Malware

MSIL/GameTool_AGen.J potentially unsafe removal instruction

Malware Removal

The MSIL/GameTool_AGen.J potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GameTool_AGen.J potentially unsafe virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/GameTool_AGen.J potentially unsafe?


File Info:

name: 452E288636EFAB10D8ED.mlw
path: /opt/CAPEv2/storage/binaries/e6454a6ef1d499d00f6ce41493a5005597a593312c1a5446062413bfb99ea735
crc32: 25388831
md5: 452e288636efab10d8ed07218e198cd2
sha1: 52ecdf2f44cbed64320f976b4e736be3ee529148
sha256: e6454a6ef1d499d00f6ce41493a5005597a593312c1a5446062413bfb99ea735
sha512: a494bf5cfbf9d965f0f81943ce10c758df231433adb0e88cb3102f8b4f4b1b9bef9ced7001ca2a4bdcc07e975c91d5b98bae9e22c45634bc40f0e88d1784ab2f
ssdeep: 1536:GLV/HZFGIvKXzgTtZHJqtBy3dbL3KhUtjGtv4n4fZHJqtBy3db1ZHVNtB83dbd:GLVPZofXzghtktGN6cG5tktGPtXtYz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193A39D1233D8C52DC22A0770A4F2D3793674A643F5A6CB0E8AE05D8F78B37464D666B7
sha3_384: b50ad5ceccf6ecd710146cf69ef81a9584915da277862c8e962e94a4fb615d9aeb092079fada0f6aaa04661e561e33a1
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-08-04 20:24:18

Version Info:

Translation: 0x0000 0x04b0
Comments: Cabal Prime Launcher
CompanyName: MMORPG Cabal Prime
FileDescription: Cabal Prime Launcher
FileVersion: 1.0.0.1
InternalName: cabal.exe
LegalCopyright: Copyright © MMORPG Cabal Prime 2021
LegalTrademarks: www.cabalprime.com
OriginalFilename: cabal.exe
ProductName: Cabal Prime Launcher
ProductVersion: 1.0.0.1
Assembly Version: 1.0.0.1

MSIL/GameTool_AGen.J potentially unsafe also known as:

BkavW32.AIDetectNet.01
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.MsilFC.S23224046
McAfeeArtemis!452E288636EF
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_70% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/GameTool_AGen.J potentially unsafe
APEXMalicious
KasperskyHEUR:Backdoor.MSIL.Androm.gen
McAfee-GW-EditionArtemis
IkarusBackdoor.Androm
AviraHEUR/AGEN.1247946
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.Agent.01O7PR
AhnLab-V3Malware/Win.AGEN.C5221115
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:Zvi1axIUWcO6WdLR9hKKwQ)
SentinelOneStatic AI – Suspicious PE
FortinetPossibleThreat

How to remove MSIL/GameTool_AGen.J potentially unsafe?

MSIL/GameTool_AGen.J potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment