Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | October 2008 (4.34) |
| Protection available since | 21 December 2004 10:32:41 (GMT) |
| Last updated | 8 September 2008 10:30:42 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/LdPinch-AL is a backdoor and password stealing Trojan.
Troj/LdPinch-AL harvests passwords, computer information and account
information and emails it to a specific email address.
When first run Troj/LdPinch-AL copies itself to the Windows folder
as csrss.exe and registers itself as a service process with the
name "Syscheck" and the display name "Syscheck".
Troj/LdPinch-AL creates the helper file hdll.dll in the Windows
folder that logs keystrokes to the following path:
%WINDOWS%\winlog\<random>.ilj
Troj/LdPinch-AL will also attempt to terminate a number of anti-virus
and security related processes.
