PUP.Gamehack.GYF

Your system has been detected with PUP.Gamehack.GYF, a potentially unwanted program that may pose risks to your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it to prevent potential harm.

What Is PUP.Gamehack.GYF?

PUP.Gamehack.GYF is a type of potentially unwanted program that may have been installed on your computer without your knowledge or consent. It is not a virus, but it can still cause problems by modifying system settings, displaying unwanted advertisements, or collecting user data. The name "Gamehack" suggests that it may be related to gaming, but its actual purpose and behavior can vary.

How PUP.Gamehack.GYF Operates

PUP.Gamehack.GYF operates by installing itself on your computer, often through bundled software or deceptive downloads. Once installed, it can start modifying system settings, registry entries, or browser configurations to achieve its goals. It may also communicate with remote servers to receive updates, send user data, or display targeted advertisements. The program's behavior can be unpredictable and may cause system instability, crashes, or performance issues.

Symptoms of Infection

The symptoms of PUP.Gamehack.GYF infection can vary, but common signs include unwanted advertisements, pop-ups, or browser redirects. You may also notice changes in your system settings, such as altered homepage or search engine settings. Additionally, your computer may become slower, or you may experience frequent crashes or errors. In some cases, you may not notice any symptoms at all, which is why regular system scans and monitoring are crucial.

  • Unwanted advertisements or pop-ups
  • Browser redirects or changed search engine settings
  • System slowdowns or performance issues
  • Frequent crashes or errors
  • Changes in system settings or configurations

How to Remove PUP.Gamehack.GYF

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full system scan and detect any related threats.
  3. Uninstall any suspicious programs or software that may be related to PUP.Gamehack.GYF.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any modified configurations.
  5. Reboot your computer and perform another full system scan to ensure that the threat has been completely removed.

Conclusion

Removing PUP.Gamehack.GYF requires careful attention to detail and a thorough approach. By following the steps outlined above, you can help ensure that your system is clean and free from this potentially unwanted program. Remember to always be cautious when downloading software, and never install programs from untrusted sources. Regular system scans and monitoring can help prevent future infections and keep your computer running smoothly and securely.

Analysis Report

General information

Family Name: PUP.Gamehack.GYF
Signature status: No Signature

Known Samples

MD5: 1a7bf74d5753f36b15dca42064230b70
SHA1: 7da551013dde1517e7b0fe848b8c995357a9d74a
SHA256: 6FF4E98F459A7E7CDBF48E4444728100D3C9C49A8867206297CE8363F235F408
File Size: 5.05 MB, 5046272 bytes
MD5: feec0d4e29c50b775d2810c7b4c0f121
SHA1: cd48d9a21ee948d55b3de894af9478ad2d7be9a0
SHA256: 6F41FE0BB53169E9F16ECDEE45B5CBEA3CB904647C00D5034B184C3B447FE8A7
File Size: 7.39 MB, 7386112 bytes
MD5: 311b5af3f2d73e9d9594608215a85ca5
SHA1: a902c2436ac7b1ebff67a8e955808880a3053999
SHA256: 72CB6CD162E5CB845C6EA2AECBF50C320C218BF0C5788698B06AF5C2E40E6F68
File Size: 3.93 MB, 3929600 bytes
MD5: 09be9dc55bff8887a9c85b6467879e5a
SHA1: d2246f8302a8357ddb4b852ca503f6001cbb74fc
SHA256: 489AAF6D62CADD729B5F2888A0807426AF44C0373B8AD77D228EAE45CCEB46D5
File Size: 7.54 MB, 7541248 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • 2+ executable sections
  • fptable
  • HighEntropy
  • imgui
  • No Version Info
  • ntdll
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 4,430
Potentially Malicious Blocks: 178
Whitelisted Blocks: 3,948
Unknown Blocks: 304

Visual Map

0 0 x 0 ? 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 1 0 0 ? ? ? ? ? ? ? 0 0 ? ? ? 0 0 0 0 x 0 ? ? 0 0 0 0 0 0 0 x x x ? x 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 x 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? ? 0 1 ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? 0 0 ? 0 ? 0 ? ? ? 0 ? 0 ? 0 ? 0 ? ? 0 0 0 0 ? ? ? ? 0 ? 0 ? ? ? 0 ? 0 0 ? ? ? ? x 0 0 ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? 0 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? x 0 0 ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 0 0 x ? ? 0 0 x x 0 0 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 x 0 ? 0 0 ? ? ? 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 ? 0 0 x x 0 0 0 ? 0 x ? 0 x ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 1 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x x 0 x x 0 0 ? ? ? ? 0 ? ? ? ? 1 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? x 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? 0 ? ? ? 0 ? 0 0 0 ? 0 0 x 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 1 0 ? ? ? 0 0 0 1 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? 0 ? x 0 0 0 x 1 x 0 ? 0 0 0 0 x ? 0 0 x ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 1 1 ? ? 0 0 0 0 0 0 ? 0 ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? 0 ? 0 ? ? ? ? ? 0 0 0 0 0 0 ? 0 0 ? ? 0 0 ? ? 0 0 ? 0 0 0 0 1 0 0 ? 0 1 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x 0 1 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x x 0 0 0 x x x 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x x x 0 0 0 x 0 0 x x x 0 x 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 1 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 1 x 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 ? ? 0 0 x 0 x 0 0 0 x x x x 0 x 0 0 ? ? ? 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 x x ? ? 0 ? 0 0 0 0 ? 0 0 0 0 ? 0 0 ? 0 0 x x 0 x x x 0 x 0 0 0 0 0 0 0 0 x x x x 0 x x 0 x 0 x x x 0 x 0 0 x 0 x x x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.KFS
  • Agent.LKFB
  • Agent.TRG
  • ClipBanker.TI
  • CoinMiner.LFA
Show More
  • Coinminer.GOA
  • Coinminer.GP
  • Downloader.Agent.BTO
  • Downloader.Agent.BTP
  • Gamehack.EH
  • Gamehack.GACH
  • Gamehack.GYF
  • NetSupport.A
  • ShellcodeRunner.G

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAllocateReserveObject
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
Show More
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletion
  • ntdll.dll!NtSetIoCompletionEx
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Encryption Used
  • CryptAcquireContext
Network Winsock2
  • WSAStartup
Network Winsock
  • freeaddrinfo
  • getaddrinfo
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Related Posts

Trending

Most Viewed

Loading...