0 Replies Latest reply on Feb 5, 2013 11:31 AM by terralynn98

    W32/Mariofev!mem Trojan in C:\WINDOWS\system32\services.exe

      I'm seeing between 2-5 of these events per week.  But hosts come up clean when re-scanned.  Has anyone else been experiencing this trogan?


      Threat Target File Path:C:\WINDOWS\system32\services.exe
      Event Category:Malware detected
      Event ID:1292
      Threat Severity:Critical
      Threat Name:W32/Mariofev!mem
      Threat Type:Trojan
      Action Taken:access denied
      Threat Handled:false
      Analyzer Detection Method:OAS
      Threat Event Descriptions 


      I have run the following

      McAfee Tools as follows:


      STINGER                                              Clean


      GETSUSP                                             Reported as suspicious

                                                                      Pointsec Protector

                                                                      PureEdge Viewer

                                                                      Approverit  cleansys 32

                                                                      Reported Unknown


                                                                      FIPS DLL


                                                                      Banner service


      ROOTKIT                                              Clean


      Message was edited by: terralynn98 on 2/5/13 11:30:22 AM CST


      Message was edited by: terralynn98 on 2/5/13 11:31:31 AM CST