Associated Malware Groups
The filename is associated with the malware groups:
- Cloaked Malware
- Malicious Software
File Behavior
CVASDS1.DLL has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Copies files
- This Process Deletes Other Processes From Disk
- Executes a Process
- This process creates other processes on disk
- Drops known malicious software during execution
- Modifies fixed, removable or USB drives using autorun to execute or spread infection
CVASDS1.DLL has been the subject of the following behavior:
- Created as a process on disk
- Registered as a Dynamic Link Library File
- The process is hooked into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Deleted as a process from disk
- Executed as a Process
Country Of Origin
The filename CVASDS1.DLL was first seen on Jul 25 2009 in the following geographical regions of the Prevx community:
- Colombia on Jul 25 2009
- El Salvador on Aug 26 2009
- Poland on Sep 15 2009
- Europe on Sep 16 2009
- France on Nov 26 2009
- Ecuador on Mar 19 2010
- Bulgaria on Mar 19 2010
File Name Aliases
CVASDS1.DLL can also use the following file names:
- CVASDS0.DLL
- CVASDS2.DLL
- TRZ515.TMP
- AM.EXE
- 09185299.DLL
Filesizes
The following file size has been seen:
- 75,325 bytes
- 74,155 bytes
- 73,730 bytes
- 227,147 bytes
- 75,776 bytes
- 76,059 bytes
File Type
The filename CVASDS1.DLL refers to many versions of a dynamic link library.
File Activity
One or more files with the name CVASDS1.DLL creates, deletes, copies or moves the following files and folders:
- Deletes c:\docume~1\user\locals~1\temp\am1.rar
- Opens/modifes c:\autoexec.bat
- Creates c:\docume~1\user\locals~1\temp\am1.rar
- Deletes c:\docume~1\user\locals~1\temp\am.exe
- Creates c:\docume~1\user\locals~1\temp\am.exe
- Deletes c:\docume~1\user\locals~1\temp\herss.exe
- Copies filec:\docume~1\user\locals~1\temp\am.exe to c:\docume~1\user\locals~1\temp\herss.exe
- Deletes c:\docume~1\user\locals~1\temp\cvasds0.dll
- Creates c:\docume~1\user\locals~1\temp\cvasds0.dll
- Deletes c:\3slhl.ex
- Copies filec:\docume~1\user\locals~1\temp\herss.exe to c:\3slhl.ex
- Deletes c:\autorun.in
- Creates c:\autorun.in
- Deletes d:\3slhl.ex
- Copies filec:\docume~1\user\locals~1\temp\herss.exe to d:\3slhl.ex
- Deletes d:\autorun.in
- Creates d:\autorun.in
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.