PDA

View Full Version : Does NOD32 detect Trojan-PSW.Win32.LdPinch.aze?


smith2006
December 4th, 2006, 06:27 AM
Is this statement true?

If it doesn't, will Eset add the signature?

{QUOTE-> However, the file is actually a trojan-carrier which will install Trojan-PSW.Win32.LdPinch.aze onto your PC.

BitTorrent users who posted reviews of the crack said that a number of antivirus programs detected the malware, though Norton AntiVirus and NOD32 did not. <-QUOTE}

Full article is here:

http://apcmag.com/node/4737

Marcos
December 4th, 2006, 06:39 AM
I have 280 variants detected by NOD32 in my collection so I cannot tell which one you mean. We'll need someone to send it to support @ eset.com

smith2006
December 4th, 2006, 06:51 AM
{QUOTE-> I have 280 variants detected by NOD32 in my collection so I cannot tell which one you mean. Please send it to support @ eset.com with a link to this thread. <-QUOTE}

I came across this article in another forum & I thought it is good to clarify with Eset.

I cannot provide you with a virus sample as I don't download anything from BitTorrent.

Perhaps you want to check with the author of this article dated 3rd December 2006?

Here are the information available at Sunbelt & Kaspersky:

http://research.sunbelt-software.com/threatdisplay.aspx?name=Trojan-PSW.Win32.LdPinch.aze&threatid=90833

http://www.viruslist.com/en/viruses/encyclopedia?virusid=137786

kjempen
December 4th, 2006, 08:50 AM
NOD32 doesn't detect this trojan, but I've sent the sample to ESET now.

{QUOTE-> Time Module Event User
04.12.2006 14:49:13 Kernel The file 'D:\xxx\xxx\Windows Vista All Versions Activation 21.11.06.exe' has been sent to ESET's labs for analysis.
<-QUOTE}

smith2006
December 4th, 2006, 08:53 AM
{QUOTE-> NOD32 doesn't detect this trojan, but I've sent the sample to ESET now. <-QUOTE}

Thank you for the information. :)

Actually this trojan has been around since Oct 07 2006.

Hopefully Marcos will take action fast.

..............................................................

Marcos,

Please let us know the status.

Bubba
December 4th, 2006, 09:14 AM
{QUOTE-> Hopefully Marcos will take action fast. <-QUOTE}Eset will take action as they deem necessary and additions of a sample-signature into the database is made on a need-to basis as mentioned here (http://www.wilderssecurity.com/showthread.php?p=198429#post198429). The action users should take has been mentioned not only in this thread but numerous other threads in this forum which is to send a suspect file to support @ eset.com. Bottom line is and as noted in past closed\removed threads of this type....these type threads are neither support issue related or helpful.

Having said that....this thread is now closed.

Regards,
Bubba

Marcos
December 4th, 2006, 09:18 AM
I've found some, but could you please submit it to samples @ eset.com with a link to this thread in the subject to make sure I check the right file?