Troj/PWSteal-G is a password stealing Trojan for the Windows platform.
When Troj/PWSteal-G is installed the following files are created:
<Program Files>\Explorer\keys.txt
<Program Files>\Explorer\crs.exe
<Windows>\megangoodslideshow1.exe
<Windows>\server.exe
The following registry entry is created to run crs.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Explorer
<Program Files>\Explorer\crs.exe