PDA

View Full Version : Trojan Mutex(es) Found


chasman
October 13th, 2003, 10:41 PM
I am having a problem with a box that is showing the following message during a Mutex Memory Scan - Trojan Mutex(es) Found ... No other details are given and it doesn't look as though anything odd is running in the process list.
Additionally, a full system scan reveals nothing about any possible trojan.

Is this a false-positive or is it something that I should be concerned about and if it is something to be concerned about how can I discover the infected file.

The TDS version in use is 3.2.1

Regards,
Charles
buynsellit.com

Gavin - DiamondCS
October 14th, 2003, 12:16 AM
False (non) alarm :) This does happen sometimes..

Do you use Tiny Trojan Trap ? ;D

There was an issue where it was stopping the proper running of the mutex checking module. TDS does at this time try to create mutexes, if they already exist then there is danger. However if something stops the creation, TDS will fall over and give this strange looking alarm you are seeing.

TDS-4 wont take this approach anyway, and wont give any false warnings like that :)

chasman
October 14th, 2003, 03:22 PM
Gavin,

Thanks for the quick reply !!!

We are not using the Tiny Trojan Trap, but do have an IDS running on the box (that is a fairly new install).

Cheers,
Charles
buynsellit.com