PUP.Gamehack.CY

The detection of PUP.Gamehack.CY on your system indicates the presence of a potentially unwanted program (PUP) that may compromise your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is PUP.Gamehack.CY?

PUP.Gamehack.CY is a type of malware that is categorized as a potentially unwanted program. This means that it may not be as overtly malicious as other types of malware, such as viruses or Trojans, but it can still cause significant problems for your computer and your personal data. PUPs often sneak onto your system through bundled software downloads, infected websites, or other means, and can lead to a range of issues, including unwanted advertisements, slowed system performance, and even data breaches.

How PUP.Gamehack.CY Operates

Once installed, PUP.Gamehack.CY may operate in various ways to achieve its goals. It may display unwanted advertisements, collect your browsing data, or even install additional malware on your system. In some cases, PUPs can also hijack your browser settings, redirecting you to suspicious websites or displaying fake alerts and warnings. The primary objective of PUP.Gamehack.CY is to generate revenue for its creators, often at the expense of your computer's security and your personal privacy.

Symptoms of Infection

If your system is infected with PUP.Gamehack.CY, you may notice several symptoms. These can include unwanted pop-ups and advertisements, slowed system performance, and unfamiliar programs or toolbars installed on your browser. You may also experience suspicious redirects, fake alerts, or other unusual behavior. In some cases, you may not notice any symptoms at all, which is why regular malware scans are essential for detecting and removing threats like PUP.Gamehack.CY.

  • Unwanted advertisements and pop-ups
  • Slowed system performance
  • Unfamiliar programs or toolbars installed on your browser
  • Suspicious redirects and fake alerts

How to Remove PUP.Gamehack.CY

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware or PUPs that may be present.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed without your consent.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any hijacked settings or malicious extensions.
  5. Reboot your computer and perform a follow-up scan to ensure that the malware has been completely removed and that your system is clean.

Conclusion

Removing PUP.Gamehack.CY from your system is crucial to prevent further damage and protect your personal data. By following the steps outlined above and maintaining good cybersecurity practices, such as regularly scanning your system for malware and being cautious when downloading software or clicking on links, you can help ensure the security and integrity of your computer. Remember, prevention and prompt action are key to dealing with malware and PUPs, so stay vigilant and take the necessary steps to safeguard your digital world.

Analysis Report

General information

Family Name: PUP.Gamehack.CY
Signature status: No Signature

Known Samples

MD5: 188e0380187d99b0ea4f23ab0d59897e
SHA1: df35bd52afa214e0ecd9c31c984fa4dd004cd033
SHA256: 461CD4AA83832380E745C7560867F4009F015B4A43EA846FCE371AB0E55AA1AD
File Size: 720.90 KB, 720896 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • fptable
  • HighEntropy
  • imgui
  • No Version Info
  • x64

Block Information

Total Blocks: 1,358
Potentially Malicious Blocks: 188
Whitelisted Blocks: 1,166
Unknown Blocks: 4

Visual Map

0 x 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 x 0 0 x x x 0 0 x x x x x 0 x x 0 x 0 x 0 0 0 0 x x 0 x x 0 0 x x 0 x 0 x 1 x 0 x 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 x x 0 0 1 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x x x 0 x 0 0 0 0 x x 0 x x 0 0 x 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 x 0 0 x 0 x x 0 x 0 0 x 0 x 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 x x x 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 x x 0 0 0 0 0 x 0 x x 0 x x 0 0 x 0 0 x 0 x 0 0 0 0 0 x 0 0 x x x 0 0 0 x x 0 x x 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x x 0 0 0 0 x 0 0 x x x x x x 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 x x x x 0 0 0 0 0 ? 0 0 x 0 0 x 0 0 x 0 x 0 x 0 x 0 0 x 0 0 0 x 0 0 x 0 0 x 0 0 0 x x 0 x 0 x x 0 x x 0 x 0 0 x 0 0 0 0 x 0 0 0 x 0 0 x 0 x 0 x 0 x 0 0 x x 0 x 0 x 0 0 0 0 0 0 0 x 0 0 1 x 0 0 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 1 x 0 x x 0 x 0 x 0 0 0 0 0 0 x x x x 0 1 0 x 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 x x 0 x x x x ? x ? 0 0 x 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 2 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gamehack.CY

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::steamworker c:\users\user\downloads\df35bd52afa214e0ecd9c31c984fa4dd004cd033_0000720896 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAllocateReserveObject
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
Show More
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletionEx
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...