PUP.Gamehack.UFB

The detection of PUP.Gamehack.UFB on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is PUP.Gamehack.UFB?

PUP.Gamehack.UFB is a type of malware that is classified as a potentially unwanted program. This means that it may not be as malicious as other types of malware, such as viruses or Trojans, but it can still cause problems with your system and compromise your personal data. PUPs are often installed on a system without the user's knowledge or consent, and they can be difficult to remove.

How PUP.Gamehack.UFB Operates

PUP.Gamehack.UFB, like other PUPs, can operate in various ways. It may be designed to display unwanted advertisements, collect user data, or install additional malware on the system. In some cases, PUPs can also be used to hijack user accounts, steal sensitive information, or disrupt system performance. The exact behavior of PUP.Gamehack.UFB will depend on its specific design and purpose, but it's clear that it's not a legitimate or desirable program.

Symptoms of Infection

If your system is infected with PUP.Gamehack.UFB, you may notice various symptoms. These can include unwanted pop-ups or advertisements, slow system performance, or unfamiliar programs installed on your computer. You may also notice that your browser settings have been changed, or that you're being redirected to suspicious websites. In some cases, you may not notice any symptoms at all, which is why it's essential to run regular virus scans and monitor your system for suspicious activity.

How to Remove PUP.Gamehack.UFB

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to give you a clean environment to work in.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware that may be present.
  3. Uninstall any suspicious programs that you don't recognize or that were installed without your consent. Be cautious when uninstalling programs, as some may be legitimate or required by your system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings that may have been installed.
  5. Reboot your system and run another scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing PUP.Gamehack.UFB from your system is crucial to preventing further damage and protecting your personal data. By following the steps outlined above, you can help ensure that your system is clean and secure. It's also essential to take steps to prevent future infections, such as being cautious when downloading software, avoiding suspicious links and emails, and keeping your operating system and software up to date. Remember to always use reputable anti-malware tools and to monitor your system regularly for suspicious activity to stay safe online.

Analysis Report

General information

Family Name: PUP.Gamehack.UFB
Signature status: No Signature

Known Samples

MD5: 8d9122470f652cb9d05326c61a53793f
SHA1: 1046a495db5bdf87982d01d5186f97a51a48fa63
SHA256: 15DC9A0FF085E5CADAED020C50D08F2332703CAD37BFECEAE64278F4E8D751DA
File Size: 5.09 MB, 5087744 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • imgui
  • x64

Block Information

Total Blocks: 9,994
Potentially Malicious Blocks: 234
Whitelisted Blocks: 9,567
Unknown Blocks: 193

Visual Map

0 0 0 0 0 0 0 x 0 0 x 0 0 0 ? ? 0 0 ? x 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 1 x 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? 0 0 ? ? 0 ? ? ? 0 ? ? x ? 0 ? ? 0 ? 0 0 ? ? ? x x 1 0 0 0 0 ? 0 x x x x ? 0 x ? 0 x ? 0 x x 0 0 0 x ? 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 x ? ? 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 x 0 ? 0 0 ? 0 0 x 0 x 0 x x x 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 x x 0 0 ? 0 0 x 0 ? 0 0 ? x 0 0 0 ? ? ? ? 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x ? 0 0 0 x 0 x x x ? x ? ? x ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 ? 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 x ? ? ? ? 0 0 x x ? 0 0 0 0 0 x 0 0 1 0 x 0 x 0 0 0 x 0 0 0 x 0 0 0 x x 0 0 0 0 x x 0 0 0 0 x x 0 0 0 0 0 ? 0 ? ? ? ? x x x 0 0 x x x 0 0 0 0 x ? x x x ? x ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? 0 ? ? x ? x 1 0 0 ? 0 ? 0 0 0 ? x 0 x 0 x 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x 0 ? 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 x x 0 0 1 x 0 0 0 0 0 x 0 0 0 0 x 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? x 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 x 0 0 x 0 x 0 0 1 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 x 0 x 0 0 0 0 0 0 x x 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 1 0 0 1 0 0 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 x x 0 0 0 0 0 ? x x ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 x 0 0 0 ? ? x 0 0 0 x x x x x x 0 0 x x 0 ? 0 ? x 0 ? 0 x 0 0 ? 0 0 0 x 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? ? 0 0 0 ? x 0 x ? 0 0 0 ? 0 0 0 0 0 ? x x 0 x x 0 0 x ? 0 x x x x 0 x 0 0 0 x 0 0 0 0 x x 0 x 0 0 0 0 0 0 x 0 x 0 0 0 0 ? ? 0 x x ? x ? x 0 x 0 x 0 0 ? x 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 0 x x 0 x 0 0 0 x x x x x x 0 0 x x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 x x ? 0 ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? x ? ? ? ? ? ? ? x ? x ? x ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...