Home Possibly Unwanted Program Zaxar Games

Zaxar Games

Posted: August 26, 2014

Threat Metric

Ranking: 3,553
Threat Level: 1/10
Infected PCs: 224,200
First Seen: August 26, 2014
Last Seen: March 6, 2025
OS(es) Affected: Windows


The Zaxar Games platform is promoted as the Adobe Flash-based alternative to Battle.net by Blizzard Entertainment. The Zaxar Games platform is hosted on Zaxargames.com and is dedicated to delivering popular games to native Russian-speaking users. Zaxargames.com has a version in English, but most of the content available on Zaxar Games is provided in the Russian language. Computer users that are interested in the Zaxar Games are directed to download the Zaxar Games Browser.

The Zaxar Games Browser is the main module that loads games from Zaxargames.com directly on your desktop and allows for a more immerse experience. Zaxar Ltd operates the Zaxar Games platform, and you will need a registration to launch the Zaxar Games Browser. Web surfers with accounts on Mail.ru, Facebook, Fotostrana, and Vkontakte can use those accounts to login hassle-free into the Zaxar Games Browser. Users are not offered the option to exit Zaxar Games Browser directly. Keep in mind that the Zaxar Games Browser will run as a background process on the system, and you will need to terminate its process to remove it manually.

Moreover, users report that the Zaxar Games Browser program may show pop-up windows with advertisements on their desktops and welcome users to benefit from coupons and discounts from sponsors. If you are willing to install the Zaxar Games Browser, you should take into consideration that it is freeware, and you are not required to pay for the games on Zaxargames.com. Therefore, Zaxar Ltd should make money somehow, and ads should be expected to appear on your screen. Remember to read the terms of service agreement on Zaxargames.com if you are not sure what to expect from the Zaxar Games Browser. Zaxar Games is deemed as a Potentially Unwanted Program (PUP) that you can remove with the help of a reliable anti-spyware instrument effortlessly.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\ProgramData\hdtask\uninstall.exe File name: uninstall.exe
Size: 37.14 KB (37142 bytes)
MD5: 8d7abb4eca74060caca1a08103c3c40c
Detection count: 6,549
File type: Executable File
Mime Type: unknown/exe
Path: C:\ProgramData\hdtask\uninstall.exe
Group: Malware file
Last Updated: March 29, 2024
%USERPROFILE%\Local Settings\Application Data\Schedule\Schedule.exe File name: Schedule.exe
Size: 110.08 KB (110080 bytes)
MD5: 8a8c89d1838150ee8b343d66f09ee2b6
Detection count: 5,115
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data\Schedule
Group: Malware file
Last Updated: August 20, 2018
C:\System Volume Information\_restore{02EF14A9-1484-4129-B0B2-B0A26FE0A77E}\RP32\A0017571.exe File name: A0017571.exe
Size: 190.97 KB (190976 bytes)
MD5: fb1f04fb851fe921aec9148495669c55
Detection count: 2,204
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\_restore{02EF14A9-1484-4129-B0B2-B0A26FE0A77E}\RP32\A0017571.exe
Group: Malware file
Last Updated: April 12, 2023
C:\ProgramData\TimeTasks\timetasks.exe File name: timetasks.exe
Size: 207.36 KB (207360 bytes)
MD5: 66b922bbf84831294fb0de74d66f2ea7
Detection count: 967
File type: Executable File
Mime Type: unknown/exe
Path: C:\ProgramData\TimeTasks\timetasks.exe
Group: Malware file
Last Updated: September 9, 2024
C:\Users\<username>\AppData\Local\Temp\ZaxarSetup.4.001.33.exe File name: ZaxarSetup.4.001.33.exe
Size: 284.32 KB (284320 bytes)
MD5: 734a9c8b47712d396bcd1562a229517e
Detection count: 105
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\ZaxarSetup.4.001.33.exe
Group: Malware file
Last Updated: August 25, 2023
%SystemDrive%\ProgramData\hdtask\hdtask.exe File name: hdtask.exe
Size: 207.87 KB (207872 bytes)
MD5: 7668e7b0cd509511738fa3e124259f06
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\ProgramData\hdtask
Group: Malware file
Last Updated: June 15, 2017
%TEMP%\zaxarsetup.4.001.30.exe File name: zaxarsetup.4.001.30.exe
Size: 363.93 KB (363936 bytes)
MD5: 986f43006fea41ad10e32b143af127b6
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: May 11, 2016
C:\Users\<username>\AppData\Roaming\Installer\ZaxarSetup.4.001.108.exe File name: ZaxarSetup.4.001.108.exe
Size: 375.98 KB (375984 bytes)
MD5: b9d958c7dd4c47a56eee13560ab69e88
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\Installer\ZaxarSetup.4.001.108.exe
Group: Malware file
Last Updated: October 17, 2024
C:\Users\<username>\AppData\Local\Temp\91221353\ZaxarSetup.4.001.31.exe File name: ZaxarSetup.4.001.31.exe
Size: 274.37 KB (274376 bytes)
MD5: 11d67eb24ccb79558c8f0ef7d4f1f723
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\91221353\ZaxarSetup.4.001.31.exe
Group: Malware file
Last Updated: January 11, 2023
%TEMP%\{B7BBE289-6754-4CCF-8BBA-2A00BEFBC2F1}\ZaxarSetup_noy.4.001.31.exe File name: ZaxarSetup_noy.4.001.31.exe
Size: 750.71 KB (750712 bytes)
MD5: 22f5fe2a5ed2f90899a7b259a0ec4737
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\{B7BBE289-6754-4CCF-8BBA-2A00BEFBC2F1}
Group: Malware file
Last Updated: May 11, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathZaxar Games Browser.lnkZaxarGameBrowser.lnkRegexp file mask%ALLUSERSPROFILE%\hdtask\hdtask.exe%PROGRAMFILES%\{AACE8122-B27D-421C-A5BB-95060941AFD7}.sys%windir%\system32\gfore[NUMBERS].dll%WINDIR%\System32\Tasks\Daily Trigger ScheduleCD%windir%\syswow64\gfore[NUMBERS].dll%windir%\tasks\gamerforest support.job%windir%\tasks\gamerforest updater.job%WINDIR%\{AACE8122-B27D-421C-A5BB-95060941AFD7}.sysHKEY..\..\..\..{RegistryKeys}Network\{AACE8122-B27D-421C-A5BB-95060941AFD7}Software\Cisco\{AACE8122-B27D-421C-A5BB-95060941AFD7}Software\gamesdepartSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Daily Trigger ScheduleCDSOFTWARE\Microsoft\Windows\CurrentVersion\Run\TimestasksSOFTWARE\Microsoft\Windows\CurrentVersion\Run\ZaxarLoaderSoftware\Schedule consumer dialogueSoftware\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\ZaxarSoftware\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files\ZaxarSoftware\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Program Files (x86)\ZaxarSoftware\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Program Files\ZaxarSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\TimestasksSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\ZaxarLoaderHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Schedule consumer dialogueTimeTasksZaxarGameBrowserZaxarGameBrowser4_is1

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\ZaxarGameBrowser%ALLUSERSPROFILE%\TimeTasks%APPDATA%\Microsoft\Windows\Start Menu\Programs\Zaxar Games Browser%LOCALAPPDATA%\GamerForest%LOCALAPPDATA%\ZaxarGameBrowser%LOCALAPPDATA%\cimei%PROGRAMFILES%\Zaxar%PROGRAMFILES(x86)%\Zaxar%appdata%\gamesdepart
Loading...