Go Back   PCMech Forums > Windows Support > Windows Legacy Support (XP and earlier)

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 11-07-2002, 08:59 PM   #1
WSW
Member (9 bit)
 
Join Date: Sep 2001
Posts: 278
scrsvr.exe virus problem

My PC repeatedly got infected by the scrsvr.exe virus. I can use McAfee anti-virus to detect and delete the virus. However, after a few days, the virus re-appear.

The virus also try to add a run command into either the system.ini or win.ini or startup. I can use msconfig to go into system.ini or win.ini or startup to delete the run scrsvr.exe command. However, after a few days a new run scrsvr.exe command will be added into the ini file again.

Anyone has experience in getting rid of this scrsvr.exe virus?

WSW is offline   Reply With Quote
Old 11-07-2002, 11:14 PM   #2
Member (12 bit)
 
Redo40's Avatar
 
Join Date: Jan 2002
Location: Central Arkansas
Posts: 2,170
Have you tried Symantecs removal tool? Removal Tool Hope this helps, from what I have read this one is pain.
__________________
Roger

"Our greatest glory is not in never falling, but in rising every time we fall."
-Confucius
Redo40 is offline   Reply With Quote
Old 11-08-2002, 02:16 AM   #3
Member (5 bit)
 
Join Date: Nov 2002
Posts: 22
The only real way to get rid of a bad worm like that is to wipe the drive clean and start from scratch. I know it sounds drastic but it will be better for the system in the long run.
SMILEYCFC is offline   Reply With Quote
Old 11-08-2002, 11:03 PM   #4
WSW
Member (9 bit)
 
Join Date: Sep 2001
Posts: 278
I am hoping that I don't have to re-format the harddisk from scratch.

I installed the Microsoft patch and ran the worm removal tool. The removal tool detected the worm in the .ini file. The worm is supposed to have been removed. I'll wait a few days to see if the computer get re-infected.

Thanks for all the suggestions.
WSW is offline   Reply With Quote
Old 11-09-2002, 12:11 AM   #5
Member (7 bit)
 
RoyKelly's Avatar
 
Join Date: Sep 2002
Location: Pueblo, Colorado
Posts: 101
Just one quick question:

IS YOUR MACAFEE ANTIVIRUS CURRENT?
RoyKelly is offline   Reply With Quote
Old 11-09-2002, 08:50 AM   #6
Member (9 bit)
 
Join Date: Jun 2000
Posts: 499
And are you running it in "always on" mode?

You want to detect trojans/worms/viruses as they arrive NOT after they have been installed and done potential damage.
galaxian is offline   Reply With Quote
Old 11-09-2002, 12:06 PM   #7
WSW
Member (9 bit)
 
Join Date: Sep 2001
Posts: 278
Yes, I am using McAfee anti-virus with the latest Superdat. However, when I install my PC, I did test Internet and email access before I installed McAfee anti-virus. The worm could have got through before I install McAfee.

McAfee anti-virus is always ON on my computer. I also use ZoneAlarm firewall.

The worm removal software seems to work so far. I will know for sure after a few days. Before I use the worm removal software the worm seems to hide somewhere in the computer and tends to re-appear a few days after I do a virus scan using McAfee.
WSW is offline   Reply With Quote
Old 11-09-2002, 12:11 PM   #8
Member (8 bit)
 
Join Date: Aug 1999
Location: Sonora CA
Posts: 193
same problem plus

I have the same problem plus every few minutes one of the following pops up:

marco!
alevir.exe
brasil.pif
I've removed the offending line from win.ini only to have it reappear, run Norton's removal tool, all to no avail. Antivirus is up to date. All Norton can do is quarantine them.

beerman

Last edited by beerman; 11-09-2002 at 12:15 PM.
beerman is offline   Reply With Quote
Old 11-09-2002, 12:59 PM   #9
digitally confused
Premium Member
 
TimPoet's Avatar
 
Join Date: Jul 2001
Location: Las Vegas
Posts: 2,301
Send a message via AIM to TimPoet
I hate to say this, but McAfee just ain't what it used to be (as I think you have found out)....
Next chance you get, buy Norton AV 2003 or get the free version of AVG. I'm using the latter. See this:

http://forum.pcmech.com/showthread.p...ight=antivirus
__________________
.

Pentium D 805 | ASUS P5L-MX | CORSAIR ValueSelect 2 GHz |Primary HDD WD 40GB Back up HDD Seagate 7200.10 250GB SATA | eVGA 7600gt | Creative X-Fi Extreme Music audio card | Hauppauge TV Tuner Card | Lite On DVD burner/ LightScribe | COOLER MASTER Case | Fortron ATX400-PA 400W Power Supply | ViewSonic Q19wb LCD
TimPoet is offline   Reply With Quote
Old 11-09-2002, 01:07 PM   #10
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,786
beerman: go to housecall.antivirus.com and get a free online scan.
glc is offline   Reply With Quote
Old 11-09-2002, 02:11 PM   #11
Member (8 bit)
 
jackjones's Avatar
 
Join Date: Apr 2002
Posts: 153
I think you are being infected again and again. Try reading the removal intructions at : http://vil.mcafee.com/dispVirus.asp?virus_k=99729

Try instaling the mentioned patch and see if it helps.
jackjones is offline   Reply With Quote
Old 11-09-2002, 03:26 PM   #12
Member (8 bit)
 
Join Date: Aug 1999
Location: Sonora CA
Posts: 193
jackjones

Unchecking file and print sharing as suggested by MaAfee seems to have done the trick for me. Wonder why Symantec didn't think of that.

Thanks,
beerman
beerman is offline   Reply With Quote
Old 11-10-2002, 08:28 PM   #13
WSW
Member (9 bit)
 
Join Date: Sep 2001
Posts: 278
I have the same problem as beerman.

The Symatic worm removal software worked only for two days and now the worm re-appeared.

I'll try the suggestion by glc to see if it works for me.

WSW is offline   Reply With Quote
Old 11-11-2002, 10:18 AM   #14
Member (8 bit)
 
jackjones's Avatar
 
Join Date: Apr 2002
Posts: 153
Smile

Why don’t you try removing it and patching the hole instead of just removing it. The removal software only removes the program it does not make your computer immune.

Last edited by jackjones; 11-11-2002 at 10:33 AM.
jackjones is offline   Reply With Quote
Old 11-11-2002, 01:18 PM   #15
Member (9 bit)
 
Join Date: Jun 2000
Posts: 499
"Wonder why Symantec didn't think of that. "

From the removal link above, How to Configure Windows Folders for maximum network protection

"Disable file and print sharing, if possible


1. Right-click the Network Neighborhood or the My Network Places icon on the Windows desktop.
2. Click Properties.
3. Click the Configuration tab.
4. Click Client for Microsoft Networks.
5. Click File and Print Sharing.
6. Uncheck both boxes, and then click OK."
galaxian is offline   Reply With Quote
Old 11-11-2002, 04:54 PM   #16
Member (8 bit)
 
Join Date: Aug 1999
Location: Sonora CA
Posts: 193
galaxian

Thanks for the Symantec link.

beerman
beerman is offline   Reply With Quote
Old 11-11-2002, 07:04 PM   #17
Member (8 bit)
 
Join Date: Apr 2002
Posts: 144
Hello there,

I have had the exact same problem - and it is still recurring. I have tried all the removal tools - including in safe mode and without any system restore programs present. I have also removed the entires in win.ini etc. All virus definitions have been updated and maintained, but it still keeps popping up and being quarantined.

As much as anything else, I am just intrigued to know where on my hard drive it is dormantly residing and then reinfecting.

Does anyone know by whay mechanism it is reinfecting.

Matt.
matt_richards is offline   Reply With Quote
Old 11-11-2002, 09:06 PM   #18
Member (9 bit)
 
Join Date: Jun 2000
Posts: 499
What OS?

And have you disabled print and file sharing?
galaxian is offline   Reply With Quote
Old 11-11-2002, 09:29 PM   #19
Member (8 bit)
 
Join Date: Aug 1999
Location: Sonora CA
Posts: 193
Matt

The ones I had---marco, brazil and alevir all were in C:\windows and I was able to delete them in safe mode.

beerman
beerman is offline   Reply With Quote
Old 11-12-2002, 05:32 AM   #20
Member (8 bit)
 
Join Date: Apr 2002
Posts: 144
The infected compuer has windows 98 on it. I have not disabled file and printer sharing, but I will do - out of interest why does this help.

What I cannot understand is where the virus or trojan is hiding so that it can refer after an all clear from the fixes and after all traces have been removed from win.ini etc.

Cheers guys.
matt_richards is offline   Reply With Quote
Old 11-12-2002, 08:39 AM   #21
Member (9 bit)
 
Join Date: Jun 2000
Posts: 499
I "presume" you are going back on the net after clearing off the virus?

If so, you are then being reinfected via the gaping security hole with File&Print sharing open.
galaxian is offline   Reply With Quote
Old 11-12-2002, 05:02 PM   #22
Member (8 bit)
 
Join Date: Apr 2002
Posts: 144
I think I am misunderstanding the context of "file and printer sharing". Am I correct in thinking that it is only a problem if it is bound to the internet connection, with "file and printer sharing" over a LAN not being as much of a problem.
matt_richards is offline   Reply With Quote
Old 11-12-2002, 07:39 PM   #23
Member (9 bit)
 
Join Date: Jun 2000
Posts: 499
I suggest you run a Shields Up test

https://grc.com/x/ne.dll?bh0bkyd2

And there is a little more info on the issue here also.

http://grc.com/su-explain.htm
galaxian is offline   Reply With Quote
Old 11-12-2002, 08:35 PM   #24
WSW
Member (9 bit)
 
Join Date: Sep 2001
Posts: 278
I followed jackjones suggestions, went into the McAfee site and followed the removal instructions. It has been 3 days and the virus has not re-appear. The McAfee removal instructions seems to work.

Basically what I did is the following:

1. Download and install McAfee's latest superdat.

2. Went into Network Neighbourhood > Properties > TCP/IP > Properties > Bindings. Uncheck "File and Printer Sharing for Microsoft Networks"

3. Ran McAfee virus scan. It detected and deleted the virus files Brasil.pif and scrsvr.exe.

This removal process seems to work for me. I'll monitor and report back if the virus re-appear.



WSW is offline   Reply With Quote
Old 11-13-2002, 01:11 PM   #25
WSW
Member (9 bit)
 
Join Date: Sep 2001
Posts: 278
In my reply I forgot to mention that I also downloaded the Microsoft patch for Windows 98SE. The patch is supposed to prevent Windows 98SE from re-infecting by the same virus. So fare it seems to work.
WSW is offline   Reply With Quote
Old 11-13-2002, 06:18 PM   #26
Member (8 bit)
 
Join Date: Apr 2002
Posts: 144
Anyone know how long you have to leave file and printer sharing unchecked until you are safe?

Cheers.
matt_richards is offline   Reply With Quote
Old 11-13-2002, 06:57 PM   #27
Member (10 bit)
 
Join Date: Jan 2002
Location: Oregon Coast
Posts: 768
Are all the computers on your network clean?If one of them has the virus it will infect the rest as soon as you start sharing again.
jamesrpm is offline   Reply With Quote
Old 11-14-2002, 03:32 AM   #28
Member (8 bit)
 
Join Date: Apr 2002
Posts: 144
At the moment the machine is not connected to the network. But I had planned to do in the near future, so I wondered what the situation was with the file and printer sharing.
matt_richards is offline   Reply With Quote
Old 11-14-2002, 08:51 AM   #29
Member (9 bit)
 
Join Date: Jun 2000
Posts: 499
What are you running that needs File and Printer Sharing enabled?
galaxian is offline   Reply With Quote
Old 11-14-2002, 04:43 PM   #30
Member (8 bit)
 
Join Date: Apr 2002
Posts: 144
nothing at the moment - so there is no problem with removing it. But I will be connecting it to an existing peer to peer network soon - I just wondered if I would get reinfected when it is re-enabled.
matt_richards is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 04:21 AM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2