PUP.Gamehack.ABB

The detection of PUP.Gamehack.ABB on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it to prevent further problems.

What Is PUP.Gamehack.ABB?

PUP.Gamehack.ABB is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems with your computer's performance, stability, and security. They can be bundled with other software, downloaded from the internet, or installed through exploits. PUPs can collect user data, display unwanted advertisements, and slow down your system.

How PUP.Gamehack.ABB Operates

PUP.Gamehack.ABB, like other PUPs, can operate in various ways to achieve its goals. It may collect user data, such as browsing history and search queries, to display targeted advertisements. It can also slow down your system by consuming system resources, such as CPU and memory. In some cases, PUPs can also install additional software or modify system settings without user consent. Understanding how PUP.Gamehack.ABB operates is crucial in removing it from your system and preventing future infections.

Symptoms of Infection

The symptoms of PUP.Gamehack.ABB infection can vary, but common signs include slow system performance, unwanted advertisements, and suspicious programs installed on your system. You may also notice that your browser settings have been modified, or your search results are being redirected to unknown websites. If you suspect that your system is infected with PUP.Gamehack.ABB, it's essential to take immediate action to remove it.

  • Unwanted advertisements and pop-ups
  • Slow system performance
  • Suspicious programs installed on your system
  • Modified browser settings
  • Redirected search results

How to Remove PUP.Gamehack.ABB

  1. Boot your system in Safe Mode with Networking to prevent PUP.Gamehack.ABB from loading and to allow for a clean removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove PUP.Gamehack.ABB and any other related malware.
  3. Uninstall any suspicious programs that may be related to PUP.Gamehack.ABB. Be cautious when uninstalling programs, as some may be legitimate.
  4. Reset your browser settings to their default values. This includes resetting Chrome, Firefox, and Edge browsers to remove any modified settings or extensions.
  5. Reboot your system and perform another scan to ensure that PUP.Gamehack.ABB has been completely removed.

Conclusion

Removing PUP.Gamehack.ABB from your system is crucial to prevent further problems and protect your personal data. By following the steps outlined above, you can ensure that your system is clean and secure. It's also essential to practice safe computing habits, such as avoiding suspicious downloads and being cautious when installing software, to prevent future infections. Remember to always use reputable anti-malware tools and keep your system and software up to date to protect against the latest threats.

Analysis Report

General information

Family Name: PUP.Gamehack.ABB
Signature status: No Signature

Known Samples

MD5: 67ada75ffda13b863907b7e4a0e09e80
SHA1: 4fad6a57e9e17e22ccf0f3c368f9ad0e62d615c4
SHA256: 29F87B06014E0303C0C77CDAAA1120EEEF641ED56B8BB23EE7337D2CB5A0FB12
File Size: 154.13 KB, 154128 bytes
MD5: e4cd05ed86308b4fd5bfd111cb57f3b3
SHA1: 23da68bc979829605cd583dd0e84e3a1cb0550dc
SHA256: 515107DDB298B4DB2A05500AFAA088638ECA3B9A3786C6C66F9DAD84CF9F0C2C
File Size: 393.22 KB, 393216 bytes
MD5: c2a0e09812c0fbf6e505364789974bf5
SHA1: 66fd80c83c718b9a69bb29613b4f336a7c1a7bfb
SHA256: 91FE45AE3A5F88A3B2D2E40909D1A8C7A62C6E4BF2F856C472CD96FD92709899
File Size: 1.18 MB, 1178112 bytes
MD5: ae5ee8b8e371ba441096bcd289a76438
SHA1: 8ecf129c3b615d26a9122ae4aed69babecbd0c1a
SHA256: 28CF829F42CC4770D39449EFDC4B11A0EC92DDE97129C0B05C91E3E4C7587E4D
File Size: 2.92 MB, 2917376 bytes
MD5: 62a2ee0a5d57f5f8fc49c83f2244690a
SHA1: a529c15d0837e522ff3166ceb659f39941e27780
SHA256: 282F1B112D73978C2449A09A91C3D18885B2DC99671189F12F5FD235A1212C6F
File Size: 790.02 KB, 790016 bytes
Show More
MD5: 5abc0cc8384ba1e1d652231d1eaff4a6
SHA1: f5babc6b9771a270feb6e697fda874b213128b1c
SHA256: 120E3A0CC817C189E23B8F5F03A6C98BAF8583912F37DCD618EF0C933AEC19FC
File Size: 153.60 KB, 153600 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • dll
  • fptable
  • GetConsoleWindow
  • imgui
  • No Version Info
  • ntdll
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 326
Potentially Malicious Blocks: 46
Whitelisted Blocks: 246
Unknown Blocks: 34

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 x x x x x ? 0 ? x 0 ? ? 0 ? ? 0 x x ? x 0 x x x ? x x ? 0 x 0 0 0 x x 0 0 ? ? ? ? ? x x 0 0 x x ? ? ? 0 ? ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 x 0 ? x x x x x x x x x ? 0 0 0 ? 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 x 0 0 0 0 0 0 x 0 x ? 0 x 0 0 x x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.KPF
  • DNSChanger.B
  • Downloader.Agent.BTF
  • Gamehack.EDD
  • Kryptik.ODFFC
Show More
  • PSWDump.C
  • Trojan.Downloader.Gen.KB

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 畻렫髪ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 憟렷髪ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ��v��� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAccessCheckByType
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
Show More
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtImpersonateAnonymousToken
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnloadDriver
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN

2 additional items are not displayed above.

Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Network Urlomon
  • URLOpenBlockingStream
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c cls
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c taskkill /f /im HTTPDebuggerUI.exe >nul 2>&1
C:\WINDOWS\system32\taskkill.exe taskkill /f /im HTTPDebuggerUI.exe
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c taskkill /f /im HTTPDebuggerSvc.exe >nul 2>&1
C:\WINDOWS\system32\taskkill.exe taskkill /f /im HTTPDebuggerSvc.exe

Related Posts

Trending

Most Viewed

Loading...