PUP.Gamehack.ABB
The detection of PUP.Gamehack.ABB on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it to prevent further problems.
Table of Contents
What Is PUP.Gamehack.ABB?
PUP.Gamehack.ABB is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems with your computer's performance, stability, and security. They can be bundled with other software, downloaded from the internet, or installed through exploits. PUPs can collect user data, display unwanted advertisements, and slow down your system.
How PUP.Gamehack.ABB Operates
PUP.Gamehack.ABB, like other PUPs, can operate in various ways to achieve its goals. It may collect user data, such as browsing history and search queries, to display targeted advertisements. It can also slow down your system by consuming system resources, such as CPU and memory. In some cases, PUPs can also install additional software or modify system settings without user consent. Understanding how PUP.Gamehack.ABB operates is crucial in removing it from your system and preventing future infections.
Symptoms of Infection
The symptoms of PUP.Gamehack.ABB infection can vary, but common signs include slow system performance, unwanted advertisements, and suspicious programs installed on your system. You may also notice that your browser settings have been modified, or your search results are being redirected to unknown websites. If you suspect that your system is infected with PUP.Gamehack.ABB, it's essential to take immediate action to remove it.
- Unwanted advertisements and pop-ups
- Slow system performance
- Suspicious programs installed on your system
- Modified browser settings
- Redirected search results
How to Remove PUP.Gamehack.ABB
- Boot your system in Safe Mode with Networking to prevent PUP.Gamehack.ABB from loading and to allow for a clean removal process.
- Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove PUP.Gamehack.ABB and any other related malware.
- Uninstall any suspicious programs that may be related to PUP.Gamehack.ABB. Be cautious when uninstalling programs, as some may be legitimate.
- Reset your browser settings to their default values. This includes resetting Chrome, Firefox, and Edge browsers to remove any modified settings or extensions.
- Reboot your system and perform another scan to ensure that PUP.Gamehack.ABB has been completely removed.
Conclusion
Removing PUP.Gamehack.ABB from your system is crucial to prevent further problems and protect your personal data. By following the steps outlined above, you can ensure that your system is clean and secure. It's also essential to practice safe computing habits, such as avoiding suspicious downloads and being cautious when installing software, to prevent future infections. Remember to always use reputable anti-malware tools and keep your system and software up to date to protect against the latest threats.
Analysis Report
General information
| Family Name: | PUP.Gamehack.ABB |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
67ada75ffda13b863907b7e4a0e09e80
SHA1:
4fad6a57e9e17e22ccf0f3c368f9ad0e62d615c4
SHA256:
29F87B06014E0303C0C77CDAAA1120EEEF641ED56B8BB23EE7337D2CB5A0FB12
File Size:
154.13 KB, 154128 bytes
|
|
MD5:
e4cd05ed86308b4fd5bfd111cb57f3b3
SHA1:
23da68bc979829605cd583dd0e84e3a1cb0550dc
SHA256:
515107DDB298B4DB2A05500AFAA088638ECA3B9A3786C6C66F9DAD84CF9F0C2C
File Size:
393.22 KB, 393216 bytes
|
|
MD5:
c2a0e09812c0fbf6e505364789974bf5
SHA1:
66fd80c83c718b9a69bb29613b4f336a7c1a7bfb
SHA256:
91FE45AE3A5F88A3B2D2E40909D1A8C7A62C6E4BF2F856C472CD96FD92709899
File Size:
1.18 MB, 1178112 bytes
|
|
MD5:
ae5ee8b8e371ba441096bcd289a76438
SHA1:
8ecf129c3b615d26a9122ae4aed69babecbd0c1a
SHA256:
28CF829F42CC4770D39449EFDC4B11A0EC92DDE97129C0B05C91E3E4C7587E4D
File Size:
2.92 MB, 2917376 bytes
|
|
MD5:
62a2ee0a5d57f5f8fc49c83f2244690a
SHA1:
a529c15d0837e522ff3166ceb659f39941e27780
SHA256:
282F1B112D73978C2449A09A91C3D18885B2DC99671189F12F5FD235A1212C6F
File Size:
790.02 KB, 790016 bytes
|
Show More
|
MD5:
5abc0cc8384ba1e1d652231d1eaff4a6
SHA1:
f5babc6b9771a270feb6e697fda874b213128b1c
SHA256:
120E3A0CC817C189E23B8F5F03A6C98BAF8583912F37DCD618EF0C933AEC19FC
File Size:
153.60 KB, 153600 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have security information
- File has exports table
- File has TLS information
- File is 64-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.File Traits
- dll
- fptable
- GetConsoleWindow
- imgui
- No Version Info
- ntdll
- WriteProcessMemory
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 326 |
|---|---|
| Potentially Malicious Blocks: | 46 |
| Whitelisted Blocks: | 246 |
| Unknown Blocks: | 34 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Agent.KPF
- DNSChanger.B
- Downloader.Agent.BTF
- Gamehack.EDD
- Kryptik.ODFFC
Show More
- PSWDump.C
- Trojan.Downloader.Gen.KB
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 畻렫髪ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 憟렷髪ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | ��v��� | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
2 additional items are not displayed above. |
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| Network Urlomon |
|
| Other Suspicious |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c cls
|
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c taskkill /f /im HTTPDebuggerUI.exe >nul 2>&1
|
C:\WINDOWS\system32\taskkill.exe taskkill /f /im HTTPDebuggerUI.exe
|
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c taskkill /f /im HTTPDebuggerSvc.exe >nul 2>&1
|
C:\WINDOWS\system32\taskkill.exe taskkill /f /im HTTPDebuggerSvc.exe
|