Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Nov 17, 2010 | Updated Sep 15, 2017

PWS:Win32/Sinowal.H

Detected by Microsoft Defender Antivirus

Aliases: TR/Spy.ZBot.asx.14 (Avira) Trojan-Spy.Zbot (Ikarus) Troj/Torpig-CB (Sophos) Trojan.Mebroot!gen1 (Symantec)

Summary

PWS:Win32/Sinowal.H is a component of Win32/Sinowal - a family of password-stealing and backdoor trojans.
To detect and remove this threat and other malicious software that may be installed in your computer, run a full-system scan with an up-to-date antivirus product such as the following:
 
 
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.
Additional remediation instructions for this threat
This threat may make lasting changes to a computer’s configuration that are NOT restored by detecting and removing this threat. For more information on returning an infected computer to its pre-infected state, please see the following article/s: 
Follow us