here is info concerning your question.
http://www.f-secure.com/v-
Glenn
Main Topics
Browse All TopicsA couple of clients have expressed concern over the Sinowal trojan as this has been in the news recently for comprising over 500k bank and credit card accounts in the US, UK, Australia and Poland.
Should McAfee detect this and remove it fully? If not, will Mbam or Combofix remove it or will HiJackThis detect it and if so, what are the signs?
Thanks,
Mike
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
here is info concerning your question.
http://www.f-secure.com/v-
Glenn
With PSW trojans etc, you won't really know just how much the pc have been compromised, if it was my pc I would just reformat and start again and change all passwords that have been used in the infected pc(using another clean pc if possible) and of course check with your bank.
It's a good idea to run MBAM and combofix as these are good scanners and with combofix script function can also remove bad entries that aren't removed in the first run(with a Helper's guide). SDFix is also another good tool.
Hijackthis scan might detect the bad entries or it's possible that it will not, Hijackthis only scans locations in the registry where malware are known to hide, but it's a good starting point for cleanup. When fixing entries in Hijackthis only disables startup entries from loading it doesn't delete files or directories except the 02 lines.
Here's another link:
http://www.threatexpe
"With PSW trojans etc, you won't really know just how much the pc have been compromised, if it was my pc I would just reformat and start again and change all passwords that have been used in the infected pc(using another clean pc if possible) and of course check with your bank."
Would Combofix, SFix and MBAM identify Sinowal by name, so I can justify a reformat.
Thanks for the ThreatExpert link - does Sinowal always make the same changes to the Registry and, if so, would it be sufficient to check these on a suspicious computer?
mikeabc27: Kaspersky 30-day free trial with identify by name.
www.kaspersky.com
Hope
-kaddict
>>>Would Combofix, SFix and MBAM identify Sinowal by name<<<
Combofix detects and removes the service/driver and legacy keys and files but won't identify it by name 'sinowal'
Combofix deleted service and legacy
-------\Legacy_{BEE6
-------
Hijackthis entry:
O23 - Service: {bee686b9-4c84-4487-9d72-9
This one has more registry keys and values.
http://www.threatex
Kaspersky 30-day free trial will identify by name."
Thanks Kaddict - I do find Kaspersky really slow on an infected PC - evaluation version anyway.
"Combofix detects and removes the service/driver and legacy keys and files but won't identify it by name 'sinowal'
Combofix deleted service and legacy
-------\Legacy_{BEE6
-------
Hijackthis entry:
O23 - Service: {bee686b9-4c84-4487-9d72-9
Thanks for pointing me in the right direction. Once the keys have been removed would you still recommend a reformat? Obviously, all passwords would changed on a clean machine.
</P>
</P>
Hi back,
It would be "the safest way" to format,
And it should be ok without formatting but there's always a risk with such powerful trojans.
If you reboot and scan again with the tools that found / repaired and find nothing it'll soothe your mind but always remember that there's a risk.
About Kaspersky being slow, of course a powerful solution uses some more power then none or something "less powerful" but on my computer (dual core, 4gb ram, vista) I can game without noticeable lag. Maybe its just because the computer ain't very powerful, and maybe because you start with some infection that causes slowdowns too.
happy to hear it helped!
-kaddict
We have identified it with this program: GMER (www.gmer.net)
Business Accounts
Answer for Membership
by: KaddictPosted on 2008-11-02 at 06:52:01ID: 22861809
My first search was about my own antivirus (Kaspersky Internet Security), and I'm happy to see that it detects and even CLEANS the Sinowal infection. A kaspersky internet security free 30-day trial will detect and clean it too. http://www.kaspersky.com/v iruswatchl ite?search _virus=sin owal& x=0&y =0&hour_of fset=-2
ut McAfee I don't know if it detects it, but will search more for you
Abo
hope it helps,
-kaddict