PUP.Gamehack.AEG

The detection of PUP.Gamehack.AEG on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take steps to remove it to prevent potential harm.

What Is PUP.Gamehack.AEG?

PUP.Gamehack.AEG is a type of malware that falls under the category of potentially unwanted programs. These programs are often installed on a system without the user's knowledge or consent, usually through bundled software or deceptive downloads. While they may not be as malicious as other types of malware, PUPs can still cause problems, such as displaying unwanted advertisements, collecting user data, or altering system settings.

How PUP.Gamehack.AEG Operates

Once installed, PUP.Gamehack.AEG may operate in the background, potentially collecting user data, monitoring browsing habits, or displaying unwanted advertisements. It may also attempt to modify system settings or install additional software without the user's consent. In some cases, PUPs like PUP.Gamehack.AEG may be used to distribute more malicious software or to create a backdoor for remote access.

Symptoms of Infection

Systems infected with PUP.Gamehack.AEG may exhibit a range of symptoms, including slowed performance, unwanted pop-ups or advertisements, and changes to browser settings or homepage. Users may also notice unfamiliar programs or icons on their system, or experience unexpected crashes or errors. In some cases, PUPs can also lead to more severe issues, such as data breaches or identity theft.

  • Unwanted advertisements or pop-ups
  • Changes to browser settings or homepage
  • Slowed system performance
  • Unfamiliar programs or icons
  • Unexpected crashes or errors

How to Remove PUP.Gamehack.AEG

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove any malicious files or programs.
  3. Uninstall any suspicious programs or software that may be related to the PUP.Gamehack.AEG infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that all remnants of the malware have been removed.

Conclusion

Removing PUP.Gamehack.AEG from your system is crucial to preventing potential harm and maintaining the security and performance of your computer. By following the steps outlined above and taking proactive measures to protect your system, you can help prevent future infections and keep your data safe. It's also essential to remain vigilant and monitor your system for any suspicious activity, as PUPs like PUP.Gamehack.AEG can be persistent and difficult to detect.

Analysis Report

General information

Family Name: PUP.Gamehack.AEG
Signature status: No Signature

Known Samples

MD5: 2dfcb24851d09cb90f8a623083646eac
SHA1: c3ea9debbd5d04bb6c529f52180f8ac6c5be0aef
SHA256: 4BEDFEE01A8325AAFFD248969265C763A3B063E4219FF4F4872F00E6058F0B2B
File Size: 1.14 MB, 1136640 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 3,535
Potentially Malicious Blocks: 503
Whitelisted Blocks: 2,608
Unknown Blocks: 424

Visual Map

0 x 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? ? ? 0 0 0 0 0 0 0 ? x ? ? ? 0 ? ? ? ? 0 ? 0 0 ? 0 0 0 0 x x x x x x x x x x x x 0 x 0 0 0 0 ? 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? x 0 0 ? ? ? ? x x x x x ? ? x ? 0 0 0 0 x ? x ? x 0 ? 0 ? ? ? x 0 0 x 0 ? x 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 x 0 ? 0 0 0 0 ? ? ? x 0 0 x x 0 ? ? 0 ? ? ? 0 0 0 x x 0 ? ? 0 x ? ? 0 x 0 0 0 ? x 0 x x x ? 0 0 0 0 x 0 x x 0 0 0 x ? x x x x x 0 0 x 0 ? x ? x ? x ? x x ? ? x x x x 0 0 0 x ? 0 0 x 0 0 ? ? ? ? ? 0 x 0 0 x 0 x 0 0 0 ? 0 0 ? x x 0 ? 0 ? 0 0 x ? 0 x ? ? 0 0 0 x ? ? 0 ? 0 x 0 x 0 x ? 0 0 ? 0 ? 0 ? ? ? ? ? 0 0 0 0 ? 0 0 0 ? ? x x x 0 0 0 ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 x 0 0 0 ? ? ? ? ? x 0 0 ? 0 0 x 0 0 0 0 ? 0 0 0 0 0 0 ? ? x 0 0 0 x 0 0 x x ? ? ? ? 0 0 ? 0 x 0 ? 0 ? 0 ? 0 0 0 x 0 0 ? x x x 0 x ? x x x x 0 0 ? ? 0 ? 0 0 0 0 0 0 0 ? ? ? 0 ? ? x ? x 0 0 0 ? ? ? ? x 0 ? 0 ? 0 ? ? ? 0 0 x 0 0 0 x 0 x ? x 0 ? 0 0 ? ? 0 ? 0 ? ? 0 ? 0 0 0 0 0 x 0 0 ? x 0 0 0 x x 0 0 0 0 ? 0 0 x x x x ? 0 x x 0 0 0 x ? 0 0 0 0 x 0 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 x ? ? ? 0 x ? 0 ? 0 0 0 x ? 0 ? 0 0 0 0 ? 0 0 0 ? ? 0 x 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 x 0 0 ? x ? ? ? ? ? ? 0 ? ? 0 x ? 0 0 x 0 0 0 x x x 0 0 x ? ? 0 0 0 0 ? x 0 0 0 0 0 0 ? ? x 0 0 0 0 0 0 1 x 0 0 0 x 0 0 0 0 x 0 0 0 0 x x 0 ? ? 0 x 0 0 0 0 ? x 0 ? ? x 0 x 0 0 0 ? 0 x 0 0 0 0 x ? ? x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x ? ? 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 ? ? 0 ? ? 0 0 ? x x x x x x 0 0 0 0 0 x x 0 x 0 0 x ? 0 ? x ? ? ? ? ? ? 0 0 0 ? ? ? 0 0 0 ? ? ? ? ? 0 ? ? x x x x 0 0 0 0 0 0 0 ? x 0 0 0 0 x x ? ? ? ? x x ? ? x 0 x x ? 0 x ? 0 0 0 0 0 x 0 0 0 0 ? x x ? ? 0 ? 0 0 x 0 ? ? x ? x ? ? ? x x 0 ? ? ? 0 x ? 0 x 0 x x x x 0 x x x x x 0 x x x x 0 x 0 0 0 0 0 0 0 0 ? ? 0 0 x x x x x x 0 0 x x x x x x ? 0 x ? 0 0 ? ? 0 x ? ? 0 0 x x x ? 0 0 ? ? ? 0 ? ? ? ? ? x x x x x 0 ? x 0 0 x 0 ? 0 0 ? 0 0 x x x x 0 x ? ? ? x 0 0 0 0 0 0 x ? ? ? 0 0 ? x x x x x x x x x x x x x x ? x x x x x x x 0 0 0 0 0 0 0 x x x x x 0 0 x ? x x x ? 0 ? x ? x ? ? x ? 0 ? 0 0 0 0 ? 0 0 x 0 0 0 0 x 0 0 ? ? 0 x ? x x x 0 0 x x 0 ? ? 0 ? ? ? ? x 0 0 x ? 0 0 x ? x x x 0 0 0 ? 0 0 0 0 ? 0 ? x 0 ? x x x ? ? 0 ? ? ? ? 0 ? ? ? ? ? 0 ? 0 0 0 0 0 ? 0 ? ? ? ? x ? 0 ? ? x 0 0 0 0 0 ? ? ? ? 0 ? 0 x x x 0 x ? 0 x x x 0 x x 0 0 ? 0 0 x x x x x x ? 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtGdiAnyLinkedFonts
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiComputeXformCoefficients
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateRectRgn
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiDoPalette
  • win32u.dll!NtGdiExcludeClipRect
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiExtSelectClipRgn
  • win32u.dll!NtGdiExtTextOutW
  • win32u.dll!NtGdiFontIsLinked
  • win32u.dll!NtGdiGetCharABCWidthsW
  • win32u.dll!NtGdiGetDCDword
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiGetDIBitsInternal
  • win32u.dll!NtGdiGetFontData
  • win32u.dll!NtGdiGetGlyphIndicesW
  • win32u.dll!NtGdiGetOutlineTextMetricsInternalW
  • win32u.dll!NtGdiGetRandomRgn
  • win32u.dll!NtGdiGetRealizationInfo
  • win32u.dll!NtGdiGetTextCharsetInfo
  • win32u.dll!NtGdiGetTextExtentExW
  • win32u.dll!NtGdiGetTextFaceW
  • win32u.dll!NtGdiGetTextMetricsW
  • win32u.dll!NtGdiGetWidthTable
  • win32u.dll!NtGdiHfontCreate
  • win32u.dll!NtGdiIntersectClipRect

76 additional items are not displayed above.

Related Posts

Trending

Most Viewed

Loading...