Crack

About “Win32/GameHack.EPB potentially unsafe” infection

Malware Removal

The Win32/GameHack.EPB potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GameHack.EPB potentially unsafe virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Network anomalies occured during the analysis.
  • A process created a hidden window
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/GameHack.EPB potentially unsafe?


File Info:

name: 92C11BA0A1247E4C2B77.mlw
path: /opt/CAPEv2/storage/binaries/d8b695f6c72fe34c0c3b3e59db3958051e35c9b763df9ecb0760eb07ac901dd0
crc32: 7D9C2A3C
md5: 92c11ba0a1247e4c2b77e856b4d9ed0a
sha1: 00b1e192cce4955e4dfdb054e787d344871abe14
sha256: d8b695f6c72fe34c0c3b3e59db3958051e35c9b763df9ecb0760eb07ac901dd0
sha512: 6da514debf982f011437756e48c45646faf3a66e8a3b5db41f590b8b37ba26d601b96a07a1064c67f5740ead6a2e3df980f59b9cefffb7e8922984958b11b6c0
ssdeep: 49152:D32OlU3FUfBaDbo2V1hv1GXMOxTDJGwq96lDhdJa1ey4OloR2+OcqEO30R:D32rwB6XbSTDJGwxDdJyoR2ER
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T142F59C22B202412DF5E50831BBFE975B566ABEB00F44C0C7F3805EDAE5E51D1A9B325B
sha3_384: c631defb51dd422a14ac337116d8141dedd6768c33209ddd83688655dfca7df400a853d842dec960f9fec2a59f27f877
ep_bytes: e8a0040000e974feffff836104008bc1
timestamp: 2021-12-12 02:24:50

Version Info:

0: [No Data]

Win32/GameHack.EPB potentially unsafe also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47644298
FireEyeGeneric.mg.92c11ba0a1247e4c
McAfeeArtemis!92C11BA0A124
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 00568a481 )
K7GWUnwanted-Program ( 00568a481 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GameHack.EPB potentially unsafe
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.SelfDel.gen
BitDefenderTrojan.GenericKD.47644298
AvastFileRepMalware
Ad-AwareTrojan.GenericKD.47644298
EmsisoftTrojan.GenericKD.47644298 (B)
TrendMicroTROJ_GEN.R023C0RLF21
McAfee-GW-EditionBehavesLike.Win32.Generic.wh
SophosMal/Generic-R + Mal/Behav-118
GDataTrojan.GenericKD.47644298
JiangminTrojan.Selfdel.tlv
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Mamson.A!ac
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.47644298
MAXmalware (ai score=89)
VBA32BScope.Trojan.SelfDel
TrendMicro-HouseCallTROJ_GEN.R023C0RLF21
RisingTrojan.Generic@ML.84 (RDML:89kbfSV67fOWQyLuunrcTg)
YandexTrojan.SelfDel!JKKqOVl0VWA
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMalicious_Behavior.SB
AVGFileRepMalware
Cybereasonmalicious.2cce49
PandaTrj/GdSda.A

How to remove Win32/GameHack.EPB potentially unsafe?

Win32/GameHack.EPB potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment