PUP.GameHack.CCA

The detection of PUP.GameHack.CCA on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.GameHack.CCA?

PUP.GameHack.CCA is a type of potentially unwanted program that is designed to disrupt the normal functioning of your computer. While it may not be as malicious as other types of malware, it can still cause problems and compromise your system's security. PUPs like PUP.GameHack.CCA often sneak onto your system through bundled software downloads, infected websites, or suspicious email attachments.

How PUP.GameHack.CCA Operates

Once installed, PUP.GameHack.CCA may operate in the background, consuming system resources and potentially collecting sensitive information. It may also attempt to modify your browser settings, display unwanted advertisements, or redirect you to suspicious websites. In some cases, PUPs can also download and install additional malware or unwanted software, further compromising your system's security.

Symptoms of Infection

If your system is infected with PUP.GameHack.CCA, you may experience a range of symptoms, including slow system performance, frequent crashes, and unwanted pop-ups or advertisements. You may also notice that your browser settings have been changed or that your search results are being redirected to suspicious websites. In some cases, you may not notice any symptoms at all, which is why it's essential to regularly scan your system for malware and other threats.

  • Unwanted changes to your browser settings or homepage
  • Pop-ups or advertisements that appear unexpectedly
  • Slow system performance or frequent crashes
  • Redirected search results or suspicious website redirects

How to Remove PUP.GameHack.CCA

  1. Boot your system in Safe Mode with Networking to prevent PUP.GameHack.CCA from loading and to allow for a more effective removal process
  2. Use a reputable malware removal tool, such as SpyHunter, to perform a full scan of your system and detect and remove any malware or unwanted software
  3. Uninstall any suspicious programs or software that may be related to PUP.GameHack.CCA
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any unwanted changes or extensions
  5. Reboot your system and perform a follow-up scan to ensure that PUP.GameHack.CCA has been completely removed

Conclusion

Removing PUP.GameHack.CCA from your system requires a combination of technical expertise and caution. By following the steps outlined above and taking proactive measures to protect your system, you can help prevent future infections and keep your computer running smoothly and securely. Remember to always be cautious when downloading software or clicking on links, and to regularly scan your system for malware and other threats to ensure your computer remains safe and secure.

Analysis Report

General information

Family Name: PUP.GameHack.CCA
Signature status: No Signature

Known Samples

MD5: 0995484a5f655cc8d437336129b99cef
SHA1: 23761919b19a4be2952433763e5fa29ea8e4d6f8
SHA256: AE02766507604CB28624E70459ECEAB0BE798D4E7BBA97CECA7D23FB77EAEAF4
File Size: 826.88 KB, 826880 bytes
MD5: b17450d6f3ab2af2d135560aa34dbc07
SHA1: 2ebe2b0d79ae4a46af54b3fe79e0d86258ccd6f0
SHA256: FAC70627EAF70DBA766B062B3DABC11D31B959F5CBFA46E4E237B07F92E1376D
File Size: 338.43 KB, 338432 bytes
MD5: cd34ba1ae257e26351492ca13ff2014f
SHA1: 99127f3b1dda3942f232c1115e7774c9a61c7b8c
SHA256: 1CA0C06BE48A0EB637016AC6C86CD0B1437900DB571F8BD2C47DA00C9D163BF4
File Size: 646.66 KB, 646656 bytes
MD5: 1396b40e3b74bd4dfd5d52f66eb49a22
SHA1: ef66efe52dbbae46705334f5500c84853a162244
SHA256: 97EE7AABA503E78D08D95C09A53DB7014F5C6EA6B9698EC410F4F337BBB13593
File Size: 367.62 KB, 367616 bytes
MD5: a187b3c233e5e220b04e715646bc0e62
SHA1: 2a5276ada611d014809b9980ef464d1d51fef851
SHA256: 60331A5C90BA697A28B281D00C83C68F749860001860C936F9BD459EC98C734E
File Size: 745.47 KB, 745472 bytes
Show More
MD5: 896b7555284470573a5fbf5b24f9030e
SHA1: de8e7bd0c4ae119207d2c0b3c86a8829acb836d9
SHA256: 0B4B4ED5518C1FB3B5D52A5B9317420DAAB9FB4413C4BA0C7ECA2DF3976DC024
File Size: 674.30 KB, 674304 bytes
MD5: 4329c6e320ac6154c0dc81c7cdc5ed16
SHA1: 4ba315d870f5914399262ab352913fd666a2b016
SHA256: 9944545CF6C4361D742DBB090107D12E70DC5EC35109ECFBEA8912D2061BBA87
File Size: 504.32 KB, 504320 bytes
MD5: 7c1315d60df75afaba64b314af2e9235
SHA1: d94a4b5431c3ba8f4185a53e5b8871d402b9a57f
SHA256: 7094D2A13A35206DE3F9D2C6B142D6B0405943E216B320C0B341829CCA596691
File Size: 643.58 KB, 643584 bytes
MD5: 6c05ca3994efa99952eb097e38e3b848
SHA1: 6a55a3542844a7cffc62adca1124840c1d8cd856
SHA256: 940D9DF87D9216FCFF8DD34D8EE6E18E7F36DA3CC0F589BAF6EF0D4430B849D3
File Size: 664.06 KB, 664064 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 2,143
Potentially Malicious Blocks: 296
Whitelisted Blocks: 1,713
Unknown Blocks: 134

Visual Map

0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 ? 0 ? 0 x x ? 0 0 ? 0 0 0 ? 0 ? 0 0 ? ? ? ? ? 0 x 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 x 0 ? 0 ? 0 ? ? 0 0 0 ? 0 0 ? 0 0 x 0 0 0 0 1 0 ? 0 0 ? 0 0 ? 0 x ? 0 0 0 0 0 0 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 ? x 0 0 ? ? ? x 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? 0 0 0 ? ? 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 ? ? ? 0 0 x x x x 0 0 ? ? ? ? ? ? 0 ? 0 0 x 0 x x x 0 x ? 0 ? x x x x x x x x x x x x x ? x 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x 0 x x x 0 x 0 x x x x x x x x x x x x 0 x x 0 x x x x x x x x x 0 x ? x x ? 0 x x x x x x x x x 0 0 0 ? 0 0 0 0 0 x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x x x x x x x x 0 0 x x x x x x x x 0 ? 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 x x 0 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 x 0 0 x x 0 0 x x x x x x x x x x 0 0 0 0 0 x 0 x 0 0 x 0 0 x 0 0 x x 0 0 x x x x x x x x 0 0 0 0 0 x x 0 x x 0 0 x 0 0 x 0 0 x x 0 0 x x x x x x x x 0 0 0 0 0 x 0 x 0 0 x 0 0 x 0 0 x x 0 0 x x x x x x x x x x 0 0 0 0 0 x 0 x 0 0 x 0 0 x 0 0 x x 0 0 x x x x x x x x 0 0 0 0 0 x x 0 x x 0 0 x 0 0 x 0 0 x x 0 0 x x x x x x x x 0 0 0 0 0 x 0 x 0 0 x 0 0 x 0 0 x x 0 0 x x x x x x x x x x 0 0 0 0 0 x 0 x 0 0 x 0 0 x 0 0 x x 0 0 x x x x x x x x 0 0 0 0 0 x x 0 x x 0 0 x 0 0 x 0 0 x x 0 0 x x x x x x x x 0 0 0 0 0 x 0 x 0 0 x 0 0 x 0 0 x x 0 0 x x x x x x x x 0 0 0 0 0 x 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 ? 0 ? 0 ? 0 0 0 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 0 ? 0 ? 0 0 0 x 0 0 x x 0 x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 3 1 1 1 1 1 1 1 0 0 0 0 0 2 0 0 0 0 1 0 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 1 0 1 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\23761919b19a4be2952433763e5fa29ea8e4d6f8_0000826880.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2ebe2b0d79ae4a46af54b3fe79e0d86258ccd6f0_0000338432.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\99127f3b1dda3942f232c1115e7774c9a61c7b8c_0000646656.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\ef66efe52dbbae46705334f5500c84853a162244_0000367616.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2a5276ada611d014809b9980ef464d1d51fef851_0000745472.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\de8e7bd0c4ae119207d2c0b3c86a8829acb836d9_0000674304.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4ba315d870f5914399262ab352913fd666a2b016_0000504320.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d94a4b5431c3ba8f4185a53e5b8871d402b9a57f_0000643584.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\6a55a3542844a7cffc62adca1124840c1d8cd856_0000664064.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...