PUP.MSIL.Gamehack.CCD

The detection of PUP.MSIL.Gamehack.CCD on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is PUP.MSIL.Gamehack.CCD?

PUP.MSIL.Gamehack.CCD is a type of malware that is classified as a potentially unwanted program. This means that it is not necessarily a virus or a trojan, but it can still cause problems with your system and compromise your personal data. PUPs are often installed without the user's knowledge or consent, and they can be difficult to remove.

It's worth noting that PUP.MSIL.Gamehack.CCD is not a specific malware family, but rather a detection name used by security software to identify a particular type of threat. The name suggests that it may be related to gaming hacks or other types of software that are designed to manipulate or cheat in online games.

How PUP.MSIL.Gamehack.CCD Operates

PUP.MSIL.Gamehack.CCD operates by installing itself on your system and then running in the background, often without your knowledge or consent. It may collect personal data, such as browsing history and login credentials, and transmit it to remote servers. It may also display unwanted advertisements, slow down your system, and cause other problems.

It's possible that PUP.MSIL.Gamehack.CCD was installed on your system through a software bundle or a malicious download. It may also have been installed by exploiting a vulnerability in your system or by using social engineering tactics to trick you into installing it.

Symptoms of Infection

If your system is infected with PUP.MSIL.Gamehack.CCD, you may notice a range of symptoms, including slow system performance, unwanted advertisements, and suspicious behavior. You may also notice that your browser settings have been changed, or that new toolbars or extensions have been installed.

Other symptoms of infection may include pop-ups, redirects, and other types of unwanted behavior. You may also notice that your system is crashing or freezing more frequently, or that you are experiencing problems with your internet connection.

How to Remove PUP.MSIL.Gamehack.CCD

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to give you a clean environment to work in.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect and remove any malware that is present.
  3. Uninstall any suspicious programs that you have installed recently, as they may be related to the PUP.MSIL.Gamehack.CCD infection.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any malicious extensions or toolbars that may have been installed.
  5. Reboot your system and perform a follow-up scan to ensure that the malware has been completely removed.

Conclusion

Removing PUP.MSIL.Gamehack.CCD from your system requires careful attention to detail and a thorough understanding of the malware removal process. By following the steps outlined above, you can help to ensure that your system is clean and free of malware, and that your personal data is protected.

It's essential to be proactive in protecting your system from malware and other types of threats. This includes keeping your operating system and software up to date, using strong antivirus software, and being cautious when downloading and installing new programs.

By taking these steps, you can help to prevent future infections and keep your system running smoothly and securely.

Analysis Report

General information

Family Name: PUP.MSIL.Gamehack.CCD
Signature status: No Signature

Known Samples

MD5: f674e7ec482a85ee366ec7992ca627ed
SHA1: 94f5d3219ae76ee755d35b757dba59c64cdd23ca
SHA256: 078DEC6851B89EFC7E69C53946C6D56438AA68BB98011EFC9E216FE28867E308
File Size: 1.56 MB, 1555968 bytes
MD5: ce30181f90e3e49e1f231ba99043bc6a
SHA1: 253540c0c15d004958a4aa7dcdd1856d9e7e543a
SHA256: F09F2B0A249CC073D379E70D0E2D0F61423B4E07CB8823FC495A0FA2A1595DFF
File Size: 5.24 MB, 5244416 bytes
MD5: d63f2a63175bc518301cd9fd74f03b57
SHA1: 68e710b0681d125692cb9ac8fb25b7aaa2548613
SHA256: 0252022FBAAFE99FDA028272A33BA05213F96CF492AFEE88E2F4B8E190C965BA
File Size: 2.61 MB, 2607616 bytes
MD5: 696fb4452eaf8cee8f2056a7aab78551
SHA1: 840316dc8ac382d7a90a399d408d71f99ec4e900
SHA256: D56D30516BE87FEC5B40C75104F5732CCF65B083FCA60CC00B0071A9DEC1939B
File Size: 2.04 MB, 2044416 bytes
MD5: 16c3baa1b9c722070c9c12b746f2270e
SHA1: 6704500072fb09eb9bdd7346ff61d5c6b8382144
SHA256: 30409A2ECC8080DA0093E0A43B56E41C3ED33C998C48B9050BBC17EE89CD25DD
File Size: 590.85 KB, 590848 bytes
Show More
MD5: d81dec997bbe623769b6192dd109b40c
SHA1: fd1f95dd497435ec6d4b1b9bd23e2330370f2923
SHA256: F11E33317DBEFB25ACBD803FB59113870459A0DD8E1FCE439E172AB940936ACB
File Size: 1.65 MB, 1649664 bytes
MD5: afee41274603c228c33866c834d2ffa9
SHA1: 7073f6586d04aa6ded1e78f8ef997d6efded61b1
SHA256: 000E55E389E50C9565C69A759023EBD30529B399DEC76F7FBD2FFC39EDA3F5DD
File Size: 336.38 KB, 336384 bytes
MD5: 893171eabe140f17fbcb8026eeae40c1
SHA1: b5fd4bbb85ade541bb90fef231eb14d822c16524
SHA256: A5894FFA94BD24C5BE1074ECC8730D7814147950BFE4DB078A6C92CEB92F17A9
File Size: 1.56 MB, 1555456 bytes
MD5: 49dee0d65db97d7a5b13cd85175d0fba
SHA1: 42171090353769b1162bfe642ff86b83f4b52e27
SHA256: 05BD6AF16F42CDC984EB2DE26340FDBA848BBD0FDB0B60B65A688418BF40F3A2
File Size: 9.21 MB, 9213440 bytes
MD5: 939dd7e32bb9133333fb7e4b560a6157
SHA1: e29ad3bb06a765c49d6054e1d75cd06bf2d411c0
SHA256: 9B1E347020F0A89CCB0E3018C4B437E7216854CF33CBD43823153FE432748C95
File Size: 1.78 MB, 1777664 bytes
MD5: a43593e3be4823dcaafe8b010119b568
SHA1: 31a7fe7c8e91dba8b4339be63c840fa6715dc0b4
SHA256: 65AB91D168C76EF26805405CAB4D6029AE652B3C08552663EAF70BADDD057165
File Size: 1.65 MB, 1649664 bytes
MD5: 2c7892105b50355fdd978f6aedb3f05b
SHA1: b8010160ccf04ba1950da66c093c9a07ffce637c
SHA256: C1D043397DEDCD15209FE8A71C40AB7C8B3AAC8A1A706B5BC15DD2A95A98C486
File Size: 1.39 MB, 1391104 bytes
MD5: 7b9a4d01da78111a05bbc634abdcd73e
SHA1: 9d30c74a840cdf206484083b90395c1513b8dff3
SHA256: 24E2C9DE432227777BA2C452F5E20B4AC3BECE77DC40FEB350A4BC64DD4089CC
File Size: 453.12 KB, 453120 bytes
MD5: 7be6a43349c6f7bec4701b6ccdc1ed18
SHA1: 708fd9ffb54586c69cd1cb499320cfec0ae223c5
SHA256: 6AA2B14CD5D1D7AC5904BE43A841297E652C458AD3F5BC512BC84D30C70636F6
File Size: 1.86 MB, 1859072 bytes
MD5: c1299e51b8cabc377d884c2cd7159bc0
SHA1: 219f2e7046cb54584c5697f1c68a1ae02eb1c51f
SHA256: 974C30C3EAA281680A3E69FD03C549C15ADFD75C14AFD67594BE15691070C607
File Size: 589.82 KB, 589824 bytes
MD5: 9e655b31cfbec481fd0885d8ccb0e1d0
SHA1: 883fa579cc22a06dc4920c9e2f0e5299c511e853
SHA256: 647044C5B6BB109CD30813763EA1B6A3564B8F18D4FF232BD9388D6F8E549898
File Size: 441.86 KB, 441856 bytes
MD5: e78f13ec35345011adba3580f47ac980
SHA1: 28b24b2e428f723208b3ae623b101c12ad8f8bc5
SHA256: 28D8AD1CAC07051B576E302536D9EE1F31C7280C19C0AB5DA8597B1AB69B722D
File Size: 480.26 KB, 480256 bytes
MD5: 415c0000cbfea3fc3fbb2b163960eff3
SHA1: b4472509ec98733e217b865e819db0dd207ee2b4
SHA256: CBF1088E2E95863C8DEA6DBA2E9349EDD92EA41725995C98F85140F6BCADE796
File Size: 1.86 MB, 1856512 bytes
MD5: 7b8f06b2d895d0fae074ffd9f9a4cab4
SHA1: ee7f505a765613ceabd7177cf8a915231dbe7800
SHA256: 236FC2B02873E641D8E988C7566421BF14C75BD644DF5002210F42E024A56228
File Size: 510.98 KB, 510976 bytes
MD5: 54e44e3febbcf2685a654858bd6dc47f
SHA1: 69804710bd388c81172433ff7dad3afc6b560996
SHA256: ECF18EE5B351271CD52715DEBB83BC3216768433A975DB5F2D148E63F9E1F3AC
File Size: 1.64 MB, 1644032 bytes
MD5: a8034b4ea22210f690fb6075d9ec4e30
SHA1: 43716f078addfa52e09fedc71b93aa48f596cbca
SHA256: B89261F60F8BD4BCAE45AD58D164DCD9487654065EC1E83DE2A3D712E9B64938
File Size: 2.65 MB, 2650624 bytes
MD5: 50f6d9e9148ec36cfae9cf3f2c18c82c
SHA1: e9adfc04c136428d47194e5ada7d4a5070d77154
SHA256: 51B69AE90B702A1EB516597EB19BBDD079A29DDBB729BF56875EBF1CBBEAC252
File Size: 971.26 KB, 971264 bytes
MD5: f0db6d2076f63f39a47e442fdc3d09bc
SHA1: 87a41e54980d295a818729fd555e28775f495080
SHA256: 243656A7A8A2E8B2B0592BFC7A2D62B3E1E2492F7B9F2CF6E01B9D22F16C1C0D
File Size: 1.01 MB, 1012224 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version
  • 1.1.0.0
  • 1.0.239.0
  • 1.0.235.0
  • 1.0.218.0
  • 1.0.199.0
  • 1.0.176.0
  • 1.0.171.0
  • 1.0.158.0
  • 1.0.147.0
  • 1.0.133.0
Show More
  • 1.0.77.0
  • 1.0.0.1
  • 1.0.0.0
Comments Softland.Email.ConfiguracionSistema - Lee la configuraci�n de empresa y realiza el env�o de correos segun esa configuraci�n
Company Name
  • CamMod
  • EXO Engine
  • HurtworldClientExt
  • KaizenLicenseUtility
  • ORBIT FREE
  • QuorumAPI
  • RexonAuth
  • SelfTracker
  • Softland Ltda.
File Description
  • CamMod
  • EXO Engine
  • HurtworldClientExt
  • KaizenLicenseUtility
  • ORBIT FREE
  • QuorumAPI
  • RexonAuth
  • SelfTracker
  • ShibaGT Genesis
  • Softland.Email.ConfiguracionSistema
File Version
  • 1.1.0.0
  • 1.0.239.0
  • 1.0.235.0
  • 1.0.218.0
  • 1.0.199.0
  • 1.0.176.0
  • 1.0.171.0
  • 1.0.158.0
  • 1.0.147.0
  • 1.0.133.0
Show More
  • 1.0.77.0
  • 1.0.0.47
  • 1.0.0.1
  • 1.0.0.0
Internal Name
  • CamMod.dll
  • EXO Engine.dll
  • HurtworldClientExt.dll
  • KaizenLicenseUtility.dll
  • ORBIT FREE.dll
  • QuorumAPI.dll
  • RexonAUTH.dll
  • SelfTracker.dll
  • ShibaGT Genesis.dll
  • Softland.Email.ConfiguracionSistema.dll
Legal Copyright
  • Copyright © 2023
  • Softland Ltda. Copyright � 2018
Legal Trademarks Softland Chile Ltda.
Original Filename
  • CamMod.dll
  • EXO Engine.dll
  • HurtworldClientExt.dll
  • KaizenLicenseUtility.dll
  • ORBIT FREE.dll
  • QuorumAPI.dll
  • RexonAUTH.dll
  • SelfTracker.dll
  • ShibaGT Genesis.dll
  • Softland.Email.ConfiguracionSistema.dll
Product Name
  • CamMod
  • EXO Engine
  • HurtworldClientExt
  • KaizenLicenseUtility
  • ORBIT FREE
  • QuorumAPI
  • RexonAuth
  • SelfTracker
  • ShibaGT Genesis
  • Softland.Email.ConfiguracionSistema
Product Version
  • 1.1.0
  • 1.0.239
  • 1.0.235
  • 1.0.218
  • 1.0.199
  • 1.0.176
  • 1.0.171
  • 1.0.158
  • 1.0.147
  • 1.0.133
Show More
  • 1.0.77
  • 1.0.1+e467ea6d712af8055c3578f2281a823222a5cc45
  • 1.0.0.47
  • 1.0.0.0
  • 1.0.0+f88d31a47768a4df4ff33b6971accb481afdca11
  • 1.0.0

File Traits

  • .NET
  • CryptUnprotectData
  • dll
  • No CryptProtectData
  • ntdll
  • RijndaelManaged
  • x64
  • x86

Block Information

Total Blocks: 603
Potentially Malicious Blocks: 45
Whitelisted Blocks: 382
Unknown Blocks: 176

Visual Map

x 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? ? 0 0 0 0 0 0 0 ? ? x ? 0 0 0 0 0 0 0 x ? 0 0 0 0 ? ? ? ? ? ? 0 0 ? 0 ? 0 0 0 0 ? ? 0 ? x 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? ? ? 0 0 0 ? ? ? ? 0 0 ? 0 ? ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 x 0 0 ? 0 ? 0 ? x 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 x 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 x x ? ? ? ? 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 x ? 0 0 0 0 x 0 x ? 0 0 x ? 0 0 0 0 x 0 x ? 0 0 ? ? 0 x 0 0 0 ? 0 ? 0 0 0 ? ? ? x 0 0 0 ? 0 0 0 x 0 0 0 ? 0 ? 0 0 0 x 0 0 ? 0 ? ? x 0 ? 0 0 0 0 0 ? 0 0 ? ? 0 0 ? ? ? 0 0 ? 0 0 0 ? 0 0 0 x ? 0 ? 0 ? ? ? x 0 0 0 0 ? 0 ? ? ? 0 0 0 ? ? ? 0 0 ? ? ? 0 0 ? 0 0 0 ? ? ? ? ? ? 0 ? ? ? x ? 0 ? ? ? 0 0 ? 0 0 0 0 0 ? 0 ? ? ? ? x x 0 0 ? ? 0 0 ? ? ? ? x ? ? ? ? 0 0 0 0 ? x 0 x ? ? 0 ? ? 0 x 0 x ? 0 0 0 0 x ? 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 0 x ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 x ? 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x ? 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.FSDA
  • MSIL.Gamehack.CCD

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
Show More
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserGetWindowCompositionAttribute
  • win32u.dll!NtUserIsNonClientDpiScalingEnabled
  • win32u.dll!NtUserIsTopLevelWindow
  • win32u.dll!NtUserMessageCall
  • win32u.dll!NtUserRegisterClassExWOW
  • win32u.dll!NtUserRegisterWindowMessage
  • win32u.dll!NtUserReleaseDC
  • win32u.dll!NtUserRemoveProp
  • win32u.dll!NtUserSelectPalette
  • win32u.dll!NtUserSetCursorIconData
  • win32u.dll!NtUserSetWindowFNID

3 additional items are not displayed above.

Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\219f2e7046cb54584c5697f1c68a1ae02eb1c51f_0000589824.,LiQMAxHB