haggard
June 3rd, 2003, 07:14 PM
I purchased TDS-3 last night and after reading through around 60% of the help files I can honestly say this trojan scanner is what I have been looking for. I only wish I was advanced enough to use some of its more complex and powerful tools.
However I have a few questions.
1. Once I activate the Environment Settings List I recieve only 7 values far from what was shown in the help files./ OS-win98se/.
2. Under Scan Control / Advanced Scan Options/ Regarding the Scan for EICAR test string option. I am not clear what TDS-3 does with this does it copy a eicar test string from some location in its files and after activating it attempts to find it itself. Or does it activate the file to test your AV scanner to see if it can pick it up. Or does TDS-3 merely note that an EICAR test file exists. Or do you have to manually d/l and install a EICAR test file and TDS-3 will attempt to find it. In anycase once checked and TDS-3 reloaded neither TDS nor Norton (AV) picked up a EICAR test string.
3.Do I have the full version of TDS-3 I recieved the .kf file and was directed to a page where the evaulation TDS-3 was located so I d/led it and installed the key as mentioned does this activate the full version from the eval version.
4.First scan revealed four suspicious files with dual extensions three with a (tmp.exe) and another which was named quake iii with a dual extension I cannot recall in anycase I have quake installed on my system but when I performed a second scan only the three files where found so could this quake iii file have been what I believe is called a false positive or did it change itself. I think it is important to note here that awhile back something was installed on my system called qtxxx the reason for the xxx is because its name changed. The two times I hunted it down it was a different file but it always had the qt/QT prefix. Anyway I havent seen it around for a very long time so maybe it was a legitimate program. Anyway I rarely if ever send in unknown files. I will submit known files but who knows what the unknown files might carry out with them.
I will post back about other questions about unknown processes to see if they are legitimate.
5. Someone has been methodically scanning my ports for the last three days now. I believe there are two constant ip addresses I was wondering if there is a quick start guide to using some of the TDS tools mentioned in help and the faq to discourage this activity. Note it may be my isp but I do not know why they would be scanning some many ports.
6. Using System Analysis/ Memory objects tree I have found a listing called hiddenwindow in outlook express which I use as a newsreader it is not configured for email. Is this normal.
I guess this is the question I will ask the most or its variant is this normal. Should item xxx be here at this location. What does this program do etc...
However I have a few questions.
1. Once I activate the Environment Settings List I recieve only 7 values far from what was shown in the help files./ OS-win98se/.
2. Under Scan Control / Advanced Scan Options/ Regarding the Scan for EICAR test string option. I am not clear what TDS-3 does with this does it copy a eicar test string from some location in its files and after activating it attempts to find it itself. Or does it activate the file to test your AV scanner to see if it can pick it up. Or does TDS-3 merely note that an EICAR test file exists. Or do you have to manually d/l and install a EICAR test file and TDS-3 will attempt to find it. In anycase once checked and TDS-3 reloaded neither TDS nor Norton (AV) picked up a EICAR test string.
3.Do I have the full version of TDS-3 I recieved the .kf file and was directed to a page where the evaulation TDS-3 was located so I d/led it and installed the key as mentioned does this activate the full version from the eval version.
4.First scan revealed four suspicious files with dual extensions three with a (tmp.exe) and another which was named quake iii with a dual extension I cannot recall in anycase I have quake installed on my system but when I performed a second scan only the three files where found so could this quake iii file have been what I believe is called a false positive or did it change itself. I think it is important to note here that awhile back something was installed on my system called qtxxx the reason for the xxx is because its name changed. The two times I hunted it down it was a different file but it always had the qt/QT prefix. Anyway I havent seen it around for a very long time so maybe it was a legitimate program. Anyway I rarely if ever send in unknown files. I will submit known files but who knows what the unknown files might carry out with them.
I will post back about other questions about unknown processes to see if they are legitimate.
5. Someone has been methodically scanning my ports for the last three days now. I believe there are two constant ip addresses I was wondering if there is a quick start guide to using some of the TDS tools mentioned in help and the faq to discourage this activity. Note it may be my isp but I do not know why they would be scanning some many ports.
6. Using System Analysis/ Memory objects tree I have found a listing called hiddenwindow in outlook express which I use as a newsreader it is not configured for email. Is this normal.
I guess this is the question I will ask the most or its variant is this normal. Should item xxx be here at this location. What does this program do etc...