|
-
September 29th, 2002, 11:50 PM
#1
scrsvr.exe
Anyone know what this is? ZoneAlarm pops up asking if I want to let this file access the network.
It's a 28k file in the Windows directory with no modified date.
Didn't find anything with a google search.
Who is General Failure and why is he reading my disk?
-
September 29th, 2002, 11:58 PM
#2
I'd guess it's a trojan but don't recognize the filename. Do you have TDS-3 ?
-
September 30th, 2002, 12:01 AM
#3
Hi mawil - Housecall picks up most trojans. You can run a free online scan here
-
September 30th, 2002, 09:54 AM
#4
No TDS-3. I've tried housecall before, a long time ago. It didn't want to work on my system.
I also did a restore of a backed up drive image and it got rid of it for a little while. Then it came back last nite.
My cable access has been down over the weekend and I'm connecting using free Juno right now. Soon as the cable is back up, I'll give Housecall another try.
Who is General Failure and why is he reading my disk?
-
September 30th, 2002, 10:30 AM
#5
mawil, You could also go to the link below and download "The Cleaner" which has a Free 30 day Trial Period and is excellent at detecting & removing any Trojans your computer may have picked up.
http://www.moosoft.com/thecleaner/
HTH
Tufenuf
-
September 30th, 2002, 10:37 AM
#6
Tufenuf, I've scanned with eTrust AV, The Cleaner and Tauscan.
Nothing shows up.
Who is General Failure and why is he reading my disk?
-
September 30th, 2002, 10:46 AM
#7
mawil, I found a few references to that file here.
http://groups.google.com/groups?as_q...59-1&lr=&hl=en
You may want to try renaming the file to scrsvr.exe.old and see if it causes any problems. It's worth a try.
Tufenuf
-
September 30th, 2002, 11:01 AM
#8
Mawil,
If you do decide to try HouseCall anyways, make sure you have all your other anti-virus, etc shut down. In fact, have everything else shut down except what you need to connect. 
Have you run AdAware?
-
September 30th, 2002, 12:21 PM
#9
It's interesting that most of those references that Tufenuf found are the last couple of days. Can you look through any logs and see what type of request it was. Can you zip the file and email it to me? There's been an interesting rise in udp port 137 stuff over the last couple of days.
-
September 30th, 2002, 01:42 PM
#10
mawil, Below is how someone else corrected the scrsvr.exe file problem.
Well, I answered my own questions!!! Am I a computer detective or WHAT......I tried to delete that scrsvr.exe file and it wouldn't let me@%^#@?"}, so I rebooted to DOS and deleted it there..........that HD noise was beginning to drive me crazy, and so I reboot and guess what.......no more noise! whaddarelief.
Sue
She also edited the win.ini file as shown below.
I just had the W32 Hai worm and it was renamed but it keeps causing a notice on bootup that there's a file (caused by the worm)that can't be found; I find a line in the win.ini in sysedit that says run=thefilename.exe,c:/windows/scrsvr.exe
She followed the editing instructions at this link.
http://securityresponse.symantec.com....hllw.hai.html
Tufenuf
Last edited by Tufenuf; September 30th, 2002 at 01:48 PM.
-
September 30th, 2002, 02:49 PM
#11
I aggree with Tuf follow what he says, most trojan accsess files are about that size, and when you rid yourself of that file an error will come up saying the file is missing anyways, so go into windows sys.ini or win.ini and search for any entries with the file name you provided and delete just the name from you dir. had about 4 differnt trojans so i have had some experience ridding myself of them, and just a tip: never download file about that size unless you reall know what it is!!!
-
September 30th, 2002, 07:42 PM
#12
Well, I didn't download it. Just don't know where it came from. I did go into dos this morning and deleted it. Just got off work and am going to edit win.ini, etc. now.
I wonder why it came back after doing the drive image restore? That is what is scary.
Who is General Failure and why is he reading my disk?
-
September 30th, 2002, 07:59 PM
#13
IMM, as I said, I deleted the file this A.M., but if it comes back again, I'll certainly send it to you.
I just edited my win.ini file and no more messages at startup.
I did find another reference to it in my windows\applog file, scrsvr.lgc.
Got rid of it too.
Who is General Failure and why is he reading my disk?
-
September 30th, 2002, 08:10 PM
#14
I think it's a spy file attached to a program you downloaded.
-
September 30th, 2002, 08:15 PM
#15
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|