PUP.MSIL.Gamehack.OIA

The detection of PUP.MSIL.Gamehack.OIA on your system indicates the presence of a potentially unwanted program (PUP) that may compromise your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is PUP.MSIL.Gamehack.OIA?

PUP.MSIL.Gamehack.OIA is a type of malware that falls under the category of potentially unwanted programs. These programs are often installed without the user's knowledge or consent, usually through bundled software or deceptive download links. They can cause a range of problems, from annoying pop-ups and slowed system performance to more severe issues like data theft and system crashes.

How PUP.MSIL.Gamehack.OIA Operates

PUPs like PUP.MSIL.Gamehack.OIA typically operate by exploiting vulnerabilities in software or using social engineering tactics to trick users into installing them. Once installed, they can collect user data, display unwanted advertisements, or even install additional malware. They may also interfere with system settings, causing problems with browser functionality, network connectivity, or other critical system components.

Symptoms of Infection

Identifying a PUP.MSIL.Gamehack.OIA infection can be challenging, as these programs often disguise themselves as legitimate software. However, common symptoms include unexpected pop-ups, changes in browser settings, slowed system performance, and unfamiliar programs or toolbars installed on your computer. If you notice any of these symptoms, it is crucial to take action promptly to prevent further damage.

  • Unwanted advertisements or pop-ups
  • Changes in browser settings or homepage
  • Slowed system performance or frequent crashes
  • Unfamiliar programs or toolbars installed

How to Remove PUP.MSIL.Gamehack.OIA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to ensure a stable environment for removal.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of the PUP.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time the symptoms began.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the PUP.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all components of the PUP have been removed.

Conclusion

Removing PUP.MSIL.Gamehack.OIA from your system is crucial to restoring your computer's security and performance. By following the steps outlined above and maintaining good computer hygiene, such as regularly updating your software and being cautious with downloads, you can protect your system from similar threats in the future. Remember, prompt action is key to minimizing the impact of a PUP infection and preventing further damage to your system.

Analysis Report

General information

Family Name: PUP.MSIL.Gamehack.OIA
Signature status: No Signature

Known Samples

MD5: 031282f05b213dbaac5c7cd62c24d93d
SHA1: c399e3e8f871cef212de87ace13b1fc14e3ca04e
SHA256: 839650D91F08A0457CADE126B4E7370F196F2CDA004E8E7D9CF742A0476162C5
File Size: 44.54 KB, 44544 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Description Gameloft Server Blocker
File Version 0.0.0.0
Internal Name BlockGameloftGUI.exe
Original Filename BlockGameloftGUI.exe
Product Version 0.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 65
Potentially Malicious Blocks: 21
Whitelisted Blocks: 44
Unknown Blocks: 0

Visual Map

0 0 0 0 x 0 0 x x 0 0 0 x 0 0 0 0 x x x x 0 0 0 0 0 0 0 x 0 0 0 x 0 x x x x x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Gamehack.BAVG
  • MSIL.Gamehack.BOWG
  • MSIL.Gamehack.HM
  • MSIL.Gamehack.O
  • MSIL.Gamehack.OI
Show More
  • MSIL.Gamehack.OIA

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134181003020461919.5248.defaultappdomain.c399e3e8f871cef212de87ace13b1fc14e3ca04e_0000044544 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_0ilvpkxj.lzp.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_letwh3ap.cj1.psm1 Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects

7 additional items are not displayed above.

User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent

Related Posts

Trending

Most Viewed

Loading...