PUP.Gamehack.EDA

The detection of PUP.Gamehack.EDA on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.Gamehack.EDA?

PUP.Gamehack.EDA is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as malicious as other types of malware, it can still cause problems with your system and compromise your privacy. PUPs are often installed unintentionally, bundled with other software or downloaded from untrusted sources.

How PUP.Gamehack.EDA Operates

PUPs like PUP.Gamehack.EDA typically operate by installing themselves on your system and then modifying your browser settings, registry entries, or other system files. They may also collect your personal data, such as browsing history, search queries, or other sensitive information. In some cases, PUPs can also download and install additional malware or unwanted software on your system.

It's worth noting that PUPs can be particularly tricky to detect and remove, as they often disguise themselves as legitimate programs or system files. However, by being aware of the symptoms of infection and taking proactive steps to protect your system, you can reduce the risk of PUPs causing harm.

Symptoms of Infection

If your system is infected with PUP.Gamehack.EDA, you may notice a range of symptoms, including slow system performance, unwanted pop-ups or ads, and modified browser settings. You may also notice that your system is crashing or freezing more frequently, or that your antivirus software is detecting and blocking suspicious activity.

  • Unwanted changes to your browser homepage or search engine
  • Pop-ups or ads appearing on your desktop or in your browser
  • Slow system performance or crashes
  • Unexplained changes to your system settings or files

How to Remove PUP.Gamehack.EDA

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow you to download and install removal tools
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan of your system to detect and remove the PUP
  3. Uninstall any suspicious programs or software that you don't recognize or need
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge
  5. Reboot your system and run another scan with your anti-malware tool to ensure that the PUP has been fully removed

Conclusion

Removing PUP.Gamehack.EDA from your system requires a combination of technical knowledge and caution. By following the steps outlined above and being proactive about protecting your system, you can reduce the risk of PUPs and other types of malware causing harm. Remember to always be cautious when downloading software or clicking on links, and to keep your antivirus software and operating system up to date to ensure that you have the latest security patches and protection.

Analysis Report

General information

Family Name: PUP.Gamehack.EDA
Signature status: No Signature

Known Samples

MD5: 93813680a34b0ec6255b2f8064a2b2f4
SHA1: 17db2e7ef6c1659e26b7dcc98c3d1700303d9737
File Size: 94.72 KB, 94720 bytes
MD5: 46263104498ab6332d548db08e66f2d5
SHA1: 62511baad63aa3d6a0a8a1981462ebe7b41a3472
SHA256: CD269C7FF20A5535448871A2FDE2D2FAD2D7C9D604F45441AE2F8850D636A6E9
File Size: 115.71 KB, 115712 bytes
MD5: 090e7a85634bc76f99457420bba8f4a0
SHA1: 72c9c77aebfe71e4adba89eb1901ee02d2f2c463
SHA256: D8174DB27FD7952947C55F938559EA2234E69F3A80A705314824ED78091902F0
File Size: 99.33 KB, 99328 bytes
MD5: 8307adcd429c3a96f7c0d4bb5d2c77a1
SHA1: a5283a2688baaf67f801ed790593c7096446c505
SHA256: B1C102F41D50D356BC0214B14C046258C569705758EA78061E3B6C73F95E2710
File Size: 141.82 KB, 141824 bytes
MD5: 2a9c25dab533091b430eeceeb10a160e
SHA1: c9b37e4f311dbaca2eb5fa8844a4c313e3bebfaa
SHA256: E9CE202C686B0EC56B52B2C80974B9F8D28C63D93214301CC3C3C52A1DD351A3
File Size: 1.54 MB, 1542781 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • HighEntropy
  • No Version Info
  • ntdll
  • WriteProcessMemory
  • x64

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nshd130.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshd130.tmp\modern-wizard.bmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nshd130.tmp\nsdialogs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshd130.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsmd100.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\utils\portchecker.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\utils\portchecker\app.go Generic Write,Read Attributes
c:\users\user\appdata\local\temp\utils\portchecker\go.mod Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Related Posts

Trending

Most Viewed

Loading...