Technical Information
- <SYSTEM32>\tasks\taloncybersecupdatetaskmachinecore
- <SYSTEM32>\tasks\taloncybersecupdatetaskmachineua
- [<HKLM>\System\CurrentControlSet\Services\talon] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\talon] 'ImagePath' = '"%ProgramFiles(x86)%\TalonCyberSec\Update\TalonUpdate.exe" /svc'
- [<HKLM>\System\CurrentControlSet\Services\talonm] 'ImagePath' = '"%ProgramFiles(x86)%\TalonCyberSec\Update\TalonUpdate.exe" /medsvc'
- 'talon' "%ProgramFiles(x86)%\TalonCyberSec\Update\TalonUpdate.exe" /svc
- 'talonm' "%ProgramFiles(x86)%\TalonCyberSec\Update\TalonUpdate.exe" /medsvc
- %ProgramFiles(x86)%\taloncybersec\temp\gute16a.tmp
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_lt.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_lv.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_ml.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_mr.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_ms.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_nl.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_kn.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_ko.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_no.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_pt-pt.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_ro.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_ru.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_sk.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_sl.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_sr.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_pl.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_pt-br.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_sw.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_sv.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_it.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_en-gb.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_es.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_es-419.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_et.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_fa.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_iw.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_el.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_ja.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_fi.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_hi.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_hr.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_hu.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_id.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_is.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_fil.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_fr.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_gu.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_kn.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_ta.dll
- %WINDIR%\temp\cabab61.tmp
- %WINDIR%\temp\cababb1.tmp
- %WINDIR%\temp\tarabb2.tmp
- %WINDIR%\temp\cabc1d2.tmp
- %WINDIR%\temp\tarc1d3.tmp
- %WINDIR%\temp\cabd9f6.tmp
- %WINDIR%\temp\tar9486.tmp
- %WINDIR%\temp\tard9f7.tmp
- %WINDIR%\temp\tarab62.tmp
- %WINDIR%\temp\tarf056.tmp
- %WINDIR%\temp\tarf0c5.tmp
- %WINDIR%\temp\cab7cf.tmp
- %WINDIR%\temp\tar7d0.tmp
- %WINDIR%\temp\cab82f.tmp
- %WINDIR%\temp\tar830.tmp
- %WINDIR%\temp\cabf055.tmp
- %WINDIR%\temp\cab9485.tmp
- %WINDIR%\temp\cabf0c4.tmp
- %WINDIR%\temp\tar9417.tmp
- %WINDIR%\temp\cab9416.tmp
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_th.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_uk.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_ur.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_vi.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_zh-cn.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_zh-tw.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\psuser.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\psuser_64.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_tr.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\psmachine.dll
- %ProgramFiles(x86)%\taloncybersec\update\talonupdate.exe
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\talonupdatesetup.exe
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\talonupdatebroker.exe
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\talonupdateondemand.exe
- %WINDIR%\temp\cab57c0.tmp
- %WINDIR%\temp\tar57c1.tmp
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_de.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\psmachine_64.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_en.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_da.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_cs.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_ca.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_es.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_es-419.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_et.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_fa.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_fi.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_el.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_da.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_en-gb.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_fil.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_hr.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_hu.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_id.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_is.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_it.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_fr.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_gu.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_hi.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_de.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_cs.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_iw.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\taloncrashhandler.exe
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdate.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\talonupdatebroker.exe
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\talonupdateondemand.exe
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\talonupdatecomregistershell64.exe
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\psmachine.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\psmachine_64.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\talonupdate.exe
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\psuser.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\taloncrashhandler64.exe
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\talonupdatecore.exe
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_am.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_ar.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_bg.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_bn.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_ca.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\psuser_64.dll
- %WINDIR%\temp\cab1e5f.tmp
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_te.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_ja.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_lv.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_vi.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_zh-cn.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_zh-tw.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\talonupdatesetup.exe
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\talonupdate.exe
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_tr.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdate.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_ur.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\taloncrashhandler.exe
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\talonupdatecomregistershell64.exe
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_am.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_ar.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_bg.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\goopdateres_bn.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\talonupdatecore.exe
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_en.dll
- %ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\taloncrashhandler64.exe
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_uk.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_th.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_te.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_ml.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_mr.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_ms.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_nl.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_no.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_pl.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_lt.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_pt-br.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_ro.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_ru.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_sk.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_sl.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_sr.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_sv.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_sw.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_pt-pt.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_ta.dll
- %ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\goopdateres_ko.dll
- %WINDIR%\temp\tar1e60.tmp
- %WINDIR%\temp\cab57c0.tmp
- %WINDIR%\temp\tar830.tmp
- %WINDIR%\temp\cab82f.tmp
- %WINDIR%\temp\tar7d0.tmp
- %WINDIR%\temp\cab7cf.tmp
- %WINDIR%\temp\tarf0c5.tmp
- %WINDIR%\temp\cabf0c4.tmp
- %WINDIR%\temp\tarf056.tmp
- %WINDIR%\temp\cabf055.tmp
- %WINDIR%\temp\tard9f7.tmp
- %WINDIR%\temp\cabd9f6.tmp
- %WINDIR%\temp\tarc1d3.tmp
- %WINDIR%\temp\cabc1d2.tmp
- %WINDIR%\temp\tarabb2.tmp
- %WINDIR%\temp\cababb1.tmp
- %WINDIR%\temp\tarab62.tmp
- %WINDIR%\temp\cabab61.tmp
- %WINDIR%\temp\tar9486.tmp
- %WINDIR%\temp\cab9485.tmp
- %WINDIR%\temp\tar9417.tmp
- %WINDIR%\temp\cab9416.tmp
- %WINDIR%\temp\tar57c1.tmp
- %WINDIR%\temp\cab1e5f.tmp
- %WINDIR%\temp\tar1e60.tmp
- 'bf#######21507bb.talon-sec.com':443
- 'microsoft.com':80
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- 'bf#######21507bb.talon-sec.com':443
- DNS ASK bf#######21507bb.talon-sec.com
- DNS ASK microsoft.com
- '%ProgramFiles(x86)%\taloncybersec\temp\gume169.tmp\talonupdate.exe' /installsource taggedmi /install "appguid={1609A9BE-6579-42B3-B531-A08423FCDA33}&appname=TalonWork&needsadmin=prefers&usagestats=1&lang=en"
- '%ProgramFiles(x86)%\taloncybersec\update\talonupdate.exe' /regsvc
- '%ProgramFiles(x86)%\taloncybersec\update\talonupdate.exe' /regserver
- '%ProgramFiles(x86)%\taloncybersec\update\1.3.100.3\talonupdatecomregistershell64.exe'
- '%ProgramFiles(x86)%\taloncybersec\update\talonupdate.exe' /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xMDAuMyIgc2hlbGxfdmVyc2lvbj0iMS4zLjEwMC4zIiBpc21hY2hpbmU...
- '%ProgramFiles(x86)%\taloncybersec\update\talonupdate.exe' /handoff "appguid={1609A9BE-6579-42B3-B531-A08423FCDA33}&appname=TalonWork&needsadmin=prefers&usagestats=1&lang=en" /installsource taggedmi /sessionid "{53EABA45-902A-455A-B0CC-444B9FBCDDAE}"
- '%ProgramFiles(x86)%\taloncybersec\update\talonupdate.exe' /svc