Malware

GameThief.1 removal tips

Malware Removal

The GameThief.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GameThief.1 virus can do?

  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the PCRat malware family
  • Detects Bochs through the presence of a registry key
  • Attempted to write directly to a physical drive
  • Creates known PcClient mutex and/or file changes.
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine GameThief.1?


File Info:

name: 5CAF3E9017EE795E7426.mlw
path: /opt/CAPEv2/storage/binaries/2cd1403b7ceeded5393461b6da154c601bcb13d9b4d099159542516249e7e100
crc32: B592E54E
md5: 5caf3e9017ee795e7426d3455712c758
sha1: bc574ab98eaa277e34f412636fcbd6850bb39c01
sha256: 2cd1403b7ceeded5393461b6da154c601bcb13d9b4d099159542516249e7e100
sha512: 2aae1c4f2683d419d6eb613dd9ea981bf1e73f2ce09c5736f0ed41fded311e0175a761b02bf3230d9705181b9b3291e1113c953f27c25fb30a6e5f753f2f2cd0
ssdeep: 3072:SPhz5C9qblUloHkRz9Vg6cBLGKip8Fk6k47WUyC5TIc:SPIoH+5IoK2Gjk4Cx2TI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6E36B00F68600FDE9A8117C14AB3776A63B6DB8866D4AD3772CFD6608B3045BF26747
sha3_384: 6167adbbe98cf1ede5c40ecc4fb087b523c1b5a50b1195ac7420116be0882dcba1bc3d5bfa12a950245048f059b8131a
ep_bytes: 558bec6aff68e020400068c019400064
timestamp: 2011-11-08 15:22:42

Version Info:

Comments:
CompanyName: Phoenix Studio
FileDescription: TheWorld Browser
FileVersion: 2, 4, 1, 7
InternalName: TheWorld
LegalCopyright: Copyright (C) 2004 - 2010
LegalTrademarks:
OriginalFilename: TheWorld.exe
PrivateBuild:
ProductName: Phoenix TheWorld
ProductVersion: 2, 4, 1, 7
SpecialBuild:
Translation: 0x0804 0x04b0

GameThief.1 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lwnv
MicroWorld-eScanGen:Variant.GameThief.1
FireEyeGeneric.mg.5caf3e9017ee795e
CAT-QuickHealBackdoor.Farfli.O
SkyhighBehavesLike.Win32.Generic.ch
ALYacGen:Variant.GameThief.1
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.GameThief.1
K7GWTrojan ( 0051a9ba1 )
K7AntiVirusTrojan ( 0051a9ba1 )
ArcabitTrojan.GameThief.1
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Farfli.AYK
APEXMalicious
ClamAVWin.Dropper.Gh0stRAT-6992317-0
KasperskyTrojan-GameThief.Win32.Magania.uakd
AlibabaTrojanDropper:Win32/Farfli.9b575d8f
NANO-AntivirusTrojan.Win32.KillProc.zrsmw
RisingBackdoor.Farfli!1.64A3 (CLASSIC)
SophosMal/Generic-S
F-SecureBackdoor.BDS/Zegost.ukva
DrWebTrojan.KillProc.13336
VIPREGen:Variant.GameThief.1
TrendMicroTROJ_FARDAM.SM
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.GameThief.1 (B)
IkarusBackdoor.Win32.FirstInj
MAXmalware (ai score=100)
JiangminTrojan/Generic.qeeb
GoogleDetected
AviraBDS/Zegost.ukva
VaristW32/Backdoor.AE.gen!Eldorado
Antiy-AVLTrojan[GameThief]/Win32.Magania
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Jorik.WMG@50lwli
MicrosoftTrojanDropper:Win32/Farfli.E
ViRobotTrojan.Win32.A.PSW-Magania.77824.J
ZoneAlarmTrojan-GameThief.Win32.Magania.uakd
GDataWin32.Trojan.PSE.CGJLAQ
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.OnlineGameHack.R3269
McAfeeGeneric Dropper.abs
TACHYONTrojan-PWS/W32.WebGame.154624.N
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Downloader
MalwarebytesFarFli.Backdoor.Bot.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FARDAM.SM
TencentMalware.Win32.Gencirc.116db60d
YandexTrojan.GenAsa!at6/Z+qeUOE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.11801483.susgen
FortinetW32/Dropper.ABS!tr
BitDefenderThetaGen:NN.ZexaE.36792.jq0@ayknMTkb
AVGWin32:Farfli-AX [Trj]
Cybereasonmalicious.98eaa2
AvastWin32:Farfli-AX [Trj]

How to remove GameThief.1?

GameThief.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment