PUP.Gamehack.UDA

The detection of PUP.Gamehack.UDA on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is PUP.Gamehack.UDA?

PUP.Gamehack.UDA is a type of malware that is categorized as a potentially unwanted program. This means that while it may not be as malicious as other types of malware, such as viruses or Trojans, it can still cause problems with your system and compromise your personal data. PUPs are often installed without the user's knowledge or consent, and they can be difficult to remove.

How PUP.Gamehack.UDA Operates

PUP.Gamehack.UDA, like other PUPs, operates by installing itself on your system and then executing its payload. This can include displaying unwanted advertisements, collecting personal data, and modifying system settings. PUPs can also install additional malware or unwanted software, which can further compromise your system's security. In some cases, PUPs can also be used to steal sensitive information, such as login credentials or financial data.

Symptoms of Infection

If your system is infected with PUP.Gamehack.UDA, you may notice a range of symptoms. These can include unwanted pop-ups and advertisements, slow system performance, and unexpected changes to your system settings. You may also notice that your browser homepage or search engine has been changed, or that you are being redirected to unwanted websites. In some cases, you may also experience system crashes or freezes.

  • Unwanted pop-ups and advertisements
  • Slow system performance
  • Unexpected changes to system settings
  • Changes to browser homepage or search engine
  • Redirects to unwanted websites
  • System crashes or freezes

How to Remove PUP.Gamehack.UDA

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove PUP.Gamehack.UDA and any other malware that may be present.
  3. Uninstall any suspicious programs that you have installed recently, as these may be related to the PUP infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by the malware.
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing PUP.Gamehack.UDA from your system requires a combination of technical knowledge and the right tools. By following the steps outlined above, you can help to ensure that your system is free from this potentially unwanted program and any other malware that may be present. It's also essential to take steps to prevent future infections, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when downloading and installing software from the internet.

Analysis Report

General information

Family Name: PUP.Gamehack.UDA
Signature status: No Signature

Known Samples

MD5: baffd7b0b6cdffd8dbb04af5499d58e1
SHA1: b9414e9287dea3f2978d46686d348e21fcabefe9
SHA256: 9DA9F9DBEC0814B84FF4D779F89AE040BF5C26A6B63E65474887C2E03F30C561
File Size: 2.49 MB, 2494464 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • imgui
  • x64

Block Information

Total Blocks: 3,181
Potentially Malicious Blocks: 220
Whitelisted Blocks: 2,342
Unknown Blocks: 619

Visual Map

? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? ? ? ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? 0 0 0 0 0 1 0 0 x 0 0 0 0 0 0 0 0 x ? ? 0 0 0 ? ? ? ? ? 0 0 0 ? ? 0 ? ? ? ? 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 x 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 1 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 ? x 0 0 x 0 0 0 0 0 0 ? 0 0 ? ? 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? ? 0 ? ? x 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? x ? ? 0 ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x ? ? 0 1 0 0 0 0 0 1 0 ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 ? x 0 0 0 x 0 0 x 0 0 x 0 0 x 0 0 x 0 0 ? 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x ? x ? x x 0 ? x x 0 0 ? ? 0 ? ? ? ? x ? ? x ? ? ? 0 ? ? x 0 0 1 x 0 ? 0 ? ? x 0 0 ? 0 ? ? ? ? ? ? x 0 ? ? ? ? ? 0 0 0 ? 0 ? ? x x ? 0 ? 0 ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x x ? ? ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 x ? 0 ? x x 0 x 0 0 x ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x ? 0 0 ? ? ? 0 ? 0 ? ? 0 ? ? ? ? 0 ? ? 1 ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 ? 0 0 0 0 ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? x x ? 0 ? ? ? 0 0 ? ? ? ? 0 ? 0 x ? 0 0 0 x x ? ? ? ? 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? x x ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 ? 0 0 0 0 ? 0 0 x 0 ? 0 ? x 0 x x 0 x ? ? ? ? ? ? ? ? ? ? ? x x ? 0 x x 0 ? ? ? 0 ? 0 0 ? 0 0 0 ? ? ? ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 x 0 0 0 x 0 x x x x ? ? ? ? 0 ? ? 0 ? ? ? ? ? 0 0 ? 0 0 ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? 0 0 ? ? ? 0 ? ? 0 ? ? ? 0 ? 0 0 ? ? x ? ? 0 0 ? ? ? 0 0 ? ? ? ? x 0 ? 0 ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? 0 ? 0 0 ? 0 1 ? ? ? ? ? ? x ? ? 0 x ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? 0 0 ? ? ? ? 0 0 ? 0 ? 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 1 0 ? x 0 ? 0 ? ? ? 0 ? 0 0 0 ? ? 0 0 ? ? 0 0 0 x ? ? 0 ? 1 ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? ? ? x x 0 x ? ? ? 0 ? ? ? ? 0 ? 0 0 ? 0 ? 0 ? 0 ? ? 0 0 0 0 0 1 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 x x x x x ? x x 0 0 x 0 x x x ? ? ? ? ? ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 x 0 0 0 0 0 0 0 0 0 1 0 0 ? 0 0 0 x x x ? 0 0 x 0 0 0 0 0 0 ? 0 0 ? ? 0 0 x 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? 0 ? ? ? ? x x ? 0 ? 0 ? ? ? ? ? 0 x ? ? ? 0 ? ? 0 x x ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? 0 ? 0 0 ? ? 0 ? ? 0 ? 0 ? 0 0 0 ? 0 ? 0 ? 0 0 ? 0 ? 0 ? ? ? 0 ? 0 x ? ? ? 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? 0 0 0 ? ? 0 ? ? 0 ? 0 ? ? 0 ? 0 0 ? ? 0 0 0 1 ? ? 0 0 0 1 ? ? ? ? ? 0 ? 0 0 0 0 0 1 ? 0 0 0 0 ? ? 0 ? 0 0 ? ? 0 ? ? ? ? 0 ? 0 ? ? ? 1 ? ? ? 0 ? 0 ? ? 0 ? 0 ? ? 0 ? ? x 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 x x ? 0 0 0 ? 0 0 0 ? 0 0 ? x ? x x x x 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? 0 0 0 x 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 x x 0 0 0 x x x x x x 0 0 x x x x x x x 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 x 0 x x 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 1 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
Show More
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...