Sophos

Troj/PWS-CW

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from January 2006 (4.01)
Protection available since 10 November 2005 15:17:22 (GMT)
Detected by All Sophos products

Action

More Information

Troj/PWS-CW is a password-stealing Trojan for the Windows platform.

The following registry entry is created to run the Trojan on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
MSSever
<path to Trojan>

The following registry entry is set or modified, so that the Trojan is run when files with extensions of TXT are opened/launched:

HKCR\txtfile\shell\open\command
(default)
<path to Trojan> "%1"

Troj/PWS-CW attempts to steal passwords and other account information and send these details to the author by email.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer