Malware

AdWare.Win32.KuwanBar.a removal

Malware Removal

The AdWare.Win32.KuwanBar.a is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.KuwanBar.a virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity contains more than one unique useragent.

Related domains:

api.pcsoft.jshhdian.com
ggstats.yb.jshhdian.com
dw.jshhdian.com
api.pcsoft.70gj.cn

How to determine AdWare.Win32.KuwanBar.a?


File Info:

crc32: D7758255
md5: 9c71734f7e0cb30e0a3e4f404c64d464
name: _______________________________24_247.exe
sha1: 68a95f9f8c2058a8ed901fabb86185a0896b1e8b
sha256: eb25ad4609aea56b3812c270792c3786c39899b6a8d62d5574f8f32124c73265
sha512: 00bc2e9ba5e065a92d000248feeacf33a52de9216e5cd8c81d1cae3f0fde0004ff43c3932fe5a52bf56eefb846e6425ffd63f7c118e8bcc8fd3427f62965af64
ssdeep: 98304:7djrfbWvOUlCnJ+I9P0ABLGejAMJ8C2IXDOXqHBQ+RSQnhj1Emq3v05hX6mx3o16:dCO0E0ABLlJfCQjqX3vU3IrftzU7
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2019
FileVersion: 3.0.1.2
ProductName: x6781x901fx4e0bx8f7dx5668
ProductVersion: 3.0.1.2
FileDescription: x6781x901fx4e0bx8f7dx5668
OriginalFilename: Install.exe
Translation: 0x0804 0x03a8

AdWare.Win32.KuwanBar.a also known as:

MicroWorld-eScanTrojan.GenericKD.42284019
CAT-QuickHealPUA.IgenericRI.S10596407
McAfeeGenericRXAA-AA!9C71734F7E0C
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0050b49d1 )
BitDefenderTrojan.GenericKD.42284019
K7GWRiskware ( 0050b49d1 )
CrowdStrikewin/malicious_confidence_80% (D)
F-ProtW32/S-d8efc1c1!Eldorado
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.42284019
Kasperskynot-a-virus:AdWare.Win32.KuwanBar.a
Endgamemalicious (moderate confidence)
F-SecurePrivacyRisk.SPR/GameTool.Gen8
ZillyaTool.YouXun.Win32.803
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.9c71734f7e0cb30e
EmsisoftTrojan.GenericKD.42284019 (B)
IkarusPUA.RiskWare.Youxun
CyrenW32/S-d8efc1c1!Eldorado
JiangminDownloader.YXdown.bz
AviraSPR/GameTool.Gen8
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=89)
Antiy-AVLRiskWare[Downloader]/Win32.YXdown
MicrosoftTrojan:Win32/Wacatac.D!ml
ArcabitTrojan.Generic.D28533F3
ZoneAlarmnot-a-virus:AdWare.Win32.KuwanBar.a
AhnLab-V3Malware/Win32.Generic.C3974891
VBA32Downloader.YXdown
ALYacTrojan.GenericKD.42284019
Ad-AwareTrojan.GenericKD.42284019
MalwarebytesRiskWare.YouXun
ESET-NOD32a variant of Win32/RiskWare.YouXun.H
RisingAdware.Downloader!1.B962 (RDMK:cmRtazqNJNepVcp8MfFXEqb69QTV)
YandexPUA.Downloader!
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.74721109.susgen
FortinetW32/GenericKD.32784984!tr
BitDefenderThetaGen:NN.ZexaF.34096.@pLfaqRCqwnj
AVGWin32:Malware-gen
Cybereasonmalicious.f8c205
Qihoo-360HEUR/QVM11.1.9BA3.Malware.Gen

How to remove AdWare.Win32.KuwanBar.a?

AdWare.Win32.KuwanBar.a removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment