Crack

How to remove “Win32/GameHack.CLY potentially unsafe”?

Malware Removal

The Win32/GameHack.CLY potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GameHack.CLY potentially unsafe virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings

How to determine Win32/GameHack.CLY potentially unsafe?


File Info:

name: 845F407E368B0B4C1EB7.mlw
path: /opt/CAPEv2/storage/binaries/98efb27a1b77aee2dd1058ca1a5b2248dad7696f81b9d7f6af8c87793171b06c
crc32: 6388659E
md5: 845f407e368b0b4c1eb755d57e737806
sha1: cca7b896a81d56185e258e291a6dce7eec8c608d
sha256: 98efb27a1b77aee2dd1058ca1a5b2248dad7696f81b9d7f6af8c87793171b06c
sha512: f2c60dfec5dee755f2c7f3379b424a7892e88ae8eab08f8ba3c7a1543ad2638be1975535d6cf4ba1e0b6ea7e3b911adbca4ef442d1255fdab9d53ce9c259ab81
ssdeep: 12288:1vCkl1fv7+62ENgfSiOtaKKpGGW1n2N9by0/3PXAcERD8jU2kK7Jl6zygTT:1fq62E+qiOcpbGn260/3PXuekY6mi
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11E157B00F182C039D1AA20716DFCA37E4A39EC741B1954E773C85A799BF85C1FD726AA
sha3_384: 62ee465687b4a2f5ba9cd0af15a2784f5015b8a9091620944f8965343785f1955c97361e91e0419af2f39acfa30d8329
ep_bytes: e807070000e97efeffff8b4df464890d
timestamp: 2018-09-29 06:01:47

Version Info:

0: [No Data]

Win32/GameHack.CLY potentially unsafe also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865631
FireEyeGeneric.mg.845f407e368b0b4c
ALYacGen:Variant.Razy.865631
MalwarebytesRiskWare.GameHack
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 0053cc4d1 )
K7GWUnwanted-Program ( 0053cc4d1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GameHack.CLY potentially unsafe
APEXMalicious
Paloaltogeneric.ml
KasperskyHackTool.Win32.Gamehack.amfu
BitDefenderGen:Variant.Razy.865631
NANO-AntivirusTrojan.Win32.Gamehack.iwxygk
AvastFileRepMalware
Ad-AwareGen:Variant.Razy.865631
EmsisoftGen:Variant.Razy.865631 (B)
DrWebTrojan.DownLoader27.61857
ZillyaTool.GameHack.Win32.17795
TrendMicroTROJ_FRS.0NA103EP20
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosGeneric PUA MM (PUA)
SentinelOneStatic AI – Malicious PE
JiangminRiskTool.Generic.oif
Antiy-AVLTrojan/Generic.ASMalwS.2831884
GridinsoftRansom.Win32.Skeeyah.sa
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ZoneAlarmHackTool.Win32.Gamehack.amfu
GDataGen:Variant.Razy.865631
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R266435
Acronissuspicious
McAfeeGenericRXGN-TI!845F407E368B
MAXmalware (ai score=99)
VBA32BScope.Trojan.Convagent
TrendMicro-HouseCallTROJ_FRS.0NA103EP20
RisingExploit.Skeeyah!8.1282E (CLOUD)
YandexTrojan.GenAsa!CVFZsqKcKK4
IkarusTrojan.Win32.Skeeyah
FortinetRiskware/GameHack
BitDefenderThetaGen:NN.ZexaF.34212.1uW@aqA7K0ai
AVGFileRepMalware
Cybereasonmalicious.6a81d5
PandaTrj/GdSda.A

How to remove Win32/GameHack.CLY potentially unsafe?

Win32/GameHack.CLY potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment