Crack

How to remove “Win32/GameHack.QW potentially unsafe”?

Malware Removal

The Win32/GameHack.QW potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GameHack.QW potentially unsafe virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/GameHack.QW potentially unsafe?


File Info:

name: F02488B2F487BA67A91C.mlw
path: /opt/CAPEv2/storage/binaries/f3621856ef4d534f3b6363da1d36a4225ef059ea8621b4d38b2d2aee39a98c41
crc32: 69EE9D6C
md5: f02488b2f487ba67a91cc7b766d00001
sha1: 620c522267dafd7e357940b7b12fc237988c0a25
sha256: f3621856ef4d534f3b6363da1d36a4225ef059ea8621b4d38b2d2aee39a98c41
sha512: 3a9ad319dff52359949b6cc85664986f22e35f2a18eeb903518cc331780c42682411c975d0111d386eae8478fe3c228102fe55a5eb0fa5ab7252537a6aff2960
ssdeep: 96:rpD6ILOQhuiv6ZXfAoXOtCrZQ9uARO+UtDmVthcX:rlL7hVgXfAlCrZQ9uSOjtAC
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16AC12947F2DDAB3EC7568073AB8BD012129FA66807EE53482CF8E55BA95B07903150A7
sha3_384: 629dd883a327e1e9f0f44059c0b679340e9b97c333dd48728b3690aa200f13ffe767ff2b24e58c0ade95c58734d59233
ep_bytes: 60be006040008dbe00b0ffff57eb0b90
timestamp: 2007-05-04 00:03:02

Version Info:

0: [No Data]

Win32/GameHack.QW potentially unsafe also known as:

CAT-QuickHealTrojan.IGENERICPMF.S3072800
CylanceUnsafe
SangforTrojan.Win32.Agent.Vtyd
CrowdStrikewin/grayware_confidence_90% (W)
K7GWUnwanted-Program ( 00568e2f1 )
K7AntiVirusUnwanted-Program ( 00568e2f1 )
VirITTrojan.Win32.Generic.AEJZ
CyrenW32/Injector.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/GameHack.QW potentially unsafe
APEXMalicious
McAfee-GW-EditionGenericRXFU-YU!AEE786F54F70
IkarusTrojan-Dropper.Agent
GDataWin32.Trojan.Agent.8YZZVM
WebrootW32.Malware.Gen
MicrosoftRansom:Win32/Cobra
McAfeeArtemis!F02488B2F487
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.AI.2818992360
RisingTrojan.Wacatac!8.10C01 (CLOUD)
YandexRiskware.Agent!f0fcL61EDjI
MaxSecureTrojan.Malware.1381587.susgen
FortinetRiskware/PUP
PandaPUP/Generic

How to remove Win32/GameHack.QW potentially unsafe?

Win32/GameHack.QW potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment