PUP.Gamehack.NCB
The detection of PUP.Gamehack.NCB on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.
Table of Contents
What Is PUP.Gamehack.NCB?
PUP.Gamehack.NCB is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are often bundled with other software or downloaded from untrusted sources, and they can cause a range of problems, including slowing down your computer, displaying unwanted advertisements, and potentially compromising your personal data.
How PUP.Gamehack.NCB Operates
Once installed, PUP.Gamehack.NCB may operate in the background, consuming system resources and potentially communicating with remote servers to download additional components or transmit data. It may also attempt to modify system settings, install additional software, or create unwanted shortcuts and folders. In some cases, PUPs like PUP.Gamehack.NCB may be used to distribute more malicious software, such as viruses, Trojans, or spyware.
Symptoms of Infection
If your system is infected with PUP.Gamehack.NCB, you may notice a range of symptoms, including slow system performance, unwanted pop-ups or advertisements, and unexpected changes to your system settings. You may also notice that your browser homepage or search engine has been modified, or that new toolbars or extensions have been installed. In some cases, you may receive alerts or warnings from your antivirus software or other security tools.
- Unwanted changes to system settings or browser configurations
- Slow system performance or crashes
- Unwanted pop-ups, advertisements, or browser redirects
- Unexpected installation of additional software or toolbars
How to Remove PUP.Gamehack.NCB
- Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for easier removal
- Perform a full scan of your system using a reputable antivirus tool, such as SpyHunter, to detect and remove any malicious components
- Uninstall any suspicious programs or software that may be related to the PUP
- Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any unwanted extensions or modifications
- Reboot your system and perform a follow-up scan to ensure that all components of the PUP have been removed
Conclusion
Removing PUP.Gamehack.NCB from your system requires a combination of technical expertise and caution. By following the steps outlined above and using reputable security tools, you can help to ensure that your system is free from this potentially unwanted program and any associated malware. It is also essential to take steps to prevent future infections, including being cautious when downloading software, avoiding untrusted sources, and keeping your antivirus software up to date.
Analysis Report
General information
| Family Name: | PUP.Gamehack.NCB |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
4e17820e363e352b5d953e948825a351
SHA1:
ef59917566ce949366c3cd0d20901c2972333477
SHA256:
0E9EC0F892408A44CF05C59782A0E4FCAB9A0EF75EB36F21E0165FDAD833CB57
File Size:
600.58 KB, 600576 bytes
|
|
MD5:
33b947b3e36048b7814b11708e067205
SHA1:
3e88d51da073ae3b4b480b36dbc2ab5e19d93f58
SHA256:
84DBFB8D1E96979D1A412EFBEC78D418AD9B749465F4789EA30214A6E1326620
File Size:
48.13 KB, 48128 bytes
|
|
MD5:
0dfbe44c62a76a9bfdd779b6a2102b44
SHA1:
a4c7cc75cf1364bb8ddf58675bf7faae309778cd
SHA256:
A01BD166DD3B501F278FF640ECFE58153D2006FDA3189D16EAE5A56D1CD49C52
File Size:
987.14 KB, 987136 bytes
|
|
MD5:
60cc19bca1fb01305c8d3777ed9bf793
SHA1:
3a20d86e36e19f4593b41d12375ab05fcbb85555
SHA256:
1D4B2084F15152FFB136C7A64396082C30D3AA7B14AB1EFBAF5FCE129C63AFE8
File Size:
700.93 KB, 700928 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have security information
- File has exports table
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Traits
- 2+ executable sections
- dll
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 2,062 |
|---|---|
| Potentially Malicious Blocks: | 59 |
| Whitelisted Blocks: | 1,982 |
| Unknown Blocks: | 21 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Gamehack.NCC
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\windows\syswow64\prot\log.txt | Generic Write,Read Attributes |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| Process Shell Execute |
|
| Anti Debug |
|
| Process Manipulation Evasion |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\ef59917566ce949366c3cd0d20901c2972333477_0000600576.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3e88d51da073ae3b4b480b36dbc2ab5e19d93f58_0000048128.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\a4c7cc75cf1364bb8ddf58675bf7faae309778cd_0000987136.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3a20d86e36e19f4593b41d12375ab05fcbb85555_0000700928.,LiQMAxHB
|