I just got hit with that virus - First marioforever.exe
It copies itself through unsecured network shares (generally with everyone modify access)...
To really completely get rid of it - lock down your shares - so only certain people have access....
To track down who is doing it - up your windows security log for object create (that'll let you see who is creating files on that share.....
Another thing is - check the property information of the file it creates - the marioforever / spamuzle variant that i had basically replicates through smb shares and creates autorun.inf and modifies registry keys of the victim computer..... Basically - it will attempt to launch an application everytime you click on the network share drive (just like a cdrom autorun).
To check to see if the autorun.inf file is there - Click on the network share location - unhide system files and unhide hidden files (both)....
That will display all the hidden stuff.
Click on properties of the autorun.inf and check to see who the owner is - the owner is the one who copied to file over there.
After you find out who did it - take the computer offline and reimage...
Hope it works for you as it did for me
Clear
Main Topics
Browse All Topics





by: BasheerptPosted on 2008-10-18 at 13:32:57ID: 22749662
Remove Administrative privilege from their respevtive stations from all the network users.
Uninstall any toolbars through add/remove programs