PUP.Gamehack.HZA

The detection of PUP.Gamehack.HZA on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take immediate action to remove it to prevent further damage.

What Is PUP.Gamehack.HZA?

PUP.Gamehack.HZA is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems with your computer's performance, stability, and security. They can be bundled with other software, downloaded from the internet, or installed through exploits. PUPs can collect user data, display unwanted advertisements, and slow down system performance.

How PUP.Gamehack.HZA Operates

PUP.Gamehack.HZA, like other PUPs, operates by installing itself on your system and integrating with your web browser or other applications. It may collect user data, such as browsing history, search queries, and personal information, and transmit it to remote servers. This data can be used for targeted advertising, marketing, or other malicious purposes. PUPs can also slow down system performance by consuming system resources, such as CPU, memory, and disk space.

Symptoms of Infection

If your system is infected with PUP.Gamehack.HZA, you may experience a range of symptoms, including slow system performance, unwanted advertisements, and suspicious program installations. You may also notice that your web browser is redirected to unwanted websites, or that your search results are being hijacked. Additionally, you may see pop-ups, banners, and other types of advertisements that are not related to the websites you are visiting.

  • Unwanted advertisements and pop-ups
  • Suspicious program installations
  • Slow system performance
  • Web browser redirects and hijacking
  • Unexplained changes to system settings

How to Remove PUP.Gamehack.HZA

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for a clean removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious components related to PUP.Gamehack.HZA.
  3. Uninstall any suspicious programs or applications that may be related to the PUP.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that all components of the PUP have been removed.

Conclusion

Removing PUP.Gamehack.HZA from your system is essential to prevent further damage and protect your personal data. By following the steps outlined above, you can effectively remove this potentially unwanted program and restore your system to a safe and stable state. It is also important to practice safe computing habits, such as regularly updating your operating system and software, using reputable anti-virus software, and avoiding suspicious downloads and websites. By taking these precautions, you can reduce the risk of infection and keep your system secure.

Analysis Report

General information

Family Name: PUP.Gamehack.HZA
Signature status: No Signature

Known Samples

MD5: cfba4cc8e77cdc93f9e52a62286a8d11
SHA1: 70d603461a2af30d3fdf76f9139d91f7d8ba0599
SHA256: 2D3B10646AD011DDD6DBFD5702981EDEFE900CD3DDB710F384DA87166408EC97
File Size: 32.26 KB, 32256 bytes
MD5: bd9d5cddd6f6d8c3bdd955ad41ef75d7
SHA1: 106525639bfb2a545c4e8217975715fda6a0dd0c
SHA256: FBD2B4E7A802474CD9FC4884DC63699A72EF9F2309D38AB3A1059558731EAF02
File Size: 8.70 KB, 8704 bytes
MD5: bab957e4b067718de3594864b1de7471
SHA1: dd3e613aee38a3f3b9ae6f308b664b08f81ce223
SHA256: 392A5D29FD9059FB140CCCB61DDF28150DB6BF99BE8F89D86099A7B8DD0A3DEE
File Size: 27.14 KB, 27136 bytes
MD5: 2182f605db24508b336c9918e0d4296e
SHA1: 121efc38353d5732387ce83f1abd99762810ac77
SHA256: 3B9B6E30FD8A1DA67707EC71CEBC2404F6FBB3D65ED78BF4C703BF3594D83300
File Size: 27.14 KB, 27136 bytes
MD5: 1c1b09500cb4eb0cec6d8f805332422d
SHA1: 3f523b39fd6238d8dd54ec3abb034c183e2dcadd
SHA256: 03A82865AFA05EDDAD72C565A8345AC3DF9D6DE641BFD920AEA8AE79329BE52B
File Size: 30.21 KB, 30208 bytes
Show More
MD5: 11dfcdad5561647c577114deca1d54b5
SHA1: 8aa9dd6d76721aa0d0d3446f36c52ccf21b46533
SHA256: 40941384EF0C3548EA663B8AFA34A418EAE1E721390274D5EB0A677ACC9C1668
File Size: 8.70 KB, 8704 bytes
MD5: 34e8266726e61856499eeb7c91470b05
SHA1: 4ad3c58223e6eeb50183940599ef9baed3c3242b
SHA256: 79891AC43992D5A74E39A585A65FC034359D160FCB9628E1B858604B5ABCE49F
File Size: 8.70 KB, 8704 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 42
Potentially Malicious Blocks: 1
Whitelisted Blocks: 40
Unknown Blocks: 1

Visual Map

? x 2 0 0 1 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 2 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 䡚輕ⱌǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Terminate
  • TerminateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection
Keyboard Access
  • GetAsyncKeyState

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\70d603461a2af30d3fdf76f9139d91f7d8ba0599_0000032256.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\106525639bfb2a545c4e8217975715fda6a0dd0c_0000008704.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\dd3e613aee38a3f3b9ae6f308b664b08f81ce223_0000027136.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\121efc38353d5732387ce83f1abd99762810ac77_0000027136.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3f523b39fd6238d8dd54ec3abb034c183e2dcadd_0000030208.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8aa9dd6d76721aa0d0d3446f36c52ccf21b46533_0000008704.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4ad3c58223e6eeb50183940599ef9baed3c3242b_0000008704.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...