malware @ \AppData\Local\Thinstall\Cache\Stubs\ (pdfSaver4.exe, verclsid.exe)??

Discussion in 'Application Software' started by clone767, Sep 6, 2012.

  1. clone767

    clone767 MDL Novice

    Feb 10, 2011
    8
    0
    0
    malwarebytes found on my vista sp2 the following 2:

    C:\Users\...\AppData\Local\Thinstall\Cache\Stubs\16c45ebb594127bee8f8f44d1d6e2d3b9ff63d3\pdfSaver4.exe

    C:\Users\...\AppData\Local\Thinstall\Cache\Stubs\47479dcab2124cfb767ff48b3579f364f6c2432\verclsid.exe

    pdfSaver4.exe is a pdf-xchange file, and verclsid.exe is a windows file.

    now, since i read that many threats use known file names to camouflage themselves, i' m wondering about these two (otherwise i know most of the cracks and gens i' ve used :biggrin:), cause i'm not familiar with stub programs. :confused:

    moreover, since i use this vista sp2 setup for some years now, i see in windows explorer that verclsid.exe and pdfSaver4.exe have been both modified in october 2009, and i have to say i haven't had any terrible issues since that time. :p

    i also used jotti online multi-engine virus scanner to check these 2 files, whereby only crappy scanners like arcavir, virusbuster and clamav (this one is not even intended for windows) found a threat with both files.

    any ideas?:confused: