PUP.Gamehack.GDDI

The detection of PUP.Gamehack.GDDI on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take prompt action to remove it and prevent further damage.

What Is PUP.Gamehack.GDDI?

PUP.Gamehack.GDDI is a type of malware that is categorized as a potentially unwanted program. This means that while it may not be as malicious as other types of malware, such as viruses or trojans, it can still cause problems with your system and compromise your personal data. PUPs are often installed unintentionally, and they can be difficult to remove without the right tools and expertise.

How PUP.Gamehack.GDDI Operates

PUP.Gamehack.GDDI, like other PUPs, operates by installing itself on your system and then executing its payload. This can happen through various means, such as downloading software from untrusted sources, clicking on malicious links, or opening infected email attachments. Once installed, PUP.Gamehack.GDDI can start to cause problems, such as displaying unwanted advertisements, collecting your personal data, and slowing down your system's performance.

Symptoms of Infection

The symptoms of a PUP.Gamehack.GDDI infection can vary, but common signs include unwanted pop-ups and advertisements, slow system performance, and suspicious programs running in the background. You may also notice that your browser settings have been changed, or that you are being redirected to unfamiliar websites. If you suspect that your system has been infected with PUP.Gamehack.GDDI, it's crucial to take action quickly to prevent further damage.

  • Unwanted advertisements and pop-ups
  • Slow system performance
  • Suspicious programs running in the background
  • Changed browser settings
  • Redirection to unfamiliar websites

How to Remove PUP.Gamehack.GDDI

  1. Boot your system in Safe Mode with Networking to prevent PUP.Gamehack.GDDI from running and interfering with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs that were installed without your knowledge or consent.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan to ensure that PUP.Gamehack.GDDI has been completely removed.

Conclusion

Removing PUP.Gamehack.GDDI from your system requires careful attention to detail and the right tools. By following the steps outlined above, you can help to ensure that your system is free from this potentially unwanted program and any other malicious software that may be present. Remember to always be cautious when downloading software or clicking on links, and to keep your anti-malware tools up to date to prevent future infections.

Analysis Report

General information

Family Name: PUP.Gamehack.GDDI
Signature status: No Signature

Known Samples

MD5: 2f25515e4afae9f5e4bf76c31df726d9
SHA1: 8ff2fef4dd497f35df0a907f45cf98cc68095653
SHA256: 9361C89F316260D1AB3A72B4AEBF18CDD8A70287ABA4D2F1003DE1618263539A
File Size: 3.60 MB, 3601408 bytes
MD5: 155e22413435b7a8d916bc3511dbc3f3
SHA1: ac620c7812f018d17868d10eba89b0149de20ebc
SHA256: A8DD28464F62F1E6A1C7AB047C60123670354AB1D56A81D09ABDC8C61CF36654
File Size: 7.43 MB, 7434752 bytes
MD5: 0e89d894ff753b6863fe5e6779b616d7
SHA1: 86be507ba0527062f349fe5b10721336909db231
SHA256: CE9906D0238F4A08F29A59258BB9DD7DD6E632158F295882FAD2D9136BB43C36
File Size: 3.71 MB, 3709952 bytes
MD5: 026264c263b79e810070a07d6b8f2ec8
SHA1: 0fbba8858165161fd32a14eb27b2b91a3bfc3f18
SHA256: 0B9727C6C93D64F085F076C4EA18EE0F11E14CC25992529C3C10B66A8F815A08
File Size: 3.40 MB, 3401216 bytes
MD5: 42fa8332e80b66c3d6c74ced64573fba
SHA1: bcfb7c857b4bdd2e5bed0d441230aa8f717d6f68
SHA256: 542C28CF8E0CF8A693C71A880B395002EC66BCB2123C787FF6EAFBF6B7EB993F
File Size: 1.44 MB, 1443328 bytes
Show More
MD5: 09576cdc69f18132219b091301946592
SHA1: 36cfa55e3c39812bf3018e45fd7d4ab8616f4d8e
SHA256: 729B75E6A65AC1799A687E0269FA3D7ABA79299D21D9725F46CF4F62E923E663
File Size: 4.71 MB, 4706304 bytes
MD5: 4ed9ff816810413cceb3ce1a5b3cec82
SHA1: d4564abba473c8bfda6a06b204ebf53dffdb735d
SHA256: D2B4878C39D460FADB239AB412ADD05A4A1719A68F156AA2D5E7635B2CBA261E
File Size: 6.37 MB, 6365696 bytes
MD5: b07895b5d75c1d01714dd56d6cd152d2
SHA1: cd9c885cdcdfdaf4b9024eac8ff7bfa0588877e0
SHA256: E483EBBA12114D2659E0391AC4EE1C9A7D68BCFB9E24E6A07A335DAB4A6E0E60
File Size: 6.47 MB, 6469632 bytes
MD5: 1b8689bcae05a18b335d61042e76499a
SHA1: bf15745c9addb88f5f9b1c432fc5347df626e7e5
SHA256: 4C3E8F28787DE9ACDD9A841D180D82E2334861775AAFD18FDAB180554BE40AD2
File Size: 1.87 MB, 1866240 bytes
MD5: c698caefdb6c62b5ddb350cdf06883db
SHA1: c14514a59c1b4298fc5b897a5a028b6261c154ac
SHA256: 64374F2B01C1BC96BB72D72B6BEE349CB8878DF1BA9E7D6B6CC19A4BA7AC029D
File Size: 371.71 KB, 371712 bytes
MD5: 894e97070dc954efc4695b3981ae3937
SHA1: aff39a275ab0d9fa5a120d804e9087f49e5a778b
SHA256: 44672DD2F3AFBCA77ACFC6D64A4E3C9A40AC748297C8CA13399E69BFDCA0F2CE
File Size: 3.31 MB, 3314688 bytes
MD5: a884a0368ef2d8f9d97a1eddc357adb0
SHA1: fbe494076c3f5ab911864dde1e23cc1362fcc8be
SHA256: A0840F3E3AF335BF663B7C3FEE31165353CBDE7B23BB48CC0C54046B81F661DC
File Size: 6.29 MB, 6290965 bytes
MD5: 95eca22782197d0f92e6adf28f5ea147
SHA1: b74204f1116a7def0dead19464fd5a3194892ee4
SHA256: 3A69B7D248366F63D14D89C6D0684FAA8DA04DA84FB68C6A33C045CE1C77E33F
File Size: 4.03 MB, 4029279 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments Free crypto library, more information available at www.cryptopp.com
Company Name Crypto++® project
File Description
  • Crypto++® Library DLL
  • OBS Studio
File Version
  • 17.0.0.0
  • 8, 9, 0, 0
Internal Name
  • cryptopp
  • OBS Studio
Legal Copyright
  • Copyright OBS Corporation. All rights are reserved within OBS Corporation.
  • Copyright© 1995-2021 by Wei Dai
Legal Trademarks Crypto++®
Original Filename
  • cryptopp.dll
  • OBS.exe
Product Name
  • Crypto++® Library
  • OBS
Product Version
  • 3169.31.0
  • 8, 9, 0, 0

File Traits

  • big overlay
  • dll
  • fptable
  • GetConsoleWindow
  • HighEntropy
  • imgui
  • No Version Info
  • ntdll
  • VirtualQueryEx
  • WriteProcessMemory
Show More
  • x64

Block Information

Total Blocks: 4,240
Potentially Malicious Blocks: 701
Whitelisted Blocks: 3,509
Unknown Blocks: 30

Visual Map

0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 x x x x x x 0 x x x 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x x x 0 0 x 0 0 0 x 0 x x 0 x x 0 0 0 0 x x 0 0 x 0 0 x x 1 x x x x 0 x x x x x 0 x 0 0 x x x x 0 x 0 x x 0 x x x 0 0 x x 0 0 x 0 0 0 0 x x 0 0 x 0 0 x x x 0 0 0 x 0 0 0 x x 0 0 x 0 x x 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 x x 0 x x 0 0 0 0 0 0 x x x 0 x x x x 0 0 x x x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 x x 0 x x x 0 x x 0 0 ? 0 ? 0 x ? x 0 0 x 0 0 0 x 0 x 0 0 0 x x 0 x 0 x 0 x 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 x 0 0 x 0 0 0 x 0 0 x x 0 0 0 x 0 0 x 0 x x 0 x 0 0 0 x 0 0 x x 1 0 0 1 x 0 x 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 x x 0 x 0 0 0 0 0 x x x x 0 0 0 0 0 0 x 0 0 0 0 x x x 0 0 x x 0 0 0 0 x x x x x 0 x 0 x x x 0 x 1 x 0 0 0 0 x x 0 x 0 x 0 x x 0 x 0 x 0 x 0 0 x x 0 0 x x x 0 0 0 x x 0 0 0 0 0 x 1 0 0 0 x 0 0 1 0 x 0 0 x 0 x x x 0 x x x 0 x 0 x x 0 0 0 0 x x x x x 0 x 0 0 x x x x x 1 0 x 0 0 x 1 x 0 x 1 x x x 0 0 0 0 0 x 1 x 0 0 0 x 0 x x 0 x 0 x x x 0 x 0 0 0 x x x x 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 x 0 x x x x 0 0 0 0 x x x 0 x 0 x 0 x 0 x x x x x 0 0 0 0 0 0 x 0 0 x 0 x 0 0 x x 0 x 0 x x x x 0 0 0 0 0 0 x x x x x 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x 0 x 0 0 1 0 0 1 0 0 0 1 0 0 1 0 0 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x x 0 x x x 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 1 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 x 0 x x x 0 0 0 x 0 0 0 0 x x 0 0 x 0 x 0 0 0 0 0 x 0 0 0 x x 0 0 x 0 0 x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 x x x 0 x 0 0 x x 0 x x x 0 x 0 x x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 x 0 x 0 x x 0 x 0 0 x x 0 0 x 0 0 0 0 x x x 0 x 0 0 x 0 0 0 x 0 0 x 0 0 0 0 x x 0 0 x 0 0 0 x x x 0 x x x 0 0 0 x x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x x x x x x x x 0 x 0 x 0 x 0 x 0 x 0 0 x 0 x x x x 0 x x x 0 x 0 0 x x x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 x x 0 0 x 0 0 x x 0 x x x x 0 x x x x x 0 x x x x x 0 0 x 1 0 x x 0 x x x 0 x 0 0 0 0 0 0 0 0 x x x x x 0 x 0 0 0 0 x 0 0 x x 0 0 x 0 x 0 x x x 0 0 0 0 x 0 x x x 0 0 0 0 x 0 x x x 0 0 0 0 x 0 0 x x x 0 0 0 0 x x x x 0 0 x x x x x 0 0 x 0 0 0 0 0 0 x x x x 0 x x 0 0 0 0 x x x x 0 x x 0 0 0 0 x x x x 0 x x 0 0 x 0 x x x x 0 x x 0 0 x 0 x x x 0 0 0 x x x 0 x x x 0 0 x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 1 0 x x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 x x x x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 1 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 x x 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 0 x x 0 x 0 0 x x x 0 0 x 0 x x 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 x x x x x x 0 x x 0 x x x 0 0 0 x x 0 x x x x ? 0 0 ? ? x x x x 0 0 x x 0 ? x x 0 x x 1 x x x x x x ? x x x x x x 0 x x ? 0 x x 0 x x x x x 0 ? x 0 x 0 0 ? 0 x 0 0 ? ? x x x x 0 0 x x x x x x x x x x x ? x ? x x 0 x x 0 0 0 x 0 x x x x x x x x x x 0 0 x x x 0 x ? x x x x x x 0 x x x x x ? x 0 x ? x ? x x ? 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 ? 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gamehack.CAB
  • Gamehack.DSE
  • Gamehack.EBB
  • Gamehack.GAGC
  • Gamehack.GDDI
Show More
  • Gamehack.GSM
  • Kryptik.DTE
  • Kryptik.DYT
  • Kryptik.NPD
  • Trojan.Kryptik.Gen.DJG

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 泷蚏Ÿǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 쉓螨Ÿǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 헲౛Ꮳǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ಿᏣǝ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAllocateReserveObject
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreateSecurityContext
Show More
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcOpenSenderProcess
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletionEx
  • ntdll.dll!NtSetSystemInformation
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl

13 additional items are not displayed above.

Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Keyboard Access
  • GetAsyncKeyState
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • WriteConsole
Network Winsock2
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • getpeername
  • getsockname
  • send
  • setsockopt
  • socket

Shell Command Execution

C:\WINDOWS\system32\mode.com mode con: cols=90 lines=26
WriteConsole: Access is denied

Related Posts

Trending

Most Viewed

Loading...