Malware

Downloader.Win32.Sogou.h removal guide

Malware Removal

The Downloader.Win32.Sogou.h is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Sogou.h virus can do?

  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity contains more than one unique useragent.
  • Anomalous binary characteristics

Related domains:

yz.app.sogou.com
ping.t.sogou.com
yze.t.sogou.com

How to determine Downloader.Win32.Sogou.h?


File Info:

crc32: 18FC9D95
md5: fdee58b0ef20babc97fd873e5bd0a001
name: sogouhbci.e
sha1: 42304ea70159730bd1d07b2cf5f6740a051e9857
sha256: 986d38ee49f283876c605a9060bd0731d5e01273d16c2b7917b36b485bfccb74
sha512: e82ad0a4acf35168ceb11a5240a5bf4254daf0f7abd39633cc691a96eea97ff22ff9671931de43c9411f8d69381dd2d6ffbb405661bc389819b0a8cc97b06132
ssdeep: 12288:JUHzKufgk0IpzpXxsPsM+80/9OCOaVLR7g1xGkgBaFSkYu8DU0OYhLu0O49gY4B:6HVfSIpzpBsGACO0LRs1kk6i6uKVOu4B
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2014 Sogou.com Inc. All rights reserved.
InternalName: MiniDownLoad.exe
FileVersion: 2.0.8.1
CompanyName: Sogou.com Inc.
ProductName: x641cx72d7x9ad8x901fx4e0bx8f7dx52a9x624b
ProductVersion: 2.0.8.1
FileDescription: x641cx72d7x9ad8x901fx4e0bx8f7dx52a9x624bx5b89x88c5x5305
OriginalFilename: MiniDownLoad.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Sogou.h also known as:

BkavW32.HfsAdware.170E
CAT-QuickHealDownloader.Sogou
MalwarebytesAdware.Downloader.CN
VIPRETrojan.Win32.Generic!BT
K7GWUnwanted-Program ( 004cca081 )
K7AntiVirusUnwanted-Program ( 004cca081 )
TrendMicroTROJ_GEN.R08NC0OFH17
BaiduWin32.Trojan.WisdomEyes.16070401.9500.9819
SymantecSMG.Heur!gen
TrendMicro-HouseCallTROJ_GEN.R08NC0OFH17
Kasperskynot-a-virus:Downloader.Win32.Sogou.h
NANO-AntivirusTrojan.Win32.Sogou.engykk
SophosGeneric PUA EC (PUA)
DrWebBackDoor.Gbot.2817
ZillyaDownloader.SogouCRTD.Win32.237
Invinceaheuristic
McAfee-GW-EditionArtemis!PUP
EmsisoftApplication.Chindo (A)
CyrenW32/Trojan.VQGV-3115
Antiy-AVLRiskWare[Downloader]/Win32.Sogou
Endgamemalicious (high confidence)
SUPERAntiSpywareAdware.Sogou/Variant
ZoneAlarmnot-a-virus:Downloader.Win32.Sogou.h
AhnLab-V3PUP/Win32.Sogou.C1514212
McAfeeArtemis!FDEE58B0EF20
AVwareTrojan.Win32.Generic!BT
VBA32Downloader.Sogou
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Downloader.Sogou.AA potentially unwanted
YandexPUA.Downloader!
SentinelOnestatic engine – malicious
FortinetRiskware/Downloader_Sogou
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikemalicious_confidence_100% (D)

How to remove Downloader.Win32.Sogou.h?

Downloader.Win32.Sogou.h removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment