Associated Malware Groups
The filename is associated with the malware groups:
- Cloaked Malware
- Malicious Software
File Behavior
CVASDS2.DLL has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Copies files
- This Process Deletes Other Processes From Disk
- Executes a Process
- Drops known malicious software during execution
- Modifies fixed, removable or USB drives using autorun to execute or spread infection
CVASDS2.DLL has been the subject of the following behavior:
- Created as a process on disk
- Registered as a Dynamic Link Library File
- Deleted as a process from disk
- Executed as a Process
Country Of Origin
The filename CVASDS2.DLL was first seen on Sep 15 2009 in the following geographical regions of the Prevx community:
- Europe on Sep 15 2009
- Uruguay on Sep 15 2009
- on Sep 22 2009
- Turkey on Dec 5 2009
- The United States on Mar 13 2010
File Name Aliases
CVASDS2.DLL can also use the following file names:
Filesizes
The following file size has been seen:
- 73,831 bytes
- 223,096 bytes
- 75,435 bytes
- 76,004 bytes
- 231,021 bytes
File Type
The filename CVASDS2.DLL refers to many versions of a dynamic link library.
File Activity
One or more files with the name CVASDS2.DLL creates, deletes, copies or moves the following files and folders:
- Deletes c:\docume~1\user\locals~1\temp\am1.rar
- Creates c:\docume~1\user\locals~1\temp\am1.rar
- Creates c:\docume~1\user\locals~1\temp\am.exe
- Deletes c:\docume~1\user\locals~1\temp\am.exe
- Deletes c:\docume~1\user\locals~1\temp\herss.exe
- Copies filec:\docume~1\user\locals~1\temp\am.exe to c:\docume~1\user\locals~1\temp\herss.exe
- Deletes c:\docume~1\user\locals~1\temp\cvasds0.dll
- Creates c:\docume~1\user\locals~1\temp\cvasds0.dll
- Deletes c:\ucivd6xi.ba
- Copies filec:\docume~1\user\locals~1\temp\herss.exe to c:\ucivd6xi.ba
- Deletes c:\autorun.in
- Creates c:\autorun.in
- Deletes d:\ucivd6xi.ba
- Copies filec:\docume~1\user\locals~1\temp\herss.exe to d:\ucivd6xi.ba
- Deletes d:\autorun.in
- Creates d:\autorun.in
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.