Virus

What is “Win32/UniversalVirusSniffer.A potentially unsafe”?

Malware Removal

The Win32/UniversalVirusSniffer.A potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/UniversalVirusSniffer.A potentially unsafe virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Enumerates physical drives
  • Accessed credential storage registry keys
  • Harvests information related to installed mail clients
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/UniversalVirusSniffer.A potentially unsafe?


File Info:

name: 5FA687A1E2AA9051DC2D.mlw
path: /opt/CAPEv2/storage/binaries/1dbf776231db8cc9634a2b321127870c002b31a044e191c8f3c1c8a7adea3748
crc32: 1713CF7E
md5: 5fa687a1e2aa9051dc2d51e92284392b
sha1: ac3bb9285969c6859241cd20b40a87a0260242d0
sha256: 1dbf776231db8cc9634a2b321127870c002b31a044e191c8f3c1c8a7adea3748
sha512: a4aa150acaa4764b32fc6774ddb492a5423aa56cc5480126d994856c8a4fc99f40f7b164c5c87d3fccadc2d558cb656b6aa08622621221f8e42a70b1456f035d
ssdeep: 12288:ypd+Y61yGneM0MDHILsxtf9YzLeHWUbI9lVawsUYH4oSnI:GIj1NeMDDoLsPf9AjUbu8wsUY4I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10694226CDAD6832BC90E103EB11F06A75726FC0DF493AB039A249E0DFD61BA91F9C155
sha3_384: 8f644de9a0d65654bbec1c8925e14800a48f002c4cb91ce53ecffb42d3961e4430348e923f8efb559bfb756b10f7e6f0
ep_bytes: 60be00e05d008dbe0030e2ff5789e58d
timestamp: 2018-10-11 07:32:01

Version Info:

0: [No Data]

Win32/UniversalVirusSniffer.A potentially unsafe also known as:

SkyhighBehavesLike.Win32.SoftPulse.gc
McAfeeArtemis!5FA687A1E2AA
MalwarebytesMachineLearning/Anomalous.100%
CrowdStrikewin/grayware_confidence_60% (W)
BitDefenderThetaGen:NN.ZexaE.36744.AmGfaqSCftlk
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/UniversalVirusSniffer.A potentially unsafe
APEXMalicious
CynetMalicious (score: 100)
SophosUniversal Virus Sniffer (PUA)
IkarusPUA.UniversalVirusSniffer
Cylanceunsafe
PandaPUP/Hacktool
RisingPUA.UniversalVirusSniffer!8.17CF2 (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
DeepInstinctMALICIOUS

How to remove Win32/UniversalVirusSniffer.A potentially unsafe?

Win32/UniversalVirusSniffer.A potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment