PUP.Gametool.RA

Your system has been detected to have PUP.Gametool.RA, a potentially unwanted program that may cause various issues on your computer. It's essential to understand the nature of this threat and take immediate action to remove it to prevent potential harm to your system and data.

What Is PUP.Gametool.RA?

PUP.Gametool.RA is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. It can be bundled with other software or downloaded from the internet, often through deceptive means. This type of program can cause a range of problems, including slowing down your system, displaying unwanted advertisements, and potentially leading to more severe malware infections.

How PUP.Gametool.RA Operates

PUP.Gametool.RA operates by installing itself on your system and then executing its payload, which can include a range of malicious activities. It may modify system settings, create unwanted registry entries, and even communicate with remote servers to download additional malware or transmit sensitive information. This type of program can be challenging to detect and remove, as it often disguises itself as a legitimate program or hides in the background, making it difficult to identify.

Symptoms of Infection

If your system is infected with PUP.Gametool.RA, you may experience a range of symptoms, including slow system performance, unwanted pop-ups or advertisements, and unfamiliar programs or icons on your desktop. You may also notice that your browser settings have been changed, or that your system is crashing or freezing frequently. In some cases, you may not notice any symptoms at all, which is why it's essential to run regular virus scans and monitor your system's behavior closely.

  • Unwanted advertisements or pop-ups
  • Slow system performance
  • Unfamiliar programs or icons on your desktop
  • Changed browser settings
  • System crashes or freezes

How to Remove PUP.Gametool.RA

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan to detect and remove PUP.Gametool.RA and any other malware that may be present.
  3. Uninstall any suspicious programs or applications that you don't recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another scan to ensure that the malware has been completely removed.

Conclusion

Removing PUP.Gametool.RA requires careful attention to detail and a thorough understanding of the malware removal process. By following the steps outlined above, you can help to ensure that your system is completely clean and free of malware. It's also essential to take preventative measures to avoid future infections, including keeping your operating system and software up to date, using strong antivirus software, and being cautious when downloading and installing software from the internet. Remember to always prioritize your system's security and take immediate action if you suspect that your system has been infected with malware.

Analysis Report

General information

Family Name: PUP.Gametool.RA
Signature status: No Signature

Known Samples

MD5: 743c6adda3166f090bf65d8a62731cf3
SHA1: 017e28f11fc76ff0387b0899c951482dc57a57cd
SHA256: FEA9C3A478EA240FE33911C603AFFE888A819FB7F5297166D01FA1520094242D
File Size: 1.58 MB, 1580544 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description UmbraUnlockAll
File Version 1.0.0
Internal Name UmbraInjector.exe
Legal Copyright Copyright © 2020
Original Filename UmbraInjector.exe
Product Name UmbraUnlockAll
Product Version 1.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 22
Potentially Malicious Blocks: 8
Whitelisted Blocks: 14
Unknown Blocks: 0

Visual Map

0 0 x x 0 x 0 0 x x x 0 x 0 0 0 0 0 0 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gametool.RA

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Network Winsock2
  • WSASend
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • bind
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • setsockopt
Network Winhttp
  • WinHttpOpen
Encryption Used
  • BCryptOpenAlgorithmProvider

Related Posts

Trending

Most Viewed

Loading...