Home Possibly Unwanted Program Zaxar Games

Zaxar Games

Posted: August 26, 2014

Threat Metric

Ranking: 3,157
Threat Level: 1/10
Infected PCs: 223,186
First Seen: August 26, 2014
Last Seen: October 17, 2023
OS(es) Affected: Windows


The Zaxar Games platform is promoted as the Adobe Flash-based alternative to Battle.net by Blizzard Entertainment. The Zaxar Games platform is hosted on Zaxargames.com and is dedicated to delivering popular games to native Russian-speaking users. Zaxargames.com has a version in English, but most of the content available on Zaxar Games is provided in the Russian language. Computer users that are interested in the Zaxar Games are directed to download the Zaxar Games Browser.

The Zaxar Games Browser is the main module that loads games from Zaxargames.com directly on your desktop and allows for a more immerse experience. Zaxar Ltd operates the Zaxar Games platform, and you will need a registration to launch the Zaxar Games Browser. Web surfers with accounts on Mail.ru, Facebook, Fotostrana, and Vkontakte can use those accounts to login hassle-free into the Zaxar Games Browser. Users are not offered the option to exit Zaxar Games Browser directly. Keep in mind that the Zaxar Games Browser will run as a background process on the system, and you will need to terminate its process to remove it manually.

Moreover, users report that the Zaxar Games Browser program may show pop-up windows with advertisements on their desktops and welcome users to benefit from coupons and discounts from sponsors. If you are willing to install the Zaxar Games Browser, you should take into consideration that it is freeware, and you are not required to pay for the games on Zaxargames.com. Therefore, Zaxar Ltd should make money somehow, and ads should be expected to appear on your screen. Remember to read the terms of service agreement on Zaxargames.com if you are not sure what to expect from the Zaxar Games Browser. Zaxar Games is deemed as a Potentially Unwanted Program (PUP) that you can remove with the help of a reliable anti-spyware instrument effortlessly.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\ProgramData\hdtask\uninstall.exe File name: uninstall.exe
Size: 37.14 KB (37142 bytes)
MD5: 8d7abb4eca74060caca1a08103c3c40c
Detection count: 6,541
File type: Executable File
Mime Type: unknown/exe
Path: C:\ProgramData\hdtask\uninstall.exe
Group: Malware file
Last Updated: October 17, 2023
C:\System Volume Information\_restore{02EF14A9-1484-4129-B0B2-B0A26FE0A77E}\RP32\A0017571.exe File name: A0017571.exe
Size: 190.97 KB (190976 bytes)
MD5: fb1f04fb851fe921aec9148495669c55
Detection count: 2,204
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\_restore{02EF14A9-1484-4129-B0B2-B0A26FE0A77E}\RP32\A0017571.exe
Group: Malware file
Last Updated: April 12, 2023
C:\ProgramData\hdtask\hdtask.exe File name: hdtask.exe
Size: 180.22 KB (180224 bytes)
MD5: edc7eb442a17faeb8bc02a7c16551bf1
Detection count: 1,066
File type: Executable File
Mime Type: unknown/exe
Path: C:\ProgramData\hdtask\hdtask.exe
Group: Malware file
Last Updated: October 17, 2023
C:\ProgramData\TimeTasks\timetasks.exe File name: timetasks.exe
Size: 207.36 KB (207360 bytes)
MD5: 66b922bbf84831294fb0de74d66f2ea7
Detection count: 965
File type: Executable File
Mime Type: unknown/exe
Path: C:\ProgramData\TimeTasks\timetasks.exe
Group: Malware file
Last Updated: May 12, 2022
C:\Users\<username>\AppData\Local\Temp\ZaxarSetup.4.001.33.exe File name: ZaxarSetup.4.001.33.exe
Size: 284.32 KB (284320 bytes)
MD5: 734a9c8b47712d396bcd1562a229517e
Detection count: 105
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\ZaxarSetup.4.001.33.exe
Group: Malware file
Last Updated: August 25, 2023
%SystemDrive%\ProgramData\hdtask\hdtask.exe File name: hdtask.exe
Size: 207.87 KB (207872 bytes)
MD5: f7e6c8fb2a63ae92e17cd563083c4e9b
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\ProgramData\hdtask
Group: Malware file
Last Updated: June 15, 2017
%ALLUSERSPROFILE%\hdtask\hdtask.exe File name: hdtask.exe
Size: 207.87 KB (207872 bytes)
MD5: 68054bea64db21f339130b505d0597ca
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\hdtask
Group: Malware file
Last Updated: June 15, 2017
%SystemDrive%\ProgramData\hdtask\hdtask.exe File name: hdtask.exe
Size: 207.87 KB (207872 bytes)
MD5: 7668e7b0cd509511738fa3e124259f06
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\ProgramData\hdtask
Group: Malware file
Last Updated: June 15, 2017
C:\Users\<username>\AppData\Local\Temp\ZaxarSetup.4.001.29.exe File name: ZaxarSetup.4.001.29.exe
Size: 544.48 KB (544480 bytes)
MD5: 3f177d822d3b87db47df9d59bb4eb23b
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\ZaxarSetup.4.001.29.exe
Group: Malware file
Last Updated: June 27, 2022
%TEMP%\zaxarsetup.4.001.30.exe File name: zaxarsetup.4.001.30.exe
Size: 363.93 KB (363936 bytes)
MD5: 986f43006fea41ad10e32b143af127b6
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: May 11, 2016
%TEMP%\ZaxarSetup.4.001.29.exe File name: ZaxarSetup.4.001.29.exe
Size: 406.99 KB (406992 bytes)
MD5: c8ef4f18bc1a99db5df324124fd7261d
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: November 12, 2020
%TEMP%\7z3CD19D54\application\ZaxarSetup.4.001.30.exe File name: ZaxarSetup.4.001.30.exe
Size: 368.47 KB (368472 bytes)
MD5: a690b40eb4dc16b7f7f1f5b31c7be6b0
Detection count: 31
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\7z3CD19D54\application
Group: Malware file
Last Updated: May 11, 2016
C:\Users\<username>\AppData\Roaming\Installer\ZaxarSetup.4.001.108.exe File name: ZaxarSetup.4.001.108.exe
Size: 375.98 KB (375984 bytes)
MD5: b9d958c7dd4c47a56eee13560ab69e88
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\Installer\ZaxarSetup.4.001.108.exe
Group: Malware file
Last Updated: December 15, 2022
C:\Users\<username>\AppData\Local\Temp\ZaxarSetup.4.001.29.exe File name: ZaxarSetup.4.001.29.exe
Size: 365.06 KB (365064 bytes)
MD5: 2bb8aec5fec5a9f0344aff6236279315
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\ZaxarSetup.4.001.29.exe
Group: Malware file
Last Updated: May 20, 2023
C:\Users\<username>\AppData\Local\Temp\91221353\ZaxarSetup.4.001.31.exe File name: ZaxarSetup.4.001.31.exe
Size: 274.37 KB (274376 bytes)
MD5: 11d67eb24ccb79558c8f0ef7d4f1f723
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\91221353\ZaxarSetup.4.001.31.exe
Group: Malware file
Last Updated: January 11, 2023
%ALLUSERSPROFILE%\hdtask\hdtask.exe File name: hdtask.exe
Size: 291.81 KB (291816 bytes)
MD5: e8ccc4b35ac5d294b0d02df104c626ef
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\hdtask
Group: Malware file
Last Updated: June 15, 2017
%ALLUSERSPROFILE%\hdtask\hdtask.exe File name: hdtask.exe
Size: 180.22 KB (180224 bytes)
MD5: 477e33b43b83ba48adf1e8a941b97491
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\hdtask
Group: Malware file
Last Updated: June 15, 2017
%ALLUSERSPROFILE%\hdtask\hdtask.exe File name: hdtask.exe
Size: 258.5 KB (258503 bytes)
MD5: ab1b670a4e043cacec312e1cb543255e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\hdtask
Group: Malware file
Last Updated: June 15, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathZaxar Games Browser.lnkZaxarGameBrowser.lnkRegexp file mask%ALLUSERSPROFILE%\hdtask\hdtask.exe%PROGRAMFILES%\{AACE8122-B27D-421C-A5BB-95060941AFD7}.sys%windir%\system32\gfore[NUMBERS].dll%WINDIR%\System32\Tasks\Daily Trigger ScheduleCD%windir%\syswow64\gfore[NUMBERS].dll%windir%\tasks\gamerforest support.job%windir%\tasks\gamerforest updater.job%WINDIR%\{AACE8122-B27D-421C-A5BB-95060941AFD7}.sysHKEY..\..\..\..{RegistryKeys}Network\{AACE8122-B27D-421C-A5BB-95060941AFD7}Software\Cisco\{AACE8122-B27D-421C-A5BB-95060941AFD7}Software\gamesdepartSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Daily Trigger ScheduleCDSOFTWARE\Microsoft\Windows\CurrentVersion\Run\TimestasksSOFTWARE\Microsoft\Windows\CurrentVersion\Run\ZaxarLoaderSoftware\Schedule consumer dialogueSoftware\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\ZaxarSoftware\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files\ZaxarSoftware\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Program Files (x86)\ZaxarSoftware\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Program Files\ZaxarSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\TimestasksSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\ZaxarLoaderHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Schedule consumer dialogueTimeTasksZaxarGameBrowserZaxarGameBrowser4_is1

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\ZaxarGameBrowser%ALLUSERSPROFILE%\TimeTasks%APPDATA%\Microsoft\Windows\Start Menu\Programs\Zaxar Games Browser%LOCALAPPDATA%\GamerForest%LOCALAPPDATA%\ZaxarGameBrowser%LOCALAPPDATA%\cimei%PROGRAMFILES%\Zaxar%PROGRAMFILES(x86)%\Zaxar%appdata%\gamesdepart
Loading...