PUP.Gamehack.HDK

The detection of PUP.Gamehack.HDK on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.Gamehack.HDK?

PUP.Gamehack.HDK is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software programs that may not be malicious in nature but can still cause problems with your computer's performance, stability, and security. They often come bundled with other software or are downloaded from the internet, and can be difficult to remove without proper guidance.

How PUP.Gamehack.HDK Operates

PUPs like PUP.Gamehack.HDK typically operate by installing themselves on your system and then running in the background, often without your knowledge or consent. They may collect data about your browsing habits, search history, and other online activities, and may use this information to display targeted advertisements or sell it to third-party companies. In some cases, PUPs may also install additional software or malware on your system, which can lead to further problems and security risks.

Symptoms of Infection

If your system is infected with PUP.Gamehack.HDK, you may notice a range of symptoms, including slow system performance, unwanted pop-ups and advertisements, and changes to your browser settings or homepage. You may also experience issues with your system's stability, such as crashes or freezes, and may notice that your system is running more slowly than usual. In some cases, you may not notice any symptoms at all, which is why it's essential to run regular scans and check for updates to ensure your system is protected.

  • Unwanted changes to your browser settings or homepage
  • Slow system performance or crashes
  • Unwanted pop-ups or advertisements
  • Changes to your system's configuration or settings

How to Remove PUP.Gamehack.HDK

  1. Boot your system in Safe Mode with Networking to prevent the PUP from running and to allow you to download and install removal tools
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan to detect and remove the PUP and any associated malware
  3. Uninstall any suspicious programs or software that may be related to the PUP, using the Add/Remove Programs feature in your system's Control Panel
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any changes made by the PUP
  5. Reboot your system and run another scan to ensure that the PUP has been fully removed and that your system is clean

Conclusion

Removing PUP.Gamehack.HDK from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above and taking proactive measures to protect your system, you can help prevent future infections and keep your computer running smoothly and securely. Remember to always be cautious when downloading software or clicking on links from unknown sources, and to run regular scans to ensure your system is protected against the latest threats.

Analysis Report

General information

Family Name: PUP.Gamehack.HDK
Signature status: No Signature

Known Samples

MD5: b3e595fffb3fe7fcb45c030d111281ad
SHA1: 16e60f184f0f1577bca9551d45938fe7d0afbc14
SHA256: AB01F1A65DAC3F081B8F594DF88694EBE28218901D4B2989BE1FDC0FD6161D13
File Size: 2.45 MB, 2445312 bytes
MD5: 7d98039c538c63fee95a06b937a84de2
SHA1: cb769505f9d64ea3607ee8aff8f51f2e7f522c6e
SHA256: F8D1BFC5C0D18E0D2D8A106A72136396E600CC772CD8E1555ADBB087F45B9CDD
File Size: 349.18 KB, 349184 bytes
MD5: a4f27cdab1b9a91763d8bc1077a7849a
SHA1: c4a163d166e26556627b72e1b00bff755cc3896a
SHA256: A5DB7EA89BF99920237E0548C86FD12025E91E89B28052401F294A7CFC792EA2
File Size: 1.07 MB, 1068032 bytes
MD5: b95a76c5c80dee266307a78b8ca9b9f2
SHA1: 6b9d5d7a57d470de9f9c85087e09b78d952239e6
SHA256: A5F2726C25605048139917520564F8D7ED55B371BDF9CFB19FC7E273B9B8E850
File Size: 1.79 MB, 1785856 bytes
MD5: 80db3abb72f613a673ea659623cb73f4
SHA1: adcbed5e2745f5301968919ba700b12871bacd83
SHA256: 1AA9B0895CAB641120F297DD20D5B13A06D9D816C2719174FDE7C94EAE12F24E
File Size: 409.60 KB, 409600 bytes
Show More
MD5: b9aa8be6582ab033e2af83969ba4fc65
SHA1: 7bd760e41ae9901ee3910de311bdc67bca58a990
SHA256: 4B5343C317CB32DC3470BC5B822D33CE5C842CCC4D3C78D839DA2C0EEE759A84
File Size: 1.31 MB, 1314816 bytes
MD5: 2b6440e0b9a2a2d648ae6a917813abb0
SHA1: 731e27d1bf40cb22a21344f324db2f5e36e67f3c
SHA256: 2A2173D8CA9602B05ED7C59A93DD690F472D8E923C397993008E735E01A4B219
File Size: 1.81 MB, 1805312 bytes
MD5: d9fc803d4d359c9f7c033c8a1e59d2d3
SHA1: 3f92207f80ad83d65af833d118753fd41e855756
SHA256: FE42903D6C86BCABA3E0CC722F8B596258974EF6CFAE895844F77D2D12B7F7C5
File Size: 3.83 MB, 3830784 bytes
MD5: d49e43f12fa0797ff70e56e329a14b2b
SHA1: 52e2ecc73f53ad82db3a330d466d0639cb2362a0
SHA256: EC81E0DB7EE80503F4C494044E54BE1201F6EC0ACCC3B3EDB7E36682C4B2D874
File Size: 1.94 MB, 1944064 bytes
MD5: 98c95e38f3e449061a84310eae53861a
SHA1: 2bca0a2e9b99e0f962446d9f703d214310ce28e2
SHA256: B2F1DA03A5EA2FA295085A290515F84EE52A70CB867D610765445BEA92597ACB
File Size: 3.83 MB, 3830272 bytes
MD5: 3aca25c34fb9183c247dd77000dc9e8d
SHA1: 6e6bc2f60fe717e6f0deee21926dcbb5ee59f41f
SHA256: 8BA277BFAABDCB7FE76D14B1373D5FA68FDCE82DF1CF7655621F471D523E409F
File Size: 2.51 MB, 2513920 bytes
MD5: a7615ffb35efffac391140e9a34425d8
SHA1: c70c1d3ecbdc7c27a5510f424024f38f6d4899dd
SHA256: F14F622C65ABF19DFB17EFAC25E100BEC323C3E924FD60ED52D7162C44CAA8F2
File Size: 1.54 MB, 1540096 bytes
MD5: d6ddabd7ce300d9da3bc5c209583a27b
SHA1: 2dbd29f89a20fd0f0d909f1b1aadd022ba92ee71
SHA256: AE6E40FEEE564902E6FF9D0EC4ECA2FF2F5BBA3143520474B758D8F1878D6458
File Size: 1.24 MB, 1236480 bytes
MD5: 7810c82469f0db0b03b550f08de136b8
SHA1: 82ea976108cdf9fda2699d43e33773ff5e35caef
SHA256: 28CDCB1F3B0DC8B8E518EB4D6105D26296899EF2CE450C29BB84E85E8CDCCFC8
File Size: 1.17 MB, 1166336 bytes
MD5: f994ae94c26bc292e085cd8e1ec4027c
SHA1: 367dbdc5b06b898d4f102a131cc1a6bfd6805383
SHA256: 4C3FE75C5A55BC77DFA5F9D239BA935CE7862767EEAB0AF322ACADA485641573
File Size: 1.29 MB, 1292800 bytes
MD5: 83a8dcf01af4f934fc782d4c707a3984
SHA1: 26c2e9b901281a367f3f438a276ebf4d18e617d9
SHA256: 4E0F2ADAA0CD003F290722F009B0A683D05DE6792BD56DA48F4390F24F978D5E
File Size: 1.77 MB, 1772032 bytes
MD5: fef73580a70a90b7e366b34540dc8411
SHA1: cb6592dde27c2e83c3e77162b01332680030a6c9
SHA256: D3F0ACFB5FFBF991343D535155139580877FA66E7037760FDB6C82303C19842F
File Size: 1.77 MB, 1772544 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description
  • IW3 single player modification
  • Modern Operations
  • Portal 2 RTX Remix Compatibility Mod
File Version
  • 3.9.7.85
  • 3.9.5.83
  • 2.0
  • 0.0.0
Internal Name
  • IW3SP-MOD
  • Modern-Ops
  • p2-rtx
Legal Copyright
  • Jerry4LT
  • xoxor4d.github.io
Original Filename
  • game.dll
  • p2-rtx.dll
Product Name
  • IW3SP-MOD
  • Modern-Ops
  • p2-rtx
Product Version
  • 3.9.7
  • 3.9.5
  • 2.0
  • 0.0.0

File Traits

  • dll
  • fptable
  • HighEntropy
  • imgui
  • No Version Info
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 4,273
Potentially Malicious Blocks: 155
Whitelisted Blocks: 3,015
Unknown Blocks: 1,103

Visual Map

0 0 0 0 ? 0 ? 0 0 0 0 x 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 x ? 0 0 ? 0 0 0 ? ? 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 ? ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 1 0 0 0 0 ? 0 0 0 ? 0 ? ? ? 0 ? 0 ? ? 0 0 0 0 0 ? 0 0 0 ? 0 ? ? ? ? 0 ? 0 0 ? 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? ? ? ? 0 ? 0 ? ? 0 0 0 ? ? 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 ? 0 ? 0 0 ? 0 0 ? 0 0 0 ? 0 0 ? ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 x 0 0 0 0 ? x 0 ? 0 0 0 ? ? ? 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 1 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? ? ? 0 0 0 0 0 0 ? 0 ? ? 0 ? ? ? 0 0 0 0 ? ? ? ? 0 ? 0 ? 0 ? ? ? 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 ? 1 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 ? ? 0 0 ? 0 ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? 1 ? ? ? ? ? ? ? ? ? ? 0 x x 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 0 0 0 ? ? ? 0 ? 0 0 ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? 0 0 0 ? 0 ? 0 ? 0 0 ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 0 ? 0 ? 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? 0 0 ? ? 0 ? 0 ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 1 ? ? 1 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? 0 ? 0 0 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 ? ? x ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? ? 0 ? ? 0 0 ? ? 0 0 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 0 ? ? 0 0 ? 0 0 ? ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 ? 0 ? ? ? 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 ? 0 ? 0 0 ? 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? 0 ? 0 0 0 ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 0 ? ? ? ? ? 0 0 0 0 ? 0 ? ? ? 0 0 0 0 ? 0 0 ? ? ? ? 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 1 0 0 ? ? 0 0 0 ? ? ? ? 0 ? 0 0 ? 0 0 ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 ? ? ? 0 ? 0 0 ? ? 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 ? 0 0 0 ? ? ? ? 0 0 ? 0 0 0 0 ? ? 0 0 0 ? ? ? ? ? 0 0 0 ? ? ? 0 ? ? ? ? 0 ? 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? 0 0 0 0 ? 0 0 0 ? 0 0 ? ? 0 0 0 0 0 ? ? ? 0 0 0 0 ? ? ? 0 ? ? ? 0 0 0 0 ? ? 0 ? 0 0 0 ? 0 0 0 ? ? 0 0 ? ? 0 ? ? 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? 0 ? ? ? ? 0 0 0 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 0 0 0 ? ? 0 0 0 ? ? ? ? ? ? 0 ? ? 0 ? ? x ? 0 0 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? 0 0 0 0 0 ? ? 0 0 0 ? 0 0 ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\windows\syswow64\shader patch.log Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::watchdog c:\users\user\downloads\52e2ecc73f53ad82db3a330d466d0639cb2362a0_0001944064 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\16e60f184f0f1577bca9551d45938fe7d0afbc14_0002445312.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\c4a163d166e26556627b72e1b00bff755cc3896a_0001068032.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\6b9d5d7a57d470de9f9c85087e09b78d952239e6_0001785856.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\7bd760e41ae9901ee3910de311bdc67bca58a990_0001314816.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\731e27d1bf40cb22a21344f324db2f5e36e67f3c_0001805312.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3f92207f80ad83d65af833d118753fd41e855756_0003830784.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2bca0a2e9b99e0f962446d9f703d214310ce28e2_0003830272.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\6e6bc2f60fe717e6f0deee21926dcbb5ee59f41f_0002513920.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2dbd29f89a20fd0f0d909f1b1aadd022ba92ee71_0001236480.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\82ea976108cdf9fda2699d43e33773ff5e35caef_0001166336.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\367dbdc5b06b898d4f102a131cc1a6bfd6805383_0001292800.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\26c2e9b901281a367f3f438a276ebf4d18e617d9_0001772032.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\cb6592dde27c2e83c3e77162b01332680030a6c9_0001772544.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...