Threat Database Adware Golden Palace Casino

Golden Palace Casino

By CagedTech in Adware
Published:
Last updated:

Threat Scorecard

Popularity Rank: 3,837
Threat Level: 20 % (Normal)
Infected Computers: 5,494
First Seen: July 24, 2009
Last Seen: September 28, 2026
OS(es) Affected: Windows

The detection of Golden Palace Casino on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational methods, symptoms of infection, and most importantly, steps to remove it from your system.

What Is Golden Palace Casino?

Golden Palace Casino is identified as a Trojan-type threat. Trojans are malicious programs that disguise themselves as legitimate software but are designed to allow unauthorized access to a computer system. They can lead to a variety of harmful activities, including data theft, installation of additional malware, and disruption of system operation. The name "Golden Palace Casino" might suggest a connection to online gaming or casino activities, but it's crucial to understand that the actual functionality and purpose of this malware are far more sinister.

How Golden Palace Casino Operates

Trojan-type threats like Golden Palace Casino typically operate by deceiving users into installing them on their systems. This can happen through various means, such as downloading and executing files from untrusted sources, clicking on malicious links, or opening attachments from spam emails. Once installed, Golden Palace Casino can create a backdoor on the infected system, allowing remote access and control by the attackers. This access can be used for a wide range of malicious activities, including stealing sensitive information, installing ransomware or other types of malware, and using the infected system as part of a botnet for distributed denial-of-service (DDoS) attacks.

Symptoms of Infection

Symptoms of a Golden Palace Casino infection can vary widely, depending on the specific goals of the attackers and the actions they take through the malware. Common indicators of infection include unusual system behavior, such as unexpected crashes, slow performance, or unfamiliar programs and icons appearing on the desktop. Users might also notice unauthorized access to their personal data, unexpected changes in system settings, or the presence of additional malware. In some cases, the infection might not exhibit noticeable symptoms immediately, making regular system monitoring and antivirus scans crucial for early detection.

How to Remove Golden Palace Casino

  1. Enter Safe Mode with Networking: This will help prevent the malware from loading and make it easier to remove. Restart your computer and press the key to access the boot menu (this varies by manufacturer but is often F12, F2, or Del). Select the option to boot into Safe Mode with Networking.
  2. Perform a Full Scan with a Reputable Tool: Use an anti-malware tool like SpyHunter to perform a full scan of your system. This can help identify and remove the Golden Palace Casino malware as well as any other threats that might be present.
  3. Uninstall Suspicious Programs: Go through the list of installed programs on your system and uninstall any that you don't recognize or that were installed around the time the malware was detected.
  4. Reset Your Browser Settings: Malware often makes changes to browser settings, so resetting Chrome, Firefox, Edge, or any other browser you use can help remove unwanted extensions and restore default settings.
  5. Reboot and Re-scan: After taking the above steps, reboot your system to ensure all changes take effect, and then run another scan with your anti-malware tool to confirm that the threat has been removed.

Conclusion

Removing Golden Palace Casino from your system requires a combination of technical knowledge and the right tools. By following the steps outlined above and maintaining vigilance through regular system scans and updates, you can protect your system from this and other malware threats. It's also important to practice safe computing habits, such as avoiding suspicious downloads and links, to prevent future infections. Remember, the key to securing your digital life is a proactive approach to security, coupled with the right strategies for dealing with threats when they arise.

Registry Details

Golden Palace Casino may create the following registry entry or registry entries:

Cookies

The following cookies may be associated with Golden Palace Casino:

goldenpalace
www.goldenpalace

Analysis Report

General information

Family Name: Golden Palace Casino
Signature status: Root Not Trusted

Known Samples

MD5: a00167fe3570881c3e4773ea5abeed27
SHA1: 3fe28c8adeb87245adb7aac30db211ac9c654890
File Size: 1.23 MB, 1234136 bytes
MD5: c3989adc721d39b9fdd92dfeb6666933
SHA1: 8d798900aad0608519143cc33a20518a03091d6d
File Size: 698.97 KB, 698968 bytes
MD5: 14ed9511347504a135e6411cac1039e8
SHA1: 9ad56f4d1b30adf14c041412e097813caec2b679
File Size: 719.50 KB, 719504 bytes
MD5: eef7b3d65e956ceeb9b9088c9762851c
SHA1: 31015297de7944d56e8f2445541da827f23ff5f4
File Size: 699.26 KB, 699256 bytes
MD5: c389a91e4b99a10d15890d64a38c61e5
SHA1: d73e57206a6da3840627ab858a644711545593c6
File Size: 699.90 KB, 699896 bytes
Show More
MD5: efd6cd00c738319ff4e64623a518c6c1
SHA1: ae7c6d0282c5e31f90b8cae79770cc8432092a63
SHA256: 27B22C272FDCDF3F3C2F53B7F7C4E4E91E1295E517E47A0B8198F4286AF43039
File Size: 662.38 KB, 662376 bytes
MD5: d8ca5a8760678020d607f35061e825ca
SHA1: f91924b650939cb1db2fa95e5fc3bf638b7aec9d
SHA256: E7CFAF49EE15D4DDB046618C9856BFF94B49F14BCC753AA427A6AD567E1044AE
File Size: 719.78 KB, 719776 bytes
MD5: 458b6b1ea103569999297fba694acfce
SHA1: e12b4a1761890b2dfa29de27dc5ba3078c73c820
SHA256: EABB180E947AC577D5579DED105B252EAF71DB06C555582891602DC5B0FD7726
File Size: 699.35 KB, 699352 bytes
MD5: 68ac30c6279bd4065b8aaaa2ff2df0fb
SHA1: 223ce4353d5d80a522dfedafa90f7059b2920950
SHA256: BF86E69F452D47580E7CE94DF48E48BE4FBF320BC2A2C1B2046DB09198080910
File Size: 719.67 KB, 719672 bytes
MD5: 482f096196bef76de61ece40a971f588
SHA1: 443058160c94cf85cf994c6833811a399eefe0f0
SHA256: 7505BA3023048153879DC75C8E5112B76D05A8342B63B69CAF7505450D6FFA8C
File Size: 682.35 KB, 682352 bytes
MD5: fc669dbfd3b11662458a79feb3ec2fa9
SHA1: d9174947b3d63962c0d3c807f4612859335b1af5
SHA256: 1CE61AD5648F1EA3DBBBFDCEB62BC3A79A7EFE12C419348EC5B82B28654EB70F
File Size: 699.39 KB, 699392 bytes
MD5: 58742418aa1911241b028a7e8e94b401
SHA1: 177d7e54ac7c3f922cbdb03d3384bfa833eaf74c
SHA256: F092E03FBA86DFC9CAFF6928C4FEA704865E687CE2B610A405D94B225F5E4289
File Size: 720.02 KB, 720016 bytes
MD5: 5dcbf5d2565c2ba37ba229e7c6752d97
SHA1: 238d5741d0419b58485a91807745854bda7b7cbc
SHA256: FB67A2CD912F6E116A833A93D9B262F11EC0B092FBDCB4CF52EA4E0A41E71418
File Size: 695.18 KB, 695176 bytes
MD5: eaeb98f6ae28478cf497b3d87c949aa1
SHA1: 104f8f1d7c31d8a36c2969b5a6a177d8582b7039
SHA256: F017AEB0D8D3A6131F83EBB5875FF211AFFE51F4B44E52095E6D7896BDB3EC31
File Size: 719.60 KB, 719600 bytes
MD5: f9b9b900483340eff8946cfa0b03e35d
SHA1: a35673cdd51987ffc2408c251fab60323a73e2ff
SHA256: 3304CA7A572700C51F0167350C5EAA80182B0818696B36BBCC99904EFA7FA253
File Size: 719.99 KB, 719992 bytes
MD5: 64be24f01c4d788118c94eb293dda9d6
SHA1: 90517119fc67dc917558aa2b3a1d4222dd69df35
SHA256: C7CCE7C01576FDBAAAD31ECB9963F864F035C3F80F3127AEF2592728E798092F
File Size: 301.70 KB, 301696 bytes
MD5: 3390ed139b571dc89e74f798a407ebb6
SHA1: 638bba31252bbbaa8527e947627abe60e8004efd
SHA256: DB463D5C8A943F5926A0C97993F35C9938AF55EA33F226044141153304719181
File Size: 720.19 KB, 720192 bytes
MD5: 6b31e6353550629fd78e280d9fe404aa
SHA1: 98648aa8067acc8cee05195929cbf001add0b856
SHA256: 81F31BC1060E77F04E8EEFA8770A0F84EB4319D995A91E889747879FF16122F8
File Size: 720.59 KB, 720592 bytes
MD5: 52a5a3bacd63cedab941075a89ce6095
SHA1: d1c6454b928327f96709e016abfb4c5091d09f1b
SHA256: 3A6EA1930709409A86C0A78F6064415B054EE1E66FC3EB8063017A291D48A1AD
File Size: 641.35 KB, 641352 bytes
MD5: ace5ada8c15fd97cc5b0c62a8b3332f6
SHA1: 5e6dc11242cb6140e5804f53b6e122530fc865b6
SHA256: 4181CC5C7974ABF7EFA8F32052B2A15FAE6DF70BB50E72B724BD7F50B51656CA
File Size: 626.72 KB, 626720 bytes
MD5: 5848bc8665edeb367aea49c2dbc29720
SHA1: e910524795ec8bf6230224d551a46db29d124db8
SHA256: 2177CE11F2A944ED7994E524D6D82A56F786193E654D29B16BAE8201D92EC2A0
File Size: 695.22 KB, 695224 bytes
MD5: 6083ec9d02dd63630e1e68a6d7aa50bb
SHA1: 7aff91849ce602bcea35a6bce710724a38b5f42e
SHA256: B3FA3FE3C3EC14FC06532BA069897022F298412F033406F73D53217C4A0B131C
File Size: 699.02 KB, 699024 bytes
MD5: e1f01bb5bc2bcf42e086ffe843e7d881
SHA1: b046963708269977beb993578bca7ae817c0b59d
SHA256: 188E93DD8A7A3681D4BFD60A08156BA48117DFC61D0E9FD0E5862EA9BA074B64
File Size: 699.10 KB, 699096 bytes
MD5: 01d9154be8ec6fdb1602d5a07c827c02
SHA1: ae2fbd31631440f76da3c9b0774a7dbe9399c32e
SHA256: 7FA6D1812B268F9468B69308E170C95BAE1FF1721CEE2ABDAFF56F915DB02DC1
File Size: 299.27 KB, 299272 bytes
MD5: ee72e45eb708be0194c5e1ea35c6c7af
SHA1: 58229eb047f382742448e6dfbfb0dd550be95c8d
SHA256: 6E61AF552A8AFDBAE61E5F6FDBBB7D5ABAED6450BD0480852A0C52A4F779279B
File Size: 719.67 KB, 719672 bytes
MD5: 28d4b2f9c65b34a182bdb3ef2592c5df
SHA1: a997483b25feb492118234ac12184fc0272ff5ab
SHA256: E7472936139EAFD8F13FA0D3071F8F73A51D0CC4EA34F9079438906ACDDEDA86
File Size: 719.06 KB, 719056 bytes
MD5: 01d7896d43f9a323bc5140045f5cc180
SHA1: 98ab2f7923f9c853eb6bd29b23ec63cac79c253d
SHA256: B0956272FD855E392BE94E273BBA9CFCBCD16DD38166F97BB6C9E6CE3A27D7AB
File Size: 158.96 KB, 158960 bytes
MD5: b0515a2e03d9e3853771881d8972f72b
SHA1: 527b00b14ab0ac3dbd11bbaf5968acd801131daf
SHA256: 8B5450ABFF9FFE0B459D19959687A637AF2C16CCF63905AB23CB2DBDB60E31E3
File Size: 662.30 KB, 662304 bytes
MD5: 7b44c1b4cb62ac2db5eebf66401371f3
SHA1: 715853ea00b93feddca306cdecf096d494ae2b9d
SHA256: 25A8C9319B934C25F947A540DB563A2E57F53CA5F3F150C2926D86FFE2526381
File Size: 699.14 KB, 699144 bytes
MD5: f2875d5af2d3ed11d86e5a21a1d86e8e
SHA1: 4851e54174c5577d97ee6817db2254147e7fa429
SHA256: 9FB123CF63358037DAC0A54031C5E096F8407C42D896FEB1CE478E955DBDAB33
File Size: 695.21 KB, 695208 bytes
MD5: 641e0c42f3e3c239bb08a40edc0b9a1d
SHA1: 7b831d666ccf2211848fba595340d437f59a5924
SHA256: C40D5E6D653BF2892F9AC1AF8F1FEC6C24E7FAE1D7A6206740696D3D8CA1E8BA
File Size: 720.20 KB, 720200 bytes
MD5: 354ae96f24ba2513eb2af019eb807737
SHA1: 226d747e21d884dd47fcb225335585b837774d7e
SHA256: 0D8CDC7C4AE764F66A4CC9A25057E25B79749ECBCC469028216BF583E21216AA
File Size: 303.26 KB, 303264 bytes
MD5: 3970e1ec3fb53f2fa956be7db39c6f26
SHA1: 623b2ee4bccbcde4088b9f553a53072382fe733b
SHA256: 3E4BAF00B6713014252DB1BE1991F6DC902CF527F1BEE2616DD1E5944FE79697
File Size: 690.90 KB, 690904 bytes
MD5: faae7ab894f61546a3efeb1e9d8b4074
SHA1: 6acbcf2b91fe9ba3875665d70ef80f39c06343f5
SHA256: 2278C201AF8DF0E505795DFDA0C3C943E1404530EE72DB83C7AE00AFD7404E42
File Size: 295.03 KB, 295032 bytes
MD5: 40dc08128df93e006eeb22f6ade6ec59
SHA1: 310bbad149ed4a0eb33811be99d8e2ae67a3fae0
SHA256: 464617A0FBE123A47BFBA50FEC3ED2831770B4378A149B86F9FE84DD4E2F01F2
File Size: 719.71 KB, 719712 bytes
MD5: 61e0f89f16346d9e7cc596ed8927b2f4
SHA1: 23d52b6d5f2102a89f9a6f51eddddf055fbf0b20
SHA256: 7FB6BAE521384ADD84097AFC1BD06EC5071E88EBF2FF6236D7EB883FE32E2513
File Size: 719.98 KB, 719976 bytes
MD5: 36c455b0c3fb28761795897fe6511eac
SHA1: 4b3ad9957ec29e9eaa1f14992da3c36e016b4b03
SHA256: 88F5A17675275119049EDC810A5F8098F54E3B0DC615B3C193701D8D6A7883B3
File Size: 699.38 KB, 699376 bytes
MD5: 809ecd3fbba367c58c8839d9f172d0e5
SHA1: 6649e070cfad6f7819bff765ac566974822b66b5
SHA256: 25F14EF2A7CCEC89A332701A41C66BD397420018C4CB9F7A8691AEB7E66A2364
File Size: 699.38 KB, 699376 bytes
MD5: 4728559715aa827d618715a030f42fee
SHA1: 712ac4c13e6e7503ce266c49b0344bfbc0cda35d
SHA256: BE8800D49593E8C3E6933718113A4D8581E0DCB5E4EC10BDE1561B8178B0526F
File Size: 699.19 KB, 699192 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Random-Logic
File Description
  • Installer
  • Web Installer
File Version
  • 3.5.0.6
  • 3, 7, 0, 28
  • 3, 7, 0, 25
  • 1.1.2.80
  • 1.1.2.79
  • 1.1.2.68
  • 1.1.2.39
  • 1.1.2.33
  • 1.1.2.32
  • 1.1.2.31
Show More
  • 1.1.2.29
  • 1.1.2.25
  • 1.0.0.146
  • 1.0.0.143
  • 1.0.0.123
Internal Name
  • Installer
  • WebInstaller.exe
Legal Copyright
  • Copyright © 2004
Original Filename
  • Installer.exe
  • WebInstaller.exe
Product Name
  • Random-Logic Installer
  • Web Installer
Product Version
  • 3, 7, 0, 28
  • 3, 7, 0, 25
  • 3, 5, 0, 6
  • 1.1.2.80
  • 1.1.2.79
  • 1.1.2.68
  • 1.1.2.39
  • 1.1.2.33
  • 1.1.2.32
  • 1.1.2.31
Show More
  • 1.1.2.29
  • 1.1.2.25
  • 1.0.0.146
  • 1.0.0.143
  • 1.0.0.123

Digital Signatures

Signer Root Status
Everest Gaming Marketing Services Thawte Code Signing CA Root Not Trusted
Ultra Internet Media S A Thawte Code Signing CA Root Not Trusted
Cassava Enterprises (Gibraltar) Limited Thawte Premium Server CA Root Not Trusted
888 Holdings PLC VeriSign Class 3 Public Primary Certification Authority - G5 Root Not Trusted
Cassava Enterprises (Gibraltar) Limited VeriSign Class 3 Public Primary Certification Authority - G5 Root Not Trusted
Show More
Everest Gaming Limited thawte Primary Root CA Root Not Trusted

Block Information

Total Blocks: 2,534
Potentially Malicious Blocks: 1
Whitelisted Blocks: 2,245
Unknown Blocks: 288

Visual Map

? ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? 0 0 ? 0 0 0 ? 0 ? 0 ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? 0 ? ? 0 ? 0 0 ? 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 ? ? ? ? ? ? ? ? x 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? ? 0 0 ? ? ? ? 0 ? 0 ? ? ? ? 0 ? ? 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? 0 0 0 0 ? 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 ? 0 ? ? ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 1 0 0 0 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 1 1 0 3 1 1 0 0 2 3 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 1 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0e33ddbdbddb6f9b.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~df30fb9a9fb499c081.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~df3107cc763952d05c.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~df35b38bae27ae4271.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\documents\pokerinstallerlogs\installer.log Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\pokerinstaller::fullpath c:\users\user\downloads\ae2fbd31631440f76da3c9b0774a7dbe9399c32e_0000299272 RegNtPreCreateKey
HKCU\software\pokerinstaller::installer_guid 28eb42f1-f23a-4fbb-9015-76fe6a92f5e8 RegNtPreCreateKey
HKCU\software\vhld\machine_id::machine_id ꠁ⠭ RegNtPreCreateKey
HKCU\software\casinonetinstaller::installer_guid 4bdb4cc1-5139-4f6c-bc6a-cbf9530259a RegNtPreCreateKey
HKCU\software\casinonetinstaller::fullpath c:\users\user\downloads\98ab2f7923f9c853eb6bd29b23ec63cac79c253d_0000158960 RegNtPreCreateKey
HKCU\software\vhld\machine_id::machine_id 猸㌊ RegNtPreCreateKey
HKCU\software\pokerinstaller::fullpath c:\users\user\downloads\226d747e21d884dd47fcb225335585b837774d7e_0000303264 RegNtPreCreateKey
HKCU\software\pokerinstaller::installer_guid 2bcec370-6f56-49c9-80b-aad19c1f3131 RegNtPreCreateKey
HKCU\software\vhld\machine_id::machine_id ꛸⛔ RegNtPreCreateKey

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Network Wininet
  • InternetConnect
  • InternetOpen
Network Winsock2
  • WSARecv
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • gethostbyname
  • gethostname
  • inet_addr
  • send
  • socket