The malicious program is made happen through a new tool of Google that serves to lower music from multiple sources and frees of virus.
One is Win32/PSW.LdPinch.NBL, a troyano that is made happen through a MP3 tool search of Google. This it is being distributed through a site of Internet, which has been promoted in diverse forums.
The tool is well-known like Google MP3 Search Tool, theoretically he would be able to look for and to unload archives MP3 from multiple sources as no other product of unloading and interchange of archives could do it.
The troyano, the being installed by the user, does not show any window, but that begins to compile passwords and lodged data of access in the rigid disk, storing them in a file c:pass.bin.
This file is sent to a direction of electronic mail of the supposed author of the troyano. The author malicious code has published the direction of the false site in several recognized forums and sites related to interchange of archives.
The troyano is detected by NOD32, the product antivirus of Eset, with the Win32/PSW.LdPinch.NBL name and according to Eset, NOD32 are one of the few antivirus able to detect them until the moment in complete form.
Source