Malware

AdWare.Win32.GameModding.dme removal guide

Malware Removal

The AdWare.Win32.GameModding.dme is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.GameModding.dme virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Starts servers listening on 127.0.0.1:0
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • A possible heap spray exploit has been detected
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine AdWare.Win32.GameModding.dme?


File Info:

name: 1C2A9D807463DC4B8CB8.mlw
path: /opt/CAPEv2/storage/binaries/de44fc96efd7d28755c5c5f28f5ac360d5f79a0ae3b513b2fe6109718d1c5aab
crc32: 59C53B10
md5: 1c2a9d807463dc4b8cb846c29a0ef5a0
sha1: 13c068d5361a80cc8b51259ed5d4fa36af0b10aa
sha256: de44fc96efd7d28755c5c5f28f5ac360d5f79a0ae3b513b2fe6109718d1c5aab
sha512: 35cc7902cf7f63f0e6f24422122485bd05c0b13498d7fbf27473619db19c4b1e7e9843e26fa1cd862f0066c39143147b053549ea3978f218423e3eda7feecd50
ssdeep: 24576:CxGgX5StIAU2GFOZ4EvtOe+AQkGeGfLJBIbPbVitRxzmOUSCAUV4NVQ8O9NefIpR:nWA0M7Fw5zJq4jZUSCAN7QcE/fmDJo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11F952312B3C34032FA154A3AD9F580542D57BDBA19E248193FF8D64E49386CA8CBB773
sha3_384: 0aa929196086c5ee8caa37e5df62b0d2ef95c6c06bfad8ccc8f9f4180cffa71175a58efbba9ef1625b52b38b3417c280
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2016-01-15 08:22:50

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: FreeSmartSoft
FileDescription: FSS Google Books Downloader 1.9.0.6
FileVersion: 1.9.0.6
LegalCopyright: © FreeSmartSoft, 2012-2016. All rights reserved.
ProductName: FSS Google Books Downloader
ProductVersion: 1.9.0.6
Translation: 0x0000 0x04b0

AdWare.Win32.GameModding.dme also known as:

LionicAdware.Win32.GameModding.2!c
MicroWorld-eScanTrojan.GenericKD.47347488
FireEyeTrojan.GenericKD.47347488
ALYacTrojan.GenericKD.47347488
CylanceUnsafe
SangforTrojan.Win32.Occamy.CDE
AlibabaAdWare:Win32/MediaMagnet.53ecdd8e
ESET-NOD32a variant of Win32/MediaMagnet.CV potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H0CF722
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.GameModding.dme
BitDefenderTrojan.GenericKD.47347488
NANO-AntivirusRiskware.Win32.MediaMagnet.impfiv
AvastFileRepMetagen [PUP]
Ad-AwareTrojan.GenericKD.47347488
DrWebAdware.MediaMagnet.10
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftTrojan.GenericKD.47347488 (B)
APEXMalicious
AviraPUA/MediaGet.Gen
ViRobotAdware.Mediamagnet.1960951
GDataTrojan.GenericKD.47347488
McAfeeArtemis!1C2A9D807463
MAXmalware (ai score=99)
MalwarebytesMalware.AI.4274654993
TencentWin32.Adware.Gamemodding.Dygw
YandexRiskware.Agent!niYisbwelZg
FortinetRiskware/MediaMagnet
AVGFileRepMetagen [PUP]
CrowdStrikewin/grayware_confidence_100% (W)

How to remove AdWare.Win32.GameModding.dme?

AdWare.Win32.GameModding.dme removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment