Adware

About “SigAdware.GuangzhouKuGouComputerTechnologyCoLtd” infection

Malware Removal

The SigAdware.GuangzhouKuGouComputerTechnologyCoLtd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What SigAdware.GuangzhouKuGouComputerTechnologyCoLtd virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine SigAdware.GuangzhouKuGouComputerTechnologyCoLtd?


File Info:

name: 965060A6CFE44D15872D.mlw
path: /opt/CAPEv2/storage/binaries/c3d96ee0487e0f35ff5a06ee43f40c76db99d865755609e2a0a521211ad85b0f
crc32: 98AC507A
md5: 965060a6cfe44d15872d3c4db6117682
sha1: 5fcc4045d287bf06bf32f21399520173f07bc589
sha256: c3d96ee0487e0f35ff5a06ee43f40c76db99d865755609e2a0a521211ad85b0f
sha512: 966a2c753956b7900e7aadc6f77ae9397e5d926e49c2d2fdcf7d5be7cf9738cacdafbb54cd0615e54d501229b30964526a38353b95623d01347425321e4818e8
ssdeep: 393216:z/hx9sQDXsC72qz2AHPFXxT/5flT8lQ1RJVoVmYEJ:z/hx75fz2AHPJ9/5gWRJVWh6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15FD63313C13297BDCE928EB133054724E2F648649EE49F1AFF49A58E124CDEDA14397E
sha3_384: b0b0419c2072f0e951469fd635ac6b1ce42438a7971fc609e4713286491e3918a076ddc7af8b142aa02c93011441391b
ep_bytes: e8e3feffff33c050505050e8be2b0000
timestamp: 2010-03-15 06:27:50

Version Info:

0: [No Data]

SigAdware.GuangzhouKuGouComputerTechnologyCoLtd also known as:

BkavW32.Common.0AE6DD6D
ZillyaWorm.WhiteIce.Win32.2190
K7AntiVirusTrojan ( 00587c3f1 )
K7GWTrojan ( 00587c3f1 )
APEXMalicious
NANO-AntivirusRiskware.Win32.Plugin.hjnyxg
AvastWin32:Adware-gen [Adw]
RisingTrojan.Bitrep!8.F596 (RDMK:cmRtazoxlpHl2kNYyMZNCZ5iAU7r)
DrWebWin32.HLLW.Bice
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
Trapminemalicious.moderate.ml.score
JiangminDownloader.Generic.axsd
MicrosoftProgram:Win32/Wacapew.C!ml
VBA32SigAdware.GuangzhouKuGouComputerTechnologyCoLtd
MaxSecureTrojan.Malware.3411146.susgen
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove SigAdware.GuangzhouKuGouComputerTechnologyCoLtd?

SigAdware.GuangzhouKuGouComputerTechnologyCoLtd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment