Could be this possible undetected malware

Hi :slight_smile:

Could be this possible undetected malware?

Virustotal: http://www.virustotal.com/sl/analisis/c873c946255237b2a3bc42148ea4678a1b9678506e1d6a48ddedf5e90d9b0885-1265132461

Have a nice day :slight_smile:

sounds so ??? anyone?

It is apparently this pass word stealing dropper, described here: http://vil.nai.com/vil/content/v_100539.htm
Kill the process and delete the file in SafeMode and disable and enable System Restore,

Kill the following processes
parser.exe, pinchbuilder.exe, trojan.psw.ldpinch.p.exe
Remove the following files
parser.dpr, parser.exe, pinch.asm, pinch.dpr, pinch.tbp, pinchbuilder.cfg, pinchbuilder.dof, pinchbuilder.dpr, pinchbuilder.exe, pinchbuilder.res, trojan.psw.ldpinch.p.exe.

[%SYSTEM%]\msthost12.exe
[%WINDOWS%]\BTGrab.dll
[%WINDOWS%]\inf\btgrab.inf
[%PROFILE_TEMP%]\p3.exe
[%PROFILE_TEMP%]\p3g.exe
[%PROFILE_TEMP%]\Pinch;002.exe

view mapping details
Folders:
[%PROGRAM_FILES%]\windupdates
[%SYSTEM%]\lavan
[%WINDOWS%]\inet20091

view mapping details

Scan your File System for LdPinch

Registry Keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{00000000-F09C-02B4-6EC2-AD0300000000}
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mnbdipu

If a file is locked (in use by some application), its deletion will fail (the Windows will display a corresponding message).You can delete such locked files with the RemoveOnReboot utility of your av tool,

polonus

Look like a true virus undetected by avast!,kaspersky,microsoft,nod32 and more… Unbelievable. I suggest you do send it to the chest and for removing maybe use Malwarebytes ? :wink:


I do not believe you can do both. If it is possible and sent to the Chest, MBAM will not be able to remove it.

Similarly, if MBAM removes it, there is nothing to send to the Chest.

:wink: