My virus software found sircam.worm@mm and now when I try to open any program I get a window called "real time protector for windows," and my access is denied. It appears I am missing something called Sirc32.exe. Any prompt advice for a solution is greatly appreciated!


    Requires Free Membership to View

I checked with one of my friends who has taken this little nasty apart. He passed on the info you need to fix this.

When the SirCam virus infects your machine, the default value of the registry key:
HKEY_CLASSES_ROOT\exefile\shell\open\command
is set to
C:\recycled\sirc32.exe "%1" %*"

This change to the registry ensures that the virus runs first each time you try to run any executable. If the removal process used eliminates the sirc32.exe file but does not correct the registry, then no executables will be able to run, as the file no longer exists.

To get around this, the file regedit.exe will need to be renamed to regedit.com and the key corrected to read:
@= "%1" %*"

There is a batch file that will make this fix available here.

This was first published in July 2001

There are Comments. Add yours.

 
TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: