Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Aug 04, 2009 | Updated Sep 15, 2017

VirTool:WinNT/Sinowal.F

Detected by Microsoft Defender Antivirus

Aliases: Win-Trojan/Sinowal.352256.BT (AhnLab) Win32/Mebroot.BO (ESET) Backdoor.Win32.Sinowal.ayp (Kaspersky) PWS-JA.gen.c (McAfee) Trj/Sinowal.DW (Panda) Mal/Sinowa-A (Sophos) Trojan.Mebroot (Symantec) Trojan.DR.Sinowal.Gen.12 (VirusBuster)

Summary

Trojan:WinNT/Sinowal.F is a complex driver component associated with command and control functions and the advanced stealth features of the Win32/Sinowal family. WinNT/Sinowal.F may download other malware from a predefined Web site.
 
Win32/Sinowal is a family of password-stealing and backdoor trojans. These trojans may try to find a cryptographic certificate on the infected computer and install a certificate on the computer to mislead users in Secure Sockets Layer (SSL) Web transactions. Some Win32/Sinowal components may also use advanced stealth functionality, or try to perform certain operations from the context of a trusted process such as explorer.exe in order to bypass local software-based firewalls.
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, see http://www.microsoft.com/protect/computer/viruses/vista.mspx.
Follow us