PUP.MSIL.Brute.AAC

The detection of PUP.MSIL.Brute.AAC on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.MSIL.Brute.AAC?

PUP.MSIL.Brute.AAC is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are often bundled with other software or downloaded from untrusted sources, and they can cause a range of problems, including slowing down your computer, displaying unwanted ads, and potentially leading to more severe security issues.

How PUP.MSIL.Brute.AAC Operates

PUPs like PUP.MSIL.Brute.AAC typically operate by installing themselves on your system and then running in the background, often without your knowledge or consent. They may collect data about your browsing habits, display unwanted ads, or even install additional malware on your system. In some cases, PUPs may also attempt to brute-force passwords or exploit vulnerabilities in your system to gain unauthorized access.

Symptoms of Infection

If your system is infected with PUP.MSIL.Brute.AAC, you may notice a range of symptoms, including slow system performance, unwanted ads or pop-ups, and unexpected changes to your browser settings or homepage. You may also notice that your system is running more slowly than usual or that you are experiencing frequent crashes or freezes. In some cases, you may even notice that your system is being used for unauthorized activities, such as sending spam emails or participating in botnet attacks.

  • Slow system performance
  • Unwanted ads or pop-ups
  • Unexpected changes to browser settings or homepage
  • Frequent crashes or freezes
  • Unauthorized system activity

How to Remove PUP.MSIL.Brute.AAC

  1. Boot your system in Safe Mode with Networking to prevent the PUP from running and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan of your system to detect and remove the PUP and any associated malware.
  3. Uninstall any suspicious programs that may be related to the PUP, taking care to follow the uninstallation instructions carefully to ensure that all components are removed.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any changes made by the PUP.
  5. Reboot your system and run a follow-up scan with your anti-malware tool to ensure that the PUP and any associated malware have been completely removed.

Conclusion

Removing PUP.MSIL.Brute.AAC from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above and taking steps to prevent future infections, you can help to keep your system safe and secure. Remember to always be cautious when downloading software or clicking on links from untrusted sources, and to keep your anti-malware tools up to date to ensure that you are protected against the latest threats.

Analysis Report

General information

Family Name: PUP.MSIL.Brute.AAC
Packers: UPX
Signature status: Modified signature

Known Samples

MD5: 42cf87389d29336fb6de65173750bef8
SHA1: 92950b6303c59accd994b2886218acb44ceb8216
File Size: 491.90 KB, 491896 bytes
MD5: ab622b4f39060e6aa35c2e404275d06d
SHA1: 501b190f8a9ed63b86a97fd266074eedc52a5fe3
File Size: 517.10 KB, 517096 bytes
MD5: ecfa0874e3d805428d27e1cbaed885f4
SHA1: 78b4d7f3ee54c2826356b361052eab3b49544b0a
File Size: 513.40 KB, 513400 bytes
MD5: 883913c32e3295afde4e7156b275110d
SHA1: dd29149cc10334d81a6179b17f43845ae4026dd9
SHA256: E6694BE0390F6A88A02C06536818AFBF7387B481204725E47100E3B04C785D76
File Size: 506.73 KB, 506728 bytes
MD5: 740731e584274a5b54ed85e91af9ec0d
SHA1: 7f4da1f5f800289f47c7e792abcd27f51943271a
SHA256: 30758A8724516EFDF2DD9DF66D8F4CE404304E490755109F41B2F0EF159663F5
File Size: 509.29 KB, 509288 bytes
Show More
MD5: 7c7498a9ac72d7992b6f356c51592fcc
SHA1: 0b6c692679dc89466c5399d0b44e80b11f21506a
SHA256: 74570FA0036DB3735A4B58ABB04A8C6A17456A2BC0F5E2C5DDD512A36FA8DDD8
File Size: 459.23 KB, 459232 bytes
MD5: bd9bcb108208f04b3b5fadecfb43cbb6
SHA1: 5bd156b5c6e0a0de10ea986932d7ff0c4aca8759
SHA256: DEECA6DDBBB8EDE1E7DF1341BD278BE626FBF21605AC3CA47E0EEC87D1BB0ACA
File Size: 507.36 KB, 507360 bytes
MD5: e8921bbb01406bd6951915e090e2379c
SHA1: 172a120098063839fbbeffff2b001254851604fc
SHA256: 3C8A55486A3AE147C0AF0F6D9D7ACBE905B5A9A07A57C17E5F9857AA6FDDFDD8
File Size: 496.50 KB, 496504 bytes
MD5: d5221f1e837de9b26e5ff67df31c7868
SHA1: 23780c218de60f6e7fefbe0e18da381e93d22c44
SHA256: 74C5AEFAD587F3254364C12609FA4B2FE25DCA146544312837BBFB8F25DE2D6C
File Size: 522.10 KB, 522104 bytes
MD5: e85ace567db4d834676279edf92434b7
SHA1: 6789be2f6ffd696c4a1335aa5d24dba709aed2f3
SHA256: C296E8EDC84C771EAF720270C1F37C645BFE9ADBB01871D3A6A9E503F2D0721D
File Size: 521.18 KB, 521184 bytes
MD5: 9d67a71979f2cf33fd0d3431c9b96a22
SHA1: d38a77c44e09c5ae687e3131cd69b99b1629cf58
SHA256: 9C1F281C133A40932A23B96FE9869F781EF3CD6C99C21E0076B65F5FF979CAD2
File Size: 515.45 KB, 515448 bytes
MD5: 0d3c27ba741b84646d1b21a7cf4b98f7
SHA1: 045c956889ffd6d95366905ae1489b0c75eb0dc1
SHA256: 4ADD32E5E2C1B964BB65A20E4491CFB4241557328A29FEA23339A4FC09B7EACF
File Size: 532.09 KB, 532088 bytes
MD5: 9930ad500beaee6d03754d7d7f7b4e2f
SHA1: 6e4ba3ed7378e10060e9f6c02a2633f169d4aed1
SHA256: 10B2535A4EA3AA537593BEEE8964AADFFB9ACA3A090CEDFC29CDD3EEDC3E1A0C
File Size: 504.87 KB, 504872 bytes
MD5: bd790dcd22f86c11f05cf34464e5b23d
SHA1: 3fb417fef73ad67619f65ccdc16178890b53fb1f
SHA256: 3E638F7DEFE2FF6CA05F811BA8C6F7D4385A153A85FF291D81DCB6501834C458
File Size: 501.32 KB, 501320 bytes
MD5: 2a5e9ec331a10f1a80dd3dcbfee55935
SHA1: faac0e906966c8598cfd0be02db1c757a294cac4
SHA256: DC3C12FC6F288F9E913DB8D832123969FE84510BDC826EBC3D98A4E4A40D793D
File Size: 514.94 KB, 514936 bytes
MD5: 9773b544d7ee16f11674475a9857b915
SHA1: e477c76132ac697211e2c2b7a9a539872ced890f
SHA256: 531DDD35736ACA80D59EA3F4B528D50F85EF354FF745A12EEF325CB599108D8E
File Size: 524.26 KB, 524264 bytes
MD5: e2b1ebee52219c37a6e75f7399d36579
SHA1: 6143a0a4d09295ebfe33c1591b01881bee6de886
SHA256: 24DD1D7508797835D4C62ECE461BB629F5CC3CCBCC685DEADAC61771D4BA792E
File Size: 526.71 KB, 526712 bytes
MD5: 154b3102ec4aa7f8b04bdf6f2c4da708
SHA1: 506db760b18888958779422562e3acf8b71578f6
SHA256: 940B98A743F08839655061E956E28712C0A5B82F0EA563778E4CF0DFEA4E046F
File Size: 507.43 KB, 507432 bytes
MD5: e96552d396c66f721ec6ed98eb392d01
SHA1: 5c80da984dd5f942153862d3329e56079da7d669
SHA256: 2A5129C538C4BDFD51CCB41E97C7E2A0D8585320325595200566FF3D047B1010
File Size: 521.18 KB, 521184 bytes
MD5: 1512b490519d2a149aa010c7942395e4
SHA1: 64e383468acbd6aacf7ddc4fcc7c16faa932c4ec
SHA256: D340B3391E69F9CCE425CF5158E98E9FFF9740710145B065117F2DF22766254D
File Size: 473.18 KB, 473184 bytes
MD5: 68e56e1bea59df33cf4819f9960e3488
SHA1: f88ae7012129acc717770e65c0584e1aacc9560f
SHA256: B0340975DF97628F59F04B3CD5F1EB6BA1AE3C06CED71962F6B4EF1C6EDE9E80
File Size: 528.42 KB, 528424 bytes
MD5: 5a14a9a4ba7812330ff0db3beb9b9907
SHA1: 2b5ffbb696be74f42951376aabb0505ddf712e3e
SHA256: 06E84FF7184DC800B082297C8C5E9D5C2B53F251D46A1630C8C2120D2278F906
File Size: 506.73 KB, 506728 bytes
MD5: b0ea679921808e48252ea8f3b5b0bc6a
SHA1: b670bc59a3cb76f1b6fe7f9675c4bddab6d5c2fd
SHA256: A14E75511ED39072B549C6CE6D588139C2C40EF8EC3E084A9131AA6F5A428F57
File Size: 502.24 KB, 502240 bytes
MD5: fc8a3a1731ef1763c8ad8e5511d10123
SHA1: cbf3ebdbf600d719dc81c7c915180af578a5eecc
SHA256: A66B175884BDF38677CEA13DEE1CFCA4390B91E29A5954E2DC4E543FA038736A
File Size: 510.94 KB, 510944 bytes
MD5: 488c943f779ebb5a540a16f361f21a01
SHA1: 1dc1206166407d66c1c21a8f2fc254e020dc691e
SHA256: 5E5E2EA8167E09CE9657EB5201D3D451CF9CDC4F2381ABAA887F7B5B8F022E31
File Size: 466.02 KB, 466016 bytes
MD5: 90f0c9cf5eb6ea3cef6fa9c9c860075b
SHA1: 8f0bf3e46f85356c61d33d0e66a51de4a340d7fe
SHA256: 00548CBC308347E90F3102DA55B473D664B010CEFDAC4A5ECF03E2827FD9E490
File Size: 514.54 KB, 514536 bytes
MD5: fabdcb2c145871e7bfbc282b5b9655d2
SHA1: e771460ee8cb722b2d9c240fddf0b67c5feca81e
SHA256: 2712750B65A37509B6F3EE398B31648B1A089BB3562DD53ED416440D45C549AC
File Size: 492.92 KB, 492920 bytes
MD5: 0b0054dce586f33bb3a7aae6235d237d
SHA1: 94b31d5fa87fbafae284334d83bbb4fc848efc0a
SHA256: 3ADEC9A5085FBB14CE8CA7B987443206932D3BA3BCCED2B332E25AE49D64BDB0
File Size: 517.50 KB, 517496 bytes
MD5: 24c62c07b4dbaaf49e530f98bef353e6
SHA1: 6ecf3412f136f3cd7682c139a50c39168b633520
SHA256: 715FCAEC1E8B5048D1A52418D3F2FC5EA9BB75E7DE84569EFA6208A80BFE2FC5
File Size: 516.19 KB, 516192 bytes
MD5: d2193ecb17e3007e708db7d1b658caaf
SHA1: ab8a8e23b9b6cf569cae07c21eb7b31d6b8170ff
SHA256: D95445558914C9B65E28EF9AB744D8B69E7775C4752284EFDD5C9192ED203EE6
File Size: 509.99 KB, 509992 bytes
MD5: c3073963ab9765ce73ef4f1fc76489f1
SHA1: 1e129c6e7e2061250938945e487078f485b803cb
SHA256: 1893F9A316845D205076B82F72569837990BADB0362E8D052EB6F4A4E7D1649F
File Size: 485.47 KB, 485472 bytes
MD5: 95c07f00a2583ef886ca763e313bb0c8
SHA1: d4072e91412d81ca95859cc806479633d61aeaad
SHA256: F71C28517C4918EBD35108DAD7162955D676FACAC58C45E4DB53E83AE125CEB9
File Size: 468.46 KB, 468456 bytes
MD5: e381d87bb28b15da637103609a4b4944
SHA1: 024798358edb369d62cf0e3b363423918c0cb84b
SHA256: 90ED931D3819567F327127E25FFF13663FFB3EABA512D1E19E83FCF38E05491C
File Size: 481.25 KB, 481248 bytes
MD5: 559e24eb14a630e532e2ac26cb5f75cc
SHA1: 6ffe2b2178576c560fb22b8e47f3e03aa57de6dc
SHA256: AA4D1E48F6BE712A786C31807A06E889102D18F240079AAA9FC9D48885F4ECDB
File Size: 489.96 KB, 489960 bytes
MD5: 36976ba8e0ce6c9aeca0dab9e042100e
SHA1: cfc3377ade638acf9f3efbd03a4434c3a8c91530
SHA256: B493A8E8E72A589C6F51EB5ED8655B733CC12E05735E3A2FD3E2C37D84EBF860
File Size: 518.75 KB, 518752 bytes
MD5: 5bfb43f198c936ff6f9fc47c44989e8e
SHA1: bea2ee0200a91d2b97f629debf938e8be71c71e1
SHA256: 37B0B4BC45B886C8773D15B14B3CE5CF1364BE0BA21F93083EE675F5A0AE5559
File Size: 523.74 KB, 523744 bytes
MD5: e5cda5669e255909b20c1593ed1d98c8
SHA1: 7e6fef2ffa6f28fcb58ce895fd1fe528be98f6fc
SHA256: 96682215D9B5D2232B2E13F4ECB13563EE6DF57DB6C019E338C5F631AD7545D8
File Size: 494.56 KB, 494560 bytes
MD5: eabfe239defa9b7baab0f241c5eb55d7
SHA1: 7ae52815dc5aca442776717bfcfa9e6900ebb947
SHA256: 8E864DD97307A73802A969A0920A20ADEF545B79E8B61C7FFAB20169FF86E8DF
File Size: 499.17 KB, 499168 bytes
MD5: 792a3a46c441b904e57aa795f7c3b545
SHA1: 15a1354706186f456cfec5cfa41e1bc8a9be7d8f
SHA256: 46B17F0151B9AB383F6A8D10E1A8191F80950966280E7534C05994ECDD0B2467
File Size: 502.88 KB, 502880 bytes
MD5: fc9db55c6b0f54591d42182979e2067d
SHA1: 0d8c23e71fdc91570facb3bb257f2d088498dabb
SHA256: 398924012440F71B10942941E019AC8A8DFFA7B1A99C76F809AD4B6253B9C5B0
File Size: 488.42 KB, 488416 bytes
MD5: a268b6491937c4561369b47374c6850b
SHA1: 7ed3c9b7cf15217ff1e7ab61bd757468f285795a
SHA256: C079819BFA40DCDB34CABCC38DF0D65B7592C3678C35AFF1B6F2409634F421C9
File Size: 496.50 KB, 496504 bytes
MD5: 504aa7d303037b3ae97d2357b019ddda
SHA1: ea79bfea33814f6949c4edb21b62b59ff7fab25c
SHA256: 85B833299D35E4A9BDC1DBE1A4421029CAB65EE776A6AC466210DCD7938FFC73
File Size: 528.38 KB, 528384 bytes
MD5: 35488001a76f74894430c4fe4d45e056
SHA1: 4e70f38dd4f433b4ac82c0195c0a3b6d42a2505e
SHA256: 0D955768D6B6B3BFE3DF4DBEBAAFFAFCC1B010F8EAE1EAF0B23B893276044B5F
File Size: 516.70 KB, 516704 bytes
MD5: 05635e55d374a1ab75bfb36c80087e71
SHA1: 6a08b493ce5c304902b4de04e4b5b8f9c696560e
SHA256: A82EB74B695B074EDAFF4EE1BE2718B34DD1657475686749324E1DE3C3BE3D52
File Size: 515.55 KB, 515552 bytes
MD5: c85b2c5edfcbfdc331079cf8e6ff44b6
SHA1: 3daaaa480baa1ac7d8ce99bc0103bd9eab35f606
SHA256: ED9BC9358FA5AC812CB09C4B25588DC2CCA7BAC0354AC4B3415796622A27FE31
File Size: 502.24 KB, 502240 bytes
MD5: 798e67d3c857738dc545f3c805f12959
SHA1: 2b9a56332078eb64f85bce960e296d1709e6db27
SHA256: 9F3E94814DED968B26622B5BE47716D8A1D0F2D33B85D56B301B2B8FD1FF07CC
File Size: 472.69 KB, 472688 bytes
MD5: c11e479675985157ecae0996531f6ee6
SHA1: f822473700d0153c52d3ab8482e9c06009002071
SHA256: B6836A831B44F725E4E197186587FBA787B9574B2686133FE012F9E5F504F844
File Size: 517.60 KB, 517600 bytes
MD5: 6dc2484ddc0be37d39c94412b6257548
SHA1: 30974376b085de3e349600bc1d9ea23a27904145
SHA256: 40A1B689196116C5E9F6E537D0BC068AAF7FCA452ED620CCE7938436633FD167
File Size: 509.82 KB, 509816 bytes
MD5: 07967babf3ee6ab1d62c66f238c42150
SHA1: b25416e47e5f7809e313d9803573bba65806fb34
SHA256: A7590440CB379D741A1F7AFC3C766400FC121DAEBC6206DC30E90E8D9B27D1CD
File Size: 521.06 KB, 521064 bytes
MD5: 7a5992a00c807690899b75f6055daac4
SHA1: b4b015ac5960dbf4ffaa4d199b2614b0d9709b52
SHA256: 7FBB5618CA2B65BF5427116058D7D463780C003AF5678601060A1AE56FC83BFD
File Size: 496.50 KB, 496504 bytes
MD5: 911cb3e65ac34a9523f11076f1ec3978
SHA1: d24d7de3b71602c8be3e24eeeb9b99d9e8335714
SHA256: C5E501A5A15A059AC2FAF52837B22DF15B8AA6EF3B0BF2239CE024B7508B7397
File Size: 508.39 KB, 508392 bytes
MD5: a03bdd255e6058e174cb90bfbd665c42
SHA1: 1776311c91961db109aa0ab1f4e8b9b71eafafb1
SHA256: 0359297DFDDDE1CA3A8EC1164FCA0E6ED40308F7070B6D205F615F0D9DC55099
File Size: 516.10 KB, 516096 bytes
MD5: 1c4445487cf57b412b29fbe6892fa2b1
SHA1: f0fd9a8dd5dd7c42c6d84aa4990527ce07583300
SHA256: 0C977A360803CE2E3A250ACAA7244017D45A7CA2C9C5C2BFAE37F5749247AE03
File Size: 525.38 KB, 525384 bytes
MD5: 6954342929169086398bbaa728999032
SHA1: 9728899627d4bf48c60a87dfcff9a14bb41486b0
SHA256: 68F56B5CE57BD40ADBE767E3908D0D0D6262961DFBA47020DB07A7B65805EB05
File Size: 484.18 KB, 484184 bytes
MD5: c540de4d729a80e0928663b3396f5944
SHA1: 0227a01fdd96494ff620faf6de08d803a97f9003
SHA256: 87CCB8EC01951316BB4B46FB18F033DB93885CB1410E618152CC9F96510AF3CB
File Size: 497.02 KB, 497016 bytes
MD5: 7b665f1f4d32c7acfbae762906d3e706
SHA1: 8d124848721d89c03ca65d4fcbbde4857aed6053
SHA256: CE10CA240D3D426507872F66C878A14102F2E14A798229F84CDCB74507A5C9C5
File Size: 527.91 KB, 527912 bytes
MD5: f8b368a8dd35a6e246d9a40648a01a64
SHA1: b52c662038432058d44233b1e03076c3928e274a
SHA256: A32E0C0D208057B4E07DEC34D954E4AD2DEDFC254E0BD6B8EBE4867E9F67991C
File Size: 476.77 KB, 476768 bytes
MD5: ba6e7e8666ce4652ab7f8a1fdfdcaf4b
SHA1: 3ac22bd5260e1aef66b1c65f28abd9dba43e140d
SHA256: C2FC97FD2E99AEE4F5F1A65733BD051A349F822A0FBBE93873E979F2E6F2E21C
File Size: 499.68 KB, 499680 bytes
MD5: bf0b19614f7de4a02dd803a255770ca6
SHA1: e3f5c99996be62ba56e04972f6de066246ce280f
SHA256: 4D818CCD1D086BBC0E67B73B8798ABF51DFE98DA52F34EEAC8619235BDE2B266
File Size: 527.84 KB, 527840 bytes
MD5: 36862c92bbdab48e71370064ddb14f85
SHA1: 662c2ed8085c69a4a72d337bfb6908510ca6849d
SHA256: 269DA8AAFE328FB1C2F7EDCAE81CD80BBD26E6FA4A636CF1878CE3785FB29A51
File Size: 504.42 KB, 504416 bytes
MD5: 3f4c83af8b2480a7fe95c201e146e750
SHA1: bdb90fc48a0d02b98a323ca02ec3bca7435355f4
SHA256: 1393228FDAFBC68337D45A54A49C0A5B96E198E03EF08DA23818FFEDE3EB6E30
File Size: 499.30 KB, 499296 bytes
MD5: 56de3f48b2fb0fde2a91cf21c211db08
SHA1: 82856b9edd2bdd7ce565d19cb4dd681b9e506daf
SHA256: F2B0C4CD490161F1C3B7BADD3C18408F808157ECE8EABA8A0B816F5D6B98B3F2
File Size: 522.62 KB, 522616 bytes
MD5: d991e22a393b8c751435b34401174d0c
SHA1: 06ea9c180dd109c8a697fee7bf555dd852cd7e50
SHA256: F9C55F367143399D28342CC9AEDFB90FACD2E6883432347E39728772F13F87E3
File Size: 506.23 KB, 506232 bytes
MD5: 48299cbd44aed46313c018a10ceb74d6
SHA1: 81ac3756e8d12f7fae81787253dcbc42c570e145
SHA256: EE5DDB64C3FD51C11B5E064672B48B5440C37726225C235ACA07FF3E670E10DC
File Size: 471.01 KB, 471008 bytes
MD5: 18505c7577e0ced7f85ca3f8056e7cd0
SHA1: 778286d35f341dcfac2e230bd50bbe4712fd7c68
SHA256: 71D65C04441D04DDBA150DBA6700D24EAD94459CBBCF3CFFD75836E8EB86EA13
File Size: 500.71 KB, 500712 bytes
MD5: 4833a173bfeed017cf9f458a5cd2305a
SHA1: 4d1adbb69415bc6c8a11afa8f6ed34f5f58e40bf
SHA256: 6F764C5C898E50F81003C6C355E0206E370F52A81421397362DEA673E338F4CA
File Size: 471.42 KB, 471416 bytes
MD5: a28818b9a84c83fd72f6b8ce8823be25
SHA1: 09d66ef8e6893bde76b0d0220bb83c15bf68dad0
SHA256: F049181F6AE727A055927BF9F6C01757F36ADA3247214F8221D97EFED715CECD
File Size: 510.07 KB, 510072 bytes
MD5: e7da8e0e046f9b66989cb88c32fb137e
SHA1: d82ac41f96fe066d171cd0de4a7aa557db52cac4
SHA256: 548E9641D1403C563FA000DE3168D09BBDD628AB698A74E2ADB4E488B5C1BF09
File Size: 522.10 KB, 522104 bytes
MD5: 583f9e104e0396fa1ad60027a3f511bc
SHA1: f151352c5c0a20cf48f0233bea68f776008c1254
SHA256: 9B94C9709052C13065E338DD6EF683F8765029438CB1E29D530842E3AE68BB8E
File Size: 504.32 KB, 504320 bytes
MD5: ee1440454f0c00146e8740ae9c035ba4
SHA1: 67fc4c81ca86c0a5b9bf2ee32ba1f75b7f80837d
SHA256: 92372308B5FA7F67BFA7E783A00965E2825BEC724A347EEFE6D367EC67B7938E
File Size: 519.03 KB, 519032 bytes
MD5: f524b369879c4b0239033662a4353d04
SHA1: 5a825db644f465bee805ea1b601468ee2e01db8b
SHA256: 677B5DB5D5433E6B78A80363839A7F27C541CC4C497B9316CB597A9A0CF945BA
File Size: 506.85 KB, 506848 bytes
MD5: bfd406ad60212046a71c33e0127dc3ec
SHA1: edee8564ed0a9ed944f6ef83732d691740b9549a
SHA256: BE6EE9085031977F0A69090EC0EB4A3846452F289AAFB44980BF5AB425351D31
File Size: 522.62 KB, 522616 bytes
MD5: a4a00dbdaf680bf462a9fcfe98ef755f
SHA1: cec5e90302b10fa7495bf07e419dd9253bf139d3
SHA256: 0E58AE4D4E855B3BEA429E07B9D0CAC7C97FA82248E2429131B91502090FF9BD
File Size: 522.72 KB, 522720 bytes
MD5: 57335929da7be87ee0dc20ab53ca90ff
SHA1: aeee1e271b7c4bccc48b8732b47aea1b5bea6c12
SHA256: 1B223B098FAF5F3DF8EFE57617EFD23F122487EC77F53A6300736CFC050E6914
File Size: 496.74 KB, 496736 bytes
MD5: 068da9a85cf1de592cfe5fe65f357de8
SHA1: ea3226d9fd02dd901f447d4f0c2c7a78782131c3
SHA256: E183207E368516AE4419076ACFBA54673F0F76905522CEAEEB89182CFB78BE98
File Size: 509.30 KB, 509304 bytes
MD5: d441abaa75dea18322d910d5ed89c8c4
SHA1: fde013aa0d6df9730ce63d215170eea8a496ff8e
SHA256: 9486A1F7468E05649B3A9C498017698F742AD37EA769FF3CB8782BC721ED3C9C
File Size: 496.61 KB, 496608 bytes
MD5: 9b99e2fa50ed5fb43b24fe8803a6af8e
SHA1: e1bc9c53848a99fb2ca5876807dca4d7c2a98f5d
SHA256: F6F3A9D1439865D95A294F8CA85633873B50F25A14E9C8E44DD24A30814CE610
File Size: 495.20 KB, 495200 bytes
MD5: 14b1aacf7c34156c2fd5430a82d58ca6
SHA1: 7da972b7d9f4199da95e0396e25f6275c3341f27
SHA256: 35B4774D3BB7E0F66C20DA54FC8C898F5D482F7328520B958835308050AC5D47
File Size: 504.16 KB, 504160 bytes
MD5: ca05ff0d71c7c037dd3c5e02ce3e4df4
SHA1: 745286d69e8166d73d9e8eb1bfd306f40ade6f96
SHA256: 96617E21C653FB5666BE814914925B03163D58B47E4291E0AED3937F3B3B6A7E
File Size: 493.15 KB, 493152 bytes
MD5: 79a5fed04fc67f0b9a80f2bd693b232d
SHA1: fc37683f58a10e274db7c38cb03e59742d69949f
SHA256: EE7041DA89ED6E66B53D78D168C87D4C7F4FB20DDCFED9323DEDDF0CCEF91015
File Size: 539.62 KB, 539616 bytes
MD5: 7590e5687d9b1d8d27495ae3ec1be973
SHA1: 5042fe40e78b50e4225bcd727072f491569a8e20
SHA256: 4C6C6D362E5244E282DBE9112215D7DB40B218FBBB0722D79BE5B308C48045AE
File Size: 515.45 KB, 515448 bytes
MD5: 241d6b2354051a55494e3bf79559662d
SHA1: df6e7adcba0c5188fa6f5757b3a3fe5794e0fad6
SHA256: 6E18E4053956E7FB4EC9064650B35888917A14C65954806E13F81FCAA555D8AC
File Size: 473.57 KB, 473568 bytes
MD5: 8910bb6f9de3f9e218cbdc8f92efc498
SHA1: c5fead6857b9c709c6e96006d97c5fb128cd85ee
SHA256: 1846C2898BA0C4BBD8EF81A9AFA717FC8A23348A4373F8BC171DE4BB5E51E783
File Size: 497.76 KB, 497760 bytes
MD5: aa6605db2f96b52659eac0e734202d3f
SHA1: 362ee66be0eea955ad63ab3a54cd9ce02e0cccad
SHA256: 53C29DB0517A6B4C463DED234D6756C99692A45CA2CF05BC3BC05E67D46FB6B1
File Size: 510.56 KB, 510560 bytes
MD5: d842a75972d58fd28d9645ceb6b88704
SHA1: feaadac0d4c0d79b90f40cb095890c138ae45259
SHA256: 369194E14249CA4E9B81639DF324B56326580554705CECDCE955D8F9E9D07F31
File Size: 497.02 KB, 497016 bytes
MD5: fcddc4086ae2ec9389e5a8ba7299154a
SHA1: 23c8b1a8bc5e3bf817bae5acf91e3c02320a1c3c
SHA256: 104AA0E5125491B7E423D5059C376663BD8D5C5C8A0DB902DFCBB54CBE318BF8
File Size: 518.52 KB, 518520 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Show More

232 additional icons are not displayed above.

Windows PE Version Information

Name Value
Company Name GOG Sp. z o.o.
File Description
  • 18 Wheels of Steel: Extreme Trucker
  • Agony UNRATED
  • Another World: 20th Anniversary Edition
  • A Plague Tale: Requiem
  • Arx Fatalis
  • Baldur's Gate 3
  • Battle Brothers
  • Battlestar Galactica Deadlock
  • CARRION
  • Cat Quest II
Show More
  • Chicken Assassin: Reloaded
  • Crystal Caves HD
  • Cyberpunk 2077
  • Dark Reign 2
  • Deep Sky Derelicts
  • Don't Starve
  • Door Kickers: Action Squad
  • DragonStrike
  • Drakensang
  • DREDGE
  • FATE
  • Fetish Locator Week One
  • Fran Bow
  • Frostpunk
  • Ghost Song
  • God's Trigger
  • Greak: Memories of Azur
  • Hitman: Blood Money
  • Hollow Knight
  • Horizon Zero Dawn™ Complete Edition
  • Hotline Miami
  • HuniePop 2: Double Date
  • Imperium Romanum Gold Edition
  • Just Cause
  • Kao the Kangaroo
  • Little Nightmares II
  • M1 Tank Platoon II
  • Mail Time
  • Mount & Blade: Warband
  • Neverwinter Nights: Enhanced Edition
  • Once Upon a Jester
  • OpenTTD
  • Operation Body Count
  • OTXO
  • Pacific General
  • Peglin
  • Prey
  • Project Zomboid
  • Shadow Tactics: Blades of the Shogun
  • Shores Unknown: Arrival
  • Sins of a Solar Empire®: Rebellion Ultimate Edition
  • Snowtopia Demo
  • SOMA
  • Spiritfarer Demo
  • SpongeBob SquarePants: Battle for Bikini Bottom - Rehydrated
  • STAR WARS™ Knights of the Old Republic™ II: The Sith Lords™
  • Star Wolves
  • Stellaris
  • Stronghold Crusader HD
  • Super Huey™ 1 & 2 Airdrop
  • System Shock Demo
  • The Black Guards of Odom - Desert Town Prison
  • The Falconeer
  • The House of Da Vinci
  • The Suicide of Rachel Foster
  • The Whisperer
  • The Whispering Valley
  • The Witcher 3: Wild Hunt
  • This War of Mine
  • Tower of Time
  • Treasure of Nadia
  • TUNIC
  • Two Point Hospital
  • Under the Witch
  • Urbek City Builder Prologue
  • Vagrus - The Riven Realms: Prologue
  • Warbreeds
  • Warhammer 40,000: Gladius - Relics of War
  • Werewolf: The Apocalypse - Earthblood
  • Wolfenstein II: The New Colossus
  • XCOM®: Chimera Squad
File Version 2.0.0.2
Internal Name GOG Galaxy - Game Installer.exe
Legal Copyright (C) GOG Sp. z o.o. 2020
Product Name
  • 18 Wheels of Steel: Extreme Trucker
  • Agony UNRATED
  • Another World: 20th Anniversary Edition
  • A Plague Tale: Requiem
  • Arx Fatalis
  • Baldur's Gate 3
  • Battle Brothers
  • Battlestar Galactica Deadlock
  • CARRION
  • Cat Quest II
Show More
  • Chicken Assassin: Reloaded
  • Crystal Caves HD
  • Cyberpunk 2077
  • Dark Reign 2
  • Deep Sky Derelicts
  • Don't Starve
  • Door Kickers: Action Squad
  • DragonStrike
  • Drakensang
  • DREDGE
  • FATE
  • Fetish Locator Week One
  • Fran Bow
  • Frostpunk
  • Ghost Song
  • God's Trigger
  • Greak: Memories of Azur
  • Hitman: Blood Money
  • Hollow Knight
  • Horizon Zero Dawn™ Complete Edition
  • Hotline Miami
  • HuniePop 2: Double Date
  • Imperium Romanum Gold Edition
  • Just Cause
  • Kao the Kangaroo
  • Little Nightmares II
  • M1 Tank Platoon II
  • Mail Time
  • Mount & Blade: Warband
  • Neverwinter Nights: Enhanced Edition
  • Once Upon a Jester
  • OpenTTD
  • Operation Body Count
  • OTXO
  • Pacific General
  • Peglin
  • Prey
  • Project Zomboid
  • Shadow Tactics: Blades of the Shogun
  • Shores Unknown: Arrival
  • Sins of a Solar Empire®: Rebellion Ultimate Edition
  • Snowtopia Demo
  • SOMA
  • Spiritfarer Demo
  • SpongeBob SquarePants: Battle for Bikini Bottom - Rehydrated
  • STAR WARS™ Knights of the Old Republic™ II: The Sith Lords™
  • Star Wolves
  • Stellaris
  • Stronghold Crusader HD
  • Super Huey™ 1 & 2 Airdrop
  • System Shock Demo
  • The Black Guards of Odom - Desert Town Prison
  • The Falconeer
  • The House of Da Vinci
  • The Suicide of Rachel Foster
  • The Whisperer
  • The Whispering Valley
  • The Witcher 3: Wild Hunt
  • This War of Mine
  • Tower of Time
  • Treasure of Nadia
  • TUNIC
  • Two Point Hospital
  • Under the Witch
  • Urbek City Builder Prologue
  • Vagrus - The Riven Realms: Prologue
  • Warbreeds
  • Warhammer 40,000: Gladius - Relics of War
  • Werewolf: The Apocalypse - Earthblood
  • Wolfenstein II: The New Colossus
  • XCOM®: Chimera Squad
Product Version 2.0.0.2

Digital Signatures

Signer Root Status
GOG sp. z o.o GOG sp. z o.o Self Signed

File Traits

  • HighEntropy
  • Installer Version
  • packed
  • x86

Block Information

Total Blocks: 3,277
Potentially Malicious Blocks: 285
Whitelisted Blocks: 2,992
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 x x x x x 0 x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x x x x x 0 0 x x x 0 0 x x 0 0 x 0 0 0 0 0 0 x 0 x x x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 x x 0 0 x 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 x x x x 0 0 0 0 0 x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 0 x x x x 0 0 x 0 0 x x 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x 0 x x x x x x x x 0 x 0 x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 1 0 x x 0 x x 0 x 0 x x 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 x x 0 0 0 x x x x x x x x x 0 x 0 0 x x x x 0 x x x x x x x x x x x 0 x x 0 0 x 0 x x x 0 x 0 0 0 0 x 0 0 0 x x 0 0 0 0 x x 0 x 0 0 0 0 0 0 x x x x x x x 0 0 0 0 x 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 x x x 0 0 0 0 0 x x 0 0 0 0 0 x 0 x x 0 0 x 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 x x x 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 1 1 0 0 0 1 0 0 0 1 0 1 0 0 0 0 1 1 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.LX
  • MSIL.Brute.AAC
  • MSIL.Brute.AAF
  • MSIL.Brute.AAFA
  • MSIL.Brute.AAR

Files Modified

File Attributes
c:\programdata\gog.com\galaxy\logs\installerbootstrapper.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\de\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\es-mx\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\es\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\fr\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\galaxyinstaller.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\galaxyinstaller.exe.config Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\it\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\ja\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\ko\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\payload.base64 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\pl\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\pt-br\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\ru\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\zh-hant\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\zh\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\de\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\es-mx\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\es\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\fr\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\galaxyinstaller.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\galaxyinstaller.exe.config Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\it\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\ja\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\ko\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\payload.base64 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\pl\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\pt-br\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\ru\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\zh-hant\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\zh\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\de\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\es-mx\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\es\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\fr\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\galaxyinstaller.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\galaxyinstaller.exe.config Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\it\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\ja\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\ko\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\payload.base64 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\pl\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\pt-br\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\ru\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\zh-hant\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bcado\zh\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\de\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\es-mx\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\es\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\fr\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\galaxyinstaller.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\galaxyinstaller.exe.config Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\it\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\ja\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\ko\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\payload.base64 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\pl\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\pt-br\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\ru\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\zh-hant\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bsbyl\zh\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\de\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\es-mx\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\es\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\fr\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\galaxyinstaller.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\galaxyinstaller.exe.config Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\it\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\ja\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\ko\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\payload.base64 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\pl\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\pt-br\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\ru\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\zh-hant\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bwxea\zh\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\de\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\es-mx\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\es\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\fr\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\galaxyinstaller.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\galaxyinstaller.exe.config Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\it\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\ja\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\ko\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\payload.base64 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\pl\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\pt-br\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\ru\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\zh-hant\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_bxlpe\zh\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\de\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\es-mx\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\es\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\fr\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\galaxyinstaller.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\galaxyinstaller.exe.config Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\it\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\ja\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\ko\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\payload.base64 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\pl\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\pt-br\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\ru\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\zh-hant\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\zh\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\de\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\es-mx\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\es\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\fr\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\galaxyinstaller.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\galaxyinstaller.exe.config Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\it\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\ja\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\ko\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\payload.base64 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\pl\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\pt-br\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\ru\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\zh-hant\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cjsbk\zh\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\de\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\es-mx\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\es\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\fr\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\galaxyinstaller.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\galaxyinstaller.exe.config Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\it\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\ja\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\ko\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\payload.base64 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\pl\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\pt-br\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\ru\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\zh-hant\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\zh\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\de\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\es-mx\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\es\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\fr\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\galaxyinstaller.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\galaxyinstaller.exe.config Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\it\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\ja\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\ko\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\payload.base64 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\pl\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\pt-br\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\ru\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\zh-hant\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_csbwt\zh\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\de\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\es-mx\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\es\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\fr\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\galaxyinstaller.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\galaxyinstaller.exe.config Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\it\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\ja\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\ko\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\payload.base64 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\pl\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\pt-br\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\ru\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\zh-hant\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dlxnz\zh\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\de\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\es-mx\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\es\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\fr\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\galaxyinstaller.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\galaxyinstaller.exe.config Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\it\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\ja\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\ko\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\payload.base64 Generic Write,Read Attributes

1265 additional files are not displayed above.

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 붳ȁ4龡^紘Ç獖}좟Ê RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 䵪€ĸ鈉øꌉĶꄍ阎Ľ鬎ʂԏÞ䈑Âø밓Ɣ똕ĥ츕ëǬ䈛x䤝Ē猟ɢ䀣ʲ갤Ç숤ʨ春ʐ븥ė椧ĒꄨěสĹ뜪Ģ윪Þ㴬倰ĥ䠱Oⰵɝ혺ɲ츻Ĵ噀ñ끀Ī덂®䡆¶賂¦홌ʅ቎ĤÁꝒª穔R띔Ü录Ī瑜ť፡Ĥ陣w걣ʛづŔ퍥h坧ʡ㹭ŃŁ詰ʜ䁱£㱲湲J畴ʣꍵ~ RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 4�c xykP~ �ރ���n��^۴�}��Vs}WkP~�)�W��1������dB (F eP���1���h �n�}e��e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �P�r�n��*����8\x��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�����B�O�����x�%���8�5����Bx��� ���\�!IN�sb �!>!wz#@�#��#�O$kF$��$¨%:�%f�%� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� xykP~�ރ���-��^۴�1}��Vs}UkP~U��1J��O�3���dB $F ee�� ���1���fe��h�n�i%e��ke��p RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��Vs} RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �Y��0P%1HO@V�N$\ten�Atu�y�^�P��x������7�������������m���p�'��IV�gi�$�Κ�(!�^��j A�B��`�VtǤ��3����zH�_� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �$@ xykP~�ރ������^۴�}�cVs}`kP~ �)�`��1(�� ���dB .F e� ��1 ��h�n�}e��e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �S�r�v��*����8\x��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�����B�O�����x�%���8�5����Bx��� �����\�!I�RN�sb �!>!wz#@�#��#�O$kF$��$¨%: RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �;h xykP~ �ރ������^۴�"}� Vs}jkP~j��1���#���dB 4F e�B��14��h �n�}e��e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �W�r�e��*����8\x��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�����B�O�����x�%���8�5����Bx�����\�!I�RN�sb!>!wz#@�#��#�O$kF$��$¨%:�%f�%�' RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ?_ xykP~�ރ���H��^۴���z}��Vs}RkP~R��1������dB &F eز��1���h �n�}e��e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 T8 xykP~�ރ������^۴�}��Vs}TkP~T��1�����dB (F e8���1���h�n�}e��e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �[�r�R��*����8\x��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�����B�����x�%���8�5����Bx�����\�!IN�sb!>!wz#@�#��#�O$kF$��%:�%f�%�'�'i'�!(�) RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� xy,kP~�ރ,������^,۴�M}�CVs}�kP~���1P��M���d,B XF e����14��h�n�},e��,e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �" xy�ރC��^��z�}��Vs}��)�D������ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �R��8\x +� �� �6 xy ���=�����B�O�����%���5Bx��Isb!wz#@�#��#�O$��$¨%:�%f�%�'i(�*9*�"*��,=�0P%1HO1�D4.�5,]6�^9�9ߔ:�r;�4>3�@V�@�*B&JB��C�!FH�H��J��K�iL7�L�K RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 퍵ȁᮚ龡^Į紘ÇŎ獖}Ĵ좟Ê RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 墤‹ĸ⬉ʾ鈉øꌉĶꄍ阎Ľ鬎ʂ먎ÍԏÞ阐†䈑Âø밓Ɣ똕ĥ츕ë䈛x䤝Ē猟ɢ䀣ʲ찣ŏ갤Ç숤ʨ春ʐ븥ė椧ĒꄨěสĹ뜪Ģ윪Þ㴬倰ĥ䠱Oⰵɝ혺ɲ츻Ĵ噀ñ끀Ī덂®䡆¶賂¦홌ʅ቎ĤÁꝒª穔R띔Ü录Ī乖ʗ瑜ť፡Ĥ陣w걣ʛづŔ퍥h坧ʡ㹭ŃŁ詰ʜ䁱£ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� xy�ރ�v��^}��Vs}��)��� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 3 xy�ރaK��^��z}��Vs}y�)�D��$���h,� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 㑐ȁҶ龡^.紘Ç2獖}3좟Êh֢ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �S�����8\x +� �� �6 �� � ۀ�=�������B�����%���5��BxI�Rsb#@�#��#�O$��$¨%f�%�'i(�*9*�"*��,=�0P%1HO1�D5,]9�9ߔ:�r;�4@V�@�*@��A��B��FH�H��LօN$N�R20R� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 y)P xy*kP~ �ރ*���� ��^*۴�0}��Vs}�kP~���1r��0���d*B TF e0���1���h �n�}*e��*e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �T�r�^��*����8��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�����B�O�����x�%���8�5����Bx�������\�!IN�sb!>!wz#@�#��#�O$kF$��%:�%f�%�'�'i'� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 t60 xykP~�ރ���T��^۴�}�Vs}OkP~O��1������dB &F ex���1���h�n�}e��e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 W�r�W��*����8��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�����B�O�����x�%���8�5����Bx�����\�!IN�sb!>!wz#@�#��#�O$kF$��%:�%f�%�'�'i'�!(� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �7P xy!kP~ �ރ!��� ��^!۴�#}��Vs}�kP~���1r��#���d!B BF e ���1���h �n�}!e��!e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 E8 xykP~�ރ���@��^۴�}��Vs}jkP~j��1 �����dB 2F e�7��13��h�n�}e��e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 yY�r�Z��*����8\x��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�����B�O�����x�%���8�5����Bx�����\�!IN�sb!>!wz#@�#��#�O$kF$��%:�%f�%�'�'i'� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 Z xykP~�ރ���e��^۴�}��Vs}FkP~F��1������dB "F e����1���h�n�}e��e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 0^�r�U��*����8��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�����B�O�����x�%���8�5����Bx�����\�!IN�sb!>!wz#@�#��$kF$��%:�%f�%�'�'i'�!(�) RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 Yj xykP~�ރ������^۴�}�Vs};kP~;��1o�����dB F e�-��1���h�n�}e��e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 v`�r�T��*����8��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�����B�O�����x�%���8�5����Bx�����\�!IN�sb!>!wz#@�$kF$��%:�%f�%�'�'i'�!(�) ;)� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �kH xykP~ �ރ������^۴�$}��Vs}�kP~���1M��$���dB >F eh���1���h �n�}e��e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �h` xy"kP~ �ރ"���� ��^"۴�)}�%Vs}�kP~���1���)���d!B BF e���1���h �n�}"e��"e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �_�r�S��*����8��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�����B�����x�%���8�5����Bx�����\�!IN�sb!>!wz#@�#��#�O$kF$��$¨%:�%f�%�'�'i'�!(�) RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �-- xy kP~�ރ ���t��^ ۴�}�iVs}1kP~1��1������d B F eP��1���h�n�} e�� e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 i�r�f��*����8\x��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�����B�O�����x�%���8�5����Bx�����\�!I�RN�sb!>!wz#@�#��#�O$kF$��$¨%:�%f�%�' RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 04d xykP~�ރ���x��^۴���z&}��Vs}tkP~t��1���&���dB 8F epo��1S��h �n�}e��e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 㯡ȁ 偫~ Ꚑơʈ龡^ 듛ï 紘ÇȢ獖}(偫~(엦1 좟Êd ᵂċᵆċe잀엦1i¶} ꙥž ꙥž RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 _k�r�I��*����8\x��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�����B�O�����x�%���8�5����Bx�����\�!IN�sb!>#@�#��$kF$��$¨%f�%�'�'i'�!(�) RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 p�` xy5kP~ �ރ5������^5۴�f}�JVs}�kP~���1���g���d5B jF eP���1x��h �n�}5e��5e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 7h�r�e��*����8\x��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�������B�����x�%���8�5����Bx�������\�!I�RN�sb!>!wz#@�#��#�O$kF$��$¨%:�%f�%�' RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 <= xy�ރ%Vs}kP~��1��O�dB F e���1��ie��r!� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 `l�\x�B +� �� �6 �� 7� xy �� ���B���%��Bx�<�!�R#@�#��$kF$��%f�%�'�'�!(�) ;)�*9*�",=�0P%1HO4.�5,]9�:6�>3�>��@V�@�*@��B B��F Fy�H��K�iN$N�R��U_*X �\tec�wd��e0T RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 Z� xy�ރ��^��zVs} kP~ ��1;��e���1�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 jT\x xy�5��Bx��!wz#@�#��%:�%f�0P%1HO1�D6�^9�9ߔ>3�@V�@��A��J��N$R20R�JVN�\te`�2g��n�ArnJtu�u�~y�y�^{�=|ۘ���P��{�jI�ރ�x������7����b:�������������6��T��T��a ���T���*��� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 v��ރ��^Vs}kP~��1��ee�����1��ie��r1�ve�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Lhq\x �� �6 xy ��������%���5Bx�<���R#@�#��$¨%f�'�(�)E*9*�"0P%1HO1�D5,]9�9ߔ@V�@��B��H��J��K�iN$R20U_*VN�\te`�2c�wd��g��lR n�ArnJr�Btu�u�~v�!y�y�^{�=|ۘ~D���P� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 t��ރ��^"Vs} kP~ ��1��ee�����1��ie��r>�ve�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Jhe\x �� �6 xy ��������%��Bx�<���R#@�#��$¨%f�'�(�)E*9*�"0P%1HO5,]9�@V�@��B��H��J��K�iN$U_*VN�\tec�wd��g��n�ArnJtu�u�~v�!y�y�^|ۘ~D���P����jI�x������7��a��3��� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 u��ރ��^%Vs} kP~ ��1��ee�����1��ie��r>�ve�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Jho\x �� �6 xy ��������%���5Bx�<���R#@�#��$¨%f�'�(�)E*9*�"0P%1HO1�D5,]9�9ߔ@V�B��H��J��K�iN$R20U_*VN�\te`�2c�wd��lR n�ArnJr�Btu�u�~v�!y�y�^{�=|ۘ~D���P����jI RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 m=�ރ��^eeIVs} kP~ ��1��ee�� ��1��fe��i(e��r:�ve�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �l|\x +� �� �6 xy �� ۀ����%���5Bx���R!wz#@�#��%f�'�(�*9*�"0P%1HO1�D5,]9�9ߔ@V�@ڙ@��B��H��J��K�iN$N�R20U_*VN�\te`�2c�wd��g��lR n�Ao��rnJr�Btu�u�~v�!y�y�9y�^{�=|ۘ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� xy�ރ ��^��zeeQVs}%kP~%��1>��ee�����1��fe��ise��r��se��ue��ve��{e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� xykP~�ރ��^ee=�4�Vs}$kP~$��15��dB F e e��w��q�P2��1��f�e��w��gr�hq��n�i�e��k RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��ރPVs}kP~��1��e���1��ie��r � RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 hj\x +� �� xy �� ۀ�����%��Bx�<���R#@�#��$¨%f�(�)E*9*�"0P%1HO5,]9�=�@V�@ڙ@��B��J��N$N�U_*VN�\tec�wd��g��n�Ao��rnJtu�u�~v�!y�y�9y�^|ۘ~D���P����jI�x������|��7 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xykP~�ރ��^eeQVs}%kP~%��1R��ee������1��fe��g�h��n�i]e��ke��pe��r��s RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �g��8\x�B +� �� �6 xy ����B���%���5Bx�<�R!wz#@�#��$��$¨%:�%f�%�(�)A*9*�",=�/9�0P%1HO1�D5,]9�9ߔ=�>3�@V�@ڙ@��B&JB��H��J��K�iL7�L�AL�KLօN$N�R20U_*V �VN�Y�M\te RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xy�ރ��^��zeeVs}kP~��1C��ee���`��1��fe��g�h��n�ige��pe��r��se��u RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 ji��8�"a�B +� �� xy ������B��%���5Bx�<��!wz#@�#��$��$¨%:�%f�%�(�*9*�",=�/9�0P%1HO1�D5,]6�^9�9ߔ=�>3�@V�@��B��D�J��LօN$N�R20TzRU_*V �VN�\te]D�`�2a$c�we0Te�h RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xy�ރeeVs} kP~ ��1��ee��0��1��ie��ra�ve�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �i2 +� xy��Bx#@�#��$¨%f�0P%1HO9�@V�@��A��\teg��rnJtu�u�~y�y�^���P��ރ�x������|��7�b:�������a ������ [�m�Ù���p�'��IV�gi�t����$�[��`�(!�^��o��j A�/�B��`�V�P���3�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xy�ރVs}�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �i) +� xy��Bx#@�$¨0P%1HO9�@V�\ternJtu�u�~y�^���P��ރ�x������|��7�b:����������a ����m�Ù���p�'��IV�t����$�`�(!�^��o��j�`�V�P���3����zH�Q]��@K� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��2 xy* �/��Y�d�kP~��� ��ރ�p��^�o���zee)Vs} kP~ ��1���7 ���ﺃee����1��fe��h RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 'k�8��8tX��B�8 �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^6�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 (k�8��8tX��B�8 �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^6�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �  xy* �/��Y�d�kP~� ��ރ�p��^�o���zeeBVs}kP~��1k��7 ���ﺃe e��� ��1 ��fe��g RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81z��B�8 �6 �v y� z �Z xy �� �a ۀT�B������1�����5����ee +Bx�<��5 � �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �  xy* �/��Y�d�kP~� ��ރ�p��^�o���zeeBVs}kP~��1k��7 ���ﺃe e��� ��1 ��fe��g RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81z��B�8 �6 �v y� z �Z xy �� �a ۀT�B������1�����5����ee +Bx�<��5 � �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� xy* �/��Y�d�� ��ރ�p��^�o���zVs}kP~��14��7 ���ﺃee����1��h�n�ie��r4� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �k��jg�8 �� �v �Z xy ��T��������5����Bx!wz#�#��%:�&� (�(X�)�`*J*�"+�[,��-!R/9�/��1`1�1HO1�D5�06�^9ߔ;��<.:>3�@V�G�IH[uH�pI��J��K��N$R20U_*V �X�`�2b"hc�wc�zg�g�X RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �k��jg�8 �� �v �Z xy ��T��������5����Bx!wz#�#��%:�&� (�(X�)�`*J*�"+�[,��-!R/9�/��0P%1`1�1HO1�D5�06�^9ߔ;��<.:>3�@V�G�IH[uH�pI��J��K��N$R20U_*V �X�\te`�2b"hc�wc�z RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �k��jg�8 �� �v �Z xy ��T��������5����Bx!wz#�#��%:�&� (�(X�)�`*J*�"+�[,��-!R/9�/��0P%1`1�1HO1�D5�06�^9ߔ;��<.:>3�@V�G�IH[uH�pI��J��K��N$R20U_*V �X�\te`�2b"hc�wc�z RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �  xy* �/��Y�d�� ��ރ�p�o�7Vs}kP~��1��7 ���ﺃdB F e��1 ��ie��r� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 sk�8��jg�B �� �6 �v �� 7� xy �� ���T�B���������%���5����Bx�<�!�R#�#��$kF$��%�&� '�!(�(X�(�) ;)�`*J*9*�",=�,��-!R0P%1`1�1HO1�D5,]5�G9ߔ>��@V�@�*A��B  RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��7 xy* �/��Y�d�kP~��� ��ރ�p��^�o���zee*Vs} kP~ ��1���7 ���ﺃee����1��fe��h RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 1k 8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 2k8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� 6 xy* �/��Y�d�kP~� ��ރ�p��^�o���zee*Vs} kP~ ��1���7 ���ﺃee�� ��1��fe��h�n RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 .k8��8tXz��B�8 �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 /k 8��8tXz��B�8 �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� 6 xy* �/��Y�d�kP~� ��ރ�p��^�o���zee*Vs} kP~ ��1���7 ���ﺃee����1��fe��h�n RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 2k 8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 3k8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��  xy* �/��Y�d�� ��ރ�p��^�o�Vs}"��7 ���ﺃh�n� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �k�8��jg �6 �v �Z xy ��T�������5����Bx!wz#�#��$kF%:�&� (�(X�)E)�`*J+�[,��-!R/9�/��0P%1`1�1HO1�D5�09ߔ<.:>3�@V�F?G�IH[uH�pH��I��J��N$R20U5�U_*V �X�\te_�z`b.`�2 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� xy* �/��Y�d�� ��ރ�p ��^�o�BVs}kP~��1,��7 ���ﺃee�� ��1 ��h�n�ie��rA�v RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 l�8��jg�8 �6 �v xy ��T���������5����Bx��!wz#�#��$kF%:�&� (�(X�)E)�`*J*9*�h+�[,��-!R/9�/��1`1�1HO1�D5�09ߔ<.:>3�@V�F?G�IH[uH�pH��I��J��K��N$R20U5�U_*V �X� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 l�8��jg�8 �6 �v xy ��T���������5����Bx��!wz#�#��$kF%:�&� (�(X�)E)�`*J*9*�h+�[,��-!R/9�/��0P%1`1�1HO1�D5�09ߔ<.:>3�@V�F?G�IH[uH�pH��I��J��K��N$R20U5�U_*V � RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 l�8��jg�8 �6 �v xy ��T���������5����Bx��!wz#�#��$kF%:�&� (�(X�)E)�`*J*9*�h+�[,��-!R/9�/��0P%1`1�1HO1�D5�09ߔ<.:>3�@V�F?G�IH[uH�pH��I��J��K��N$R20U5�U_*V � RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 闶ȁ ਪˣ鈯ˣ遙̃豤̃অˣ炑̃龡^濖̃賬̃3獖}偫~엦1਷ˣ邯̃뫯ʃdᵂċᵆċeఆ엦1¶i ꙥžr֢ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 rk�8�jg�B �� �6 �v �� 7� �� �� ۀ���T�B���������%��Bx�<���!#��$kF$��%�&� &�-'�!(�(X�(�) ;)E)�`*J*9*�",=�-!R0P%1`1�1HO5,]5�G>��@V�@�*A��B B��E�mF Fy�G�I RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 闭ȁ獖} RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 bkw �� �6 �v �� ۀ��T�����%��Bx��#��&� &�-(�(X�(�*J*9*�"0P%1`1�1HO5,]@V�A��B��E�mG�IH[uH�pH��N$N�U_*X�.\te_�zc�wh�rj�bk`k�ql(�o��q�Xr�BsU�tǤvy�v�!w�ny�9{b�|ۘ~D RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � * xy* �/��Y�d�kP~� ��ރ�p��^�o���zee,Vs} kP~ ��1���7 ���ﺃee����1��fe��h�n RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 ,k�8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 -k8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ~� % xy* �/��Y�d�kP~� ��ރ�p��^�o���zee,Vs} kP~ ��1���7 ���ﺃee����1��fe��h�n RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 ,k�8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 -k8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 .k�8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 /k8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��  xy* �/��Y�d�� ��ރ�p ��^�o�IVs}kP~��11��7 ���ﺃee����1"��h�n�i e��rA�v RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 l�8��jg�8 �6 �v �Z xy ��T���������5����Bx!wz#�#��$kF%:�&� (�(X�)E)�`*J*9+�[,��-!R/9�/��1`1�1HO1�D5�09ߔ<.:>3�@V�F?G�IH[uH�pH��I��J��K��N$R20U_*V �X�_�z`�2 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 l�8��jg�8 �6 �v �Z xy ��T���������5����Bx!wz#�#��$kF%:�&� (�(X�)E)�`*J*9+�[,��-!R/9�/��0P%1`1�1HO1�D5�09ߔ<.:>3�@V�F?G�IH[uH�pH��I��J��K��N$R20U_*V �X�\te RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � % xy* �/��Y�d�kP~� ��ރ�p��^�o���zee,Vs} kP~ ��1���7 ���ﺃee�� ��1��fe��h�n RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xy* �/��Y�d�kP~� ��ރ�p��^�o�ee4Vs}kP~��1.��7 ���ﺃee��� ��1 ��fe��g� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �j8��81��B �6 �v y� �Z xy �� �a ۀT�B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/��0P%1` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � % xy* �/��Y�d�kP~� ��ރ�p��^�o���zee,Vs} kP~ ��1���7 ���ﺃee�� ��1��fe��h�n RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 -k�8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 .k8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 闪ȁ獖}偫~엦1dᵂċᵆċr֢ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Hkq�B �� �v �� 7� �� ���T�B������%Bx�<�!$��%�'�!(�(X�(�) ;*J*9*�",=�1�1HO5,]5�G>��@V�@�*A��B F Fy�G�IH[uH�pM�lN$N�P@jR��X �_�zc�we0Te�hh�rk�qq(q�XrnJr�vy�v�! RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Ikz�B �� �v �� 7� �� ���T�B������%Bx�<�!$��%�'�!(�(X�(�) ;*J*9*�",=�0P%1�1HO5,]5�G>��@V�@�*A��B F Fy�G�IH[uH�pM�lN$N�P@jR��X �\te_�zc�we0Te�hh�rk�qq(q�XrnJr� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xy* �/��Y�d�kP~� ��ރ�p��^�o�ee=Vs}kP~��1.��7 ���ﺃee��� ��1��fe��g� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀT�B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/��0P% RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xy* �/��Y�d�kP~� ��ރ�p��^�o�ee=Vs}kP~��1.��7 ���ﺃee��� ��1��fe��g� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �j8��81��B �6 �v y� �Z xy �� �a ۀT�B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/��0P%1` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 'k�8��8tX��B �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 (k�8��8tX��B �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 +k�8��8tX��B�8 �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^6�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 ,k�8��8tX��B�8 �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^6�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��  xy* �/��Y�d�� ��ރ�p��^�o�JVs}kP~��11��7 ���ﺃee����1��h�n�i e��rX�v RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 l�8���8 �6 �v �Z xy ��T���������5����Bx!wz#�#��$kF%:�%`�&� (�(X�)E*J*9+�[,��/9�/��0P%1`1�1HO1�D5�09ߔ<.:>3�@V�F?G�IH[uH�pH��I��J��K��N$R20U5�U_*V �X�\te_�z RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 +k�8��8tX��B �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 ,k8��8tX��B �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��  xy* �/��Y�d�� ��ރ�p��^�o�TVs}kP~��11��7 ���ﺃee����1��h�n�i e��rN�v RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 l�8�tX�jg�8 �� �6 �v �Z xy ��T���������5����Bx!wz#�#��$kF%:�%`�&� (�(X�)E)�`*J*9*�"+�[,��-!R/9�/��1`1�1HO1�D5�09ߔ<.:>3�@V�F?G�IH[uH�pH��I��J��K��N$R20U_* RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 l�8�tX�jg�8 �� �6 �v �Z xy ��T���������5����Bx!wz#�#��$kF%:�%`�&� (�(X�)E)�`*J*9*�"+�[,��-!R/9�/��0P%1`1�1HO1�D5�09ߔ<.:>3�@V�F?G�IH[uH�pH��I��J��K��N$R20 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 陏ȁਪˣ鈯ˣ遙̃豤̃অˣ炑̃濖̃賬̃獖}਷ˣ邯̃뫯ʃ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 elR �v �Z ��T�����Bx!wz#��&� (�(X�*J0P%1`1�1HO@V�G�IH[uH�p\te_�zb"hh�ri��j�bk`k�ql(�q�XrnJtǤu�~vy�w�nz��{b��P��/��x������7�M�b:�������6�X��V�����.���a ���48��v�j���r RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 降ȁਪˣ鈯ˣ遙̃豤̃অˣ炑̃濖̃賬̃獖}਷ˣ邯̃뫯ʃ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 blLtX �v �ZT������5Bx!wz#��&� (�(X�*J0P%1`1�1HO@V�G�IH[uH�p\te_�zb"hh�ri��j�bk`k�ql(�q�XrnJtǤu�~w�nz��{b��P��/��x������7�M�b:�������X��V�����.���a �48��v�j���r�m�Ù� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鳼ȁ ਪˣ鈯ˣ遙̃豤̃অˣ炑̃龡^濖̃賬̃攘ť 獖}偫~엦1਷ˣ邯̃뫯ʃeꙥžࠄ엦1¶fꙥži/ꙥžr;֢vꙥž RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m^jg �� �v ��T������%��Bx�<#��(�(X�(�)�`*J*9*�"-!R0P%1�1HO5,]@V�A��G�IH[uH�pN$N�\te_�zb"hc�wh�rj�bk`k�ql(�lR q�Xr�BsU�vy�w�ny�9{b�~D�P����x������7�M�b:�������� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鴃ȁ獖}r ֢ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m( �v����(�0P%1`1�1HO@V�A��H[u\teb"hk`k�ql(�w�n{b��P��x������7�M�����������j��m�Ù��IV����$�8წ���&M�(!�^��j��=�SB1_T�Vw�`�V��3��%�������AE��D��&��$���L RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 陾ȁ ਪˣ鈯ˣ遙̃豤̃偫~অˣ炑̃龡^濖̃賬̃攘ťX獖}!偫~!엦1਷ˣ邯̃뫯ʃe.ꙥž㐚엦11¶f ꙥžiüꙥžpꙥžrƒ֢ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 (m�1 �� �6 �v ����T������1���%��3bBx�<���R �7#��%`�&� &�-'�(�(X�(�)�`*9*�"*�h+��0P%1`1�1HO5,]=�@V�A��B��F?H[uH��N$N�U_*Z^�\te_�zb"hc�wc�zg�jj�bk`k�k�q RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � * �/��Y�d�� ��ރ�p��^�o�uVs}kP~��1��7 ���ﺃee����1��ie��r$�ve�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 n�8�tX�jg�8 �� �v xy ����T�������dc�%���5��3bBx�<��#��$kF&� &�-(�(X�(�)E)�`*J*9*�"-!R0P%1`1�1HO5,]=�@V�A��B��G�IH[uH�pI��J��K��N$N�U_*X�.X�Z^�\te_�z RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鴂ȁ獖}eЂ엦1¶r"֢ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m,tX �v �Z����(�*J0P%1�1HO@V�A��G�IH[uH�p\teb"hk�ql(�q�Xw�n{b��P��x������7�M�����������j��m�Ù��IV����$�8წ���&M�(!�^��j��=�SB1_T�Vw�`�V��3��%�������AE��D�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �  xy* �/��Y�d�kP~� ��ރ�p-��^�o�eeiVs}HkP~H��1D��7 ���ﺃeTe���"D��1V��fe��g� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m8��8tXz�jg�B�8 �� �6 �v z �Z xy �� �a��T�B��������dc���5���� +Bx�<��5�R �!wz"Wc#�#��$kF$��%:�%`�%�&� &�-(�(X�)E)�`*J*9*�"+�[,=�,��-!R/9�/�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 o� xy* �/��Y�d�� ��ރ�p ��^�o�@Vs}kP~��1!��7 ���ﺃee����1(��fe��h�n�iUe��rG RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �l�8��8tXz�jg�8 �� �6 �v z �Z xy ����T�B���������%���5���� +3bBx�<��5 �!wz"Wc#�#��$kF$��%:�%`�%�&� &�-(�(X�(�)�`*J*9*�"+�[,=�,��-!R/9�/��0P%1` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鴍ȁ龡^(獖}偫~엦1eꙥž¶i ꙥžr ֢vꙥž RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m~ �� �v �Z ��T������5��Bx�<#�#��&� (�(X�*J*9*�"+�[0P%1`1�1HO1�D5�09ߔ<.:=�@V�A��G�IH[uH�pN$N�R20Z^�\te_�z`�2b"hc�wh�ri��j�bk`k�qk�8l(�lR o�q�XrnJr�BtǤu�~vy�w�n RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鴀ȁ獖}r ֢ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m'tX �� �v����&� (�*J*�"1�1HO@V�G�IH[u_�zb"hc�wk�qq�XtǤw�n{b��P������7�����������m��IV�V����$�8წ���Κ�&M�=�S)�B1_T�Vw�`�V�`���%�������AE��"�zH��D��&��$��� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m/tX �� �v����&� (�*J*�"0P%1�1HO@V�G�IH[u\te_�zb"hc�wk�qq�XtǤw�n{b��P��x������7�M�����������j��m��IV�V����$�8წ���Κ�&M�(!�^��j��=�S)�B1_T�Vw�`�V�`���3�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m0tX �� �v����&� (�*J*�"0P%1�1HO@V�G�IH[u\te_�zb"hc�wk�qq�XtǤw�n{b��P��x������7�M�������������j��m��IV�V����$�8წ���Κ�&M�(!�^��j��=�S)�B1_T�Vw�`�V�`��� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 陽ȁ 砍y偫~龡^攘ť獖}0偫~0엦1鰚²eHꙥž䐢엦1U¶fꙥžh溼´iƠꙥžpꙥžrÓ֢s ꙥžuꙥžvꙥž{ꙥž RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 m�1tX��8 �6 �v xy ��T��������1���5����Bx�R �7!wz#�#��%:�&� '�(�(X�*J*9+�[+��,��/9�/��0P%1�1HO1�D9ߔ=�>3�@V�A��F?G�IH[uH�pH��J��N$N�R20U_*V �X�Z^�\te RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鴰ȁਪˣ鈯ˣ遙̃豤̃অˣ炑̃濖̃賬̃獖}਷ˣ邯̃뫯ʃfꙥžiNꙥžsꙥž}ꙥžꙥž RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 `nV8��"a �� �v ��T�������Bx"Wc$kF&� (�(X�)�`*9*�"1�1HO@V�A��D�N$N�U_*_�zb"hc�we�vj�bk�ql(�lR p*tǤw�ny�9z��{b�~D�P��jI�/������7�b:������� �����q�X����V�����.�a  RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 an]8��"a �� �v ��T�������Bx"Wc$kF&� (�(X�)�`*9*�"0P%1�1HO@V�A��D�N$N�U_*\te_�zb"hc�we�vj�bk�ql(�lR p*tǤw�ny�9z��{b�~D�P��jI�/��x������7�M�b:������� �����q�X��� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 bn^8��"a �� �v ��T�������Bx"Wc$kF&� (�(X�)�`*9*�"0P%1�1HO@V�A��D�N$N�U_*\te_�zb"hc�we�vj�bk�ql(�lR p*tǤw�ny�9z��{b�~D�P��jI�/��x������7�M�b:������� �����q�X��� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鴲ȁ獖} RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n* �v���5(�1�1HO1�D9ߔ@V�H[uR20_�z`�2i��k�qrnJu�~w�n{b�{�=�P�������������T��T���.�T��T��T��m�Ù�������$�>წ�����(��o�=�SB1_T�Vw���%�������AE�Q]��D��&��$���L� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n4 �v���5(�0P%1�1HO1�D9ߔ@V�H[uR20\te_�z`�2i��k�qrnJu�~w�n{b�{�=�P��x������7�M���������T��T���.�T��j��T��T��m�Ù��IV������$�>წ����(!��(�^��o��j��=�SB1_T�Vw RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n5 �v���5(�0P%1�1HO1�D9ߔ@V�H[uR20\te_�z`�2i��k�qrnJu�~w�n{b�{�=�P��x������7�M���������T��T���.���T��j��T��T��m�Ù��IV������$�>წ����(!��(�^��o��j��=�SB1_T� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 x� xy* �/��Y�d�� ��ރ�p��^�o�GVs}kP~��1!��7 ���ﺃee����1(��fe��h�n�iUe��rG RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �l8��8�"tXaz�jg�8 �� �6 �v z �Z 0E xy ����T�B���������%���5���� +3bBx�<��5 �!wz"Wc#�#��$kF$��%:�%`�%�&� &�-(�(X�(�)�`*J*9*�"*�h+�[,=�,��-!R RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鴳ȁ獖} RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n; �v ��T����5��Bx#�(�(X�1`1�1HO1�D9ߔ@V�H[uR20U_*_�z`�2b"hi��k`k�ql(�o�rnJu�~w�n{b�{�=�Jq�P�������������T��Ǐ�T���.�T��T��T��Dt�T��m�Ù�������=��$�>წ����?��o RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �nE �v ��T����5��Bx#�(�(X�0P%1`1�1HO1�D9ߔ@V�H[uR20U_*\te_�z`�2b"hi��k`k�ql(�o�rnJu�~w�n{b�{�=�Jq�P��x������7�M���������T��Ǐ�T���.�T��T��j��T��Dt�T��m�Ù��IV������=� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �nF �v ��T����5��Bx#�(�(X�0P%1`1�1HO1�D9ߔ@V�H[uR20U_*\te_�z`�2b"hi��k`k�ql(�o�rnJu�~w�n{b�{�=�Jq�P��x������7�M���������T��Ǐ�T���.���T��T��j��T��Dt�T��m�Ù��IV����� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鴴ȁ砍y獖} 鰚² RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n3� �v xy������!wz%:�(�1`1�1HO>3�@V�J��X�_�zi��k`k�qrnJu�~w�n{b����P��{�ރ�������b:���������6��h �a �n��F��m�Ù�ͪ�t�������$�8წ���`��o�=�SB1_T�Vw�`�V�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n=� �v xy������!wz%:�(�0P%1`1�1HO>3�@V�J��X�\te_�zi��k`k�qrnJu�~w�n{b����P��{�ރ�x������7����M�b:���������6��h �a �j��n��F��m�Ù��IVͪ�t�������$�8წ���`�(!�^ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n>� �v xy������!wz%:�(�0P%1`1�1HO>3�@V�J��X�\te_�zi��k`k�qrnJu�~w�n{b����P��{�ރ�x������7����M�b:���������6��h ���a �j��n��F��m�Ù��IVͪ�t�������$�8წ���`�(! RegNtPreCreateKey

Windows API Usage

Category API
Network Urlomon
  • URLDownloadToFile
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory

Shell Command Execution

(NULL) C:\Users\Lqywjgcg\AppData\Local\Temp\GalaxyInstaller_pAFBQ\GalaxyInstaller.exe 1439487606 "SOMA"
(NULL) C:\Users\Xjlzpcno\AppData\Local\Temp\GalaxyInstaller_XXRyK\GalaxyInstaller.exe 1716751705 "TUNIC"
(NULL) C:\Users\Byeyfpkv\AppData\Local\Temp\GalaxyInstaller_eFsvN\GalaxyInstaller.exe 1213448387 "Agony UNRATED"
(NULL) C:\Users\Pdelgmur\AppData\Local\Temp\GalaxyInstaller_JjsSl\GalaxyInstaller.exe 2067281194 "Crystal Caves HD"
(NULL) C:\Users\Kddmkfbc\AppData\Local\Temp\GalaxyInstaller_Rjjgo\GalaxyInstaller.exe 1209025141 "Horizon Zero Dawn™ Complete Edition"
Show More
(NULL) C:\Users\Whkhynwd\AppData\Local\Temp\GalaxyInstaller_uslRO\GalaxyInstaller.exe 1654462894 "Fetish Locator Week One"
(NULL) C:\Users\Ptbuhthb\AppData\Local\Temp\GalaxyInstaller_zEewm\GalaxyInstaller.exe 1937407919 "Mail Time"
(NULL) C:\Users\Njboqgjo\AppData\Local\Temp\GalaxyInstaller_YnXyq\GalaxyInstaller.exe 1871006055 "Little Nightmares II"
(NULL) C:\Users\Uzdthsau\AppData\Local\Temp\GalaxyInstaller_GajEP\GalaxyInstaller.exe 1207666913 "Mount & Blade: Warband"
(NULL) C:\Users\Oyzqeqdc\AppData\Local\Temp\GalaxyInstaller_IFaqC\GalaxyInstaller.exe 1592693763 "Treasure of Nadia"
(NULL) C:\Users\Buupcwwe\AppData\Local\Temp\GalaxyInstaller_Xwwzc\GalaxyInstaller.exe 2116300560 "System Shock Demo"
(NULL) C:\Users\Gidmabri\AppData\Local\Temp\GalaxyInstaller_lxjZh\GalaxyInstaller.exe 1293297882 "OpenTTD"
(NULL) C:\Users\Bglzehlm\AppData\Local\Temp\GalaxyInstaller_elSTC\GalaxyInstaller.exe 1421404581 "STAR WARS™ Knights of the Old Republic™ II: The Sith Lords™"
(NULL) C:\Users\Ehshvtid\AppData\Local\Temp\GalaxyInstaller_CPLPW\GalaxyInstaller.exe 1648559910 "Frostpunk"
(NULL) C:\Users\Fcrxbivg\AppData\Local\Temp\GalaxyInstaller_NcDbX\GalaxyInstaller.exe 2050639399 "FATE"
(NULL) C:\Users\Dqkxhaoc\AppData\Local\Temp\GalaxyInstaller_MqobP\GalaxyInstaller.exe 1453298883 "Project Zomboid"
(NULL) C:\Users\Zdkningn\AppData\Local\Temp\GalaxyInstaller_XMtLQ\GalaxyInstaller.exe 1207658713 "Stronghold Crusader HD"
(NULL) C:\Users\Xihkinxo\AppData\Local\Temp\GalaxyInstaller_UHmRx\GalaxyInstaller.exe 1827190281 "The Suicide of Rachel Foster"
(NULL) C:\Users\Uorgbamz\AppData\Local\Temp\GalaxyInstaller_Gytle\GalaxyInstaller.exe 1979367321 "Warbreeds"
(NULL) C:\Users\Hhjmrmac\AppData\Local\Temp\GalaxyInstaller_mmQgD\GalaxyInstaller.exe 1942346586 "Hitman: Blood Money"
(NULL) C:\Users\Ktwwfbdh\AppData\Local\Temp\GalaxyInstaller_RurrN\GalaxyInstaller.exe 1197512724 "Urbek City Builder Prologue"
(NULL) C:\Users\Qgspmcab\AppData\Local\Temp\GalaxyInstaller_qOLzg\GalaxyInstaller.exe 1354443325 "Kao the Kangaroo"
(NULL) C:\Users\Dlgskesu\AppData\Local\Temp\GalaxyInstaller_MpOiR\GalaxyInstaller.exe 1158493447 "Prey"
(NULL) C:\Users\Uybrilpu\AppData\Local\Temp\GalaxyInstaller_wFetH\GalaxyInstaller.exe 1207659210 "Don't Starve"
(NULL) C:\Users\Jusxvqgc\AppData\Local\Temp\GalaxyInstaller_UYCAv\GalaxyInstaller.exe 1097893768 "Neverwinter Nights: Enhanced Edition"
(NULL) C:\Users\Ycpxidfk\AppData\Local\Temp\GalaxyInstaller_yGeIP\GalaxyInstaller.exe 1940028140 "Two Point Hospital"
(NULL) C:\Users\Wuluehul\AppData\Local\Temp\GalaxyInstaller_FgJbV\GalaxyInstaller.exe 1847884051 "Wolfenstein II: The New Colossus"
(NULL) C:\Users\Arnpdzve\AppData\Local\Temp\GalaxyInstaller_ldzee\GalaxyInstaller.exe 2142923325 "Greak: Memories of Azur"
(NULL) C:\Users\Qoermhoi\AppData\Local\Temp\GalaxyInstaller_qystg\GalaxyInstaller.exe 1545755591 "SpongeBob SquarePants: Battle for Bikini Bottom - Rehydrated"
(NULL) C:\Users\Egqlbbun\AppData\Local\Temp\GalaxyInstaller_FVVFp\GalaxyInstaller.exe 1590012242 "Battle Brothers"
(NULL) C:\Users\Adcqqgrd\AppData\Local\Temp\GalaxyInstaller_hMVAq\GalaxyInstaller.exe 1508702879 "Stellaris"
(NULL) C:\Users\Jxpqhawl\AppData\Local\Temp\GalaxyInstaller_UxUgx\GalaxyInstaller.exe 1155924803 "Peglin"
(NULL) C:\Users\Emzkrjqu\AppData\Local\Temp\GalaxyInstaller_vICUE\GalaxyInstaller.exe 1308320804 "Hollow Knight"
(NULL) C:\Users\Ixkebtui\AppData\Local\Temp\GalaxyInstaller_HbosX\GalaxyInstaller.exe 1207664643 "The Witcher 3: Wild Hunt"
(NULL) C:\Users\Ruvdvtuy\AppData\Local\Temp\GalaxyInstaller_twdMW\GalaxyInstaller.exe 1958338581 "Cat Quest II"
(NULL) C:\Users\Helhgbms\AppData\Local\Temp\GalaxyInstaller_qUuZv\GalaxyInstaller.exe 1305299338 "Ghost Song"
(NULL) C:\Users\Mvpmmqjg\AppData\Local\Temp\GalaxyInstaller_myFkK\GalaxyInstaller.exe 1207658845 "Another World: 20th Anniversary Edition"
(NULL) C:\Users\Ciazshqq\AppData\Local\Temp\GalaxyInstaller_VHhaL\GalaxyInstaller.exe 1358404037 "Under the Witch"
(NULL) C:\Users\Sdrumymu\AppData\Local\Temp\GalaxyInstaller_PwVcz\GalaxyInstaller.exe 1629258827 "Deep Sky Derelicts"
(NULL) C:\Users\Xatqztxt\AppData\Local\Temp\GalaxyInstaller_UhuAT\GalaxyInstaller.exe 1508702879 "Stellaris"
C:\Users\Hhriuvby\AppData\Local\Temp\GalaxyInstaller_PPDxG\GalaxyInstaller.exe "C:\Users\Hhriuvby\AppData\Local\Temp\GalaxyInstaller_PPDxG\GalaxyInstaller.exe" 1797575342 "Battlestar Galactica Deadlock"
(NULL) C:\Users\Hhriuvby\AppData\Local\Temp\GalaxyInstaller_PPDxG\GalaxyInstaller.exe 1797575342 "Battlestar Galactica Deadlock"
C:\Users\Kqvmamrk\AppData\Local\Temp\GalaxyInstaller_oAWgh\GalaxyInstaller.exe "C:\Users\Kqvmamrk\AppData\Local\Temp\GalaxyInstaller_oAWgh\GalaxyInstaller.exe" 1455877361 "HuniePop 2: Double Date"
(NULL) C:\Users\Kqvmamrk\AppData\Local\Temp\GalaxyInstaller_oAWgh\GalaxyInstaller.exe 1455877361 "HuniePop 2: Double Date"
C:\Users\Xeipmcee\AppData\Local\Temp\GalaxyInstaller_emRos\GalaxyInstaller.exe "C:\Users\Xeipmcee\AppData\Local\Temp\GalaxyInstaller_emRos\GalaxyInstaller.exe" 1207666873 "This War of Mine"
(NULL) C:\Users\Xeipmcee\AppData\Local\Temp\GalaxyInstaller_emRos\GalaxyInstaller.exe 1207666873 "This War of Mine"
C:\Users\Twmhxrbs\AppData\Local\Temp\GalaxyInstaller_xltRl\GalaxyInstaller.exe "C:\Users\Twmhxrbs\AppData\Local\Temp\GalaxyInstaller_xltRl\GalaxyInstaller.exe" 1423049311 "Cyberpunk 2077"
(NULL) C:\Users\Twmhxrbs\AppData\Local\Temp\GalaxyInstaller_xltRl\GalaxyInstaller.exe 1423049311 "Cyberpunk 2077"
C:\Users\Kxzxhbgt\AppData\Local\Temp\GalaxyInstaller_rLoOa\GalaxyInstaller.exe "C:\Users\Kxzxhbgt\AppData\Local\Temp\GalaxyInstaller_rLoOa\GalaxyInstaller.exe" 1552771812 "A Plague Tale: Requiem"
(NULL) C:\Users\Kxzxhbgt\AppData\Local\Temp\GalaxyInstaller_rLoOa\GalaxyInstaller.exe 1552771812 "A Plague Tale: Requiem"
C:\Users\Rtnzeuvq\AppData\Local\Temp\GalaxyInstaller_DuYTs\GalaxyInstaller.exe "C:\Users\Rtnzeuvq\AppData\Local\Temp\GalaxyInstaller_DuYTs\GalaxyInstaller.exe" 1497384733 "OTXO"
(NULL) C:\Users\Rtnzeuvq\AppData\Local\Temp\GalaxyInstaller_DuYTs\GalaxyInstaller.exe 1497384733 "OTXO"
C:\Users\Tbwtnppw\AppData\Local\Temp\GalaxyInstaller_HGMZq\GalaxyInstaller.exe "C:\Users\Tbwtnppw\AppData\Local\Temp\GalaxyInstaller_HGMZq\GalaxyInstaller.exe" 1438948561 "Fran Bow"
(NULL) C:\Users\Tbwtnppw\AppData\Local\Temp\GalaxyInstaller_HGMZq\GalaxyInstaller.exe 1438948561 "Fran Bow"
C:\Users\Grwzppmf\AppData\Local\Temp\GalaxyInstaller_OtBaJ\GalaxyInstaller.exe "C:\Users\Grwzppmf\AppData\Local\Temp\GalaxyInstaller_OtBaJ\GalaxyInstaller.exe" 1601442230 "Shadow Tactics: Blades of the Shogun"
(NULL) C:\Users\Grwzppmf\AppData\Local\Temp\GalaxyInstaller_OtBaJ\GalaxyInstaller.exe 1601442230 "Shadow Tactics: Blades of the Shogun"
C:\Users\Ramtwyee\AppData\Local\Temp\GalaxyInstaller_wmAjT\GalaxyInstaller.exe "C:\Users\Ramtwyee\AppData\Local\Temp\GalaxyInstaller_wmAjT\GalaxyInstaller.exe" 1935795441 "18 Wheels of Steel: Extreme Trucker"
(NULL) C:\Users\Ramtwyee\AppData\Local\Temp\GalaxyInstaller_wmAjT\GalaxyInstaller.exe 1935795441 "18 Wheels of Steel: Extreme Trucker"
C:\Users\Oenltajo\AppData\Local\Temp\GalaxyInstaller_BcAdO\GalaxyInstaller.exe "C:\Users\Oenltajo\AppData\Local\Temp\GalaxyInstaller_BcAdO\GalaxyInstaller.exe" 1147957142 "Door Kickers: Action Squad"
(NULL) C:\Users\Oenltajo\AppData\Local\Temp\GalaxyInstaller_BcAdO\GalaxyInstaller.exe 1147957142 "Door Kickers: Action Squad"
C:\Users\Yosrauvr\AppData\Local\Temp\GalaxyInstaller_IsDjc\GalaxyInstaller.exe "C:\Users\Yosrauvr\AppData\Local\Temp\GalaxyInstaller_IsDjc\GalaxyInstaller.exe" 1456460669 "Baldur's Gate 3"
(NULL) C:\Users\Yosrauvr\AppData\Local\Temp\GalaxyInstaller_IsDjc\GalaxyInstaller.exe 1456460669 "Baldur's Gate 3"
C:\Users\Qqcftgdi\AppData\Local\Temp\GalaxyInstaller_ubpPX\GalaxyInstaller.exe "C:\Users\Qqcftgdi\AppData\Local\Temp\GalaxyInstaller_ubpPX\GalaxyInstaller.exe" 1423049311 "Cyberpunk 2077"
(NULL) C:\Users\Qqcftgdi\AppData\Local\Temp\GalaxyInstaller_ubpPX\GalaxyInstaller.exe 1423049311 "Cyberpunk 2077"
C:\Users\Bfqzaenf\AppData\Local\Temp\GalaxyInstaller_aVUyz\GalaxyInstaller.exe "C:\Users\Bfqzaenf\AppData\Local\Temp\GalaxyInstaller_aVUyz\GalaxyInstaller.exe" 1100566473 "Drakensang"
(NULL) C:\Users\Bfqzaenf\AppData\Local\Temp\GalaxyInstaller_aVUyz\GalaxyInstaller.exe 1100566473 "Drakensang"
C:\Users\Xyzrmktb\AppData\Local\Temp\GalaxyInstaller_UvTDg\GalaxyInstaller.exe "C:\Users\Xyzrmktb\AppData\Local\Temp\GalaxyInstaller_UvTDg\GalaxyInstaller.exe" 1744110647 "DREDGE"
(NULL) C:\Users\Xyzrmktb\AppData\Local\Temp\GalaxyInstaller_UvTDg\GalaxyInstaller.exe 1744110647 "DREDGE"
C:\Users\Acetzohg\AppData\Local\Temp\GalaxyInstaller_KcCuT\GalaxyInstaller.exe "C:\Users\Acetzohg\AppData\Local\Temp\GalaxyInstaller_KcCuT\GalaxyInstaller.exe" 2147483137 "The Falconeer"
(NULL) C:\Users\Acetzohg\AppData\Local\Temp\GalaxyInstaller_KcCuT\GalaxyInstaller.exe 2147483137 "The Falconeer"
C:\Users\Usgnjuzu\AppData\Local\Temp\GalaxyInstaller_wLOfn\GalaxyInstaller.exe "C:\Users\Usgnjuzu\AppData\Local\Temp\GalaxyInstaller_wLOfn\GalaxyInstaller.exe" 1207658911 "Dark Reign 2"
(NULL) C:\Users\Usgnjuzu\AppData\Local\Temp\GalaxyInstaller_wLOfn\GalaxyInstaller.exe 1207658911 "Dark Reign 2"
C:\Users\Dzfwblta\AppData\Local\Temp\GalaxyInstaller_jakrX\GalaxyInstaller.exe "C:\Users\Dzfwblta\AppData\Local\Temp\GalaxyInstaller_jakrX\GalaxyInstaller.exe" 1103034679 "Snowtopia Demo"
(NULL) C:\Users\Dzfwblta\AppData\Local\Temp\GalaxyInstaller_jakrX\GalaxyInstaller.exe 1103034679 "Snowtopia Demo"
C:\Users\Jrgsdwlt\AppData\Local\Temp\GalaxyInstaller_QtOij\GalaxyInstaller.exe "C:\Users\Jrgsdwlt\AppData\Local\Temp\GalaxyInstaller_QtOij\GalaxyInstaller.exe" 1430136184 "Pacific General"
(NULL) C:\Users\Jrgsdwlt\AppData\Local\Temp\GalaxyInstaller_QtOij\GalaxyInstaller.exe 1430136184 "Pacific General"
C:\Users\Xmmwsves\AppData\Local\Temp\GalaxyInstaller_XQAgA\GalaxyInstaller.exe "C:\Users\Xmmwsves\AppData\Local\Temp\GalaxyInstaller_XQAgA\GalaxyInstaller.exe" 1456460669 "Baldur's Gate 3"
(NULL) C:\Users\Xmmwsves\AppData\Local\Temp\GalaxyInstaller_XQAgA\GalaxyInstaller.exe 1456460669 "Baldur's Gate 3"
C:\Users\Qqxhmhnq\AppData\Local\Temp\GalaxyInstaller_ucpus\GalaxyInstaller.exe "C:\Users\Qqxhmhnq\AppData\Local\Temp\GalaxyInstaller_ucpus\GalaxyInstaller.exe" 1207658680 "Arx Fatalis"
(NULL) C:\Users\Qqxhmhnq\AppData\Local\Temp\GalaxyInstaller_ucpus\GalaxyInstaller.exe 1207658680 "Arx Fatalis"
C:\Users\Kwcrcmiw\AppData\Local\Temp\GalaxyInstaller_UlFqu\GalaxyInstaller.exe "C:\Users\Kwcrcmiw\AppData\Local\Temp\GalaxyInstaller_UlFqu\GalaxyInstaller.exe" 1381758449 "Vagrus - The Riven Realms: Prologue"
(NULL) C:\Users\Kwcrcmiw\AppData\Local\Temp\GalaxyInstaller_UlFqu\GalaxyInstaller.exe 1381758449 "Vagrus - The Riven Realms: Prologue"
C:\Users\Nviumapf\AppData\Local\Temp\GalaxyInstaller_cGabq\GalaxyInstaller.exe "C:\Users\Nviumapf\AppData\Local\Temp\GalaxyInstaller_cGabq\GalaxyInstaller.exe" 1094441612 "Super Huey™ 1 & 2 Airdrop"
(NULL) C:\Users\Nviumapf\AppData\Local\Temp\GalaxyInstaller_cGabq\GalaxyInstaller.exe 1094441612 "Super Huey™ 1 & 2 Airdrop"
C:\Users\Shuevwtk\AppData\Local\Temp\GalaxyInstaller_Lmwsd\GalaxyInstaller.exe "C:\Users\Shuevwtk\AppData\Local\Temp\GalaxyInstaller_Lmwsd\GalaxyInstaller.exe" 1992658104 "Imperium Romanum Gold Edition"
(NULL) C:\Users\Shuevwtk\AppData\Local\Temp\GalaxyInstaller_Lmwsd\GalaxyInstaller.exe 1992658104 "Imperium Romanum Gold Edition"
C:\Users\Zedgcpdx\AppData\Local\Temp\GalaxyInstaller_dmDQo\GalaxyInstaller.exe "C:\Users\Zedgcpdx\AppData\Local\Temp\GalaxyInstaller_dmDQo\GalaxyInstaller.exe" 1426240474 "The Whisperer"
(NULL) C:\Users\Zedgcpdx\AppData\Local\Temp\GalaxyInstaller_dmDQo\GalaxyInstaller.exe 1426240474 "The Whisperer"
C:\Users\Rezerieg\AppData\Local\Temp\GalaxyInstaller_tsTCt\GalaxyInstaller.exe "C:\Users\Rezerieg\AppData\Local\Temp\GalaxyInstaller_tsTCt\GalaxyInstaller.exe" 1316203883 "Chicken Assassin: Reloaded"
(NULL) C:\Users\Rezerieg\AppData\Local\Temp\GalaxyInstaller_tsTCt\GalaxyInstaller.exe 1316203883 "Chicken Assassin: Reloaded"
C:\Users\Aatvwwzg\AppData\Local\Temp\GalaxyInstaller_Khudr\GalaxyInstaller.exe "C:\Users\Aatvwwzg\AppData\Local\Temp\GalaxyInstaller_Khudr\GalaxyInstaller.exe" 1084263831 "Just Cause"
(NULL) C:\Users\Aatvwwzg\AppData\Local\Temp\GalaxyInstaller_Khudr\GalaxyInstaller.exe 1084263831 "Just Cause"
C:\Users\Ikyxwocy\AppData\Local\Temp\GalaxyInstaller_BBhzB\GalaxyInstaller.exe "C:\Users\Ikyxwocy\AppData\Local\Temp\GalaxyInstaller_BBhzB\GalaxyInstaller.exe" 1349516820 "Werewolf: The Apocalypse - Earthblood"
(NULL) C:\Users\Ikyxwocy\AppData\Local\Temp\GalaxyInstaller_BBhzB\GalaxyInstaller.exe 1349516820 "Werewolf: The Apocalypse - Earthblood"
C:\Users\Wfxewsvo\AppData\Local\Temp\GalaxyInstaller_upwiU\GalaxyInstaller.exe "C:\Users\Wfxewsvo\AppData\Local\Temp\GalaxyInstaller_upwiU\GalaxyInstaller.exe" 1785384169 "CARRION"
(NULL) C:\Users\Wfxewsvo\AppData\Local\Temp\GalaxyInstaller_upwiU\GalaxyInstaller.exe 1785384169 "CARRION"
C:\Users\Ufexmazn\AppData\Local\Temp\GalaxyInstaller_GNCbg\GalaxyInstaller.exe "C:\Users\Ufexmazn\AppData\Local\Temp\GalaxyInstaller_GNCbg\GalaxyInstaller.exe" 1974801979 "Once Upon a Jester"
(NULL) C:\Users\Ufexmazn\AppData\Local\Temp\GalaxyInstaller_GNCbg\GalaxyInstaller.exe 1974801979 "Once Upon a Jester"
C:\Users\Idfbshzb\AppData\Local\Temp\GalaxyInstaller_HMkXi\GalaxyInstaller.exe "C:\Users\Idfbshzb\AppData\Local\Temp\GalaxyInstaller_HMkXi\GalaxyInstaller.exe" 1718217391 "Operation Body Count"
(NULL) C:\Users\Idfbshzb\AppData\Local\Temp\GalaxyInstaller_HMkXi\GalaxyInstaller.exe 1718217391 "Operation Body Count"
C:\Users\Pooyexob\AppData\Local\Temp\GalaxyInstaller_CjSbK\GalaxyInstaller.exe "C:\Users\Pooyexob\AppData\Local\Temp\GalaxyInstaller_CjSbK\GalaxyInstaller.exe" 1466717340 "The Black Guards of Odom - Desert Town Prison"
(NULL) C:\Users\Pooyexob\AppData\Local\Temp\GalaxyInstaller_CjSbK\GalaxyInstaller.exe 1466717340 "The Black Guards of Odom - Desert Town Prison"
C:\Users\Upvdycvo\AppData\Local\Temp\GalaxyInstaller_KtFrX\GalaxyInstaller.exe "C:\Users\Upvdycvo\AppData\Local\Temp\GalaxyInstaller_KtFrX\GalaxyInstaller.exe" 1207658864 "Star Wolves"
(NULL) C:\Users\Upvdycvo\AppData\Local\Temp\GalaxyInstaller_KtFrX\GalaxyInstaller.exe 1207658864 "Star Wolves"
C:\Users\Cwcxkgij\AppData\Local\Temp\GalaxyInstaller_ZlxGG\GalaxyInstaller.exe "C:\Users\Cwcxkgij\AppData\Local\Temp\GalaxyInstaller_ZlxGG\GalaxyInstaller.exe" 1604634952 "Warhammer 40,000: Gladius - Relics of War"
(NULL) C:\Users\Cwcxkgij\AppData\Local\Temp\GalaxyInstaller_ZlxGG\GalaxyInstaller.exe 1604634952 "Warhammer 40,000: Gladius - Relics of War"
C:\Users\Nfwfdbeu\AppData\Local\Temp\GalaxyInstaller_bxLPe\GalaxyInstaller.exe "C:\Users\Nfwfdbeu\AppData\Local\Temp\GalaxyInstaller_bxLPe\GalaxyInstaller.exe" 1449139823 "Sins of a Solar Empire®: Rebellion Ultimate Edition"
(NULL) C:\Users\Nfwfdbeu\AppData\Local\Temp\GalaxyInstaller_bxLPe\GalaxyInstaller.exe 1449139823 "Sins of a Solar Empire®: Rebellion Ultimate Edition"
C:\Users\Xexoswlj\AppData\Local\Temp\GalaxyInstaller_bsbyL\GalaxyInstaller.exe "C:\Users\Xexoswlj\AppData\Local\Temp\GalaxyInstaller_bsbyL\GalaxyInstaller.exe" 1207659118 "Hotline Miami"
(NULL) C:\Users\Xexoswlj\AppData\Local\Temp\GalaxyInstaller_bsbyL\GalaxyInstaller.exe 1207659118 "Hotline Miami"
C:\Users\Wvibqflt\AppData\Local\Temp\GalaxyInstaller_BWxeA\GalaxyInstaller.exe "C:\Users\Wvibqflt\AppData\Local\Temp\GalaxyInstaller_BWxeA\GalaxyInstaller.exe" 1658549380 "M1 Tank Platoon II"
(NULL) C:\Users\Wvibqflt\AppData\Local\Temp\GalaxyInstaller_BWxeA\GalaxyInstaller.exe 1658549380 "M1 Tank Platoon II"
C:\Users\Kgappagf\AppData\Local\Temp\GalaxyInstaller_oOKJz\GalaxyInstaller.exe "C:\Users\Kgappagf\AppData\Local\Temp\GalaxyInstaller_oOKJz\GalaxyInstaller.exe" 1150150052 "God's Trigger"
(NULL) C:\Users\Kgappagf\AppData\Local\Temp\GalaxyInstaller_oOKJz\GalaxyInstaller.exe 1150150052 "God's Trigger"
C:\Users\Adehugqw\AppData\Local\Temp\GalaxyInstaller_NwMvO\GalaxyInstaller.exe "C:\Users\Adehugqw\AppData\Local\Temp\GalaxyInstaller_NwMvO\GalaxyInstaller.exe" 1423049311 "Cyberpunk 2077"
(NULL) C:\Users\Adehugqw\AppData\Local\Temp\GalaxyInstaller_NwMvO\GalaxyInstaller.exe 1423049311 "Cyberpunk 2077"
C:\Users\Vgiumyba\AppData\Local\Temp\GalaxyInstaller_WlHwg\GalaxyInstaller.exe "C:\Users\Vgiumyba\AppData\Local\Temp\GalaxyInstaller_WlHwg\GalaxyInstaller.exe" 1411626324 "Tower of Time"
(NULL) C:\Users\Vgiumyba\AppData\Local\Temp\GalaxyInstaller_WlHwg\GalaxyInstaller.exe 1411626324 "Tower of Time"
C:\Users\Qqroikmp\AppData\Local\Temp\GalaxyInstaller_DlXnZ\GalaxyInstaller.exe "C:\Users\Qqroikmp\AppData\Local\Temp\GalaxyInstaller_DlXnZ\GalaxyInstaller.exe" 2085685147 "DragonStrike"
(NULL) C:\Users\Qqroikmp\AppData\Local\Temp\GalaxyInstaller_DlXnZ\GalaxyInstaller.exe 2085685147 "DragonStrike"
C:\Users\Capwunzk\AppData\Local\Temp\GalaxyInstaller_YRTgQ\GalaxyInstaller.exe "C:\Users\Capwunzk\AppData\Local\Temp\GalaxyInstaller_YRTgQ\GalaxyInstaller.exe" 1689019552 "Shores Unknown: Arrival"
(NULL) C:\Users\Capwunzk\AppData\Local\Temp\GalaxyInstaller_YRTgQ\GalaxyInstaller.exe 1689019552 "Shores Unknown: Arrival"
C:\Users\Nkptuqty\AppData\Local\Temp\GalaxyInstaller_YoJEw\GalaxyInstaller.exe "C:\Users\Nkptuqty\AppData\Local\Temp\GalaxyInstaller_YoJEw\GalaxyInstaller.exe" 2044656083 "The Whispering Valley"
(NULL) C:\Users\Nkptuqty\AppData\Local\Temp\GalaxyInstaller_YoJEw\GalaxyInstaller.exe 2044656083 "The Whispering Valley"
C:\Users\Wnwoaoar\AppData\Local\Temp\GalaxyInstaller_EIVeV\GalaxyInstaller.exe "C:\Users\Wnwoaoar\AppData\Local\Temp\GalaxyInstaller_EIVeV\GalaxyInstaller.exe" 1908018720 "Spiritfarer Demo"
(NULL) C:\Users\Wnwoaoar\AppData\Local\Temp\GalaxyInstaller_EIVeV\GalaxyInstaller.exe 1908018720 "Spiritfarer Demo"
C:\Users\Ltfnaamq\AppData\Local\Temp\GalaxyInstaller_WfpLz\GalaxyInstaller.exe "C:\Users\Ltfnaamq\AppData\Local\Temp\GalaxyInstaller_WfpLz\GalaxyInstaller.exe" 1604634952 "Warhammer 40,000: Gladius - Relics of War"
(NULL) C:\Users\Ltfnaamq\AppData\Local\Temp\GalaxyInstaller_WfpLz\GalaxyInstaller.exe 1604634952 "Warhammer 40,000: Gladius - Relics of War"
C:\Users\Iengivad\AppData\Local\Temp\GalaxyInstaller_KeIYa\GalaxyInstaller.exe "C:\Users\Iengivad\AppData\Local\Temp\GalaxyInstaller_KeIYa\GalaxyInstaller.exe" 1554935533 "The House of Da Vinci"
(NULL) C:\Users\Iengivad\AppData\Local\Temp\GalaxyInstaller_KeIYa\GalaxyInstaller.exe 1554935533 "The House of Da Vinci"
C:\Users\Osiwxgaf\AppData\Local\Temp\GalaxyInstaller_CSbWt\GalaxyInstaller.exe "C:\Users\Osiwxgaf\AppData\Local\Temp\GalaxyInstaller_CSbWt\GalaxyInstaller.exe" 1914671919 "XCOM®: Chimera Squad"
(NULL) C:\Users\Osiwxgaf\AppData\Local\Temp\GalaxyInstaller_CSbWt\GalaxyInstaller.exe 1914671919 "XCOM®: Chimera Squad"