PUP.MSIL.Gamehack.BOD

The detection of PUP.MSIL.Gamehack.BOD on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand what this detection means and how to properly remove it to prevent any potential harm.

What Is PUP.MSIL.Gamehack.BOD?

PUP.MSIL.Gamehack.BOD is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. The name suggests that it may be related to gaming, but its actual purpose and behavior can vary. PUPs are often bundled with other software or downloaded from untrusted sources, and they can cause a range of problems, including slowing down your computer, displaying unwanted ads, and potentially stealing personal data.

How PUP.MSIL.Gamehack.BOD Operates

PUPs like PUP.MSIL.Gamehack.BOD can operate in various ways, but they often use similar tactics to evade detection and persist on a system. They may use stealthy installation methods, such as bundling with other software or exploiting vulnerabilities in operating systems or applications. Once installed, they can collect user data, display unwanted ads, or even install additional malware. In some cases, PUPs can also interfere with system settings, causing performance issues or crashes.

Symptoms of Infection

If your system is infected with PUP.MSIL.Gamehack.BOD, you may notice various symptoms, including slow system performance, unwanted ads or pop-ups, and changes to your browser settings or homepage. You may also experience crashes or freezes, especially when running resource-intensive programs. In some cases, you may notice suspicious programs or processes running in the background, consuming system resources.

  • Unwanted ads or pop-ups
  • Changes to browser settings or homepage
  • Slow system performance
  • Crashes or freezes
  • Suspicious programs or processes running in the background

How to Remove PUP.MSIL.Gamehack.BOD

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for a clean removal process.
  2. Run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove PUP.MSIL.Gamehack.BOD and any related malware.
  3. Uninstall any suspicious programs or applications that may be related to the PUP.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any changes made by the PUP.
  5. Reboot your system and run another scan to ensure that the PUP has been completely removed.

Conclusion

Removing PUP.MSIL.Gamehack.BOD from your system is crucial to prevent any potential harm and restore your computer's performance and security. By following the steps outlined above, you can effectively remove the PUP and prevent future infections. It's essential to remain vigilant and take proactive measures to protect your system, including keeping your operating system and software up to date, using reputable anti-malware tools, and being cautious when downloading software or clicking on links from untrusted sources.

Analysis Report

General information

Family Name: PUP.MSIL.Gamehack.BOD
Signature status: No Signature

Known Samples

MD5: 5f9f782f273c355ab40cabf29268a2f3
SHA1: c573f1326ddb33885b334b63512eef512c63fc0d
SHA256: 764534F1EC005FDE0337096602E9820EA505BCA6AA8D9B9F2EDFEFC0E62C8F71
File Size: 968.19 KB, 968192 bytes
MD5: 8e571f47f390a946eb7dc0c967ce5ccb
SHA1: 6735861de0d02ca06ec975b35afba25da41cfbab
SHA256: 9B24583A4EDA6FC748B994FF161AEA9DAC7377BEE5E060C25F61E952B5D0CC13
File Size: 2.41 MB, 2409984 bytes
MD5: 9b5e9fca608a5dabdc93e0645af713c6
SHA1: e5d0290f04d6e1bd5768934c3b1bad6c1aab73db
SHA256: 04DFD13A3F87A379345AA290CCA36950BBF04E8BECC69B242FB2DFDDEC3D9D70
File Size: 6.63 MB, 6633472 bytes
MD5: 8500b552d282e2cdf06f0eadc8cad77d
SHA1: fc2386d896d90f0b6c96b4e100b0f96f2a789c25
SHA256: 3A3AD28EC7EC28F3347E0B7ED385E6BFAF770763CBC4138619D54217366CB13D
File Size: 1.12 MB, 1122304 bytes
MD5: 4460d97169c4960821f34257506df747
SHA1: 08c509cddd0b82f09f7c44f0fb82d3d50395c961
SHA256: 467932DED84E82130622D59FCE22DB2D9B8D5F991F6280FDFA831E0A0C63E88B
File Size: 56.32 KB, 56320 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 134.5.2021.14
  • 1.5.0.0
  • 1.2.50.0
  • 1.0.0.0
Comments
  • Libreria de controles para C# y VB.net
  • Outlast 2 Trainer + 3rd person Mod v1.5
Company Name
  • MZ Design Software
  • Timm3D
File Description
  • Commission_Report_Generator
  • Deising UI Librery By: Manuel Zaragoza
  • FlatUI
  • Outlast 2 Trainer + 3rd person Mod v1.5
  • Pokemon Wallpaper 2.0.6
File Version
  • 1.5
  • 1.2.50.0
  • 1.0.0.0
Internal Name
  • Commission_Report_Generator.exe
  • FlatUI.dll
  • Outlast 2 Trainer + 3rd person Mod v1.5.exe
  • Pokemon Wallpaper 2.0.6.exe
  • UIDC.dll
Legal Copyright
  • Copyright © 2015
  • Copyright © 2017 - 2090
  • Copyright © 2018
  • Copyright © 2021
  • Copyright © Manuel Zaragoza 2020
Legal Trademarks
  • Manuel Zaragoza
  • Timm3D
Original Filename
  • Commission_Report_Generator.exe
  • FlatUI.dll
  • Outlast 2 Trainer + 3rd person Mod v1.5.exe
  • Pokemon Wallpaper 2.0.6.exe
  • UIDC.dll
Product Name
  • Commission_Report_Generator
  • Deising UI
  • FlatUI
  • Outlast 2 Trainer + 3rd person Mod v1.5
  • Pokemon Wallpaper 2.0.6
Product Version
  • 1.5
  • 1.2.50.0
  • 1.0.0.0

File Traits

  • .NET
  • dll
  • HighEntropy
  • NewLateBinding
  • Pastebin
  • WriteProcessMemory
  • x64
  • x86

Block Information

Total Blocks: 305
Potentially Malicious Blocks: 101
Whitelisted Blocks: 204
Unknown Blocks: 0

Visual Map

0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 x 0 x x x x 0 0 x x x 0 x 0 0 0 x 0 0 x 0 x x x x x x x x 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 x x 0 0 0 x x x 0 x 0 x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x x x x 0 0 0 0 x 0 0 0 0 x x x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 x x x x x x 0 0 0 0 0 x x 0 x 0 x x 0 x x x x 0 0 0 0 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Gamehack.BOD

Files Modified

File Attributes
c:\users\user\vs_executions\c573f1326ddb33885b334b63512eef512c63fc0d_0000968192.html Generic Write,Read Attributes

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...