Hi
Could be this possible undetected malware?
Have a nice day
Hi
Could be this possible undetected malware?
Have a nice day
sounds so ??? anyone?
It is apparently this pass word stealing dropper, described here: http://vil.nai.com/vil/content/v_100539.htm
Kill the process and delete the file in SafeMode and disable and enable System Restore,
Kill the following processes
parser.exe, pinchbuilder.exe, trojan.psw.ldpinch.p.exe
Remove the following files
parser.dpr, parser.exe, pinch.asm, pinch.dpr, pinch.tbp, pinchbuilder.cfg, pinchbuilder.dof, pinchbuilder.dpr, pinchbuilder.exe, pinchbuilder.res, trojan.psw.ldpinch.p.exe.
[%SYSTEM%]\msthost12.exe
[%WINDOWS%]\BTGrab.dll
[%WINDOWS%]\inf\btgrab.inf
[%PROFILE_TEMP%]\p3.exe
[%PROFILE_TEMP%]\p3g.exe
[%PROFILE_TEMP%]\Pinch;002.exe
view mapping details
Folders:
[%PROGRAM_FILES%]\windupdates
[%SYSTEM%]\lavan
[%WINDOWS%]\inet20091
view mapping details
Scan your File System for LdPinch
Registry Keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{00000000-F09C-02B4-6EC2-AD0300000000}
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mnbdipu
If a file is locked (in use by some application), its deletion will fail (the Windows will display a corresponding message).You can delete such locked files with the RemoveOnReboot utility of your av tool,
polonus
Look like a true virus undetected by avast!,kaspersky,microsoft,nod32 and more⦠Unbelievable. I suggest you do send it to the chest and for removing maybe use Malwarebytes ?
I do not believe you can do both. If it is possible and sent to the Chest, MBAM will not be able to remove it.
Similarly, if MBAM removes it, there is nothing to send to the Chest.