Home Malware Programs Potentially Unwanted Programs (PUPs) Games Bot

Games Bot

Posted: March 16, 2015

Threat Metric

Threat Level: 1/10
Infected PCs: 522
First Seen: March 16, 2015
Last Seen: January 19, 2023
OS(es) Affected: Windows

Games Bot is a typical Potentially Unwanted Program (PUP), developed by Games Bot Team. It tries to attract the attention of the user with a seemingly useful feature but then proceeds to perform unpleasant actions in the background. Games Bot offers the free download of Shockwave games. It is only after the installation, however, when the people notice that their computer speed is significantly decreased. The reason for this is because the main executable file of Gamer Bot, gbRunner.exe, constantly starts Google Chrome and access certain sites without the knowledge of the user. Some of these domains may be malicious and keeping Games Bot may harm the infected computer. What is more, the PUP modifies the Windows Task Scheduler in order to start itself automatically. Games Bot comes bundled with another program and relies on the fact that many people don't read the End-user license agreement. Experts advise against keeping this application because it may have negative results for the whole system.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\Games BotSoftware\Microsoft\Windows\CurrentVersion\Run\GamesbotSOFTWARE\Wow6432Node\Games BotSYSTEM\ControlSet001\Services\EventLog\Application\GamesBotServiceSYSTEM\ControlSet001\Services\GamesBotServiceSYSTEM\ControlSet002\Services\EventLog\Application\GamesBotServiceSYSTEM\ControlSet002\Services\GamesBotServiceSYSTEM\CurrentControlSet\Services\EventLog\Application\GamesBotServiceSYSTEM\CurrentControlSet\Services\GamesBotService

Additional Information

The following directories were created:
%APPDATA%\GbUpdSrv%APPDATA%\Microsoft\Windows\Start Menu\Programs\Games Bot%LOCALAPPDATA%\Games Bot%PROGRAMFILES%\Games Bot%PROGRAMFILES(x86)%\Games Bot
Loading...