Malware

Should I remove “PWS:Win32/Sinowal!AA”?

Malware Removal

The PWS:Win32/Sinowal!AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Sinowal!AA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempted to write directly to a physical drive

How to determine PWS:Win32/Sinowal!AA?


File Info:

name: DB454B64446B23B6AD2E.mlw
path: /opt/CAPEv2/storage/binaries/49ded6bdac4728c6bb4dda1cfc6098830cd1ec48a86ab42bc1f6b74bf61e700a
crc32: DB642B9C
md5: db454b64446b23b6ad2ea8f9743cdff1
sha1: de912bfde19da7629e84c4ccbeab922406a518ab
sha256: 49ded6bdac4728c6bb4dda1cfc6098830cd1ec48a86ab42bc1f6b74bf61e700a
sha512: abc26e73bd7a7390d549d4194bd6a910cc95132c150b977546593eaea67b62ae0a393406cc13e5531bf3a16b6d2c94dce9729feb51db0d0f34181d3e1950cb47
ssdeep: 768:TtFDsLzYFSLxK/864vPuFUJPJIFqYF+SPA8ckVxBm85ih+2:PoLSSLAn4XuFUPoqYFq8/xBb552
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T19B432A1F599EF8F3E0BA15B6DC0BB45A94745676D1006CC3E7622E398220CD34E2BE4E
sha3_384: b9aa130646f964bfa152c3dc6db03aa7a00cbc75c593ff9183ce3dbd1cc9042367b49b58c24955d04b753e67e430c27b
ep_bytes: 833dc4f40010007529e8a65e0000e8fa
timestamp: 2002-03-20 11:39:41

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows NT Setup Executable
FileVersion: 5.1.2600.5512 (xpsp.080413-2111)
InternalName: SETUP.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: SETUP.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.5512
Translation: 0x0409 0x04b0

PWS:Win32/Sinowal!AA also known as:

BkavW32.Common.B8ECA3B7
LionicTrojan.Win32.Sinowal.m!c
tehtrisGeneric.Malware
DrWebTrojan.Packed.22026
CynetMalicious (score: 99)
FireEyeGeneric.mg.db454b64446b23b6
SkyhighBehavesLike.Win32.Infected.qh
Cylanceunsafe
ZillyaBackdoor.Agent.Win32.32468
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Sinowal.f9bac068
K7GWTrojan ( 002d20821 )
K7AntiVirusBackdoor ( 002d20821 )
BitDefenderThetaGen:NN.ZedlaF.36744.du8@aeNYgXki
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.SJI
APEXMalicious
ClamAVWin.Trojan.Sinowal-5104
KasperskyBackdoor.Win32.Agent.brve
BitDefenderGen:Variant.Zbot.17
NANO-AntivirusTrojan.Win32.Sinowal.dtrqi
MicroWorld-eScanGen:Variant.Zbot.17
AvastWin32:Cryptor
TencentWin32.Backdoor.Agent.Dnhl
EmsisoftGen:Variant.Zbot.17 (B)
F-SecureTrojan.TR/Kazy.3545812
VIPREGen:Variant.Zbot.17
TrendMicroCryp_Sinowal
SophosMal/Sinowal-N
IkarusBackdoor.Win32.Sinowal
JiangminBackdoor/Agent.cyrm
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Kazy.3545812
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Hack.Agent.brve
MicrosoftPWS:Win32/Sinowal.gen!AA
XcitiumTrojWare.Win32.TrojanDownloader.Agent.NIGH@4o0eer
ArcabitTrojan.Zbot.17
ZoneAlarmBackdoor.Win32.Agent.brve
GDataGen:Variant.Zbot.17
VaristW32/Sinowal.AC.gen!Eldorado
AhnLab-V3Backdoor/Win32.Sinowal.R11338
McAfeeBackDoor-DWL.c
MAXmalware (ai score=100)
VBA32BScope.Trojan.MTA.01512
PandaTrj/Genetic.gen
TrendMicro-HouseCallCryp_Sinowal
RisingTrojan.Generic@AI.97 (RDML:qXb+dal45g6ZJ+/0ENemNg)
YandexTrojan.DR.Sinowal.Gen.20
MaxSecureTrojan.Malware.2820559.susgen
FortinetW32/Sinowal.NYN!tr
AVGWin32:Cryptor
DeepInstinctMALICIOUS

How to remove PWS:Win32/Sinowal!AA?

PWS:Win32/Sinowal!AA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment