Malware

How to remove “NetTool.Win32.Sniffer.er”?

Malware Removal

The NetTool.Win32.Sniffer.er is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NetTool.Win32.Sniffer.er virus can do?

  • Unconventionial language used in binary resources: Hebrew
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs WinPCAP

How to determine NetTool.Win32.Sniffer.er?


File Info:

name: A550281B0F431B78119E.mlw
path: /opt/CAPEv2/storage/binaries/a80f938336024b50b126fd953a2f977e06ac1bf47865b7062c42b170efb11277
crc32: D6017636
md5: a550281b0f431b78119ee5c39e703ca3
sha1: 84f2301432c86b2e6df499d25f20275bb0fe6d38
sha256: a80f938336024b50b126fd953a2f977e06ac1bf47865b7062c42b170efb11277
sha512: f52809e87ca646cb34ff0c1ff9ce95ec94de28c1b8a02d2daf88143ef1adc86460ccf534da62e04a4417449133664f0ba066ac34481d86eb6e61328e3fef940d
ssdeep: 1536:LBkPVUuFTUIzw301xkUhu/+pV4o1RtgUm4jrSo:LBkVrz7Fhu81Rt35XSo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15F33D04AE6981D98E5BB40B00817C97C17B4FC09FB7A13578A05A86FFC75295FE2234D
sha3_384: d0ca74c1f80be95c3f5d072d0bcc8a6bd6753e59e6c1df530b54f16f2dd14dfc0c92defd79c6243bae6209e0d8078ec1
ep_bytes: 60be003041008dbe00e0feff57eb0b90
timestamp: 2009-01-18 18:32:43

Version Info:

CompanyName: NirSoft
FileDescription: SmartSniff
FileVersion: 1.45
InternalName: SmartSniff
LegalCopyright: Copyright © 2004 - 2009 Nir Sofer
OriginalFilename: smsniff.exe
ProductName: SmartSniff
ProductVersion: 1.45
Translation: 0x0409 0x04b0

NetTool.Win32.Sniffer.er also known as:

LionicRiskware.Win32.Sniffer.1!c
SkyhighBehavesLike.Win32.PUP.qc
McAfeeArtemis!A550281B0F43
MalwarebytesGeneric.Malware/Suspicious
SangforPUP.Win32.Sniffer.Vjsj
K7AntiVirusTrojan ( 0043b6001 )
K7GWTrojan ( 0043b6001 )
CrowdStrikewin/grayware_confidence_90% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Sniffer.SniffPass.B potentially unsafe
APEXMalicious
Kasperskynot-a-virus:NetTool.Win32.Sniffer.er
NANO-AntivirusTrojan.Win32.MLW.echkwq
AvastWin32:PUP-gen [PUP]
SophosNirSoft SmartSniff (PUA)
ZillyaTool.Sniffer.Win32.3252
JiangminNetTool.Sniffer.ac
GoogleDetected
Antiy-AVLHackTool[Sniffer]/Win32.SniffPass
MicrosoftPUA:Win32/Presenoker
ViRobotAdware.Sniffer.54272
ZoneAlarmnot-a-virus:NetTool.Win32.Sniffer.er
GDataWin32.Riskware.SmartSniff.A
VaristW32/Trojan.IVT.gen!Eldorado
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CLF21
RisingPUA.Sniffer!8.18EF (CLOUD)
YandexRiskware.NetTool!TNE+M/ygZ0g
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/SniffPass
AVGWin32:PUP-gen [PUP]
DeepInstinctMALICIOUS

How to remove NetTool.Win32.Sniffer.er?

NetTool.Win32.Sniffer.er removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment