Malware

PWS:Win32/Sinowal information

Malware Removal

The PWS:Win32/Sinowal is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Sinowal virus can do?

  • Authenticode signature is invalid

How to determine PWS:Win32/Sinowal?


File Info:

name: 17503656647A2C30A767.mlw
path: /opt/CAPEv2/storage/binaries/1e1ac650654445f28ad65616cffabb28ab0b5dadb01fedb35985efee92a3e57d
crc32: 6F7B06C8
md5: 17503656647a2c30a767e4ff0a8badbd
sha1: 35d4de927b0ccd804ae19283dd4bcd2e50a4889d
sha256: 1e1ac650654445f28ad65616cffabb28ab0b5dadb01fedb35985efee92a3e57d
sha512: a09968491d1c5d602e5bde84a2aa811514d704751d94e74b6d1e95c7401c4e4ff6bdb2ae3f1fe87e36f9e504709c03342b73fdffc5b2f242a3c5d0dfe2d9ebb8
ssdeep: 3072:/dKgq89i+1a+EDlt5KhMV4VKIBVShu9andGmaEDV7Aqa5dq:/dl7V0+Ep6MV48IBIpHDV7A/o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154E38D47B25F4B64FE7B75FA8C360A1B0FDCC1547AA634AFE629C9E014EE7A41E18005
sha3_384: ed116b20f1a846892a15a5182e19c037e96db275794116e2055f89c855034c92b3995097d4e6ccadd01862f76c78560d
ep_bytes: 33c050505050e81ff9ffffc3558bec81
timestamp: 2006-04-23 10:41:05

Version Info:

0: [No Data]

PWS:Win32/Sinowal also known as:

LionicTrojan.Win32.Sinowal.i!c
MicroWorld-eScanTrojan.CryptRedol.Gen.2
ClamAVWin.Spyware.Sinowal-23
FireEyeGeneric.mg.17503656647a2c30
CAT-QuickHealTrojanPSW.Sinowal.12860
ALYacTrojan.CryptRedol.Gen.2
CylanceUnsafe
ZillyaTrojan.Small.Win32.30659
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00008c5b1 )
AlibabaTrojanPSW:Win32/Sinowal.1d39a618
K7GWTrojan ( 00008c5b1 )
Cybereasonmalicious.6647a2
CyrenW32/Sinowal.MPWH-3865
SymantecTrojan.Anserin
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Small.NDG
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Sinowal.r
BitDefenderTrojan.CryptRedol.Gen.2
NANO-AntivirusTrojan.Win32.Sinowal.kxzm
AvastWin32:Sinowal-K [Trj]
TencentWin32.Trojan-QQPass.QQRob.Zmhl
Ad-AwareTrojan.CryptRedol.Gen.2
EmsisoftTrojan.CryptRedol.Gen.2 (B)
ComodoTrojWare.Win32.TrojanSpy.Small.D@wgwwi
DrWebTrojan.MulDrop.3675
VIPRETrojan.CryptRedol.Gen.2
TrendMicroTSPY_SINOWAL.GR
McAfee-GW-EditionGenericRXEO-OI!17503656647A
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Torpig-Gen
GDataTrojan.CryptRedol.Gen.2
JiangminTrojan/PSW.Sinowal.at
AviraTR/Spy.Small.DG.98
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.96
ArcabitTrojan.CryptRedol.Gen.2
ViRobotTrojan.Win32.A.PSW-Sinowal.73728
MicrosoftPWS:Win32/Sinowal
GoogleDetected
AhnLab-V3Trojan/Win32.Sinowal.C226688
McAfeeGenericRXEO-OI!17503656647A
TACHYONTrojan-PWS/W32.Sinowal.151552.C
VBA32BScope.Trojan-Spy.Zbot
MalwarebytesMalware.Heuristic.1006
TrendMicro-HouseCallTSPY_SINOWAL.GR
RisingTrojan.PSW.Sinowal.GEN (CLASSIC)
YandexTrojan.GenAsa!J0CgVssiric
IkarusTrojan-PWS.Win32.Sinowal
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Sinowal.L!tr.pws
BitDefenderThetaAI:Packer.B688ACA51B
AVGWin32:Sinowal-K [Trj]
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_100% (W)

How to remove PWS:Win32/Sinowal?

PWS:Win32/Sinowal removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment