Thought of the Day

“A goal is a dream with a deadline.”

Napoleon Hill

Total Pageviews

Thursday, February 12, 2009

new virus problem and solution (Sirc32.exe )

issue is virus, can’t open any programs (any exe files)

Observed: Many exe file were their in c drive I deleted those things and the regedit, taskmgr, mspaint, outlook, is not opening if you click on the exe it will give open with option are file missing error.

Cause: The W32.Sircam.Worm@mm worm virus can cause this issue. The W32/Sircam virus spreads itself through e-mail messages or unprotected network file shares and can reveal or delete information on your computer. To verify that your computer is infected with this kind of virus:

Restart your computer, press F8 at the Windows XP Startup menu, and then select Safe Mode with Command Prompt.
At the command prompt, type regedit, and press ENTER.
If the following registry key is set to C:\recycled\sirc32.exe "%1" %*, your computer is infected with the W32/SirCam worm virus:
HKEY_CLASSES_ROOT\exefile\shell\open\command

Note If this registry setting is anything other than

"%1" %*

Your computer may be infected with a different virus.


Solution

In front of the above data anything is their just delete it. and run combofix in command prompt.
Note:

The removal of the Sirc32.exe virus without modification of the HKEY_CLASSES_ROOT\Exefile\Shell\Open\Command key will invalidate every executable file on the computer because, according to this line in the registry, the executable files are to be run as a command line parameter to the Sirc32.exe file which no longer exists. This prompts the "Windows cannot find" message when you try to start the executable file

For more info check Article ID: 311446

No comments:

Followers