Malware

MSIL/GameTool.CI potentially unsafe removal

Malware Removal

The MSIL/GameTool.CI potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GameTool.CI potentially unsafe virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/GameTool.CI potentially unsafe?


File Info:

name: 85EAABFD3EB895A16D82.mlw
path: /opt/CAPEv2/storage/binaries/d347044248754688973599320759edeead6cbf945c09a39330e00d8277b46998
crc32: F7BCDCEB
md5: 85eaabfd3eb895a16d820d6fc7c0027f
sha1: 18d7dd0c420bb7a794708257250b93e363cc29a4
sha256: d347044248754688973599320759edeead6cbf945c09a39330e00d8277b46998
sha512: 3fb2f92536d401bc51e44c3a989348886fdf005c33815de05a15178c8a663b45c6c2ce3e04c5e4efe46989a2583517125a6b79a148454229da21d65d526850ec
ssdeep: 24576:qh/3sjaJjRbLD5EfgZvtDe3jVtmdse7oTNcLgDOGeZ:Kh96xqseCY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10C05D00073AE4B11D6DE4EB9B46D3200D638DE165AFBD74E39AD35DD68B27028E0634B
sha3_384: 14c88f0e8ce544f5057d116f81e14c1b8dcc209ec69b32b731474de394b8f78d3d345822745c32de9d8bbbe2d38474db
ep_bytes: ff250020400000000000000000000000
timestamp: 2078-01-08 12:06:26

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Network
FileDescription: Network Graphics
FileVersion: 2.0.1.5
InternalName: Network Graphics.exe
LegalCopyright: © 2021 Network
LegalTrademarks:
OriginalFilename: Network Graphics.exe
ProductName: Graphics
ProductVersion: 2.0.1.5
Assembly Version: 2.0.1.5

MSIL/GameTool.CI potentially unsafe also known as:

LionicTrojan.MSIL.Agent.a!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeTrojan.GenericKD.37857722
CAT-QuickHealTrojan.MFC.S21584451
ALYacTrojan.GenericKD.37857722
CylanceUnsafe
ZillyaDownloader.Agent.Win32.441759
SangforTrojan.MSIL.Agent.gen
K7GWUnwanted-Program ( 0057c5411 )
K7AntiVirusUnwanted-Program ( 0057c5411 )
CyrenW32/MSIL_Troj.BAN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GameTool.CI potentially unsafe
Paloaltogeneric.ml
ClamAVWin.Packed.KryptikAGen-9938209-0
KasperskyHEUR:Trojan-Downloader.MSIL.Agent.gen
BitDefenderTrojan.GenericKD.37857722
MicroWorld-eScanTrojan.GenericKD.37857722
AvastFileRepMalware
TencentMsil.Trojan-downloader.Agent.Ecuk
EmsisoftTrojan.GenericKD.37857722 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXOO-FL!85EAABFD3EB8
SophosGeneric PUA BI (PUA)
JiangminTrojanDownloader.MSIL.abba
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-Downloader.MSIL.Agent.gen
GDataTrojan.GenericKD.37857722
AhnLab-V3Malware/Win.Generic.C4516786
McAfeeGenericRXOO-FL!85EAABFD3EB8
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:QRNn2PRatMZi0q1Yd46plg)
YandexTrojan.Igent.bVSDQy.5
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Agent.FB28!tr
AVGFileRepMalware
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.73433372.susgen

How to remove MSIL/GameTool.CI potentially unsafe?

MSIL/GameTool.CI potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment