Malware

Win32/GameTool.D potentially unsafe removal guide

Malware Removal

The Win32/GameTool.D potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GameTool.D potentially unsafe virus can do?

  • Executable code extraction
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/GameTool.D potentially unsafe?


File Info:

crc32: FF16443B
md5: 806201a239d44d888084b8bd2cb8e83f
name: 806201A239D44D888084B8BD2CB8E83F.mlw
sha1: 73668e7a4f7821839853d79a13cb9ebaff310769
sha256: 2922770af40f82e30d0f28127c8d471027b61db634d05c1f4d0a17bfe68dc662
sha512: c7c8f6061ca97f1babf677ddf6aa45059cc54c147ff1f40e6c9aca76947eb29e46c208b87b6de0f31c87a5e0b5d7f3a9da0c3bc1d5892cd4ebf45e8fc3298ea5
ssdeep: 768:RZ/FqoVsBcVH5QS8m3XeVXH3+4LpoVzsT:RZ/FqasBcVHb8m+V33XLpaoT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Copyright (C) 2011 killer666
InternalName: UltimateNameChanger
FileVersion: 0.00.0003
CompanyName: killer666
ProductName: Ultimate Name Changer
ProductVersion: 0.00.0003
FileDescription: Ultimate Name Changer
OriginalFilename: UltimateNameChanger.exe

Win32/GameTool.D potentially unsafe also known as:

K7AntiVirusUnwanted-Program ( 004b98b31 )
LionicTrojan.Win32.Generic.4!c
CynetMalicious (score: 99)
CylanceUnsafe
ZillyaAdware.BrowseFox.Win32.314588
CrowdStrikewin/malicious_confidence_80% (W)
K7GWUnwanted-Program ( 004b98b31 )
Cybereasonmalicious.a4f782
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GameTool.D potentially unsafe
APEXMalicious
AvastFileRepMetagen [Malware]
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34294.fm2@ay83Mglk
McAfee-GW-EditionBehavesLike.Win32.VBObfus.nz
FireEyeGeneric.mg.806201a239d44d88
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.Agent.WT25QK
McAfeeGenericRXBS-ZD!806201A239D4
MalwarebytesHackTool.GameHack
TrendMicro-HouseCallTROJ_GEN.R002H06KK21
YandexTrojan.GenAsa!XTIqScyx/Xs
MaxSecureTrojan.Malware.73703437.susgen
FortinetRiskware/GameTool
AVGFileRepMetagen [Malware]

How to remove Win32/GameTool.D potentially unsafe?

Win32/GameTool.D potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment