Associated Malware Groups
The filename is associated with the malware groups:
- Fraudulent Security Program
- Cloaked Malware
- Worm
File Behavior
ADSN.DLL has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Enables an In Process Object/Server - Common with DLL Injections
- Found on infected systems and resists interrogation by security products
ADSN.DLL has been the subject of the following behavior:
- Registered as a Dynamic Link Library File
- Enabled as an In Process Object/Server - Common with DLL Injections
- Created as a process on disk
- Creation and Registered as a Browser Helper Object in Internet Explorer
Country Of Origin
The filename ADSN.DLL was first seen on Dec 19 2007 in the following geographical regions of the Prevx community:
- The UNITED KINGDOM on Dec 19 2007
- CANADA on Aug 1 2008
- SPAIN on Nov 12 2008
- INDIA on Nov 13 2009
File Name Aliases
ADSN.DLL can also use the following file names:
- CABINE.DLL
- APPMG.DLL
- CMUTI.DLL
- BACKUP-20090321-140206-449.DLL
- COMCA.DLL
- AAAAMO.DLL
- ATMPVCN.DLL
- BTPANU.DLL
- DOCPRO.DLL
- ADPTI.DLL
- FSUS.DLL
- MFCANS3.DLL
- NVOPENG.DLL
- AMSTREA.DLL
- ASFERRO.DLL
- AUTODIS.DLL
- AVMETE.DLL
- CNBJMO.DLL
- COLBAC.DLL
- COMPSTU.DLL
- ALRSV.DLL
- ATPARTNER.DLL
- CNETCF.DLL
- CD.DLL
- CL.DLL
- 87140417.DLL
- 54722667.DAT
Filesizes
The following file size has been seen:
- 104,524 bytes
- 118,272 bytes
- 116,480 bytes
- 84,992 bytes
- 91,648 bytes
File Type
The filename ADSN.DLL refers to many versions of a dynamic link library.
File Activity
One or more files with the name ADSN.DLL creates, deletes, copies or moves the following files and folders:
- Deletes c:\windows\system32\ipv6mops.dl_
- Moves c:\windows\system32\ipv6mops.dll to c:\windows\system32\ipv6mops.dl_
- Deletes c:\windows\system32\ipv6mopz.dl_
- Moves c:\windows\system32\ipv6mopz.dll to c:\windows\system32\ipv6mopz.dl_
- Deletes c:\windows\system32\ipv6mons.dl_
- Moves c:\windows\system32\ipv6mons.dll to c:\windows\system32\ipv6mons.dl_
- Deletes c:\windows\system32\ipv6motp.dl_
- Moves c:\windows\system32\ipv6motp.dll to c:\windows\system32\ipv6motp.dl_
- Deletes c:\windows\system32\ipv6mopk.dl_
- Moves c:\windows\system32\ipv6mopk.dll to c:\windows\system32\ipv6mopk.dl_
- Deletes c:\windows\system32\ipv6monq.dl_
- Moves c:\windows\system32\ipv6monq.dll to c:\windows\system32\ipv6monq.dl_
- Deletes c:\windows\system32\ipv6monl.dl_
- Moves c:\windows\system32\ipv6monl.dll to c:\windows\system32\ipv6monl.dl_
- Deletes c:\windows\system32\ipv6mote.dl_
- Moves c:\windows\system32\ipv6mote.dll to c:\windows\system32\ipv6mote.dl_
- Deletes c:\windows\system32\AClient.dl_
- Moves c:\windows\system32\AClient.dll to c:\windows\system32\AClient.dl_
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.