Adware

Adware:Win32/Sogou removal guide

Malware Removal

The Adware:Win32/Sogou is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:Win32/Sogou virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to create or modify a Browser Helper Object

How to determine Adware:Win32/Sogou?


File Info:

name: 43730375541FA2E8C4B4.mlw
path: /opt/CAPEv2/storage/binaries/4645c5a2df9b9453533263099675fffe49ba689c4db5f01fb99589c38ec1b53e
crc32: CDDBE41F
md5: 43730375541fa2e8c4b430f281952020
sha1: 08e6df370dd9028739b729a708c4cb44bea316ce
sha256: 4645c5a2df9b9453533263099675fffe49ba689c4db5f01fb99589c38ec1b53e
sha512: 21ae172bea83256f67ff3cf40cf8a06d9c91bf911ce36c172d6739f65370ad2c54692c1e6d45715cec5a3320fca663725b8a406fa3df635836638489640e69fb
ssdeep: 3072:EmeDmBqskJCUi7FPzVwdPYu7jp0uc1gGJEk5cNiibsWEfXIRwyn:E8FU6LyJb7jp0uc1ugcNXJRw4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160C3012626E19477DF9787B04A779378DB73A6802A1104CB27A10FFA6E690C5CF062D3
sha3_384: 42a177033ed8ff6e26a0a29b5a81a36ffbf138bea09773381214d04816bb90956d2959000c5cf7f91ed8074a8b229916
ep_bytes: 81ec7c01000053555633f65789742418
timestamp: 2006-11-27 17:36:08

Version Info:

0: [No Data]

Adware:Win32/Sogou also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Adware.Sogou.Gen
ClamAVWin.Adware.Generic-9764337-0
FireEyeGeneric.mg.43730375541fa2e8
CAT-QuickHealPUA.CPush.A5
SkyhighBackDoor-FEH
ALYacDropped:Adware.Sogou.Gen
Cylanceunsafe
ZillyaTrojan.BHO.Win32.29868
SangforSuspicious.Win32.Save.ins
K7AntiVirusAdware ( 005189a81 )
AlibabaTrojan:Win32/AdClick.81968fef
K7GWAdware ( 005189a81 )
CrowdStrikewin/grayware_confidence_100% (W)
ArcabitAdware.Sogou.Gen
BitDefenderThetaGen:NN.ZedlaF.36744.mu8@aiyh@kdj
VirITAdware.Generic5.AJTW
SymantecAdware.CPush
ESET-NOD32Win32/Adware.Cinmus
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.BHO.cyzs
BitDefenderDropped:Adware.Sogou.Gen
NANO-AntivirusTrojan.Win32.BHO.crkfzi
SUPERAntiSpywareTrojan.Agent/Gen-CPush
AvastNSIS:Cpush [Adw]
TencentWin32.Trojan.Bho.Anhl
TACHYONTrojan/W32.BHO.127919
EmsisoftDropped:Adware.Sogou.Gen (B)
BaiduMulti.Threats.InArchive
F-SecureTrojan.TR/BHO.Gen2
DrWebAdware.Sogou.915
VIPREDropped:Adware.Sogou.Gen
TrendMicroTROJ_SPNR.35EE13
SophosTroj/AdClick-ER
JiangminHeur:Adware/BHO
GoogleDetected
AviraADWARE/Cinmus.Gen
Antiy-AVLTrojan/Win32.BHO
Kingsoftmalware.kb.a.998
XcitiumApplication.Win32.Cinmus.KS@544fcq
MicrosoftAdware:Win32/Sogou
ZoneAlarmTrojan.Win32.BHO.cyzs
GDataNSIS.Adware.Cinmus.B
VaristW32/Cpush.B.gen!Eldorado
AhnLab-V3Dropper/Win32.Cinmus.R11328
McAfeeBackDoor-FEH
MAXmalware (ai score=100)
VBA32Trojan.BHO
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/NsisDownloader.A
TrendMicro-HouseCallTROJ_SPNR.35EE13
RisingAdware.CPush!1.9D6F (CLASSIC)
YandexTrojan.BHO!axawFN+V9CU
IkarusWin32.Malware
MaxSecureTrojan.BHO.cgoz
FortinetW32/Agent.7593!tr
AVGNSIS:Cpush [Adw]
Cybereasonmalicious.70dd90
DeepInstinctMALICIOUS

How to remove Adware:Win32/Sogou?

Adware:Win32/Sogou removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment