Malware

About “Malware.AI.3816876094” infection

Malware Removal

The Malware.AI.3816876094 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3816876094 virus can do?

  • Injection (inter-process)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • A potential decoy document was displayed to the user
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

www.cheathappens.com

How to determine Malware.AI.3816876094?


File Info:

crc32: 848F0F01
md5: 8ef7d794d9a360bb08bf78d0aa491945
name: 8EF7D794D9A360BB08BF78D0AA491945.mlw
sha1: 127ed0a9042382453fafade5424c3c71345cbf44
sha256: dcbe0c2a8b3e98e67048abf85dfc6de84d05b1253396777c7aecbed4b4168ca4
sha512: f810804f6fac9cdc57b38b8916b7273b8908975ea19d7301dfe55b1cecd16baa6eaa9f9cb300887101c90101a65d0dd00284d1aca20065cd6eb329700cc684fe
ssdeep: 12288:9H68IDU377zL3KBTRXexGhwa7pCLXggJBV1Ls2LMpB8ac1WJBV1Ls2LMpB8aUH0h:9H68j/zI+Or7pCLwgJBV1Ls2wBPc1WJY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 1.50
ProductName: Motorsport Manager
ProductVersion: 22124
CompanyName: Cheathappens
Translation: 0x0000 0x04b0

Malware.AI.3816876094 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.20947382
FireEyeGeneric.mg.8ef7d794d9a360bb
CAT-QuickHealPUA.Gamehack.AL5
McAfeeBackDoor-EIO
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004b8e591 )
BitDefenderTrojan.Generic.20947382
K7GWTrojan ( 004b8e591 )
CrowdStrikewin/malicious_confidence_90% (D)
CyrenW32/S-cfac14f9!Eldorado
SymantecTrojan.Gen
APEXMalicious
AvastWin64:PUP-gen [PUP]
ClamAVWin.Trojan.Gamehack-6725407-0
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Generic@ML.100 (RDMK:+1zzQbZLbL8XiQKYzNDNGw)
Ad-AwareTrojan.Generic.20947382
EmsisoftTrojan.Generic.20947382 (B)
ComodoTrojWare.Win32.GameHack.DC@5qhv2d
F-SecureHeuristic.HEUR/AGEN.1112617
DrWebTrojan.Siggen8.18301
ZillyaTrojan.DotBundle.Win32.3
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosCheathappens (PUA)
IkarusPUA.HackTool.Cheatengine
JiangminTrojan.Generic.arlqd
AviraHEUR/AGEN.1112617
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D13FA1B6
SUPERAntiSpywareHack.Tool/Gen-GameHack
GDataWin32.Application.GameHack.L
CynetMalicious (score: 100)
AhnLab-V3Unwanted/Win32.GameHack.R327786
Acronissuspicious
VBA32Trojan.MSIL.Inject
ALYacTrojan.Generic.20947382
MalwarebytesMalware.AI.3816876094
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/GameHack.BFJ potentially unsafe
TencentMalware.Win32.Gencirc.10bc0d84
YandexTrojan.GenAsa!TrbYwsvDGF8
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetRiskware/CheatEngine
BitDefenderThetaGen:NN.ZexaF.34804.Du1@aSjy9Pni
AVGWin64:PUP-gen [PUP]
Cybereasonmalicious.4d9a36
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.e19

How to remove Malware.AI.3816876094?

Malware.AI.3816876094 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment