PUA

PUA:Win32/WDJiange malicious file

Malware Removal

The PUA:Win32/WDJiange is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/WDJiange virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
ini.xiaoxiongbizhi.com

How to determine PUA:Win32/WDJiange?


File Info:

crc32: C23B85FB
md5: 27329ba75f953f2aff1679dc5b0b5fb2
name: xiaoxin.exe
sha1: 93a52e9132583a0b6ba3513a48fd521bbbc24cc1
sha256: 550041abd97f222881ded785868176c4cb2b6ae2b13e6bf7486c9f9fe5f876f9
sha512: 8211bd80b5adf80f365a799a905ba2a14bda8afaac7a12978db320206f0de454636df12e80aaf1de96a1d1494a084aa6920213f08b06e21a3173db6789648f87
ssdeep: 98304:2LwZsLJJvlh0wbovkQe3u94jh4rtEjX86:QSveu9n6B
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2012-2015 x9ad8x6e05x58c1x7eb8, Inc.
FileVersion: 2015.0528.1703.22
CompanyName: x9ad8x6e05x58c1x7eb8
Comments: This installation was built with Inno Setup.
ProductName: x9ad8x6e05x58c1x7eb8
ProductVersion: 1.0
FileDescription: x9ad8x6e05x58c1x7eb8x66f4x591ax66f4x597dx73a9x7684x58c1x7eb8x5206x4eabx7ed9x4f60
Translation: 0x0000 0x04b0

PUA:Win32/WDJiange also known as:

BkavW32.HfsAdware.EB59
MicroWorld-eScanAdware.GenericKD.30904101
McAfeeArtemis!27329BA75F95
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusUnwanted-Program ( 004e0a341 )
BitDefenderAdware.GenericKD.30904101
K7GWUnwanted-Program ( 004e0a341 )
Cybereasonmalicious.75f953
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
ClamAVWin.Trojan.14687943-1
GDataAdware.GenericKD.30904101
Kasperskynot-a-virus:AdWare.Win32.Agent.izjh
AlibabaAdWare:Win32/Agent.0d0b634a
NANO-AntivirusRiskware.Win32.Agent.dvaxil
SophosGeneric PUA JD (PUA)
ComodoMalware@#316driuyxgw1k
F-SecureHeuristic.HEUR/AGEN.1003958
DrWebAdware.WDJiange.1
ZillyaAdware.AgentCRT.Win32.182
Invinceaheuristic
McAfee-GW-EditionGenericRXAB-LI!67C87CE72ADF
FireEyeAdware.GenericKD.30904101
EmsisoftAdware.GenericKD.30904101 (B)
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1003958
Antiy-AVLTrojan/Win32.BTSGeneric
MicrosoftPUA:Win32/WDJiange
ArcabitAdware.Generic.D1D78F25
ZoneAlarmnot-a-virus:AdWare.Win32.Agent.izjh
VBA32AdWare.Agent
ALYacAdware.GenericKD.30904101
Ad-AwareAdware.GenericKD.30904101
PandaTrj/CI.A
ESET-NOD32Win32/Adware.WDJiange.A
YandexPUA.Agent!
MaxSecureTrojan.Malware.8556941.susgen
FortinetAdware/Agent
AVGFileRepMalware [PUP]

How to remove PUA:Win32/WDJiange?

PUA:Win32/WDJiange removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment