The ToolUnlock v4 8 exe (Tencent Game Downloader) Tencent File Malware Analysis
Gridinsoft Logo
File Icon

The ToolUnlock_v4.8.exe (Tencent Game Downloader) File Analysis

Technical Analysis

File Name ToolUnlock_v4.8.exe
File Type
Win32 EXE
Magic Bytes PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
SSDEEP Hash
49152:LuKYLslB9dz1FXuPkHldIhm0H8o/qSM7K0:LH1FXuP4ldIX/qhK0
Scanner Version 1.0.224.174
Database Version 2025-09-11 09:00:56 UTC

Suspicious File Detected

Detected by 44 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
61%
Detection Rate
2,733,192
File Size (bytes)
44/72
Engines Detected
2025-09-11
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
9cbc0bad76a36fccbc8ab42a0370f9b5
SHA1
c1d4917a6c4b718b25d11a671d1b4a4bdda00fdf
SHA256
6b6fddd636e662f9e0718cf0ebea63d395ecfd412dff773d44b577d1c24f295d
SHA512
a9b1bf3963d62e2e8d335d4b59666747968aa667569ea37eac6bece7256356ba85ba06fbe8f54b2089bd66a41ebb7bc4d365eef5b95d5530c8710078ca385da9
ImpHash
d42595b695fc008ef2c56aabd8efd68e

Security Engines with Detections (44 of 72)

Bkav
W64.AIDetectMalware Malicious
Lionic
Trojan.Win32.Stealerc.1m!c Malicious
Elastic
malicious (moderate confidence) Malicious
MicroWorld-eScan
Trojan.GenericKDZ.113339 Malicious
Skyhigh
Artemis!Trojan Malicious
ALYac
Trojan.GenericKDZ.113339 Malicious
VIPRE
Trojan.GenericKDZ.113339 Malicious
Sangfor
Infostealer.Win32.Kryptik.Vwnh Malicious
K7AntiVirus
Trojan ( 005cd5021 ) Malicious
Alibaba
TrojanPSW:Win32/Stealerc.d1c5496b Malicious
K7GW
Trojan ( 005cd5021 ) Malicious
CrowdStrike
win/malicious_confidence_60% (W) Malicious
Symantec
ML.Attribute.HighConfidence Malicious
ESET-NOD32
a variant of WinGo/Kryptik.JD Malicious
TrendMicro-HouseCall
TrojanSpy.Win64.VIDAR.YXFIHZ Malicious
Paloalto
generic.ml Malicious
Kaspersky
Trojan-PSW.Win32.Stealerc.rdu Malicious
BitDefender
Trojan.GenericKDZ.113339 Malicious
Avast
Win64:Evo-gen [Trj] Malicious
Rising
Trojan.Kryptik!8.8 (CLOUD) Malicious
Emsisoft
Trojan.GenericKDZ.113339 (B) Malicious
Google
Detected Malicious
F-Secure
Trojan.TR/AVI.PWS.Agent.axzcb Malicious
TrendMicro
TrojanSpy.Win64.VIDAR.YXFIHZ Malicious
McAfeeD
ti!6B6FDDD636E6 Malicious
Trapmine
malicious.moderate.ml.score Malicious
CTX
exe.trojan.kryptik Malicious
Sophos
Mal/Generic-S Malicious
Ikarus
Trojan.Win64.Agent Malicious
GData
Trojan.GenericKDZ.113339 Malicious
Avira
TR/AVI.PWS.Agent.axzcb Malicious
Arcabit
Trojan.Generic.D1BABB Malicious
Microsoft
Trojan:Win32/Egairtigado!rfn Malicious
Cynet
Malicious (score: 99) Malicious
AhnLab-V3
Trojan/Win.Evo-gen.R721180 Malicious
Malwarebytes
Trojan.MalPack Malicious
Panda
Trj/Chgt.AD Malicious
Tencent
Win32.Trojan.LummaStealer.Ckjl Malicious
TrellixENS
Artemis!9CBC0BAD76A3 Malicious
MaxSecure
Trojan.Malware.345032208.susgen Malicious
Fortinet
W32/Kryptik.JD!tr Malicious
AVG
Win64:Evo-gen [Trj] Malicious
DeepInstinct
MALICIOUS Malicious
alibabacloud
Trojan[stealer]:Multi/Wacatac.B9nj Malicious
28 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: c2fc8ab993ffbdb912225455b9583345
Fuzzy: 483971c513317e3de8fc35081d213929
dHash: c8ce9a0b07a6f831
Image Base 0x00400000
Entry Point 0x0046f8e0
Compilation Time 1970-01-01 00:00:00
Checksum 0x0029d4f5 (Actual: 0x0029d4f5)
OS Version 6.1
PEiD Signatures PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 1 libraries
kernel32
Exports 0 functions
Resources 9 Resources
Sections 9 Sections

Version Information

CompanyName Tencent
FileDescription Tencent Game Downloader
FileVersion 1, 0, 0, 1
InternalName TGBDownloader.exe
LegalCopyright Copyright ? 2020 Tencent. All Rights Reserved.
OriginalFilename TGBDownloader.exe
ProductName Tencent Game Downloader
ProductVersion 1, 0, 0, 1
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 744,305 bytes 744,448 bytes 6.25 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_16BYTES 12A392356B083829771F83A3DA864312
.rdata 0x000b7000 1,304,840 bytes 1,305,088 bytes 6.26 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_16BYTES 056DB579FF8A674B6D85FFA7ABAFDCB4
.data 0x001f6000 354,304 bytes 55,808 bytes 3.91 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_16BYTES 26F99CA5B62875BCF59397202BE6A330
.pdata 0x0024d000 20,184 bytes 20,480 bytes 5.19 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES 3829129E50F43E12E1E7013A613ADBDD
.xdata 0x00252000 180 bytes 512 bytes 1.79 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES E66E9B1BED4745B4BE6646411E455900
.idata 0x00253000 1,342 bytes 1,536 bytes 4.01 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES 6053C6BE756E8391EC497026941A7A02
.reloc 0x00254000 17,796 bytes 17,920 bytes 5.43 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES 6D6B67606FFF4A33D4902BE63D08E355
.symtab 0x00259000 115,093 bytes 115,200 bytes 5.05 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES E61BE0DB2ED325908CABFCF933121084
.rsrc 0x00276000 459,799 bytes 460,288 bytes 7.79 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E9122C15B1A3DF20EDE08AB7A65C50DF
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 9 (459,129 bytes)
Resource Type Count Total Size Percentage
CUSTOM 2 85,830 bytes
18.7%
ZIPRES 1 360,872 bytes
78.6%
RT_ICON 1 9,640 bytes
2.1%
RT_MENU 1 80 bytes
0%
RT_STRING 1 84 bytes
0%
RT_GROUP_ICON 1 20 bytes
0%
RT_VERSION 1 828 bytes
0.2%
RT_MANIFEST 1 1,775 bytes
0.4%

Certificate Chain Analysis

Certificate Information
Product Tencent Game Downloader
Description Tencent Game Downloader
File Version 1, 0, 0, 1
Original Name TGBDownloader.exe
Internal Name TGBDownloader.exe
Copyright Copyright ? 2020 Tencent. All Rights Reserved.
Certificate Chain Summary
Symantec Time Stamping Services CA - G2 #1 Primary
Validity Period: 2012-12-21 00:00:00 → 2020-12-30 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 7E 93 EB FB 7C C6 4E 59 EA 4B 9A 77 D4 06 FC 3B
Symantec Time Stamping Services Signer - G4 #2 Chain
Validity Period: 2012-10-18 00:00:00 → 2020-12-29 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 0E CF F4 38 C8 FE BF 35 6E 04 D8 6A 98 1B 1A 50
Tencent Technology(Shenzhen) Company Limited #3 Chain
Validity Period: 2013-01-17 00:00:00 → 2016-02-16 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 71 70 BD 93 CF 3F 18 9A E6 45 2B 51 4C 49 34 0E
Tencent Technology(Shenzhen) Company Limited #4 Chain
Validity Period: 2020-11-25 00:00:00 → 2024-02-22 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 0E 33 12 30 52 5A 25 A7 F8 10 E5 34 88 B0 AA 40
DigiCert Assured ID Code Signing CA-1 #5 Chain
Validity Period: 2011-02-11 12:00:00 → 2026-02-10 12:00:00
Signature Algorithm: sha1RSA
Serial Number: 0F A8 49 06 15 D7 00 A0 BE 21 76 FD C5 EC 6D BD
DigiCert SHA2 Assured ID Code Signing CA #6 Chain
Validity Period: 2013-10-22 12:00:00 → 2028-10-22 12:00:00
Signature Algorithm: sha256RSA
Serial Number: 04 09 18 1B 5F D5 BB 66 75 53 43 B5 6F 95 50 08
Tencent Technology(Shenzhen) Company Limited #7 Chain
Validity Period: 2020-11-25 00:00:00 → 2024-02-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0E A7 F6 86 BC 40 35 4A 70 F2 C2 97 C1 31 5E F6
DigiCert Timestamp 2021 #8 Chain
Validity Period: 2021-01-01 00:00:00 → 2031-01-06 00:00:00
Signature Algorithm: sha256RSA
Serial Number: 0D 42 4A E0 BE 3A 88 FF 60 40 21 CE 14 00 F0 DD
DigiCert SHA2 Assured ID Timestamping CA #9 Chain
Validity Period: 2016-01-07 12:00:00 → 2031-01-07 12:00:00
Signature Algorithm: sha256RSA
Serial Number: 0A A1 25 D6 D6 32 1B 7E 41 E4 05 DA 36 97 C2 15

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
44 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware