PUA

Should I remove “PUP.Optional.AcePasswdSniffer”?

Malware Removal

The PUP.Optional.AcePasswdSniffer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.AcePasswdSniffer virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Accessed credential storage registry keys
  • Installs WinPCAP
  • Uses suspicious command line tools or Windows utilities

How to determine PUP.Optional.AcePasswdSniffer?


File Info:

name: 00610EFDEF4008F70B8A.mlw
path: /opt/CAPEv2/storage/binaries/0858d5c85a70632f8eaf349370fc74bc5b87ca09b8dbf94503cee1c0db12bee8
crc32: 6DF3EA9A
md5: 00610efdef4008f70b8afedb7bc8dbc7
sha1: 0563776f6b3e0f3a6b39686c8c089634997f9e9c
sha256: 0858d5c85a70632f8eaf349370fc74bc5b87ca09b8dbf94503cee1c0db12bee8
sha512: 7bc92f6e3d8dc910d90ae93d4feb52f97b307b8233c3e98767b8033de90f1e1e59482450ad45818be8e8e4e78834996c0daf7fee85657adf1e9370967c681ca9
ssdeep: 24576:CHJduFt5hBYq2BXTKf2YiNY5xXcW5V6Ao5k0+9KAM5zHgL:sJMl8xNKxXcW5s3knKAMs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BC15337DC7B64DBBE483D3316354FEB2E1A6A5F881C042E79D529D2C80476842EE1D8B
sha3_384: 7c0500f89f5d082f6cb71b5997d46e13fb5cc220bccc5f31b302924d55549086e5fd6c4e7bb381df4c5572f27ddfe745
ep_bytes: 558bec81ec2c0500005356576a015e6a
timestamp: 2001-10-25 19:47:11

Version Info:

CompanyName: EffeTech
FileDescription: Ace Password Sniffer v1.2 Installation
FileVersion: 1.2
LegalCopyright: EffeTech 2004

PUP.Optional.AcePasswdSniffer also known as:

LionicRiskware.Win32.APS.1!c
MicroWorld-eScanSpyware.Pws.APS
FireEyeSpyware.Pws.APS
ALYacSpyware.Pws.APS
CylanceUnsafe
SangforHacktool.Win32.APS.buxin
K7AntiVirusRiskware ( 0040eff71 )
AlibabaRiskWare:Win32/HTool.1e0fdd5b
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.def400
CyrenW32/Tool.RIQC-7593
SymantecHacktool.AceSniffer
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:PSWTool.Win32.APS.12
BitDefenderSpyware.Pws.APS
NANO-AntivirusRiskware.Win32.PassSteel.vrsrx
AvastWin32:Malware-gen
TencentWin32.Trojan.Psw.Chd
SophosAcePassSniff-Installer (PUA)
ComodoMalware@#yxfddw8clxy4
DrWebTool.PassSteel.691
VIPREAce Password Sniffer
TrendMicroSPYW_ACEPSTL.12
McAfee-GW-EditionHTool-APSniffer
EmsisoftSpyware.Pws.APS (B)
GDataSpyware.Pws.APS
JiangminPSWTool.APS.a
WebrootSystem.Monitor.Effetech.Ace.Pas
AviraDR/PSW.APS.12
KingsoftWin32.Troj.Generic.(kcloud)
MicrosoftTrojan:Win32/Occamy.C08
McAfeeHTool-APSniffer
MAXmalware (ai score=79)
MalwarebytesPUP.Optional.AcePasswdSniffer
TrendMicro-HouseCallSPYW_ACEPSTL.12
YandexTrojan.GenAsa!u6zR7hK14Zs
eGambitnot-a-virus:Generic.PSW
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove PUP.Optional.AcePasswdSniffer?

PUP.Optional.AcePasswdSniffer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment