Home Malware Programs Trojans TDSServ

TDSServ

Posted: July 26, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 63
First Seen: July 26, 2012
OS(es) Affected: Windows

TDSServ is a Trojan that installs itself onto the affected computer system through vulnerabilities in already installed programs, mainly InternetExplorer, or by using rogue anti-spyware applications. TDSServ uses rootkit techniques created by attackers to disguise its existence in the infected computer system. TDSServ is difficult to detect and uninstall by many security programs. Once installed, TDSServ will be configured to run automatically every time you start Windows. While running, TDSServ may compromise Internet Explorer, display many pop-up messages and fake security alerts, block access to security-related websites, disable Windows Task Manager, Windows Security Center and Registry Editor, and redirect search results in Google, Yahoo, MSN and other similar search engines to suspicious websites.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Windows\System32\TDSS[RANDOM CHARACTERS].sys File name: C:\Windows\System32\TDSS[RANDOM CHARACTERS].sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
C:\Windows\System32\TDSS[RANDOM CHARACTERS].dat File name: C:\Windows\System32\TDSS[RANDOM CHARACTERS].dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
C:\Windows\System32\TDSS[RANDOM CHARACTERS].tmp File name: C:\Windows\System32\TDSS[RANDOM CHARACTERS].tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
C:\Windows\System32\drivers\TDSS[RANDOM CHARACTERS].sys File name: C:\Windows\System32\drivers\TDSS[RANDOM CHARACTERS].sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
C:\Windows\System32\TDSS[RANDOM CHARACTERS].log File name: C:\Windows\System32\TDSS[RANDOM CHARACTERS].log
Mime Type: unknown/log
Group: Malware file
C:\Windows\System32\TDSSservers.dat File name: C:\Windows\System32\TDSSservers.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
C:\Windows\System32\TDSSl.dll File name: C:\Windows\System32\TDSSl.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Windows\System32\TDSSserv.sys File name: C:\Windows\System32\TDSSserv.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
C:\Windows\System32\TDSSerrors.log File name: C:\Windows\System32\TDSSerrors.log
Mime Type: unknown/log
Group: Malware file
C:\Windows\System32\TDSSlog File name: C:\Windows\System32\TDSSlog
Group: Malware file
C:\Windows\System32\TDSSpopup.dll File name: C:\Windows\System32\TDSSpopup.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Windows\System32\TDSSlog.dll File name: C:\Windows\System32\TDSSlog.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Windows\System32\TDSSadw.dll File name: C:\Windows\System32\TDSSadw.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Windows\System32\TDSSmain.dll File name: C:\Windows\System32\TDSSmain.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Windows\System32\TDSSinit.dll File name: C:\Windows\System32\TDSSinit.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Windows\System32\TDSSosvn.dat File name: C:\Windows\System32\TDSSosvn.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
C:\Windows\System32\TDSStkdv.log File name: C:\Windows\System32\TDSStkdv.log
Mime Type: unknown/log
Group: Malware file
C:\Windows\System32\TDSStkdu.log File name: C:\Windows\System32\TDSStkdu.log
Mime Type: unknown/log
Group: Malware file
C:\Windows\System32\TDSSkkai.log File name: C:\Windows\System32\TDSSkkai.log
Mime Type: unknown/log
Group: Malware file
C:\Windows\System32\TDSSproc.log File name: C:\Windows\System32\TDSSproc.log
Mime Type: unknown/log
Group: Malware file
C:\Windows\System32\drivers\TDSSoeqh.sys File name: C:\Windows\System32\drivers\TDSSoeqh.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
C:\Windows\System32\drivers\TDSSmqlt.sys File name: C:\Windows\System32\drivers\TDSSmqlt.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
C:\Windows\System32\drivers\TDSSpaxt.sys File name: C:\Windows\System32\drivers\TDSSpaxt.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDSSserv.sysHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSServ.sysHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDSServ.sysHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSServHKEY_LOCAL_MACHINE\SOFTWARE\TDSS\"serversdown" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\TDSS\"type" = "popup"HKEY_LOCAL_MACHINE\SOFTWARE\TDSS\injectorHKEY_LOCAL_MACHINE\SOFTWARE\TDSS\"build" = "standart"HKEY_LOCAL_MACHINE\SOFTWARE\TDSS\versionHKEY_LOCAL_MACHINE\SOFTWARE\TDSS\connectionsHKEY_LOCAL_MACHINE\SOFTWARE\TDSS\disallowedHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata\"affid" = "39"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata\"asubid" = "v2test7"
Loading...