English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Trojan-PSW.Win32.LdPinch.a

Detected Dec 23 2008 15:00 GMT
Released Dec 23 2008 22:42 GMT
Published Sep 10 2003 07:51 GMT

Manual description Auto description
This description was created by experts at Kaspersky Lab. It contains the most accurate information available about this program.

Technical Details

This family of Trojans steals user passwords.

When launching, the Trojan writes the following value to the system registry.

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    putil = %windir%\%file name%

This ensures that the Trojan will be run every time the system is started.

It then copies itself to the Windows folder, and launches itself from there, deleting the original file.

The Trojan harvests information about the system (operating system, configuration etc.) and passwords for a range of services and applications, including RAS, POP3, IMAP, ICQ, FTP etc.

The information collected is encoded using MIME (Base64) and sent to the Trojan's author by email, using an SMTP server with an IP address which is coded in the Trojan's body.


Bookmark and Share
Share
Trojan-PSW

Trojan-PSW programs are designed to steal user account information such as logins and passwords from infected computers. PSW is an acronym of Password Stealing Ware.

When launched, a PSW Trojan searches system files which store a range of confidential data or the registry. If such data is found, the Trojan sends it to its “master.” Email, FTP, the web (including data in a request), or other methods may be used to transit the stolen data.

Some such Trojans also steal registration information for certain software programs.


Other versions

Aliases

Trojan-PSW.Win32.LdPinch.a (Kaspersky Lab) is also known as:

  • Trojan.PSW.LdPinch.a (Kaspersky Lab)
  • Trojan.PSW.LdPinch (Kaspersky Lab)
  • Trojan: Generic Downloader.x (McAfee)
  • Mal/Generic-A (Sophos)
  • VirTool:Win32/Bober.A (MS(OneCare))
  • Trojan.PWS.LDPinch.1941 (DrWeb)
  • Win32/TrojanDownloader.FakeAlert.GC trojan (Nod32)
  • Trojan.PWS.LDPinch.TRO (BitDef7)
  • Win32:Trojan-gen (AVAST)
  • Trojan-PWS.Win32.LdPinch (Ikarus)
  • Downloader.Generic7.ATRW (AVG)
  • TR/Crypt.XPACK.Gen (AVIRA)
  • Infostealer (NAV)
  • W32/LdPinch.AXKK (Norman)
  • Generic Downloader.x (NAI)
  • Trojan-PSW.Win32.LdPinch.afqq [AVP] (FSecure)
  • TROJ_Generic.DIT (TrendMicro)
  • Trojan.Fakealert (Sunbelt)