Sophos

Troj/CWS-F

Aliases
  • Trojan-Dropper.Win32.Small.qv
  • StartPage-CQ.dr
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from April 2005 (3.92)
Protection available since 14 February 2005 21:47:39 (GMT)
Detected by All Sophos products

Action

More Information

Troj/CWS-F is a dropper Trojan for the Windows platform.

Troj/CWS-F will drop and register a DLL file named WTLBASS32.DLL, detected as Troj/CWS-C.

When first run, Troj/CWS-F will copy itself to the Windows system folder as CTFMONSS.EXE and CSRSSW.EXE. In order to run automatically each time a user logs on, Troj/CWS-F will set the following registry entries:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
CTFMONSS
<Windows system folder>\CTFMONSS.EXE

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
CSRSSW
<Windows system folder>\CSRSSW.EXE

The following registry branches will also be created:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{A0ED918D-B8E6-4c3d-BD15-1DB1AE9A5DD3}

HKCR\WTLBAss.VDOMP
HKCR\WTLBAss.VDOMP.1
HKCR\CLSID\{A0ED918D-B8E6-4c3d-BD15-1DB1AE9A5DD3}
HKCR\Interface\{0B6EF17E-18E5-4449-86EA-64C82D596EAE}
HKCR\Interface\{B1E68D42-02C4-465B-8368-5ED9B732E22D}
HKCR\TypeLib\{64BFAE89-DA25-41B1-A349-88032CDA7F88}
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\WTLBAstp
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\MSMsgSvc

For further information, see Troj/CWS-C.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer