Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Spyware Info
October 22, 2007

Posted on 10/22/2007 8:55:41 AM PDT by BulletBobCo

Yesterday morning, Spy Sweeper detected a trojan called "ldpinch" on my computer. It was quarantined and I deleted it. It showed up again today so I called Webroot, which makes Spy Sweeper. I was on hold for over an hour. Customer service told me that it is a false positive, that it probably came from Windows updates for Windows Messenger. They should have new definitions to correct this false positive in the next 24 hours. Customer service said that they have been swamped with calls on this issue and that is why there is such a long wait. So now I have to apologize to the kids because I thought they were the ones that downloaded this bugger.


TOPICS:
KEYWORDS: spysweeper; spyware

1 posted on 10/22/2007 8:55:42 AM PDT by BulletBobCo
[ Post Reply | Private Reply | View Replies]

To: BulletBobCo

This needs to be in Breaking News...


2 posted on 10/22/2007 8:57:37 AM PDT by JRios1968 (Faith is not believing that God can. It is knowing that God will. - Ben Stein)
[ Post Reply | Private Reply | To 1 | View Replies]

To: JRios1968

When I read what the real ldpinch can do, I got a bit excited.


3 posted on 10/22/2007 8:58:49 AM PDT by BulletBobCo
[ Post Reply | Private Reply | To 2 | View Replies]

To: BulletBobCo
Please post the ENTIRE name of the file:


Home / Viruses / Virus Encyclopedia / Malware Descriptions / Trojan Programs / PSW Trojans Trojan-PSW.Win32.LdPinch.ab

Other versions: .bik, .rn, .ur, .zm

Aliases Trojan-PSW.Win32.LdPinch.a (Kaspersky Lab) is also known as: Trojan.PSW.LdPinch.a (Kaspersky Lab), PWS-Dimon (McAfee), PWSteal.Trojan (Symantec), Trojan.PWS.LDPinch (Doctor Web), PWS:Win32/LdPinch.A (RAV), PSW.Ldpinch.E (Grisoft), Trojan.PWS.LdPinch.A (SOFTWIN), Trojan Horse (Panda), NewHeur_PE (Eset) Description added Sep 10 2003 Behavior PSW Trojan

Technical Details

This family of Trojans steals user passwords.

When launching, the Trojan writes the following value to the system registry.

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] putil = %windir%\%file name% This ensures that the Trojan will be run every time the system is started.

It then copies itself to the Windows folder, and launches itself from there, deleting the original file.

The Trojan harvests information about the system (operating system, configuration etc.) and passwords for a range of services and applications, including RAS, POP3, IMAP, ICQ, FTP etc.

The information collected is encoded using MIME (Base64) and sent to the Trojan's author by email, using an SMTP server with an IP address which is coded in the Trojan's body.

4 posted on 10/22/2007 9:01:57 AM PDT by Gorzaloon (Food imported from China = "Cesspool + Flavor-Straw")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gorzaloon

All I know is from this link

http://research.spysweeper.com/search.php?serialnumber=ldptrj14&lang=en&loc=USA&category=Trojan%20Horse&rc=1


5 posted on 10/22/2007 9:04:39 AM PDT by BulletBobCo
[ Post Reply | Private Reply | To 4 | View Replies]

To: BulletBobCo

ldpinch?

New York Times virus?


6 posted on 10/22/2007 9:09:29 AM PDT by VeniVidiVici (No buy China!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BulletBobCo

That reminds me - it’s time to run Spybot and Ad-Aware.


7 posted on 10/22/2007 9:11:21 AM PDT by PAR35
[ Post Reply | Private Reply | To 1 | View Replies]

To: BulletBobCo

SpySweeper is available, free, to users of ATT.net.

I have not downloaded it yet. What’s your opinion of it?

TIA.


8 posted on 10/22/2007 9:15:38 AM PDT by ButThreeLeftsDo (Donate.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: PAR35
There's also something else out there called Advanced Windows Care 2....I installed it upon the recommendation of those that know a whole lot more about this stuff than I; so far, so good.

It's freeware, and seems to be a nice additional tool.

9 posted on 10/22/2007 9:16:05 AM PDT by ErnBatavia (...forward this to your 10 very best friends....)
[ Post Reply | Private Reply | To 7 | View Replies]

To: ErnBatavia

Bump for later


10 posted on 10/22/2007 9:18:45 AM PDT by jonascord (Hurray! for the Bonny Blue Flag that bears the Single Star!)
[ Post Reply | Private Reply | To 9 | View Replies]

To: ButThreeLeftsDo

I have had Spy Sweeper for about 4 years and I’m pleased with it. They did have a couple of versions that did not work well early on but I have had no problems lately. They are located in the Peoples Republic of Boulder, Colorado.


11 posted on 10/22/2007 9:25:14 AM PDT by BulletBobCo
[ Post Reply | Private Reply | To 8 | View Replies]

To: BulletBobCo

Thanks.


12 posted on 10/22/2007 9:26:22 AM PDT by ButThreeLeftsDo (Donate.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: BulletBobCo
Please consider downloading and installing the free version of SuperAntiSpyware.

It will find and fix problems (FOR GOOD) that most other anti-spyware's can't or don't.

Make sure you download the latest definition updates before scanning your machine.

Good luck.

13 posted on 10/22/2007 9:41:11 AM PDT by jdm
[ Post Reply | Private Reply | To 1 | View Replies]

To: BulletBobCo

“ldpinch” as in “I’d pinch”?

Sounds like something one might acquire from a fetish porn site.


14 posted on 10/22/2007 9:42:34 AM PDT by TomGuy
[ Post Reply | Private Reply | To 1 | View Replies]

To: BulletBobCo

BTTT


15 posted on 10/22/2007 10:24:29 AM PDT by USNA74
[ Post Reply | Private Reply | To 1 | View Replies]

To: jdm

agreed. hands down it’s the best out there.


16 posted on 10/22/2007 10:27:59 AM PDT by Bommer (“He that controls the spice controls the universe!” (unfortunately that spice is Nutmeg!)
[ Post Reply | Private Reply | To 13 | View Replies]

To: jdm

Thanks for posting this. I have had a ton of problems lately with adware, and am illiterate when it comes to computing. So, I asked for, and received, freeper help, followed it, and think it’s straightened out.

I never used to read the techie threads on FR, but now check them out!!!

Grammy, pinging you on this one.


17 posted on 10/22/2007 10:32:43 AM PDT by girlangler (Fish Fear Me)
[ Post Reply | Private Reply | To 13 | View Replies]

To: LucyJo

Hey LucyJo,

I remembered your past freepmail (don’t remember if I ever answered it, it’s crazy hectic here right now). Be sure to read post #13.


18 posted on 10/22/2007 10:34:46 AM PDT by girlangler (Fish Fear Me)
[ Post Reply | Private Reply | To 13 | View Replies]

To: ButThreeLeftsDo

I find the spyware part works pretty well. I do have a problem when I upgraded to the virus package...my email quit working. I had to re-set up my email on another machine.


19 posted on 10/22/2007 10:38:40 AM PDT by Cyber Liberty (Don’t trust anyone who can’t take a joke. [Congressman BillyBob])
[ Post Reply | Private Reply | To 8 | View Replies]

To: BulletBobCo

If you need something to worry about, worry about “Storm.”


20 posted on 10/22/2007 10:42:09 AM PDT by js1138
[ Post Reply | Private Reply | To 1 | View Replies]

To: BulletBobCo
Customer service told me that it is a false positive, that it probably came from Windows updates for Windows Messenger. They should have new definitions to correct this false positive in the next 24 hours.

Ever heard of a false alarm? Do you not believe them?

Incidentally I use a free program Ad-Aware 2007 that works just fine.

21 posted on 10/22/2007 10:45:08 AM PDT by McGruff (If I can't have Cheney I guess Fred will have to do.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: McGruff

When Microsoft bought Gator, they reclassified Gator’s horrible spyware.

Such “false positives” are sometimes classified as such by corporate mergers.

Doesn’t mean that the software is “nice”.


22 posted on 10/22/2007 10:51:43 AM PDT by weegee (NO THIRD TERM. America does not need another unconstitutional Clinton co-presidency.)
[ Post Reply | Private Reply | To 21 | View Replies]

To: girlangler

Thanks much! :-)


23 posted on 10/22/2007 11:09:23 AM PDT by LucyJo
[ Post Reply | Private Reply | To 18 | View Replies]

To: Grammy

Grammy, pinging you on this one.


24 posted on 10/22/2007 11:13:03 AM PDT by girlangler (Fish Fear Me)
[ Post Reply | Private Reply | To 17 | View Replies]

To: BulletBobCo

If you’re that paranoid, buy a Mac.


25 posted on 10/22/2007 11:25:19 AM PDT by George W. Bush (Apres moi, le deluge.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: jdm; All

jdm,I downloaded and ran SuperAntiSpyware, but it didn’t remove the Adware_BHOT_Mirar that is on my computer.

I got TrendMicro with this computer, and I finally got frustrated with their team trying to help me remove this and another one called Virtumundo, or some such, so a young man we know removed it, but overlooked this one.

If any of you are familiar with this, I’d appreciate your suggestions for getting rid of it.

Thanks,
LJ


26 posted on 10/22/2007 1:24:26 PM PDT by LucyJo
[ Post Reply | Private Reply | To 13 | View Replies]

To: BulletBobCo

I really feel left out these days. I, first of all, had to even find a good program to run on my Macintosh, to look for viruses and trojans and other malware. After finding one, I had to wait for four or five years before even finding one “hit” finding one — which turned out to be a Windows virus. Such disappointment!

I can’t find a single virus to get excited about on the Macintosh. Something must be really wrong with that system... LOL!

Regards,
Star Traveler


27 posted on 10/22/2007 3:31:13 PM PDT by Star Traveler
[ Post Reply | Private Reply | To 1 | View Replies]

To: BulletBobCo

bookmark


28 posted on 10/22/2007 5:02:51 PM PDT by UCANSEE2 (- Attention all planets of the solar Federation--Secret plan codeword: Banana)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BulletBobCo
My experience has been that running ANY type of instant messaging is inviting problems.

I don’t use them. But my son and many former coworkers do. And they catch every damn thing that comes along because they don’t practice safe computing.

I personally don’t activate any instant messaging. I use Antivir (free) for virus checks and guard, Spybot Search & Destroy for other nasties, Adaware for unwanted crap, and the free version of Kerio Firewall. I try to scan my disk with all these at least every week or so. For added measure, our broadband router has a built-in hardware firewall.

29 posted on 10/22/2007 5:21:02 PM PDT by 2111USMC
[ Post Reply | Private Reply | To 1 | View Replies]

To: JRios1968

It’s serially hugh!


30 posted on 10/22/2007 5:22:20 PM PDT by Redcloak (The 2nd Amendment isn't about sporting goods.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Gorzaloon

The latest from Webroot

http://webroot.custhelp.com/cgi-bin/webroot.cfg/php/enduser/home.php

Message Board
10/22/2007- Webroot Antivirus/Spy Sweeper is falsely detecting a registry key associated with Windows Live Messenger as a trojan labeled ‘LDPinch’. The registry entry is quarantined by Webroot Antivirus/Spy Sweeper, however, there is no severe impact to a user’s system. The registry entry is simply restored after restarting the system.

Webroot has identified the erroneous detection and has removed the false positive from the lastest definition update. Webroot Antivius/Spy Sweeper will automatically update itself once the definition update is available.


31 posted on 10/22/2007 5:28:21 PM PDT by BulletBobCo
[ Post Reply | Private Reply | To 4 | View Replies]

To: ButThreeLeftsDo

Since everyone is throwing recommendations out there, I’ll get mine in. AVG makes a superb anti-spyware program. As Sr. Network Admin, I have successfully lobbied to have the paid version added to most of our Critical user/Execs PC’s. You can get the same program for free, the only difference being that you have to manually update and scan with the free version. I have been a big fan of AVG A/V suite for years, and their A/S offering is every bit on par.

http://free.grisoft.com/doc/29116/us/frt/0


32 posted on 10/22/2007 5:30:38 PM PDT by Space Wrangler
[ Post Reply | Private Reply | To 8 | View Replies]

To: 2111USMC

I don’t use instant messaging either, I disabled mine, however the files are still in the registry and that is what was causing the problem.


33 posted on 10/22/2007 5:33:17 PM PDT by BulletBobCo
[ Post Reply | Private Reply | To 29 | View Replies]

To: girlangler

Thanks girl. I will pass this on to my IT guy 8-)

(Mr G for those in the know). I know about enough to get into trouble, and nothing more.

By the way, how was the fishing last weekend?


34 posted on 10/22/2007 5:40:22 PM PDT by Grammy
[ Post Reply | Private Reply | To 17 | View Replies]

To: Gorzaloon
Thanks for posting the detailed info.

The information collected is encoded using MIME (Base64) and sent to the Trojan's author by email...

This is why you need a good firewall that traps incoming as well as outgoing threats.

35 posted on 10/22/2007 7:25:21 PM PDT by upchuck (Hildabeaste as Prez... unimaginable, devastating misery! She will redefine "How bad can it get?")
[ Post Reply | Private Reply | To 4 | View Replies]

To: jdm
BUMP to SuperAntiSpyware. Excellent software!

SAS, Spybot (with Tea Timer) and AVG Anti-virus and you’re good to go.

36 posted on 10/22/2007 7:28:07 PM PDT by upchuck (Hildabeaste as Prez... unimaginable, devastating misery! She will redefine "How bad can it get?")
[ Post Reply | Private Reply | To 13 | View Replies]

To: Grammy

I’m in the know when it comes to who your IT guy is (LOL).

You’re in good hands too.

Don’t remember the last time we talked, but the trip to Dale Hollow Lake was not what we’d been accustomed to in the past.

Since Dale Hollow is downstream from the Cumberland Dam (which is undergoing dam repairs) on the Cumberland River, Dale Hollow had really low water levels. To keep enough oxygenated water below Cumberland Dam (for trout, mussels and other threatened species), they drained Dale Hollow. I saw places (normally deep underwater) that I’d fished for years without knowing what structure underwater I was targeting.

Anyway, the fishing was tough, but spent two days with wonderful people you and Mr.Grammy would love.

I still want we two gals to hit a trout stream before it gets too cold. We can do this.


37 posted on 10/22/2007 8:35:45 PM PDT by girlangler (Fish Fear Me)
[ Post Reply | Private Reply | To 34 | View Replies]

To: girlangler

We seem to be getting some make up rain tonight! More than an inch so far, and more tomorrow. Boy, do we need it!


38 posted on 10/22/2007 8:42:00 PM PDT by Grammy
[ Post Reply | Private Reply | To 37 | View Replies]

To: Grammy

We have been getting rain, steadily, from a downfall to a light one, for the past two days, and forecast into the end of the week (WE NEED IT).

I am so happy, I have my many flowers, veggie garden, and I have grieved the toll taken on them over the summer. I lost some rhodederoms, and others, that I cherished.

Grammy, soon things will settle down and we’ll go fishing, the water will be there for us to do so.

I have, and suspect you do, some equipment and clothing where we can fish in some wet and cold weather and still be comfortable.

We need to set a time, a place that is convenient to you and me. We are blessed to have many of these places halfway betwen you and I, and they are productive fishing holes.

I’d like a day on a stream with just you and I. The last time we fished, we had to bait hooks for others, etc. The next time it needs to be me and you on that stream, concentrating, and me kicking your butt (grin)


39 posted on 10/22/2007 8:58:54 PM PDT by girlangler (Fish Fear Me)
[ Post Reply | Private Reply | To 38 | View Replies]

To: girlangler

As if....

8-)


40 posted on 10/22/2007 9:00:33 PM PDT by Grammy
[ Post Reply | Private Reply | To 39 | View Replies]

To: Space Wrangler
Since everyone is throwing recommendations out there, I’ll get mine in. AVG makes a superb anti-spyware program. As Sr. Network Admin, I have successfully lobbied to have the paid version added to most of our Critical user/Execs PC’s.

I am the admin for my teensy little network here. The Windows boxes have the paid version of AVG with firewall and spyware detection. File and print sharing with the Linux machines takes a little tweaking with the AVG firewall, but it's worth it. AVG updates every few days, and its footprint is not as mammoth as the Symantech offerings, which have been so bloated it's hard to say if perhaps getting a virus may be better. Tried most of the biggies: McAffee is given away free by ISP's and to Universitites, because that's what it's worth, at least in my experience.

41 posted on 10/23/2007 3:56:28 AM PDT by Gorzaloon (Food imported from China = "Cesspool + Flavor-Straw")
[ Post Reply | Private Reply | To 32 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson