Duis mollis, est non commodo luctus, nisi erat porttitor ligula, eget lacinia odio sem nec elit. Sed posuere consectetur est at lobortis. Vestibulum id ligula porta felis euismod semper. Donec ullamcorper nulla non metus auctor fringilla. Aenean lacinia bibendum nulla sed consectetur. Cras justo odio, dapibus ac facilisis in, egestas eget quam. Cras mattis consectetur purus sit amet fermentum. Morbi leo risus, porta ac consectetur ac, vestibulum at eros. Sed posuere consectetur est at lobortis. Etiam porta sem malesuada magna mollis euismod. Cum sociis natoque penatibus et magnis dis parturient montes, nascetur ridiculus mus. Duis mollis, est non commodo luctus, nisi erat porttitor ligula, eget lacinia odio sem nec elit. Cras justo odio, dapibus ac facilisis in, egestas eget quam. Aenean eu leo quam. Pellentesque ornare sem lacinia quam venenatis vestibulum. Curabitur blandit tempus porttitor. Sed posuere consectetur est at lobortis.
Hi Mike
I've had a look through our sample collection and can't find a file which matches this name.
Before we go down a more complicated root, can you ensure that you're displaying hidden files and folders? You can go this in Explorer through Tools --> Folder Options. Go to the view tab and choose the option for "Show hidden files and folders". If you can then see the file in explorer, then please submit it to us for analysis through https://submit.symantec.com/retail.
Thanks
Orla
Symantec Security Response
Hi Orla
Yes, I've tried showing hidden files so I could clear out the temp internet files. I've even tried to type the folder into the path bar, but it came up as not found. So no joy with that one I'm afraid. I haven't been brave enough to see if I can find it through DOS. It's been a long time since I've been in there....
Mike
I'm seeing quite a bit of Google discussion about fauxvirus.
General thinking is rootkit which would explain your situation.
I have found a file named 6x8be16.cmd and I guess this is the source of the infection.
The code:
[Edit: code of possible infection removed; data still available]
javigast wrote:
I have found a file named 6x8be16.cmd and I guess this is the source of the infection...
I would recommend sending a virus submission sample here:
https://submit.symantec.com/websubmit/retail.cgi
Thanks!
I have the same problem. Scans hit C:\fauxvirus\carny_ride.exe and then stop. Searches with Windows Explorer and at the command prompt come up empty even when searching system and hidden files. Other AV and anti-spy products fail to report it. Not seeing anything under Task Manager which seem to be it. Some forums are saying it is a rootkit or haxdoor. Some say it is a bug in Norton and doesn’t really exist.
SatelliteGuy wrote:
I have the same problem. Scans hit C:\fauxvirus\carny_ride.exe and then stop. Searches with Windows Explorer and at the command prompt come up empty even when searching system and hidden files. Other AV and anti-spy products fail to report it. Not seeing anything under Task Manager which seem to be it. Some forums are saying it is a rootkit or haxdoor. Some say it is a bug in Norton and doesn't really exist.
Have you also followed the steps listed in the How To Troubleshoot a Suspected Malware Infection announcement? This is a more advanced way to troubleshoot the issue, and it sounds as if you have tried the more simple suggestions. Please let us know how this document helps. Thanks!
I noticed this today as well. The only thing Ive downloaded is Malwarebytes’ Anti-Malware. Could it be a part of that software?
i have this file showing up also. can’t find it in my computer anywhere. only showed up when quick scaning with norton 360 1.0. swithched to 2.0 and it doesn’t show up anymore. is this a real virus or not? it isn’t causing any problems.
ok, i have been looking at the same problem. But let me give this a new angle and how this came about for me.
-My old harddrive failed and was faced with buying a brand new harddrive.
-Installed new drive and booted from windows xp cd and installed fresh copy of xp with no other drives attached and not connected to the internet and no other computers on the network (not even plugged into computer)
-After installing windows xp, installed norton 360 from cd
-Then hooked up computer to internet through router
-ran update on norton 360
-also ran update for windows xp to get it with all avaible secuirity fixes and other stuff
-but still when running virus scans its comes up with same problem
-I HAVE NOTHING ELSE INSTALLED ON THE COMPUTER EXCEPT WINDOWS XP AND NORTON, NOTHING AT ALL
-I HAVE NOW REINSTALLED WINDOWS FRESH FROM FORMAT 3 TIMES WITH THE SAME RESULT
-btw the windows and norton cd are legit from store so dont bother suggesting or asking me if there legit
-I can not detrmine the source of the file, i also can not locate this file on the harddrive, enabled view hidden files and folders
-Checked registry and run through msconfig to see if i could see anything out of place and nothing
what makes this odd is the fact this is from a fresh install with no way realistically of infection from outside sources other than just being connected to the internet (which would mean that until all security fixes are applied from microsoft and updates from norton) then the system is vunerable from random exploits which at this time havent been addressed with a norton update?
I have the same issue, found this thread through googling. Odd that searches for "Carny Ride" and "fauxvirus" only point here and no other virus websites.
I have some suspicion that neither the folder nor the virus exist, that this is something Norton's is looking for but not actually found. Or perhaps some sort of internal check.
The folder "C:\fauxvirus\" does not exist, and as far as I can tell I'm not having any virus-related problems, but I would feel better knowing one way or another whether I should be concerned.
Can everyone who is seeing this “shown” by their Norton product post a screenshot of what they are actually seeing? My guess would be that you are seeing this during a scan, where the scanner is displaying what it is searching for. The name of the malware is that full pathname, which can be a bit misleading.
[bad image removed]
What is this? Norton didn’t show up in my task bar on startup like it should, so I did a quick scan and this is the last program it scans during the quick scan and finds nothing wrong. I also did a full system scan with no problems.
I also detected the same issue few hours ago. And when I take a look at KLB's screenshot, I see that we probably have same symptoms.
I'm running on Vista with Norton Internet Security 10.2.0.30. At first I had a problem with starting some of my aplications (like Windows Live Mail and Microsoft Office), than I noticed very strange problem - networking icon on systray is frozen, with the red X, and did nothing when clicked, but I have Internet connection (I'm connected via LAN). Also when I go to Networking and Sharing center, it freezes. I also cannot go to the Task Manager, when I press Ctrl+Alt+Delete and than Go to Task Manager, it never opens. The Language selector for the keyboard is also missing on task bar, and I cannot change langs by Alt+Shift. And at first, there was no Norton IS icon on systray...
After several reboots I runned full system scan, and norton simply blocks like on KLB's screenshot. I searched on c: and trough registry for that folder and that filename, and I found nothing...
Does anybody have the solution for this issue...?
<< I'm running on Vista with Norton Internet Security 10.2.0.30. >>
That is NIS 2007 isn't it?
OS Required Microsoft Windows XP Home Edition, Microsoft Windows XP Professional
Was it intended for VISTA?
Have you thought of upgrading to NIS 2009? If you have a valid subscription to NIS 2007 you can upgrade free for the remainder of that subscription period.
I think it is 2007 version, but I have not find that label in program, just that version number.
I think it should work fine with my Vista HP, because I got that version of NIS with my brand new Toshiba Satellite laptop that has preinstalled Vista HP with bundled software. I have 90 days free licence, and 35 day remaining...
I will try to upgrade to the newest version and hope that that will solve my problem cause, at least in my case, it is not just a false alarm or some kind of joke software, some features on my system are disabled, and I have problems with strarting some applications, and not to mention that I cannot shut down my comp properly nor access task manager...
I am pretty sure I saw this 'fauxvirus' come up in MS Defender on a routine check. I can't find it anywhere on my computer either. I haven't noticed any ill effects on my system, apart from the fact I think it takes my Safari browser time to load sometimes when the computer has just been booted up. That could just be my imagination. I downloaded Superantispy & have found nothing. In fact I have not seen it come up in a scan since I have run that & had my Norton uninstalled & reinstalled. I found this freeware scanner which mentions 'Carny Ride'.
http://spywarefiles.prevx.com/spywarefiles.asp?FXC=HFCI10495894
This may be of some use. I have run this & it has given my computer a clean bill of health (of course, that could mean nothing).
Actually, now I think about it, it wasn't on MS Defender that I saw this, but was on Norton. I only run Defender when I want to, as opposed to having it do routine scans. This was what made me think it was on that when I saw this 'fauxvirus'. Sorry if I have confused anyone with this.
I must say, since I have been running some anti-spyware programs I have not seen it since. I will keep my eyes peeled as they say.