Adware

What is “Adware.Maskit”?

Malware Removal

The Adware.Maskit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Maskit virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid

How to determine Adware.Maskit?


File Info:

name: C5508E8451FD8AE9CD03.mlw
path: /opt/CAPEv2/storage/binaries/159875ba54e18a586c754217b2f64b8b5aabd2e0017cff9c50c4a3c80b6d899b
crc32: 9F6C7721
md5: c5508e8451fd8ae9cd0378c6af549a67
sha1: eb1df4db1f39b97522a91d63558ba78ace596bf1
sha256: 159875ba54e18a586c754217b2f64b8b5aabd2e0017cff9c50c4a3c80b6d899b
sha512: 49aa30b2b8fff8a75039fa0b687ddbc6d76a7498ccc670fc433011f7368e7522c53457acba24429c90e79151536f4a97e8c0beb2b30c9f3115cf289a771d192b
ssdeep: 1536:PUlkQK25Tshw7iB6kLbehG3lJlqBwwwYgzoze83lzioQ+n9:PUlkQK25Tse66EeU3lX8wwwYmKeqlzD
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T168D35B09FA83C8F5EB2719B448DFD6BF9534BE019C129D5AEB883B56F832F4D6905018
sha3_384: ffbe75fabc5be3b8d75f918eee41c3d35a595701e49a43bccdb217bfbbcab24c67698200d8c4bd6a6823571edf586168
ep_bytes: c7057030410000000000e9a1fcffff90
timestamp: 2021-12-02 13:02:57

Version Info:

CompanyName: Kirill
FileVersion: 1.0
FileDescription: kpi_re_lab_3
InternalName: Hello Kitty
LegalCopyright: Copyright (C) 2021
LegalTrademarks:
OriginalFilename: hellokitty.exe
ProductName: Kitty
ProductVersion: 1.0
Translation: 0x0409 0x04e4

Adware.Maskit also known as:

LionicAdware.Win32.Maskit.2!c
MicroWorld-eScanTrojan.GenericKDZ.81196
FireEyeTrojan.GenericKDZ.81196
CAT-QuickHealTrojan.IGENERIC
McAfeeGenericRXQZ-AV!C5508E8451FD
CylanceUnsafe
K7AntiVirusUnwanted-Program ( 00533c1b1 )
AlibabaAdWare:Win32/ParanoidFish.7dff2c0b
K7GWUnwanted-Program ( 00533c1b1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/ParanoidFish.A potentially unsafe
Kasperskynot-a-virus:HEUR:AdWare.Win32.Maskit.gen
BitDefenderTrojan.GenericKDZ.81196
AvastFileRepMalware
Ad-AwareTrojan.GenericKDZ.81196
EmsisoftTrojan.GenericKDZ.81196 (B)
ZillyaAdware.Maskit.Win32.61
TrendMicroTROJ_GEN.R023C0WL921
McAfee-GW-EditionGenericRXQZ-AV!C5508E8451FD
SophosGeneric PUA OL (PUA)
JiangminAdWare.Maskit.ap
MAXmalware (ai score=88)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataTrojan.GenericKDZ.81196
AhnLab-V3Malware/Win.Generic.R456201
ALYacTrojan.GenericKDZ.81196
VBA32Adware.Maskit
TrendMicro-HouseCallTROJ_GEN.R023C0WL921
YandexPUA.Maskit!Ic2X+DUFXFE
MaxSecureTrojan.Malware.74485283.susgen
FortinetRiskware/ParanoidFish
AVGFileRepMalware
PandaTrj/GdSda.A

How to remove Adware.Maskit?

Adware.Maskit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment