This type of trojan steals passwords and other sensitive information. It may also secretly install other malicious programs.
Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.
More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.
You may also refer to the Knowledge Base on the F-Secure Community site for further assistance.
Security programs will sometimes unintentionally identify a clean program or file as malicious if its code or behavior is similar to a known harmful program or file. This is known as a False Alarm or False Positive (FP).
For example, 'tmp.edb' and other '.edb' files stored at the location 'C:\WINDOWS\SoftwareDistribution\DataStore\Logs\' may be unintentionally detected as malicious by various security programs.
In most cases, a False Positive is fixed in a subsequent database release; updating your F-Secure security product to use the latest database is enough to resolve the issue. If you suspect a detected file may be a False Positive, you can check by first updating your F-Secure security product to use the latest detection database updates, then rescanning the suspect file.
After checking, if you believe the file or program is still incorrectly detected, you can submit a sample of it to F-Secure Labs for analysis and correction:
If you are positive that the suspect file is safe and you want to continue using it, you can exclude it from further scanning by the F-Secure security product:
You may also refer to the Knowledge Base on the F-Secure Community site for more assistance.
Microsoft provides enterprise-level instructions for excluding files from scanning by antivirus software:
A Trojan-PWS is very similar to a Trojan-Spy, but is geared mainly towards stealing account log-in details, including passwords (the PWS stands for password stealer). In addition, some Trojan-PWSs may also include spying and data-stealing routines.
To perform its password-stealing routine, a Trojan-PWS will usually drop a keylogging component. Such components stays active in Windows memory and starts keylogging (recording keystrokes) when a user is asked to input a log-in ID and a password.
Stolen log-ins and passwords can allow an attacker to read a user's e-mail on public and corporate mail servers, as well as giving access to more sensitive material, such as online banking accounts.
As of March 2010, the former naming convention 'Trojan-PSW' has been updated to 'Trojan-PWS' to make identification easier for users and to ensure naming practices are in line with current industry standards.