Backdoor

Backdoor.Sinowal removal instruction

Malware Removal

The Backdoor.Sinowal is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Sinowal virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor.Sinowal?


File Info:

name: 71B503364C630015C821.mlw
path: /opt/CAPEv2/storage/binaries/fe72bf5f6b4bac615a418bf23556bb08d7b80f297587b64859bbb020e5683843
crc32: 532CFC90
md5: 71b503364c630015c82146a9778a66fe
sha1: aace521c5e44682ddae2f9f4601379b59400ac3e
sha256: fe72bf5f6b4bac615a418bf23556bb08d7b80f297587b64859bbb020e5683843
sha512: 4efd69e841b82b19d69ff8c20f0ca43dfc482fe6b674f51fb58e5c77f92c9fd9508de1231d68c04d0918083ea4a531ca54ae7be96cb4ce090f353d6bf4fac455
ssdeep: 192:Ki5qDXX6dLnKfzFFmWC3S9btZXGAP2r7MnoFLgTTulAfZ:F5qHWzKfzFcjS9bt5GAPwgTTbh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E71284386ED41677E3BBDABAC9F645CBF971B02239015C0E408647440C23F5BADE1A5E
sha3_384: a161dc6d3c315b91fed69596801ac40047bb7fa7bb3701046deae3483f3226c82ed9f6a4b34464496dcc3cc4371ab7f2
ep_bytes: 83c49c8bece8000000005b81c47cffff
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Backdoor.Sinowal also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Downloader.JRAX
ClamAVWin.Trojan.Downloader-64009
FireEyeGeneric.mg.71b503364c630015
CAT-QuickHealDownloader.Upatre.21743
ALYacTrojan.Downloader.JRAX
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Waski.Win32.64483
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0049d22b1 )
AlibabaMalware:Win32/km_2ad8.None
K7GWTrojan-Downloader ( 0049d22b1 )
Cybereasonmalicious.64c630
VirITTrojan.Win32.Upatre.D
CyrenW32/A-7e979cf2!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.F
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Downloader.JRAX
NANO-AntivirusTrojan.Win32.DownLoad3.devbpe
ViRobotTrojan.Win.Z.Waski.9824.AG
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-DL.Win32.Waski.hf
SophosMal/Upatre-AS
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Upatre.112
VIPRETrojan.Downloader.JRAX
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Generic.zt
Trapminemalicious.high.ml.score
EmsisoftTrojan.Downloader.JRAX (B)
IkarusTrojan-Downloader.Win32.Upatre
GDataWin32.Trojan.PSE.17P1L14
JiangminTrojanDropper.Dapato.pfz
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Sinowal
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.BC@5qv3w8
ArcabitTrojan.Downloader.JRAX
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Vindor!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R120254
Acronissuspicious
McAfeeGenericRXHD-JB!71B503364C63
MAXmalware (ai score=85)
VBA32Backdoor.Sinowal
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Upatre!8.B5 (TFE:2:tC3BeTrMP9U)
YandexTrojan.GenAsa!BcZoWQSCCN0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.B!tr.dldr
BitDefenderThetaAI:Packer.767B75971E
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Sinowal?

Backdoor.Sinowal removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment