General Car Related Discussion. To discuss anything that is related to cars and automotive technology that doesnt naturally fit into another forum catagory.

New virus out.....becareful people...

Thread Tools
 
Search this Thread
 
Old 28-11-2008, 08:41 AM
  #1  
Dingy
PassionFord Post Troll
Thread Starter
 
Dingy's Avatar
 
Join Date: Aug 2006
Location: Sydney, NSW
Posts: 3,191
Likes: 0
Received 0 Likes on 0 Posts
Default New virus out.....becareful people...

We are currently experiencing a large number of virus reports from customers regarding a virus that comes in to the network as marioforever.exe, which all AV vendors (including trend micro) are currently unable to quarantine/clean.
Old 28-11-2008, 09:09 AM
  #2  
Nash_mr2
I've found that life I needed.. It's HERE!!
 
Nash_mr2's Avatar
 
Join Date: Nov 2006
Posts: 1,169
Likes: 0
Received 0 Likes on 0 Posts
Default

http://www.precisesecurity.com/files...rioforeverexe/

looks like it sends random print jobs over the network
Old 28-11-2008, 09:12 AM
  #3  
Dingy
PassionFord Post Troll
Thread Starter
 
Dingy's Avatar
 
Join Date: Aug 2006
Location: Sydney, NSW
Posts: 3,191
Likes: 0
Received 0 Likes on 0 Posts
Default

Yeah and down's your network by deleting random dll files from workstations and servers.
Old 28-11-2008, 09:36 AM
  #4  
5t1g
Shotgun Bunter
 
5t1g's Avatar
 
Join Date: Jun 2005
Location: CRAWLEY
Posts: 697
Likes: 0
Received 0 Likes on 0 Posts
Default

Handy
Old 28-11-2008, 09:39 AM
  #5  
Seademon
Regular Contributor
 
Seademon's Avatar
 
Join Date: Aug 2005
Location: Dubai
Posts: 324
Likes: 0
Received 0 Likes on 0 Posts
Default

From that link its been going round since May so not that new!
Old 28-11-2008, 09:56 AM
  #6  
Dingy
PassionFord Post Troll
Thread Starter
 
Dingy's Avatar
 
Join Date: Aug 2006
Location: Sydney, NSW
Posts: 3,191
Likes: 0
Received 0 Likes on 0 Posts
Default

Maybe not that new then but we have experienced a large number of people being infected yesterday for some reason......

Not sure why.
Old 28-11-2008, 10:15 AM
  #7  
Turbocabbie
Top Cab !!
 
Turbocabbie's Avatar
 
Join Date: Aug 2006
Location: .
Posts: 3,989
Likes: 0
Received 1 Like on 1 Post
Default

marioforever.exe is also known as W32.Mariofev.A and you can remove it as follows :

1. Temporarily Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Reboot computer in SafeMode
4. Run a full system scan and clean/delete all infected file(s)
5. Find and stop the service.
Click Start > Run.
- Type services.msc, and then click OK.
- Locate and select the service that was detected.

Service name: SCNa
Display name: SCNa Service

- Click Action > Properties.
- Click Stop.
- Change Startup Type to Manual.
- Click OK and close the Services window.

6. Delete/Modify any values added to the registry. [how to edit registry]
Navigate to and delete the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\[NUMBER]\”[34 DIGIT HEX NUMBER]” = “[RANDOM DATA]”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
\”ztpInit_Dlls” = “nvrsma”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\”ccnt” = “[NUMBER OF INFECTION ATTEMPTS]”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\”mid” = “[RANDOM HEX DATA]”

Navigate to and delete the following registry subkey:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SCNa

7. Exit registry editor and restart the computer.

Trending Topics

Old 28-11-2008, 10:28 AM
  #8  
Dingy
PassionFord Post Troll
Thread Starter
 
Dingy's Avatar
 
Join Date: Aug 2006
Location: Sydney, NSW
Posts: 3,191
Likes: 0
Received 0 Likes on 0 Posts
Default

Could be a new strain out then cause its not that easy to remove LOL.....
Old 28-11-2008, 05:20 PM
  #9  
foreigneRS
Testing the future
 
foreigneRS's Avatar
 
Join Date: Jul 2003
Location: W. Sussex
Posts: 17,597
Received 24 Likes on 16 Posts
Default

what kind of idiot would execute a file like that? if you are in charge of a corporate network where such people exist, i would think that you should make sure that any .exe file is blocked. easier said than done i expect?
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
PhoneShopRS
PassionFord FAQs
3
05-11-2020 06:50 PM
yorkie92
General Car Related Discussion.
0
06-09-2015 05:34 PM
Rob_DOHC
Computers, Consoles and I.T.
5
15-08-2015 11:17 AM
jayRS
General Car Related Discussion.
24
07-11-2004 09:05 PM
luke89
General Car Related Discussion.
4
12-10-2004 04:37 PM



Quick Reply: New virus out.....becareful people...



All times are GMT. The time now is 01:42 PM.