PUP.MSIL.Gamehack.Z

The detection of PUP.MSIL.Gamehack.Z on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.MSIL.Gamehack.Z?

PUP.MSIL.Gamehack.Z is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. The name suggests that it may be related to gaming, but its actual purpose and behavior can vary. PUPs are often bundled with other software or downloaded from untrusted sources, and they can cause a range of problems, from annoying pop-ups and ads to more serious issues like data theft and system compromise.

How PUP.MSIL.Gamehack.Z Operates

Like other PUPs, PUP.MSIL.Gamehack.Z may operate by installing itself on your system and then running in the background, often without your knowledge or consent. It may collect data about your browsing habits, search history, and other online activities, and use this information to display targeted ads or sell it to third-party companies. In some cases, PUPs can also install additional software or malware on your system, which can lead to more serious problems.

PUPs can be difficult to detect and remove, as they often disguise themselves as legitimate programs or hide in plain sight. They may also use tactics like fake alerts and warnings to trick you into installing additional software or paying for unnecessary services.

Symptoms of Infection

If your system is infected with PUP.MSIL.Gamehack.Z, you may notice a range of symptoms, including slow system performance, annoying pop-ups and ads, and unexpected changes to your browser settings or homepage. You may also notice that your system is running more slowly than usual, or that your browser is crashing or freezing frequently. In some cases, you may also receive fake alerts or warnings that claim to have detected malware or other problems on your system.

  • Slow system performance
  • Annoying pop-ups and ads
  • Unexpected changes to browser settings or homepage
  • System crashes or freezes
  • Fake alerts or warnings

How to Remove PUP.MSIL.Gamehack.Z

  1. Boot your system in Safe Mode with Networking to prevent the PUP from running and interfering with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware or PUPs that may be present.
  3. Uninstall any suspicious programs or software that you don't recognize or need, as these may be related to the PUP.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any changes made by the PUP.
  5. Reboot your system and run another scan with your anti-malware tool to ensure that the PUP has been completely removed.

Conclusion

Removing PUP.MSIL.Gamehack.Z from your system requires a combination of technical knowledge and caution. By following the steps outlined above and using reputable anti-malware tools, you can help to ensure that your system is safe and secure. It's also essential to be vigilant when downloading software or clicking on links, as PUPs can often be bundled with other programs or disguised as legitimate software. By taking the necessary precautions and staying informed, you can help to protect your system and your personal data from the risks associated with PUPs like PUP.MSIL.Gamehack.Z.

Analysis Report

General information

Family Name: PUP.MSIL.Gamehack.Z
Signature status: No Signature

Known Samples

MD5: f776e7683a93ff8ebdaf57e8d3441170
SHA1: e92d27e7a7ba3194cd39ce164f5d5cad8d198144
SHA256: 8D49C9664684E27094CAF0010ADFA39FEED29D4CACCD84D861B68C7BFB3A6CC7
File Size: 6.17 MB, 6173696 bytes
MD5: 30616a76ec377dba180a814a7c59b214
SHA1: 80a605c6799a7781479491b02832c39e10f7c361
SHA256: 59B651A346CD12B1107AE1F5C7621B73FEC39C49D3A417E79D6659BCB5A6CF9F
File Size: 9.17 MB, 9173504 bytes
MD5: 0c8cbf729759ecd96edcb9ca4975fcb8
SHA1: 3364e53714b75f04d23ecc810146e908ae7edb9e
SHA256: 70526DED9A3D9B9EF5570826C6CD4A2D6992336F172008785CD951BB462C0D49
File Size: 7.53 MB, 7532544 bytes
MD5: 79b33b3e00e41f862573ea0ede958852
SHA1: e5f75c882333a30616808a411ff073e04fd74651
SHA256: 917EEAB7B4AEB44523C190E162B4A866108EED51F0B6700665B044D74977C979
File Size: 9.17 MB, 9173504 bytes
MD5: 584c5279c6e808fec11f0b8c3d8b2412
SHA1: ad1bba3f632b15151a1566983412771685ffb3be
SHA256: 7C36440C24324E323DCB8D2B85AC9EA6E6C007DEFF8977C436A624FDB7F7C071
File Size: 9.17 MB, 9173504 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 1.0.0.3
  • 1.0.0.1
Comments
  • Cabal Launcher
  • ElementsGO Launcher
  • Uno Launcher
Company Name
  • Cabal Online
  • unodevelopments
File Description
  • Cabal Launcher
  • ElementsGO Launcher
  • Uno Launcher
File Version
  • 1.0.0.3
  • 1.0.0.1
Internal Name
  • Update.exe
  • update.exe
Legal Copyright
  • Copyright © 2016
  • Copyright © Cabal Online 2025
  • Copyright © Uno 2025
Original Filename
  • Update.exe
  • update.exe
Product Name
  • Cabal Launcher
  • ElementsGO Launcher
  • Uno Launcher
Product Version
  • 1.0.0.3
  • 1.0.0.1

File Traits

  • .NET
  • HighEntropy
  • RijndaelManaged
  • x64
  • x86

Block Information

Total Blocks: 126
Potentially Malicious Blocks: 44
Whitelisted Blocks: 74
Unknown Blocks: 8

Visual Map

? ? x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 x 0 x x x x x ? x x x ? ? 0 0 x x x x x 0 0 0 x x 0 0 0 x 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 x 0 x 0 x x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Gamehack.Z

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\software\microsoft\tip\aggregateresults::data 馐ʊ耀ŚT쎫ʝ耀誙꣗ߦ÷ⳛ˼耀塉½ⳛ˼耀塉ⳛ˼䀀ᯙ鏾隞̃؁耀꧌ߎބ䮑̛༺䮩̛耀ѷ꛵ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Process Terminate
  • TerminateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Network Winsock2
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • setsockopt
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 1016

Related Posts

Trending

Most Viewed

Loading...