Malware

Pua.Kuaiba.A5 removal instruction

Malware Removal

The Pua.Kuaiba.A5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Pua.Kuaiba.A5 virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

css.jipinfeiche.cn

How to determine Pua.Kuaiba.A5?


File Info:

crc32: 6D1CECA9
md5: c8d6db2388714fdbe5da455612fd901c
name: chongwulianliankan25banzhongwenban.exe
sha1: 684ce978f3ec86c0f5767ddfe63e8ba23040dc13
sha256: 195b9f9d77cd47007c51a29be29473aed0d845885a2f5a152c2a486ce4b0dfef
sha512: 8435176f277efdee766f97026fad1613e4e7d52be23c53b3c0e03caf3d7f60363065ac9eb56d8c53683ba2cbaa36db0e354aee70d88b508e2f026e2dc5aef361
ssdeep: 196608:hIQb3kX+EJ025Irmh+7K8/+ZIoW/sq1oIQb3kX+EJ025Irmh+7K8/+ZIoW/sqhbl:hIQb3kuES25Irmh+7K8/+ZIoW/sq1oIE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2015
InternalName: x6e38x620fx5b89x88c5x7a0bx5e8f
FileVersion: 1, 0, 0, 2
ProductName: x6e38x620fx5b89x88c5x7a0bx5e8f
ProductVersion: 1, 0, 0, 2
FileDescription: x6e38x620fx5b89x88c5x7a0bx5e8f
OriginalFilename: setup.exe
Translation: 0x0804 0x04b0

Pua.Kuaiba.A5 also known as:

DrWebTrojan.StartPage1.58502
MicroWorld-eScanTrojan.GenericKD.32643178
FireEyeGeneric.mg.c8d6db2388714fdb
CAT-QuickHealPua.Kuaiba.A5
McAfeePUP-XFC-LJ
MalwarebytesAdware.Kuaiba
VIPREAdware.Win32.Kuaiba
SangforMalware
K7AntiVirusAdware ( 004b87351 )
BitDefenderTrojan.GenericKD.32643178
K7GWAdware ( 004b87351 )
Cybereasonmalicious.388714
TrendMicroTROJ_GEN.R002C0CFS19
BitDefenderThetaGen:NN.ZexaF.33558.@x3@aejYKphj
CyrenW32/Startpage.CK.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
ClamAVWin.Adware.Kuaiba-16
GDataTrojan.GenericKD.32643178
Kasperskynot-a-virus:AdWare.Win32.Kuaiba.aey
AlibabaAdWare:Win32/Kuaiba.5dfa4b3c
NANO-AntivirusRiskware.Win32.Kuaiba.eaecvc
ViRobotAdware.Kuaiba.7620267
AegisLabAdware.Win32.Kuaiba.mDzu
RisingTrojan.Generic@ML.100 (RDMK:JESSqBOlvlfi8FplJzMF5Q)
Ad-AwareTrojan.GenericKD.32643178
EmsisoftTrojan.GenericKD.32643178 (B)
ComodoApplicUnwnt@#1v5jlybdcq1qj
F-SecureAdware.ADWARE/Adware.Gen7
BaiduWin32.Adware.kuaiba.a
ZillyaAdware.Kuaiba.Win32.21
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosGeneric PUA ND (PUA)
IkarusPUA.Kuaiba
F-ProtW32/Startpage.CK.gen!Eldorado
JiangminAdware.Adware.aoz
WebrootW32.Adware.Gen
AviraADWARE/Adware.Gen7
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F2186A
ZoneAlarmnot-a-virus:AdWare.Win32.Kuaiba.aey
MicrosoftAdware:Win32/Kuaiba.A
AhnLab-V3PUP/Win32.Kuaiba.R183989
Acronissuspicious
VBA32AdWare.Kuaiba
ALYacTrojan.GenericKD.32643178
MAXmalware (ai score=100)
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Adware.Kuaiba.A
TrendMicro-HouseCallTROJ_GEN.R002C0CFS19
TencentMalware.Win32.Gencirc.10b3c917
YandexPUA.Kuaiba!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/StartPage.CK!tr
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM41.2.Malware.Gen

How to remove Pua.Kuaiba.A5?

Pua.Kuaiba.A5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment