PUP.Gamehack.GDDI
The detection of PUP.Gamehack.GDDI on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take prompt action to remove it and prevent further damage.
Table of Contents
What Is PUP.Gamehack.GDDI?
PUP.Gamehack.GDDI is a type of malware that is categorized as a potentially unwanted program. This means that while it may not be as malicious as other types of malware, such as viruses or trojans, it can still cause problems with your system and compromise your personal data. PUPs are often installed unintentionally, and they can be difficult to remove without the right tools and expertise.
How PUP.Gamehack.GDDI Operates
PUP.Gamehack.GDDI, like other PUPs, operates by installing itself on your system and then executing its payload. This can happen through various means, such as downloading software from untrusted sources, clicking on malicious links, or opening infected email attachments. Once installed, PUP.Gamehack.GDDI can start to cause problems, such as displaying unwanted advertisements, collecting your personal data, and slowing down your system's performance.
Symptoms of Infection
The symptoms of a PUP.Gamehack.GDDI infection can vary, but common signs include unwanted pop-ups and advertisements, slow system performance, and suspicious programs running in the background. You may also notice that your browser settings have been changed, or that you are being redirected to unfamiliar websites. If you suspect that your system has been infected with PUP.Gamehack.GDDI, it's crucial to take action quickly to prevent further damage.
- Unwanted advertisements and pop-ups
- Slow system performance
- Suspicious programs running in the background
- Changed browser settings
- Redirection to unfamiliar websites
How to Remove PUP.Gamehack.GDDI
- Boot your system in Safe Mode with Networking to prevent PUP.Gamehack.GDDI from running and interfering with the removal process.
- Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
- Uninstall any suspicious programs that were installed without your knowledge or consent.
- Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any malicious extensions or add-ons.
- Reboot your system and perform another scan to ensure that PUP.Gamehack.GDDI has been completely removed.
Conclusion
Removing PUP.Gamehack.GDDI from your system requires careful attention to detail and the right tools. By following the steps outlined above, you can help to ensure that your system is free from this potentially unwanted program and any other malicious software that may be present. Remember to always be cautious when downloading software or clicking on links, and to keep your anti-malware tools up to date to prevent future infections.
Analysis Report
General information
| Family Name: | PUP.Gamehack.GDDI |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
2f25515e4afae9f5e4bf76c31df726d9
SHA1:
8ff2fef4dd497f35df0a907f45cf98cc68095653
SHA256:
9361C89F316260D1AB3A72B4AEBF18CDD8A70287ABA4D2F1003DE1618263539A
File Size:
3.60 MB, 3601408 bytes
|
|
MD5:
155e22413435b7a8d916bc3511dbc3f3
SHA1:
ac620c7812f018d17868d10eba89b0149de20ebc
SHA256:
A8DD28464F62F1E6A1C7AB047C60123670354AB1D56A81D09ABDC8C61CF36654
File Size:
7.43 MB, 7434752 bytes
|
|
MD5:
0e89d894ff753b6863fe5e6779b616d7
SHA1:
86be507ba0527062f349fe5b10721336909db231
SHA256:
CE9906D0238F4A08F29A59258BB9DD7DD6E632158F295882FAD2D9136BB43C36
File Size:
3.71 MB, 3709952 bytes
|
|
MD5:
026264c263b79e810070a07d6b8f2ec8
SHA1:
0fbba8858165161fd32a14eb27b2b91a3bfc3f18
SHA256:
0B9727C6C93D64F085F076C4EA18EE0F11E14CC25992529C3C10B66A8F815A08
File Size:
3.40 MB, 3401216 bytes
|
|
MD5:
42fa8332e80b66c3d6c74ced64573fba
SHA1:
bcfb7c857b4bdd2e5bed0d441230aa8f717d6f68
SHA256:
542C28CF8E0CF8A693C71A880B395002EC66BCB2123C787FF6EAFBF6B7EB993F
File Size:
1.44 MB, 1443328 bytes
|
Show More
|
MD5:
09576cdc69f18132219b091301946592
SHA1:
36cfa55e3c39812bf3018e45fd7d4ab8616f4d8e
SHA256:
729B75E6A65AC1799A687E0269FA3D7ABA79299D21D9725F46CF4F62E923E663
File Size:
4.71 MB, 4706304 bytes
|
|
MD5:
4ed9ff816810413cceb3ce1a5b3cec82
SHA1:
d4564abba473c8bfda6a06b204ebf53dffdb735d
SHA256:
D2B4878C39D460FADB239AB412ADD05A4A1719A68F156AA2D5E7635B2CBA261E
File Size:
6.37 MB, 6365696 bytes
|
|
MD5:
b07895b5d75c1d01714dd56d6cd152d2
SHA1:
cd9c885cdcdfdaf4b9024eac8ff7bfa0588877e0
SHA256:
E483EBBA12114D2659E0391AC4EE1C9A7D68BCFB9E24E6A07A335DAB4A6E0E60
File Size:
6.47 MB, 6469632 bytes
|
|
MD5:
1b8689bcae05a18b335d61042e76499a
SHA1:
bf15745c9addb88f5f9b1c432fc5347df626e7e5
SHA256:
4C3E8F28787DE9ACDD9A841D180D82E2334861775AAFD18FDAB180554BE40AD2
File Size:
1.87 MB, 1866240 bytes
|
|
MD5:
c698caefdb6c62b5ddb350cdf06883db
SHA1:
c14514a59c1b4298fc5b897a5a028b6261c154ac
SHA256:
64374F2B01C1BC96BB72D72B6BEE349CB8878DF1BA9E7D6B6CC19A4BA7AC029D
File Size:
371.71 KB, 371712 bytes
|
|
MD5:
894e97070dc954efc4695b3981ae3937
SHA1:
aff39a275ab0d9fa5a120d804e9087f49e5a778b
SHA256:
44672DD2F3AFBCA77ACFC6D64A4E3C9A40AC748297C8CA13399E69BFDCA0F2CE
File Size:
3.31 MB, 3314688 bytes
|
|
MD5:
a884a0368ef2d8f9d97a1eddc357adb0
SHA1:
fbe494076c3f5ab911864dde1e23cc1362fcc8be
SHA256:
A0840F3E3AF335BF663B7C3FEE31165353CBDE7B23BB48CC0C54046B81F661DC
File Size:
6.29 MB, 6290965 bytes
|
|
MD5:
95eca22782197d0f92e6adf28f5ea147
SHA1:
b74204f1116a7def0dead19464fd5a3194892ee4
SHA256:
3A69B7D248366F63D14D89C6D0684FAA8DA04DA84FB68C6A33C045CE1C77E33F
File Size:
4.03 MB, 4029279 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have security information
- File has TLS information
- File is 64-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Comments | Free crypto library, more information available at www.cryptopp.com |
| Company Name | Crypto++® project |
| File Description |
|
| File Version |
|
| Internal Name |
|
| Legal Copyright |
|
| Legal Trademarks | Crypto++® |
| Original Filename |
|
| Product Name |
|
| Product Version |
|
File Traits
- big overlay
- dll
- fptable
- GetConsoleWindow
- HighEntropy
- imgui
- No Version Info
- ntdll
- VirtualQueryEx
- WriteProcessMemory
Show More
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 4,240 |
|---|---|
| Potentially Malicious Blocks: | 701 |
| Whitelisted Blocks: | 3,509 |
| Unknown Blocks: | 30 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Gamehack.CAB
- Gamehack.DSE
- Gamehack.EBB
- Gamehack.GAGC
- Gamehack.GDDI
Show More
- Gamehack.GSM
- Kryptik.DTE
- Kryptik.DYT
- Kryptik.NPD
- Trojan.Kryptik.Gen.DJG
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 泷蚏Ÿǝ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 쉓螨Ÿǝ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 헲Ꮳǝ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | ಿᏣǝ | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
13 additional items are not displayed above. |
| Anti Debug |
|
| User Data Access |
|
| Keyboard Access |
|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| Network Winsock2 |
|
| Network Winsock |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\WINDOWS\system32\mode.com mode con: cols=90 lines=26
|
WriteConsole: Access is denied
|