1. Welcome! Please take a few seconds to create your free account to post threads, make some friends, remove a few ads while surfing and much more. ClutchFans has been bringing fans together to talk Houston Sports since 1996. Join us!

SirCam virus alert!

Discussion in 'BBS Hangout' started by bobrek, Jul 23, 2001.

  1. bobrek

    bobrek Politics belong in the D & D

    Joined:
    Sep 16, 1999
    Messages:
    36,288
    Likes Received:
    26,639
    Apparently a new virus named SirCam was unleashed recently. My virus scan program did not detect it in the email but it did detect the .exe file it copied onto my system.

    It apprently emails itself to folks in your address book, but it was sent to people that I have never heard of from my computer.

    Here is a URL:

    http://news.cnet.com/news/0-1003-200-6647394.html?tag=mn_hd

    ------------------
     
  2. Major

    Major Member

    Joined:
    Jun 28, 1999
    Messages:
    41,417
    Likes Received:
    15,853
    This virus is annoying as hell. I've received it over 50 times since Saturday. I didn't open any of the files, but I wonder what kind of goodies were in them. [​IMG]



    ------------------
    http://www.swirve.com ... more fun than a barrel full of monkeys and midgets.
     
  3. bobrek

    bobrek Politics belong in the D & D

    Joined:
    Sep 16, 1999
    Messages:
    36,288
    Likes Received:
    26,639
    After verifying the attachment I received did not contain a virus, I stupidly opened it anyway. It place a file named scam32.exe onto my machine and set up the registry to run that program upon every startup. I removed the file and cleaned the registry. This is the first virus I have ever inflicted upon myself and potentially upon others. It even sent itself to Jeff, even though he IS NOT in my contact list, so I don't know where it gets its send to file.

    ------------------
     
  4. PhiSlammaJamma

    Joined:
    Aug 29, 1999
    Messages:
    28,761
    Likes Received:
    7,043
    I don't even open attachments without carefully scruntinizing them anymore. This one is very annoying.

    ------------------
    humble, but hungry.
     
  5. rockHEAD

    rockHEAD Contributing Member

    Joined:
    Mar 22, 1999
    Messages:
    10,337
    Likes Received:
    122
    This virus hides in the recycle bin and most virus scans exclude scanning the recycle bin. The virus takes your rundll32.exe file and deletes it making it impossible to run certain executable files. I have cleaning methods for the computer savvy, but they're at work. I cleaned this virus from 10+ machines. It propagated over our open network. Very nasty. My computer at home is down right now, or I'd ask you to email me and I'd send you instructions. You can use the McAfee or Norton website for cleaning instructions but one critical step in cleaning is to rename your regedit file from regedit.exe to regedit.com before making your registry changes. This is a nasty virus and it also tries to send out copies of itself attaching itself to image files from your PC so when your friends get email from you it looks like a legitimate image... the virus originated from prodigy.net.mx... it's a mexican virus... ching-gow!

    rH

    ------------------
    Updated: The Psychedelic Groove House of Rockets Basketball Love!

    join the club! Rockets Psychedelic Groove House Club on Yahoo!

    Stop annoying X10 ads! This link will set a cookie on your system that will disable X10 ads for one year!
     
  6. bobrek

    bobrek Politics belong in the D & D

    Joined:
    Sep 16, 1999
    Messages:
    36,288
    Likes Received:
    26,639
    I must have caught it before it completely propogated itself. It did not make it into my recycle bin, nor did it write the part dealing with the recylce bin into the registry. It did create the scam32.exe file and its registry entry which I have deleted. It also did not touch my run32dll file.

    It is interesting that it uses address it finds in your internet cache directory in addition to address book entries.

    ------------------
     
  7. rockHEAD

    rockHEAD Contributing Member

    Joined:
    Mar 22, 1999
    Messages:
    10,337
    Likes Received:
    122
    bo, check your rundll32 file.. if it's bigger than 24K, it could be a problem. The virus makes that file 124K... very suspicious...

    also check your autoexec.bat file...
    it puts a file at the bottom that has an @ symbol and 32 something....

    rH

    ------------------
    Updated: The Psychedelic Groove House of Rockets Basketball Love!

    join the club! Rockets Psychedelic Groove House Club on Yahoo!

    Stop annoying X10 ads! This link will set a cookie on your system that will disable X10 ads for one year!
     
  8. bobrek

    bobrek Politics belong in the D & D

    Joined:
    Sep 16, 1999
    Messages:
    36,288
    Likes Received:
    26,639
    Thanks for the advice RockHead, but I had already checked rundll32 and verified that it was correct (24K) against a known good version of the file. In addition, there is nothing in autoexec.bat or config.sys.

    ------------------
     
  9. bobrek

    bobrek Politics belong in the D & D

    Joined:
    Sep 16, 1999
    Messages:
    36,288
    Likes Received:
    26,639
    If you do get this virus and you want to see who you mailed stuff to, go to C:\Windows\System and search for a file named sc**.dll where ** is 2 random digits. This is the email file that the SirCam virus generated based on a combination of your Windows Address Book (WAB) file as well as stuff stored in your Internet Cache directory.

    ------------------
     

Share This Page

  • About ClutchFans

    Since 1996, ClutchFans has been loud and proud covering the Houston Rockets, helping set an industry standard for team fan sites. The forums have been a home for Houston sports fans as well as basketball fanatics around the globe.

  • Support ClutchFans!

    If you find that ClutchFans is a valuable resource for you, please consider becoming a Supporting Member. Supporting Members can upload photos and attachments directly to their posts, customize their user title and more. Gold Supporters see zero ads!


    Upgrade Now