Threat Database Backdoors Trojan-PWS.Win32.LdPinch

Trojan-PWS.Win32.LdPinch

By LoneStar in Backdoors

There is a group of Trojans known with the generic name Trojan-PWS.Win32.LdPinch. Trojans belonging to the Trojan-PWS.Win32.LdPinch category enter the system through a "backdoor" and are known to record personal information and relay it to a third party. The Trojan-PWS.Win32.LdPinch Trojan has also been known to attack firewalls and legitimate security programs. Trojan-PWS.Win32.LdPinch does this so that it can relay stolen data to Trojan-PWS.Win32.LdPinch's creators. The Trojan-PWS.Win32.LdPinch Trojans have received some attention in the gaming community. This is because certain computer games have been erroneously diagnosed as a Trojan-PWS.Win32.LdPinch Trojan by some anti-virus tools. Regardless of this, the Trojan-PWS.Win32.LdPinch Trojan is an extremely serious infection. Do not take any infection lightly.

Even if there is a reason for you to believe that it is a false positive, you should perform several system-wide scans to be sure. The Trojan-PWS.Win32.LdPinch Trojan doesn't limit itself to wrecking your computer. By stealing your personal information, Trojan-PWS.Win32.LdPinch can also severely affect your life. Trojan-PWS.Win32.LdPinch can do this by placing your bank account information and personal passwords in the hands of criminals. Unscrupulous individuals can use this information to steal your identity or worse.

What Do All Trojan-PWS.Win32.LdPinch Trojans Have in Common?

As was mentioned in the beginning, Trojan-PWS.Win32.LdPinch is really a name given to a whole group of Trojans. Because of this, they all have different features and ways of infecting your system. However, they all have some characteristics in common. If you see any of the following behaviors on your computer, it is likely that you have a Trojan-PWS.Win32.LdPinch Trojan infection.

- You may be infected by the Trojan-PWS.Win32.LdPinch Trojan if there are new and unfamiliar processes in your Task Manager. There may also be an unusually high level of memory use, and your system resources are strained. It isn't enough to simply stop the active processes related to the Trojan-PWS.Win32.LdPinch Trojan. One of the first things this intruder will do is alter your registry, so that Trojan-PWS.Win32.LdPinch will load at start-up. Because of this, you should assume that the Trojan-PWS.Win32.LdPinch Trojan is recording and relaying your moves from the very moment you start up your operating system.
- If you notice that there was an attempt to retrieve private information from your system, you may be infected by the Trojan-PWS.Win32.LdPinch Trojan.

Email addresses and passwords are especially at risk if you have this infection on your computer. As long as the Trojan-PWS.Win32.LdPinch Trojan is on your computer, anything on your hard drive is at risk for being divulged.

- Users with the Trojan-PWS.Win32.LdPinch Trojan may notice extremely high spikes of usage of system resources. This has been associated with a built-in email client in some versions of Trojan-PWS.Win32.LdPinch. Trojan-PWS.Win32.LdPinch will attempt to email your contacts using this email client, often using your email address in the sender field. These will not appear in your "Sent" box. However, your contacts may let you know if they have received unusual spam email from your address.

- A symptom of a Trojan-PWS.Win32.LdPinch Trojan infection is a file in your Windows folder that refuses to go away. It usually will have a random name, and sometimes will be hidden. To see it, set your preferences so that your computer shows you hidden files. Some versions of Trojan-PWS.Win32.LdPinch can replicate themselves, like worms. That is why you must be careful with USB devices and other external storage units.

The Problem with Trojan-PWS.Win32.LdPinch False Positives

There have been some false positive problems with the computer game Armed and Dangerous on Steam. This false positive has been detected on many reliable anti-virus applications from different manufacturers. To reduce the chances of a false positive report of a Trojan-PWS.Win32.LdPinch Trojan infection, make sure to keep your security applications updated. In case your game is still showing up as a Trojan-PWS.Win32.LdPinch Trojan, most scanners will allow you to permit exceptions. However, you should treat any Trojan-PWS.Win32.LdPinch infection alert as genuine at first, since false positives are still very rare.

File System Details

Trojan-PWS.Win32.LdPinch may create the following file(s):
# File Name Detections
1. %Windir%\cftnom.exe
2. %AppData%\lssas.exe
3. %AppData%\conima.exe
4. %AppData%\k4m5g.exe
5. %AppData%\Input.bat
6. %AppData%\xfpk9wycw.exe
7. %AppData%\oyti57l58.exe
8. %AppData%\manager.exe
9. %AppData%\69b5mxsh4.exe
10. %AppData%\Plug.bat
11. %System%\lips\hotr.exe
12. %AppData%\rgnrpx9j.exe
13. %AppData%\xi1q2460i.exe
14. %AppData%\m2hy2z7a.exe
15. %AppData%\fjgoq0fgn.exe
16. %AppData%\MouseDriver.bat
17. %Windir%\cftnom.bat
18. %AppData%\mlog
19. %AppData%\LocalAccountAuthority.ba
20. %AppData%\ylog
21. %AppData%\addons.dat
22. %Temp%\x1jkfdsal.inf
23. %AppData%\inlog
24. %AppData%\rv02se.log
25. %Temp%\00000000

Registry Details

Trojan-PWS.Win32.LdPinch may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Input Manager\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Local Account Authority Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Plug Manager\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\System Updater
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Local Account Authority Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Local Account Authority Service\Security HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MouseDriver
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Enigma Protector\D98C1DD404B2008F-980980E97E42F8EC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Input Manager
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MouseDriver\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Plug Manager
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Input Manager
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Input Manager\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Plug Manager
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\System Updater
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\System Updater\Security
HKEY_CURRENT_USER\Software\shmr
HKEY_LOCAL_MACHINE\SOFTWARE\shmr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{519AEC14-99E3-92B2-986E-F62944F7066D}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MouseDriver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Local Account Authority Service\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\System Updater\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MouseDriver\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Plug Manager\Security
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History
HKEY_CURRENT_USER\Software\Enigma Protector
HKEY_CURRENT_USER\Software\Enigma Protector\D98C1DD404B2008F-980980E97E42F8EC\D98C1DD404B2008F-980980E97E42F8EC

Trending

Most Viewed

Loading...