Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 16 December 2004 04:37:20 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
Change any data that may have become compromised.
More Information
Troj/LdPinch-AK is a backdoor and password stealing Trojan.
Troj/LdPinch-AK harvests passwords, computer information and account information which it emails to a specific email address.
When first run Troj/LdPinch-AK copies itself to the Windows folder as csrss.exe and creates the following registry entry:
HKCR\CLSID\{81382AEF-4F23-4C63-B0CC-13D4B60E1DFB}\InProcServer32
*
syslg.dll
Troj/LdPinch-AK also creates a helper DLL called syslg.dll into the Windows folder which acts as a simple loader for the Trojan and can be removed along with the following registry entry:
The Trojan also listens for network connections and may spawn a remote command prompt when a connection is established.
