General Car Related Discussion. To discuss anything that is related to cars and automotive technology that doesnt naturally fit into another forum catagory.

New virus out.....becareful people...

Thread Tools
 
Search this Thread
 
Old Nov 28, 2008 | 08:41 AM
  #1  
Dingy's Avatar
Dingy
Thread Starter
PassionFord Post Troll
 
Joined: Aug 2006
Posts: 3,191
Likes: 0
From: Sydney, NSW
Default New virus out.....becareful people...

We are currently experiencing a large number of virus reports from customers regarding a virus that comes in to the network as marioforever.exe, which all AV vendors (including trend micro) are currently unable to quarantine/clean.
Reply
Old Nov 28, 2008 | 09:09 AM
  #2  
Nash_mr2's Avatar
Nash_mr2
I've found that life I needed.. It's HERE!!
 
Joined: Nov 2006
Posts: 1,169
Likes: 0
Default

http://www.precisesecurity.com/files...rioforeverexe/

looks like it sends random print jobs over the network
Reply
Old Nov 28, 2008 | 09:12 AM
  #3  
Dingy's Avatar
Dingy
Thread Starter
PassionFord Post Troll
 
Joined: Aug 2006
Posts: 3,191
Likes: 0
From: Sydney, NSW
Default

Yeah and down's your network by deleting random dll files from workstations and servers.
Reply
Old Nov 28, 2008 | 09:36 AM
  #4  
5t1g's Avatar
5t1g
Shotgun Bunter
 
Joined: Jun 2005
Posts: 697
Likes: 0
From: CRAWLEY
Default

Handy
Reply
Old Nov 28, 2008 | 09:39 AM
  #5  
Seademon's Avatar
Seademon
Regular Contributor
 
Joined: Aug 2005
Posts: 324
Likes: 0
From: Dubai
Default

From that link its been going round since May so not that new!
Reply
Old Nov 28, 2008 | 09:56 AM
  #6  
Dingy's Avatar
Dingy
Thread Starter
PassionFord Post Troll
 
Joined: Aug 2006
Posts: 3,191
Likes: 0
From: Sydney, NSW
Default

Maybe not that new then but we have experienced a large number of people being infected yesterday for some reason......

Not sure why.
Reply
Old Nov 28, 2008 | 10:15 AM
  #7  
Turbocabbie's Avatar
Turbocabbie
Top Cab !!
 
Joined: Aug 2006
Posts: 3,989
Likes: 1
From: .
Default

marioforever.exe is also known as W32.Mariofev.A and you can remove it as follows :

1. Temporarily Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Reboot computer in SafeMode
4. Run a full system scan and clean/delete all infected file(s)
5. Find and stop the service.
Click Start > Run.
- Type services.msc, and then click OK.
- Locate and select the service that was detected.

Service name: SCNa
Display name: SCNa Service

- Click Action > Properties.
- Click Stop.
- Change Startup Type to Manual.
- Click OK and close the Services window.

6. Delete/Modify any values added to the registry. [how to edit registry]
Navigate to and delete the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\[NUMBER]\”[34 DIGIT HEX NUMBER]” = “[RANDOM DATA]”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
\”ztpInit_Dlls” = “nvrsma”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\”ccnt” = “[NUMBER OF INFECTION ATTEMPTS]”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\”mid” = “[RANDOM HEX DATA]”

Navigate to and delete the following registry subkey:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SCNa

7. Exit registry editor and restart the computer.
Reply
Old Nov 28, 2008 | 10:28 AM
  #8  
Dingy's Avatar
Dingy
Thread Starter
PassionFord Post Troll
 
Joined: Aug 2006
Posts: 3,191
Likes: 0
From: Sydney, NSW
Default

Could be a new strain out then cause its not that easy to remove LOL.....
Reply
Old Nov 28, 2008 | 05:20 PM
  #9  
foreigneRS's Avatar
foreigneRS
Testing the future
 
Joined: Jul 2003
Posts: 17,597
Likes: 24
From: W. Sussex
Default

what kind of idiot would execute a file like that? if you are in charge of a corporate network where such people exist, i would think that you should make sure that any .exe file is blocked. easier said than done i expect?
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
PhoneShopRS
PassionFord FAQs
3
Nov 5, 2020 06:50 PM
yorkie92
General Car Related Discussion.
0
Sep 6, 2015 05:34 PM
Rob_DOHC
Computers, Consoles and I.T.
5
Aug 15, 2015 11:17 AM
jayRS
General Car Related Discussion.
24
Nov 7, 2004 09:05 PM
luke89
General Car Related Discussion.
4
Oct 12, 2004 04:37 PM




All times are GMT. The time now is 04:03 PM.