Threat Database Adware Adware.Kuaiba

Adware.Kuaiba

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 14,709
Threat Level: 20 % (Normal)
Infected Computers: 3,627
First Seen: February 28, 2022
Last Seen: June 12, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Adware.Kuaiba
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 71d7cb3bb281a3d457d5ced9647bbeac
SHA1: ef0c95c4e56b9971aa1317ae7cf51ef7f87e8130
SHA256: 205BAF61BCA1192DE030A722F6446B8A0B182BD7733614BB25D9256B788B02DB
File Size: 8.26 MB, 8263904 bytes
MD5: ed759b8f45745fbda8f3b690a04f66db
SHA1: 007177cf0a47dfe596f4b23157531550fb6f261d
SHA256: 7B979C1662618579CAC69C06D7FF11C26BE6085FDC465B48F2C26C4FB8A29C42
File Size: 337.41 KB, 337408 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments 快快运行库修复助手 v2.0
Company Name 和御嘉网络
File Description
  • Kawaks
  • 快快运行库修复助手 v2.0 安装程序 6887c71
File Version
  • 2.0.1.287
  • 1, 0, 0, 1
Internal Name WinKawaks
Legal Copyright
  • Copyright (C) 2001
  • 版权所有 (C) 2022 和御嘉网络
Original Filename WinKawaks.exe
Product Name
  • WinKawaks Application
  • 快快运行库修复助手
Product Version
  • 2.0.1.287
  • 1, 0, 0, 1
Special Build 000000

Digital Signatures

Signer Root Status
南京和御嘉网络科技有限公司 AAA Certificate Services Root Not Trusted
南京和御嘉网络科技有限公司 AAA Certificate Services Root Not Trusted

File Traits

  • .UPX
  • 2+ executable sections
  • HighEntropy
  • packed
  • x86

Block Information

Total Blocks: 304
Potentially Malicious Blocks: 1
Whitelisted Blocks: 18
Unknown Blocks: 285

Visual Map

0 ? ? ? ? ? ? 0 0 0 ? ? ? ? x 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 1 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsxa8af.tmp\buttonevent.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsxa8af.tmp\kkrtnsisminiextend.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsxa8af.tmp\kkrtskin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsxa8af.tmp\nsdialogs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsxa8af.tmp\skin_image.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsxa8af.tmp\system.dll Generic Write,Read Attributes

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx

Trending

Most Viewed

Loading...