RIFLEMAN
February 16th, 2004, 08:21 AM
Hello. I have used TDS for a week now and just found it wasn't scanning my entire drive so I reconfigured it to do so. As it scans right now it has many alarms showing these NTFS Alternate data streams. I see a couple of email addresses that I sent mail to and also a few that I didn't. What in the heck are these things? I am pretty green when it comes to this stuff; but have suspected a problem for some time now. Is there anything in there I should be concerned about? Thanks for your time.
:43:45 Trojan Defence Suite v3.2.0 (UNLICENSED)
06:43:45 [Init] Started 16-02-04 06:43:45 Eastern Standard Time (UTC: 5), Internet Time @530.38
06:43:45 [Init] Loading TDS-3 Systems ...
06:43:45 [Init] Token successfully adjusted.
06:43:45 [Init] • TDS Privileges : OK. Adjusted TDS-3 token privileges to maximum
06:43:45 [Init] • Plugins : OK. Loaded 13
06:43:45 [Init] • Exec Protection : Not Installed
06:43:45 [Init] WARNING: Your Radius.TD3 database needs to be updated!
06:43:45 [Init] Please download the latest from http://tds.diamondcs.com.au/radius.td3
06:43:45 [Init] Licensed users can use the Update facility from the TDS menu
06:43:46 [Init] Loading Radius Advanced Scanning Systems ... <R3 Engine, DCS Labs>
06:43:51 [Init] • Radius Advanced Specialist Extensions on standby for 13 trojan families
06:43:51 [Init] • Systems Initialised [31795 references - 11432 primaries/9084 traces/11279 variants/other]
06:43:51 [Init] Radius Systems loaded. <Databases updated 11-02-2004>
06:43:51 [Init] TDS-3 Ready. <[i]Edit Canada>
06:43:51 [Tip Of The Day] Visit the TDS-3 homepage at http://tds.diamondcs.com.au regularly to check for updates.
06:43:51 [TDS] Good morning Rifleman Working early?
06:43:55 [Mutex Memory Scan] Started...
06:43:57 [Mutex Memory Scan] Finished (no trojan mutexes found).
06:43:57 [Trace Scan] Started...
06:44:06 [Trace Scan] Finished.
06:44:06 [TDS-3] This is an EVALUATION demo of TDS-3. Please see the help file for help on registering.
06:44:24 [Trace Scan] Started...
06:44:33 [Trace Scan] Finished.
06:44:42 [Memory Scan] Memory scan started, please wait a moment ...
06:44:43 [Memory Scan] Memory scan complete.
06:59:11 [Trace Scan] Started...
06:59:21 [Trace Scan] Finished.
06:59:21 [Service\Driver Scan] Scanning for services and drivers ...
06:59:24 [Service\Driver Scan] Scanned 266 services and drivers.
06:59:24 [File Scan] Scanning in C:\WINDOWS\ ...
07:00:55 [File Scan] Scanned 1613 files: 0 alarms in 90.57813 seconds (Avg 18.81 files/sec)
07:00:55 [Scan] Finished.
07:02:38 [Trace Scan] Started...
07:02:48 [Trace Scan] Finished.
07:02:48 [Service\Driver Scan] Scanning for services and drivers ...
07:02:51 [Service\Driver Scan] Scanned 266 services and drivers.
07:02:51 [File Scan] Scanning in C:\WINDOWS\ ...
07:12:16 [File Scan] Scanned 9161 files: 0 alarms in 564.0938 seconds (Avg 17.24 files/sec)
07:12:16 [File Scan] Scanning in C:\ ...
07:12:16 [NTFS ADS] Stream found - c:\aaw.exe:SummaryInformation
07:12:17 [NTFS ADS] Stream found - c:\aaw.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
07:12:18 [NTFS ADS] Stream found - c:\lrsetup.exe:SummaryInformation
07:12:18 [NTFS ADS] Stream found - c:\lrsetup.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
07:12:18 [NTFS ADS] Stream found - c:\zasetup_37_143.exe:SummaryInformation
07:12:18 [NTFS ADS] Stream found - c:\zasetup_37_143.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
07:21:15 [Script Error] ERR: Type mismatch: 'hello' (LINE: 1 COL:0)
07:31:53 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc20.exe for read access, file is locked
07:31:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc64.exe for read access, file is locked
07:31:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc65.exe for read access, file is locked
07:31:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc73.exe for read access, file is locked
07:31:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc83.exe for read access, file is locked
07:31:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc84.exe for read access, file is locked
07:31:55 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc126.exe:SummaryInformation
07:31:55 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc126.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
07:31:58 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc214:
07:31:58 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc215:
07:31:58 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc227:
07:42:38 [File Scan] Scanned 35719 files: 11 alarms in 1821.672 seconds (Avg 20.61 files/sec)
07:42:38 [File Scan] Scanning in C:\WINDOWS\ ...
07:51:08 [File Scan] Scanned 9161 files: 11 alarms in 509.4375 seconds (Avg 18.98 files/sec)
07:51:08 [File Scan] Scanning in C:\ ...
07:51:08 [NTFS ADS] Stream found - c:\aaw.exe:SummaryInformation
07:51:08 [NTFS ADS] Stream found - c:\aaw.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
07:51:09 [NTFS ADS] Stream found - c:\lrsetup.exe:SummaryInformation
07:51:09 [NTFS ADS] Stream found - c:\lrsetup.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
07:51:09 [NTFS ADS] Stream found - c:\zasetup_37_143.exe:SummaryInformation
07:51:09 [NTFS ADS] Stream found - c:\zasetup_37_143.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
08:01:16 [TDS] Good morning Robert.
08:10:53 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc20.exe for read access, file is locked
08:10:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc64.exe for read access, file is locked
08:10:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc65.exe for read access, file is locked
08:10:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc73.exe for read access, file is locked
08:10:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc83.exe for read access, file is locked
08:10:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc84.exe for read access, file is locked
08:10:55 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc126.exe:SummaryInformation
08:10:55 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc126.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
08:10:59 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc214:
08:10:59 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc215:
08:10:59 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc227:
08:21:52 [File Scan] Scanned 35853 files: 22 alarms in 1843.984 seconds (Avg 20.44 files/sec)
08:21:52 [Scan] Finished.
08:25:01 [Screen Text] Saved to C:\Program Files\TDS3\scr0.txt
r perusal and some help? Thanks for the ime.
:43:45 Trojan Defence Suite v3.2.0 (UNLICENSED)
06:43:45 [Init] Started 16-02-04 06:43:45 Eastern Standard Time (UTC: 5), Internet Time @530.38
06:43:45 [Init] Loading TDS-3 Systems ...
06:43:45 [Init] Token successfully adjusted.
06:43:45 [Init] • TDS Privileges : OK. Adjusted TDS-3 token privileges to maximum
06:43:45 [Init] • Plugins : OK. Loaded 13
06:43:45 [Init] • Exec Protection : Not Installed
06:43:45 [Init] WARNING: Your Radius.TD3 database needs to be updated!
06:43:45 [Init] Please download the latest from http://tds.diamondcs.com.au/radius.td3
06:43:45 [Init] Licensed users can use the Update facility from the TDS menu
06:43:46 [Init] Loading Radius Advanced Scanning Systems ... <R3 Engine, DCS Labs>
06:43:51 [Init] • Radius Advanced Specialist Extensions on standby for 13 trojan families
06:43:51 [Init] • Systems Initialised [31795 references - 11432 primaries/9084 traces/11279 variants/other]
06:43:51 [Init] Radius Systems loaded. <Databases updated 11-02-2004>
06:43:51 [Init] TDS-3 Ready. <[i]Edit Canada>
06:43:51 [Tip Of The Day] Visit the TDS-3 homepage at http://tds.diamondcs.com.au regularly to check for updates.
06:43:51 [TDS] Good morning Rifleman Working early?
06:43:55 [Mutex Memory Scan] Started...
06:43:57 [Mutex Memory Scan] Finished (no trojan mutexes found).
06:43:57 [Trace Scan] Started...
06:44:06 [Trace Scan] Finished.
06:44:06 [TDS-3] This is an EVALUATION demo of TDS-3. Please see the help file for help on registering.
06:44:24 [Trace Scan] Started...
06:44:33 [Trace Scan] Finished.
06:44:42 [Memory Scan] Memory scan started, please wait a moment ...
06:44:43 [Memory Scan] Memory scan complete.
06:59:11 [Trace Scan] Started...
06:59:21 [Trace Scan] Finished.
06:59:21 [Service\Driver Scan] Scanning for services and drivers ...
06:59:24 [Service\Driver Scan] Scanned 266 services and drivers.
06:59:24 [File Scan] Scanning in C:\WINDOWS\ ...
07:00:55 [File Scan] Scanned 1613 files: 0 alarms in 90.57813 seconds (Avg 18.81 files/sec)
07:00:55 [Scan] Finished.
07:02:38 [Trace Scan] Started...
07:02:48 [Trace Scan] Finished.
07:02:48 [Service\Driver Scan] Scanning for services and drivers ...
07:02:51 [Service\Driver Scan] Scanned 266 services and drivers.
07:02:51 [File Scan] Scanning in C:\WINDOWS\ ...
07:12:16 [File Scan] Scanned 9161 files: 0 alarms in 564.0938 seconds (Avg 17.24 files/sec)
07:12:16 [File Scan] Scanning in C:\ ...
07:12:16 [NTFS ADS] Stream found - c:\aaw.exe:SummaryInformation
07:12:17 [NTFS ADS] Stream found - c:\aaw.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
07:12:18 [NTFS ADS] Stream found - c:\lrsetup.exe:SummaryInformation
07:12:18 [NTFS ADS] Stream found - c:\lrsetup.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
07:12:18 [NTFS ADS] Stream found - c:\zasetup_37_143.exe:SummaryInformation
07:12:18 [NTFS ADS] Stream found - c:\zasetup_37_143.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
07:21:15 [Script Error] ERR: Type mismatch: 'hello' (LINE: 1 COL:0)
07:31:53 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc20.exe for read access, file is locked
07:31:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc64.exe for read access, file is locked
07:31:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc65.exe for read access, file is locked
07:31:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc73.exe for read access, file is locked
07:31:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc83.exe for read access, file is locked
07:31:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc84.exe for read access, file is locked
07:31:55 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc126.exe:SummaryInformation
07:31:55 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc126.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
07:31:58 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc214:
07:31:58 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc215:
07:31:58 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc227:
07:42:38 [File Scan] Scanned 35719 files: 11 alarms in 1821.672 seconds (Avg 20.61 files/sec)
07:42:38 [File Scan] Scanning in C:\WINDOWS\ ...
07:51:08 [File Scan] Scanned 9161 files: 11 alarms in 509.4375 seconds (Avg 18.98 files/sec)
07:51:08 [File Scan] Scanning in C:\ ...
07:51:08 [NTFS ADS] Stream found - c:\aaw.exe:SummaryInformation
07:51:08 [NTFS ADS] Stream found - c:\aaw.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
07:51:09 [NTFS ADS] Stream found - c:\lrsetup.exe:SummaryInformation
07:51:09 [NTFS ADS] Stream found - c:\lrsetup.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
07:51:09 [NTFS ADS] Stream found - c:\zasetup_37_143.exe:SummaryInformation
07:51:09 [NTFS ADS] Stream found - c:\zasetup_37_143.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
08:01:16 [TDS] Good morning Robert.
08:10:53 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc20.exe for read access, file is locked
08:10:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc64.exe for read access, file is locked
08:10:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc65.exe for read access, file is locked
08:10:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc73.exe for read access, file is locked
08:10:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc83.exe for read access, file is locked
08:10:54 [Locked File] Couldn't open c:\recycler\qrspfaxogmtjuqjltvpaborobkqowmcmeewlajkipfqgnj\dc84.exe for read access, file is locked
08:10:55 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc126.exe:SummaryInformation
08:10:55 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc126.exe:(4c8cc155-6c1e-11d1-8e41-00c04fb9386d)
08:10:59 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc214:
08:10:59 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc215:
08:10:59 [NTFS ADS] Stream found - c:\recycler\s-1-5-21-1644491937-1788223648-839522115-1004\dc227:
08:21:52 [File Scan] Scanned 35853 files: 22 alarms in 1843.984 seconds (Avg 20.44 files/sec)
08:21:52 [Scan] Finished.
08:25:01 [Screen Text] Saved to C:\Program Files\TDS3\scr0.txt
r perusal and some help? Thanks for the ime.