Home Malware Programs Trojans PWDoor

PWDoor

Posted: March 28, 2006

PWDoor is a trojan designed to steal passwords that the user enters into particular web sites opened in Internet Explorer. The threat sends gathered data to a predetermined e-mail address. PWDoor can also work as a backdoor, which gives the attacker unauthorized remote access to a compromised PC. The intruder can download and run arbitrary files, record keystrokes and retrieve user confidential information.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 direct32.dll

Registry Modifications

  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}BC687D94-3EA9-47F9-9C24-12F0B59DD9DC
Loading...