TDSSConf.A

TDSSConf.A Description

TDSSConf.A is a dangerous malware infection that may install harmful compressed files onto the affected PC system. Once TDSSConf.A installs on your computer system, it always traces your online activities and steals your confidential data, such as credit card information, bank details, login details, etc. TDSSConf.A can create additional files that add files that run on the hard disk. You need to remove TDSSConf.A immediately from your computer before it harms your PC system.

Technical Information

File System Details

TDSSConf.A creates the following file(s):
# File Name Detection Count
1 C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe N/A
2 C:\Program Files\Mozilla Firefox\firefox.exe N/A
3 C:\Program Files\SafeConnect\scManager.sys N/A
4 C:\WINDOWS\system32\hkcmd.exe N/A
5 C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe N/A
6 C:\WINDOWS\system32\ctfmon.exe N/A
7 C:\Program Files\iPod\bin\iPodService.exe N/A
8 C:\Program Files\Bonjour\mDNSResponder.exe N/A
9 C:\WINDOWS\Explorer.EXE N/A
10 C:\WINDOWS\AGRSMMSG.exe N/A
11 C:\Program Files\Winamp\winampa.exe N/A
12 C:\Program Files\SafeConnect\scClient.exe N/A
13 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe N/A
14 C:\WINDOWS\system32\svchost.exe N/A
15 C:\WINDOWS\SOUNDMAN.EXE N/A

Registry Details

TDSSConf.A creates the following registry entry or registry entries:
RegistryKey
HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
HKLM\..\Run: [ATSwpNav] "C:\Program Files\Fingerprint Sensor\ATSwpNav" -run
HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page
HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page
HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL
HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext