Security Incidents mailing list archives

Re: Unknown Malware found csdiv.dll


From: Valdis.Kletnieks () vt edu
Date: Tue, 29 Jun 2004 14:21:47 -0400

On Tue, 29 Jun 2004 08:16:57 PDT, Harlan Carvey said:

Malware http://www.demoserver.de/csdiv.dll_malware

The file itself is not found by AdAware. But it
seems after getting
started it drops some well known other parts which
are recognized and removed by AdAware.

What are some of the "well known other parts", and how
do you know that they're "dropped" by this DLL?

Just out of curiosity, have we ruled out the possibility that
more than one piece of malware found its way in?  Often, it's
hard to tell if you're playing "5 blind men and an elephant", or
"5 blind men and 5 different animals"...

(If you find that hard to believe, consider the recent study that
found an *average* of 7 or so *different* pieces of spyware on
the boxes surveyed....)

Attachment: _bin
Description:


Current thread: