Threat Search: 

ThreatExpert's Statistics for Packed.Win32.Tdss.c [Kaspersky Lab]:

Packed.Win32.Tdss.c [Kaspersky Lab] is also known as:
Threat AliasNumber of Incidents
Mal/EncPk-CZ [Sophos]110
TrojanDownloader:Win32/Renos.gen!AQ [Microsoft]85
Virus.Win32.Fasec [Ikarus]82
Packed.Generic.200 [Symantec]77
TROJ_FAKEAV.MQ [Trend Micro]75
Trojan.Blusod [Symantec]70
DNSChanger.r [McAfee]56
Trojan.Blusod!sd6 [PC Tools]50
Trojan.Fakealert.AFB [Ikarus]50
Joke-Bluescreen.c [McAfee]45
Generic Downloader.x [McAfee]31
Win-Trojan/Xema.variant [AhnLab]28
Mal/EncPk-GR, Mal/EncPk-GR [Sophos]24
Trojan:Win32/Alureon.gen!J [Microsoft]23
Trojan:Win32/Vundo.JC.dll [Microsoft]20
VirTool:Win32/CeeInject.gen!J [Microsoft]19
Trojan Horse [Symantec]16
Mal/Alureon-C, Mal/FakeVirPk-A [Sophos]14
Trojan-Downloader.Win32.Renos.AQ [Ikarus]14
VirTool.Win32.CeeInject [Ikarus]11
DNSChanger.f.gen.a [McAfee]10
Packed.Win32.Tdss [Ikarus]10
Rootkit.Win32.TDSS [Ikarus]10
Win-Trojan/Fakeav.118784.B [AhnLab]10
Mal/FakeVirPk-A, Mal/EncPk-CZ [Sophos]8
SpywareGuard2008 [Symantec]8
W32/Xirtem@MM [McAfee]8
Backdoor.Trojan [Symantec]7
Mal/FakeVirPk-A [Sophos]7
Packed.Win32.Tdss.f [Kaspersky Lab]7
Rootkit.TDSS!sd6 [PC Tools]7
DNSChanger.gen [McAfee]6
Generic FakeAlert.c [McAfee]6
Mal/TDSS-A [Sophos]6
Trojan.TDss.1 [Ikarus]6
Trojan.Win32.FakeSpyguard [Ikarus]6
Trojan:Win32/Alureon.gen [Microsoft]6
Trojan:Win32/FakeSpyguard [Microsoft]6
Trojan:Win32/Sudiet.B [Microsoft]6
W32/Autorun-XI [Sophos]6
W32/AutoVrt-Gen, Mal/CryptBox-A [Sophos]6
Worm.Win32.AutoTDSS [Ikarus]6
Trojan.FakeAlert [PC Tools]5
Trojan.Win32.Alureon [Ikarus]5
Trojan:Win32/InternetAntivirus [Microsoft]5
TrojanDownloader:Win32/Rugzip.A [Microsoft]5
BackDoor-DVT [McAfee]4
Generic.dx [McAfee]4
Mal/EncPk-GR, Mal/EncPk-GR, Mal/TDSSPack-E [Sophos]4
Mal/FakeVirPk-A, Mal/TDSS-A [Sophos]4
Troj/Mdrop-BZI [Sophos]4
Virus.Win32.Rootkit [Ikarus]4
Generic FakeAlert.h [McAfee]3
Mal/Alureon-C, Mal/Alureon-B, Mal/FakeAV-S [Sophos]3
Mal/CryptBox-A [Sophos]3
Trojan:WinNT/Alureon.C [Microsoft]3
Win-Trojan/Fraudpack.37245 [AhnLab]3
Generic FakeAlert.k [McAfee]2
Mal/Alureon-C, Mal/Alureon-B [Sophos]2
Mal/Alureon-C, Mal/Alureon-B, Mal/FakeAV-S, Mal/FakeVirPk-A [Sophos]2
Mal/EncPk-HT [Sophos]2
Mal/Generic-A [Sophos]2
Mal/TDSS-A, Mal/EncPk-CZ [Sophos]2
Mal/TDSSPack-A, Mal/EncPk-CZ [Sophos]2
Mal/TDSSPack-E, Mal/Alureon-C, Mal/FakeVirPk-A [Sophos]2
Rootkit.Win32.TDSS.eyj [Kaspersky Lab]2
Troj/FakeVir-KG [Sophos]2
Trojan.TDss [Ikarus]2
Trojan:Win32/Witer.B [Microsoft]2
VirTool:Win32/DelfInject.gen!L [Microsoft]2
Win32/Autotdss.worm.30720 [AhnLab]2
Backdoor.Bifrose [Symantec]1
Backdoor.Tidserv [Symantec]1
Backdoor.Win32.TDSS [Ikarus]1
Constructor.Win32.Bifrose.j [Kaspersky Lab]1
Downloader.MisleadApp [Symantec]1
Dropper/DnsChanger.65536 [AhnLab]1
FakeAlert-AB.gen.e [McAfee]1
FakeAlert-SpywareGuard.gen.b [McAfee]1
Generic BackDoor [McAfee]1
Generic BackDoor.u [McAfee]1
Generic Dropper [McAfee]1
Generic Dropper.dp [McAfee]1
Generic PUP.z [McAfee]1
InternetAntivirus [Symantec]1
Mal/Alureon-A [Sophos]1
Mal/Alureon-B, Mal/FakeAV-S [Sophos]1
Mal/Alureon-C, Mal/FakeVirPk-A, Troj/Virtum-Gen [Sophos]1
Mal/EncPk-IT [Sophos]1
Mal/FakeAV-AD, Mal/Alureon-C, Mal/FakeVirPk-A, Troj/Virtum-Gen [Sophos]1
Mal/FakeAV-AD, Mal/TDSSPack-A, Mal/TDSSPack-E, Mal/EncPk-CZ, Troj/Virtum-Gen [Sophos]1
Mal/FakeAV-M [Sophos]1
Mal/FakeVirPk-A, Mal/TDSS-A, Mal/TDSS-C [Sophos]1
Mal/RootKit-Fam, Mal/Alureon-A [Sophos]1
Mal/TDSSPack-E, Mal/Alureon-C [Sophos]1
Mal/TDSSPack-E, Mal/TDSSPack-A, Mal/FakeVirPk-A, Mal/EncPk-CZ, Troj/Virtum-Gen [Sophos]1
Mal/TDSSPack-Q, Mal/EncPk-HT, Mal/TDSS-A [Sophos]1
not-a-virus:FraudTool.Win32.InternetAntivirusPro.m [Kaspersky Lab]1
Packed.Generic.188 [Symantec]1
Program:Win32/FakeWG.A [Microsoft]1

Packed.Win32.Tdss.c [Kaspersky Lab] has the following possible country of origin:
OriginNumber of Incidents
Russian Federation28

Packed.Win32.Tdss.c [Kaspersky Lab] is known to be created as:
%CommonAppData%\microsoft\network\dlls\iemodule.dll
%CommonAppData%\microsoft\network\dlls\ofphdqyidn.dll
%CommonAppData%\microsoft\network\dlls\qnxdsbimtf.dll
%CommonAppData%\microsoft\network\install.exe
%CommonAppData%\svhost.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\loz\regedit.exe
%ProgramFiles%\system guard 2009\systemguard.exe
%ProgramFiles%\system guard 2009\uninstall.exe
%System%\bifrost\server.exe
%System%\blphc35dj0erc1.scr
%System%\dgmoeqh.dll
%System%\drivers\dgmpqxt.sys
%System%\drivers\skynetnmfvxtqx.sys
%System%\javame.exe
%System%\javame1.1.exe
%System%\javame2.exe
%System%\javame4.exe
%System%\jmx.exe
%System%\kdfnh.exe
%System%\kdjlv.exe
%System%\kdjrf.exe
%System%\kdpvv.exe
%System%\kdwau.exe
%System%\kdwfk.exe
%System%\sa\ses.exe
%System%\senekaaelyvfva.dll
%System%\senekadbyuscvn.dll
%System%\senekaelbqfoow.dll
%System%\senekagambcjpe.dll
%System%\senekagvrchxfy.dll
%System%\senekaiylbjlxi.dll
%System%\senekakbkuktqs.dll
%System%\senekalkbevyic.dll
%System%\senekamiqufjpy.dll
%System%\senekapdkswqwe.dll
%System%\senekasvthfger.dll
%System%\senekaxeqcxnqv.dll
%System%\uacpylxbwqj.dll
%System%\winscenter.exe
%Temp%\ixp000.tmp\ere.exe
%Temp%\ma_r.exe
%Temp%\ma_v.exe
%Temp%\stub.exe
c:\resycled\boot.com
c:\resycled\ntldr.com
c:\server.exe
Notes:
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).