Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 26 September 2005 22:43:45 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/PWDoor-A is a Trojan for the Windows platform.
The Trojan steals passwords from Internet Explorer sessions with certain websites and emails the stolen credentials to a remote user.
When run, Troj/PWDoor-A creates the file Direct32.dll in the Windows system folder and then runs it. The Direct32.dll file is also detected as Troj/PWDoor-A.
The following registry entries are created:
HKCR\CLSID\{BC687D94-3EA9-47F9-9C24-12F0B59DD9DC}
(default)
"Office.MyDLL.1"
HKCR\CLSID\
{BC687D94-3EA9-47F9-9C24-12F0B59DD9DC}\InProcServer32
(default)
"<Windows system folder>\Direct32.dll"
HKCR\CLSID\{BC687D94-3EA9-47F9-9C24-12F0B59DD9DC}\InProcServer32
ThreadingModel
"Apartment"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
ShellExecuteHooks
{BC687D94-3EA9-47F9-9C24-12F0B59DD9DC}
""
The Direct32.dll file may further function as a backdoor, allowing remote users access to the infected computer.
