PDA

View Full Version : Problem with 16/2/2005 update?


Pikachu762
February 17th, 2005, 12:54 AM
Hi...

I just updated TDS-3. After doing so, I tried to start Opera 7.54u1 and TDS prevented the executable from running, saying it detected Scramble Tool 0.2

I closed down TDS, restarted it, and the initial quick scans it does resulted in this:

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\avpersonal\avwupsrv.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\windows\system32\ctsvccda.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\processguard\dcsuserprot.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\windows\system32\nvsvc32.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\progra~1\agnitum\outpos~1.0\outpost.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\windows\explorer.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\windows\agrsmmsg.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\java\jre1.5.0\bin\jusched.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\processguard\pgaccount.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\avpersonal\avgnt.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\spybot - search & destroy\teatimer.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\processguard\procguard.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\united devices\ud.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\folding@home\winfah.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\united devices\ud_7174683.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\united devices\ud_7174683_0.dir\ud_ligfit_release.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\juno\exec.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\port explorer\portexplorer.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\juno\exec.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\avpersonal\avguard.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\program files\opera\opera.exe

Trojan Client\EditServer found: Scramble Tool 0.2 (Utility)
File: c:\windows\msagent\agentsvr.exe


I strongly suspect this is an error in the latest definitions. Or maybe I've been totally owned :) But until now, nothing has been detected by my AV or TDS.

As a secondary question, while I'm here... When I right click on a file from Explorer, the option to scan the file with TDS is there. Upon clicking to scan, however, nothing happens. I believe that I might have deleted the registry entry associated with this option while using RegSeeker to clean out my registry. Where in the registry should I create a new DWORD (or whatever) and what values or data should I include in it? Or would it be easier to just reinstall TDS? :)

Gavin - DiamondCS
February 17th, 2005, 02:45 AM
Try manually updating again please
http://tds.diamondcs.com.au/index.php?page=update

That is an old signature, and it must be a corrupt database.. maybe when you downloaded a few bytes in the database got corrupted to all 00 00 00 for this signature.. :)

Your right click scan would most likely be broken if you changed the location of the TDS folder, AFTER installing. If you did, rename/move it back to where it was. You can protect TDS with PG Free if you are worried about trojans attacking it

Pikachu762
February 17th, 2005, 03:27 AM
Thank you, Gavin. I have updated manually and changed the name of the directory back to the default. Everything is working fine now :)

Gavin - DiamondCS
February 17th, 2005, 06:10 AM
Great ! :)