TDSS.d!men

By LoneStar in Rootkits

TDSS.d!men is a rootkit detection that belongs to the TDSS family of rootkits. TDSS.d!men circulates mostly via free game, song or movie downloads, malicious adult websites, chat and messaging systems and spam emails. TDSS.d!men can collect and send your personal information to remote attackers. TDSS.d!men may also modify essential system executable files, which may then be used to hide files and processes installed by the attackers. It is highly recommended to uninstall TDSS.d!men as soon as you can immediately after detection.

File System Details

TDSS.d!men may create the following file(s):
# File Name Detections
1. %UserProfile%\804127477.exe
2. %AppData%\Ncxaxn.exe
3. %UserProfile%\r

Registry Details

TDSS.d!men may create the following registry entry or registry entries:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] 804127477 = "%UserProfile%\804127477.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent] (Default) =
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent] (Default) =
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\PchSvc] DataCollection =

Trending

Most Viewed

Loading...