PUP.Gamehack.HDG

The detection of PUP.Gamehack.HDG on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it to prevent any potential harm.

What Is PUP.Gamehack.HDG?

PUP.Gamehack.HDG is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems, such as displaying unwanted advertisements, collecting user data, or modifying system settings. The "Gamehack" part of the name suggests that this PUP may be related to gaming or cheating software, which can be particularly problematic as it may compromise the integrity of online games or steal sensitive information.

How PUP.Gamehack.HDG Operates

PUPs like PUP.Gamehack.HDG often operate by exploiting vulnerabilities in software or using social engineering tactics to trick users into installing them. Once installed, they may run in the background, consuming system resources, and performing unwanted actions. In the case of PUP.Gamehack.HDG, it may be designed to interact with online games, potentially allowing cheaters to gain an unfair advantage or stealing sensitive information such as login credentials or credit card numbers.

Symptoms of Infection

Systems infected with PUP.Gamehack.HDG may exhibit a range of symptoms, including slow performance, unwanted pop-ups or advertisements, and unexpected changes to system settings. Users may also notice unusual network activity or suspicious processes running in the background. In some cases, the PUP may cause system crashes or freezes, particularly if it is interfering with other software or system components.

  • Unwanted advertisements or pop-ups
  • Slow system performance
  • Unexpected changes to system settings
  • Suspicious network activity
  • System crashes or freezes

How to Remove PUP.Gamehack.HDG

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for easier removal.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove any malicious components.
  3. Uninstall any suspicious programs or applications that may be related to the PUP.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that the PUP has been completely removed.

Conclusion

Removing PUP.Gamehack.HDG from your system is crucial to preventing any potential harm and ensuring the security and performance of your computer. By following the steps outlined above, you can effectively remove this PUP and prevent any further issues. It's also essential to practice good cybersecurity habits, such as regularly updating your software, using strong passwords, and being cautious when installing new applications, to prevent similar threats in the future.

Analysis Report

General information

Family Name: PUP.Gamehack.HDG
Signature status: Root Not Trusted

Known Samples

MD5: dd28f3c15e4b74aa5c2ab42b2d9b7d94
SHA1: 1faadf21018446fd536be403115b163a4b78795d
SHA256: FA6E6773B7E6FFEF5546589AF7F4BCF2C0D425B8B14D67BA888E98550D33D993
File Size: 340.48 KB, 340480 bytes
MD5: ca4936eabb2eb7f12354e12ac9f431d4
SHA1: dab8713a657ee5dd1a1ea15c879b8ad316a7c4d8
SHA256: F923A243D1F7CAEA5B70AA807135A30769D8F6766778394A25B4DF8B7CE7DB5D
File Size: 614.40 KB, 614400 bytes
MD5: 65e052051f2c7e212c49a9b80a44ea18
SHA1: bfcf296f4807afa3d6c6765dbbf8ed7867c948eb
SHA256: 937E77F49F7BFFF94AD0FBD79C3CE59794E2A48C82FB8116F6C6B0561126EC3D
File Size: 629.76 KB, 629760 bytes
MD5: 7b7c499685a7c44a6fbad963c6c968ec
SHA1: a3ac47214614bc74e1ee070745938779ddcc7d59
SHA256: 894909E51E2AD35A3C2D88DC9261367F865D1249CF7F17EEBD32A1FEA0F1BFA1
File Size: 2.58 MB, 2575360 bytes
MD5: 7ed9f17cc8e57e7f92b33c8ca0f5d805
SHA1: d3a3160a1cbf4daac4bcda065b2d7885194325e1
SHA256: 827BBEC9343C26C6DE1E95D2E2DC410179F8A040C94F6FE9CD1266E388DDDA25
File Size: 2.74 MB, 2735616 bytes
Show More
MD5: c94bdb44e8729bcd59f8a9020455fc72
SHA1: 6b9ce6110287cae672e5a31e2ee2ba9884a37760
SHA256: 45F4D037F99FF2DEB4F97DF40A0C013138EE939EEA5981060FF1B6F940A893F4
File Size: 1.11 MB, 1109504 bytes
MD5: aada3fdca2a4fa9d016978d54c23bf7d
SHA1: c8ee1c59b7f7e0ba6691e910474dae835cad4d78
SHA256: 7284FD1277E0B83DA342C13766C8450487284CB6731AF56BFE4EDED8A72E5C94
File Size: 314.66 KB, 314656 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Archie Workshop
File Description
  • A graphics mod for Need for Speed: Most Wanted
  • Based on crosire's brand new project.
File Version
  • 1.12.0.0
  • 1.0.0.1
Internal Name
  • AwesomeD3D8
  • SunSet.asi
Legal Copyright
  • Copyright (C) 2024 Crosire & VanitasShield
  • © 2026 No rights reserved.
Original Filename
  • AwesomeD3D8
  • SunSet.dll
Product Name
  • AwesomeD3D8
  • NFS Most Wanted - Sun Set
Product Version
  • 1.12.0.0
  • 1.0.0.1

Digital Signatures

Signer Root Status
山西荣升源科贸有限公司 DigiCert Trusted Root G4 Root Not Trusted

File Traits

  • dll
  • fptable
  • HighEntropy
  • imgui
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 1,187
Potentially Malicious Blocks: 8
Whitelisted Blocks: 1,157
Unknown Blocks: 22

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 ? ? 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 2 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 2 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 3 1 1 1 1 0 2 2 0 0 0 1 1 0 0 0 2 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gamehack.HDG

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\direct3d\mostrecentapplication::name rundll32.exe RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\1faadf21018446fd536be403115b163a4b78795d_0000340480.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\dab8713a657ee5dd1a1ea15c879b8ad316a7c4d8_0000614400.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\bfcf296f4807afa3d6c6765dbbf8ed7867c948eb_0000629760.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\a3ac47214614bc74e1ee070745938779ddcc7d59_0002575360.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d3a3160a1cbf4daac4bcda065b2d7885194325e1_0002735616.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\6b9ce6110287cae672e5a31e2ee2ba9884a37760_0001109504.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\c8ee1c59b7f7e0ba6691e910474dae835cad4d78_0000314656.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...