PUA

PUP.Optional.Microleaves (file analysis)

Malware Removal

The PUP.Optional.Microleaves is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Microleaves virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Collects information to fingerprint the system

How to determine PUP.Optional.Microleaves?


File Info:

name: C313DDB7DF24003D25BF.mlw
path: /opt/CAPEv2/storage/binaries/e3bc81a59fc45dfdfcc57b0078437061cb8c3396e1d593fcf187e3cdf0373ed1
crc32: CA9C313E
md5: c313ddb7df24003d25bf62c5a218b215
sha1: 20a3404b7e17b530885fa0be130e784f827986ee
sha256: e3bc81a59fc45dfdfcc57b0078437061cb8c3396e1d593fcf187e3cdf0373ed1
sha512: 542e2746626a066f3e875ae2f0d15e2c4beb5887376bb0218090f0e8492a6fdb11fa02b035d7d4200562811df7d2187b8a993a0b7f65489535919bdf11eb4cff
ssdeep: 98304:h35E+vGaiDnXGtwcmoQvoTn0ib3xuisXNSAngKvbN/k:/vGacofn0IGtXK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E8F5AE31778AC53BD56219706A2CDBAF51287BB50F7294C7A3D81E6E04F48C29732E27
sha3_384: 95e3a9234768b2f404ea5e33eca6baaf7ca8fab01c59cc030a2ff2f5b73ddb544704ad109c2bdad4d21d3edc2f9885aa
ep_bytes: e886060000e97afeffffcccccccccccc
timestamp: 2021-04-23 07:52:46

Version Info:

CompanyName: AW Manager
FileDescription: Windows Manager Installer
FileVersion: 1.0.0
InternalName: Yonatan_Installer_1.0.0
LegalCopyright: Copyright (C) 2021 AW Manager
OriginalFileName: Yonatan_Installer_1.0.0.exe
ProductName: Windows Manager
ProductVersion: 1.0.0
Translation: 0x0409 0x04b0

PUP.Optional.Microleaves also known as:

LionicAdware.Win32.AdUpdater.2!c
DrWebAdware.OnlineGuard.9
MicroWorld-eScanApplication.Bundler.CTT
FireEyeApplication.Bundler.CTT
CAT-QuickHealTrojan.Win32
ALYacApplication.Bundler.CTT
MalwarebytesPUP.Optional.Microleaves
AlibabaAdWare:Win64/Microleaves.60b6fb1c
VirITPUP.Win32.MicroLeaves.A
CyrenW32/Trojan.XXQL-5033
ESET-NOD32Win64/Microleaves.A potentially unwanted
Kasperskynot-a-virus:HEUR:AdWare.Win32.AdUpdater.gen
BitDefenderApplication.Bundler.CTT
Ad-AwareApplication.Bundler.CTT
EmsisoftApplication.Bundler.CTT (B)
VIPRETrojan.Win32.Generic!BT
GDataApplication.Bundler.CTT
WebrootW32.Adware.Gen
MAXmalware (ai score=76)
GridinsoftPUP.Microleaves.sd!c
VBA32TrojanProxy.Win64.Microleaves
CylanceUnsafe
FortinetRiskware/Microleaves

How to remove PUP.Optional.Microleaves?

PUP.Optional.Microleaves removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment