PUP.MSIL.Gamehack.YD

The detection of PUP.MSIL.Gamehack.YD on your system indicates the presence of a potentially unwanted program (PUP) that may compromise your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it and prevent future infections.

What Is PUP.MSIL.Gamehack.YD?

PUP.MSIL.Gamehack.YD is a type of potentially unwanted program that is designed to operate on Microsoft Intermediate Language (MSIL) platforms. The ".Gamehack" part of the name suggests that it may be related to gaming or cheating software, which can be used to gain unfair advantages in online games or to compromise game security. PUPs like PUP.MSIL.Gamehack.YD can be installed on a system without the user's knowledge or consent, often through bundled software downloads or exploits.

How PUP.MSIL.Gamehack.YD Operates

PUP.MSIL.Gamehack.YD, like other PUPs, can operate in various ways to achieve its goals. It may collect user data, display unwanted advertisements, or install additional malware on the system. PUPs can also modify system settings, registry entries, and configuration files to maintain their presence and evade detection. In some cases, PUPs can even communicate with remote servers to receive updates or transmit stolen data.

Symptoms of Infection

The symptoms of a PUP.MSIL.Gamehack.YD infection can vary, but common indicators include slow system performance, unwanted pop-ups or advertisements, and suspicious program installations. You may also notice unusual network activity, changes to your browser settings, or the presence of unfamiliar programs in your system tray. If you suspect that your system is infected with PUP.MSIL.Gamehack.YD, it is crucial to take immediate action to remove the threat and prevent further damage.

How to Remove PUP.MSIL.Gamehack.YD

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of PUP.MSIL.Gamehack.YD and other potential threats.
  3. Uninstall any suspicious programs or applications that may be related to the PUP, as they can be used to reinstall the malware or maintain its presence on the system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any modifications made by the PUP and to prevent further malicious activity.
  5. Reboot your system and perform another full scan to ensure that all remnants of PUP.MSIL.Gamehack.YD have been removed and that your system is secure.

Conclusion

The removal of PUP.MSIL.Gamehack.YD requires a combination of technical expertise and caution. By following the steps outlined above and using reputable security tools, you can effectively remove this potentially unwanted program and prevent future infections. It is essential to remain vigilant and to maintain good security practices, such as regularly updating your operating system and software, using strong antivirus protection, and avoiding suspicious downloads or links, to protect your system and data from emerging threats.

Analysis Report

General information

Family Name: PUP.MSIL.Gamehack.YD
Signature status: No Signature

Known Samples

MD5: c86d1ee281ba532306b05e6e4981fd2e
SHA1: 280413882e877199b4a130f91acbb7ec7f4262cc
SHA256: 98FB7620D8777A75F644297F5C79B787A91841BA5598EB34D7EF9CDF2F2FE1B0
File Size: 1.07 MB, 1068239 bytes
MD5: 5e2f372062249e320696a645ab51ca64
SHA1: ee001347aee74dccf939519c74fe5aa0ba246885
SHA256: 8521B081B091D42DCF413171005FD29ECE09FA9D89238D759C6C1ACFFB97EEC7
File Size: 4.47 MB, 4471808 bytes
MD5: bfeceb39df03d5691090f59450dafb8d
SHA1: ba0141be24da4a90c022deacd0526bf82a801151
SHA256: C20C443D37A2C78326BDC744029AF838354AA9A20B7BDAAE3501C7B4137F420F
File Size: 6.82 MB, 6815981 bytes
MD5: d15cac2a05aa539b63304f0c5b69aa82
SHA1: e30337b3634def362ea68cd646378b89cc8ebd6f
SHA256: 038A5A9BD39E56164FF3CA5A71C5173B6BEA4ABEDBD8A30978DDFE7BB79F0D41
File Size: 483.33 KB, 483328 bytes
MD5: 88e38ea604dc073ef3a626b33d5afbec
SHA1: 52f9527fd5b71a7903033e7a1259a61df54a639b
SHA256: 6781FB629B66B3CE31A82873300174A71C450E3AB2F953B5345D604281A798C5
File Size: 976.38 KB, 976384 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments This installation was built with Inno Setup.
Company Name
  • Arroyo MU
  • ElproSys
File Description
  • Cabal Launcher
  • DiagProg4 Manager Setup
  • Launcher
  • WYD Launcher
File Version
  • 1.00
  • 1.0.0.0
Internal Name
  • Cabal.exe
  • Launcher.exe
  • TJprojMain
  • WYDLauncher.exe
Legal Copyright
  • Copyright © Argmus 2025
  • Copyright © WYD 2024
  • Nicke Coder
Original Filename
  • Cabal.exe
  • Launcher.exe
  • TJprojMain.exe
  • WYDLauncher.exe
Product Name
  • Cabal Launcher
  • DiagProg4 Manager
  • Launcher
  • Project1
  • WYD
Product Version
  • 1.00
  • 1.0.0.0
  • 1.0

File Traits

  • .NET
  • Agile.net
  • Confuser
  • Fody
  • HighEntropy
  • NewLateBinding
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 76
Potentially Malicious Blocks: 9
Whitelisted Blocks: 45
Unknown Blocks: 22

Visual Map

0 0 0 0 x 0 x x 0 x x x 0 0 ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 ? 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? x x 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? x ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-5231u.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-c94j8.tmp\280413882e877199b4a130f91acbb7ec7f4262cc_0001068239.tmp Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 1k 8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�-&�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P% RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 隞̃缁耀꧌ØÊ RegNtPreCreateKey

Windows API Usage

Category API
Process Shell Execute
  • CreateProcess
User Data Access
  • GetComputerNameEx
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Other Suspicious
  • SetWindowsHookEx
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

"C:\Users\Urfpsnxx\AppData\Local\Temp\is-C94J8.tmp\280413882e877199b4a130f91acbb7ec7f4262cc_0001068239.tmp" /SL5="$30066,676605,121344,c:\users\user\downloads\280413882e877199b4a130f91acbb7ec7f4262cc_0001068239"
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 860

Related Posts

Trending

Most Viewed

Loading...