Malware

How to remove “Win32/Downloader.Sogou.AA potentially unwanted”?

Malware Removal

The Win32/Downloader.Sogou.AA potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Downloader.Sogou.AA potentially unwanted virus can do?

  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

yz.app.sogou.com
ping.t.sogou.com
yze.t.sogou.com

How to determine Win32/Downloader.Sogou.AA potentially unwanted?


File Info:

crc32: DB7010B7
md5: 3d35295aa476472339ee6f6b2d8fa6d9
name: sogoubel.e
sha1: 8283d57f797de2d2963a90e3a05c1feb67bd5a3e
sha256: 0c46feb05adf41a08d7db050536bb68101a73d3e67b098ea9e314f0d2dba7aa9
sha512: f3acccedff25746504fdbae22e24166bfc54ae93ec6e41ad38a8612fc567ecbc5ceaf6ef85b2fe2abb7be7cc55ae8754b8271d5f3869c4d7374268cad6215694
ssdeep: 12288:iUHzKufgk0IpzpXxsPsM+80/9OCOaVLR7g1xGkgBaFSkYu8DU0OYhLu0O49gY4B:ZHVfSIpzpBsGACO0LRs1kk6i6uKVOu4B
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2014 Sogou.com Inc. All rights reserved.
InternalName: MiniDownLoad.exe
FileVersion: 2.0.8.1
CompanyName: Sogou.com Inc.
ProductName: x641cx72d7x9ad8x901fx4e0bx8f7dx52a9x624b
ProductVersion: 2.0.8.1
FileDescription: x641cx72d7x9ad8x901fx4e0bx8f7dx52a9x624bx5b89x88c5x5305
OriginalFilename: MiniDownLoad.exe
Translation: 0x0804 0x04b0

Win32/Downloader.Sogou.AA potentially unwanted also known as:

BkavW32.HfsAdware.170E
CAT-QuickHealTrojan.IGENERIC
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7GWUnwanted-Program ( 004cca081 )
K7AntiVirusUnwanted-Program ( 004cca081 )
TrendMicroTROJ_GEN.R002C0OGI18
BaiduWin32.Trojan.WisdomEyes.16070401.9500.9819
SymantecSMG.Heur!gen
TrendMicro-HouseCallTROJ_GEN.R002C0OGI18
AvastWin32:PUP-gen [PUP]
GDataWin32.Trojan.Agent.7M079D
Kasperskynot-a-virus:AdWare.Win32.Sogou.awj
NANO-AntivirusTrojan.Win32.Sogou.engykk
SophosGeneric PUA IC (PUA)
DrWebBackDoor.Gbot.2817
ZillyaDownloader.SogouCRTD.Win32.237
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.dc
EmsisoftApplication.Chindo (A)
CyrenW32/Trojan.EBNZ-7354
Antiy-AVLRiskWare[Downloader]/Win32.Sogou
Endgamemalicious (high confidence)
SUPERAntiSpywareAdware.Sogou/Variant
ZoneAlarmnot-a-virus:AdWare.Win32.Sogou.awj
MicrosoftPUA:Win32/Sogou
AhnLab-V3PUP/Win32.Sogou.C1514212
McAfeeDownloader
AVwareTrojan.Win32.Generic!BT
MAXmalware (ai score=100)
VBA32Downloader.Sogou
MalwarebytesAdware.Downloader.CN
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Downloader.Sogou.AA potentially unwanted
YandexPUA.Downloader!
SentinelOnestatic engine – malicious
AVGWin32:PUP-gen [PUP]
Cybereasonmalicious.f797de
CrowdStrikemalicious_confidence_100% (D)

How to remove Win32/Downloader.Sogou.AA potentially unwanted?

Win32/Downloader.Sogou.AA potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment