PUP.MSIL.Gamehack.YC

The detection of PUP.MSIL.Gamehack.YC on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take appropriate steps to remove it to prevent any potential harm.

What Is PUP.MSIL.Gamehack.YC?

PUP.MSIL.Gamehack.YC is a type of potentially unwanted program that is designed to operate in the background of your system, often without your knowledge or consent. The name suggests that it may be related to gaming hacks or cheats, but its actual purpose and behavior can vary. PUPs like this one can be bundled with other software, downloaded from untrusted sources, or installed through exploits in vulnerable applications.

How PUP.MSIL.Gamehack.YC Operates

Once installed, PUP.MSIL.Gamehack.YC may start to collect data about your system, browsing habits, or gaming activities. It might also display unwanted advertisements, modify system settings, or install additional software without your permission. In some cases, PUPs can even communicate with remote servers to receive updates or transmit stolen data. The primary goal of such programs is often to generate revenue for their creators through affiliate marketing, pay-per-click schemes, or by selling collected data to third parties.

Symptoms of Infection

Systems infected with PUP.MSIL.Gamehack.YC may exhibit a range of symptoms, including slower performance, increased pop-up advertisements, or unexpected changes to browser settings. You might also notice unfamiliar programs or toolbars installed on your system, or experience frequent crashes and freezes. In some cases, the presence of a PUP can lead to more severe issues, such as data breaches or the installation of additional malware.

  • Unwanted advertisements and pop-ups
  • Changes to browser settings or homepage
  • Slow system performance or crashes
  • Unfamiliar programs or toolbars installed
  • Data breaches or identity theft

How to Remove PUP.MSIL.Gamehack.YC

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for a more straightforward removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any associated files or registry entries.
  3. Uninstall any suspicious programs or applications that were installed around the time the PUP was detected.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or modifications.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that all remnants of the PUP have been removed.

Conclusion

Removing PUP.MSIL.Gamehack.YC from your system is crucial to prevent any potential harm and maintain your computer's performance and security. By following the steps outlined above and using reputable anti-malware tools, you can effectively eliminate this threat and protect your system from similar infections in the future. Remember to always be cautious when downloading software, keep your operating system and applications up-to-date, and use strong antivirus protection to minimize the risk of PUPs and other types of malware.

Analysis Report

General information

Family Name: PUP.MSIL.Gamehack.YC
Signature status: No Signature

Known Samples

MD5: 82f239a33af9a606a45bcb1e35d6dc8d
SHA1: 10a9c4dc124b5c5905543ea237c84711f4a936d0
SHA256: DA62DDDEAA65CB1E29E8D502FBBD1F1F6BE7D5A68374CE489D9B0F671BBBD942
File Size: 4.18 MB, 4176384 bytes
MD5: e38ebbc3b27e0e01b3f904b5ac832fd5
SHA1: 1087e1f3533ff743cfca7dff570daffcef12665d
SHA256: 966D0FBF53DF863D118440F3B6148EC290B2FD5D4A28FFF5D74E8F83DF343202
File Size: 6.06 MB, 6056960 bytes
MD5: 7e83e72548a900c242765bd494410aeb
SHA1: fdf2e4e499d451166581c731956824f9fc25ce45
SHA256: D4EAB0F6FA163AB1EA245EF8CBE2AF8C0F5360779CBCADE03E31AEC68A12A356
File Size: 5.62 MB, 5618688 bytes
MD5: bdcaf06b8c7b2a785aec8ae90db08ecd
SHA1: 9a3079b2473b99bd0169fdf5bb96c0cd63804670
SHA256: 75678616E7744E37951AFFC3DF7C503E2AD5439AB8DB7D473106D147F722B2D0
File Size: 4.11 MB, 4106240 bytes
MD5: 3e4c28e5936170b9acf6d09a096d6915
SHA1: d1d0bb8a4fefc912d9200cd6b9fbe9b72e484857
SHA256: C6A7DBB5C8D6A17A8FF5017A2B14A00063FC3EDA8E12156AE0D52F83D75888BB
File Size: 5.28 MB, 5282304 bytes
Show More
MD5: da4870bf25b24cc4655ae6dfd7c6febd
SHA1: 479fc5e04d499741e55dca3eb3554fc76a607523
SHA256: 69B4E39C84566FEA85E3C53A73DA1F338305358D339DD9D21471818D9D27431A
File Size: 6.06 MB, 6056960 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 1.0.1.6
  • 1.0.0.0
Comments
  • Launcher Premium GamesWteam
  • MuRoX - Season 2
  • XTEAM - Launcher
Company Name
  • GamesWteam
  • www.murox.net
  • www.xteam.com
File Description
  • Launcher MuOnline
  • Launcher X
  • MuRoX
  • XTEAM
File Version
  • 1.0.26.0
  • 1.0.1.6
  • 1.0.0.1
  • 1.0.0.0
Internal Name Launcher.exe
Legal Copyright
  • Copyright © 2017
  • Copyright © 2017 ~ 2023
  • Copyright © 2017 ~ 2024
  • Copyright © MuRoX
  • Copyright © XTEAM
Original Filename Launcher.exe
Product Name
  • Launcher - GamesWteam
  • Launcher X - by louis
  • MuRoX
  • XTEAM
Product Version
  • 1.0.26.0
  • 1.0.1.6
  • 1.0.0.1
  • 1.0.0.0

File Traits

  • .NET
  • HighEntropy
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 302
Potentially Malicious Blocks: 100
Whitelisted Blocks: 187
Unknown Blocks: 15

Visual Map

x 0 x 0 x 0 x 0 0 0 x 0 x 0 x 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x x 0 0 0 0 x x 0 0 ? x x x x x x x x x x x 0 0 x 0 x 0 x 0 0 0 x x 0 x 0 0 0 0 x 0 0 0 0 0 x 0 0 x x x 0 x x x x x 0 0 0 0 x 0 0 0 x 0 x 0 0 x 0 0 0 0 0 0 x 0 0 0 x x x 0 0 x x 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 ? ? x x 0 0 0 0 0 0 0 0 0 ? ? x ? x x x 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x ? x x x x x x x x ? x ? x x x x x x x ? ? ? x 0 0 0 0 0 x 0 x x 0 x x x 0 0 0 x 0 0 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes
c:\windows\appcompat\programs\amcache.hve.log1 Read Data,Write Data
c:\windows\appcompat\programs\amcache.hve.log2 Read Data,Write Data

Registry Modifications

Key::Value Data API Name
HKLM\system\software\microsoft\tip\aggregateresults::data 馐ʊ耀ŚT隞̃耀꧌є2 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �lZ1 �6 �vT������1��3bBx�R �7#��%`�&�-'�(�(X�*9+��1�1HO=�@V�F?H[uH��N�Z^�_�zb"hc�zg�jj�bk`k�k�qk�8l(�r�BsU�vy�w�nx�{b��P��jI�/������7����M�b:�������!��X��� RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 鐄ȴ 鲱綗픋˹耀뫹躧隞̃ﴁ耀꧌Ѭĥ RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
Show More
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Shell Command Execution

C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 884
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 692
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 876
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 840

Related Posts

Trending

Most Viewed

Loading...