PDA

View Full Version : Unknown Trojan


HoundDog
June 15th, 2003, 09:45 AM
Hi all. New to this forum. Have had TDS-3 for awhile.
I installed a small desktop utility referred by Lockergnome and the LangaList. It's called StatBar and shows cpu usage, free ram, etc. TDS says that it's an unknown trojan. I deleted it, uninstalled it, removed the folder and ran a registry cleaner. Downloaded a fresh copy and reinstalled. Again TDS-3 says it's an unknown trojan. Does anyone know anything about StatBar? Could TDS be wrong? BTW, I removed StatBar. :-\

Pilli
June 15th, 2003, 09:59 AM
Hi HoundDog, I cannot find any bad info' on Statbar - Doing a search here http://www.spywareinfoforum.com/ shows nothing.
If you still have a copy of your statbar zip would you please send it to submit@diamoncs.com.au DCS wiil be able to affirm a false positive or not ;D

HTH Pilli

spy1
June 15th, 2003, 10:33 AM
http://www.statbar.nl/ . Pete

Paul Wilders
June 15th, 2003, 10:36 AM
Thanks Pete! ;)

regards.

paul

spy1
June 15th, 2003, 10:40 AM
YW! (Just Googled the LangaList and did a search there for StatBar).

Pete

HoundDog
June 15th, 2003, 10:41 AM
Thanks Pilli. Mailed copy of statbar zip to submit... Wait and see.
HoundDog

Jooske
June 15th, 2003, 01:58 PM
Hi Hounddog,
not sure where you downloaded the program, i got it now from the place Pete posted from their first mirror the zipped edition and scanned that, unzipped it and scanned again, not any alarm with that.
Did you d/l it from another maybe less trusted location?

HoundDog
June 15th, 2003, 02:42 PM
-{ Quote: " quoting: Jooske link=board=5;threadid=10317;start=0#msg67043 date=1055699909]
Hi Hounddog,
not sure where you downloaded the program, i got it now from the place Pete posted from their first mirror the zipped edition and scanned that, unzipped it and scanned again, not any alarm with that.
Did you d/l it from another maybe less trusted location?
" }-

Got it from a link at statbar home page. Did you install it and let it run? That's when TDS picked it up (memory process).

PS. Yes, from same address ( the first zip option ) Tried the EXE. version also. (same result)

HoundDog
June 15th, 2003, 03:00 PM
-{ Quote: " quoting: Pilli link=board=5;threadid=10317;start=0#msg66994 date=1055685573]
Hi HoundDog, I cannot find any bad info' on Statbar - Doing a search here http://www.spywareinfoforum.com/ shows nothing.
If you still have a copy of your statbar zip would you please send it to submit@diamoncs.com.au DCS wiil be able to affirm a false positive or not ;D

HTH Pilli
" }-
Pilli,
How do I find out what DCS finds?

Pilli
June 15th, 2003, 03:06 PM
DCS will either reply in this thread and or to your private email address ;D

Mr.Blaze
June 15th, 2003, 04:09 PM
;D blaze raise hand me me i know i know

i use to get fake postives untill i updated to the newest tds and got the latest updates

i had same prob except i think it said i had muster worm lol

Jooske
June 15th, 2003, 05:59 PM
Same file Blaze, from the same place?
With a TDS scan?
False positives with TDS? what did Gavin tell you about the files you submitted to him from those alarms?
If this would have been the same file and same suspicious code and the original was submitted for advice, the refining in detection would have been added to the references since and no further alerts would have been given as "suspicious" but a name or "not a trojan" or such a message would have been given to it.
So either it is a different file you're talking about or it was never submitted, but it is impossible you would get a name for a nasty on the same file another gets an alarm "suspicious" without mentioning a name.

HoundDog
June 15th, 2003, 06:38 PM
-{ Quote: " quoting: Pilli link=board=5;threadid=10317;start=0#msg67058 date=1055704002]
DCS will either reply in this thread and or to your private email address ;D
" }-

Cool. Thanx Pilli

Gavin - DiamondCS
June 15th, 2003, 10:57 PM
Statbar is not a trojan, the author has been informed how to fix the problem if they wish :) I thought there was a new version available which wouldn't be detected.. dont worry about it for now :)

Mr.Blaze
June 17th, 2003, 01:52 AM
;D now thats service not only did you hear it from the man but he also take the time to help out the maker of the file to fix it

;D

nah Jooske i had similar problems with old tds and out dated database

and yup i turn in all my stuffs to the big boys for review

one thing i love about those guys is the privacy service they provide

they really do respect your privacy and confidentiality no question's asked when submitting a file

just a yes or no either by bord or by private e-mail

i think thats perty nice ;D

Wayne - DiamondCS
June 17th, 2003, 01:54 AM
Think nothing of it my friend, your privacy and security is our job

Mr.Blaze
June 17th, 2003, 01:57 AM
;Ddid i mention he is super fast to reply wow

Mr.Blazer
June 19th, 2003, 06:43 PM
TDS is simply the best - period!

gruss,

Mr.Blazer

Pilli
June 19th, 2003, 06:53 PM
TDS3, Without a doubt + Port Explorer, Wormguard, Autostart viewer & Advanced process manipulation - The latter two being totally free ;D