Home Page Owners Registry Discussion Forums ProwlerMall Event Scrapbooks About

Click here to return to the Prowler Online Board Main Page
Thread Closed  Topic Closed
  ProwlerOnline, Plymouth/Chrysler Prowler Discussion Forum
  General Prowler Discussion
  W32.Sircam Virus

Post New Topic  
edit profile | register | preferences | faq | search

   Bottom of Page next newest topic | next oldest topic
Author Topic:   W32.Sircam Virus
dpena




POA Site Supporter
Administrating Kat
Visit Dan's Prowler Excitement
Personal ScrapBook

From:San Jose Ca Santa Clara
Registered: Jul 2000
Admin Use

posted 07-24-2001 01:53 AM     Click Here to See the Profile for dpena     send a private message to dpena   Edit/Delete Message   Reply w/Quote   Search for more posts by dpena
Okay folks,

I ran the FixSirc.com virus program posted here earlier but the program told me this;

**************************************
Attention:

The FixSircam could not delete 9 W32.Sricam.Worm@mm files from your PC,
Please restart the computer in Safe Mode and run the removal tool again.

If the problem persists, then contact Technical Support.
**************************************


I went ahead and did the following so that the FixSircam program would delete the 9 infected files.

Windows ME Info:
NOTE: Windows ME utilizes a backup utility that backs up selected files automatically to the C:\_Restore folder. This means that an infected file could be stored there as a backup file, and VirusScan will be unable to delete these files. These instructions explain how to remove the infected files from the C:\_Restore folder.
Disabling the Restore Utility
1. Right click the My Computer icon on the Desktop.
2. Click on the Performance Tab.
3. Click on the File System button.
4. Click on the Troubleshooting Tab.
5. Put a check mark next to "Disable System Restore".
6. Click the Apply button.
7. Click the Close button.
8. Click the Close button again.
9. You will be prompted to restart the computer. Click Yes.
NOTE: The Restore Utility will now be disabled.
10. Restart the computer in Safe Mode.
11. Run a scan with VirusScan to delete all infected files, or browse the file's located in the C:\_Restore folder and remove the file's.
12. After removing the desired files, restart the computer normally.
NOTE: To re-enable the Restore Utility, follow steps 1-9 and on step 5 remove the check mark next to "Disable System Restore". The infected file's are removed and the System Restore is once again active.
Registry Entries:
The W32/SirCam@MM virus makes changes to the registry.
HKLM\Software\Microsoft\Windows\CurrentVersion\ RunServices\Driver32=C:\WINDOWS\SYSTEM\SCam32.exe
HKLM\Software\Sircam
In Infected state: HKCR\exefile\shell\open\command \Default="C:\recycled\SirC32.exe" "%1"%*
In Clean state this should be: HKCR\exefile\shell\open\command \Default=""%1"%*"


After all this, I am disenfected.

That is one nasty virus...

------------------
Watch Me In Action
Watch Me Burn Rubber With My 331 RWHP Prowler


www.prowlerexcitement.com
links.prowlerexcitement.com

dpena




POA Site Supporter
Administrating Kat
Visit Dan's Prowler Excitement
Personal ScrapBook

From:San Jose Ca Santa Clara
Registered: Jul 2000
Admin Use

posted 07-24-2001 02:08 AM     Click Here to See the Profile for dpena     send a private message to dpena   Edit/Delete Message   Reply w/Quote   Search for more posts by dpena
Just incase the link goes away I posted this info here for others later...

It came from here http://www.mcafee.com/anti-virus/viruses/sircam/default.asp?cid=2360


W32/SirCam@MM Help Center

DESCRIPTION - What virus is this?

This is a HIGH RISK virus that is spread to email recipients found in the Windows Address Book and addresses found in cached files. The infected email can come from addresses that you recognize. Attached is a file with two different extensions. The file name itself varies.
The email message can appear as follows:
Subject: [filename (random)]
Body: Hi! How are you?
I send you this file in order to have your advice
or I hope you can help me with this file that I send
or I hope you like the file that I sendo you
or This is the file with the information that you ask for
See you later. Thanks
--- the same message may be received in Spanish ---

Hola como estas ?
Te mando este archivo para que me des tu punto de vista
or Espero me puedas ayudar con el archivo que te mando
or Espero te guste este archivo que te mando
or Este es el archivo con la información que me pediste
Nos vemos pronto, gracias.


PAYLOAD - What can this virus do?

When run, the document will be saved to the C:\RECYCLED folder and then opened while the virus copies itself to C:\RECYCLED\SirC32.exe folder to conceal its presence and creates a registry key value to load itself whenever .EXE files are executed.
The virus searches for .GIF, .JPG, .JPEG, .MPEG, .MOV, .MPG, .PDF, .PNG, .PS, and .ZIP files in the MY DOCUMENTS folder and attempts to send copies of these documents to email recipients found in the Windows Address Book and addresses found in cached files.


Scan Your System for Infected Files
McAfee.com VirusScan Online and Clinic users, click here to perform a Scan.
If W32/SirCam@MM is found, use the delete option to remove it.

Rename the Windows Registry Editor
Click on the Start button.

Highlight Run.

Type in COMMAND and hit the OK button. A window will then appear with a black background. The last line of text in the window will look something like C:\Windows> (followed by a blinking cursor).

Type in the following at the prompt: COPY REGEDIT.EXE REGEDIT.BAT EXIT The window will then disappear.
Boot into Safe Mode
Shut the computer down so the power is off.

Wait 20 seconds or so.

Turn the computer on and immediately begin pressing the F8 key on the keyboard, once every second repeatedly. Do this until the Windows Startup Menu appears. If you get a keyboard error, press F1 to resume and then continue pressing the F8 key once every second.

Select Safe Mode from the Windows Startup Menu, then press the Enter key on the keyboard.

Windows will then boot into Safe Mode.
NOTE: This may take longer than a normal boot.

At the end of the boot process a dialog box will appear informing you that Windows is in Safe Mode. Click OK on this dialog box.

Windows is now in Safe Mode.
Backup the Registry
Click on the Start button.

Click on Run.

Type REGEDIT.BAT in the Open field.

Click the OK button. The Registry Editor window will appear.

Click on the Registry pull-down menu.

Click on Export Registry File.

In the File Name field type "backup" (without the quotation marks).

In the Save In field be sure that the desktop is selected (if it is not, click on the pull down menu and select "Desktop").

Select "All" in the Export Range group box.

Click on the Save button. The registry will then be saved.

Click the X in the top right corner to close the Registry Editor.

NOTE: You now have a backup of your Registry saved as "backup" on your desktop. If you need to restore the Registry you can double-click on the "backup" file located on the desktop. Once these instructions are complete and everything is running properly be sure to delete this backup file by right-clicking on it then left-clicking on Delete from the pop-up menu that appears. This will ensure that the old registry is not accidentally restored once the Trojan has been removed.

Remove the Worm Entries from the Registry
As you go through this process, you will be asked to confirm each change. Make sure that the change is correct, then confirm each change.
Click the Start button.
Click on Run.
Type in REGEDIT.BAT in the Open field.
Click the OK button. The Registry Editor window will appear.
Click on the plus sign next to HKEY_CLASSES_ROOT.
Click on the plus sign next to exefile.
Click on the plus sign next to shell.
Click on the plus sign next to open.
Single-click on command so it is highlighted.
On the right side of the screen is a Name column and a Data column. Locate and right-click on (Default) under the Name column.
A pop-up menu will appear. Left-click on Modify.
The Edit String dialog box will appear with the value highlighted. Delete all text in the Value and type the following characters (WITHOUT THE BRACKETS): ["%1" %*] If you are unsure of how the characters should be, the following is a spelled out version of the correct characters: quote, percentage, one, quote, space, percentage, asterisk.
Click the OK button to close the Edit String dialog box.
On the left side of the screen click on the minus sign next to open.
Click on the minus sign next to shell.
Click on the minus sign next to exefile.
click on the minus sign next to HKEY_CLASSES_ROOT.
Click on the plus sign next to HKEY_LOCAL_MACHINE.
Click on the plus sign next to SOFTWARE.
Single click on the SIRCAM folder so it is highlighted, then hit delete.
Click the plus sign next to Microsoft.
Click the plus sign next to Windows.
Click the plus sign next to CurrentVersion.
Single click on the RunServices Folder so it is highlighted.
On the right side of the screen is a Name column and a Data column. Under the Name column locate and single-click on Driver32 = C:\WINDOWS\SYSTEM\SCam32.exe so it is highlighted.
Press the Delete key on the keyboard to remove the entry.
Close the Registry Editor by clicking the X in the top right corner.
Remove reference in Autoexec.bat file:
Click Start, and click Run.
Type the following, and then click OK.
edit c:\autoexec.bat
The MS-DOS Editor opens.
Remove the line "@win \recycled\sirc32.exe" if it is present.
Click File and then click Save.
Exit the MS-DOS Editor

cwatsonjr
unregistered
Personal ScrapBook
Admin Use
posted 07-24-2001 09:26 AM           send a private message to dpena   Edit/Delete Message   Reply w/Quote   Search for more posts by cwatsonjr
One of the reasons you have boot into safe mode to complete the clean is because the virus infects some of the registry that runs some devices. When the computer is in safe mode - the devices are not loaded so that part of the registry is not used.

I had a co-worker that got infected and I had to help him get his computer cleaned last night at work - fun stuff :0

------------------
Cliff Watson

CJ





POA Lifetime Site Supporter
Prowler Junkie
Personal ScrapBook

From:Rochester Hills, MI USA
Registered: Jul 2000
Admin Use

posted 07-30-2001 08:27 PM     Click Here to See the Profile for CJ     send a private message to CJ   Edit/Delete Message   Reply w/Quote   Search for more posts by CJ
Bitten by the virus!!! Ouch!

After running a scan with our virus software, it found 3 infected files. When we tried to "clean" the file, it wouldn't. Hubby deleted one of the files.

When I restarted the computer, it came up with a window stating that the file "C:\SirC32.exe" could not be found and the file was necessary to run any "application". I could not access internet, email, program, Windows Explorer, NOTHING. Tried to access my Windows 98 disc to find file and copy and couldn't do that either.

Got help today from an expert and we reloaded the Windows 98 through Boot Disk. Everything is working fine again and the virus seems to be gone (fingers crossed)!

He said that the "window" was "lying". That is a virus file, not a file in W98. It was the virus blocking me from accessing anything and making me look for a file that does not exist!!

Hope this solves the problem!

------------------
CJ - The One and Only - 1999 Black
Mopar Exhaust System
Splash Guards
Matching Prowler Trailer
PProwler Vanity Plate

Classic/Beautiful - I'm referring to the Cat!

Mike Krehel





POA Site Supporter
The World's Quickest Prowler (11.65 sec) and Administrating Kat
Personal ScrapBook

From:United States
Registered: Jul 2000
Admin Use

posted 07-30-2001 09:05 PM     Click Here to See the Profile for Mike Krehel     send a private message to Mike Krehel   Edit/Delete Message   Reply w/Quote   Search for more posts by Mike Krehel
CJ,
It sounds like the autoexec.bat file is trying to call the file you just described. This virus modifies autoexec.bat, so you should open autoexec.bat with the dos edit program and delete the line that refers to C:\SirC32.exe.

------------------
Mike Krehel
ProwlerOnline.com Click and see me go!

cwatsonjr
unregistered
Personal ScrapBook
Admin Use
posted 07-31-2001 12:17 PM           send a private message to Mike Krehel   Edit/Delete Message   Reply w/Quote   Search for more posts by cwatsonjr
Actually - I have seen this virus hit two other computers. I had to go into the registry and edit it. The virus changes the registry to associate .exe files with the virus file. If the file is deleted than you can't run an .exe file.

What I did is delete the infected file, change the regedit.exe to regedit.com, run the registry editor and remove the association, reboot and change the regedit.com back to regedit.exe.

Sure beats having to reinstall windows... yeech.

Oh yea - you have to edit the .ini files too because it puts a run statement in them.

------------------
Cliff Watson

This message has been edited by cwatsonjr on 07-31-2001 at 12:18 PM

jd2ksilver


POA Site Supporter
Prowler Junkie
Personal ScrapBook

From:Mt. View, CA
Registered: Jul 2000
Admin Use

posted 07-31-2001 12:28 PM     Click Here to See the Profile for jd2ksilver     send a private message to jd2ksilver   Edit/Delete Message   Reply w/Quote   Search for more posts by jd2ksilver
O yeah,, I understand all that.

Thanks Norton Antivirus,

------------------
See me WAX a Roush
See me WAX a Cobra


CAR & DRIVER of The Month

butchcee


POA Site Supporter
Prowler Junkie

From:Lake Ariel, Pa.
Registered: Sep 2000
Admin Use

posted 07-31-2001 12:38 PM     Click Here to See the Profile for butchcee     send a private message to butchcee   Edit/Delete Message   Reply w/Quote   Search for more posts by butchcee
me too JD-just look at my computer tech post. CJ-my symtoms were the same as yours. I ended up using the recovery discs and started fresh.

------------------

Yellow is DCOOLEST

cwatsonjr
unregistered

Admin Use
posted 07-31-2001 01:29 PM           send a private message to butchcee   Edit/Delete Message   Reply w/Quote   Search for more posts by cwatsonjr
The virus that I posted about above wasn't the SirCam but another one - I guess very similar to it though.

------------------
Cliff Watson

dpena




POA Site Supporter
Administrating Kat
Visit Dan's Prowler Excitement
Personal ScrapBook

From:San Jose Ca Santa Clara
Registered: Jul 2000
Admin Use

posted 07-31-2001 01:32 PM     Click Here to See the Profile for dpena     send a private message to dpena   Edit/Delete Message   Reply w/Quote   Search for more posts by dpena
CJ,

So sorry I was not there to help you. I was in southern california celebrating my wifes parents 50th anniversary.

I got home this morning at 2:00am. At this time I received John Davies voice mail about calling you to help you and later this morning got the other voicemail at work. It was John Davies telling me to call you also.

Sure glad things worked out and realize this was a scarry moment.


Cliff,

Don't know what John Davies is talking about.... I understood you fully.


Later...

All times are CT (US)  Top of Page  Previous Page

 Return to General Prowler Discussion  next newest topic | next oldest topic



Administrative Options: Open Topic |Make Sticky | Archive/Move | Delete Topic
Post New Topic  
Hop to:

Contact Us | Prowler Online Homepage

All material contained herein, Copyright 2000 - 2012 ProwlerOnline.com
E-Innovations, LP

POA Terms of Service