PUP.Gamehack.GSH

The detection of PUP.Gamehack.GSH on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand what this detection means and how to properly remove it to prevent any potential harm.

What Is PUP.Gamehack.GSH?

PUP.Gamehack.GSH is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as harmful as other types of malware, such as viruses or Trojans, it can still cause problems with your system and compromise your privacy. PUPs are often installed unintentionally, and they can be difficult to remove without the proper tools and guidance.

How PUP.Gamehack.GSH Operates

PUPs like PUP.Gamehack.GSH typically operate by installing themselves on your system without your knowledge or consent. They may be bundled with other software, or they may be downloaded from the internet through exploits or other means. Once installed, PUPs can collect data about your browsing habits, search history, and other personal information, which can be used for targeted advertising or other malicious purposes. They may also cause system instability, slow down your computer, and interfere with other programs.

Symptoms of Infection

If your system is infected with PUP.Gamehack.GSH, you may notice a range of symptoms, including slow system performance, unwanted pop-ups and advertisements, and changes to your browser settings. You may also notice that your system is crashing or freezing more frequently, or that your antivirus software is detecting and blocking suspicious activity. In some cases, you may not notice any symptoms at all, which is why it's essential to regularly scan your system for malware and other threats.

How to Remove PUP.Gamehack.GSH

  1. Boot your system in Safe Mode with Networking to prevent the PUP from interfering with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware or other threats.
  3. Uninstall any suspicious programs or software that may be related to the PUP.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any changes made by the PUP.
  5. Reboot your system and perform another scan to ensure that the PUP has been completely removed.

Conclusion

Removing PUP.Gamehack.GSH from your system requires careful attention to detail and the right tools. By following the steps outlined above, you can help ensure that your system is free from this potentially unwanted program and any other malware or threats. Remember to always be cautious when installing software or downloading files from the internet, and to regularly scan your system for malware to prevent future infections. With the right guidance and tools, you can keep your system safe and secure, and prevent the problems caused by PUPs like PUP.Gamehack.GSH.

Analysis Report

General information

Family Name: PUP.Gamehack.GSH
Signature status: No Signature

Known Samples

MD5: 3ac00288e0b9a19ec7414ad0ceab4f09
SHA1: 6e5b8b350447d251209c5890faee8cf631367b2e
SHA256: 8D946CF1A87459985679F2EC49BD3EE35221FA85EE52410CBC4F0CB3FE293E22
File Size: 2.60 MB, 2597376 bytes
MD5: 6f80affe61112565678224ccf827c4fe
SHA1: e8a55c491ce09e7444d8cbf7793f433d35a8975c
SHA256: 0EE45DE623C3F1F47C5F520F24195DA377E9F5CE2941B969DED5C9BC5D04FBCB
File Size: 1.49 MB, 1487360 bytes
MD5: a51a8c14ffa92b8a398168e28e7e87ef
SHA1: 02acb0f95fd26a0c4e5e45de7fe186e7cc29712d
SHA256: 909701B9792E7A72D31B9E45CD486AF97B4918C177313D5BF91275BB72AA748B
File Size: 2.93 MB, 2932736 bytes
MD5: 5d1d115798e19810bee6d855f9174f8e
SHA1: fe4092c810174f7eb8ff34f1b3a274674ee530c4
SHA256: 4A9B84565475131BEE91B32BC04935E55AD3EBCF094378FA21E659761596D090
File Size: 2.08 MB, 2077184 bytes
MD5: 615d2fd08e1942eda93632e0b3a40175
SHA1: 9a2600ad4faa0d9dd0bcec0399c811a09012a073
SHA256: FEF36CC6B15D31B2F6B8C0C12A99373BDE84F3C2DB22F551517430569762566A
File Size: 2.45 MB, 2448896 bytes
Show More
MD5: 2950de56d8dfd09e3fa0c24e8f8710f3
SHA1: ad420ddd33d2e458a0f32cd1da8c04684d6c4bb4
SHA256: 9D2BF1FEDADB19BE069159CA8103FF5D48C46EF895BA74562C42B4BF92C9031D
File Size: 3.02 MB, 3019264 bytes
MD5: f01279fb5a009b55d9b6eda69febbf7e
SHA1: 1e70cea4f1a7c59317aedbc5694f9cb5466348a6
SHA256: F8DC4AF473B89131EECBDBE1FF19E33149B22FF73FCBB035FE5BBCE0DD4BD712
File Size: 2.87 MB, 2868736 bytes
MD5: bc7672c0c7f9627cb2cc6687390ac510
SHA1: d442b87b26acfa56a66f396d6c7a8a8709514301
SHA256: B32360C462906816A6034AEE9275E49685553B344C24FDC7E0174FEBB5FDF9AF
File Size: 2.19 MB, 2185728 bytes
MD5: df4622b547abe38656ee4c60fe05507a
SHA1: 63020048f25e66fb93ac8451d66e53dcce0d83b5
SHA256: D45C6BD96A0AA695CE3971B644E5FCABD6D0A321A776AA72870804ECC46CBE30
File Size: 3.20 MB, 3198464 bytes
MD5: 70e59c729e019767dfedd9beddfba4f7
SHA1: 571ffda91732d39c69a69ce60c0dab91f111d87c
SHA256: 3DE414746FDD687B51C0704768904E8484B2730B00494B66DF23CE0316A7A2E8
File Size: 2.06 MB, 2064896 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Tsuda Kageyu
File Description
  • MinHook - The Minimalistic API Hook Library for x64/x86
  • SKSE64 plugin template using CommonLibSSE-NG
File Version
  • 2.0.0.0
  • 1.3.3.0
Internal Name
  • MinHookD
  • Modex
Legal Copyright
  • Copyright (C) 2009-2017 Tsuda Kageyu. All rights reserved.
  • Patchuli | GPL-3.0 License
Legal Trademarks Tsuda Kageyu
Product Name
  • MinHook DLL
  • Modex
Product Version
  • 2.0.0.0
  • 1.3.3.0

File Traits

  • dll
  • HighEntropy
  • imgui
  • No Version Info
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 6,709
Potentially Malicious Blocks: 314
Whitelisted Blocks: 5,722
Unknown Blocks: 673

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 1 0 0 0 1 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 ? 0 0 0 0 0 0 ? ? 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 ? 0 ? ? 0 ? 0 0 ? ? ? ? 0 ? ? ? ? 0 0 0 ? ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 ? 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 ? 0 0 ? ? 1 ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? 1 0 ? ? ? ? ? ? ? 0 0 0 0 0 ? ? ? 0 ? 0 ? 0 ? ? ? ? 0 ? 0 0 0 x ? ? ? ? 0 0 0 0 ? ? 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? 0 0 ? 0 ? ? ? ? ? ? 0 0 ? ? 0 ? 0 x ? ? 1 0 x 0 0 ? 0 0 0 ? 0 ? ? x ? ? ? 0 ? ? 0 ? 0 x 0 0 0 x ? ? ? ? ? ? 0 0 ? 0 x x ? ? ? ? 0 ? ? ? 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? 1 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? ? ? ? 0 0 0 0 ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 ? ? ? 0 0 0 ? 0 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? ? ? 0 0 0 ? ? ? 0 0 ? ? 0 ? 0 0 0 0 0 0 0 ? x ? ? 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 0 0 ? 0 ? 0 ? ? ? 0 ? 0 0 0 ? 0 ? 0 0 ? ? ? ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 1 ? ? 0 0 ? 0 0 ? ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? ? 0 ? ? ? ? 0 ? 0 ? 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? 0 0 0 0 0 0 x 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 0 ? ? ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 ? 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 1 0 0 ? ? 0 0 0 ? 0 0 0 0 ? ? ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 1 0 0 0 0 0 0 0 ? 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Downloader.Agent.BTW
  • Gamehack.CAA

Files Modified

File Attributes
c:\users\user\documents\dsy\config.json Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m �� �v����(�*�"1�1HO@V�H[uc�wk�q�P����������m��V�$�8��)�B1_�`������"A*�" RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateReserveObject
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryTimerResolution
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletionEx
  • ntdll.dll!NtSetSystemInformation
  • ntdll.dll!NtSetThreadExecutionState
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSetTimerResolution
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile

1 additional items are not displayed above.

Network Winsock2
  • WSARecvFrom
  • WSASendTo
  • WSASocket
  • WSAStartup
Network Winsock
  • bind
  • closesocket
  • connect
  • gethostbyname
  • getsockname
  • setsockopt
  • socket
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Related Posts

Trending

Most Viewed

Loading...