JCC
December 29th, 2003, 07:51 AM
I did a full system scan. My results are below.
As you can see, there are some locked files. If TDS cannot open them, how can it test them for Trojans?
Also, what is the point of the "show all streams option" if TDS doesn't find Trojans or executables in them? Are streams dangerous even if TDS doesn't find executables and Trojans in them?
I hope I don't sound to frustrated. I am having fun learning this program.
Scan Results:
23:37:13 [Init] Trojan Defence Suite v3.2.0 (UNLICENSED)
23:37:13 [Init] Started 28-12-03 23:37:13 Pacific Standard Time (UTC: 8), Internet Time @1359.18
23:37:13 [Init] Loading TDS-3 Systems ...
23:37:13 [Init] Token successfully adjusted.
23:37:13 [Init] • TDS Privileges : OK. Adjusted TDS-3 token privileges to maximum
23:37:13 [Init] • Plugins : OK. Loaded 13
23:37:13 [Init] • Exec Protection : Not Installed
23:37:13 [Init] WARNING: Your Radius.TD3 database needs to be updated!
23:37:13 [Init] Please download the latest from http://tds.diamondcs.com.au/radius.td3
23:37:13 [Init] Licensed users can use the Update facility from the TDS menu
23:37:13 [Init] Loading Radius Advanced Scanning Systems ... <R3 Engine, DCS Labs>
23:37:18 [Init] • Radius Advanced Specialist Extensions on standby for 13 trojan families
23:37:18 [Init] • Systems Initialised [30784 references - 10832 primaries/8859 traces/11093 variants/other]
23:37:18 [Init] Radius Systems loaded. <Databases updated 27-12-2003>
23:37:18 [Init] TDS-3 Ready.
23:37:18 [Tip Of The Day] DiamondCS have, and continue to develop a wide range of software, including the world's original and still the strongest BO2K scanner. Visit http://www.diamondcs.com.au for free downloads!
23:37:18 [TDS] Good evening Joe.
23:37:21 [Mutex Memory Scan] Started...
23:37:23 [Mutex Memory Scan] Finished (no trojan mutexes found).
23:37:23 [Trace Scan] Started...
23:37:30 [Trace Scan] Finished.
23:37:30 [TDS-3] This is an EVALUATION demo of TDS-3. Please see the help file for help on registering.
23:38:22 [CRC32] Started - verifying 29 files ...
23:38:25 [CRC32] Test finished.
23:40:05 [Memory Scan] Memory scan started, please wait a moment ...
23:40:07 [Memory Scan] Memory scan complete.
23:40:07 [Mutex Memory Scan] Started...
23:40:09 [Mutex Memory Scan] Finished (no trojan mutexes found).
23:40:09 [Trace Scan] Started...
23:40:16 [Trace Scan] Finished.
23:40:16 [ServiceScan] Scanning for services and drivers ...
23:40:19 [ServiceScan] Scanned 302 services and drivers.
23:40:19 [File Scan] Scanning in A:\ ...
23:40:20 [File Scan] Scanned 0 files: 0 alarms in 1.085938 seconds (Avg 1. files/sec)
23:40:20 [File Scan] Scanning in C:\ ...
23:40:24 [NTFS ADS] Stream found - c:\documents and settings\all users\application data\microsoft\windows nt\msfax\sentitems\s-1-5-21-927890586-3685698554-67682326-1005$201c3c3defd6bea.tif:Xj1phwzh5qcwungrN45kt3kiCe
23:40:24 [NTFS ADS] Stream found - c:\documents and settings\all users\application data\microsoft\windows nt\msfax\sentitems\s-1-5-21-927890586-3685698554-67682326-1005$201c3c3df944244.tif:Xj1phwzh5qcwungrN45kt3kiCe
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq307274$\spuninst\spuninst.exe for read access, file is locked
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq308131$\spuninst\spuninst.exe for read access, file is locked
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq308402$\spuninst\spuninst.exe for read access, file is locked
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq308677$\spuninst\spuninst.exe for read access, file is locked
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq311345$\spuninst\spuninst.exe for read access, file is locked
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq311455$\spuninst\spuninst.exe for read access, file is locked
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq311889$\spuninst\spuninst.exe for read access, file is locked
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq312368$\spuninst\spuninst.exe for read access, file is locked
23:51:22 [Locked File] Couldn't open c:\windows\$ntuninstallq314412$\spuninst\spuninst.exe for read access, file is locked
23:51:22 [Locked File] Couldn't open c:\windows\$ntuninstallq315000$\netsetup.exe for read access, file is locked
23:51:22 [Locked File] Couldn't open c:\windows\$ntuninstallq315000$\spuninst\spuninst.exe for read access, file is locked
00:00:36 [File Scan] Scanned 35127 files: 2 alarms in -85184.13 seconds (Avg .59 files/sec)
00:00:36 [File Scan] Scanning in D:\ ...
00:00:36 [File Scan] Scanned 0 files: 2 alarms in 9.998322E-03 seconds (Avg 1. files/sec)
00:00:36 [Scan] Finished.
As you can see, there are some locked files. If TDS cannot open them, how can it test them for Trojans?
Also, what is the point of the "show all streams option" if TDS doesn't find Trojans or executables in them? Are streams dangerous even if TDS doesn't find executables and Trojans in them?
I hope I don't sound to frustrated. I am having fun learning this program.
Scan Results:
23:37:13 [Init] Trojan Defence Suite v3.2.0 (UNLICENSED)
23:37:13 [Init] Started 28-12-03 23:37:13 Pacific Standard Time (UTC: 8), Internet Time @1359.18
23:37:13 [Init] Loading TDS-3 Systems ...
23:37:13 [Init] Token successfully adjusted.
23:37:13 [Init] • TDS Privileges : OK. Adjusted TDS-3 token privileges to maximum
23:37:13 [Init] • Plugins : OK. Loaded 13
23:37:13 [Init] • Exec Protection : Not Installed
23:37:13 [Init] WARNING: Your Radius.TD3 database needs to be updated!
23:37:13 [Init] Please download the latest from http://tds.diamondcs.com.au/radius.td3
23:37:13 [Init] Licensed users can use the Update facility from the TDS menu
23:37:13 [Init] Loading Radius Advanced Scanning Systems ... <R3 Engine, DCS Labs>
23:37:18 [Init] • Radius Advanced Specialist Extensions on standby for 13 trojan families
23:37:18 [Init] • Systems Initialised [30784 references - 10832 primaries/8859 traces/11093 variants/other]
23:37:18 [Init] Radius Systems loaded. <Databases updated 27-12-2003>
23:37:18 [Init] TDS-3 Ready.
23:37:18 [Tip Of The Day] DiamondCS have, and continue to develop a wide range of software, including the world's original and still the strongest BO2K scanner. Visit http://www.diamondcs.com.au for free downloads!
23:37:18 [TDS] Good evening Joe.
23:37:21 [Mutex Memory Scan] Started...
23:37:23 [Mutex Memory Scan] Finished (no trojan mutexes found).
23:37:23 [Trace Scan] Started...
23:37:30 [Trace Scan] Finished.
23:37:30 [TDS-3] This is an EVALUATION demo of TDS-3. Please see the help file for help on registering.
23:38:22 [CRC32] Started - verifying 29 files ...
23:38:25 [CRC32] Test finished.
23:40:05 [Memory Scan] Memory scan started, please wait a moment ...
23:40:07 [Memory Scan] Memory scan complete.
23:40:07 [Mutex Memory Scan] Started...
23:40:09 [Mutex Memory Scan] Finished (no trojan mutexes found).
23:40:09 [Trace Scan] Started...
23:40:16 [Trace Scan] Finished.
23:40:16 [ServiceScan] Scanning for services and drivers ...
23:40:19 [ServiceScan] Scanned 302 services and drivers.
23:40:19 [File Scan] Scanning in A:\ ...
23:40:20 [File Scan] Scanned 0 files: 0 alarms in 1.085938 seconds (Avg 1. files/sec)
23:40:20 [File Scan] Scanning in C:\ ...
23:40:24 [NTFS ADS] Stream found - c:\documents and settings\all users\application data\microsoft\windows nt\msfax\sentitems\s-1-5-21-927890586-3685698554-67682326-1005$201c3c3defd6bea.tif:Xj1phwzh5qcwungrN45kt3kiCe
23:40:24 [NTFS ADS] Stream found - c:\documents and settings\all users\application data\microsoft\windows nt\msfax\sentitems\s-1-5-21-927890586-3685698554-67682326-1005$201c3c3df944244.tif:Xj1phwzh5qcwungrN45kt3kiCe
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq307274$\spuninst\spuninst.exe for read access, file is locked
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq308131$\spuninst\spuninst.exe for read access, file is locked
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq308402$\spuninst\spuninst.exe for read access, file is locked
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq308677$\spuninst\spuninst.exe for read access, file is locked
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq311345$\spuninst\spuninst.exe for read access, file is locked
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq311455$\spuninst\spuninst.exe for read access, file is locked
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq311889$\spuninst\spuninst.exe for read access, file is locked
23:51:21 [Locked File] Couldn't open c:\windows\$ntuninstallq312368$\spuninst\spuninst.exe for read access, file is locked
23:51:22 [Locked File] Couldn't open c:\windows\$ntuninstallq314412$\spuninst\spuninst.exe for read access, file is locked
23:51:22 [Locked File] Couldn't open c:\windows\$ntuninstallq315000$\netsetup.exe for read access, file is locked
23:51:22 [Locked File] Couldn't open c:\windows\$ntuninstallq315000$\spuninst\spuninst.exe for read access, file is locked
00:00:36 [File Scan] Scanned 35127 files: 2 alarms in -85184.13 seconds (Avg .59 files/sec)
00:00:36 [File Scan] Scanning in D:\ ...
00:00:36 [File Scan] Scanned 0 files: 2 alarms in 9.998322E-03 seconds (Avg 1. files/sec)
00:00:36 [Scan] Finished.