Malware

MSIL/GameTool_AGen.V potentially unsafe (file analysis)

Malware Removal

The MSIL/GameTool_AGen.V potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GameTool_AGen.V potentially unsafe virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/GameTool_AGen.V potentially unsafe?


File Info:

name: 02414C6ACE7BB87D7007.mlw
path: /opt/CAPEv2/storage/binaries/6d52ad9497eebd8678d1a8eeb4c703687ef0f10dfd95cad67b687455f9106065
crc32: 95CC9691
md5: 02414c6ace7bb87d7007a850aad0a059
sha1: e3598690f303f1e180728c62fbb9471ce5157822
sha256: 6d52ad9497eebd8678d1a8eeb4c703687ef0f10dfd95cad67b687455f9106065
sha512: 8d2f98795a1fbd8c6ac3414453b16839ac7917d3a505c2abc8498856f2f21ca196b0f0685173d65367f20b55104d5f758f01189c5d5efa748b1790608fb58b37
ssdeep: 24576:ZERnjJPCuV0Y+Iay73/ZwOJM6uMCFkxjysgpnnWvylAjWZ0Xq9YLuxMfCVy:ZERnjJPCiayzi6uMekxjysgpnWvylAjI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17B35D026338C8616D16E07B7C0FB915443F2E9513A2BDB5E6DCC72ED0E123959E423AB
sha3_384: 4799bf5bb1eb1d5e5ace55d6cfd43c3d79b9c961fb176736ae65f5f884a2f9a805b30a491c8fdc7d1a0ba58f74d4f57b
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-03-31 12:14:14

Version Info:

Translation: 0x0000 0x04b0
Comments: Lineage Launcher
CompanyName: NcSoft
FileDescription: Lineage Launcher
FileVersion: 18.06.04.1001
InternalName: Launcher.exe
LegalCopyright: Copyright (C) 2017 NCSOFT
LegalTrademarks:
OriginalFilename: Launcher.exe
ProductName: Lineage Launcher Application
ProductVersion: 18.06.04.1001
Assembly Version: 18.6.4.1001

MSIL/GameTool_AGen.V potentially unsafe also known as:

LionicRiskware.Win32.Ursu.1!c
Elasticmalicious (high confidence)
ClamAVWin.Malware.Generic-6843270-0
FireEyeGeneric.mg.02414c6ace7bb87d
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
Cylanceunsafe
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaGen:NN.ZemsilF.36662.hr0@aSrt8y
CyrenW32/Trojan.DZF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GameTool_AGen.V potentially unsafe
APEXMalicious
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Suspicious PE
GoogleDetected
RisingPUA.GameTool!8.148 (CLOUD)
IkarusTrojan.Win32.Generic
MaxSecureTrojan.Malware.300983.susgen
DeepInstinctMALICIOUS

How to remove MSIL/GameTool_AGen.V potentially unsafe?

MSIL/GameTool_AGen.V potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment