Adware

Should I remove “Adware:Win32/Kuaiba.RS!MTB”?

Malware Removal

The Adware:Win32/Kuaiba.RS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:Win32/Kuaiba.RS!MTB virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Adware:Win32/Kuaiba.RS!MTB?


File Info:

name: 21DB8B14E8B43312856F.mlw
path: /opt/CAPEv2/storage/binaries/0e4a64d80809fe301f63d090c9ace2f9416ef637d4296aa451bb66dbc56232b0
crc32: 19FB60AB
md5: 21db8b14e8b43312856f8ca4f58a9669
sha1: da30c25a30f659c10df5c7896d22aabe030d868f
sha256: 0e4a64d80809fe301f63d090c9ace2f9416ef637d4296aa451bb66dbc56232b0
sha512: 2054ea0ca6838a0244fadf9a4821a45a674541eb3a258e58c4fad784b973177dff498b958cfaee99af6ab5ba970ce1c59d0670483ffa9015895c14534ed7b11b
ssdeep: 24576:zio3EfzEEK7K65oCVi2MeVBkSSTiiq5ttdyrThXv8DsoX:lY4En3TqtdyrThXEDRX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC358D11FBDA81B1C64341B11DB6D71E9735BE89172986EBE7C03E0EEE302C1987625E
sha3_384: e496c4db50169fe28506131820d7432227313662b804bb0b3c7e6b370efc9ab6d32ab88d09db83dd4dc4b74dd3a34dd1
ep_bytes: e868d20000e917feffff833de0f94c00
timestamp: 2014-06-05 05:35:41

Version Info:

FileDescription: GameLoader
FileVersion: 1, 0, 0, 6
InternalName: GameLoader
LegalCopyright: Copyright (C) 2014
OriginalFilename: GMStartGame.rc
ProductName: GameLoader
ProductVersion: 1, 0, 0, 6
Translation: 0x0804 0x04b0

Adware:Win32/Kuaiba.RS!MTB also known as:

LionicAdware.Win32.Kuaiba.2!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.21db8b14e8b43312
CAT-QuickHealPUA.Generic.12215
McAfeeAdware-Kuaiba
CylanceUnsafe
ZillyaAdware.Agent.Win32.13865
SangforPUP.Win32.Kuaiba.A
K7AntiVirusAdware ( 004b87351 )
AlibabaAdWare:Win32/Kuaiba.ae27ae0e
K7GWAdware ( 004b87351 )
CrowdStrikewin/grayware_confidence_90% (W)
VirITTrojan.Win32.DownLoader12.OZ
CyrenW32/Adware.OFFO-8081
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Adware.Kuaiba.A
BaiduWin32.Adware.kuaiba.a
TrendMicro-HouseCallTROJ_GEN.R002C0PHL22
ClamAVWin.Adware.Agent-1250029
Kasperskynot-a-virus:AdWare.Win32.Kuaiba.agm
NANO-AntivirusRiskware.Win32.Kuaiba.deeoie
CynetMalicious (score: 99)
SUPERAntiSpywarePUP.Kuaiba/Variant
APEXMalicious
TencentMalware.Win32.Gencirc.10b0d18b
ComodoApplication.Win32.Kuaiba.BC@5np13a
DrWebTrojan.DownLoader12.389
TrendMicroTROJ_GEN.R002C0PHL22
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
SophosGeneric PUA NK (PUA)
IkarusPUA.Kuaiba
JiangminAdware/Agent.hxi
WebrootW32.Malware.Heur
AviraHEUR/AGEN.1222849
MAXmalware (ai score=56)
Antiy-AVLTrojan/Generic.ASSuf.5B3E
ViRobotAdware.Kuaiba.1155072.A
MicrosoftAdware:Win32/Kuaiba.RS!MTB
GoogleDetected
VBA32AdWare.Agent
MalwarebytesMalware.AI.4277034541
AvastWin32:Adware-gen [Adw]
RisingTrojan.Occamy!8.F1CD (RDMK:cmRtazrLQY6GXIaGzfKr2dPD8Pkt)
YandexPUA.Kuaiba!7qIetXHu8NU
MaxSecureTrojan.Malware.7164915.susgen
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.4e8b43

How to remove Adware:Win32/Kuaiba.RS!MTB?

Adware:Win32/Kuaiba.RS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment