PUP.MSIL.Gamehack.CJO

The detection of PUP.MSIL.Gamehack.CJO on your system indicates the presence of a potentially unwanted program (PUP) that may compromise your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it to prevent potential harm.

What Is PUP.MSIL.Gamehack.CJO?

PUP.MSIL.Gamehack.CJO is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. The name suggests that it may be related to gaming, but its actual purpose and behavior can vary. PUPs are often bundled with other software or downloaded from untrusted sources, and they can cause a range of problems, including slowing down your system, displaying unwanted ads, and potentially leading to more severe malware infections.

How PUP.MSIL.Gamehack.CJO Operates

PUPs like PUP.MSIL.Gamehack.CJO typically operate by installing themselves on your system and then running in the background, often without your knowledge or consent. They may collect data about your browsing habits, system configuration, and other sensitive information, which can be used for targeted advertising or other malicious purposes. In some cases, PUPs may also attempt to download and install additional malware or unwanted software, further compromising your system's security.

Symptoms of Infection

If your system is infected with PUP.MSIL.Gamehack.CJO, you may notice a range of symptoms, including slow system performance, unwanted ads or pop-ups, and unexpected changes to your browser settings or system configuration. You may also notice that your system is running more slowly than usual, or that certain programs or applications are not functioning properly. In some cases, you may not notice any symptoms at all, which is why it's essential to regularly scan your system for malware and other threats.

How to Remove PUP.MSIL.Gamehack.CJO

  1. Boot your system in Safe Mode with Networking to prevent the PUP from running and to give you more control over the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware or other threats that may be present.
  3. Uninstall any suspicious programs or applications that may be related to the PUP, using the Add/Remove Programs feature in your system's Control Panel.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or add-ons that may be associated with the PUP.
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that the PUP has been completely removed and that your system is free from any other threats.

Conclusion

Removing PUP.MSIL.Gamehack.CJO from your system is essential to prevent potential harm and protect your personal data. By following the steps outlined above, you can help ensure that your system is secure and free from malware. It's also important to take steps to prevent future infections, such as being cautious when downloading software, avoiding untrusted sources, and keeping your operating system and security software up to date. By taking a proactive approach to system security, you can help protect yourself from a range of threats and keep your system running smoothly and efficiently.

Analysis Report

General information

Family Name: PUP.MSIL.Gamehack.CJO
Signature status: No Signature

Known Samples

MD5: 16deb00c870104de42175e0e08395611
SHA1: 547a0e505eb670e3e38282e02ea1682e58530d83
SHA256: F3761414191BA39DE3F150F2A9EE6F3AF95BD3C535B813BEC8813C37296C22EC
File Size: 184.32 KB, 184320 bytes
MD5: cabd693c484c31bf2be09c6b9684fd50
SHA1: 2546ee92ad40ea99094934c1ba32cf0ff663d0a8
SHA256: 8A999FF9E8C7140383B2BFA160985CE875D2598AD76248AF5BE2AF3061002651
File Size: 119.30 KB, 119296 bytes
MD5: d7f7eff2c1635a53041a40dc54a8a60f
SHA1: 624b4818f3e11dc26969b17d019ee48bbef227fc
SHA256: F27E50D6D0B9688887CFD69ABCC498961C7BF9D3AD0D27D3BAD8E1870677C68A
File Size: 125.44 KB, 125440 bytes
MD5: 1a47d37d58014d62ae00623fc30b7ce3
SHA1: b7488527f7666fc16a923fbc25cbf38cc54099b9
SHA256: 4C14C940350D0F6914A95FFE056D0EC7F1AD5306664D24A75F72273BCA6FCAD9
File Size: 53.25 KB, 53248 bytes
MD5: 291fd99c9b0ae287fb8587a406378385
SHA1: a4d29bd8f9666086c0b8669b32439ffd37b6ade1
SHA256: E7754A53C87C1E94685632376A69F04C45B0BD7395C8F53E45AAFF2292A95664
File Size: 211.97 KB, 211968 bytes
Show More
MD5: abefcc2f1775a3d5f780244f5d5b6f52
SHA1: 0c198fc5ccac7b558f5d1849d003aae8ae8906f2
SHA256: 2DFA48AA1D9AFE146BE0C93914F88D924B30DC4604FFA7D6B50FB2ACE254605D
File Size: 214.02 KB, 214016 bytes
MD5: 97ae2d5dcb72d143ed7c1360c08785a4
SHA1: f199d61d3fb371c11f9a91518e3f57778689b5d3
SHA256: 4B64CE408795A0A022234CEC78D2FC50D6A849FC4D78D72190247C8AD596C82C
File Size: 308.74 KB, 308736 bytes
MD5: 0b397dcfafa6e89480f249d96324b572
SHA1: dc0860e512c1002eda6599d867c1f14b8246efe7
SHA256: 429A560737B5B8B47C414A8C266B5B48CD4192B46354A39BA2A50FD8BF931B14
File Size: 148.99 KB, 148992 bytes
MD5: f0f2e701f2698bd67920eb2336e0713d
SHA1: 6fabdc0de1015da6adfd08609996bd76fef90b5f
SHA256: 12A3CC914D754917C3031C42B02FFD673420F8B14A5720EB68C2DEDA30C715BF
File Size: 240.64 KB, 240640 bytes
MD5: ee1f3a9d9ca04d0aba0b066f52c3ffea
SHA1: 22f91173d103e11d19981b3ec3172e62b9519c33
SHA256: 6B6951388A535B5B066E489702D85B150BF9F7EE262CB2A955D2E460459A6270
File Size: 119.30 KB, 119296 bytes
MD5: b76f93b07ab955102651acfb667ffb95
SHA1: 8177138e402c2ac82ebc7b31a11ba5d05af1fa70
SHA256: 3E786B465D6D1D29BD92E762C84164FBAD6545464A16D0237B102829505BB7CC
File Size: 152.58 KB, 152576 bytes
MD5: 2ddb1efb4c0bf86c75746c70a78f0c91
SHA1: 916817ee8b0e6e1e554ee0aab6013f5ae41251d1
SHA256: B2598C0766822ABE62DEE12A4C4B08D5F00105F3927500441EC9284347CAA3A8
File Size: 259.58 KB, 259584 bytes
MD5: 035d94e52f19d5416dfd7f12b6ff1a09
SHA1: fb4188413744e0c2815bd887c0e394ee92986ed5
SHA256: 5D55B2AF5ADC0359518A28EDBC920ABECAD74C54487BF7D87CC76488AAC84462
File Size: 118.27 KB, 118272 bytes
MD5: e0e6cf29917938ae4b04d625a2640e9f
SHA1: 2a7749db2f22062c58e2f7ae16bbbe6bca05bcd4
SHA256: B45E060F19D6DCC764CB287A199B12CCB055932D9D7C0558C62038E22B23E849
File Size: 99.33 KB, 99328 bytes
MD5: 81c76dad4d02e0973fe5900bd55aa7b0
SHA1: 4ecff1cca890ed2184987f818d4bceec637200fe
SHA256: 2817BCF65C2122B3F8C5C08C83808B523A0BBF3C97D11B4AC293BF4B991F586E
File Size: 91.14 KB, 91136 bytes
MD5: 068ae22505df2c2dbf0dae9246945660
SHA1: 844c756350b289ca5d4e343eb4ba4bbd4a03fb09
SHA256: 2817AB856C3D568804632CEBAE25D3D33A51F885F55CFFE1F0E2AE5DE0F1DC63
File Size: 110.59 KB, 110592 bytes
MD5: c98198ddcc755ba4be6e8cc7c37bf8b9
SHA1: d0dba353657f898dee2b76a18dbb4a3f5d1e9c19
SHA256: A493DC5B827F24A381B2A826490E5B21DEDB3F2BECA490CD15A94829E0200E51
File Size: 66.05 KB, 66048 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments
  • A Good Menu Made By Malachi
  • A Perfect Template Made By Malachi
Company Name
  • AetherTemplate
  • BreezeV2
  • Frost Byte Menu
  • LeanMenuBeta
  • MeltsMenu
  • Project Malachi
  • pxslware
  • ReviaClient
  • Selenite
  • Singularity OS
Show More
  • StupidTemplate
  • ViperX1 Coaster Menu V7.0
File Description
  • AetherTemplate
  • BreezeV2
  • Frost Byte Menu
  • LeanMenuBeta
  • Malachis Menu Reborn
  • MalachiTemp
  • MeltsMenu
  • pxslware
  • ReviaClient
  • Selenite
Show More
  • Singularity OS
  • StupidTemplate
  • ViperX1 Coaster Menu V7.0
File Version 1.0.0.0
Internal Name
  • AetherTemplate.dll
  • BreezeV2.dll
  • Frost Byte Menu.dll
  • GKongMenu.dll
  • LeanMenuBeta.dll
  • Malachis_Menu_Reborn.dll
  • MalachiTemp.dll
  • MeltsMenu.dll
  • pxslware.dll
  • ReviaClient.dll
Show More
  • Selenite.dll
  • Singularity OS.dll
  • StupidTemplate.dll
  • ViperX1 Coaster Menu V7.0.dll
  • WizzyClientV2.dll
Legal Copyright Copyright Project Malachi© 2024
Original Filename
  • AetherTemplate.dll
  • BreezeV2.dll
  • Frost Byte Menu.dll
  • GKongMenu.dll
  • LeanMenuBeta.dll
  • Malachis_Menu_Reborn.dll
  • MalachiTemp.dll
  • MeltsMenu.dll
  • pxslware.dll
  • ReviaClient.dll
Show More
  • Selenite.dll
  • Singularity OS.dll
  • StupidTemplate.dll
  • ViperX1 Coaster Menu V7.0.dll
  • WizzyClientV2.dll
Product Name
  • AetherTemplate
  • BreezeV2
  • Frost Byte Menu
  • LeanMenuBeta
  • Malachis Menu Reborn
  • MalachiTemp
  • MeltsMenu
  • pxslware
  • ReviaClient
  • Selenite
Show More
  • Singularity OS
  • StupidTemplate
  • ViperX1 Coaster Menu V7.0
Product Version
  • 1.0.0.0
  • 1.0.0+5d06d32c2b3d2f09648ab58cfa45674c45f0af05
  • 1.0.0

File Traits

  • .NET
  • dll
  • Pastebin
  • x86

Block Information

Total Blocks: 98
Potentially Malicious Blocks: 28
Whitelisted Blocks: 16
Unknown Blocks: 54

Visual Map

x ? ? 0 x x ? ? ? ? x 0 x x x x x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? x x x x ? ? x x ? ? 0 0 ? x ? ? x x ? x x ? ? x x 0 x 0 ? x 0 x x ? 0 0 ? ? x ? 0 0 ? ? 0 0 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserGetWindowCompositionAttribute
  • win32u.dll!NtUserIsNonClientDpiScalingEnabled
  • win32u.dll!NtUserIsTopLevelWindow
  • win32u.dll!NtUserMessageCall
  • win32u.dll!NtUserRegisterClassExWOW
  • win32u.dll!NtUserRegisterWindowMessage
  • win32u.dll!NtUserReleaseDC
  • win32u.dll!NtUserRemoveProp
  • win32u.dll!NtUserSelectPalette
  • win32u.dll!NtUserSetCursorIconData
  • win32u.dll!NtUserSetWindowFNID
  • win32u.dll!NtUserSetWindowLongPtr
  • win32u.dll!NtUserSetWindowPos
  • win32u.dll!NtUserUpdateInputContext