Trojan.PWS.Sinowal.AK
| Alert Level : | veryhigh |
| Discovered: | 2006Aug25 |
| Tag: | Trojan PWS |
| Discoverer and Source: | http://www.bitdefender.com/ |
Malware Behavior and Technical Description
Presence of IBMXXXXX.EXE and IBMYYYYY.DLL (5 digit numbers) in %SystemDir%\\..\\temp or %CommonFilesDir%\\Microsoft Shared\\Web Folders.
Presence of one of the following:
$_3472452.EXEin the mentioned folders can also be a sign of this malware.
$_2341233.TMP
$_2341234.TMP
$_2341235.TMP
The trojan drops 3 files in %SystemDir%\\..\\temp or in %CommonFilesDir%\\Microsoft Shared\\Web Folders, named IBM
Removal Trojan.PWS.Sinowal.AK instructions:
Please let BitDefender disinfect your files.
Need help? Live computer support via remote at SupportSpace |

