Re: Unknown Malware found csdiv.dll
From: Harlan Carvey (keydet89_at_yahoo.com)
Date: 06/29/04
- Previous message: Jim Halfpenny: "Re: Unknown Malware found csdiv.dll"
- In reply to: Sven Carstens: "Unknown Malware found csdiv.dll"
- Next in thread: Valdis.Kletnieks_at_vt.edu: "Re: Unknown Malware found csdiv.dll"
- Reply: Valdis.Kletnieks_at_vt.edu: "Re: Unknown Malware found csdiv.dll"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 29 Jun 2004 08:16:57 -0700 (PDT) To: incidents@securityfocus.com
Sven,
I was wondering if you could provide a little more
information that might help narrow this baddy down a
bit...
> a friend of mine caught some really pain in the ass
> piece of malware.
Caught? You mean he just found the file?
> As I didn't find any references to it via google,
Not surprising, but thanks for saying that you looked.
> I'm posting a link, so
> the real experts out there have a new toy to play
> with.
>
> Malware http://www.demoserver.de/csdiv.dll_malware
>
> The file itself is not found by AdAware. But it
> seems after getting
> started it drops some well known other parts which
> are recognized and removed by AdAware.
What are some of the "well known other parts", and how
do you know that they're "dropped" by this DLL?
> Anyway I didn't find the injection point in the
> registry
Where did you check, specifically? Did you check
specific keys (if so, which ones?) or did you just
search the Registry for the DLL name?
> and searching all
> files on disk for the dll name brought nothing at
> all.
Searching all files on disk? What does that mean?
Did you look for the DLL name within files, or did you
search for the file name itself?
> What it found was some logfiles, dated on 2004-06-28
> (same date as the dll).
> These seem to be some installer logfiles.
Could it be that the DLL was called by one of the EXE
files mentioned in the logfile you posted? Did you
happen to find those files, too?
- Previous message: Jim Halfpenny: "Re: Unknown Malware found csdiv.dll"
- In reply to: Sven Carstens: "Unknown Malware found csdiv.dll"
- Next in thread: Valdis.Kletnieks_at_vt.edu: "Re: Unknown Malware found csdiv.dll"
- Reply: Valdis.Kletnieks_at_vt.edu: "Re: Unknown Malware found csdiv.dll"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|