Carny Ride

I also noticed this yesterday when I did a scan.  Did some research...cant find out much about it.  Am hoping that someone from Norton/Symantec can get to the bottom of this issue.  I noticed a posting on another site...scroll down to a poster called hellothere.

http://www.wilderssecurity.com/showthread.php?t=197064&page=3

Yes, I believe I have seen that page when I was doing some research about this whole phenomenon. I am not a great conspiracy theorist, but I often wonder if these 'joke' viruses aren't manufactured by some companies to make people think more about buying anti-spyware. I have just run a Norton quick scan & guess what? I saw our friend CARNY_RIDE back (it had probably never left & I just hadn't noticed it). It is the same as everyone says & comes at the end of a quick scan. Sometimes the halo appears around the pointer as if some activity is about to happen. Apart from complete Norton scans I have scanned with Yahoo anti-spy (toolbar), Superantispy, MS Defender & Prevx CSI. All of these have given me a clean bill of health.

 

Is this thing a real virus or not? Is it on my system (I can't find it) or not? Is it just Norton looking for this virus/rootkit?

 

I am getting a little paranoid now ...

Message Edited by Daveski17 on 10-15-2008 12:40 PM

Daveski17 wrote:
...Is it just Norton looking for this virus/rootkit?

Bingo. That's EXACTLY what's happening. From the screenshot in KLB's post, you can see the system scanning for "C:\FAUXVIRUS\carny ride.exe" - this is the full name of the malware. It has not FOUND this malware, nor does this path or malware exist on your system, the scanner is just telling you what it is looking for. If your system is infected at all, you will be alerted. There will be no ambiguity about Security Risks that are detected.

Thank YOU so much!!!  One less thing to worry about :smileywink:  I am so glad someone finally figured this out!!!

Excellent, I am glad that this has been resolved. I know Norton is pretty effiicient so I wasn’t losing large amounts of sleep over this, but I will admit that I was starting to become a little nervy. Thank you Mr Weiss for putting my mind finally at rest.

But my computer freezes when it comes to C:\FAUXVIRUS.... part, and I have to manualy restart it...

Is that happening only to me?

 

Btw, I found the solution... Good old c:\format c: :smileywink:

 

It became unbearable. It's possibile that something else caused my problems, and crashing NIS was just a collateral damadge, among other programs...

 

I'm glad that's over now, and now I have to install all necessary programs, bring back files... I hate when something like this happens... I have to be more cautious in the future...

Message Edited by buda on 10-15-2008 06:20 PM

Sorry, I think there is more happening here.  The system scans for "C:\FAUXVIRUS\carny_ride.exe".  And scans.  And scans.  (This is part of its "commonly infected areas and start-up files" scan.)  And scans.  I'm not sure why it doesn't just figure out why the thing is or isn't there.  While scanning, "rundll32.exe" and "appsvc32.exe" are eating my Task Manager time.

 

But what happens instead is the ENTIRE SCAN STOPS RIGHT THERE.  I get a message saying that Norton has completely scanned my computer successfully, with 13,156 items scanned.  Normally this total is well into six figures.  "No viruses, spyware, or other risks were found."  Well yeah, that's because they're on the other side of the carny ride!  Most of my computer has NOT been scanned.

 

I have noticed some serious issues with my system, notably the icons in Explorer flashing every few seconds.  This began a few days ago, seemingly the same time this message thread started generating lots of hits.

 

I hope this helps.  I have looked for "carny_ride.exe" anywhere -- registry, hidden files, etc, with no luck.  Some other thing is telling Norton this file exists and for whatever reason it causes the scan to stop with a false success.

 

- Bowen 

As a follow-up, I have also tried direct exclusion of the directory and specific file names by using "Virus and Spyware Protection Options" -> "Scan Exclusions".  This was not successful.  The scan continues to reach "C:\FAUXVIRUS\carny_ride.exe" and hangs.

 

When the scan begins, "AppSvc32.exe" takes over a chunk of CPU time, between 25-50%.  When the scan reaches this FAUXVIRUS phase, an extra program called "rundll32.exe" is added to the pile, and eats the rest of the CPU.  This grinds the scan to a halt, and the scan abandons after 1-2 minutes of grinding.  If, instead, I halt "rundll32.exe" by Task Manager, the Norton scan stops instantly, still claiming it has scanned the entire computer (it hasn't).

 

Again, I hope this helps, and am baffled about what may be going on.  I have also been seeing Norton defeating a rootkit threat each time I start up the computer.  I don't know what that is, but it sounds bad... 

As a second follow-up, my Web history today says I've been to ya-tracker.com and grabbed some file called "flashba.pdf".  Don't do this -- it's on the unsafe list.  https://safeweb.norton.com/report/show?url=ya-tracker.com

 

But I didn't go there, and I don't think anything redirected me there, either.  Not sure if it's related.

 

Okay, I've re-run the scan with Process Explorer active (I am on XP).  When C:\FAUXVIRUS\carny_ride.exe is searched for, an extra DLL is started by this command:

 

c:\windows\system32\rundll32.exe c:\progra~1\common~1\symant~1\virusd~1\20081018.004\cceraser.dll, DetectCache 1500

 

Once this happens, it hangs, end of search.

 

This is the "Symantec Shared / VirusDefs" folder, where there are a number of subfolders as YYYYMMDD.xxx.  Within this folder is cceraser.dll.  Do I know what it does?  Nope, but this crazy carny thing does.  And I can't rename or delete the folder or its contents.

 

I don't think shutting off the ability to run cceraser.dll is a good idea... it seems to do something important.

 

http://norton.lithium.com/norton/board/message?board.id=nis_feedback&message.id=9374

 

Anyway, that's all I got.  My problem is NOT resolved, and I'm concerned that I am still wide open.  Thanks in advance for your help.

Just when you thought it was safe to go back to the computer ...

 

I think this is all a bit scary. I have scanned my computer with SUPERAntiSpy, MS Defender, Yahoo-antispy & Prevx CSI regularly (let alone Norton quick & full scans) & come up clean everytime. Are you sure you are not being overly paranoid? I do think it is strange that CARNY_RIDE is virtually the last thing to show up on the scans though. I would like to know why.

Hi im new here, is a very rare thing and im so concerned about it , on saturday i downloaded a program and i removed it quicklier , after that i noticed a spyglass icon on thesystem tray advising me about aprogram to avoid some system changes , now heres the deal , after deleted that i ran  a scan since i have norton 360 1.0 and it detected the file fauxvirus carny_ride.exe i already formatted my HDdrive and it appears again i tried to upgrade norton with live update and it constanly asks for reebot. i have win vista and i tried to switch to norton 360 2.0 but im unable to do that , and norton seems to not have any info about that spyware or something, now the strange thing is that my pc is working fine but im worried of the possible issue that i may have.

 

By the way i already reviewed all the post of the forum and that screenshot of KLB dissapeared. Please someone tellme if you solved this issue

I am unable to complete a full system scan because of this. It just lags on this file forever, and never completes. In order to even stop the scan, I have to go into Task Manager and stop the process manually. I have tried everything that has been posted here, with no luck at all. I am getting very aggravated with this. So does Norton have a fix for this yet or not???

Message Edited by pyrexia65 on 10-20-2008 07:15 AM
Message Edited by pyrexia65 on 10-20-2008 07:17 AM

I haven’t noticed this on a full scan. I have a feeling this may be a Norton bug that affects spme people more than others. There again I don’t know a great deal about computers. As this whole topic has scared the pants off of a lot of people (including me at times) I have installed extra anti-spyware. SUPERAntiSpy (highly recommended by Spyware Warrior) has found nothing (well, apart from a lot of tracking cookies) neither has Prevx CSI (which claims it can spot our friend CARNY_RIDE a mile away). It could just be that this anti viral/rootkit program came with a Norton/Symantec upgrade & Norton is having a bloody good look for it. I do think you would know about it if your system was infected though. Regardless of what people say about Norton/Symantec security it is probably the second most popular anti viral software used on the net (I believe the free AVG is the most widely used). I should say it was as effective as anything else if not better. That combined with multiple other anti-spyware systems should be a good enough barrier or remedy to anything. I hope…

Tony

 

Since the screenshot mentioned in your reply has been taken away from the server, I post my own and ask you if this is the same case - not a virus FOUND but a search for a certain virus in a common library?

 

Excuse the strange language for you all, but if I translate the important part from my mother toungh it reads out "Searching commonly infected libraries" or something similar.

 

As extra information my wife told me that "faux" is French for "False".

 

MOLB 

 

Norton Internet Security scanning

Well, my Swedish isn’t too hot but I know ‘faux’ translates as ‘false’ in French. That is what I have seen on my interface as well. As soon as I figure out how to post a screen shot I will do that.

Do like this Daveski17:

  1. Grab your highlighted antivirus window at the right moment by pressing Alt + Ctrl + Prt Sc. This saves your grabbed bitmap into your memory stack.
  2. Open any picture or photo processing software and paste your bitmap into an empty "file" (Ctrl + V) and save the file in .GIF format for smallest file size.
  3. Use the.GIF file as it pleases you!

Good Luck / MOLB

Thanks MOLB I will give it a try!

I’m getting this now too.  I did not have this problem yesterday(I scan my PC every morning) so, I believe it’s either from something in the latest Norton update or in Windows Service Pack 3. I installed them both last night and now i’m getting the same show of Carny Ride in my daily scan along with the lock-up.

I’m getting the really long delay when running a full system scan, then eventually I get a message about an “internal program error, 3038,105” I think.  I follow the Norton instructions, by everything eventually loopsback to the same message with no resolution of the original problem.  The scan always stalls on the fauxvirus\carny_ride.  I’ve also had a problem with being directed to restart over and over.  Can anyone help me?  I’m not real computer-savy.

1 Like

I encounted this today.  My Computer has been disconnected for two months.  I reconnect, run the update and the quick scan and notice that the quick scan is held up on C:\fauxvirus\carny ride.exe for about 3 minutes toward the end of the run and the quickly finishes with no faults.  This file is not on the computer as far as I can tell (not just hidden).  My screen looked just like the screen shot posted except in english.