Home Malware Programs Potentially Unwanted Programs (PUPs) Zula Games

Zula Games

Posted: November 4, 2013

Threat Metric

Ranking: 10,401
Threat Level: 1/10
Infected PCs: 42,556
First Seen: November 4, 2013
Last Seen: October 8, 2023
OS(es) Affected: Windows

Zula Games is a toolbar and Potentially Unwanted Program that includes the definitive traits of a browser hijacker and adware-based PC threat. By taking over your browser to display advertisements and redirect you to Zula Games-affiliated sites, Zula Games impedes your ordinary Web-browsing activities without so much as giving you any easy options for restoring your browser to normal. Even though Zula Games shouldn't be mistaken for a Trojan or other high-level PC threat, deleting Zula Games via suitable anti-malware utilities should be treated as the SOP for keeping your browser at optimal performance and under your complete control.

When Gaming Goes Too Far into Your Browser

As an appendage of yet another freeware gaming site that hopes to make money off of fiddling with the browsers of its user base, Zula Games is packaged with other software from zulagames.com as a semi-hidden add-on, and most Zula Games infections are the direct result of interested gamers indulging in zulagames.com products. However, along with the prerequisite gaming experiences, Zula Games also delivers more than most gamers would bargain on getting – as malware experts have discovered:

  • Zula Games modifies your browser's default search engine to promote its alternative search features.
  • Zula Games locks your browser's homepage to an affiliated website.
  • Zula Games redirects your browser when it encounters certain stock website error messages (such as 'URL not found').
  • Zula Games injects advertisements (banners, hyperlinks, etc.) into your Web browser and monitors your online habits to deliver advertisements that seem relevant to any loaded sites.

Even though the Zula Games website provides uninstallation instructions, most scenarios involving normal uninstall methods for Zula Games have failed to delete all associated components and system changes. Like most PUPs designed to take advantage of the user through basic browser changes, Zula Games is equally compatible with Internet Explorer, Firefox and Chrome – as well as Apple's Safari.

How to Find Free Entertainment without Getting Browser Hijacks in the Bargain

Even though Zula Games only is categorized as a PUP and, therefore, more of a minor inconvenience than a major security issue, malware researchers still consider deleting Zula Games and other browser-hijacking programs to be an essential part of keeping your browser optimized. To be sure of removing Zula Games and the semi-universal browser changes Zula Games causes, using anti-malware programs to scan your PC and remove all relevant components strongly is recommended for an efficient but easy solution.

Zula Games is a clear case of social engineering-based browser attacks, wherein the visitor is offered something valuable – free games – and, in exchange, is subjected to various negative and unwanted system changes. While Zula Games's gaming library may seem tempting, malware experts note that numerous safe free gaming sites exist around the Web and that you never should need to let your browser be attacked in exchange for some platforming or shoot 'em up playtime.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\Zula Games\ScriptHost64.dll File name: ScriptHost64.dll
Size: 381.76 KB (381760 bytes)
MD5: 095816e4cdb1a314d4ecf566c251887f
Detection count: 11,825
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files\Zula Games\ScriptHost64.dll
Group: Malware file
Last Updated: October 24, 2022
I:\Program Files (x86)\Zula Games\ScriptHost.dll File name: ScriptHost.dll
Size: 382.27 KB (382272 bytes)
MD5: d9c9f29893f88f197c41279f0e8c25c1
Detection count: 9,094
File type: Dynamic link library
Mime Type: unknown/dll
Path: I:\Program Files (x86)\Zula Games\ScriptHost.dll
Group: Malware file
Last Updated: May 21, 2022
I:\Program Files (x86)\Zula Games\BackgroundHost.exe File name: BackgroundHost.exe
Size: 598.84 KB (598848 bytes)
MD5: 3e8bd965f881bb9723cbe217ae19d46f
Detection count: 1,499
File type: Executable File
Mime Type: unknown/exe
Path: I:\Program Files (x86)\Zula Games\BackgroundHost.exe
Group: Malware file
Last Updated: June 28, 2022
C:\Program Files\Zula Games\BackgroundHost.exe File name: BackgroundHost.exe
Size: 635.71 KB (635712 bytes)
MD5: dfe3f6f9cb055d1f3c9a0948817875d1
Detection count: 1,148
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Zula Games\BackgroundHost.exe
Group: Malware file
Last Updated: October 24, 2022
%PROGRAMFILES%\Zula Games\ScriptHost.dll File name: ScriptHost.dll
Size: 382.27 KB (382272 bytes)
MD5: 957e4620189195587f2c9998213950ff
Detection count: 295
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Zula Games
Group: Malware file
Last Updated: January 8, 2014
%PROGRAMFILES%\Zula Games\ScriptHost.dll File name: ScriptHost.dll
Size: 400.7 KB (400704 bytes)
MD5: ad7963c4b8c5e13e67991c495fef35d8
Detection count: 11
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Zula Games
Group: Malware file
Last Updated: January 8, 2014
%PROGRAMFILES%\Zula Games\ScriptHost.dll File name: ScriptHost.dll
Size: 382.27 KB (382272 bytes)
MD5: bde2d2d0365fb062d5230a70b5027b4e
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Zula Games
Group: Malware file
Last Updated: January 8, 2014
%PROGRAMFILES(x86)%\Free Games (4351)\ScriptHost64.dll File name: ScriptHost64.dll
Size: 381.76 KB (381760 bytes)
MD5: caeff4959080b286ee98e5eb6bd63e61
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Free Games (4351)
Group: Malware file
Last Updated: November 5, 2013

Registry Modifications

The following newly produced Registry Values are:

CLSID{0D5F364D-D6A9-43C1-BF0C-99B378972C5B}{0FA62FD2-7954-4EE5-9648-128C4EF47ECF}{2665A19D-89C6-4E55-994B-ABDDA56F7F81}{2977C29A-6723-4436-90BB-F7C5FDEF88A1}{4398032D-0040-451D-9AB9-5CE5597EB103}{48F1DBA1-4003-4D25-8A10-6614ED65ED94}{5C71ACCF-F361-40F4-9E19-23D831490AAB}{703F72F9-5E77-450B-91D4-B594CF167EC7}{739CDEE7-D45D-426F-9776-8BC4F8C1A4AB}{813FB3C5-A4D9-4CD8-BDD0-750F40E68908}{939C3962-7375-49AF-B7B6-6730422CEC00}{A052690D-325F-467A-BCFE-0F93199835EF}{A72BB09D-9450-4909-864F-B3D5AF734D51}{D1172C15-3FA2-41ED-9CCA-C777F005DFF1}{DF776000-0872-4D61-B445-CAD0C227C731}{EF5F0737-3612-44C1-A30F-0BAAFB596EBE}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{2977C29A-6723-4436-90BB-F7C5FDEF88A1}Software\Microsoft\Internet Explorer\Approved Extensions\{402E8195-2AC9-4A7F-9BA5-14B93F1D8045}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0D5F364D-D6A9-43C1-BF0C-99B378972C5B}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2977C29A-6723-4436-90BB-F7C5FDEF88A1}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{402E8195-2AC9-4A7F-9BA5-14B93F1D8045}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2977C29A-6723-4436-90BB-F7C5FDEF88A1}SOFTWARE\Wow6432Node\Google\Chrome\Extensions\occpfaboijojdgcgbgldjckfijcdlfghSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2977C29A-6723-4436-90BB-F7C5FDEF88A1}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{402E8195-2AC9-4A7F-9BA5-14B93F1D8045}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Free Games (4357)

Additional Information

The following directories were created:
%AppData%\freegames4351%ProgramFiles%\Free Games (4351)%ProgramFiles(x86)%\Free Games (4351)
The following URL's were detected:
Free Games (4357)

One Comment

Loading...