Sophos

Troj/LdPinch-BA

Aliases
  • Trojan.LdPinch-19
  • TROJ_PSWPINCH.A
  • W32/Spybot.KJP
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from August 2005 (3.96)
Protection available since 30 May 2005 06:21:16 (GMT)
Last updated 21 June 2005 18:59:57 (GMT)
Detected by All Sophos products

Action

Please follow the instructions for removing Trojans.

Change any data that may have become compromised.

More Information

Troj/LdPinch-BA is a password-stealing Trojan that will search the host for information related to the following applications/services:

Password stored in BatMail and The Bat FTP client
Mirabilis ICQ
Trillian Passwords
Remote Access Service (RAS)
CuteFTP password
WS_FTP password
Opera/Mozilla stored password
Internet Explorer password manager
Windows NT username
Local phone book information

The Trojan will then submit this information to a preconfigured email address. Troj/LdPinch-BA includes functionality to silently download, install and run new software and send notification messages to remote locations.

When Troj/LdPinch-BA is installed the following files are created:

<System>\cssrs.exe
<Windows>\vr_sys.dll

The following registry entry is created to run code exported by the Trojan library on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
System
{CC570D7A-39DB-4431-837B-AF18D44CAB5E}

The file vr_sys.dll is registered as a COM object, creating registry entries under:

HKCR\CLSID\{CC570D7A-39DB-4431-837B-AF18D44CAB5E}

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer