Go Back   Professional Soldiers ® > Technical FAQ Forum > KnuckleDragger Questions

Reply
 
Thread Tools Display Modes
Old 02-02-2005, 21:14   #1
Smokin Joe
Area Commander
 
Smokin Joe's Avatar
 
Join Date: Feb 2004
Location: Phoenix, AZ
Posts: 1,691
Trojan Horse Help

My wife's login on my desktop PC has the winstat.exe and winstatkeep.exe trojan horse. I have Norton anit-virus, ace utilites reg cleaner, and Xoftspy ware. I have all of this and I can't get ride of it.

Thanks for any help.
__________________
"This is the law: The purpose of fighting is to win. There is no possible victory in defense. The sword is more important than the shield and skill is more important than either. The final weapon is the brain. All else is supplemental." - John Steinbeck, "The Law"
Smokin Joe is offline   Reply With Quote
Old 02-02-2005, 21:20   #2
Kyobanim
Moderator
 
Kyobanim's Avatar
 
Join Date: Feb 2004
Location: Central Florida
Posts: 3,045
I'll see if I can find something
__________________
"Are you listening or just waiting to talk?"


Light travels faster than sound. This is why some people appear bright until you hear them speak.

"Fate rarely calls upon us at a moment of our choosing."
Optimus Prime
Kyobanim is offline   Reply With Quote
Old 02-02-2005, 21:38   #3
Kyobanim
Moderator
 
Kyobanim's Avatar
 
Join Date: Feb 2004
Location: Central Florida
Posts: 3,045
Joe, ghuinness has a thought. I think she's going to post it. Yell at her if she doesn't.
__________________
"Are you listening or just waiting to talk?"


Light travels faster than sound. This is why some people appear bright until you hear them speak.

"Fate rarely calls upon us at a moment of our choosing."
Optimus Prime
Kyobanim is offline   Reply With Quote
Old 02-02-2005, 21:41   #4
gits
Quiet Professional
 
gits's Avatar
 
Join Date: Oct 2004
Location: WA
Posts: 311
Does the virus get deleted by the virus scanner and just simply comes back? or does the scanner say its not possible to remove it or just can't remove the virus? If it can't remove the virus try booting to safe mode and running the scanner.
gits is offline   Reply With Quote
Old 02-02-2005, 23:25   #5
Smokin Joe
Area Commander
 
Smokin Joe's Avatar
 
Join Date: Feb 2004
Location: Phoenix, AZ
Posts: 1,691
Okay here is what I have going on.

I have a laptop and am posting here (PS.com) with it now.

I'm running windows XP (on both systems)
The Trojan Horse is not affecting my login on the desktop PC but to be safe I'm not using it until I get it off the pc entirely.

The message I get is a popup (not the internet kind the error kind) it gives me "Blah Blah Blah winstat.exe failed to intialize blah blah blah click okay to continue". So I click okay. It gives me the same popup no matter how many times I click okay. Same-same for the winstatkeep.exe Trojan Horse.

It has also pissed of my Norton Anti-virus because sometimes on start up it gives me an error message that states "blah blah blah Norton could not intialize".

I just ran ace, xoftspy, and norton again on my log in and Norton on my wife's log in. It may have fixed the problem.

Thanks everyone for your help.
__________________
"This is the law: The purpose of fighting is to win. There is no possible victory in defense. The sword is more important than the shield and skill is more important than either. The final weapon is the brain. All else is supplemental." - John Steinbeck, "The Law"
Smokin Joe is offline   Reply With Quote
Old 02-03-2005, 23:32   #6
hoepoe
Guerrilla
 
Join Date: Feb 2004
Location: Israel
Posts: 405
Do a google search for a program called "hijackthis".

Download and execute, if anything can save your data, this can.

Good luck

Hoepoe
hoepoe is offline   Reply With Quote
Old 02-04-2005, 00:20   #7
hotntot
Asset
 
Join Date: Nov 2004
Location: Flint, Michigan coming soon to ban city
Posts: 14
Norton

Don't know if this will help or if problem is fixed.However my son and myself had the same problem until we removed norton from our programming---it worked--no problems.Who knows but my .o2. Good luck.
hotntot is offline   Reply With Quote
Old 02-04-2005, 00:22   #8
aricbcool
Guerrilla Chief
 
Join Date: Jan 2005
Location: Idaho
Posts: 819
winstat or winstart

Don't know if you fixed it yet. Also, I was wondering if winstat or winstart is the problem file. Reason is I found two different sets of info. on such a small variation of spelling. Anyways, this is what I found:

For winstat: http://www.greatis.com/appdata/d/w/winstat.exe.htm

"winstat.exe
Steals passwords / ICQ trojan
Also known as: Backdoor.Kodorian, Win32/Kodorian, Troj/Kodoria
Displays a Firework and simultanlously starts in the backround. Sends the passwords encrypted via e-mail.
Kill the processes:
winstat.exe
kodorjan.exe
server.exe
Remove Files:
c:\manasi.yok
c:\winstat.exe
kodorjan.exe
okursan?yiedersinokumazsan?yibokyersin.txt
server.exe"

For winstart: http://securityresponse.symantec.com...oor.optix.html

"Run LiveUpdate to make sure that you have the most recent virus definitions.
Start Norton AntiVirus (NAV), and make sure that NAV is configured to scan all files. For instructions on how to do this, read the document How to configure Norton AntiVirus to scan all files.
Run a full system scan.
Delete all files that are detected as Backdoor.Optix. If any files are detected as Backdoor.Optix, delete the Winstart.bat file before you restart the computer. For detailed information, read the section that follows."

Hope that helps.

Regards,
Aric
aricbcool is offline   Reply With Quote
Old 02-04-2005, 00:23   #9
Smokin Joe
Area Commander
 
Smokin Joe's Avatar
 
Join Date: Feb 2004
Location: Phoenix, AZ
Posts: 1,691
Thanks for all the help and suggestions everyone. I finally got it cleaned out I re-ran Norton, Ace Uti., and Xoftspy. Except I did it on the wifes login. At first I didn't think it would matter/ help but evidently it did.
__________________
"This is the law: The purpose of fighting is to win. There is no possible victory in defense. The sword is more important than the shield and skill is more important than either. The final weapon is the brain. All else is supplemental." - John Steinbeck, "The Law"
Smokin Joe is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump



All times are GMT -6. The time now is 17:45.



Copyright 2004-2022 by Professional Soldiers ®
Site Designed, Maintained, & Hosted by Hilliker Technologies