PUP.Gamehack.GADC
Your system has been detected with PUP.Gamehack.GADC, a potentially unwanted program that may pose a risk to your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it to prevent any potential harm.
Table of Contents
What Is PUP.Gamehack.GADC?
PUP.Gamehack.GADC is a type of potentially unwanted program (PUP) that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems, such as slowing down your system, displaying unwanted ads, or collecting your personal data. The "Gamehack" part of the name suggests that it may be related to gaming, but it's crucial to note that this does not necessarily mean it's a malicious program designed to harm your system.
How PUP.Gamehack.GADC Operates
PUPs like PUP.Gamehack.GADC often operate by exploiting vulnerabilities in your system or by being bundled with other software applications. They may also be installed through deceptive means, such as fake updates or free downloads. Once installed, PUPs can run in the background, consuming system resources, and potentially causing problems with your computer's performance. They may also collect your personal data, such as browsing history or search queries, and use it for advertising or other purposes.
Symptoms of Infection
If your system is infected with PUP.Gamehack.GADC, you may experience a range of symptoms, including slow system performance, unwanted ads or pop-ups, and suspicious programs running in the background. You may also notice that your browser settings have been changed, or that you are being redirected to unwanted websites. In some cases, PUPs can also cause system crashes or freezes, making it difficult to use your computer.
- Unwanted ads or pop-ups
- Suspicious programs running in the background
- Slow system performance
- Changed browser settings
- System crashes or freezes
How to Remove PUP.Gamehack.GADC
- Boot your system in Safe Mode with Networking to prevent any malicious programs from running
- Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and remove any detected threats
- Uninstall any suspicious programs or applications that you do not recognize or need
- Reset your browser settings to their default values, including Chrome, Firefox, and Edge
- Reboot your system and perform another scan to ensure that the threat has been fully removed
Conclusion
Removing PUP.Gamehack.GADC from your system is crucial to preventing any potential harm and ensuring your computer's security and performance. By following the steps outlined above, you can effectively remove this potentially unwanted program and protect your system from similar threats in the future. It's essential to remain vigilant and take proactive measures to protect your system, such as keeping your operating system and software up to date, using reputable anti-malware tools, and being cautious when downloading or installing new applications.
Analysis Report
General information
| Family Name: | PUP.Gamehack.GADC |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
d7d18fe75ba6de54b1b408778e1da4c6
SHA1:
d94aac9f0a17f027ba4ffc485b227edb75d06f5c
SHA256:
86358B9236EB5D79E853629328D68E69E4D1CAEF522FFEE32402ADBB188955FC
File Size:
945.66 KB, 945664 bytes
|
|
MD5:
5ddcce1b31fd1ef0de4584c5e8eb020d
SHA1:
ac1250c55cca92e86bacd702b42b46e6c88c3417
SHA256:
52693D70E704C3EA8C88734F24E879F626F7E8B8ED207068F80746A59B37C42B
File Size:
928.77 KB, 928768 bytes
|
|
MD5:
fd400b8e509d9d4cba5a6754814fef53
SHA1:
b48bd9f6014433ddef6f980fa43e14f649818a23
SHA256:
57CD6039804CE0ED4AA5FE32A2198259182BFE1C5B4FFCCDF1F91F397E82AF3D
File Size:
275.97 KB, 275968 bytes
|
|
MD5:
ac29659f4343323d12fa14619bd3e050
SHA1:
b94365b1c9da5e69970e9dbcf8ceecf3ba6f3645
SHA256:
7138487DC3BB4282B7FB008E170FE46BEB3290FAE4DD5E07762D7B1C5D49CFB9
File Size:
1.09 MB, 1089536 bytes
|
|
MD5:
b5d4317454fe268775d73e6922587e10
SHA1:
4c40f47709c682ad7c3d6758ba13f513efc46939
SHA256:
748C2E82046DCC2D794E76AE54C138551F68D64C6B5D14B558EB40E0A6165506
File Size:
283.65 KB, 283648 bytes
|
Show More
|
MD5:
8e7d18c33c4c144656f09857fb7d0de5
SHA1:
c666c7e3398a5b1d3ebb7e362dde0b45817d90b0
SHA256:
B957C417B8D0087D2C40F82F7F2E92E952CE7523FAD4079F0573C0CF57BA2973
File Size:
360.45 KB, 360448 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have resources
- File doesn't have security information
- File has exports table
- File has TLS information
- File is 64-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is Native application (NOT .NET application)
Show More
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Traits
- dll
- imgui
- No Version Info
- WriteProcessMemory
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 1,277 |
|---|---|
| Potentially Malicious Blocks: | 290 |
| Whitelisted Blocks: | 820 |
| Unknown Blocks: | 167 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | ὰ䏊䔶ǜ | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| Anti Debug |
|
| User Data Access |
|
| Process Terminate |
|