Malware

PWS:Win32/Sinowal!Y malicious file

Malware Removal

The PWS:Win32/Sinowal!Y is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Sinowal!Y virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive

How to determine PWS:Win32/Sinowal!Y?


File Info:

name: 6AC9057870B8E1CF67A5.mlw
path: /opt/CAPEv2/storage/binaries/67d4d67869f879b10190ef1009c0f19042eb28d54560947b716c7fa4afbddbe4
crc32: D9155E26
md5: 6ac9057870b8e1cf67a5f0efb38c1c80
sha1: 19adc14892329388b593eb9b71ff43e642d6bfac
sha256: 67d4d67869f879b10190ef1009c0f19042eb28d54560947b716c7fa4afbddbe4
sha512: 0e76e2843bc8acf86d97311ee2044440496fd1b9a181ede61fe46e35f8d06eb660a26b236b867c3e10d01829fc8abd0a062a5307fa0b3a56d95ee10a361e9fa9
ssdeep: 1536:430zd4p3gUu7fFlJziLInNmpYwbrH34+yot8nu5TEzPP3qu4JaaY:PzuwBJziLsspYMT7OGEzPP3qfJFY
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1F7A35B3293D5DAF7E0BD16369EB69BAA18617C310E128ECB63946D4F45707C0DC12BA2
sha3_384: 833a107f9dad365ee2a1ad182e83b391eef01561434d99f9b7e19630d0866a1358c92c884cbbd0650eba730bce4de8e5
ep_bytes: 8bff558bec8d803f7db1002b450885c0
timestamp: 2005-10-17 23:27:59

Version Info:

CompanyName: Microsoft Corporation
FileDescription: DDE Share Manager
FileVersion: 5.1.2600.5512 (xpsp.080413-2105)
InternalName: DDESHARE.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: DDESHARE.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.5512
Translation: 0x0409 0x04b0

PWS:Win32/Sinowal!Y also known as:

LionicTrojan.Win32.Sinowal.lpnx
AVGWin32:MalOb-HD [Cryp]
Elasticmalicious (high confidence)
DrWebTrojan.Packed.21724
MicroWorld-eScanTrojan.Sinowal.Gen.1
FireEyeGeneric.mg.6ac9057870b8e1cf
CAT-QuickHealTrojanpws.Sinowal.26317
SkyhighDownloader-CQT
McAfeeDownloader-CQT
ZillyaDownloader.Avalod.Win32.1828
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanDownloader:Win32/Avalod.73d31d66
K7GWTrojan-Downloader ( 00311efe1 )
K7AntiVirusTrojan-Downloader ( 00311efe1 )
VirITTrojan.Win32.Cryptic.DTH
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.VHM
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Trojan.Agent-321737
KasperskyTrojan-Downloader.Win32.Avalod.ai
BitDefenderTrojan.Sinowal.Gen.1
NANO-AntivirusTrojan.Win32.Sinowal.ejnyz
AvastWin32:MalOb-HD [Cryp]
TencentWin32.Trojan-Downloader.Avalod.Tgil
SophosMal/Sinowal-N
F-SecureBackdoor.BDS/Sinowal.ykan
VIPRETrojan.Sinowal.Gen.1
TrendMicroTROJ_SINOWAL.SMF
EmsisoftTrojan.Sinowal.Gen.1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Avalod.cbl
WebrootW32.Trojan.Gen
VaristW32/Sinowal.AF.gen!Eldorado
AviraBDS/Sinowal.ykan
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Avalod.ai
Kingsoftmalware.kb.a.990
MicrosoftPWS:Win32/Sinowal.gen!Y
XcitiumTrojWare.Win32.TrojanDownloader.Small.MEE@4kvvmx
ArcabitTrojan.Sinowal.Gen.1
ZoneAlarmTrojan-Downloader.Win32.Avalod.ai
GDataTrojan.Sinowal.Gen.1
GoogleDetected
AhnLab-V3Trojan/Win32.Avalod.R15574
VBA32BScope.Backdoor.Reveton
TACHYONBackdoor/W32.Sinowal.98304
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_SINOWAL.SMF
RisingBackdoor.Agent!1.6A28 (CLASSIC)
YandexTrojan.DR.Sinowal.Gen.20
IkarusTrojan-PWS.Win32.Sinowal
MaxSecureDownloader.Avalod.ai
FortinetW32/Kryptik!tr
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Avalod.ai

How to remove PWS:Win32/Sinowal!Y?

PWS:Win32/Sinowal!Y removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment