Attention: We have transitioned to a new AAD or Microsoft Entra ID from the week of May 20, 2024. In case your tenant requires admin consent, please refer to this document located at Overview of user and admin consent - Microsoft Entra ID | Microsoft Learn and grant access to App ID: 6ba09155-cb24-475b-b24f-b4e28fc74365 with graph permissions for Directory.Read.All and User.Read for continued access. While the app may appear unverified, you can confirm its legitimacy by verifying the App ID provided.
We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
VirTool:WinNT/Sinowal.A
Detected by Microsoft Defender Antivirus
Aliases: No associated aliases
Summary
VirTool:WinNT/Sinowal.A is a complex component associated with command and control functions and the advanced stealth features of the Win32/Sinowal family.
Win32/Sinowal is a family of password-stealing and backdoor trojans. These trojans may try to find a cryptographic certificate on the infected computer and install a certificate on the computer to mislead users in Secure Sockets Layer (SSL) Web transactions. Some Win32/Sinowal components may also use advanced stealth functionality, or try to perform certain operations from the context of a trusted process such as explorer.exe in order to bypass local software-based firewalls.
If you suspect that your system has been affected with this malware, you may need to write a known-good copy of the Master Boot Record back to the disk to prevent the malware's driver from being loaded on the next reboot. This can be accomplished by using the Windows Recovery Console.
Please see the following articles for further detail on using the Windows Recovery Console:
- Description of the Windows XP Recovery Console (Use the 'fixmbr' command)
- How to use the Bootrec.exe tool in the Windows Recovery Environment to troubleshoot and repair startup issues in Windows Vista (Use the /FixMbr option)
When the MBR has been successfully restored, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, see http://www.microsoft.com/protect/computer/viruses/vista.mspx.