Jump to content

Urgent Help Needed! .SCR virus?

★ Coups ★
Go to solution Solved by FTPCraft,

You didn't open the file so it can't do any harm unless it has external help from the site itself using plugins or something similar. So i think you're save for now.  

So. I clicked a fishy link that I received on steam. I really need help!

 

I downloaded the file of screenshot or whatever the website is called. I never opened the file, and I think I have successfully removed it. I installed it but I cannot find it in my downloads or recycling bin when I cleaned it all out.

 

I thought it was fishy, but I was stupid and curiosity has fucked me over. His profile is private and he just left.

 

CzrC: Hey, we held a competition in the group HoxHud!!!
CzrC: You have been selected one of TEN random winners!!!
CzrC: Choose any 5 item from the list, on the screen

(The link he sent, dont be stupid with it like I was, also, moderators feel free to remove it if necisary)

http://prtnsr.pw/Qd72ui/

 

♈ Chicken Coup ♈: hmm.
♈ Chicken Coup ♈: Can I see your profile please?
♈ Chicken Coup ♈: Hello?
♈ Chicken Coup ♈: Its a virus isnt it?

I then abused "it". I cut that out.

 

 

 

 

I am also running a Mcafee virus scan. Also Mcafee realtime protection didnt pick it up

 

So, my question is; I never opened the file, just downloaded it but I dont know where it has saved to. and I cant open the file path of it from the firefox download menu. (I cleared that)

 

Let me know if you need more information!

 

I will change my steam stuff when I get the file removed or whatever.

Please help me guys!

CPU - i7-4790k | CPU Cooler - NZXT Kraken X53 | Motherboard -  Asus Gyphon Z97 Armour Edition | RAM - Corsair Vengeance (2x8GB) 2400Mhz | Graphics Card - MSI GTX 1070 | Power Supply - Corsair CS750M | Storage - Seagate 1TB HDD | Samsung 500GB 850 Evo | Case - Fractal Design ARC Mini R2 | Colour Theme - Generic Red & Black

 

Operating System - Windows 10 Pro | Peripherals - Corsair RGB Mechanical K70 Keyboard/Corsair M65 Mouse

Click here to give a damn

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Use Malwarebytes along with some better form of antivirus.  Mcafee is crap.

 

Mcafee is good. I have the premium one that we payed a lot for. It has kept me safe for a seriously long time, (Ever sinse I can remember)

 

Also, I did not open the file, I just cannot find where its saved.

CPU - i7-4790k | CPU Cooler - NZXT Kraken X53 | Motherboard -  Asus Gyphon Z97 Armour Edition | RAM - Corsair Vengeance (2x8GB) 2400Mhz | Graphics Card - MSI GTX 1070 | Power Supply - Corsair CS750M | Storage - Seagate 1TB HDD | Samsung 500GB 850 Evo | Case - Fractal Design ARC Mini R2 | Colour Theme - Generic Red & Black

 

Operating System - Windows 10 Pro | Peripherals - Corsair RGB Mechanical K70 Keyboard/Corsair M65 Mouse

Click here to give a damn

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

It doesn't detect much, and has caused computers to crash since 2000.  If you wanna keep it, that's fine and your choice.  Personally, I prefer Malwarebytes and Kaspersky or Avast.  Use those 3 for the moment to see if any of them detect it.

 

Im running Malware Bytes and Macafee Scanner at the moment. Also, will Malywarebytes find this file?

CPU - i7-4790k | CPU Cooler - NZXT Kraken X53 | Motherboard -  Asus Gyphon Z97 Armour Edition | RAM - Corsair Vengeance (2x8GB) 2400Mhz | Graphics Card - MSI GTX 1070 | Power Supply - Corsair CS750M | Storage - Seagate 1TB HDD | Samsung 500GB 850 Evo | Case - Fractal Design ARC Mini R2 | Colour Theme - Generic Red & Black

 

Operating System - Windows 10 Pro | Peripherals - Corsair RGB Mechanical K70 Keyboard/Corsair M65 Mouse

Click here to give a damn

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Mcafee is good. I have the premium one that we payed a lot for. It has kept me safe for a seriously long time, (Ever sinse I can remember)

 

Also, I did not open the file, I just cannot find where its saved.

get norton. I downloaded the file and it instantly deleted it. :D

Link to comment
Share on other sites

Link to post
Share on other sites

get norton. I downloaded the file and it instantly deleted it. :D

 

 

It doesn't detect much, and has caused computers to crash since 2000.  If you wanna keep it, that's fine and your choice.  Personally, I prefer Malwarebytes and Kaspersky or Avast.  Use those 3 for the moment to see if any of them detect it.

 

 

Use Malwarebytes along with some better form of antivirus.  Mcafee is crap.

 

 

 

Thanks for the suggestions guys, but I need to find the file location.

CPU - i7-4790k | CPU Cooler - NZXT Kraken X53 | Motherboard -  Asus Gyphon Z97 Armour Edition | RAM - Corsair Vengeance (2x8GB) 2400Mhz | Graphics Card - MSI GTX 1070 | Power Supply - Corsair CS750M | Storage - Seagate 1TB HDD | Samsung 500GB 850 Evo | Case - Fractal Design ARC Mini R2 | Colour Theme - Generic Red & Black

 

Operating System - Windows 10 Pro | Peripherals - Corsair RGB Mechanical K70 Keyboard/Corsair M65 Mouse

Click here to give a damn

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

It's gunna hide in either system or system32 calling itself "WINLODR.SRC" if I remember correctly.

 

No items matched when I did CTRL + F in either system or System 32

CPU - i7-4790k | CPU Cooler - NZXT Kraken X53 | Motherboard -  Asus Gyphon Z97 Armour Edition | RAM - Corsair Vengeance (2x8GB) 2400Mhz | Graphics Card - MSI GTX 1070 | Power Supply - Corsair CS750M | Storage - Seagate 1TB HDD | Samsung 500GB 850 Evo | Case - Fractal Design ARC Mini R2 | Colour Theme - Generic Red & Black

 

Operating System - Windows 10 Pro | Peripherals - Corsair RGB Mechanical K70 Keyboard/Corsair M65 Mouse

Click here to give a damn

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

So. I clicked a fishy link that I received on steam. I really need help!

 

I downloaded the file of screenshot or whatever the website is called. I never opened the file, and I think I have successfully removed it. I installed it but I cannot find it in my downloads or recycling bin when I cleaned it all out.

 

I thought it was fishy, but I was stupid and curiosity has fucked me over. His profile is private and he just left.

 

CzrC: Hey, we held a competition in the group HoxHud!!!

CzrC: You have been selected one of TEN random winners!!!

CzrC: Choose any 5 item from the list, on the screen

(The link he sent, dont be stupid with it like I was, also, moderators feel free to remove it if necisary)

http://prtnsr.pw/Qd72ui/

 

♈ Chicken Coup ♈: hmm.

♈ Chicken Coup ♈: Can I see your profile please?

♈ Chicken Coup ♈: Hello?

♈ Chicken Coup ♈: Its a virus isnt it?

I then abused "it". I cut that out.

 

 

 

 

I am also running a Mcafee virus scan. Also Mcafee realtime protection didnt pick it up

 

So, my question is; I never opened the file, just downloaded it but I dont know where it has saved to. and I cant open the file path of it from the firefox download menu. (I cleared that)

 

Let me know if you need more information!

 

I will change my steam stuff when I get the file removed or whatever.

Please help me guys!

Might be a good idea to prevent this, download https://www.mywot.com/ it is an amazing addon, nearly got scammed by some guy who accused me of aimbotting, said he'd submitted a report on the forum, stupid me clicked the link, and WOT stopped me. (In my defense, the only difference was a .co.uk instead of a .com from the actual forum.)

My build : http://uk.pcpartpicker.com/p/Ck8VkL

[spoiler spoiler=Crimson Skyline]  My build: http://uk.pcpartpicker.com/p/Ck8VkL | I5-6600K | Hyper 212 Evo | Asus Z170 Pro Gaming + ROG Front Base | Axevir Core Series Red 2X8 2400 | Sandisk SSD Plus 240 GB | Western Digital 1TB Blue | MSI R9 390 | Corsair 760T | Corsair 850 RMI | Dell U2515H IPS | Hyper X II Cloud Red | Corsair K95 RGB | Logitech G602 |

[spoiler spoiler=Laptop] I7 3232QM | Nvidia GT635M | 17.6" TN | 1TB HD | 6GB RAM

Link to comment
Share on other sites

Link to post
Share on other sites

Might be a good idea to prevent this, download https://www.mywot.com/ it is an amazing addon, nearly got scammed by some guy who accused me of aimbotting, said he'd submitted a report on the forum, stupid me clicked the link, and WOT stopped me. (In my defense, the only difference was a .co.uk instead of a .com from the actual forum.)

 

I've already downloaded it so Its a bit late. Thanks anyway for the advice. I'll take that :D

 

But I need to find out of its doing anything

CPU - i7-4790k | CPU Cooler - NZXT Kraken X53 | Motherboard -  Asus Gyphon Z97 Armour Edition | RAM - Corsair Vengeance (2x8GB) 2400Mhz | Graphics Card - MSI GTX 1070 | Power Supply - Corsair CS750M | Storage - Seagate 1TB HDD | Samsung 500GB 850 Evo | Case - Fractal Design ARC Mini R2 | Colour Theme - Generic Red & Black

 

Operating System - Windows 10 Pro | Peripherals - Corsair RGB Mechanical K70 Keyboard/Corsair M65 Mouse

Click here to give a damn

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Try it in safe mode.  I heard it can cloak itself well in a normal boot.

 

But, that's where it is supposed to be...

 

I never opened the file, will it still do damage?

CPU - i7-4790k | CPU Cooler - NZXT Kraken X53 | Motherboard -  Asus Gyphon Z97 Armour Edition | RAM - Corsair Vengeance (2x8GB) 2400Mhz | Graphics Card - MSI GTX 1070 | Power Supply - Corsair CS750M | Storage - Seagate 1TB HDD | Samsung 500GB 850 Evo | Case - Fractal Design ARC Mini R2 | Colour Theme - Generic Red & Black

 

Operating System - Windows 10 Pro | Peripherals - Corsair RGB Mechanical K70 Keyboard/Corsair M65 Mouse

Click here to give a damn

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

You didn't open the file so it can't do any harm unless it has external help from the site itself using plugins or something similar. So i think you're save for now.  

Link to comment
Share on other sites

Link to post
Share on other sites

You didn't open the file so it can't do any harm unless it has external help from the site itself using plugins or something similar. So i think you're save for now.  

 

Can anyone confirm this?

CPU - i7-4790k | CPU Cooler - NZXT Kraken X53 | Motherboard -  Asus Gyphon Z97 Armour Edition | RAM - Corsair Vengeance (2x8GB) 2400Mhz | Graphics Card - MSI GTX 1070 | Power Supply - Corsair CS750M | Storage - Seagate 1TB HDD | Samsung 500GB 850 Evo | Case - Fractal Design ARC Mini R2 | Colour Theme - Generic Red & Black

 

Operating System - Windows 10 Pro | Peripherals - Corsair RGB Mechanical K70 Keyboard/Corsair M65 Mouse

Click here to give a damn

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Delete it, and look for any form of fishy scr files.  Remember that not all scr files are viruses, though.

 

It's most likely not going to do anything if you didn't touch it past deleting it.  In most cases it's just a copy pasta form of cheap malicious code.

 

And, it can depending on the design, but it also might not if you just delete it.  It really depends on the skill and creativity of the asshole/s who made it.

 

 

I dont know if I deleted it tho. I cleared my downloads and recycling bin but I dont remember seeing it

CPU - i7-4790k | CPU Cooler - NZXT Kraken X53 | Motherboard -  Asus Gyphon Z97 Armour Edition | RAM - Corsair Vengeance (2x8GB) 2400Mhz | Graphics Card - MSI GTX 1070 | Power Supply - Corsair CS750M | Storage - Seagate 1TB HDD | Samsung 500GB 850 Evo | Case - Fractal Design ARC Mini R2 | Colour Theme - Generic Red & Black

 

Operating System - Windows 10 Pro | Peripherals - Corsair RGB Mechanical K70 Keyboard/Corsair M65 Mouse

Click here to give a damn

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

You know, if you can't find the file with a antivirus/malware program you can always do a fresh reinstall of windows. It might not be the perfect option (If you haven't backed up your files you will lose them) but it's waaaaayyyy better than getting personal information stolen.

Link to comment
Share on other sites

Link to post
Share on other sites

As the above poster said, if you're that concerned just reinstall windows after backing up your files.  It would be wherever you downloaded it too.  So, check that path.

 

You really shouldn't back up your files AFTER you get infected because those files might just be infected too. You might just carry over the virus to your fresh install. You absolutely have to be sure that your new install doesn't get infected too.

Link to comment
Share on other sites

Link to post
Share on other sites

That depends on the virus, and what you've done.

Is there any way to know if its doing its thing?

CPU - i7-4790k | CPU Cooler - NZXT Kraken X53 | Motherboard -  Asus Gyphon Z97 Armour Edition | RAM - Corsair Vengeance (2x8GB) 2400Mhz | Graphics Card - MSI GTX 1070 | Power Supply - Corsair CS750M | Storage - Seagate 1TB HDD | Samsung 500GB 850 Evo | Case - Fractal Design ARC Mini R2 | Colour Theme - Generic Red & Black

 

Operating System - Windows 10 Pro | Peripherals - Corsair RGB Mechanical K70 Keyboard/Corsair M65 Mouse

Click here to give a damn

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

As long as you didn't open the file, I think you should be alright. The file should be detected by MBAM since they seem to be well aware of these sort of scams. You may want to read this: https://blog.malwarebytes.org/online-security/2014/09/steam-threats-what-they-are-and-what-you-can-do-to-protect-your-account/ or this https://blog.malwarebytes.org/fraud-scam/2014/11/rogue-scr-file-links-circulating-in-steam-chat/ for more info. 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×