Suspicious File

Discussion in 'Trojan Defence Suite' started by dallen, Feb 28, 2004.

Thread Status:
Not open for further replies.
  1. dallen

    dallen Registered Member

    Joined:
    May 11, 2003
    Posts:
    824
    Location:
    United States
    During a full system scan TDS found a file with a "suspicious filename."
    c:\windows\fonts\obc.exe

    It says that exe files should not exist in fonts. I was going to submit the file, but first, I cannot find it even when I have file options to show hidden file and system files checked. Second, when I try to use the right-click option to submit it says:
    14:01:43 [DiamondCS Labs] Background upload of obc.exe to DiamondCS Labs started.
    14:01:44 [SMTP Error] Email to submit@diamondcs.com.au failed.

    Please help.
     
  2. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Hi Dallen,
    few things could be the matter:
    i had it the other day with a file which was invisible in the TIF folder going there via windows explorer, while using the windows search/find showed the file to be there loud and clear, i could via that search window get to the file and (in my case safe to open it) after opening it save it in anlother location. I had never seen in the TIF files hidden, while in the folders under that TIF > Content > folders it is very visible too, strange!

    In your case i would try via the search option to locate the thing and to try to zip it from there (to avoid risks while manipulating it) and move or copy that to another location that way. So from there it should be submittable as an email attachment.

    For the submission failed: does your email test in the configuration tab work properly? your right smtp/mail configured there and a test message received in your inbox?

    Unexpected *exe files in the fonts folder are always suspicious -- is there another positive identification on the file?
     
  3. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    Hi Dallen, You need to configure the TDS sending in Congiguration - Servers

    In email setup put the SMTP server name that you use for email such as smtp.myISP.com and your email address in the box below - Press test and await a reply, if that is successful you can then use the TDS submit button.

    HTH Pilli
     
  4. dallen

    dallen Registered Member

    Joined:
    May 11, 2003
    Posts:
    824
    Location:
    United States
    With regard to my test email button. It used to work, but for some reason it stopped working and I haven't changed anything. Anyway I've played around with changing the SMTP server address and I've got it to work. This is what it says when I hit the "test email" button now:

    However, now when I try to submit the file using this function it says this:
    email address changed for harvesting and security reasons - paul
     
  5. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    If your test works OK then the submit should work on a selected scanned reported file.
    You may need to restart TDS and find the miscreant file again for it to work :)
     
  6. dallen

    dallen Registered Member

    Joined:
    May 11, 2003
    Posts:
    824
    Location:
    United States
    Pilli
    I am trying your suggestion to restart and rescan and after I will attempt to re-submit. Thanks for your advice and I will let you know what the result is.

    Jooske,
    While I have you hear and seeing how you are the speech guru, when I start TDS it says for example, "Good evening Dustin H. Allen." Is there any way that I can change that to simply say "Good evening Dustin Allen" (without my middle initial)? I mean the speech thing is working fine, I just want to change what she says to me so that it's clearer when she pronounces my name. My initial being there makes it difficult to interpret what she is saying.
     
  7. dallen

    dallen Registered Member

    Joined:
    May 11, 2003
    Posts:
    824
    Location:
    United States
    Jooske,
    I figured out the Name thing.
     
  8. dallen

    dallen Registered Member

    Joined:
    May 11, 2003
    Posts:
    824
    Location:
    United States
    OK. I've done some research and found this:
    I'm not sure this is the problem, but I suspect is has something to do with it. Anyway, when I use "smtp.purdue.edu" as my SMTP Server and press test button, it seems to work fine. The message I get is "Email to dallen@purdue.edu sent!" However, when I try to submit the suspicious file I get, "Failed - RCPT TO error: 550 5.7.1 <submit@diamondcs.com.au>... Relaying denied. Proper authentication required. "
    "[SMTP Error] Email to submit@diamondcs.com.au failed. "

    Any thoughts?
     
  9. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Was asleep a few hours, 4 in the morning now here, good you found the naming, you can have it say whatever you like TDS to call you.

    For the SMTP thing, in the plugins is an SMTP thing too, you will have the same problem there then.
    I remember in the Private TDS forum the auhentification was an issue discussed around two years ago, will try to find that discussion back and if there was a sulution for it.

    It's added to the wishlist for future...... Not sure if the situation looks like yours --for an outsider it does-- and if setting up an own emailserver would be an option, and how to do that! I wonder, as i suppose you do email normally too, if that works properly then!?

    And a test, if you have telnet installed:
    NB: due to ?? the < > changed into those &lt; &gt; so for those &lt;Enter&gt; just press the Enter button.

    In the meantime i hope you zipped and emailed the file as an attachment that way.
     
  10. dallen

    dallen Registered Member

    Joined:
    May 11, 2003
    Posts:
    824
    Location:
    United States
    Jooske,
    Can you clarify your last posting. I was confused when you said
    I did zip it and I sent it to:submit@diamondcs.com.au

    Should I expect a response?
    Oh, off the subject. Didn't you tell me that you live in the Netherlands? Just curious because I recently met a gentlemen that lives there. He is an eye surgeon there and is actively persuing the position of Minister of Health (I think that was what he termed the position). Anyway, when he said that's where he lives I thought about you.
     
  11. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    In the plugins is a SMTP send option too, which you can fill in and try to send emails using the SMTP server you normally do. It will most probably give you the same error message. The parts i added to my posting above were the last solutions found so i hope the authentification will be solved (as promissed) in TDS-4.

    Gavin will answer you if it is something nasty and how to deal with it.
    Did not get clear (googling around) what the file could be, saw it mentioned in so many places, but not in combination with trojans or viruses yet, so it can be anything!



    I'm not sure whom you met, but if he is getting that position we would lose a fine surgeon for which profession he will not have any time as a minister, but i hope we can win one with another vision (for which he is an eye surgeon in the first place) and able to stop the step by step banning on alternatives and prevention we have seen the last few decades and making real good holistic care available for everybody again.
     
  12. dallen

    dallen Registered Member

    Joined:
    May 11, 2003
    Posts:
    824
    Location:
    United States
    When should I expect to hear what I should do from Gavin?
     
  13. Paul Wilders

    Paul Wilders Administrator

    Joined:
    Jul 1, 2001
    Posts:
    12,472
    Location:
    The Netherlands
    Somewhere upcoming Monday (Australian Time Zone) ;)

    regards.

    paul
     
  14. dallen

    dallen Registered Member

    Joined:
    May 11, 2003
    Posts:
    824
    Location:
    United States
    I hate to sound impatient, but when should I hear something on that file I subitted for analysis?
     
  15. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    Hi Dallen, Today was labor day in Western Australia (Bank holiday) so hopefully Tuesday. :)
     
  16. dallen

    dallen Registered Member

    Joined:
    May 11, 2003
    Posts:
    824
    Location:
    United States
    Hey, even Ausies need holidays. I can cut them some slack for that. Thanks. ;)
     
Thread Status:
Not open for further replies.