Adware

About “Adware:Win32/Kuaiba.A” infection

Malware Removal

The Adware:Win32/Kuaiba.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:Win32/Kuaiba.A virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
css.jipinfeiche.cn

How to determine Adware:Win32/Kuaiba.A?


File Info:

crc32: A8E090B3
md5: b1e9ebc29364587c7b11304161b2d80e
name: lvjuren2.exe
sha1: e2141d3de4e5662d4bbf4ed502a155fc098b27d0
sha256: 9eab4ee7ac69bcf9e43ebc651cf05de74414a66619d19bf733d3e70ce52ea636
sha512: de35cac1a205895eb3f6747a5310f113308c82e37ef8658d37130a269eef0451e78efe5b33fe71abea1d7b749ff448bcdc482f04dac4a403f0cebf59b1b8798b
ssdeep: 196608:tIQb3kX+EJ025Irmh+7K8/+ZIoW/sqfiIQb3kX+EJ025Irmh+7K8/+ZIoW/sqhz0:tIQb3kuES25Irmh+7K8/+ZIoW/sqfiIx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2015
InternalName: x6e38x620fx5b89x88c5x7a0bx5e8f
FileVersion: 1, 0, 0, 2
ProductName: x6e38x620fx5b89x88c5x7a0bx5e8f
ProductVersion: 1, 0, 0, 2
FileDescription: x6e38x620fx5b89x88c5x7a0bx5e8f
OriginalFilename: setup.exe
Translation: 0x0804 0x04b0

Adware:Win32/Kuaiba.A also known as:

DrWebTrojan.StartPage1.58502
MicroWorld-eScanGen:Variant.Mikey.30696
FireEyeGeneric.mg.b1e9ebc29364587c
CAT-QuickHealPua.Kuaiba.A5
ALYacGen:Variant.Mikey.30696
MalwarebytesAdware.Kuaiba
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 004b87351 )
BitDefenderGen:Variant.Mikey.30696
K7GWAdware ( 004b87351 )
Cybereasonmalicious.293645
TrendMicroHT_GRAFTOR_GC140139.UVPM
BitDefenderThetaGen:NN.ZexaF.34084.@x3@aC8Y@Ifj
CyrenW32/Startpage.CK.gen!Eldorado
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
ClamAVWin.Adware.Kuaiba-16
GDataGen:Variant.Mikey.30696
Kasperskynot-a-virus:AdWare.Win32.Kuaiba.aey
AlibabaAdWare:Win32/Kuaiba.5dfa4b3c
NANO-AntivirusRiskware.Win32.Kuaiba.eaecvc
ViRobotAdware.Kuaiba.9742499
AegisLabAdware.Win32.Kuaiba.mDzu
RisingTrojan.Bitrep!8.F596 (CLOUD)
Ad-AwareGen:Variant.Mikey.30696
SophosGeneric PUA ND (PUA)
ComodoApplicUnwnt@#1dii20k3catk6
F-SecureAdware.ADWARE/Adware.Gen7
BaiduWin32.Adware.kuaiba.a
ZillyaAdware.Kuaiba.Win32.21
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.PUPXEP.tc
EmsisoftGen:Variant.Mikey.30696 (B)
IkarusPUA.Kuaiba
F-ProtW32/Startpage.CK.gen!Eldorado
JiangminAdware.Adware.aoz
MaxSecureTrojan.Malware.12258393.susgen
AviraADWARE/Adware.Gen7
Endgamemalicious (high confidence)
ArcabitTrojan.Mikey.D77E8
ZoneAlarmnot-a-virus:AdWare.Win32.Kuaiba.aey
MicrosoftAdware:Win32/Kuaiba.A
AhnLab-V3PUP/Win32.Kuaiba.R183989
Acronissuspicious
McAfeePUP-XFC-LJ
VBA32AdWare.Kuaiba
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Adware.Kuaiba.A
TrendMicro-HouseCallHT_GRAFTOR_GC140139.UVPM
TencentMalware.Win32.Gencirc.10b3c917
YandexPUA.Kuaiba!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/StartPage.CK!tr
WebrootW32.Adware.Gen
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Generic/Trojan.33a

How to remove Adware:Win32/Kuaiba.A?

Adware:Win32/Kuaiba.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment