Trojan

Trojan-GameThief.Win32.Magania removal tips

Malware Removal

The Trojan-GameThief.Win32.Magania is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-GameThief.Win32.Magania virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates a copy of itself

How to determine Trojan-GameThief.Win32.Magania?


File Info:

name: 80F7DE2EF50ACC363428.mlw
path: /opt/CAPEv2/storage/binaries/f2607a3e39ca692ae908dd75fdf386fa60aa7965e55d415508a790e92f378809
crc32: 9F993B9F
md5: 80f7de2ef50acc3634288bc40d41e4c3
sha1: 7830eb5b7c7af0cc90f977f4f745f567e318e0cc
sha256: f2607a3e39ca692ae908dd75fdf386fa60aa7965e55d415508a790e92f378809
sha512: 0a045f617fc9ccb418a719e146edfd71d32e534fb324534e2c6e18a47bfff52a5a6660d05fce4b3fbf40e8cc758b1bc214b8456d9e7b8edfc828d45dcb6e51e3
ssdeep: 49152:IaHrmDSbN6BPPhgryjUMaxCfQvNII0Thxw:3KDSbN6BPPJDaxHF0U
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C4C5AE13F651C0B2D11C263115FB6739BA349F261A61CE93D7A4EEB96C32361A72730E
sha3_384: 596083617e92ab802ae3b9bf5a926cfcfa8aa9282b2c69e7401e2d59eae122f8d92d496f07b91bceb3a201b8bd8073e3
ep_bytes: 558bec6aff68b03e660068e83d4a0064
timestamp: 2021-11-18 11:28:35

Version Info:

FileVersion: 1.1.5.3
FileDescription: explorer.exe
ProductName: explorer.exe
ProductVersion: 1.1.5.3
CompanyName: explorer.exe
LegalCopyright: 免责声明: 本程序是辅助程序 只供学习和研究使用 请不要拿本程序去游戏中高调和宣传, 为了防止本程序泛滥使用,影响游戏的不和谐不公平,请24小时内删除本软件, 切忌严禁在游戏中使用! 本程序的使用和购买,全是您的自愿行为,一切违法犯罪行为与本程序无关, 谢谢配合。最后请大家自觉维护游戏平衡!
Comments: explorer.exe
Translation: 0x0804 0x04b0

Trojan-GameThief.Win32.Magania also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.80f7de2ef50acc36
CAT-QuickHealRisktool.Flystudio.17324
ALYacGen:Variant.Graftor.888746
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
K7GWAdware ( 004b87ea1 )
CrowdStrikewin/malicious_confidence_70% (D)
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AC potentially unwanted
APEXMalicious
ClamAVWin.Malware.Generic-9820446-0
KasperskyHEUR:Trojan-GameThief.Win32.Magania.gen
BitDefenderGen:Variant.Graftor.888746
MicroWorld-eScanGen:Variant.Graftor.888746
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Graftor.888746
EmsisoftGen:Variant.Graftor.888746 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
DrWebTrojan.DownLoader12.50768
SophosMal/Generic-S (PUA)
IkarusPUA.BlackMoon
GDataWin32.Trojan.PSE.12FI8JT
AviraTR/Taranis.2928
Antiy-AVLTrojan/Generic.ASCommon.FA
ArcabitTrojan.Graftor.DD8FAA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Unwanted/Win32.HackTool.R370840
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34084.Js0@aOAK8Alb
MAXmalware (ai score=86)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.MalPack.FlyStudio
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazosPMcfVwlW/TBMl/5kvuhq)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.ELG!tr.pws
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.ef50ac

How to remove Trojan-GameThief.Win32.Magania?

Trojan-GameThief.Win32.Magania removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment