PUA

Should I remove “PUA:Win32/Xiaoxiong”?

Malware Removal

The PUA:Win32/Xiaoxiong is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Xiaoxiong virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Detects VMware through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

ht.suzip.cn

How to determine PUA:Win32/Xiaoxiong?


File Info:

crc32: 258D58B3
md5: 82eb63674be6a6a14da3c7fc3a361f0a
name: suzip_103.exe
sha1: 7575ec95a01408495c3aa692cf1dbc4ad4b5816d
sha256: 1756d722a70423554b348827b072b09390e7eb050eac011a60f11576d1f9e9f3
sha512: 0ef5ea80cd75a5d3f84acb588b50817f2a091099c857d9ffb88685d065f4d59c2358898a6dca6e780f633de22af372e6ed43550938759f7b5eb63ec686350ce1
ssdeep: 49152:6r7JirSYsCyPAOAnHifNWMeCwhMJtXVxFSLfM7RRbBzuNsZYr4Uk6t0Mq6oxZ:eArSHCyPAOAnOWnbhYXfFBRRbBipjk+m
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C)XunTux7248x6743x6240x6709
ProductVersion: 1.0.0.1
ProductName: x6781x901fx538bx7f29
FileVersion: 1.0.0.1
FileDescription: x6781x901fx538bx7f29
Translation: 0x0804 0x03a8

PUA:Win32/Xiaoxiong also known as:

MicroWorld-eScanAdware.GenericKD.12067083
FireEyeGeneric.mg.82eb63674be6a6a1
McAfeeArtemis!82EB63674BE6
CylanceUnsafe
VIPREAdware.Sogou
K7AntiVirusTrojan ( 004de2f61 )
BitDefenderAdware.GenericKD.12067083
K7GWTrojan ( 004de2f61 )
Cybereasonmalicious.74be6a
ESET-NOD32a variant of Win32/Packed.NSISmod.E suspicious
APEXMalicious
AvastWin32:Adware-gen [Adw]
GDataAdware.GenericKD.12067083
Kasperskynot-a-virus:AdWare.Win32.Sogou.oq
AlibabaAdWare:Win32/Sogou.2a9cfa31
NANO-AntivirusTrojan.Win32.Langsu.ewjogv
AegisLabAdware.Win32.Sogou.2!c
SophosGeneric PUA HF (PUA)
ComodoApplicUnwnt@#697usm3lc7ni
F-SecureHeuristic.HEUR/AGEN.1003166
DrWebAdware.ShouQu.5
ZillyaAdware.GenericKDCRTD.Win32.12133
Invinceaheuristic
McAfee-GW-EditionArtemis
IkarusPUA.NSISmod
MaxSecureTrojan.Malware.11037112.susgen
AviraHEUR/AGEN.1113526
Antiy-AVLGrayWare[AdWare]/Win32.PackedNsisMod.e
Endgamemalicious (high confidence)
ArcabitAdware.Generic.DB8210B
AhnLab-V3PUP/Win32.Helper.R233014
ZoneAlarmnot-a-virus:AdWare.Win32.Sogou.oq
MicrosoftPUA:Win32/Xiaoxiong
VBA32AdWare.Sogou
ALYacAdware.GenericKD.12067083
MAXmalware (ai score=100)
PandaTrj/CI.A
RisingPUA.Xiaoxiong!8.F651 (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitGeneric.Malware
FortinetW32/Generic.AC.3909B7!tr
WebrootW32.Adware.Gen
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove PUA:Win32/Xiaoxiong?

PUA:Win32/Xiaoxiong removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment