Wizard 101

By GoldSparrow in Potentially Unwanted Programs

Threat Scorecard

Popularity Rank: 21,302
Threat Level: 50 % (Medium)
Infected Computers: 1
First Seen: June 19, 2013
Last Seen: August 30, 2026
OS(es) Affected: Windows

Wizard 101 is a gaming application, which is automatically dropped onto the PC when the computer user logs into Wizard101.com website to play some online game. While Wizard 101 is not as dangerous as numerous damaging applications, it is reported by security researchers and PC users to be an unwanted program. Wizard 101 is difficult to uninstall from the corrupted PC because it doesn't show up on the list of Add/Remove Programs. If Wizard 101 has entered the PC without the computer user's authorization asked, it means that this application can be configured to record browsing activity, result in disturbing diversions on the hijacked Internet browser and show unwanted pop-up advertisements during your Internet sessions. Once Wizard 101 enters the targeted computer system, it modifies some computer system's settings involving the default start page, default search engine and other.

Analysis Report

General information

Family Name: PUP.GameHack.HG
Signature status: No Signature

Known Samples

MD5: a6029007ec1662ee7886e9853d917673
SHA1: f498d5b7a34d2583e3f3536f3ddae33e0afec7e3
SHA256: 588B8BCF5A626AB5BDA9F4FDBB94B703BC0333CF42EA9D46EA48E5A3FF32947C
File Size: 9.37 MB, 9374720 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • x86

Block Information

Total Blocks: 18,523
Potentially Malicious Blocks: 10,308
Whitelisted Blocks: 8,215
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x x x 0 x 0 x x 0 0 x x x x x x x x x x x x x x x x x x x x 0 x 0 0 0 x x x x 0 x 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x x x x 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x x x x x x x 0 x x x 0 0 0 0 0 0 x x x x x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 x x x x 0 x 0 x x x x x x x x x x x x x 0 x x 0 0 0 0 x x x x x x x x x x 0 0 x 0 0 x x 0 0 0 x x x 0 x x 0 x 0 x x x x 0 0 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 0 x 0 x 0 x 0 x 0 0 x 0 x x x x 0 0 0 x x x x x x x x 0 x x 0 0 x 0 x x x x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x 0 x 0 x x x 0 x x x x x x x 0 0 x 0 0 x 0 x x x x x x 0 x x 0 x 0 x x x 0 x 0 0 0 0 0 x x x 0 0 0 x x 0 0 x 0 0 x 0 0 0 0 0 0 0 x x 0 x x x x 0 0 x 0 x 0 x x x x x x x x 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x x x x x 0 0 0 0 x 0 0 0 0 x x x x 0 0 x 0 x x 0 x 0 0 0 0 0 0 0 x 0 x x 0 x 0 0 0 x x x 0 0 x 0 0 0 0 0 0 0 0 x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x 0 0 0 x x x x x x x x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 0 0 x x x x 0 x 0 x x 0 0 x x x x x 0 0 0 0 x x x 0 x 0 0 0 x x 0 x 0 x x 0 0 0 0 0 x x x x 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 x 0 0 x x 0 0 0 0 0 x 0 0 0 x x x x x 0 x 0 0 0 x 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 0 0 0 x x x 0 0 x x x x 0 x x 0 x 0 x x x x 0 x 0 x x 0 x 0 0 0 x x x x x x x 0 x x x x x x x x x 0 x x 0 x 0 x x 0 x x 0 x x x x x 0 0 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 x 0 x x x 0 x 0 0 x x 0 x 0 0 x x x 0 0 x 0 x x 0 x x 0 x 0 0 0 x 0 x x x x x x 0 x 0 x 0 x x x x x x 0 x 0 x x x x x 0 x x x x x x 0 x x x x x x x x 0 x 0 x x x 0 x x 0 x x x x x 0 0 x x x 0 0 0 x x 0 x x x x x 0 x 0 x x x 0 x x x x 0 x 0 x 0 x x 0 x 0 x x x x x x x x x 0 0 0 0 0 x x x x x x x x x x x x x x x 0 x x x x x 0 0 x 0 x x x x x 0 x 0 x x x x x x x 0 x x x x 0 x x 0 0 0 0 x x x x x x x 0 0 x x x x x x x x x x x 0 0 x x x 0 0 x x x x x x x x x x x x x x x x x 0 x x x 0 x x x x x 0 x x x x 0 x x x x 0 x x x x 0 x x x 0 x x x 0 0 0 0 x x x 0 0 0 x x x x x 0 x 0 x x x 0 x 0 0 x x x x x x 0 x x 0 x x x x 0 x 0 0 x x x x x x 0 x x 0 0 x x x x 0 0 0 0 x 0 x x 0 x 0 x x x x x 0 0 x x x x x x x x 0 x x x x x 0 x x x 0 0 0 0 0 x x x x x x x x x 0 x x x 0 x x 0 x x x x x 0 0 x 0 x 0 x 0 0 x x 0 x x x x 0 0 0 0 0 x x 0 0 x x x 0 0 x 0 x 0 x x 0 0 x 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 x x x 0 x x x x 0 x x x x 0 x 0 0 x 0 x x x x x x x 0 x x x x x x x x 0 x 0 x x 0 0 0 x x x 0 0 0 x x x x x x x 0 x x x x 0 0 0 0 x x x x x x x x x x x 0 0 x 0 0 x x x x x 0 x 0 x x x x x x x 0 0 x 0 0 0 x x 0 x x x x x x x 0 x x x x x x x x x x x 0 x 0 x x x x x x x 0 x x x x x x 0 x 0 x x x x x x 0 x x x 0 0 x x x x x x x 0 x x 0 x x 0 x 0 0 0 0 0 x x x x x 0 x x x x x 0 x 0 0 0 x x x x x 0 0 x x x x x x x x x x x x x x 0 x x x x x x x x x x 0 0 x x x x x x x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 0 0 0 x x x x x x x x x x x x 0 0 0 0 x x x x x x x x x x x x x 0 x x x 0 0 x x 0 0 0 0 0 x x x 0 0 x x 0 0 0 0 x x x x x x x x x x x x x 0 x 0 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 0 0 0 x 0 x 0 x x x x x x x 0 0 0 x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • GameHack.HG

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Terminate
  • TerminateProcess

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f498d5b7a34d2583e3f3536f3ddae33e0afec7e3_0009374720.,LiQMAxHB