Crack

About “Win32/GameHack.ENT potentially unsafe” infection

Malware Removal

The Win32/GameHack.ENT potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GameHack.ENT potentially unsafe virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Authenticode signature is invalid

How to determine Win32/GameHack.ENT potentially unsafe?


File Info:

name: F9BECDDD22B581BED0E7.mlw
path: /opt/CAPEv2/storage/binaries/d55c3e253b7d87aab8c7c04c873ee30daba0e9acb86eb1a04db03fe393a6f208
crc32: 802A3AA8
md5: f9becddd22b581bed0e75d0037ae263c
sha1: bda4738a66eb89243a4fbdf13e917ca5d1ccb0f8
sha256: d55c3e253b7d87aab8c7c04c873ee30daba0e9acb86eb1a04db03fe393a6f208
sha512: fbfe7d6a564ab3b4873248277e80ec88144aaabbee6ca356195e9c94634266dc95b3619041cf9cbd5a9c45bf576cbd9c6cf44ee9a67b00ebc628ff7865148ef4
ssdeep: 384:85FQOVHHsYF6i8LiFENdyeuyEIOqyd7uT8ap/bl/rjQQd7mIjMi40d:+LFEKxJkMuT84/bl/wQd7mcMi5
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B4C23A42BBB65536F8D31276E9BA636AD63E69800F0401E3E7D8B04966347F1F87F409
sha3_384: e1c8dbc3bd2773a2b9de4b8f81e7ae3ba105963e70f7f05503fcf2d6e74c4a2398d17db972dc1cd086cba5e024c7b598
ep_bytes: e894050000e974feffff558bec6a00ff
timestamp: 2020-05-14 20:21:04

Version Info:

0: [No Data]

Win32/GameHack.ENT potentially unsafe also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Babar.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38233857
FireEyeGeneric.mg.f9becddd22b581be
ALYacTrojan.GenericKD.38233857
CylanceUnsafe
SangforTrojan.Win32.Occamy.CD5
K7AntiVirusUnwanted-Program ( 00567d061 )
K7GWUnwanted-Program ( 00567d061 )
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GameHack.ENT potentially unsafe
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.38233857
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKD.38233857 (B)
ComodoMalware@#5f7lnagcy736
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic.grp
SophosGeneric PUA LN (PUA)
WebrootW32.Trojan.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.3064F29
MicrosoftTrojan:Win32/Occamy.CD5
GDataTrojan.GenericKD.38233857
AhnLab-V3Malware/Win32.RL_Generic.R335920
McAfeeRDN/Generic.grp
MalwarebytesMalware.AI.808654828
RisingTrojan.Occamy!8.F1CD (CLOUD)
MaxSecureTrojan.Malware.101232302.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
PandaTrj/GdSda.A

How to remove Win32/GameHack.ENT potentially unsafe?

Win32/GameHack.ENT potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment