PUP.Gamehack.HDJ

The detection of PUP.Gamehack.HDJ on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.Gamehack.HDJ?

PUP.Gamehack.HDJ is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software programs that may not be malicious in nature but can still cause problems with your computer's performance, stability, and security. They can be bundled with other software programs, downloaded from the internet, or installed through exploits in software vulnerabilities.

PUPs like PUP.Gamehack.HDJ can be used to display unwanted advertisements, collect user data, or install additional software programs without user consent. They can also consume system resources, causing your computer to slow down or become unresponsive. It is crucial to remove PUPs from your system to prevent potential problems and maintain your computer's security and performance.

How PUP.Gamehack.HDJ Operates

PUP.Gamehack.HDJ operates by installing itself on your system and integrating with your web browser or other software programs. It may use various techniques to evade detection, such as disguising itself as a legitimate program or using code obfuscation to hide its true intentions. Once installed, it can start collecting user data, displaying unwanted advertisements, or installing additional software programs.

PUPs like PUP.Gamehack.HDJ can be challenging to detect and remove, as they often use legitimate-looking icons, names, and descriptions to blend in with other software programs. However, by monitoring your system's behavior and watching for suspicious activity, you can identify and remove PUPs like PUP.Gamehack.HDJ to maintain your computer's security and performance.

Symptoms of Infection

If your system is infected with PUP.Gamehack.HDJ, you may experience various symptoms, including unwanted advertisements, slow system performance, or suspicious program installations. You may also notice that your web browser's homepage or search engine has been changed without your consent, or that additional software programs have been installed on your system.

Other symptoms of PUP infection may include pop-up windows, browser redirects, or suspicious network activity. If you notice any of these symptoms, it is essential to take immediate action to remove the PUP and prevent further damage to your system.

How to Remove PUP.Gamehack.HDJ

  1. Boot your computer in Safe Mode with Networking to prevent the PUP from loading and interfering with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious or unwanted programs, including PUP.Gamehack.HDJ.
  3. Uninstall any suspicious programs or software that may be related to the PUP, using the "Add/Remove Programs" or "Programs and Features" control panel.
  4. Reset your web browser settings to their default values, including Chrome, Firefox, and Edge, to remove any changes made by the PUP.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the PUP has been completely removed and that no other threats are present on your system.

Conclusion

Removing PUP.Gamehack.HDJ from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above and using reputable anti-malware tools, you can effectively remove the PUP and prevent future infections. It is also essential to maintain good computing habits, such as regularly updating your software, using strong passwords, and avoiding suspicious downloads, to minimize the risk of PUP infections and maintain your computer's security and performance.

Remember, preventing PUP infections is always better than trying to remove them after they have been installed. By being cautious when downloading software and using reputable anti-malware tools, you can protect your system from potentially unwanted programs like PUP.Gamehack.HDJ and maintain your computer's security and performance.

Analysis Report

General information

Family Name: PUP.Gamehack.HDJ
Signature status: No Signature

Known Samples

MD5: 5e55d9bfbbcc88b1f28aef105f12db71
SHA1: 8dac4aef0475c4ab3e73df57adb0343c6b32b444
SHA256: DF218F83A3F99C72D2C6CD94120D8BB521483404B12B7BA75B49152B81062808
File Size: 294.40 KB, 294400 bytes
MD5: 8db30ba98f899b8fd3667bb391a54c65
SHA1: c1ef48161552afa76eefd550d721eacb460b93ce
SHA256: 443A7787EF39DE0E7AB6C1DDBFDB63C1D1EDFC3613E5D1B1EB54C675EF7A447A
File Size: 826.37 KB, 826368 bytes
MD5: 8cc7f594e6c0a646150987790e8655e5
SHA1: 312837c08ee46edd46185f7da54ea81cf94178e7
SHA256: DCB6EB101693C5101C7382D90223DE2D66B2B484D977842848A73CC2F2577340
File Size: 325.63 KB, 325632 bytes
MD5: 3675de5539bde2257285652e6608ce21
SHA1: 455cc5fb2dffd4311d83aafed820f3c7ae72ac47
SHA256: 91F5A0DF66AAEFA43AEAB11ADA63FD785E232B48EED6DCBAE4C121CD3CCAEBEF
File Size: 299.01 KB, 299008 bytes
MD5: 5fd813e60c899c7b667d9e7ac12e9058
SHA1: cc44879569ebf11610c0dedae4c6bc9ac2dee2da
SHA256: AB15B34B0CE8E93C34A55C157650BD9968DE13DF5D45F8D18C1306AFE6EDDA34
File Size: 433.66 KB, 433664 bytes
Show More
MD5: a108bff692c480773948ed76c2bf2417
SHA1: 2ea5b0d9f92921bf2d967c939d8df4c384ecb654
SHA256: 9FC38DFB2E0A95DA2B9C3AD72DEE6B526958A9E2589F28093DAD4644AE8EFDFC
File Size: 534.02 KB, 534016 bytes
MD5: a93de45e954a9cf608d9111946b2b9e6
SHA1: 64c00a6f1be4504015f5d169eea70016c5c616bd
SHA256: CE3E4DFDAF916705D1C207A3216D0678D848CD82D4D1A939321E9E04D16CC9BD
File Size: 3.16 MB, 3162494 bytes
MD5: 6a99bdabafe06ce8545a2f9dddffa09c
SHA1: 865215757d714165f008b84e98c8f923a29bb410
SHA256: F05E8298CB1287B29964CD855CFCC6083707C60F0ADDB8F2CFE539D0FD5B8B6F
File Size: 259.07 KB, 259072 bytes
MD5: 8aa8815c5375db1fe30a59fceb536630
SHA1: a6ad591179e5a586ca189a4ebdef560caa5e5096
SHA256: 5D892D6FD282C37D15A3298E6AD2045A4073B1FEC8589A65FC5D8418CA530744
File Size: 834.56 KB, 834560 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • 2+ executable sections
  • dll
  • HighEntropy
  • imgui
  • No Version Info
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 1,362
Potentially Malicious Blocks: 157
Whitelisted Blocks: 1,083
Unknown Blocks: 122

Visual Map

0 ? x 0 0 ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? ? ? 0 x 0 x 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 ? ? ? ? 0 0 0 ? ? ? ? 0 ? ? 0 ? 0 ? x 0 ? 0 ? 0 x 0 x 0 ? 0 0 ? ? 0 0 x 0 0 ? 0 0 x x 0 0 0 0 0 x x ? x x ? x x x 0 0 0 x ? 0 x x 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 ? ? ? x x ? x 0 x x x 0 0 ? ? x ? x ? ? x ? 0 ? ? x x x ? ? ? 0 0 x 0 x x ? ? ? 0 0 0 x ? ? x 0 x x ? 0 0 0 0 0 0 x 0 ? ? x ? ? ? ? ? ? x ? ? x 0 0 0 0 0 x 0 x x 0 ? x x x 0 0 x 0 x x x x x x x x x x x 0 0 0 0 x 0 0 x 0 x 0 0 0 0 x x 0 x x x 0 ? 0 x x 0 ? 0 0 x x ? ? 0 0 0 ? x ? 0 ? x x x 0 0 ? x ? ? 0 0 0 x x x x x x 0 0 x 0 0 0 x 0 0 0 0 0 0 x x x ? 0 0 x x x 0 x x 0 x 0 x x x x x x x 0 x x ? x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x x 0 0 x x 0 0 0 ? 0 ? x 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 x x x 0 ? x x ? x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 ? ? 0 x 0 0 0 0 0 0 0 x x x ? ? 0 ? 0 0 0 ? ? ? ? ? 0 x 0 0 0 0 x ? ? 0 ? ? ? 0 ? ? 0 ? x ? 0 0 0 x 0 x 0 0 x 0 0 x x x 0 ? ? 0 0 0 ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 2 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 1 0 1 2 1 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\downloads\imgui.ini Generic Write,Read Attributes
c:\windows\syswow64\tygerframework.ini Generic Write,Read Attributes
c:\windows\syswow64\tygerframeworklog.txt Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 䛬囖ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 搥瑭큎ǜ RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Keyboard Access
  • GetAsyncKeyState
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Process Terminate
  • TerminateProcess

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\c1ef48161552afa76eefd550d721eacb460b93ce_0000826368.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\312837c08ee46edd46185f7da54ea81cf94178e7_0000325632.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2ea5b0d9f92921bf2d967c939d8df4c384ecb654_0000534016.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\a6ad591179e5a586ca189a4ebdef560caa5e5096_0000834560.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...