Malware

PWS:Win32/Ldpinch.CQ malicious file

Malware Removal

The PWS:Win32/Ldpinch.CQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Ldpinch.CQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PWS:Win32/Ldpinch.CQ?


File Info:

name: 58D13959B142FABA1A54.mlw
path: /opt/CAPEv2/storage/binaries/115fb65ebd403c4651b6d99d643b0ce42b790c1bbec09f497880c728ecbd415d
crc32: 597E46D9
md5: 58d13959b142faba1a54bf97ac5409a7
sha1: 89514bd99f55a031d07e629eff0b8662da5e0d04
sha256: 115fb65ebd403c4651b6d99d643b0ce42b790c1bbec09f497880c728ecbd415d
sha512: 513e93bc053e049122b0deca46dd8deb4bcf50ef06b60e06f716930773b65403ff9269195816f3ce1f7c4fdc3747858b37244fbfa8fe47fe4c490f402b30759c
ssdeep: 6144:iD/llOmAMQw3KdbX+GRhCfvStl4koQCF2I3K:iDvBAdwaF+SCfvSf4kyD3K
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1315423E91B98EA50EBCD403A699BC3312BFEDDA6668D5FC31474631D7C623318DA112C
sha3_384: b50266b72e8d376946c07a3f471fc161b57cea312ba3511dfb6914644f2a7858cb4af974b044fb0ef49797e275c6ff1e
ep_bytes: b8604f4c005064ff3500000000648925
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

PWS:Win32/Ldpinch.CQ also known as:

BkavW32.Common.CC1E308F
AVGWin32:Spyware-gen [Spy]
DrWebTrojan.Inject1.14975
MicroWorld-eScanTrojan.GenericKD.44868063
FireEyeGeneric.mg.58d13959b142faba
SkyhighBehavesLike.Win32.Downloader.dc
McAfeeArtemis!58D13959B142
Cylanceunsafe
ZillyaTrojan.Banker.Win32.37245
SangforBanker.Win32.Chepro.V5in
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanBanker:Win32/ChePro.5d11a652
K7GWTrojan ( 7000000f1 )
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderThetaGen:NN.ZedlaF.36802.rm4aaW7IxHjG
VirITTrojan.Win32.Scar.LP
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Banker.UKZ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Banker-18811
KasperskyTrojan-Banker.Win32.ChePro.ink
BitDefenderTrojan.GenericKD.44868063
NANO-AntivirusTrojan.Win32.Banker.cpdty
SUPERAntiSpywareTrojan.Agent/Gen
AvastWin32:Spyware-gen [Spy]
TencentWin32.Trojan-Banker.Chepro.Hjgl
EmsisoftTrojan.GenericKD.44868063 (B)
F-SecureTrojan.TR/ATRAPS.Gen
VIPRETrojan.GenericKD.44868063
TrendMicroTSPY_BANCOS.AZY
Trapminemalicious.high.ml.score
SophosMal/Bancos-AY
JiangminTrojan/Banker.anf
VaristW32/Risk.RFFT-8103
AviraTR/ATRAPS.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Banker]/Win32.ChePro
KingsoftWin32.Troj.Banker.a
MicrosoftPWS:Win32/Ldpinch.CQ
XcitiumMalware@#1g1bolnm70h1e
ArcabitTrojan.Generic.D2ACA1DF
ViRobotTrojan.Win32.PECompact.288256
ZoneAlarmTrojan-Banker.Win32.ChePro.ink
GDataTrojan.GenericKD.44868063
GoogleDetected
AhnLab-V3Trojan/Win32.Banker.R15949
VBA32TrojanBanker.ChePro
ALYacTrojan.GenericKD.44868063
PandaTrj/Banker.MJH
TrendMicro-HouseCallTSPY_BANCOS.AZY
RisingSpyware.Banker!8.8D (CLOUD)
YandexTrojan.GenAsa!EokFULOJYjU
IkarusTrojan-Spy.Win32.Banker.anv
MaxSecureTrojan.Malware.1780929.susgen
DeepInstinctMALICIOUS
alibabacloudTrojan[stealer]:Win/Banker.UKZ

How to remove PWS:Win32/Ldpinch.CQ?

PWS:Win32/Ldpinch.CQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment