PUP.GameHack.GACJ

The detection of PUP.GameHack.GACJ on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is PUP.GameHack.GACJ?

PUP.GameHack.GACJ is a type of malware that is designed to compromise the security and integrity of your system. While the exact nature of this threat is not fully understood without sandbox telemetry, it is clear that it has the potential to cause significant harm. PUPs like PUP.GameHack.GACJ often sneak onto systems through deceptive means, such as bundled software or malicious downloads, and can lead to a range of problems, including data theft, system crashes, and slowed performance.

How PUP.GameHack.GACJ Operates

Once installed, PUP.GameHack.GACJ may operate in the background, gathering sensitive information, monitoring user activity, or displaying unwanted advertisements. It may also attempt to connect to remote servers to download additional malware or receive instructions from its creators. The presence of this PUP can lead to a range of system changes, including altered settings, modified system files, and disrupted network connections.

Symptoms of Infection

Systems infected with PUP.GameHack.GACJ may exhibit a range of symptoms, including slow performance, frequent crashes, and unexpected pop-ups or advertisements. Users may also notice unusual network activity, changed browser settings, or unfamiliar programs installed on their system. In some cases, the PUP may attempt to disguise itself as a legitimate program or system process, making it difficult to detect without proper security tools.

How to Remove PUP.GameHack.GACJ

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of PUP.GameHack.GACJ.
  3. Uninstall any suspicious programs or applications that may be related to the PUP, taking care to follow proper uninstallation procedures to avoid causing further system damage.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or add-ons that may be associated with the PUP.
  5. Reboot your system and perform a follow-up scan to ensure that all remnants of PUP.GameHack.GACJ have been removed and that your system is secure.

Conclusion

Removing PUP.GameHack.GACJ from your system requires careful attention to detail and a comprehensive approach to ensure that all components of the malware are eliminated. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus protection, and being cautious when downloading and installing programs, you can help protect your system from future infections and keep your personal data safe. Remember, vigilance and proactive security measures are key to preventing the spread of malware and maintaining a secure computing environment.

Analysis Report

General information

Family Name: PUP.GameHack.GACJ
Signature status: No Signature

Known Samples

MD5: 7e124036f23325c2cec4a47ce7a4847e
SHA1: f5cfb050e8b8492d2482c99d54b4c7803782fd72
File Size: 648.70 KB, 648704 bytes
MD5: 021afbca749e2446e8c312a33b8e5533
SHA1: 770b1c2ace82fd523be6d65ea3a09ade29a518bf
SHA256: 2CDD40A90EA887003F0465DFF8692208D879E2744BAE0DC9AACCF407130D338F
File Size: 558.15 KB, 558152 bytes
MD5: a329d1a4abe5b3829f89b209bfbfc471
SHA1: 1cc65ed2eac7f8cbd207e6de64be35f7d89516c5
SHA256: 97865CADFE087E3D351F6B35FC7BAAB18AE5DE7C3D355E6C435411BA057BE7AD
File Size: 893.86 KB, 893864 bytes
MD5: 8cccd4676d52384e2e2ea440c358399f
SHA1: 6ed53b906511f73d8dfa432fde7daa80bde1a56d
SHA256: 7CD4A7705EBDCF80F7AD899BD3B720E013644C6C82502C02C6036E543EA31135
File Size: 893.86 KB, 893864 bytes
MD5: 4119d97fdb73ea9ad848dbce28ec1e10
SHA1: d00c7418cdc6db90e8e517607fd5169861ffc032
SHA256: E25C7D64C8B796A9906D42AD282E80DED137191B20E1AD92E47BA452EFC8C98E
File Size: 505.77 KB, 505768 bytes
Show More
MD5: 26acf51018fcd9236cb8fb9f289abc07
SHA1: db433f5b0698b82f6523b23030885de615d3f83f
SHA256: 4EE987D574C23507523F06EC0C3E6D8213A54C7EF972D92111B520CFEBD0A441
File Size: 332.71 KB, 332712 bytes
MD5: 51a91a4180201ae040c027a4fcf683ee
SHA1: 39c8145cffb048efb461ebd96e0f23b1ecbe1f1a
SHA256: 28CD56CB354D44410381C38CB1072FCD622624EC3B2AC21D7EF3AA288F879C21
File Size: 734.72 KB, 734720 bytes
MD5: e250aee5da13493f18b13b1c42e350b9
SHA1: 6e932e90fa826b3d4a22f911b7c781c3f3555124
SHA256: FDC7DBE82E92850E808F673CF432CFB3CDD3D76BFB97B2949578E6C3C6F09C81
File Size: 1.09 MB, 1085440 bytes
MD5: 620af42d2f6afc9fd63e129d11a1622a
SHA1: 21e2eb36ae3fc6e42654a85acd38ad20a9627cf6
SHA256: 8BAF308E7442998A8FD8CAC12D18DCB3D5433D1465D045D1C3D0E226BB795916
File Size: 443.30 KB, 443304 bytes
MD5: 570b33b0e56395ccfce30b9aa52536ba
SHA1: b44446fa27555056769768c4e5862509dcd2133f
SHA256: 9BC86154A93F94CB95720B6F7B2C3F67FE9C6DE0376081358A0B1E5A66FD4D0F
File Size: 330.75 KB, 330752 bytes
MD5: 8438ffd421c8cd909836b8fa3f7b1753
SHA1: 93383e281c524794357b18ab70a15da52917f91b
SHA256: 0C9F31AFE29E5DA242D33C7689E9C33C85EBDCDDD391D64CCB6A9DDD251CD207
File Size: 351.14 KB, 351144 bytes
MD5: 7e9acea7130887ac49e8f48b897bbc6e
SHA1: d24512bbe786eaf9ed6421ca433151969994e894
SHA256: 6515CD660EB425F1662D4B8382B38AEF38068BC0AA9EBF3517397E8C48B1B730
File Size: 432.04 KB, 432040 bytes
MD5: 38bb8fd46dbbbfaf20f48d4f65be7bf5
SHA1: 0c6f00aa0c221008d971f3d6ecc5301a20021a37
SHA256: 9B2F638FE1BB63E7F467B615448672C3544F9F9E50BE14C81329001A91E23EE8
File Size: 893.86 KB, 893864 bytes
MD5: fbaa586ed2ad7b170743d3ecf2403dee
SHA1: dc6285c7f7a5ff55bf9514722770987d7ea9c78e
SHA256: 9BE0DA44E216D8DA12AAD546690E67A27B81369923784670CB570404F9DDBD40
File Size: 693.16 KB, 693160 bytes
MD5: 7cdd192da289806349422a13a64bf0f4
SHA1: cf9c79288addb5f97f573f81c8444d38b789565c
SHA256: 35E104C3594671A729D332D7A9C1FDF1B678008B0BA706E7F9746E83D25AB5EC
File Size: 351.14 KB, 351144 bytes
MD5: add1fa8a3456256a2912d4ee25ca8e0d
SHA1: 719f24820b6b366f1b655416111a6b2bca43f07d
SHA256: B3E04B54C40C3359DA8421FA33D11B075B849F16C5DC55A8293E6AE389E76C78
File Size: 865.28 KB, 865280 bytes
MD5: ae13a6e606df23a1fe513979a1ceb2c6
SHA1: 9b401b2dcfe38df41d3ffdfb3eb91850ceb616ba
SHA256: F47772CCBC400D4F8BB002C18E6D92EBBB9B21F431D8415C92FC8113622300D9
File Size: 368.64 KB, 368640 bytes
MD5: 3e4e0c2b52197301e0c9d6cd2c68da4f
SHA1: a2f659cfee001df2c71e5c5f8a2ca63247cccf37
SHA256: DEDEF175B22873385191F9F04C2FA0A97495DBDA757E6203C63AC1F2BE7D3740
File Size: 340.39 KB, 340392 bytes
MD5: 2336fb0ed567bba85c91a9ed030a34aa
SHA1: 9974c2ac0a828aa9e87ba1721a35599976a11a11
SHA256: 2B6A295B391978D3EF4215B0E403462999BB8526392C67ED4D9EEA6445520F82
File Size: 353.70 KB, 353704 bytes
MD5: 88417ce9d0c0c83879cd54ece01f800b
SHA1: 9ce797aa4f1544748add0d7e8c4297e866adb91a
SHA256: D96CCBB4E7E62C69C296ED023C6DE64024B7BBE69DF864F1B9EB8ECC7B9EA783
File Size: 457.22 KB, 457216 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Show More

Windows PE Version Information

Name Value
Company Name
  • Double Helix Games
  • GitHub, Inc.
  • GSE
File Description
  • GSE
  • info.fragaria.okinawa.c100
  • Strider Hiryu
File Version
  • 1.0.1
  • 1.0.0.2
  • 1, 0, 0, 2
Internal Name
  • GSE
  • info.fragaria.okinawa.c100
  • Strider Hiryu
Legal Copyright
  • Copyright (C) 2015 GitHub, Inc. All rights reserved.
  • Copyright (C) 2021 GSE
  • ©MOTO KIKAKU. ©CAPCOM CO., LTD. 2014 ALL RIGHTS RESERVED
Original Filename
  • info.fragaria.okinawa.c100.exe
  • steam.exe
  • Strider Hiryu.exe
Product Name
  • GSE
  • info.fragaria.okinawa.c100
  • Strider Hiryu
Product Version
  • 1.0.1
  • 1.0.0.2
  • 1, 0, 0, 2
Source Control I D 8563863
Squirrel Aware Version 1

Digital Signatures

Signer Root Status
GSE GSE Self Signed

File Traits

  • fptable
  • HighEntropy
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 1,320
Potentially Malicious Blocks: 38
Whitelisted Blocks: 1,270
Unknown Blocks: 12

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 x x x x 0 0 0 0 x x 0 0 x x 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 x x x x 0 x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.FDZ
  • Agent.MIW
  • Brute.LC
  • BypassUAC.AR
  • Downloader.GDF
Show More
  • GameHack.GACJ
  • Gamehack.DT
  • Gamehack.FT
  • PSW.Agent.PF
  • Stealer.DN
  • Trojan.Agent.Gen.BDN
  • Trojan.Downloader.Gen.OR

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
Show More
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Related Posts

Trending

Most Viewed

Loading...