PUP.Gamehack.DBM

The detection of PUP.Gamehack.DBM on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is PUP.Gamehack.DBM?

PUP.Gamehack.DBM is a type of malware that is classified as a potentially unwanted program. This means that it is not necessarily a virus or a Trojan, but it can still cause problems with your system and compromise your personal data. PUPs are often installed without the user's knowledge or consent, and they can be difficult to remove.

PUPs like PUP.Gamehack.DBM can be bundled with other software, such as games or freeware, and can be installed when you download and install these programs. They can also be spread through infected websites, email attachments, or infected USB drives.

How PUP.Gamehack.DBM Operates

Once installed, PUP.Gamehack.DBM can operate in various ways, including collecting your personal data, such as browsing history, search queries, and login credentials. It can also display unwanted advertisements, redirect your browser to suspicious websites, and slow down your system's performance.

PUPs can also install additional malware or software on your system, which can further compromise your security and privacy. They can also modify your system's settings, such as changing your default search engine or homepage, and can even install a rootkit to hide their presence.

Symptoms of Infection

If your system is infected with PUP.Gamehack.DBM, you may notice various symptoms, including slow system performance, unwanted advertisements, and suspicious browser behavior. You may also notice that your system is crashing or freezing frequently, or that your browser is being redirected to suspicious websites.

Other symptoms of infection may include unfamiliar programs or icons on your desktop, unusual network activity, and suspicious pop-ups or alerts. If you notice any of these symptoms, it is essential to take immediate action to remove the malware and prevent further damage.

How to Remove PUP.Gamehack.DBM

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove the malware.
  3. Uninstall any suspicious programs or software that you do not recognize or need, as they may be related to the malware.
  4. Reset your browser settings, including Chrome, Firefox, and Edge, to their default values to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a second scan to ensure that the malware has been completely removed.

Conclusion

Removing PUP.Gamehack.DBM from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above, you can effectively remove the malware and prevent further damage to your system and personal data.

It is essential to remain vigilant and to take proactive steps to protect your system from future infections, including keeping your operating system and software up to date, using reputable anti-malware tools, and avoiding suspicious websites and downloads.

Analysis Report

General information

Family Name: PUP.Gamehack.DBM
Signature status: No Signature

Known Samples

MD5: b27d5fdb5150ff4a0e23c179d411aecc
SHA1: f485f6cca921838dc8a40ecfaae06435b94f7e75
SHA256: 468D730EB969852AE1D7BEAFBF82F14A797CDF1BE6C6BF7D422E3CCC1033BFE1
File Size: 1.21 MB, 1205760 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • x86

Block Information

Total Blocks: 1,480
Potentially Malicious Blocks: 99
Whitelisted Blocks: 716
Unknown Blocks: 665

Visual Map

x 0 0 ? 0 ? ? x 0 x ? 0 ? 0 ? ? x 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 ? ? x 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 x x 0 x x x ? x x x x x x x x x x ? ? x ? 0 0 ? 0 x ? ? ? ? 0 ? 0 ? 0 0 ? ? 0 x 0 ? 0 ? ? 0 ? 0 0 x ? ? 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? x 0 ? ? 0 ? 0 0 0 ? ? ? ? 0 ? 0 0 x ? ? ? 0 ? 0 ? 0 ? ? 0 ? ? 0 x ? ? 0 ? 0 ? ? 0 ? 0 ? 0 ? ? 0 0 ? ? 0 0 ? ? ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? ? ? 0 ? ? 0 x 0 ? 0 ? 0 0 0 x x ? ? ? ? 0 0 x ? ? ? 0 ? 0 ? ? ? ? 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? x ? ? ? 0 ? ? ? 0 ? ? 0 0 ? ? ? 0 0 0 ? 0 0 ? 0 ? x ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 0 ? 0 0 0 ? 0 0 ? 0 ? ? ? ? 0 0 ? ? ? 0 ? ? ? ? 0 ? ? 0 0 0 ? 0 ? ? 0 0 ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? x 0 ? 0 ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 ? ? 0 0 ? x 0 x x 0 0 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 0 ? 0 0 0 x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 ? ? ? 0 0 0 0 0 ? ? 0 ? ? ? 0 0 0 x 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x ? 0 0 0 x 0 0 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 ? 0 x 0 x 0 x 0 0 0 0 0 ? ? x 0 x x 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 x 0 x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? x x ? ? ? ? 0 ? ? ? ? ? 0 ? 0 0 0 0 0 ? ? ? x 0 ? ? 0 ? ? 0 x 0 ? ? ? ? 0 ? ? 0 ? 0 ? x ? ? 0 ? 0 ? ? 0 ? 0 ? ? ? ? 0 ? ? ? 0 0 0 ? ? ? ? 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? 0 ? ? 0 0 ? 0 ? 0 ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? 0 ? 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 x x x x x x x ? 0 ? ? ? ? ? ? 0 0 0 ? ? ? 0 ? ? 0 ? ? ? x x 0 0 0 x ? ? ? ? 0 0 x x 0 ? 0 0 0 ? ? x ? 0 ? 0 ? ? ? 0 ? 0 ? ? 0 ? ? ? ? 0 ? 0 ? 0 ? ? x ? ? 0 ? ? ? 0 ? ? 0 ? 0 ? 0 ? ? 0 ? ? 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? 0 ? 0 ? 0 0 0 1 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? x ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? 0 ? ? 0 0 0 ? ? ? ? ? ? ? ? x ? 0 ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? 0 ? ? ? 0 ? 0 ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 0 x ? ? ? ? ? x ? 0 ? 0 ? ? ? ? x ? x 0 0 0 ? ? x 0 ? x 0 x ? ? ? ? ? ? 0 ? ? 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 x 0 ? ? ? 0 ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 x 0 0 0 0 0 0 0 0 0 x x 0 ? ? ? ? ? ? x 0 ? ? ? x 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 2 0 0 0 0 0 1 0 0 0 0 1 0 1 2 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f485f6cca921838dc8a40ecfaae06435b94f7e75_0001205760.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...