PUP.Gamehack.GAG

The detection of PUP.Gamehack.GAG on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.Gamehack.GAG?

PUP.Gamehack.GAG is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as malicious as other types of malware, it can still cause problems with your system and compromise your security. PUPs are often installed unintentionally, and they can be difficult to remove without the right tools and techniques.

How PUP.Gamehack.GAG Operates

PUP.Gamehack.GAG, like other PUPs, can operate in various ways, including modifying system settings, collecting user data, and displaying unwanted advertisements. It may also install additional malware or unwanted software on your system, which can further compromise your security. PUPs can be particularly problematic because they can be designed to evade detection by traditional antivirus software, making them challenging to remove.

Symptoms of Infection

The symptoms of a PUP.Gamehack.GAG infection can vary, but common signs include slower system performance, unwanted pop-ups and advertisements, and changes to your browser settings or homepage. You may also notice that your system is crashing or freezing more frequently, or that your antivirus software is detecting and blocking suspicious activity. If you suspect that your system is infected with PUP.Gamehack.GAG, it's crucial to take action promptly to prevent further damage.

How to Remove PUP.Gamehack.GAG

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove PUP.Gamehack.GAG and any related malware.
  3. Uninstall any suspicious programs or software that you don't recognize or need, as these may be related to the PUP infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that the infection has been fully removed.

Conclusion

Removing PUP.Gamehack.GAG from your system requires careful attention to detail and the right tools. By following the steps outlined above, you can help ensure that your system is fully cleaned and protected against future infections. Remember to always be cautious when downloading and installing software, and to keep your antivirus software up to date to prevent similar infections in the future. With the right approach and tools, you can effectively remove PUP.Gamehack.GAG and restore your system to a safe and secure state.

Analysis Report

General information

Family Name: PUP.Gamehack.GAG
Signature status: No Signature

Known Samples

MD5: e71aaf08b1f51fa1bf7baad94f783b4e
SHA1: eccfe6e2fae6c1c17563ae5a7964084f12cae0b6
SHA256: 676BF5CED782F5BA2D0852A1B36FFBC47222082CBC962FBAD145B64EEDF06997
File Size: 445.95 KB, 445952 bytes
MD5: 5871a2aac2a9d0913ba40765b543463c
SHA1: 09df60e1ff98972fa53391f9f8edd600b806a73b
SHA256: 9867AA6214E822948095E082E4FDDEEEE892E4A4F9570BDE1922BD2D3C6FCCA0
File Size: 392.70 KB, 392704 bytes
MD5: 2871b90d38a1afe64f55448faaea790d
SHA1: 1be9a0fa76cb1ca3460f829c6401e9afed0248a8
SHA256: E2CD8C12F5A14FDCD0BBF825B2BD7C3828AFA85992545F51F51C3133B562A77F
File Size: 358.91 KB, 358912 bytes
MD5: edde96c2aa5b350be6ae6af71d4b5d3c
SHA1: c2c16cfacee84bb0130800a7540cd24fd340d5ce
SHA256: 72D1423B28B253C98B9E144F038A01A7C0B3C9AAD823D192D0BE228E2AA0D0DC
File Size: 339.97 KB, 339968 bytes
MD5: 80ba492d7f275df368aa9c843530bbeb
SHA1: b7066a45cc082dea799fbd16bfa8f10c1f79538e
SHA256: 25AD350CF833EDB947AC10D433D39F9F35847C56DE038C958E25A6EA7AB4F5E5
File Size: 707.07 KB, 707072 bytes
Show More
MD5: 4380169eccd47580dff040dd02f62062
SHA1: 55466b6c8df097f48bee081275e5422eb285b686
SHA256: D3B0C4E4DEA0C89546A7B30E695D8091F417D69F00DAF2CBD66862698E8D8D66
File Size: 20.99 KB, 20992 bytes
MD5: b2fb93783582e09d9bab389c9ca673f4
SHA1: 088816dff870e6ab7131a9c7fcd41c2e720a7094
SHA256: 05FDAAA3438F05EC670AC85C66D0F40B7678F2B97423F684542D7A601E3717FC
File Size: 716.80 KB, 716800 bytes
MD5: bbe30fb71b31b2680ce115de87a0a27f
SHA1: df882d71ff1786f6443d2ca19fb7becac584c337
SHA256: A58C5A6B793802F673B0F79ED82178F7D88FCC812CB7D070DF93C00762889754
File Size: 605.18 KB, 605184 bytes
MD5: f621181443741aaf5449be461ff05321
SHA1: 67c5174a1f2b726d2c9d531fdd5711dd7edcd708
SHA256: 109641A8DDFB738F2EBC1EBB29CCF14353D19C294E7DB1F2DEA3422AA05BC677
File Size: 523.26 KB, 523264 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Tsuda Kageyu
File Description MinHook - The Minimalistic API Hook Library for x64/x86
File Version 1.3.3.0
Internal Name MinHookD
Legal Copyright Copyright (C) 2009-2017 Tsuda Kageyu. All rights reserved.
Legal Trademarks Tsuda Kageyu
Product Name MinHook DLL
Product Version 1.3.3.0

File Traits

  • dll
  • imgui
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 1,798
Potentially Malicious Blocks: 69
Whitelisted Blocks: 1,594
Unknown Blocks: 135

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 ? x x 0 x x 1 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 1 0 0 ? 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 x 0 0 ? 0 0 0 ? 0 0 ? ? 0 ? 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 ? ? 0 ? ? 0 0 x 0 x 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 x 0 0 0 0 x x x 0 0 x 0 0 0 0 0 0 0 0 0 ? x 0 0 0 ? ? 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 1 x 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 x 0 x 0 x ? 0 0 0 1 0 0 0 0 0 0 0 1 ? ? ? 0 0 0 x ? 0 0 0 0 0 0 ? ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x ? ? 0 x 0 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? x 0 0 ? ? ? 0 0 ? 0 0 ? ? 0 ? 0 0 ? ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 x ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 ? 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? x 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x 0 0 x 0 0 x 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
Show More
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiAnyLinkedFonts
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiComputeXformCoefficients
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateRectRgn
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiDoPalette
  • win32u.dll!NtGdiExcludeClipRect
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiExtSelectClipRgn
  • win32u.dll!NtGdiExtTextOutW
  • win32u.dll!NtGdiFontIsLinked
  • win32u.dll!NtGdiGetCharABCWidthsW
  • win32u.dll!NtGdiGetDCDword
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiGetDIBitsInternal
  • win32u.dll!NtGdiGetFontData

92 additional items are not displayed above.

Keyboard Access
  • GetAsyncKeyState
Service Control
  • ControlService
  • OpenService
Network Wininet
  • InternetOpen

Related Posts

Trending

Most Viewed

Loading...