0 Replies Latest reply on Feb 5, 2013 11:31 AM by terralynn98

    W32/Mariofev!mem Trojan in C:\WINDOWS\system32\services.exe

      I'm seeing between 2-5 of these events per week.  But hosts come up clean when re-scanned.  Has anyone else been experiencing this trogan?

       

      Threat Target File Path:C:\WINDOWS\system32\services.exe
      Event Category:Malware detected
      Event ID:1292
      Threat Severity:Critical
      Threat Name:W32/Mariofev!mem
      Threat Type:Trojan
      Action Taken:access denied
      Threat Handled:false
      Analyzer Detection Method:OAS
      Threat Event Descriptions 

       

      I have run the following

      McAfee Tools as follows:

       

      STINGER                                              Clean

       

      GETSUSP                                             Reported as suspicious

                                                                      Pointsec Protector

                                                                      PureEdge Viewer

                                                                      Approverit  cleansys 32

                                                                      Reported Unknown

                                                                      Tumbleweed

                                                                      FIPS DLL

                                                                      Actividenty

                                                                      Banner service

       

      ROOTKIT                                              Clean

       

      Message was edited by: terralynn98 on 2/5/13 11:30:22 AM CST

       

      Message was edited by: terralynn98 on 2/5/13 11:31:31 AM CST