Skip to main content
Skip to main content
Microsoft Security Intelligence
500 entries found. Displaying page 1 of 25.
Updated on Sep 06, 2012

PWS:Win64/Sinowal.gen!B is a component of the Win32/Sinowal family.

Win32/Sinowal is a family of password-stealing and backdoor trojans. These trojans may to steal sensitive information by disrupting SEcure Socket Layer (SSL) transactions (those that use certificates) from your computer. Some Sinowal components may also be able to hide or disguise themselves to avoid detection, and perform operations pretending to be trusted processes, such as "explorer.exe", to bypass your computer's security defences.

Alert level: severe
Updated on Mar 08, 2018

Microsoft Defender Antivirus detects and removes this threat.

PWS:Win32/Dofoil.D is a trojan that steals user names and passwords for certain FTP applications and Microsoft Outlook.

On March 6, 2018, behavior monitoring and machine learning technologies in Microsoft Defender Antivirus stopped a Dofoil variant (also known as Smoke Loader) that tried to infect more than 400,000 computers. The massive campaign aimed to install a cryptocurrency miner that uses victim computers' resources for coin mining purposes. Learn how artificial intelligence stopped the attack within minutes:

Behavior monitoring combined with machine learning spoils a massive Dofoil coin mining campaign

Alert level: severe
Updated on Aug 27, 2012
PWS:Win32/Kiction.A is a trojan that is specifically used to capture personal information, such as user names and passwords, and then send that information to a remote attacker.
Alert level: severe
Updated on Mar 11, 2015

Windows Defender detects and removes this threat.

This threat can steal your personal information, such as your user names and passwords. It sends the stolen information to a malicious hacker.

This threat might have got on your PC through an exploit kit or phishing attack.

Find out ways that malware can get on your PC.  

Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Lineage.AT is a Trojan that targets computers running certain versions of Microsoft Windows. The Trojan terminates security-related processes, drops a file that captures certain passwords, and runs a file that it downloads from a Web site.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Ldpinch.UM is detection for a group of general variants of Win32/Ldpinch, a family of password-stealing trojans. This trojan gathers private user data, such as passwords, from the host computer and sends the data to the attacker at a preset e-mail address. The Win32/Ldpinch trojans use their own Simple Mail Transfer Protocol (SMTP) engine or a web-based proxy for sending the e-mail, thus copies of the sent e-mail will not appear in the affected user's e-mail client.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/OnlineGames.ZDR is a generic detection for a password-stealing trojan.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Bividon.A installs trojan components that capture logon credentials, user keystrokes and mouse operations, which are then sent to a remote server. The trojan components also attempt to stop security-related services, download configuration data files and update from a remote server. They may also report their presence on the system to the remote server.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Zbot.ZY is a password stealing trojan. Win32/Zbot also contains backdoor functionality that allows unauthorized access and control of an affected machine.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Zbot.WL is a password stealing trojan. Win32/Zbot also contains backdoor functionality that allows unauthorized access and control of an affected machine.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Zbot.WZ is a password stealing trojan. Win32/Zbot also contains backdoor functionality that allows unauthorized access and control of an affected machine.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Zbot.VE is a password stealing trojan. Win32/Zbot also contains backdoor functionality that allows unauthorized access and control of an affected machine.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Zbot.UP is a password stealing trojan. Win32/Zbot also contains backdoor functionality that allows unauthorized access and control of an affected machine.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Zbot.UY is a password stealing trojan. Win32/Zbot also contains backdoor functionality that allows unauthorized access and control of an affected machine.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Zbot.MX is a password stealing trojan. Win32/Zbot also contains backdoor functionality that allows unauthorized access and control of an affected machine.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Zbot.DY is a password stealing trojan. Win32/Zbot also contains backdoor functionality that allows unauthorized access and control of an affected machine.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Zbot.NK is a password stealing trojan. Win32/Zbot also contains backdoor functionality that allows unauthorized access and control of an affected machine.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Zbot.NS is a password stealing trojan. Win32/Zbot also contains backdoor functionality that allows unauthorized access and control of an affected machine.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Zbot.NZ is a password stealing trojan. Win32/Zbot also contains backdoor functionality that allows unauthorized access and control of an affected machine.
Alert level: severe
Updated on Apr 11, 2011
PWS:Win32/Zbot.KG is a password stealing trojan. Win32/Zbot also contains backdoor functionality that allows unauthorized access and control of an affected machine.
Alert level: severe