Home Malware Programs Trojans Awax

Awax

Posted: March 28, 2006

Awax is a trojan designed to secretly download from the Internet and execute arbitrary files, some of which may install dangerous spywares. It also collects computer information and transfers it to a predefined web server. Awax attempts to terminate running Microsoft AntiSpyware and inject malicious code into the Ad-Aware malware remover. The trojan is able to update its configuration settings via the Internet. It automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 gebcd.dll
    2 geede.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonNotifygebdc.dllHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonNotifygeede.dll
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}EA32FB3B-21C9-42cc-B8EF-01A9B28EDB0D
Loading...