PUP.Gamehack.PS
The detection of PUP.Gamehack.PS on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.
Table of Contents
What Is PUP.Gamehack.PS?
PUP.Gamehack.PS is a type of malware that is classified as a potentially unwanted program. This category of threats includes software that may not be malicious in nature but can still cause problems for users. PUPs can be installed on a system without the user's knowledge or consent, often through bundled software downloads or deceptive marketing tactics. While PUPs may not be as harmful as other types of malware, they can still compromise system security, collect user data, and display unwanted advertisements.
How PUP.Gamehack.PS Operates
PUP.Gamehack.PS, like other PUPs, can operate in various ways to achieve its goals. It may be designed to collect user data, such as browsing history, search queries, or personal information, which can be used for targeted advertising or other malicious purposes. PUPs can also modify system settings, install additional software, or create unwanted shortcuts and bookmarks. In some cases, PUPs may even be used as a conduit for more severe malware infections, making it crucial to remove them as soon as possible.
Symptoms of Infection
Systems infected with PUP.Gamehack.PS may exhibit a range of symptoms, including slow system performance, increased pop-up advertisements, and unwanted software installations. Users may also notice suspicious browser extensions, toolbars, or search engines that they did not install. In some cases, PUPs can cause system crashes, freezes, or errors, making it difficult to use the computer. If you are experiencing any of these symptoms, it is likely that your system is infected with PUP.Gamehack.PS or another type of malware.
How to Remove PUP.Gamehack.PS
- Boot your computer in Safe Mode with Networking to prevent the PUP from interfering with the removal process.
- Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of PUP.Gamehack.PS.
- Uninstall any suspicious programs or software that you did not install, as these may be related to the PUP infection.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions, toolbars, or search engines.
- Reboot your computer and perform another full scan to ensure that all remnants of PUP.Gamehack.PS have been removed.
Conclusion
Removing PUP.Gamehack.PS from your system is crucial to prevent further damage and protect your personal data. By following the steps outlined above, you can effectively remove this potentially unwanted program and restore your system to a safe and secure state. It is also essential to practice good cybersecurity habits, such as regularly updating your software, using strong antivirus protection, and being cautious when downloading and installing new programs. By taking these precautions, you can reduce the risk of PUP infections and keep your computer running smoothly and securely.
Analysis Report
General information
| Family Name: | PUP.Gamehack.PS |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
951587abf6a64b8842cdc4671d28ef85
SHA1:
ad3221df0e4098cf4a9d6209edf9eef5b1adfd67
SHA256:
6355BC8836BD4ED02838E3D1CB48F027F9D0C5C7BC781E47CF6682D87E7CD502
File Size:
478.21 KB, 478208 bytes
|
|
MD5:
0a73c46cda1106ed0ea0d386bbf0b685
SHA1:
3f66dd62de9f69590e618d75f96f04951ec47a46
SHA256:
8C1DCB8C468120FD92B4B5A2A93868671B5051BF7D2EE6867DB56F6B5C9B7D80
File Size:
396.29 KB, 396288 bytes
|
|
MD5:
7b09086ba7ab15ae79ce8779bbceec8a
SHA1:
f10f88b68ac4732b5536ee6b7d1af96d2440b782
SHA256:
A112755167F99E89E78ECB13B25CEB27B61FE449A05B975BDFB7AE0E63414D93
File Size:
382.46 KB, 382464 bytes
|
|
MD5:
dfe9f321f8a6687063636934483ecd0a
SHA1:
b70854878b09fa88b74935b87fbd900f51582ec0
SHA256:
DDBF3A8A5DE702D88877EC17491CC093F5DA08F138A585228EA317A087761D53
File Size:
507.39 KB, 507392 bytes
|
|
MD5:
d85b7fa9966a0cb8bf76cd0acedf96f2
SHA1:
14010c2596d4e0e4586125906e7647a87c1f34e5
SHA256:
F227D59A42593133D33DC55A895EF3F6C3B56954C8DEC5CFE1B24DE6F8E9C36C
File Size:
559.62 KB, 559616 bytes
|
Show More
|
MD5:
af3d173afaa6cbcc4ab4099d4ee0a13c
SHA1:
8d802ec9ea653bf9ff1986b69cdebbc24ca1b550
SHA256:
25BA5ABE52380832D4102C033A5D520516F3DA2D32ABA0F1F7BED34E447CFD92
File Size:
508.42 KB, 508416 bytes
|
|
MD5:
4a43b9ccd9d6a71dce3fd96f44fe9f18
SHA1:
1e1e71820f042766a14a2d4a57ecfe8de4ccfd4e
SHA256:
ED16B197E380ED90D25ED56C5FF252FA27C613B86067791482C3A7B1D7A74CED
File Size:
459.78 KB, 459776 bytes
|
|
MD5:
03b4a85c0c60d298a0ed4bc321bd200f
SHA1:
5db18154ade2c3a8f4308e33bb5ba8c27caf360e
SHA256:
893BCE8F549E0EA9F6465E8C49DF826464AAC62CA13AC616839910940466A333
File Size:
686.59 KB, 686592 bytes
|
|
MD5:
61325fd5ca27c8d2fa6314277b2432df
SHA1:
4540c267e4032adaee8e2351fccb8f89c402f5a3
SHA256:
2F9D10AC8480955631D0CB82CA2335064CECE354F189BD2CA11D7B4EC6BCAFCA
File Size:
780.80 KB, 780800 bytes
|
|
MD5:
675ab2dab47b318d8c9baa26e6ebe474
SHA1:
ac70cc6292eb4f1880fcec32170467e819159e98
SHA256:
BB58FF29030AED779801513B52C4454CD4D103BC6E392325D86462960A0DFA16
File Size:
1.23 MB, 1225216 bytes
|
|
MD5:
6b177b78e976d82ecc6ec5bacc389985
SHA1:
3c25cfc54459b8def218f51b90257c4e6d292435
SHA256:
F46EFE650167C39F96C200E4D9F826BD2D31804B46FFD47ED52A0DB47C9B0D86
File Size:
451.58 KB, 451584 bytes
|
|
MD5:
26b3485a3b68937e4f4989aa238e56f7
SHA1:
8a0ab0d1f114c0fa68fe17a35024e035770969bd
SHA256:
0B4705DB1F06A14EC09E111FF75D64BCE611606FBF31A2AA5D240FEA27F11237
File Size:
732.67 KB, 732672 bytes
|
|
MD5:
b93d7f7bcced90b5daa9334191918e2a
SHA1:
71a3ceb1a2cb3686e78da8f1fa275ec17c1a01d1
SHA256:
A41C835B1C9DA16D9CCDF1E37A570CC377999F6F4749C7BB451B34CB95949A19
File Size:
753.15 KB, 753152 bytes
|
|
MD5:
533cc487db41d4abad6314ddda092530
SHA1:
196ce18ca3c841637c382cf16adbc2e48d27eb66
SHA256:
1D13A521F399FF3C0B3243DAEBADE9537F62CEB2B992A1D67765CF4EBF62A119
File Size:
903.17 KB, 903168 bytes
|
|
MD5:
0991ee689ed64539498fe3ced207f64a
SHA1:
9a986b281d03cf28535ad6d612fd83026306695f
SHA256:
736153E4D312BB1833309A24B2198C7760C2D4EA60D456B970A625B8CECD556A
File Size:
362.50 KB, 362496 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have security information
- File has TLS information
- File is 64-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name | DBOZero |
| File Description | Official DBOZero game launcher and updater |
| File Version | 2.0.0.0 |
| Internal Name | LauncherZero |
| Legal Copyright | Zero Ryo and Kunay |
| Original Filename | Launcher Zero.exe |
| Product Name | LauncherZero |
| Product Version | 2.0.0.0 |
File Traits
- GetConsoleWindow
- HighEntropy
- imgui
- No Version Info
- WriteProcessMemory
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 85 |
|---|---|
| Potentially Malicious Blocks: | 3 |
| Whitelisted Blocks: | 75 |
| Unknown Blocks: | 7 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- DllInject.GUA
- Gamehack.GAIG
- Gamehack.GDDE
- Gamehack.PS
- Trojan.Kryptik.Gen.BKO
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\users\user\appdata\local\temp\609806.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\users\user\appdata\local\temp\879056.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 覡⤱⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 䶛⥗⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | ⥵⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 实⦚⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 㫎⦴⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | ᔅ⧍⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 蒇⧱⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 섆⨌⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | -⨩⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 晈⩌⛧ǜ | RegNtPreCreateKey |
Show More
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 雀⩨⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 瘽⪂⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 둤⪞⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 胆⫄⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 엝⫠⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 龵⫺⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 棳⬠⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | ⬷⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 앺⭑⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | @⭬⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 繻⮄⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 尒⮞⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 㹜⮷⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | V��+�&� | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | ᠧ⯲⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 寑Ⰾ⛧ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | ᥆韨旊ǜ | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
73 additional items are not displayed above. |
| Keyboard Access |
|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| Network Wininet |
|
| Other Suspicious |
|
| Anti Debug |
|
| User Data Access |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\Users\Hqzebgwo\AppData\Local\Temp\609806.exe (NULL)
|
C:\Users\Cvcjzppa\AppData\Local\Temp\879056.exe (NULL)
|