Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | April 2005 (3.92) |
| Protection available since | 14 February 2005 21:47:39 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/CWS-F is a dropper Trojan for the Windows platform.
Troj/CWS-F will drop and register a DLL file named WTLBASS32.DLL, detected as Troj/CWS-C.
When first run, Troj/CWS-F will copy itself to the Windows system folder as CTFMONSS.EXE and CSRSSW.EXE. In order to run automatically each time a user logs on, Troj/CWS-F will set the following registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
CTFMONSS
<Windows system folder>\CTFMONSS.EXE
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
CSRSSW
<Windows system folder>\CSRSSW.EXE
The following registry branches will also be created:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{A0ED918D-B8E6-4c3d-BD15-1DB1AE9A5DD3}
HKCR\WTLBAss.VDOMP
HKCR\WTLBAss.VDOMP.1
HKCR\CLSID\{A0ED918D-B8E6-4c3d-BD15-1DB1AE9A5DD3}
HKCR\Interface\{0B6EF17E-18E5-4449-86EA-64C82D596EAE}
HKCR\Interface\{B1E68D42-02C4-465B-8368-5ED9B732E22D}
HKCR\TypeLib\{64BFAE89-DA25-41B1-A349-88032CDA7F88}
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\WTLBAstp
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\MSMsgSvc
For further information, see Troj/CWS-C.
