PUP.MSIL.Gamehack.YC
The detection of PUP.MSIL.Gamehack.YC on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take appropriate steps to remove it to prevent any potential harm.
Table of Contents
What Is PUP.MSIL.Gamehack.YC?
PUP.MSIL.Gamehack.YC is a type of potentially unwanted program that is designed to operate in the background of your system, often without your knowledge or consent. The name suggests that it may be related to gaming hacks or cheats, but its actual purpose and behavior can vary. PUPs like this one can be bundled with other software, downloaded from untrusted sources, or installed through exploits in vulnerable applications.
How PUP.MSIL.Gamehack.YC Operates
Once installed, PUP.MSIL.Gamehack.YC may start to collect data about your system, browsing habits, or gaming activities. It might also display unwanted advertisements, modify system settings, or install additional software without your permission. In some cases, PUPs can even communicate with remote servers to receive updates or transmit stolen data. The primary goal of such programs is often to generate revenue for their creators through affiliate marketing, pay-per-click schemes, or by selling collected data to third parties.
Symptoms of Infection
Systems infected with PUP.MSIL.Gamehack.YC may exhibit a range of symptoms, including slower performance, increased pop-up advertisements, or unexpected changes to browser settings. You might also notice unfamiliar programs or toolbars installed on your system, or experience frequent crashes and freezes. In some cases, the presence of a PUP can lead to more severe issues, such as data breaches or the installation of additional malware.
- Unwanted advertisements and pop-ups
- Changes to browser settings or homepage
- Slow system performance or crashes
- Unfamiliar programs or toolbars installed
- Data breaches or identity theft
How to Remove PUP.MSIL.Gamehack.YC
- Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for a more straightforward removal process.
- Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any associated files or registry entries.
- Uninstall any suspicious programs or applications that were installed around the time the PUP was detected.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or modifications.
- Reboot your system and perform another scan with your anti-malware tool to ensure that all remnants of the PUP have been removed.
Conclusion
Removing PUP.MSIL.Gamehack.YC from your system is crucial to prevent any potential harm and maintain your computer's performance and security. By following the steps outlined above and using reputable anti-malware tools, you can effectively eliminate this threat and protect your system from similar infections in the future. Remember to always be cautious when downloading software, keep your operating system and applications up-to-date, and use strong antivirus protection to minimize the risk of PUPs and other types of malware.
Analysis Report
General information
| Family Name: | PUP.MSIL.Gamehack.YC |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
82f239a33af9a606a45bcb1e35d6dc8d
SHA1:
10a9c4dc124b5c5905543ea237c84711f4a936d0
SHA256:
DA62DDDEAA65CB1E29E8D502FBBD1F1F6BE7D5A68374CE489D9B0F671BBBD942
File Size:
4.18 MB, 4176384 bytes
|
|
MD5:
e38ebbc3b27e0e01b3f904b5ac832fd5
SHA1:
1087e1f3533ff743cfca7dff570daffcef12665d
SHA256:
966D0FBF53DF863D118440F3B6148EC290B2FD5D4A28FFF5D74E8F83DF343202
File Size:
6.06 MB, 6056960 bytes
|
|
MD5:
7e83e72548a900c242765bd494410aeb
SHA1:
fdf2e4e499d451166581c731956824f9fc25ce45
SHA256:
D4EAB0F6FA163AB1EA245EF8CBE2AF8C0F5360779CBCADE03E31AEC68A12A356
File Size:
5.62 MB, 5618688 bytes
|
|
MD5:
bdcaf06b8c7b2a785aec8ae90db08ecd
SHA1:
9a3079b2473b99bd0169fdf5bb96c0cd63804670
SHA256:
75678616E7744E37951AFFC3DF7C503E2AD5439AB8DB7D473106D147F722B2D0
File Size:
4.11 MB, 4106240 bytes
|
|
MD5:
3e4c28e5936170b9acf6d09a096d6915
SHA1:
d1d0bb8a4fefc912d9200cd6b9fbe9b72e484857
SHA256:
C6A7DBB5C8D6A17A8FF5017A2B14A00063FC3EDA8E12156AE0D52F83D75888BB
File Size:
5.28 MB, 5282304 bytes
|
Show More
|
MD5:
da4870bf25b24cc4655ae6dfd7c6febd
SHA1:
479fc5e04d499741e55dca3eb3554fc76a607523
SHA256:
69B4E39C84566FEA85E3C53A73DA1F338305358D339DD9D21471818D9D27431A
File Size:
6.06 MB, 6056960 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have security information
- File is .NET application
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Assembly Version |
|
| Comments |
|
| Company Name |
|
| File Description |
|
| File Version |
|
| Internal Name | Launcher.exe |
| Legal Copyright |
|
| Original Filename | Launcher.exe |
| Product Name |
|
| Product Version |
|
File Traits
- .NET
- HighEntropy
- RijndaelManaged
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 302 |
|---|---|
| Potentially Malicious Blocks: | 100 |
| Whitelisted Blocks: | 187 |
| Unknown Blocks: | 15 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe\gmdasllogger | Generic Write,Read Attributes |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\windows\appcompat\programs\amcache.hve | Read Data,Read Control,Write Data |
| c:\windows\appcompat\programs\amcache.hve | Write Attributes |
| c:\windows\appcompat\programs\amcache.hve.log1 | Read Data,Write Data |
| c:\windows\appcompat\programs\amcache.hve.log2 | Read Data,Write Data |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\software\microsoft\tip\aggregateresults::data | 馐ʊ耀Ś T 隞̃耀꧌ є 2 | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �l Z 1 �6 �vT������ 1��3bBx �R �7#��%`� &�-'�(�(X�*9+��1�1HO =� @V� F?H[uH�� N� Z^� _�zb"hc�zg�jj�bk`k�k�qk�8 l(�r�BsU�vy�w�nx�{b��P� �jI�/������7����M�b:��� ����!��X��� | RegNtPreCreateKey |
| HKLM\system\software\microsoft\tip\aggregateresults::data | 鐄ȴ 鲱 綗 픋˹耀뫹躧 隞̃ﴁ耀꧌ Ѭ ĥ | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| User Data Access |
|
| Anti Debug |
|
| Process Shell Execute |
|
| Encryption Used |
|
| Process Manipulation Evasion |
|
| Syscall Use |
Show More
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 884
|
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 692
|
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 876
|
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 840
|