Threat Search: 

ThreatExpert's Statistics for Trojan.TDSServ [PC Tools]:

Trojan.TDSServ [PC Tools] is also known as:
Threat AliasNumber of Incidents
Troj/AdvHack-A [Sophos]1,131
Backdoor.Tidserv!inf [Symantec]1,038
Trojan:Win32/Alureon.BB [Microsoft]984
DNSChanger.o [McAfee]855
Trojan.Fakeavalert!sd6 [PC Tools]843
Trojan.Win32.Patched.dy [Kaspersky Lab]750
Packed.Win32.PePatch [Ikarus]528
Generic.dx [McAfee]497
Trojan.Fakeavalert [Symantec]391
Trojan.Patched.CL [Ikarus]372
Trojan.FakeAlert [PC Tools]276
Trojan.SillyWorm [PC Tools]252
Trojan.Win32.Patched [Ikarus]216
Generic BackDoor.t [McAfee]108
Packed.Win32.PePatch.lb [Kaspersky Lab]93
W32/Autorun-KO [Sophos]60
Trojan.Patched.CK [Ikarus]48
FakeAlert-AG.gen.a [McAfee]30
Trojan.Knowedel [Symantec]30
Mal/EncPk-CZ [Sophos]27
Worm.Autorun.ABH [PC Tools]27
TrojanDownloader:Win32/Renos.gen!AQ [Microsoft]26
Packed.Generic.188 [Symantec]23
Backdoor.Win32.TDSS.zj [Kaspersky Lab]22
Mal/EncPk-EQ [Sophos]21
DNSChanger.gen [McAfee]20
Trojan:Win32/Alureon.gen!N [Microsoft]20
Backdoor.Win32.UltimateDefender.gen [Kaspersky Lab]16
Trojan-Downloader.Win32.Renos.AQ [Ikarus]16
Backdoor.TDSS!sd6 [PC Tools]14
Backdoor.Tidserv [Symantec]13
Trojan Horse [Symantec]10
Trojan:Win32/Alureon.gen!U [Microsoft]10
FakeAlert-SpywareGuard.gen.b [McAfee]9
Win-Trojan/Agent.35840.KQ [AhnLab]8
Mal/EncPk-CZ, Mal/TDSSPack-Q [Sophos]7
Trojan:Win32/Sudiet.B [Microsoft]5
Win-Trojan/Xema.variant [AhnLab]5
Hoax.Win32.Renos.ebd [Kaspersky Lab]4
Rootkit.Win32.TDSS.bph [Kaspersky Lab]4
Trojan.Win32.Agent2.grj [Kaspersky Lab]4
W32/AutoRun-ADF [Sophos]4
Win-Trojan/Agent2.52224.B [AhnLab]4
Worm:Win32/Autorun.MBS [Microsoft]4
Mal/Generic-A [Sophos]3
Mal/TDSS-A [Sophos]3
Packed.Win32.Tdss.b [Kaspersky Lab]3
Packed.Generic.200 [Symantec]2
Trojan.Crypt [Ikarus]2
Trojan.Win32.Tdss.ajuu [Kaspersky Lab]2
Win-Trojan/Agent.89088.CV [AhnLab]2
Backdoor.Win32.TDSS [Ikarus]1
Backdoor.Win32.TDSS.bkw [Kaspersky Lab]1
Backdoor.Win32.TDSS.blh [Kaspersky Lab]1
DNSChanger.f.gen.a [McAfee]1
Generic FakeAlert.a [McAfee]1
Generic PUP.x [McAfee]1
Generic Rootkit.d [McAfee]1
Generic.dx!bwg [McAfee]1
Mal/EncPk-HT, Mal/FakeVirPk-A, Mal/TDSS-A [Sophos]1
Rootkit.Win32.TDSS.cgh [Kaspersky Lab]1
Rootkit.Win32.TDSS.dbg [Kaspersky Lab]1
Rootkit.Win32.TDSS.eyj [Kaspersky Lab]1
RTKT_STITCH.D [Trend Micro]1
Troj/Agent-IGC [Sophos]1
Troj/Agent-IWC [Sophos]1
Troj/Rootkit-ED [Sophos]1
Trojan.Win32.Alureon.AW [Ikarus]1
Trojan.Win32.Tdss [Ikarus]1
Trojan.Win32.TDSS.amaw [Kaspersky Lab]1
Trojan:Win32/Alureon.AW [Microsoft]1
Trojan:Win32/Alureon.gen!C [Microsoft]1
Trojan:WinNT/Alureon.D [Microsoft]1
Trojan-Downloader.Win32.FraudLoad.vbxt [Kaspersky Lab]1
Trojan-PSW.Win32.Agent.lqj [Kaspersky Lab]1
Trojan-PWS.Win32.Agent [Ikarus]1
Trojan-Spy.Win32.Small.cbd [Kaspersky Lab]1
Win-Trojan/Agent.35840.JC [AhnLab]1
Win-Trojan/Rootkit.60416 [AhnLab]1

Trojan.TDSServ [PC Tools] is known to be created as:
%AppData%\chat republic games\superstar racing\advapi32.dll
%AppData%\login king\advapi32.dll
%CommonAppData%\advapi32.dll
%CommonAppData%\pinnacle\pixie\advapi32.dll
%FontsDir%\advapi32.dll
%ProgramFiles%\algbre\ag-pro2008\advapi32.dll
%ProgramFiles%\c-media\win_me\advapi32.dll
%ProgramFiles%\driverguide cd\files\html\advapi32.dll
%ProgramFiles%\gateway\hpa\advapi32.dll
%ProgramFiles%\gateway\power management\advapi32.dll
%ProgramFiles%\granado espada\advapi32.dll
%ProgramFiles%\pdf995\advapi32.dll
%ProgramFiles%\shaw\bin\advapi32.dll
%ProgramFiles%\skyline\terraexplorer\advapi32.dll
%ProgramFiles%\xerox\support centre\advapi32.dll
%System%\advapi.dll
%System%\advapi32.dll.exe
%System%\engines\advapi32.dll
%System%\kc4wog.dll
%System%\nep.dll
%System%\ok\advapi32.dll
%System%\tdssl.dll
%System%\tdssoeqh.dll
%System%\zoijyarwq.dll
%Temp%\adv_api.dll
%Temp%\advapi32.dll
%Temp%\b.dll
%Temp%\fglclienttemp\advapi32.dll
%Temp%\kpninstall\advapi32.dll
%Temp%\retscreen\retscreen4\advapi32.dll
%Temp%\tempadv.dll
%Temp%\ws\advapi32.dll
%Windir%\advapi32.dll
%Windir%\driver cache\advapi32.dll
%Windir%\temp\powerplugs3denhancedpresentation\advapi32.dll
c:\clippad995\advapi32.dll
c:\conshs\advapi32.dll
c:\plantvisor\servercomponents\advapi32.dll
c:\temp\qremove\advapi32.dll
c:\zip995\advapi32.dll
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.