PUP.GameHack.HO

The detection of PUP.GameHack.HO on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is PUP.GameHack.HO?

PUP.GameHack.HO is a type of malware that is designed to provide unauthorized access to gaming-related features or cheats, but it can also exhibit behaviors that are harmful to your system. As a PUP, it may not be as malicious as other types of malware, but it can still cause problems, such as slowing down your computer, displaying unwanted advertisements, or collecting your personal data without your consent.

How PUP.GameHack.HO Operates

PUPs like PUP.GameHack.HO often operate by exploiting vulnerabilities in software or by tricking users into installing them. They can be bundled with other programs or downloaded from untrusted sources. Once installed, they can run in the background, consuming system resources and potentially allowing unauthorized access to your computer. In some cases, PUPs can also be used to distribute more severe types of malware, making it crucial to remove them as soon as possible.

Symptoms of Infection

If your system is infected with PUP.GameHack.HO, you may notice several symptoms, including slower performance, increased pop-up advertisements, or unfamiliar programs running in the background. You might also experience issues with your web browser, such as changed homepage settings or suspicious toolbars. Additionally, you may notice that your computer is behaving erratically, such as crashing or freezing frequently.

  • Unwanted changes to your browser settings or homepage
  • Pop-up advertisements or suspicious links
  • Slow system performance or frequent crashes
  • Unfamiliar programs or processes running in the background

How to Remove PUP.GameHack.HO

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or applications that you don't recognize or that were installed without your consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing PUP.GameHack.HO from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above, you can effectively remove this potentially unwanted program and prevent further damage to your computer. It's essential to remain vigilant and to regularly scan your system for any signs of malware or other security threats. By taking proactive steps to protect your computer, you can ensure a safer and more secure online experience.

Analysis Report

General information

Family Name: PUP.GameHack.HO
Signature status: No Signature

Known Samples

MD5: fa68a2cce7f665ceafb9427d5fc8beb5
SHA1: 36532b255d656916f5742733b24a8550b5feaebf
SHA256: 97426DB35AAF8B599AF42EAAB7FC15CDEB59694750995ED8E97D0091E78D930A
File Size: 171.01 KB, 171008 bytes
MD5: d1c0b1dbf0bfb52108f579b09f27e681
SHA1: 2cdf7e03159921268876e5f8013f70f10003a83b
SHA256: E16A1BA9F9D46736E0F3C90FF55EA31C0B33703B8D63153239800FE3E068FD8C
File Size: 9.23 MB, 9229154 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • fErBl@
  • ThornLabs, LLC ©
File Description
  • 7z Self-Extract Setup
  • Quickly opens remove hardware menu in windows
File Version
  • 4, 14, 0, 0
  • 1. 2. 3. 4
Internal Name
  • 7zS.sfx
  • EjectOr
Legal Copyright
  • Copyright (C) 1999-2005 Igor Pavlov
  • Freeware
Original Filename 7zS.sfx
Product Name
  • 7-Zip
  • USB EjectOr
Product Version
  • 4, 14, 0, 0
  • 1. 2. 3. 4

File Traits

  • No Version Info
  • x86

Block Information

Similar Families

  • Injector.XN

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsb1d5.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsb1d5.tmp\burnaware_free.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsb1d5.tmp\burnaware_free.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsb1d5.tmp\install.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsb1d5.tmp\install.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\is-3b761.tmp\_isetup\_regdll.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-3b761.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-3b761.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-3b761.tmp\ask_2.bmp Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\is-3b761.tmp\ask_eula.rtf Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3b761.tmp\askinstallchecker.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3b761.tmp\asktoolbarinstaller-1.3.1.0.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-9tefj.tmp\burnaware_free.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~b669.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~b669.cmd Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 牂씒ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 씒씒ǜ RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
Show More
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Terminate
  • TerminateProcess

Shell Command Execution

.\install.exe
cmd.exe /c C:\Users\Kvkgdjeh\AppData\Local\Temp\~B669.cmd .\install.exe
WriteConsole:
WriteConsole: C:\Users\Kvkgdje
WriteConsole: burnaware_free.e
Show More
WriteConsole: /verysilent
C:\Users\Kvkgdjeh\AppData\Local\Temp\7zSB1D5.tmp\burnaware_free.exe burnaware_free.exe /verysilent
"C:\Users\Kvkgdjeh\AppData\Local\Temp\is-9TEFJ.tmp\burnaware_free.tmp" /SL5="$A0302,8621937,121856,C:\Users\Kvkgdjeh\AppData\Local\Temp\7zSB1D5.tmp\burnaware_free.exe" /verysilent
"C:\Users\Kvkgdjeh\AppData\Local\Temp\is-3B761.tmp\AskInstallChecker.exe"

Related Posts

Trending

Most Viewed

Loading...