TT Livescan Updates + More

I

idbeholda

The databases for TT Livescan 2011 are still being updated, however,
the next incarnation of TT Livescan will simply be called TT Livescan
+. The next version will implement 13 unique databases for detecting
malware. The collective database size is approximately 14GB with over
120 million definitions.

On an unrelated note, I am currently in the process of developing a
file/media organizer app. The search results are (for the most part)
limited by hardware latency. Anyone interested in testing Metalog
Media Organizer before its scheduled release shortly before the middle
of December, contact me at (e-mail address removed) or (e-mail address removed).

Enjoy.

http://www.tot-ltd.org
 
I

idbeholda

info at tot-ltd dot org or idbeholda at gmail dot com

Look like usenet is being a doodiebritches again.
 
B

Bear Bottoms

TT Livescan 2011

Unzips to it's own folder and appears totally portable.

On first run of scanner.exe:
http://bearware.info/screenshots/20111128-17m-50kb.jpg

After about a minute:
http://bearware.info/screenshots/20111128-m9g-52kb.jpg

First attempt to run the program:
http://bearware.info/screenshots/20111128-q2s-52kb.jpg

Tried running scanner.exe again as adminsitrater - no go - but I was
running as administrator anyway.

So, I sidelined it and may look into it later....maybe.
 
B

Bear Bottoms

Unzips to it's own folder and appears totally portable.

On first run of scanner.exe:
http://bearware.info/screenshots/20111128-17m-50kb.jpg

After about a minute:
http://bearware.info/screenshots/20111128-m9g-52kb.jpg

First attempt to run the program:
http://bearware.info/screenshots/20111128-q2s-52kb.jpg

Tried running scanner.exe again as adminsitrater - no go - but I was
running as administrator anyway.

So, I sidelined it and may look into it later....maybe.
Still initializing.....I might just shut it down! No way to minimize it
that I can see...

Wow...it's doing all kinds of strange things...

I had to shut it down via the task manager. I restarted it and this time
it showed a scan progress bar and finally this screen:

http://bearware.info/screenshots/20111128-m6u-65kb.jpg

I selected no to clam av and it shows it is still initializing. Tried to
bring it from the background via the tray icon seems to destroy it and
the tray icon disappears. The only way to get rid of it is via the task
manager. I think I'll pass on this one for a while.
 
B

Bear Bottoms

Still initializing.....I might just shut it down! No way to minimize it
that I can see...

Wow...it's doing all kinds of strange things...

I had to shut it down via the task manager. I restarted it and this time
it showed a scan progress bar and finally this screen:

http://bearware.info/screenshots/20111128-m6u-65kb.jpg

I selected no to clam av and it shows it is still initializing. Tried to
bring it from the background via the tray icon seems to destroy it and
the tray icon disappears. The only way to get rid of it is via the task
manager. I think I'll pass on this one for a while.
Well, I shut it down via task manager...but ran it again. After a quick
initialization this time (progress bar at the bottom was the only
indication) I clicked scan. Nothing happened...impatient I guess, so I
stopped it with the task manager...LOL...but it didn't go away...it
started scanning with a new entry in the task manager

http://bearware.info/screenshots/20111128-l95-46kb.jpg

Been running 10 minutes and it's at 3%. It's already alerted though I'm
pretty sure that's a false positive. I'll let it run and get back to
ya...(maybe later this afternoon)

http://bearware.info/screenshots/20111128-n58-57kb.jpg
 
I

idbeholda

When it's your first time of running TT Livescan 2011, it takes a few
minutes. The reason for this is that it's detecting other scanners
that are installed, and will prompt you to use them as plugins. Most
of the information is on the following two pages:

http://www.tot-ltd.org/techinf.html
http://www.tot-ltd.org/techinf2.html

If you do run into any false positives, or what you think may be a
false positive, let me know so that I can fix the issue.
 
B

Bear Bottoms

Been running 10 minutes and it's at 3%. It's already alerted though I'm
pretty sure that's a false positive. I'll let it run and get back to
ya...(maybe later this afternoon)

http://bearware.info/screenshots/20111128-n58-57kb.jpg

Get ready for a big laugh...the scan finished and here are the results
from my trashed out computer...OMG. Forget this one folks.

c:\Program Files\Dell\MediaDirect\fwnet.dll is infected with
TROJAN.DOWNLOADER.ZLOB.LPS

c:\Users\bear\Documents\MemoryStick\Tools
Internet\TeamViewer\TeamViewerQS.exe is infected with MW.GEN

c:\Users\bear\Documents\MemoryStick\Tools
Video\vlc-1.0.5\plugins\libi422_yuy2_sse2_plugin.dll is infected with
TROJAN.MONDER-136

c:\Users\bear\Documents\MemoryStick\Tools Web
Development\PSPad\Uninst\unins000.exe is infected with ADWARE REMOVER

c:\Users\JBottoms\Documents\MemoryStick\Tools File
Management\UniversalExtractor\bin\7z.dll is infected with DESKTOP SPY 4.0

c:\Users\JBottoms\Documents\MemoryStick\Tools File
Management\UniversalExtractor\bin\7z.exe is infected with DESKTOP SPY 4.0

c:\Users\JBottoms\Documents\MemoryStick\Tools
Security\AntiKeyLoggerTester\AKLT.exe is infected with SPR/TOOL.FIRETEST.A

c:\Users\JBottoms\Documents\MemoryStick\Tools Security\GMER\catchme.exe
is infected with MW.GEN

c:\Users\JBottoms\Documents\MemoryStick\Tools Utility\Google Maps
Saver\gms_v1_0_2.exe is infected with MW.GEN

c:\Users\JBottoms\Documents\MemoryStick\Tools
Video\vlc-1.1.2\plugins\libi422_yuy2_sse2_plugin.dll is infected with
TROJAN.MONDER-136

c:\Users\JBottoms\Documents\MemoryStick\Tools Web
Development\PSPad\Uninst\unins000.exe is infected with ADWARE REMOVER

c:\Users\JBottoms\JBottoms_full_files\JBottoms_full_files.cbu\JBottoms\Documents\MemoryStick\Tools
File Management\UniversalExtractor\bin\7z.dll is infected with DESKTOP
SPY 4.0

c:\Users\JBottoms\JBottoms_full_files\JBottoms_full_files.cbu\JBottoms\Documents\MemoryStick\Tools
File Management\UniversalExtractor\bin\7z.exe is infected with DESKTOP
SPY 4.0

c:\Users\JBottoms\JBottoms_full_files\JBottoms_full_files.cbu\JBottoms\Documents\MemoryStick\Tools
Internet\TeamViewer\TeamViewerQS.exe is infected with MW.GEN

c:\Users\JBottoms\JBottoms_full_files\JBottoms_full_files.cbu\JBottoms\Documents\MemoryStick\Tools
Security\Safekeys\Neo's SafeKeys v3.exe is infected with ADWARE.AGENT.PB.10

c:\Windows\notepad.exe is infected with MW.GEN

c:\Windows\System32\msvbvm60.dll is infected with EASY WEB CAM

c:\Windows\System32\notepad.exe is infected with MW.GEN

c:\Windows\System32\userinit.exe is infected with TROJAN.PSW.LDPINCH.XOV

c:\Windows\winsxs\x86_microsoft-windows-msvbvm60_31bf3856ad364e35_6.0.6001.18000_none_c283c4d351b9dd7d\msvbvm60.dll
is infected with EASY WEB CAM

c:\Windows\winsxs\x86_microsoft-windows-notepadwin_31bf3856ad364e35_6.0.6001.18000_none_42c9ccdefb0d0dc9\notepad.exe
is infected with MW.GEN

c:\Windows\winsxs\x86_microsoft-windows-notepad_31bf3856ad364e35_6.0.6001.18000_none_6f1a8d7b6fffbb73\notepad.exe
is infected with MW.GEN

c:\Windows\winsxs\x86_microsoft-windows-ole-automation-legacy_31bf3856ad364e35_6.0.6001.18000_none_3a13ba9301b4467e\olepro32.dll
is infected with EASY WEB CAM

c:\Windows\winsxs\x86_microsoft-windows-ole-automation_31bf3856ad364e35_6.0.6000.16609_none_bb22ee81fe4b8646\oleaut32.dll
is infected with EASY WEB CAM

c:\Windows\winsxs\x86_microsoft-windows-ole-automation_31bf3856ad364e35_6.0.6001.18000_none_bd002a8dfb7a3328\oleaut32.dll
is infected with EASY WEB CAM

c:\Windows\winsxs\x86_microsoft-windows-sidebar_31bf3856ad364e35_6.0.6000.16615_none_ccf09e9d29852489\sidebar.exe
is infected with MW.GEN

c:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6001.18000_none_ac3aa7fd19319fba\smss.exe
is infected with DREAMAD

c:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
is infected with TROJAN.PSW.LDPINCH.XOV
 
B

Bear Bottoms

When it's your first time of running TT Livescan 2011, it takes a few
minutes. The reason for this is that it's detecting other scanners
that are installed, and will prompt you to use them as plugins. Most
of the information is on the following two pages:

http://www.tot-ltd.org/techinf.html
http://www.tot-ltd.org/techinf2.html

If you do run into any false positives, or what you think may be a
false positive, let me know so that I can fix the issue.

Sorry to say the results were a lot of false positives...I know!

c:\Program Files\Dell\MediaDirect\fwnet.dll is infected with
TROJAN.DOWNLOADER.ZLOB.LPS

c:\Users\bear\Documents\MemoryStick\Tools
Internet\TeamViewer\TeamViewerQS.exe is infected with MW.GEN

c:\Users\bear\Documents\MemoryStick\Tools
Video\vlc-1.0.5\plugins\libi422_yuy2_sse2_plugin.dll is infected with
TROJAN.MONDER-136

c:\Users\bear\Documents\MemoryStick\Tools Web
Development\PSPad\Uninst\unins000.exe is infected with ADWARE REMOVER

c:\Users\JBottoms\Documents\MemoryStick\Tools File
Management\UniversalExtractor\bin\7z.dll is infected with DESKTOP SPY 4.0

c:\Users\JBottoms\Documents\MemoryStick\Tools File
Management\UniversalExtractor\bin\7z.exe is infected with DESKTOP SPY 4.0

c:\Users\JBottoms\Documents\MemoryStick\Tools
Security\AntiKeyLoggerTester\AKLT.exe is infected with SPR/TOOL.FIRETEST.A

c:\Users\JBottoms\Documents\MemoryStick\Tools Security\GMER\catchme.exe
is infected with MW.GEN

c:\Users\JBottoms\Documents\MemoryStick\Tools Utility\Google Maps
Saver\gms_v1_0_2.exe is infected with MW.GEN

c:\Users\JBottoms\Documents\MemoryStick\Tools
Video\vlc-1.1.2\plugins\libi422_yuy2_sse2_plugin.dll is infected with
TROJAN.MONDER-136

c:\Users\JBottoms\Documents\MemoryStick\Tools Web
Development\PSPad\Uninst\unins000.exe is infected with ADWARE REMOVER

c:\Users\JBottoms\JBottoms_full_files\JBottoms_full_files.cbu\JBottoms\Documents\MemoryStick\Tools
File Management\UniversalExtractor\bin\7z.dll is infected with DESKTOP
SPY 4.0

c:\Users\JBottoms\JBottoms_full_files\JBottoms_full_files.cbu\JBottoms\Documents\MemoryStick\Tools
File Management\UniversalExtractor\bin\7z.exe is infected with DESKTOP
SPY 4.0

c:\Users\JBottoms\JBottoms_full_files\JBottoms_full_files.cbu\JBottoms\Documents\MemoryStick\Tools
Internet\TeamViewer\TeamViewerQS.exe is infected with MW.GEN

c:\Users\JBottoms\JBottoms_full_files\JBottoms_full_files.cbu\JBottoms\Documents\MemoryStick\Tools
Security\Safekeys\Neo's SafeKeys v3.exe is infected with ADWARE.AGENT.PB.10

c:\Windows\notepad.exe is infected with MW.GEN

c:\Windows\System32\msvbvm60.dll is infected with EASY WEB CAM

c:\Windows\System32\notepad.exe is infected with MW.GEN

c:\Windows\System32\userinit.exe is infected with TROJAN.PSW.LDPINCH.XOV

c:\Windows\winsxs\x86_microsoft-windows-msvbvm60_31bf3856ad364e35_6.0.6001.18000_none_c283c4d351b9dd7d\msvbvm60.dll
is infected with EASY WEB CAM

c:\Windows\winsxs\x86_microsoft-windows-notepadwin_31bf3856ad364e35_6.0.6001.18000_none_42c9ccdefb0d0dc9\notepad.exe
is infected with MW.GEN

c:\Windows\winsxs\x86_microsoft-windows-notepad_31bf3856ad364e35_6.0.6001.18000_none_6f1a8d7b6fffbb73\notepad.exe
is infected with MW.GEN

c:\Windows\winsxs\x86_microsoft-windows-ole-automation-legacy_31bf3856ad364e35_6.0.6001.18000_none_3a13ba9301b4467e\olepro32.dll
is infected with EASY WEB CAM

c:\Windows\winsxs\x86_microsoft-windows-ole-automation_31bf3856ad364e35_6.0.6000.16609_none_bb22ee81fe4b8646\oleaut32.dll
is infected with EASY WEB CAM

c:\Windows\winsxs\x86_microsoft-windows-ole-automation_31bf3856ad364e35_6.0.6001.18000_none_bd002a8dfb7a3328\oleaut32.dll
is infected with EASY WEB CAM

c:\Windows\winsxs\x86_microsoft-windows-sidebar_31bf3856ad364e35_6.0.6000.16615_none_ccf09e9d29852489\sidebar.exe
is infected with MW.GEN

c:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6001.18000_none_ac3aa7fd19319fba\smss.exe
is infected with DREAMAD

c:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
is infected with TROJAN.PSW.LDPINCH.XOV
 
B

Bear Bottoms

Sorry to say the results were a lot of false positives...I know!

Don't get me wrong idbeholda, I appreciate you coming to this group and
presenting freeware as an author. The program has a lot of promise and
obviously is looking for the right things. You profess a huge database
which is good. The only thing I see significantly missing is a database
of false positives. I hope my comments help toward program improvements.

And, please continue to keep us updated. You are most welcome here.
 
B

Bear Bottoms

info at tot-ltd dot org or idbeholda at gmail dot com

Look like usenet is being a doodiebritches again.

Don't get me wrong idbeholda, I appreciate you coming to this group and
presenting freeware as an author. The program has a lot of promise and
obviously is looking for the right things. I hope my comments help toward
program improvements.

And, please continue to keep us at BearWare updated. You are most welcome
here.
 
I

idbeholda

Don't get me wrong idbeholda, I appreciate you coming to this group and
presenting freeware as an author. The program has a lot of promise and
obviously is looking for the right things. I hope my comments help toward
program improvements.

And, please continue to keep us at BearWare updated. You are most welcome
here.

If it's not too much to ask, send me a copy of the files that
generated false positives. Also, what version of windows are you
running?
 
I

idbeholda

Get ready for a big laugh...the scan finished and here are the results
from my trashed out computer...OMG. Forget this one folks.

c:\Program Files\Dell\MediaDirect\fwnet.dll is infected with
TROJAN.DOWNLOADER.ZLOB.LPS

c:\Users\bear\Documents\MemoryStick\Tools
Internet\TeamViewer\TeamViewerQS.exe is infected with MW.GEN

c:\Users\bear\Documents\MemoryStick\Tools
Video\vlc-1.0.5\plugins\libi422_yuy2_sse2_plugin.dll is infected with
TROJAN.MONDER-136

c:\Users\bear\Documents\MemoryStick\Tools Web
Development\PSPad\Uninst\unins000.exe is infected with ADWARE REMOVER

c:\Users\JBottoms\Documents\MemoryStick\Tools File
Management\UniversalExtractor\bin\7z.dll is infected with DESKTOP SPY 4.0

c:\Users\JBottoms\Documents\MemoryStick\Tools File
Management\UniversalExtractor\bin\7z.exe is infected with DESKTOP SPY 4.0

c:\Users\JBottoms\Documents\MemoryStick\Tools
Security\AntiKeyLoggerTester\AKLT.exe is infected with SPR/TOOL.FIRETEST.A

c:\Users\JBottoms\Documents\MemoryStick\Tools Security\GMER\catchme.exe
is infected with MW.GEN

c:\Users\JBottoms\Documents\MemoryStick\Tools Utility\Google Maps
Saver\gms_v1_0_2.exe is infected with MW.GEN

c:\Users\JBottoms\Documents\MemoryStick\Tools
Video\vlc-1.1.2\plugins\libi422_yuy2_sse2_plugin.dll is infected with
TROJAN.MONDER-136

c:\Users\JBottoms\Documents\MemoryStick\Tools Web
Development\PSPad\Uninst\unins000.exe is infected with ADWARE REMOVER

c:\Users\JBottoms\JBottoms_full_files\JBottoms_full_files.cbu\JBottoms\Docu ments\MemoryStick\Tools
File Management\UniversalExtractor\bin\7z.dll is infected with DESKTOP
SPY 4.0

c:\Users\JBottoms\JBottoms_full_files\JBottoms_full_files.cbu\JBottoms\Docu ments\MemoryStick\Tools
File Management\UniversalExtractor\bin\7z.exe is infected with DESKTOP
SPY 4.0

c:\Users\JBottoms\JBottoms_full_files\JBottoms_full_files.cbu\JBottoms\Docu ments\MemoryStick\Tools
Internet\TeamViewer\TeamViewerQS.exe is infected with MW.GEN

c:\Users\JBottoms\JBottoms_full_files\JBottoms_full_files.cbu\JBottoms\Docu ments\MemoryStick\Tools
Security\Safekeys\Neo's SafeKeys v3.exe is infected with ADWARE.AGENT.PB.10

c:\Windows\notepad.exe is infected with MW.GEN

c:\Windows\System32\msvbvm60.dll is infected with EASY WEB CAM

c:\Windows\System32\notepad.exe is infected with MW.GEN

c:\Windows\System32\userinit.exe is infected with TROJAN.PSW.LDPINCH.XOV

c:\Windows\winsxs\x86_microsoft-windows-msvbvm60_31bf3856ad364e35_6.0.6001. 18000_none_c283c4d351b9dd7d\msvbvm60.dll
is infected with EASY WEB CAM

c:\Windows\winsxs\x86_microsoft-windows-notepadwin_31bf3856ad364e35_6.0.600 1.18000_none_42c9ccdefb0d0dc9\notepad.exe
is infected with MW.GEN

c:\Windows\winsxs\x86_microsoft-windows-notepad_31bf3856ad364e35_6.0.6001..1 8000_none_6f1a8d7b6fffbb73\notepad.exe
is infected with MW.GEN

c:\Windows\winsxs\x86_microsoft-windows-ole-automation-legacy_31bf3856ad364 e35_6.0.6001.18000_none_3a13ba9301b4467e\olepro32.dll
is infected with EASY WEB CAM

c:\Windows\winsxs\x86_microsoft-windows-ole-automation_31bf3856ad364e35_6..0 .6000.16609_none_bb22ee81fe4b8646\oleaut32.dll
is infected with EASY WEB CAM

c:\Windows\winsxs\x86_microsoft-windows-ole-automation_31bf3856ad364e35_6..0 .6001.18000_none_bd002a8dfb7a3328\oleaut32.dll
is infected with EASY WEB CAM

c:\Windows\winsxs\x86_microsoft-windows-sidebar_31bf3856ad364e35_6.0.6000..1 6615_none_ccf09e9d29852489\sidebar.exe
is infected with MW.GEN

c:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6001.1800 0_none_ac3aa7fd19319fba\smss.exe
is infected with DREAMAD

c:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001. 18000_none_dc28ba15d1aff80b\userinit.exe
is infected with TROJAN.PSW.LDPINCH.XOV

Also, unless you you specified in the interface to delete the files,
the files that were flagged are still in their original locations.
 
B

Bear Bottoms

1. 18000_none_c283c4d351b9dd7d\msvbvm60.dll
00 1.18000_none_42c9ccdefb0d0dc9\notepad.exe
.1 8000_none_6f1a8d7b6fffbb73\notepad.exe
64 e35_6.0.6001.18000_none_3a13ba9301b4467e\olepro32.dll
.0 .6000.16609_none_bb22ee81fe4b8646\oleaut32.dll
.0 .6001.18000_none_bd002a8dfb7a3328\oleaut32.dll
.1 6615_none_ccf09e9d29852489\sidebar.exe
00 0_none_ac3aa7fd19319fba\smss.exe
1. 18000_none_dc28ba15d1aff80b\userinit.exe

Also, unless you you specified in the interface to delete the files,
the files that were flagged are still in their original locations.

As I said, the GUI needs some improvement. Also the line wrap on your
newsreader is not working.
 
D

David H. Lipman

From: "Bear Bottoms said:
And, please continue to keep us at BearWare updated. You are most welcome
here.

This is not BearWare. These are news groups where one is on freeware and the other two
are anti malware groups.

idbeholda has been posting for a few years now and has *always been welcome* and doesn't
need your specific welcome message or your branding.
idbeholda made numerous posts over the years concerning his anti malware utility. Very
consistently over the past ~2.5 years.
 
B

Bear Bottoms

If it's not too much to ask, send me a copy of the files that
generated false positives. Also, what version of windows are you
running?

I posted the list here! I'm running Vista on this machine.
 
B

Bear Bottoms

This is not BearWare. These are news groups where one is on freeware and the other two
are anti malware groups.

idbeholda has been posting for a few years now and has *always been welcome* and doesn't
need your specific welcome message or your branding.
idbeholda made numerous posts over the years concerning his anti malware utility. Very
consistently over the past ~2.5 years.
David, you do know you are responding to a forger right?
 
I

idbeholda

I posted the list here! I'm running Vista on this machine.

"If it's not too much to ask, send me a copy of the files that
generated false positives. Also, what version of windows are you
running? "

I asked if it was possible for you to send me the files. A text list
of the files does me no good. The reason I say that, is I've got most
of the hashes for windows vista system files included in the whitelist
portion of the database. Perhaps the results you got was the result
of some odd fluke. I won't know without actually having samples of
the files in question.
 
B

Bear Bottoms

"If it's not too much to ask, send me a copy of the files that
generated false positives. Also, what version of windows are you
running? "

I asked if it was possible for you to send me the files. A text list
of the files does me no good. The reason I say that, is I've got most
of the hashes for windows vista system files included in the whitelist
portion of the database. Perhaps the results you got was the result
of some odd fluke. I won't know without actually having samples of
the files in question.

OK, I'll collect them tonight and send them to ya or likely email you a
link to a zip file I'll put on my website.
 
B

Bear Bottoms

OK, I'll collect them tonight and send them to ya or likely email you a
link to a zip file I'll put on my website.

I sent you via your gmail a link to the zip file that contained the well
known files like notepad.exe, 7zip.exe, etc. which your program alerted to
as malware. None of these are malware, and if you have a white list as you
say you do, why isn't at the least notepad.exe on it and why is your
program alerting on one of the most common Windows programs as malware?

I'm just sayin....
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top