Technical Information
- [<HKLM>\System\CurrentControlSet\Services\Groupy] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Groupy] 'ImagePath' = '%ProgramFiles(x86)%\Stardock\Groupy\GroupySrv.exe'
- 'Groupy' %ProgramFiles(x86)%\Stardock\Groupy\GroupySrv.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im GroupyConfig.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im GroupyCtrl.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im GroupyHelp32.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im GroupyHelp64.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im SDDisplay.exe
- '%WINDIR%\syswow64\net.exe' stop Groupy
- Handler for all processes: %ProgramFiles(x86)%\Stardock\Groupy\groupy_32.dll
- Handler for all processes: %ProgramFiles(x86)%\Stardock\Groupy\groupy_64.dll
- %TEMP%\autc995.tmp
- %ProgramFiles(x86)%\stardock\groupy\sdappservices_x64.dll
- %ProgramFiles(x86)%\stardock\groupy\sddisplay.exe
- %ProgramFiles(x86)%\stardock\groupy\sddisplay.exe.config
- %ProgramFiles(x86)%\stardock\groupy\stardock.applicationservices.dll
- %ProgramFiles(x86)%\stardock\groupy\default.spak
- %ProgramFiles(x86)%\stardock\groupy\groupyhelp32.exe
- %ProgramFiles(x86)%\stardock\groupy\groupyhelp64.exe
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\stardock\groupy.lnk
- %ProgramFiles(x86)%\stardock\groupy\uninstall\irimg1.jpg
- %ProgramFiles(x86)%\stardock\groupy\uninstall\irimg2.jpg
- %ProgramFiles(x86)%\stardock\groupy\uninstall\unicode.lmd
- %LOCALAPPDATA%\stardock\groupy\saslog.txt
- %TEMP%\aut3c07.tmp
- %ProgramFiles(x86)%\stardock\groupy\~edxevvd.tmp
- %TEMP%\dup2patcher.dll
- %TEMP%\c5e3399ed9a072fe864748d49ba96094.dll
- %ProgramFiles(x86)%\stardock\groupy\pointer.bat
- %ProgramFiles(x86)%\stardock\groupy\movefile.exe
- %ProgramFiles(x86)%\stardock\groupy\pre.bat
- %ProgramFiles(x86)%\stardock\groupy\sdappservices.dll.todo
- %ProgramFiles(x86)%\stardock\groupy\sdappservices_x64.dll.todo
- %ProgramFiles(x86)%\stardock\groupy\stardock.applicationservices.dll.todo
- %ProgramFiles(x86)%\stardock\groupy\groupy_32.dll.todo
- %ProgramFiles(x86)%\stardock\groupy\groupy_64.dll.todo
- %ProgramFiles(x86)%\stardock\groupy\groupy32.exe.todo
- %ProgramFiles(x86)%\stardock\groupy\groupyconfig.exe.todo
- %ProgramFiles(x86)%\stardock\groupy\groupyctrl.exe.todo
- %ProgramFiles(x86)%\stardock\groupy\post.bat
- %WINDIR%\wontrust.dll
- %ProgramFiles(x86)%\stardock\groupy\sdappservices.dll
- %WINDIR%\womtrust.dll
- %ProgramFiles(x86)%\stardock\groupy\sasupgrade.exe
- %ProgramFiles(x86)%\stardock\groupy\groupysrv.exe
- %CommonProgramFiles(x86)%\~pmlcyls.tmp
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\lua5.1.dll
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %TEMP%\_ir_sf_temp_0\irimg1.jpg
- %TEMP%\_ir_sf_temp_0\irimg2.jpg
- %TEMP%\_ir_sf_temp_0\getmachinesid.exe
- %TEMP%\_ir_sf_temp_0\eula.txt
- %TEMP%\_ir_sf_temp_0\unicode.lmd
- %TEMP%\_ir_sf_temp_0\getmachinesid.tmp
- %TEMP%\sdwebresults.xml
- %TEMP%\groupy setup log.txt
- %ProgramFiles(x86)%\stardock\groupy\uninstall\uni9f0.tmp
- %ProgramFiles(x86)%\stardock\groupy\uninstall\uninstall.dat
- %ProgramFiles(x86)%\stardock\groupy\uninstall.exe
- %ProgramFiles(x86)%\stardock\groupy\lua5.1.dll
- %ProgramFiles(x86)%\stardock\groupy\uninstall\uninstall.xml
- %ProgramFiles(x86)%\stardock\groupy\deelevate.exe
- %ProgramFiles(x86)%\stardock\groupy\deelevate64.exe
- %ProgramFiles(x86)%\stardock\groupy\deelevator.dll
- %ProgramFiles(x86)%\stardock\groupy\deelevator64.dll
- %ProgramFiles(x86)%\stardock\groupy\eula.txt
- %ProgramFiles(x86)%\stardock\groupy\groupy_32.dll
- %ProgramFiles(x86)%\stardock\groupy\groupy_64.dll
- %ProgramFiles(x86)%\stardock\groupy\groupy32.exe
- %ProgramFiles(x86)%\stardock\groupy\groupyctrl.exe
- %ProgramFiles(x86)%\stardock\groupy\readme.txt
- %ProgramFiles(x86)%\stardock\groupy\groupyconfig.exe
- %ProgramFiles(x86)%\stardock\groupy\groupycore.exe
- %ProgramFiles(x86)%\stardock\groupy\license_sas.txt
- %HOMEPATH%\desktop\groupy.lnk
- %CommonProgramFiles(x86)%\~pmlcyls.tmp
- %TEMP%\autc995.tmp
- %TEMP%\dup2patcher.dll
- %ProgramFiles(x86)%\stardock\groupy\post.bat
- %ProgramFiles(x86)%\stardock\groupy\pre.bat
- %ProgramFiles(x86)%\stardock\groupy\pointer.bat
- %TEMP%\aut3c07.tmp
- %TEMP%\_ir_sf_temp_0\lua5.1.dll
- %ProgramFiles(x86)%\stardock\groupy\~edxevvd.tmp
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\eula.txt
- %TEMP%\_ir_sf_temp_0\getmachinesid.exe
- %TEMP%\_ir_sf_temp_0\irimg2.jpg
- %TEMP%\_ir_sf_temp_0\irimg1.jpg
- %ProgramFiles(x86)%\stardock\groupy\uninstall\uni9f0.tmp
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %TEMP%\_ir_sf_temp_0\unicode.lmd
- %CommonProgramFiles(x86)%\~pmlcyls.tmp
- http://in#####.api.stardock.net/installer/Initialize/?fo########
- http://in#####.api.stardock.net/installer/SaveInstallStats/?fo########
- DNS ASK in#####.api.stardock.net
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '' WindowName: ''
- '%CommonProgramFiles(x86)%\~pmlcyls.tmp' /S
- '%ProgramFiles(x86)%\stardock\groupy\~edxevvd.tmp' /silent /overwrite /startupworkdir="%ProgramFiles(x86)%\Stardock\Groupy"
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "Stardock.ApplicationServices.dll.todo" "Stardock.ApplicationServices.dll"
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "SdAppServices_x64.dll.todo" "SdAppServices_x64.dll"
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "SdAppServices.dll.todo" "SdAppServices.dll"
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "GroupyConfig.exe" ""
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "SdAppServices_x64.dll" ""
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "Groupy32.exe" ""
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "Groupy_64.dll" ""
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "Stardock.ApplicationServices.dll" ""
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "Groupy_64.dll.todo" "Groupy_64.dll"
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "SdAppServices.dll" ""
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "Groupy_32.dll.todo" "Groupy_32.dll"
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "Groupy_32.dll" ""
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "Groupy32.exe.todo" "Groupy32.exe"
- '%ProgramFiles(x86)%\stardock\groupy\groupysrv.exe'
- '%ProgramFiles(x86)%\stardock\groupy\groupyhelp64.exe'
- '%ProgramFiles(x86)%\stardock\groupy\groupysrv.exe' -install
- '%ProgramFiles(x86)%\stardock\groupy\groupyhelp32.exe'
- '%ProgramFiles(x86)%\stardock\groupy\groupyctrl.exe'
- '%ProgramFiles(x86)%\stardock\groupy\groupyconfig.exe'
- '%ProgramFiles(x86)%\stardock\groupy\groupycore.exe'
- '%TEMP%\_ir_sf_temp_0\irsetup.exe' /S __IRAOFF:1901490 "__IRAFN:%CommonProgramFiles(x86)%\~pmlcyls.tmp" "__IRCT:3" "__IRTSS:6274238" "__IRSID:S-1-5-21-1960123792-2022915161-3775307078-1001"
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "GroupyCtrl.exe.todo" "GroupyCtrl.exe"
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "GroupyConfig.exe.todo" "GroupyConfig.exe"
- '%ProgramFiles(x86)%\stardock\groupy\movefile.exe' /accepteula "GroupyCtrl.exe" ""
- '%TEMP%\_ir_sf_temp_0\getmachinesid.exe' %TEMP%\_ir_sf_temp_0\GetMachineSID.tmp
- '%WINDIR%\syswow64\taskkill.exe' /f /im SDDisplay.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im GroupyHelp32.exe' (with hidden window)
- '%TEMP%\_ir_sf_temp_0\getmachinesid.exe' %TEMP%\_ir_sf_temp_0\GetMachineSID.tmp' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' export HKLM\Software\Stardock %TEMP%\registry_export.txt /reg:32 /y' (with hidden window)
- '%ProgramFiles(x86)%\stardock\groupy\groupysrv.exe' -install' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im GroupyCtrl.exe' (with hidden window)
- '%ProgramFiles(x86)%\stardock\groupy\groupyhelp64.exe' ' (with hidden window)
- '%ProgramFiles(x86)%\stardock\groupy\groupyhelp32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im GroupyConfig.exe' (with hidden window)
- '%WINDIR%\syswow64\net.exe' stop Groupy' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im GroupyHelp64.exe' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' export HKLM\Software\Stardock %TEMP%\registry_export.txt /reg:32 /y
- '%WINDIR%\syswow64\net1.exe' stop Groupy
- '<SYSTEM32>\cmd.exe' /c "%ProgramFiles(x86)%\Stardock\Groupy\pointer.bat"
- '<SYSTEM32>\cmd.exe' /c "%ProgramFiles(x86)%\Stardock\Groupy\pre.bat"
- '<SYSTEM32>\cmd.exe' /c "%ProgramFiles(x86)%\Stardock\Groupy\post.bat"