|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#1 |
|
Member (9 bit)
Join Date: Sep 2001
Posts: 278
|
scrsvr.exe virus problem
My PC repeatedly got infected by the scrsvr.exe virus. I can use McAfee anti-virus to detect and delete the virus. However, after a few days, the virus re-appear.
The virus also try to add a run command into either the system.ini or win.ini or startup. I can use msconfig to go into system.ini or win.ini or startup to delete the run scrsvr.exe command. However, after a few days a new run scrsvr.exe command will be added into the ini file again. Anyone has experience in getting rid of this scrsvr.exe virus?
|
|
|
|
|
|
#2 |
|
Member (12 bit)
Join Date: Jan 2002
Location: Central Arkansas
Posts: 2,170
|
Have you tried Symantecs removal tool? Removal Tool Hope this helps, from what I have read this one is pain.
__________________
Roger "Our greatest glory is not in never falling, but in rising every time we fall." -Confucius |
|
|
|
|
|
#3 |
|
Member (5 bit)
Join Date: Nov 2002
Posts: 22
|
The only real way to get rid of a bad worm like that is to wipe the drive clean and start from scratch. I know it sounds drastic but it will be better for the system in the long run.
|
|
|
|
|
|
#4 |
|
Member (9 bit)
Join Date: Sep 2001
Posts: 278
|
I am hoping that I don't have to re-format the harddisk from scratch.
I installed the Microsoft patch and ran the worm removal tool. The removal tool detected the worm in the .ini file. The worm is supposed to have been removed. I'll wait a few days to see if the computer get re-infected. Thanks for all the suggestions. |
|
|
|
|
|
#5 |
|
Member (7 bit)
Join Date: Sep 2002
Location: Pueblo, Colorado
Posts: 101
|
Just one quick question:
IS YOUR MACAFEE ANTIVIRUS CURRENT? |
|
|
|
|
|
#6 |
|
Member (9 bit)
Join Date: Jun 2000
Posts: 499
|
And are you running it in "always on" mode?
You want to detect trojans/worms/viruses as they arrive NOT after they have been installed and done potential damage. |
|
|
|
|
|
#7 |
|
Member (9 bit)
Join Date: Sep 2001
Posts: 278
|
Yes, I am using McAfee anti-virus with the latest Superdat. However, when I install my PC, I did test Internet and email access before I installed McAfee anti-virus. The worm could have got through before I install McAfee.
McAfee anti-virus is always ON on my computer. I also use ZoneAlarm firewall. The worm removal software seems to work so far. I will know for sure after a few days. Before I use the worm removal software the worm seems to hide somewhere in the computer and tends to re-appear a few days after I do a virus scan using McAfee. |
|
|
|
|
|
#8 |
|
Member (8 bit)
Join Date: Aug 1999
Location: Sonora CA
Posts: 193
|
same problem plus
I have the same problem plus every few minutes one of the following pops up:
marco! alevir.exe brasil.pif I've removed the offending line from win.ini only to have it reappear, run Norton's removal tool, all to no avail. Antivirus is up to date. All Norton can do is quarantine them. beerman Last edited by beerman; 11-09-2002 at 12:15 PM. |
|
|
|
|
|
#9 |
|
digitally confused
Premium Member
|
I hate to say this, but McAfee just ain't what it used to be (as I think you have found out)....
Next chance you get, buy Norton AV 2003 or get the free version of AVG. I'm using the latter. See this: http://forum.pcmech.com/showthread.p...ight=antivirus
__________________
. Pentium D 805 | ASUS P5L-MX | CORSAIR ValueSelect 2 GHz |Primary HDD WD 40GB Back up HDD Seagate 7200.10 250GB SATA | eVGA 7600gt | Creative X-Fi Extreme Music audio card | Hauppauge TV Tuner Card | Lite On DVD burner/ LightScribe | COOLER MASTER Case | Fortron ATX400-PA 400W Power Supply | ViewSonic Q19wb LCD |
|
|
|
|
|
#10 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 37,786
|
beerman: go to housecall.antivirus.com and get a free online scan.
|
|
|
|
|
|
#11 |
|
Member (8 bit)
Join Date: Apr 2002
Posts: 153
|
I think you are being infected again and again. Try reading the removal intructions at : http://vil.mcafee.com/dispVirus.asp?virus_k=99729
Try instaling the mentioned patch and see if it helps. |
|
|
|
|
|
#12 |
|
Member (8 bit)
Join Date: Aug 1999
Location: Sonora CA
Posts: 193
|
jackjones
Unchecking file and print sharing as suggested by MaAfee seems to have done the trick for me. Wonder why Symantec didn't think of that.
Thanks, beerman |
|
|
|
|
|
#13 |
|
Member (9 bit)
Join Date: Sep 2001
Posts: 278
|
I have the same problem as beerman.
The Symatic worm removal software worked only for two days and now the worm re-appeared. I'll try the suggestion by glc to see if it works for me.
|
|
|
|
|
|
#14 |
|
Member (8 bit)
Join Date: Apr 2002
Posts: 153
|
Why don’t you try removing it and patching the hole instead of just removing it. The removal software only removes the program it does not make your computer immune.
Last edited by jackjones; 11-11-2002 at 10:33 AM. |
|
|
|
|
|
#15 |
|
Member (9 bit)
Join Date: Jun 2000
Posts: 499
|
"Wonder why Symantec didn't think of that. "
From the removal link above, How to Configure Windows Folders for maximum network protection "Disable file and print sharing, if possible 1. Right-click the Network Neighborhood or the My Network Places icon on the Windows desktop. 2. Click Properties. 3. Click the Configuration tab. 4. Click Client for Microsoft Networks. 5. Click File and Print Sharing. 6. Uncheck both boxes, and then click OK." |
|
|
|
|
|
#16 |
|
Member (8 bit)
Join Date: Aug 1999
Location: Sonora CA
Posts: 193
|
galaxian
Thanks for the Symantec link. beerman |
|
|
|
|
|
#17 |
|
Member (8 bit)
Join Date: Apr 2002
Posts: 144
|
Hello there,
I have had the exact same problem - and it is still recurring. I have tried all the removal tools - including in safe mode and without any system restore programs present. I have also removed the entires in win.ini etc. All virus definitions have been updated and maintained, but it still keeps popping up and being quarantined. As much as anything else, I am just intrigued to know where on my hard drive it is dormantly residing and then reinfecting. Does anyone know by whay mechanism it is reinfecting. Matt. |
|
|
|
|
|
#18 |
|
Member (9 bit)
Join Date: Jun 2000
Posts: 499
|
What OS?
And have you disabled print and file sharing? |
|
|
|
|
|
#19 |
|
Member (8 bit)
Join Date: Aug 1999
Location: Sonora CA
Posts: 193
|
Matt
The ones I had---marco, brazil and alevir all were in C:\windows and I was able to delete them in safe mode. beerman |
|
|
|
|
|
#20 |
|
Member (8 bit)
Join Date: Apr 2002
Posts: 144
|
The infected compuer has windows 98 on it. I have not disabled file and printer sharing, but I will do - out of interest why does this help.
What I cannot understand is where the virus or trojan is hiding so that it can refer after an all clear from the fixes and after all traces have been removed from win.ini etc. Cheers guys. |
|
|
|
|
|
#21 |
|
Member (9 bit)
Join Date: Jun 2000
Posts: 499
|
I "presume" you are going back on the net after clearing off the virus?
If so, you are then being reinfected via the gaping security hole with File&Print sharing open. |
|
|
|
|
|
#22 |
|
Member (8 bit)
Join Date: Apr 2002
Posts: 144
|
I think I am misunderstanding the context of "file and printer sharing". Am I correct in thinking that it is only a problem if it is bound to the internet connection, with "file and printer sharing" over a LAN not being as much of a problem.
|
|
|
|
|
|
#23 |
|
Member (9 bit)
Join Date: Jun 2000
Posts: 499
|
I suggest you run a Shields Up test
https://grc.com/x/ne.dll?bh0bkyd2 And there is a little more info on the issue here also. http://grc.com/su-explain.htm |
|
|
|
|
|
#24 |
|
Member (9 bit)
Join Date: Sep 2001
Posts: 278
|
I followed jackjones suggestions, went into the McAfee site and followed the removal instructions. It has been 3 days and the virus has not re-appear. The McAfee removal instructions seems to work.
Basically what I did is the following: 1. Download and install McAfee's latest superdat. 2. Went into Network Neighbourhood > Properties > TCP/IP > Properties > Bindings. Uncheck "File and Printer Sharing for Microsoft Networks" 3. Ran McAfee virus scan. It detected and deleted the virus files Brasil.pif and scrsvr.exe. This removal process seems to work for me. I'll monitor and report back if the virus re-appear.
|
|
|
|
|
|
#25 |
|
Member (9 bit)
Join Date: Sep 2001
Posts: 278
|
In my reply I forgot to mention that I also downloaded the Microsoft patch for Windows 98SE. The patch is supposed to prevent Windows 98SE from re-infecting by the same virus. So fare it seems to work.
|
|
|
|
|
|
#26 |
|
Member (8 bit)
Join Date: Apr 2002
Posts: 144
|
Anyone know how long you have to leave file and printer sharing unchecked until you are safe?
Cheers. |
|
|
|
|
|
#27 |
|
Member (10 bit)
Join Date: Jan 2002
Location: Oregon Coast
Posts: 768
|
Are all the computers on your network clean?If one of them has the virus it will infect the rest as soon as you start sharing again.
|
|
|
|
|
|
#28 |
|
Member (8 bit)
Join Date: Apr 2002
Posts: 144
|
At the moment the machine is not connected to the network. But I had planned to do in the near future, so I wondered what the situation was with the file and printer sharing.
|
|
|
|
|
|
#29 |
|
Member (9 bit)
Join Date: Jun 2000
Posts: 499
|
What are you running that needs File and Printer Sharing enabled?
|
|
|
|
|
|
#30 |
|
Member (8 bit)
Join Date: Apr 2002
Posts: 144
|
nothing at the moment - so there is no problem with removing it. But I will be connecting it to an existing peer to peer network soon - I just wondered if I would get reinfected when it is re-enabled.
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|