Threat Search: 

ThreatExpert's Statistics for Backdoor.Tidserv [PC Tools]:

Backdoor.Tidserv [PC Tools] is also known as:
Threat AliasNumber of Incidents
Backdoor.Tidserv [Symantec]209
Trojan:WinNT/Alureon.G [Microsoft]192
Trojan.WinNT.Alureon [Ikarus]120
Trojan:Win32/Alureon.CT [Microsoft]73
Packed.Win32.TDSS.z [Kaspersky Lab]65
Mal/TDSSPack-Q [Sophos]52
Mal/TDSSPk-C [Sophos]41
Trojan.Win32.FraudPack.akpd [Kaspersky Lab]36
DNSChanger.as [McAfee]26
Mal/TDSSPk-C, Mal/TDSSPack-W, Mal/TDSSPack-A [Sophos]13
DNSChanger!da [McAfee]12
Backdoor.Tidserv!gen2 [Symantec]11
Backdoor.Tidserv!inf [Symantec]11
Mal/Generic-A [Sophos]11
Packed.Win32.Tdss [Ikarus]11
Mal/TDSSPk-C, Mal/TDSSPack-W, Mal/TDSSPack-U [Sophos]9
Trojan.Win32.Cosmu.dzv [Kaspersky Lab]9
Win-Trojan/Xema.variant [AhnLab]8
Troj/Pushu-Gen, Mal/Fakedis-A [Sophos]6
FakeAlert-SpywareGuard.gen.b [McAfee]5
Trojan:Win32/Alureon.gen!J [Microsoft]5
Virus:Win32/Cutwail.F [Microsoft]5
DNSChanger.ba [McAfee]4
FakeAlert-FQ [McAfee]4
Mal/EncPk-CZ, Mal/TDSSPack-Q [Sophos]4
Mal/TDSSPack-U [Sophos]4
Packed.Win32.Krap.x [Kaspersky Lab]4
Packed.Win32.Tdss.b [Kaspersky Lab]4
Trojan:Win32/Alureon.BP [Microsoft]4
Trojan:WinNT/Alureon.D [Microsoft]4
W32/Autorun-AFM [Sophos]4
Win32/Dnis.D [AhnLab]4
Win-Trojan/DNSChanger.343040 [AhnLab]4
Mal/TDSSPk-C, Mal/TDSSPack-W [Sophos]3
Mal/TDSSRt-A [Sophos]3
Patched-SYSFile.a [McAfee]3
Trojan.Win32.Alureon [Ikarus]3
Trojan:Win32/Alureon.BH [Microsoft]3
Trojan:Win32/Alureon.DF [Microsoft]3
Virus:Win32/Alureon.F [Microsoft]3
Backdoor.Tidserv!gen1 [Symantec]2
DNSChanger!cg [McAfee]2
DNSChanger.t [McAfee]2
Mal/TDSS-G [Sophos]2
Mal/TDSSPack-W, Mal/TDSSPack-A, Mal/TDSSPk-C [Sophos]2
Mal/TDSSPack-W, Mal/TDSSPack-U, Mal/TDSSPk-C [Sophos]2
Packed.Win32.Krap.e [Kaspersky Lab]2
Packed.Win32.TDSS.aa [Kaspersky Lab]2
Packed.Win32.TDSS.w [Kaspersky Lab]2
Patched-SYSFile [McAfee]2
Rootkit.Win32.TDSS.u [Kaspersky Lab]2
Troj/Rootkit-ED [Sophos]2
Trojan.Win32.Patched.go [Kaspersky Lab]2
Trojan.Win32.Tdss [Ikarus]2
Trojan.Win32.Tdss.auxu [Kaspersky Lab]2
Trojan:Win32/Alureon.DA [Microsoft]2
Trojan-Downloader.Win32.FraudLoad.gcl [Kaspersky Lab]2
Virus.Win32.Virut.ce [Kaspersky Lab]2
Virus:Win32/Alureon.A [Microsoft]2
Vundo!m [McAfee]2
Win-Trojan/Patched.X [AhnLab]2
Backdoor.Tidserv!gen [Symantec]1
Backdoor.Tidserv.I!inf [Symantec]1
BackDoor-DVU [McAfee]1
DNSChanger!bl [McAfee]1
DNSChanger!cb [McAfee]1
DNSChanger!ck [McAfee]1
DNSChanger!cy [McAfee]1
DNSChanger.o [McAfee]1
Dropper/TDLRootkit.Gen [AhnLab]1
FakeAlert-IC [McAfee]1
Generic FakeAlert.d [McAfee]1
Hoax.Win32.Bravia.is [Kaspersky Lab]1
Mal/EncPk-EQ [Sophos]1
Mal/EncPk-ND [Sophos]1
Mal/EncPk-ND, Mal/TDSSPack-Q [Sophos]1
Mal/Generic-A, Mal/TDSSPack-A [Sophos]1
Mal/Generic-A, Mal/TDSSPk-C [Sophos]1
Mal/Generic-A, Troj/Virtum-Gen [Sophos]1
Mal/TDSSPack-A [Sophos]1
Mal/TDSSPack-V, Mal/TDSSRt-A [Sophos]1
Mal/TDSSPack-W, Mal/TDSSPk-C [Sophos]1
Mal/TDSSPk-C, Mal/TDSSPack-W, Mal/TDSSPack-U, Mal/TDSSPack-A [Sophos]1
Rootkit.Win32.Tdss.ai [Kaspersky Lab]1
Rootkit.Win32.TDSS.cdj [Kaspersky Lab]1
Rootkit.Win32.TDSS.y [Kaspersky Lab]1
Suspicious.Vundo.2 [Symantec]1
TDSS [McAfee]1
Troj/Agent-LQT [Sophos]1
Troj/Virtum-Gen [Sophos]1
Trojan.Generic.CJ [Ikarus]1
Trojan.Win32.Cosmu.dsc [Kaspersky Lab]1
Trojan.Win32.Cosmu.dsk [Kaspersky Lab]1
Trojan.Win32.Cosmu.dxl [Kaspersky Lab]1
Trojan.Win32.Patched [Ikarus]1
Trojan.Win32.Tdss.auxh [Kaspersky Lab]1
Trojan.Win32.Tdss.auxt [Kaspersky Lab]1
Trojan.Win32.Tdss.avrx [Kaspersky Lab]1
Trojan.Win32.Tdss.awhe [Kaspersky Lab]1
Trojan:Win32/Alureon.DB [Microsoft]1

Backdoor.Tidserv [PC Tools] has the following possible countries of origin:
OriginNumber of Incidents
China1
Germany1
Russian Federation1

Backdoor.Tidserv [PC Tools] is known to be created as:
%System%\codec.exe
%System%\dllcache\ndis.sys
%System%\drivers\h8srtlkvxbnmtnb.sys
%System%\drivers\h8srtwbpxmfoero.sys
%System%\drivers\tdssserv.sys
%Temp%\h8srtynaunhnkjm.sys
%Temp%\tdlclk.dll
%Windir%\temp\0000014e.sys
%Windir%\temp\00000e41.sys
%Windir%\temp\000014d6.sys
%Windir%\temp\000018bf.sys
%Windir%\temp\00001905.sys
%Windir%\temp\00001f66.sys
%Windir%\temp\000024c8.sys
%Windir%\temp\00003553.sys
%Windir%\temp\00005045.sys
%Windir%\temp\00005376.sys
%Windir%\temp\0000540f.sys
%Windir%\temp\00005ba0.sys
%Windir%\temp\00005dd1.sys
%Windir%\temp\0000626a.sys
%Windir%\temp\00006a57.sys
%Windir%\temp\00006b92.sys
%Windir%\temp\00007db5.sys
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.