Solved

sircam virus

Posted on 2001-07-26
6
221 Views
Last Modified: 2012-08-14
I'm trying to clean a machine that was infected with the sircam virus.

I ran through a dr solomon's scan
(updated to  virus def file 4.0.4150 scan engine 4140)

it found the virus, but couldnt clean, so i deleted the files instead.

Now when i try and run Word97 (or other.exe files)  - an error appears - sircam32.exe is needed to open file of this type

But if i run word by clicking on a word document instead, it runs ok. Outlook 2k also seems to seems to work, but i can't access anything in control panel, or run regedit or scandisk...

Any suggestions?

0
Comment
Question by:jlymn
  • 4
  • 2
6 Comments
 
LVL 20

Expert Comment

by:Dufo G. Belski
Comment Utility
Have a look at this question which was posted to this topic area immediately before you posted yours.
 
http://www.experts-exchange.com/jsp/qShow.jsp?ta=virus&qid=20158227

It has a link to a lot of information about the virus, and on the linked page are more links to various  removal tools, like SCRMOVE2.ZIP, available here:

http://www.mcafeeb2b.com/naicommon/avert/avert-research-center/tools.asp

0
 

Author Comment

by:jlymn
Comment Utility
The scrmove2.zip file didn't help. I stil have the problem of clicking on an exe and an error occuring.

Nothing i see on the web page mentions anything about this. The virus does seem to be removed, but the damage has been done - how could i fix this?
0
 
LVL 20

Expert Comment

by:Dufo G. Belski
Comment Utility
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 
LVL 20

Accepted Solution

by:
Dufo G. Belski earned 100 total points
Comment Utility
"an error appears - sircam32.exe is needed to open
file of this type"

This comes up because the virus modifies the registry key

HKEY_CLASSES_ROOTexefile\shell\open\command

The tool above fixes the registry.

0
 

Author Comment

by:jlymn
Comment Utility
that fixed it

Thanks!
0
 
LVL 20

Expert Comment

by:Dufo G. Belski
Comment Utility
Great!!!
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Suggested Solutions

As more computers now shipped with 64-bit version of Windows, more users are now using this Operating System.  So it's important to be aware how some 32-bit diagnostic tool works on these systems, so we know what to expect when analyzing the logs an…
HOW TO REMOTELY CLEAN MEROND.O WITH ESET SILENTLY PROBLEM       If you have the fortunate luck to contract the Merond.O virus on your network, it can be quite troublesome to remove as it propagates to network shares on your network. In my case, the …
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now