A key found in the registry indicates the TDL3/TDSS/Tidserv rootkit is infecting the host. Key: HKLM\SOFTWARE\TDSS Key: HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys (This audit tests for the TLD3/TDSS/Tidserv rootkit, as defined at: http://www.f-secure.com/v-descs/backdoor_w32_tdss.shtml)