Troj/PWS-CAX exhibits the following characteristics:
File Information
- Size
- 106K
- SHA-1
- 7a23aa6dc8edec318a2e92c37c1d2c1edb3d7321
- MD5
- 8ce3fcca627b1e079ff7810463f68719
- CRC-32
- b5123262
- File type
- application/x-ms-dos-executable
- First seen
- 2012-12-30
Other vendor detection
- Avira
- TR/Dropper.Gen
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\celp.exe
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
- Taskman
- c:\Documents and Settings\test user\celp.exe
Processes Created
- c:\windows\system32\svchost.exe
DNS Requests
- loca.betrule.com
- mutta.agesask.net
- uokwa.agesonest.com