Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | January 2006 (4.01) |
| Protection available since | 10 November 2005 15:17:22 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/PWS-CW is a password-stealing Trojan for the Windows platform.
The following registry entry is created to run the Trojan on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
MSSever
<path to Trojan>
The following registry entry is set or modified, so that the Trojan is run when files with extensions of TXT are opened/launched:
HKCR\txtfile\shell\open\command
(default)
<path to Trojan> "%1"
Troj/PWS-CW attempts to steal passwords and other account information and send these details to the author by email.
