bytes)
C:\ProgramData\GOG.com\Galaxy\changelogs\is-FR5S0.tmp (2 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-5VPA1.tmp (23 bytes)
%Program Files%\GOG Galaxy\web\locales\fr-FR\is-H3ORE.tmp (1 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-VEVDP.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-1UEPS.tmp (56 bytes)
%Program Files%\GOG Galaxy\is-MLSAT.tmp (6841 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Setup Log 2018-06-18 #001.txt (2865136 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\locales\is-SIBMA.tmp (1281 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\es-ES\is-D8DLO.tmp (56 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-BTM6O.tmp (2321 bytes)
%Program Files%\GOG Galaxy\is-QQT9A.tmp (26096 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-LDUAD.tmp (601 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\overlay\injected\is-U63UE.tmp (59 bytes)
C:\ProgramData\GOG.com\Galaxy\redists\web\locales\es-ES\is-GLK0G.tmp (916 bytes)
%Program Files%\GOG Galaxy\web\microserviceMenu\img\is-BEFOO.tmp (13 bytes)
%Program Files%\GOG Galaxy\web\locales\ko-KR\is-CD4HF.tmp (54 bytes)
%Program Files%\GOG Galaxy\is-IT07T.tmp (7547 bytes)
%Program Files%\GOG Galaxy\web\scripts\is-AVTI7.tmp (2105 bytes)
C:\Windows\WindowsUpdate.log (13709 bytes)
C:\989f8654a2a9bdd87e\$dpx$.tmp\de0df680e990594d8bff4484efdf984b.tmp (468 bytes)
C:\989f8654a2a9bdd87e\$dpx$.tmp\27d9f57d6d77e84d879ace4bf2d00ce6.tmp (2552 bytes)
C:\Windows\Logs\DPX\setupact.log (3028 bytes)
C:\989f8654a2a9bdd87e\$dpx$.tmp\476e18042842f849bfd39dd8de4e7dc8.tmp (6722 bytes)
C:\989f8654a2a9bdd87e\$dpx$.tmp\a25f4146e9855344b6c4b2c88ab51598.tmp (444 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab91B3.tmp (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F90F18257CBB4D84216AC1E1F3BB2C76 (550 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar91B4.tmp (2712 bytes)
C:\ProgramData\Package Cache\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\state.rsm (1808 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\696F3DE637E6DE85B458996D49D759AD (732 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7396C420A8E1BC1DA97F1AF0D10BAD21 (554 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\dd_vcredist_x86_20180618173208_001_vcRuntimeAdditional_x86.log (127738 bytes)
C:\ProgramData\Package Cache\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\VC_redist.x86.exe (5873 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F90F18257CBB4D84216AC1E1F3BB2C76 (756 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\696F3DE637E6DE85B458996D49D759AD (781 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7396C420A8E1BC1DA97F1AF0D10BAD21 (912 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\dd_vcredist_x86_20180618173208_000_vcRuntimeMinimum_x86.log (126936 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1029\license.rtf (3284 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\cab54A5CABBE7274D8A22EB58060AAB7623 (16944 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1055\license.rtf (2663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1046\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1041\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\thm.xml (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\vcRuntimeMinimum_x86 (1712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\license.rtf (2722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\2052\license.rtf (2591 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\2052\thm.wxl (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1042\license.rtf (7601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1028\thm.wxl (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1040\license.rtf (2201 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1031\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1040\thm.wxl (577 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\dd_vcredist_x86_20180618173208.log (51040 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1028\license.rtf (2682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1045\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\thm.wxl (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\BootstrapperApplicationData.xml (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\Windows7_MSU_x86 (10528 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1036\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\wixstdba.dll (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.be\VC_redist.x86.exe (106328 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1055\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1031\license.rtf (2050 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\3082\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1049\license.rtf (4025 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1029\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\3082\license.rtf (2303 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1042\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\vcRuntimeAdditional_x86 (2160 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1036\license.rtf (2922 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1045\license.rtf (2597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\logo.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1046\license.rtf (2124 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1041\license.rtf (3662 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\cabB3E1576D1FEFBB979E13B1A5379E0B16 (76515 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\.ba1\1049\thm.wxl (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1031\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1055\license.rtf (2263 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\wixstdba.dll (1890 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1055\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1031\license.rtf (1730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\logo.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1040\license.rtf (1881 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\thm.xml (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\thm.wxl (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\3082\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\2052\thm.wxl (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1040\thm.wxl (497 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1029\license.rtf (2804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\BootstrapperApplicationData.xml (817 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1042\license.rtf (7401 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1046\license.rtf (1804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1045\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1042\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1041\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1046\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1036\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1045\license.rtf (2197 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1029\thm.wxl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1049\thm.wxl (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\dd_vcredist_amd64_20180618173253.log (21751 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1036\license.rtf (2522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1028\license.rtf (2202 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1028\thm.wxl (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\2052\license.rtf (3031 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1049\license.rtf (3465 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\license.rtf (2322 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\1041\license.rtf (4022 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\.ba1\3082\license.rtf (1983 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-1D2BU.tmp\GalaxySetup.tmp (50 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GalaxyClient" = ""
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"{462f63a8-6347-4894-a1b3-dbfe3a4c981d}" = "C:\ProgramData\Package Cache\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\VC_redist.x86.exe /burn.runonce" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.