Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Dec 12, 2006 | Updated Sep 15, 2017

PWS:Win32/Ldpinch.VA

Detected by Microsoft Defender Antivirus

Aliases: Trojan-PSW.Win32.LdPinch.aze (Kaspersky) PWS-LDPinch.dr!4f8fa1f (McAfee) Infostealer.Ldpinch (Symantec) TSPY_LDPINCH.KI (Trend Micro)

Summary

PWS:Win32/Ldpinch.VA is a password-stealing trojan that masquerades as a tool to bypass Microsoft Windows Vista authentication. The trojan steals usernames, passwords and other data, and installs a backdoor on the impacted system. PWS:Win32/Ldpinch.VA will either use an existing FTP server, if found, or create its own FTP server and send the account details to the attacker. PWS:Win32/Ldpinch.VA also creates a proxy server and establishes a remote shell on the infected system, providing remote attackers the ability to create, download, upload, rename, and execute files.
Follow us