Malware

About “AdWare.Win32.Kuaiba.agm” infection

Malware Removal

The AdWare.Win32.Kuaiba.agm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Kuaiba.agm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Anomalous binary characteristics

Related domains:

www.qq5.com

How to determine AdWare.Win32.Kuaiba.agm?


File Info:

crc32: 3F3E4F24
md5: 559277c96576f9c19efa2f114bfb7fa0
name: koudaiyaoguaijin.exe
sha1: e4fb41f9bcb94bd76b10126d2141ef3d6e6cb311
sha256: 8c9ea4c946532f3cd7e1ab484389977fb1821f99622ef0955485bf0e8fff93f2
sha512: ee43814f68e220d5d77674456ee753d026803e8a7476dbc33b004d2853354f83dce3ec99faf76b832a8010a7cae2f2d3348624b2d3b3dfaf1f07ef411aad08cc
ssdeep: 98304:TX9kwZwGfUG/qBb1wohn0mb+t/lXBvsYc/Dl:BkwKGcGSZthnHwpZsYch
type: PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive

Version Info:

LegalCopyright: (C)
ProductName:
FileVersion:
FileDescription: Producer shd
Translation: 0x0804 0x04e4

AdWare.Win32.Kuaiba.agm also known as:

K7AntiVirusTrojan ( 0050b64b1 )
MicroWorld-eScanTrojan.GenericKD.4920534
CAT-QuickHealTrojan.IGENERIC
McAfeeArtemis!559277C96576
MalwarebytesTrojan.ChinAd
ZillyaTrojan.GenericKD.Win32.169624
TheHackerTrojan/.Agent.bt
BitDefenderTrojan.GenericKD.4920534
K7GWTrojan ( 0050b64b1 )
Invinceaheuristic
BaiduMulti.Threats.InArchive
NANO-AntivirusRiskware.Win32.Kuaiba.efxtnr
CyrenW32/GenBl.559277C9!Olympus
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R061C0GDI18
AvastWin32:Evo-gen [Susp]
ClamAVWin.Trojan.Ramnit-5500
Kasperskynot-a-virus:AdWare.Win32.Kuaiba.agm
Ad-AwareTrojan.GenericKD.4920534
EmsisoftTrojan.GenericKD.4920534 (B)
F-SecureTrojan.GenericKD.4920534
DrWebTrojan.DownLoader12.389
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R061C0GDI18
McAfee-GW-EditionBehavesLike.Win32.PUP.wc
SophosGeneric PUA KA (PUA)
SentinelOnestatic engine – malicious
JiangminAdware/Agent.hxi
WebrootW32.Malware.Heur
AviraADWARE/Adware.Gen7
Antiy-AVLTrojan/Win32.SGeneric
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmnot-a-virus:AdWare.Win32.Kuaiba.agm
GDataTrojan.GenericKD.4920534
VBA32AdWare.Agent
ALYacTrojan.GenericKD.4920534
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of NSIS/TrojanDropper.Agent.BT
TencentNsis.Trojan-dropper.Agent.Swba
MAXmalware (ai score=100)
FortinetW32/Agent.BT!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.96576f
CrowdStrikemalicious_confidence_60% (D)
Qihoo-360HEUR/Malware.QVM06.Gen

How to remove AdWare.Win32.Kuaiba.agm?

AdWare.Win32.Kuaiba.agm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment