Solutions Buy Download Information Partners Support Forum About us «Doctor Web» company news (RSS channel)

Beware of Trojan.PWS.LDPinch.1061 and take care of your passwords

July 28, 2006

Virus monitoring service of Doctor Web, Ltd. informs on a new modification of a Trojan program propagated via ICQ, classified by Dr.Web as Trojan.PWS.LDPinch.1061. A received message invites a user to have a look at a "funny flash" and the link where this "flash is stored. The downloaded file (oPreved.exe) has an icon of a flash movie, but is a password-stealing Troj.

Description

  • When oPreved.exe is run (The file size is 354 304 bytes. It is detected by Dr.Web Anti-virus as Trojan.PWS.LDPinch.1061), the following files are created:
    %System%\Expllorer.exe (223 392 bytes detected by Dr.Web Anti-virus as Win32.HLLW.MyBot)
    \%windir%\temp\xer.exe (223 392 bytes detected by Dr.Web Anti-virus as Win32.HLLW.MyBot)
    temporary file C:\a.bat
  • Expllorer.exe creates the following keys in the system registry:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
    "Shel"=Expllorer.exe

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
    "Shel"=Expllorer.exe

  • The passwords are being stolen via script at hxxp://220web.ru. All passwords are being collected from the system — icq, ftp, mailservices, dialup, trilian, miranda, etc.
  • Trojan.PWS.LDPinch tries to evade firewalls – both inbuilt into OS and those of independent developers.
  • Doctor Web, Ltd. calls all users to never open links received in ICQ messages from unknown addressees. If your computer has been infected with Trojan.PWS.LDPinch, we recommend to disconnect the computer from the local network and\or Internet and scan it with Dr.Web®. You can also check your computer for free and cure it, if necessary, with Dr.Web CureIt!.

    IMPORTANT! Change all passwords in your computer.


         Other news

    2008-09-05Doctor Web against extortion
    2008-09-04One of the key players of Telecom market in Smolensk adopts Dr.Web AV-Desk
    2008-09-02Subscribers of leading ISP in Belgorod shielded by Dr.Web AV-Desk
    2008-09-01August virus activity review from Doctor Web
    2008-08-28Intersvyaz starts public testing of the Dr.Web anti-virus service
    2008-08-25Leading Russian manufacturer of weapons chooses Dr.Web
    2008-08-22Comprehensive protection from Dr.Web for subscribers of Teleos-1
    2008-08-19Improved version of GUI-scanner for Dr.Web for Windows released
    2008-08-18Dr.Web for Windows standard of anti-virus protection for executive bodies of Permskiy Kray
    2008-08-13Doctor Web has released a free decryption utility to counteract the new extortion Trojan.Encoder.19
    2008-08-13Dr.Web AV-Desk anti-virus covering for subscribers of Bashinformsvyaz
    2008-08-08Doctor Web: statement on Virus Bulletin comparative reviews
    2008-08-08Telnet secures its subscribers with Dr.Web anti-virus
    2008-08-05July 2008 virus activity review by Doctor Web
    2008-08-01Dr.Web AV-Desk now in Ulyanovsk region
    2008-07-31Dr.Web AV-Desk deployment summary by Eltel
    2008-07-31Dr.Web AV-Desk moves on in Moscow region
    2008-07-24Three regions of Moscow protected by Dr.Web AV-Desk
    2008-07-23Doctor Web releases new LinkChecker for Mozilla Firefox
    2008-07-22Dr.Web AV-Desk chosen by ISP "Hazynet" in Krasnoyarsk
    2008-07-18Doctor Web, Ltd. releases Active Directory installer for Dr.Web Enterprise Suite 4.44.3
    2008-07-16Dr.Web anti-virus now accessible to subscribers of Infocentre
    2008-07-16Doctor Web launches the beta-testing of Dr.Web for MIMEsweeper
    2008-07-15Anti-virus protection is delivered to subscribers of Lintecs by Dr.Web AV-Desk
    2008-07-15”Nauka-Sviaz” deployed Dr.Web AV-Desk
    2008-07-15Dr.Web AV-Desk adopted by three ISPs in Krasnoyarsk
    2008-07-15Dr.Web will protect Internet users of GlavSET
    2008-07-14Dr.Web anti-virus is the new service for subscribers of SZT
    2008-07-14Dr.Web AV-Desk deployed by MajaNet in Estonia
    2008-07-12Dr.Web AV-Desk will secure networks of Maginfo
    2008-07-11Corrected verson of Dr.Web SpIDer Guard 4.44 released
    2008-07-11Dr.Web for IBM Lotus Domino validated by IBM

       Information



       My five cents
     
    What is the screen size of your monitor?

    12''
    14''
    15''
    17''
    19''
    more than 19''
    other



    Doctor Web, Ltd. © 2008 Doctor Web, Ltd. - a Russian company developing and distributing Dr.Web® Anti-virus solutions.
    Our customers can be found among home users from all regions of the world and in large enterprises, small companies and nationwide corporations. We thank all of them for support and long-term devotion to our product. State certificates and awards received by the Dr.Web Anti-virus, as well as the geography of our users are the best evidence of exceptional trust to the products created by the talented Russian programmers.