Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | August 2005 (3.96) |
| Protection available since | 30 May 2005 06:21:16 (GMT) |
| Last updated | 21 June 2005 18:59:57 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
Change any data that may have become compromised.
More Information
Troj/LdPinch-BA is a password-stealing Trojan that will search the host for information related to the following applications/services:
Password stored in BatMail and The Bat FTP client
Mirabilis ICQ
Trillian Passwords
Remote Access Service (RAS)
CuteFTP password
WS_FTP password
Opera/Mozilla stored password
Internet Explorer password manager
Windows NT username
Local phone book information
The Trojan will then submit this information to a preconfigured email address. Troj/LdPinch-BA includes functionality to silently download, install and run new software and send notification messages to remote locations.
When Troj/LdPinch-BA is installed the following files are created:
<System>\cssrs.exe
<Windows>\vr_sys.dll
The following registry entry is created to run code exported by the Trojan library on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
System
{CC570D7A-39DB-4431-837B-AF18D44CAB5E}
The file vr_sys.dll is registered as a COM object, creating registry entries under:
HKCR\CLSID\{CC570D7A-39DB-4431-837B-AF18D44CAB5E}
