PUP.Gamehack.GACB

The detection of PUP.Gamehack.GACB on your system indicates the presence of a potentially unwanted program (PUP) that may be causing harm or disrupting the normal functioning of your computer. It's essential to understand the nature of this threat and take immediate action to remove it to prevent further damage.

What Is PUP.Gamehack.GACB?

PUP.Gamehack.GACB is a type of malware that is classified as a potentially unwanted program. This means that it may not be as malicious as other types of malware, such as viruses or Trojans, but it can still cause problems and compromise the security of your system. PUPs are often installed unintentionally by users, usually through software bundles or by clicking on malicious links.

How PUP.Gamehack.GACB Operates

PUP.Gamehack.GACB operates by exploiting vulnerabilities in your system or by using social engineering tactics to trick you into installing it. Once installed, it can perform various malicious activities, such as displaying unwanted ads, collecting your personal data, or even installing additional malware. PUPs can also slow down your system, cause crashes, and compromise your online security.

Symptoms of Infection

The symptoms of a PUP.Gamehack.GACB infection can vary, but common signs include unwanted pop-ups, slow system performance, and unfamiliar programs or toolbars installed on your browser. You may also notice that your browser's homepage or search engine has been changed without your consent. In some cases, PUPs can also cause your system to freeze or crash frequently.

  • Unwanted ads or pop-ups
  • Slow system performance
  • Unfamiliar programs or toolbars installed on your browser
  • Changed browser settings, such as homepage or search engine
  • Frequent system crashes or freezes

How to Remove PUP.Gamehack.GACB

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove PUP.Gamehack.GACB and any other malware.
  3. Uninstall any suspicious programs or applications that you don't recognize or that were installed without your consent.
  4. Reset your browser settings, including Chrome, Firefox, and Edge, to their default values to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that the PUP has been completely removed.

Conclusion

Removing PUP.Gamehack.GACB from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above, you can help ensure that your system is free from this potentially unwanted program and any other malware that may be present. Remember to always be cautious when installing software or clicking on links, and to keep your anti-malware tool up to date to protect your system from future threats.

Analysis Report

General information

Family Name: PUP.Gamehack.GACB
Signature status: No Signature

Known Samples

MD5: 0c00473b8f32ebb5c8670d70e886e03e
SHA1: 366634c855b6a67e67f46a617ec06a0f60a6b57d
SHA256: B2E60A85E42FF2765DC65530BDE1E89A5BFCA583846F48CCEB46CBF38FCD72C9
File Size: 5.75 MB, 5745152 bytes
MD5: 0194b332e187c2f1b198daaa64bb689d
SHA1: afd64800424876874f7482df2c68c40ef76df243
SHA256: 46707385080CF9EE4B491171181DE822F5A16078E53A1267F41945D680041229
File Size: 6.13 MB, 6134784 bytes
MD5: ccf8d3da840d922ff17b64308d86d896
SHA1: 29de4a26a997013a6e35b2ab226d10102c9e6783
SHA256: 584CFA48AC7E506C24F9C67C9B2297053BCC19A55486D184093831AD84D77582
File Size: 2.96 MB, 2957313 bytes
MD5: 809e8b1c5fafa1f23917dbc888c55c6f
SHA1: 5a4531c4741f98614ad542f4af312385c4b64527
SHA256: 08B74E5DC232775BBECDB14D59FD42A2E70CD621A7F51F624E1B1EC16CAB14A1
File Size: 6.60 MB, 6597632 bytes
MD5: 121d242ce6583a6ed600a99077685c7e
SHA1: 090956cccec691f0d3a669f4d3b0e78c77a0b5ec
SHA256: 8CF206FF13242024DD9A3B12B7581893BF2D4F4F1DF1FC7D124217D08CDDA3C0
File Size: 7.80 MB, 7797760 bytes
Show More
MD5: f2371baae36b70bbd0f798bfdd7f80db
SHA1: 46a628cb7f85efa5f549178691a33978672e55c8
SHA256: AFCB4A0F1E992B05348DD05062D18E44816DB2367335F1440C4B354192378459
File Size: 3.10 MB, 3095552 bytes
MD5: 856425f9585de56c27b8d49967aa8bca
SHA1: 1d15075464a99e0a8f651d89b54d9611e6c3a455
SHA256: 51E30AFF6C64E110697BC7651038A68AFE0A31679819A1BC1C92405BFF9D2D8B
File Size: 6.06 MB, 6057472 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name N/A
File Description
  • OpenXR SteamVR Passthrough API Layer
  • SoulsyHUD
File Version
  • 0.16.9.0.0
  • 0.3.2.0
Internal Name
  • SoulsyHUD
  • XR_APILAYER_NOVENDOR_steamvr_passthrough.dll
Legal Copyright
  • Copyright (C) Rectus 2024
  • GPL-3.0 license
Original Filename XR_APILAYER_NOVENDOR_steamvr_passthrough.dll
Product Name
  • OpenXR SteamVR Passthrough API Layer
  • SoulsyHUD
Product Version
  • 0.16.9.0.0
  • 0.3.2

File Traits

  • dll
  • HighEntropy
  • imgui
  • ntdll
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 21,061
Potentially Malicious Blocks: 96
Whitelisted Blocks: 17,265
Unknown Blocks: 3,700

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 ? 0 0 ? 0 0 ? ? 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? 0 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? 0 0 ? 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 ? 0 ? 0 ? ? 0 ? 0 ? ? 0 ? 0 0 ? 0 0 ? 0 ? 0 ? ? 0 ? 0 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 0 ? 0 0 0 ? ? ? 0 ? ? ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 ? ? 0 0 ? 0 0 0 ? ? ? 0 ? ? ? ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 ? ? ? ? ? x ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 ? 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 ? 0 0 0 0 ? 0 ? 0 ? 0 0 ? 0 0 0 0 ? 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 ? ? 0 0 0 ? ? 0 ? 0 ? ? 0 ? 0 ? 0 ? ? 0 ? 0 0 0 ? 0 0 ? ? 0 0 0 0 ? ? ? 0 0 0 0 0 ? 0 0 ? ? 0 0 0 ? ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 0 ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 ? ? ? ? 0 0 0 0 ? 0 0 0 ? 0 ? ? 0 ? 0 ? 0 0 ? ? 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 ? 0 ? ? ? 0 0 0 ? ? 0 0 ? ? ? 0 0 ? ? 0 ? 0 ? ? ? ? 0 0 ? 0 0 ? ? 0 ? ? 0 0 0 ? 0 ? ? ? 0 ? 0 ? ? ? 0 ? 0 0 0 ? 0 ? 0 0 ? ? ? ? ? 0 0 ? ? ? 0 0 0 ? 0 ? 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiAnyLinkedFonts
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiComputeXformCoefficients
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateRectRgn
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiDoPalette
  • win32u.dll!NtGdiExcludeClipRect
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiExtSelectClipRgn
  • win32u.dll!NtGdiExtTextOutW
  • win32u.dll!NtGdiFontIsLinked
  • win32u.dll!NtGdiGetCharABCWidthsW
  • win32u.dll!NtGdiGetDCDword
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiGetDIBitsInternal
  • win32u.dll!NtGdiGetFontData
  • win32u.dll!NtGdiGetGlyphIndicesW
  • win32u.dll!NtGdiGetOutlineTextMetricsInternalW
  • win32u.dll!NtGdiGetRandomRgn
  • win32u.dll!NtGdiGetRealizationInfo
  • win32u.dll!NtGdiGetTextCharsetInfo
  • win32u.dll!NtGdiGetTextExtentExW

81 additional items are not displayed above.