What's new

computer problems...

2bzy4ne1

Mmmmm....Beeeeerrrr
the problem isn't happening on my computer but on my cousin's computer. They don't know what to do so they asked if i could do anything about it. So here it is. Whenever I open a program, the file always splits into two files. For example, if i were to open winamp.exe, the program would split into 2 files, winamp.exe and winamp.vxd. The winamp.exe after opening it now has an icon of a gameboy advance and acts like a frontend but does nothing. The winamp.vxd file is the actual program but renamed. Is this a virus or something similar? And how would I fix it?
 

ra5555

N64 Newbie
found it at my antivirus Pc-cillin.com :)

Description
Solution Risk rating: Low

Virus type: Worm

Destructive: Yes

Aliases: STATOR.A, Stator Virus



Description:
This Worm modifies the registry so that it executes when an EXE file is opened. It replaces the extension of EXE files to VXD. It then copies itself to the EXE file and executes the backed-up VXD file. The executed file then runs normally. Its backdoor component allows a hacker to remotely access an infected system. It is disguised as JPEG photo file that displays a picture of a woman when executed. This was coded in Borland Delphi.

Solution:


Click START|FIND|Find Files or Folders...
Type REGEDIT.EXE in the text box and then click on the button Find Now.
Highlight the found file and press F2 to rename the extension COM. If prompted to continue with rename, click on YES.
Double click on the renamed REGEDIT and delete the below registry entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Run\
ScanRegistry="C:\%winsysdir%\Scanregw.exe "%1"%*"

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\RunServices\
ScanRegistry="C:\%winsysdir%\Scanregw.exe "%1"%*"
Modify the below registry key command:HKEY_LOCAL_MACHINE\Software\Classes\exefile\Shell\
Open\Command

From:
(Default)="C:\%winsysdir%\loadpe.com "%1"%*"

To:
(Default)=""%1"%*"
Redo the above procedure with the registry keys:
HKEY_CLASSES_ROOT \exefile\Shell\ Open\
Command
Exit the registry
Search for the EXE files that were modified to have the VXD extension
Rename the files to their EXE file extension.
Reset your system
Scan your system with Trend antivirus and delete all files detected as WORM_STATOR.A. To do this, Trend customers must download the latest pattern fieand scan their system. Other email users may use Trend HouseCall, a free online virus scanner.

ADD: Or just get an antivirus scan... delet and edit the registry :)
 
Last edited:
OP
2bzy4ne1

2bzy4ne1

Mmmmm....Beeeeerrrr
I'll try doing what you said ra5555. I tried installing NAV 2002 on there but it was having problems. Maybe it is because they are using Win ME. Anyways, how would you get this virus? through email or a program?
 

Stezo2k

S-2K
hmm why not try an online scaner, theres no point installin an antivirus on a computer that has a virus, cuz the virus may sence it

Stez
 

Eagle

aka Alshain
Moderator
yes, you should not try to install NAV to investigate a virus, instead boot from the NAV CD directly. NAV is only good when installed before you get the virus. Of course if it is installed, you wont get the virus so its kind of a paradox.
 

Top