Home→Descriptions→Trojan-PSW.Win32.LdPinch.akv
| Detected | Apr 10 2006 23:24 GMT |
| Released | Apr 10 2006 23:24 GMT |
| Published | Feb 15 2007 14:16 GMT |
When launching, the Trojan launches a system process, svchost.exe, and injects its code into this process. It then deletes its original file.
The code injected into the process waits for a connection to the Internet, and downloads files from the following links:
http://85.***.23.36/o/4.exe http://85.***.23.37/e/444.exe
(At the time of writing, these links were not working.)
The Trojan saves the files it has downloaded to its current directory under the following names:
csrss.exe smss.exe
The files are then launched for execution.
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
Trojan-PSW programs are designed to steal user account information such as logins and passwords from infected computers. PSW is an acronym of Password Stealing Ware.
When launched, a PSW Trojan searches system files which store a range of confidential data or the registry. If such data is found, the Trojan sends it to its “master.” Email, FTP, the web (including data in a request), or other methods may be used to transit the stolen data.
Some such Trojans also steal registration information for certain software programs.