Trojan

What is “Trojan-PSW.Win32.LdPinch.hij”?

Malware Removal

The Trojan-PSW.Win32.LdPinch.hij is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.LdPinch.hij virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan-PSW.Win32.LdPinch.hij?


File Info:

name: 7C7953616317CBD96B71.mlw
path: /opt/CAPEv2/storage/binaries/db95435625bcec73e442ff3775aabb5793a3ca8c6cee790b141ff05754d29849
crc32: AF09383A
md5: 7c7953616317cbd96b71cd4a5514a889
sha1: b2b2866c03f6939a07991b2e787b34814eaf4c48
sha256: db95435625bcec73e442ff3775aabb5793a3ca8c6cee790b141ff05754d29849
sha512: eb4857ef3d537addfe0237e9d7b5aadd650da36b59fc54e160e08c13a51da6448b1f4045d21577edf44a96165fb53243fbef739d67417a058e3d8834976affd4
ssdeep: 768:Q1eRH+9lFh0ul16sh7iQroCHpf+RjFBSuB2X6H:Q0l+Z16sh7iQroCURB0uDH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E2037574AFD41571E37386B588F3D5F26836BD627812990D60CAFB450C33B92A8A1E1E
sha3_384: 1782348ef3934bb066ac9767bb0e95751c384d7f75e71cacdf3c4e01352eca94692305a809b0d9d39016b15c6ceaf403
ep_bytes: e88c020000e957fdffff8bff558bec8b
timestamp: 2013-11-21 06:23:38

Version Info:

0: [No Data]

Trojan-PSW.Win32.LdPinch.hij also known as:

BkavW32.FamVT.GeND.Trojan
LionicTrojan.Win32.LdPinch.tntX
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.7c7953616317cbd9
CAT-QuickHealTrojan.ZbotRI.S28718216
SkyhighBehavesLike.Win32.PWSZbot.nm
ALYacTrojan.Ppatre.Gen.1
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055c6c71 )
K7GWTrojan-Downloader ( 0055c6c71 )
Cybereasonmalicious.16317c
BitDefenderThetaAI:Packer.FA70625E1F
VirITTrojan.Win32.Generic.CJD
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Downloader.Razy-9935848-0
KasperskyTrojan-PSW.Win32.LdPinch.hij
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.LdPinch.cqjkmt
SUPERAntiSpywareTrojan.Agent/Gen-Email
AvastWin32:Evo-gen [Trj]
EmsisoftTrojan.Ppatre.Gen.1 (B)
F-SecureTrojan.TR/Spy.Zbot.gdb
DrWebTrojan.DownLoader46.54522
VIPRETrojan.Ppatre.Gen.1
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Waski
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojan/PSW.LdPinch.adnc
GoogleDetected
AviraTR/Spy.Zbot.gdb
VaristW32/Zbot.AEY.gen!Eldorado
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.BFP@54u2z9
ArcabitTrojan.Ppatre.Gen.1
ZoneAlarmTrojan-PSW.Win32.LdPinch.hij
MicrosoftTrojan:Win32/Zbot.HBAI!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.LdPinch.C5600374
Acronissuspicious
McAfeeArtemis!7C7953616317
MAXmalware (ai score=83)
VBA32BScope.TrojanPSW.LdPinch
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TencentTrojan-Downloader.Win32.Waski.16000151
YandexTrojan.PWS.LdPinch!QixbX1yZ9ks
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/ZBot.GDB!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan[stealer]:Win/Waski.A

How to remove Trojan-PSW.Win32.LdPinch.hij?

Trojan-PSW.Win32.LdPinch.hij removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment