PUP.MSIL.Gamehack.BAVG

The detection of PUP.MSIL.Gamehack.BAVG on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.MSIL.Gamehack.BAVG?

PUP.MSIL.Gamehack.BAVG is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as malicious as other types of malware, it can still cause problems with your system and compromise your personal data. PUPs are often installed unintentionally, bundled with other software or downloaded from untrusted sources.

How PUP.MSIL.Gamehack.BAVG Operates

PUP.MSIL.Gamehack.BAVG operates by installing itself on your system, often without your knowledge or consent. Once installed, it can begin to collect data, display unwanted advertisements, or even hijack your browser settings. It may also attempt to install additional malware or PUPs, further compromising your system's security. The goal of PUP.MSIL.Gamehack.BAVG is to generate revenue for its creators, often at the expense of your system's performance and your personal data.

Symptoms of Infection

If your system is infected with PUP.MSIL.Gamehack.BAVG, you may notice a range of symptoms, including slow system performance, unwanted pop-ups or advertisements, and changes to your browser settings. You may also notice that your system is crashing or freezing more frequently, or that your personal data is being collected or transmitted without your consent. It's essential to be aware of these symptoms and take action quickly to remove the infection and prevent further damage.

  • Unwanted advertisements or pop-ups
  • Changes to browser settings or homepage
  • Slow system performance or crashes
  • Collection or transmission of personal data

How to Remove PUP.MSIL.Gamehack.BAVG

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware or PUPs that may be present.
  3. Uninstall any suspicious programs or applications that may be related to the PUP.MSIL.Gamehack.BAVG infection.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any changes made by the PUP.
  5. Reboot your system and perform a follow-up scan to ensure that the PUP has been successfully removed and that no additional threats are present.

Conclusion

Removing PUP.MSIL.Gamehack.BAVG from your system requires a combination of technical knowledge and the right tools. By following the steps outlined above, you can effectively remove the PUP and prevent future infections. It's essential to remain vigilant and take proactive steps to protect your system and personal data from malware and other online threats. Regularly updating your software, avoiding untrusted sources, and using reputable security tools can help to prevent infections and keep your system secure.

Analysis Report

General information

Family Name: PUP.MSIL.Gamehack.BAVG
Signature status: No Signature

Known Samples

MD5: 0ff82aee4fdac06b60d475910762d3bd
SHA1: 45bb9a435b43abde253822f816263c7ce71252ee
SHA256: 0DBC04A4E9D13EA42871644AC62AA08EA47997C751F3438B9132CA5C75E38B86
File Size: 305.66 KB, 305664 bytes
MD5: 4bfa2c03654a7bf8f6fda580dce11bb0
SHA1: 1146e099c9abc2696e64493ba0c35bd422b42f5e
SHA256: 3F57A82AF5373CD330B270D78D422DB946CC0612F04006520B8686D66C3C2726
File Size: 325.12 KB, 325120 bytes
MD5: d53163d6aeedeae2db12489d9c3dc074
SHA1: 89473f3a3ac060ad10f1cfbe7c918c93d47fb863
SHA256: 65B4309EEF26E4EF10CB0F1FB7C8702AE73A0EDC91F991B3FD9D1EF85F615D2F
File Size: 427.52 KB, 427520 bytes
MD5: ed2758a3e5c15b4a436ace6fd031c63b
SHA1: b7d4c66502bfc477a2b7dae623d42790e71fdd45
SHA256: 664F195CA491792756FF867A2EA1D26E3A75DD2DD98874C713A56B4CD46C20F1
File Size: 102.40 KB, 102400 bytes
MD5: 340688121f393569905ed25ba2a5aefd
SHA1: 0452e36d40cb299530389040664e34f1f25f122c
SHA256: E3D6025CA9E5C8FBAB48AD60C681FA2847088BD65857A10EDDEF75E2CBEF7900
File Size: 243.71 KB, 243712 bytes
Show More
MD5: 51b3fae8041ccc8d25bea68a7c43dfde
SHA1: 549da4cedca82877bca37f40b11d07fe3dea15e0
SHA256: B63AECFA5297AFEF78C0D6946360B12C6ED4D6F5BCFAE1FED3DEF32133C8BB8F
File Size: 764.93 KB, 764928 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name
  • ForceWar.exe
  • Migrate-Printers-AEDXB.exe
  • ToolkitGoomer.exe
  • WinInstaller 2.1.exe
Original Filename
  • ForceWar.exe
  • Migrate-Printers-AEDXB.exe
  • ToolkitGoomer.exe
  • WinInstaller 2.1.exe
Product Version 0.0.0.0

File Traits

  • .NET
  • Installer Version
  • x86

Block Information

Total Blocks: 62
Potentially Malicious Blocks: 21
Whitelisted Blocks: 41
Unknown Blocks: 0

Visual Map

0 0 0 0 x 0 0 x x 0 0 0 x 0 0 0 0 x x x x 0 0 0 0 x 0 0 0 x 0 x x x x x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Gamehack.BAVB
  • MSIL.Gamehack.BAVG
  • MSIL.Gamehack.BAVH
  • MSIL.Gamehack.BOWG
  • MSIL.Gamehack.HM
Show More
  • MSIL.Gamehack.O
  • MSIL.Gamehack.OI
  • MSIL.Gamehack.OIA

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134097194927146465.8292.defaultappdomain.45bb9a435b43abde253822f816263c7ce71252ee_0000305664 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134146192618280351.4968.defaultappdomain.1146e099c9abc2696e64493ba0c35bd422b42f5e_0000325120 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134210545564212194.7204.defaultappdomain.89473f3a3ac060ad10f1cfbe7c918c93d47fb863_0000427520 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134232348954819841.9108.defaultappdomain.b7d4c66502bfc477a2b7dae623d42790e71fdd45_0000102400 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134243019303461030.6712.defaultappdomain.0452e36d40cb299530389040664e34f1f25f122c_0000243712 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134271356523887905.6676.defaultappdomain.549da4cedca82877bca37f40b11d07fe3dea15e0_0000764928 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_2en2i2ra.ip1.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_4wlverod.hop.ps1 Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\__psscriptpolicytest_bb21i0g1.aqt.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_gt1bjl4w.vmq.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_luy4ie45.r2p.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_n5zlmkuw.1wt.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_ogksnu5r.qmk.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_qsfrala4.32x.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_srmdz1ov.uym.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_xdwssp34.hzx.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_xmxdlqf2.wcq.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_xppksust.mig.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\fyuqrwcj\fyuqrwcj.0.cs Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\fyuqrwcj\fyuqrwcj.cmdline Generic Write,Read Attributes
c:\users\user\appdata\local\temp\fyuqrwcj\fyuqrwcj.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\fyuqrwcj\fyuqrwcj.err Generic Write,Read Attributes
c:\users\user\appdata\local\temp\fyuqrwcj\fyuqrwcj.out Generic Write,Read Attributes
c:\users\user\appdata\local\temp\fyuqrwcj\fyuqrwcj.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\vtek2psl\vtek2psl.0.cs Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\vtek2psl\vtek2psl.cmdline Generic Write,Read Attributes
c:\users\user\appdata\local\temp\vtek2psl\vtek2psl.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\vtek2psl\vtek2psl.err Generic Write,Read Attributes
c:\users\user\appdata\local\temp\vtek2psl\vtek2psl.out Generic Write,Read Attributes
c:\users\user\appdata\local\temp\vtek2psl\vtek2psl.tmp Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
Show More
HKLM\software\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ї뛛쿇ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 꼰庯ܖǝ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcDisconnectPort
  • ntdll.dll!NtAlpcQueryInformation
Show More
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThread
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey

23 additional items are not displayed above.

User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Afkqppck\AppData\Local\Temp\vtek2psl\vtek2psl.cmdline"
"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Qvmauxxh\AppData\Local\Temp\fyuqrwcj\fyuqrwcj.cmdline"

Related Posts

Trending

Most Viewed

Loading...