Threat Database Trojans Trojan.Gamehack.PSJ

Trojan.Gamehack.PSJ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 26,793
Threat Level: 80 % (High)
Infected Computers: 2
First Seen: April 18, 2026
Last Seen: July 28, 2026
OS(es) Affected: Windows

The detection of Trojan.Gamehack.PSJ indicates that your system has been compromised by a potentially malicious program. This type of threat is designed to infiltrate your computer without your knowledge or consent, and it can cause a range of problems, from slowing down your system to stealing your personal data. In this report, we will provide you with information about what Trojan.Gamehack.PSJ is, how it operates, and how you can remove it from your system.

What Is Trojan.Gamehack.PSJ?

Trojan.Gamehack.PSJ is a type of Trojan horse malware, which is a program that disguises itself as a legitimate application but actually contains malicious code. The name "Trojan" refers to the fact that this type of malware is designed to sneak into your system undetected, much like the Trojan horse of ancient Greek legend. The ".Gamehack" part of the name suggests that this malware may be related to online gaming, but this is not necessarily the case. The ".PSJ" suffix is likely a unique identifier assigned by the malware authors.

How Trojan.Gamehack.PSJ Operates

Trojan horse malware like Trojan.Gamehack.PSJ typically operates by exploiting vulnerabilities in your system or tricking you into installing it. Once installed, it can cause a range of problems, including slowing down your system, crashing applications, and stealing your personal data. Some Trojans are designed to provide a backdoor into your system, allowing the malware authors to access your computer remotely. Others may be used to spread additional malware or to engage in other malicious activities.

Symptoms of Infection

If your system is infected with Trojan.Gamehack.PSJ, you may notice a range of symptoms, including slow system performance, frequent crashes, and unexpected changes to your system settings. You may also notice that your browser is being redirected to unexpected websites or that you are receiving unexpected pop-ups or advertisements. In some cases, you may not notice any symptoms at all, which is why it's so important to have a reputable antivirus program installed on your system.

How to Remove Trojan.Gamehack.PSJ

  1. Boot your system in Safe Mode with Networking. This will prevent the malware from loading and allow you to remove it more easily.
  2. Use a reputable antivirus tool, such as SpyHunter, to perform a full scan of your system. This will help to detect and remove any malware that may be present.
  3. Uninstall any suspicious programs that you have installed recently. This can help to prevent the malware from spreading or causing further damage.
  4. Reset your browser settings to their default values. This can help to remove any malicious extensions or add-ons that may have been installed. For example, you can reset Chrome, Firefox, or Edge to their default settings.
  5. Reboot your system and perform another scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Gamehack.PSJ from your system requires careful attention to detail and a thorough understanding of how malware operates. By following the steps outlined above, you can help to protect your system and prevent further damage. Remember to always be cautious when installing new software or clicking on links from unknown sources, and to keep your antivirus program up to date to prevent future infections. With the right tools and knowledge, you can help to keep your system safe and secure.

Analysis Report

General information

Family Name: Trojan.Gamehack.PSJ
Signature status: No Signature

Known Samples

MD5: 452dadbb19862e394a7bc18fa347441c
SHA1: 58f52b7c789b950a5569f7719b4631f19846123b
SHA256: 12F27975401CD9E423C13C78E202F0A3DC9C437988DE838AF935437D15631671
File Size: 1.05 MB, 1046528 bytes
MD5: 398b3fc22b97a5fa072c398cf223ac78
SHA1: f7cc801da8de5e1716e196e1a293c3cb110c7d27
SHA256: 7B43D3289A50944FAFD436670BEA793952C884EABC7DF3417256566F45BCF4FE
File Size: 6.33 MB, 6334976 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Ghosty
File Description Ghosty - Euro Truck Simulator 2 External Utility
File Version 1.0.0.0
Internal Name Ghosty
Legal Copyright Copyright (C) 2024 Ghosty
Original Filename Ghosty.exe
Product Name Ghosty
Product Version 1.0.0.0

File Traits

  • fptable
  • GetConsoleWindow
  • HighEntropy
  • imgui
  • No Version Info
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 9,360
Potentially Malicious Blocks: 367
Whitelisted Blocks: 6,835
Unknown Blocks: 2,158

Visual Map

0 0 ? x x x 0 0 0 0 0 0 0 x x 0 ? ? 0 0 0 x 0 0 0 ? 0 0 x 0 0 0 0 ? ? 0 ? x x 0 ? x 0 0 ? ? ? 0 x 0 ? 0 x ? x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 0 0 x x 1 ? 0 0 x 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? x x 0 ? 0 0 ? 0 x ? 0 0 0 x x 0 0 ? 0 0 0 0 0 ? 0 ? 0 x 0 x x 0 ? x x 0 x 0 0 x 0 0 ? ? 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x 0 0 0 x x x x x 0 x 0 ? ? ? 0 0 0 x 0 x ? x 0 x 0 0 0 0 x x 0 0 x x x 0 x ? ? ? x 0 ? 0 0 1 ? x x 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 x ? ? x x ? 0 0 0 x x ? x 0 0 x 0 x ? 0 0 0 x x x x x x x ? ? ? 0 0 0 0 0 0 0 0 0 x ? ? ? 0 0 0 0 0 ? ? ? ? 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 ? ? x x 0 0 x 0 0 ? 0 ? 0 0 0 ? x ? 0 0 x ? ? ? ? 0 0 ? 0 ? 0 ? ? ? ? 0 0 ? ? 0 x ? 0 0 ? x 0 0 0 0 ? ? 0 ? 0 0 0 x ? 0 0 0 x ? ? ? x 0 ? 0 0 x 0 x x ? 0 ? ? 0 0 0 ? ? 0 ? x ? ? 0 ? x ? 0 ? x 0 x 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 1 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x ? ? ? 0 x ? ? ? ? ? 0 0 0 ? ? 0 ? ? ? ? 0 0 0 ? 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? 0 0 ? ? ? 0 ? ? ? 0 ? ? 0 ? ? 0 ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? 0 ? ? 0 ? 0 ? 0 ? ? ? ? ? 0 ? 0 ? 0 0 ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 0 0 ? ? ? ? ? 0 ? ? 0 0 ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 0 0 0 ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? 0 0 ? 0 0 ? 0 0 0 ? ? ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 1 0 ? ? 0 ? 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 ? 0 0 0 0 ? x 0 0 0 ? ? ? x 0 0 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? 0 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? ? ? 0 x x 0 0 0 0 1 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 1 x 0 x 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? ? 0 0 ? 0 0 ? ? ? 0 0 0 0 0 0 0 1 ? ? ? ? 0 0 0 0 ? ? ? 0 ? 0 ? 0 0 0 0 0 ? 0 ? ? ? 0 ? ? ? ? 0 ? ? 0 ? 0 0 ? 0 ? ? ? ? 0 x 0 ? ? 0 0 ? ? ? ? ? ? 0 0 ? ? ? ? 0 0 ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 0 ? 0 0 ? ? ? 0 x 0 ? ? 0 0 0 ? ? 0 ? 0 ? ? 0 0 0 0 x ? ? ? ? 0 0 0 ? 0 0 ? ? 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? 0 0 ? 0 0 ? ? ? ? ? ? 0 0 ? 0 0 0 0 ? ? ? ? 0 ? ? ? 0 0 0 0 0 ? ? ? ? ? 0 ? 0 0 0 ? ? 0 ? ? ? ? ? ? 0 0 ? 0 ? 0 0 ? 0 ? 0 0 ? ? 0 0 0 ? 0 ? ? 0 ? ? 0 ? 0 ? ? ? ? ? ? 0 0 ? ? 0 ? ? 0 ? ? ? ? ? 0 0 ? ? 0 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 ? ? ? 0 0 0 0 ? 0 ? ? ? ? ? ? 0 0 ? ? 0 0 0 ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 0 0 ? ? ? ? ? 0 ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? ? 0 0 ? ? 0 ? 0 0 ? ? x ? ? ? 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? 0 ? 0 0 ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? x ? 0 ? ? 0 0 0 0 ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? 0 0 0 ? ? 0 ? 0 0 ? ? ? ? 0 0 ? ? 0 ? 0 0 0 0 0 0 0 ? ? ? 0 x 0 0 ? ? 0 0 ? 0 ? ? 0 ? ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? 0 ? 0 ? 0 ? ? 0 ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? 0 0 0 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? 0 ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 ? 0 ? ? 0 ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? 0 0 ? ? ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 ? ? 0 0 ? 0 ? ? 0 ? ? 0 ? ? ? ? ? 0 ? 0 0 0 1 0 ? ? ? 0 ? 0 0 0 0 0 0 0 1 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 0 0 ? 0 0 ? ? 0 0 0 0 ? ? 0 ? 0 0 ? ? ? 0 0 ? ? ? 0 ? 0 ? ? 0 ? 0 0 0 x ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? 0 0 ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.ZFBJ
  • Downloader.Agent.BAB
  • Downloader.Agent.BTF
  • Gamehack.GACI
  • Gamehack.PSJ
Show More
  • Trojan.Downloader.Gen.KB

Files Modified

File Attributes
c:\users\user\appdata\local\ghosty\logs\startup.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\lrqvd7jy195315.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n �v��(�1`1�1HO@V�_�zi��k`k�qrnJu�~{b��P��������������.�m�Ù�������$წ����o�=�SB1_T�Vw��R���%����AE�Q]��D��&��$���L RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 靽몺ẩǝ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
Show More
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Shell Command Execution

"C:\Users\Tawpjjag\AppData\Local\Temp\lrQVd7jY195315.exe" --copied