Home Malware Programs Trojans Packed.Tdss

Packed.Tdss

Posted: May 28, 2009

Packed.Tdss is a Rootkit Trojan, which means it conceals its own presence and the presence of affiliate malware programs on the compromised computer. Therefore, Packed.Tdss is not easily detectable and quite hard to remove. Typically, Packed.Tdss uses system security backdoors and firewall flaws to get on board undetected. Once inside and active, Packed.Tdss begins downloading, installing and promoting additional malicious software onto the infected machine. Packed.Tdss opens illicit and obscure connections for remote cyber-criminals to access the compromised system without any particular obstacles. Packed.Tdss is also known to focus on recording the victim's most sensitive data such as credit card details, passwords etc. In addition to the above features of Packed.Tdss Trojan, it is also capable of mutating and rapidly spreading through networks and coping itself to removable drives.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 UACnqxnsethfqsyxcr.dll
    2 UACqkppyodbawkldgu.dll
    3 UACqxtiekcnbouoins.dll
    4 UACwusibnevxscvntv.dll
    5 UACyctgyibvpiextci.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"%WIN.SYS32%\kdrbc.exe"\"%WIN.SYS32%\kdrbc.exe"
Loading...