Threat Search: 

ThreatExpert's Statistics for Mal/TDSSPack-A [Sophos]:

Mal/TDSSPack-A [Sophos] is also known as:
Threat AliasNumber of Incidents
Trojan.Metajuan [Symantec]81
Generic FakeAlert!bo [McAfee]72
Trojan.Win32.FakeSpyguard [Ikarus]56
Packed.Win32.TDSS.aa [Kaspersky Lab]42
Trojan:Win32/Alureon.gen!C [Microsoft]37
Trojan.Win32.Tdss.anrd [Kaspersky Lab]36
Trojan.Win32.Tdss.anre [Kaspersky Lab]36
Trojan:Win32/Alureon.gen!R [Microsoft]36
Win-Trojan/Alureon.20480.B [AhnLab]36
Win-Trojan/Alureon.30208 [AhnLab]36
Trojan-Downloader.Win32.Agent.bqxc [Kaspersky Lab]34
Vundo.gen.bq [McAfee]23
Packed.Generic.200 [Symantec]17
Trojan.Vundo [Ikarus]16
Win-Trojan/Xema.variant [AhnLab]14
Trojan:Win32/Alureon.BF [Microsoft]13
FakeAlert-SpywareGuard.gen.b [McAfee]12
Trojan:Win32/Vundo.gen!BN [Microsoft]12
Packed.Win32.Tdss.m [Kaspersky Lab]11
Trojan:Win32/Alureon.gen!J [Microsoft]11
Packed.Win32.TDSS.y [Kaspersky Lab]10
Trojan.Fakeavalert [Symantec]10
Trojan:Win32/Alureon.gen!U [Microsoft]10
DNSChanger.o [McAfee]9
Trojan.Crypt [Ikarus]9
Trojan.TDss [Ikarus]9
Trojan.Win32.TDSS.amwo [Kaspersky Lab]9
Trojan.Win32.Tdss.anrc [Kaspersky Lab]9
Trojan:Win32/Alureon.BD [Microsoft]9
DNSChanger.gen [McAfee]7
Rootkit.Win32.TDSS [Ikarus]7
Worm:Win32/Vundo.B [Microsoft]7
AntiVirus2009 [Symantec]6
DNSChanger!bi [McAfee]6
Trojan.Win32.InternetAntivirus [Ikarus]6
Trojan:WinNT/Alureon.C [Microsoft]6
Backdoor.Tidserv [Symantec]5
Packed.Win32.Tdss.f [Kaspersky Lab]4
Trojan Horse [Symantec]4
Trojan.Win32.Pakes [Ikarus]4
Trojan.Win32.Pakes.mzs [Kaspersky Lab]4
Trojan:Win32/Alureon.CT [Microsoft]4
Mal/EncPk-KG, Mal/TDSSPack-A [Sophos]3
Packed.Generic.254 [Symantec]3
Packed.Win32.TDSS.z [Kaspersky Lab]3
Trojan:Win32/Alureon.gen!T [Microsoft]2
Trojan:Win32/FakeCog [Microsoft]2
Backdoor.Tidserv [PC Tools]1
CoreGuardAntivirus2009 [Symantec]1
DNSChanger!bd [McAfee]1
DNSChanger!bz [McAfee]1
FakeAlert-CT [McAfee]1
Generic FakeAlert!bu [McAfee]1
Generic FakeAlert.k [McAfee]1
RogueAntiSpyware.CoreGuardAntivirus2009 [PC Tools]1
Rootkit.Win32.TDSS.phm [Kaspersky Lab]1
Trojan.FakeAV [Symantec]1
Trojan.Win32.Agent2.kym [Kaspersky Lab]1
Trojan.Win32.Cosmu.dxl [Kaspersky Lab]1
Trojan.Win32.FakeSmoke [Ikarus]1
Trojan.Win32.Monderc [Ikarus]1
Trojan.Win32.TDSS.afpv [Kaspersky Lab]1
Trojan.Win32.TDSS.ajfg [Kaspersky Lab]1
Trojan.Win32.Tdss.ajkj [Kaspersky Lab]1
Trojan.Win32.TDSS.alra [Kaspersky Lab]1
Trojan:Win32/Alureon.gen!N [Microsoft]1
Trojan:Win32/InternetAntivirus [Microsoft]1
Trojan:Win32/Vundo.gen!G [Microsoft]1
Trojan-Dropper.Win32.FakeSmoke [Ikarus]1
Trojan-Spy.Win32.Chadem [Ikarus]1
TrojanSpy:Win32/Chadem.A [Microsoft]1
Win-Trojan/Agent2.20480.BU [AhnLab]1
Win-Trojan/Alureon.67584 [AhnLab]1
Win-Trojan/Cosmu.71680.B [AhnLab]1
Win-Trojan/Zpack.26624.B [AhnLab]1

Mal/TDSSPack-A [Sophos] has the following possible country of origin:
OriginNumber of Incidents
Russian Federation7

Mal/TDSSPack-A [Sophos] is known to be created as:
%AllUsersProfile%\microsoft private data\microsoft\lan.dll
%AppData%\microsoft\windows\winlogon.exe
%ProgramFiles%\pc scout\uninstall.exe
%System%\dabezoda.dll
%System%\dipoveya.dll
%System%\drivers\senekawktevxiq.sys
%System%\fafaropu.dll
%System%\guyugadu.dll
%System%\halaneho.dll
%System%\mavasoze.dll
%System%\muyolule.dll
%System%\ranolobi.dll
%System%\refodegu.dll
%System%\refurepo.dll
%System%\sanefaju.dll
%System%\uacuyagesjqdsktqxt.dll
%System%\yaguwune.dll
%System%\yibuvido.dll
%System%\yupabeda.dll
%System%\zekagawi.dll
%Temp%\agaopdxkdldobqp.sys
%Temp%\b.dll
%Temp%\c.dll
%Temp%\d.dll
%Temp%\e.dll
%Temp%\file.exe
%Temp%\files\rezakaju.dll
%Temp%\files\wuturoho.dll
%Temp%\ifxayqokvy.dll
%Temp%\losesafa.dll
%Temp%\merunime.dll
%Temp%\sedehobi.dll
%Temp%\sysinet.dll
%Temp%\uacjakhqdkobr.dll
%Temp%\uacjvhwuuxvvj.dll
%Temp%\uackaadsetakr.dll
%Temp%\uacpmoijwdkuh.dll
%Temp%\vavanoho.dll
Notes:
  • %AllUsersProfile% is a variable that specifies the all users' profile folder. By default, this is C:\Documents and Settings\All Users (Windows NT/2000/XP).
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).