PUA

About “PUA:Win32/Kuping” infection

Malware Removal

The PUA:Win32/Kuping is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Kuping virus can do?

  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
config.153624.com
img.wallba.com

How to determine PUA:Win32/Kuping?


File Info:

crc32: CA426D9E
md5: 35ae976aee6ccbff9925ff947a94da1e
name: hanxiongqmzzmtxgq.exe
sha1: 688af19d5e60a0837be1e08670c6bd8858fe7621
sha256: 64b5029a21ae9a31b5d14f3fde0019a9ad4f6cd78948d93ebaa4d1619f4923c4
sha512: accb7877a11505539ee1bbfec1b3da5ce8af43ba1a51fb8903ee03fe347b01f75f004dfa80c230c33e286e57c83c90f6fa57f618f5ebd39f1fb5850149d0ef5b
ssdeep: 98304:EBaYvYc11kfdFFN1NQygyIldAmvZrBgrdQRr2y1msUnLZ:a1OfPrQtl/ZVWU26mFd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2013
InternalName: InStaller
FileVersion: 0,0,0,0
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: x5b89x88c5x5305x7a0bx5e8f
SpecialBuild:
ProductVersion: 0,0,0,0
FileDescription: x5b89x88c5x5305x7a0bx5e8f
OriginalFilename: InStaller.EXE
Translation: 0x0804 0x04b0

PUA:Win32/Kuping also known as:

MicroWorld-eScanTrojan.Generic.23040316
FireEyeGeneric.mg.35ae976aee6ccbff
CAT-QuickHealDownloader.Agent.22444
McAfeeKuping
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 004c55fd1 )
BitDefenderTrojan.Generic.23040316
K7GWAdware ( 004c55fd1 )
TrendMicroTROJ_GEN.R002C0OBI20
SymantecTrojan.Gen
APEXMalicious
GDataWin32.Adware.Kuping.B
KasperskyTrojan.Win32.Gobot.byv
AlibabaTrojan:Win32/Gobot.9429fc56
NANO-AntivirusTrojan.Win32.Dwn.eeppik
ViRobotTrojan.Win32.Z.Kuping.4771432
AegisLabTrojan.Win32.Gobot.mqkp
TencentMalware.Win32.Gencirc.10b58ff7
Endgamemalicious (high confidence)
SophosGeneric PUA GI (PUA)
ComodoApplication.Win32.Kuping.B@6y68qo
DrWebTrojan.DownLoader15.3995
ZillyaAdware.VopakCRTD.Win32.6861
Invinceaheuristic
McAfee-GW-EditionKuping
EmsisoftTrojan.Generic.23040316 (B)
IkarusAdWare.Win32.Kuping
JiangminTrojan.Gobot.t
WebrootW32.Trojan.GenKD
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.KillFiles
ArcabitTrojan.Generic.D15F913C
ZoneAlarmTrojan.Win32.Gobot.byv
MicrosoftPUA:Win32/Kuping
VBA32BScope.Trojan.Gobot
ALYacTrojan.Generic.23040316
Ad-AwareTrojan.Generic.23040316
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kuping.J potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0OBI20
RisingTrojan.Gobot!8.100 (CLOUD)
YandexRiskware.Agent!
eGambitUnsafe.AI_Score_100%
Cybereasonmalicious.aee6cc
Paloaltogeneric.ml
MaxSecureTrojan.Malware.10283485.susgen

How to remove PUA:Win32/Kuping?

PUA:Win32/Kuping removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment