Security Incidents mailing list archives

Re: Unknown Malware found csdiv.dll


From: Jordan Wiens <numatrix () ufl edu>
Date: Tue, 29 Jun 2004 13:36:40 -0400 (EDT)

On Tue, 29 Jun 2004, Sven Carstens wrote:

Hi list,

a friend of mine caught some really pain in the ass piece of malware.
As I didn't find any references to it via google, I'm posting a link, so
the real experts out there have a new toy to play with.

Malware http://www.demoserver.de/csdiv.dll_malware

Couple of AV vendors detect it as:
F-Secure        TrojanDownloader.Win32.Winshow.u [AVP]
KAV             TrojanDownloader.Win32.Winshow.u
AntiVir         The Trojan horse TR/Dldr.WinSh.AC.05
Dr.Web          Trojan.DownLoader.377

Another six didn't detect it, so it looks like it's either new, or 'just'
spyware that some vendors seem reluctant to detect.

-- 
Jordan Wiens, CISSP
UF Network Security Engineer
(352)392-2061


Current thread: