PUP.Gamehack.HDG
The detection of PUP.Gamehack.HDG on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it to prevent any potential harm.
Table of Contents
What Is PUP.Gamehack.HDG?
PUP.Gamehack.HDG is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems, such as displaying unwanted advertisements, collecting user data, or modifying system settings. The "Gamehack" part of the name suggests that this PUP may be related to gaming or cheating software, which can be particularly problematic as it may compromise the integrity of online games or steal sensitive information.
How PUP.Gamehack.HDG Operates
PUPs like PUP.Gamehack.HDG often operate by exploiting vulnerabilities in software or using social engineering tactics to trick users into installing them. Once installed, they may run in the background, consuming system resources, and performing unwanted actions. In the case of PUP.Gamehack.HDG, it may be designed to interact with online games, potentially allowing cheaters to gain an unfair advantage or stealing sensitive information such as login credentials or credit card numbers.
Symptoms of Infection
Systems infected with PUP.Gamehack.HDG may exhibit a range of symptoms, including slow performance, unwanted pop-ups or advertisements, and unexpected changes to system settings. Users may also notice unusual network activity or suspicious processes running in the background. In some cases, the PUP may cause system crashes or freezes, particularly if it is interfering with other software or system components.
- Unwanted advertisements or pop-ups
- Slow system performance
- Unexpected changes to system settings
- Suspicious network activity
- System crashes or freezes
How to Remove PUP.Gamehack.HDG
- Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for easier removal.
- Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove any malicious components.
- Uninstall any suspicious programs or applications that may be related to the PUP.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or add-ons.
- Reboot your system and perform another full scan to ensure that the PUP has been completely removed.
Conclusion
Removing PUP.Gamehack.HDG from your system is crucial to preventing any potential harm and ensuring the security and performance of your computer. By following the steps outlined above, you can effectively remove this PUP and prevent any further issues. It's also essential to practice good cybersecurity habits, such as regularly updating your software, using strong passwords, and being cautious when installing new applications, to prevent similar threats in the future.
Analysis Report
General information
| Family Name: | PUP.Gamehack.HDG |
|---|---|
| Signature status: | Root Not Trusted |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
dd28f3c15e4b74aa5c2ab42b2d9b7d94
SHA1:
1faadf21018446fd536be403115b163a4b78795d
SHA256:
FA6E6773B7E6FFEF5546589AF7F4BCF2C0D425B8B14D67BA888E98550D33D993
File Size:
340.48 KB, 340480 bytes
|
|
MD5:
ca4936eabb2eb7f12354e12ac9f431d4
SHA1:
dab8713a657ee5dd1a1ea15c879b8ad316a7c4d8
SHA256:
F923A243D1F7CAEA5B70AA807135A30769D8F6766778394A25B4DF8B7CE7DB5D
File Size:
614.40 KB, 614400 bytes
|
|
MD5:
65e052051f2c7e212c49a9b80a44ea18
SHA1:
bfcf296f4807afa3d6c6765dbbf8ed7867c948eb
SHA256:
937E77F49F7BFFF94AD0FBD79C3CE59794E2A48C82FB8116F6C6B0561126EC3D
File Size:
629.76 KB, 629760 bytes
|
|
MD5:
7b7c499685a7c44a6fbad963c6c968ec
SHA1:
a3ac47214614bc74e1ee070745938779ddcc7d59
SHA256:
894909E51E2AD35A3C2D88DC9261367F865D1249CF7F17EEBD32A1FEA0F1BFA1
File Size:
2.58 MB, 2575360 bytes
|
|
MD5:
7ed9f17cc8e57e7f92b33c8ca0f5d805
SHA1:
d3a3160a1cbf4daac4bcda065b2d7885194325e1
SHA256:
827BBEC9343C26C6DE1E95D2E2DC410179F8A040C94F6FE9CD1266E388DDDA25
File Size:
2.74 MB, 2735616 bytes
|
Show More
|
MD5:
c94bdb44e8729bcd59f8a9020455fc72
SHA1:
6b9ce6110287cae672e5a31e2ee2ba9884a37760
SHA256:
45F4D037F99FF2DEB4F97DF40A0C013138EE939EEA5981060FF1B6F940A893F4
File Size:
1.11 MB, 1109504 bytes
|
|
MD5:
aada3fdca2a4fa9d016978d54c23bf7d
SHA1:
c8ee1c59b7f7e0ba6691e910474dae835cad4d78
SHA256:
7284FD1277E0B83DA342C13766C8450487284CB6731AF56BFE4EDED8A72E5C94
File Size:
314.66 KB, 314656 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have security information
- File has exports table
- File has TLS information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name | Archie Workshop |
| File Description |
|
| File Version |
|
| Internal Name |
|
| Legal Copyright |
|
| Original Filename |
|
| Product Name |
|
| Product Version |
|
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| 山西荣升源科贸有限公司 | DigiCert Trusted Root G4 | Root Not Trusted |
File Traits
- dll
- fptable
- HighEntropy
- imgui
- WriteProcessMemory
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 1,187 |
|---|---|
| Potentially Malicious Blocks: | 8 |
| Whitelisted Blocks: | 1,157 |
| Unknown Blocks: | 22 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Gamehack.HDG
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\software\wow6432node\microsoft\direct3d\mostrecentapplication::name | rundll32.exe | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| Process Shell Execute |
|
| Anti Debug |
|
| Process Manipulation Evasion |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\1faadf21018446fd536be403115b163a4b78795d_0000340480.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\dab8713a657ee5dd1a1ea15c879b8ad316a7c4d8_0000614400.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\bfcf296f4807afa3d6c6765dbbf8ed7867c948eb_0000629760.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\a3ac47214614bc74e1ee070745938779ddcc7d59_0002575360.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d3a3160a1cbf4daac4bcda065b2d7885194325e1_0002735616.,LiQMAxHB
|
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\6b9ce6110287cae672e5a31e2ee2ba9884a37760_0001109504.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\c8ee1c59b7f7e0ba6691e910474dae835cad4d78_0000314656.,LiQMAxHB
|