Carny Ride

:manhappy: Everyone, relax. This is just Symantec's software scanning for possible threats. If you're having the antivirus application stop on that file, and then claim everything is okay, it doesn't mean you have an infection, but it also doesn't me you don't. If you clicked on "Full Scan" and you know there's more folders than it's scanned, chances are you may need a 2nd opinion. A lot of viruses like to block the common scanners such as "McAfee" and "Norton"/"Symantec". This is because these are the popular ones, but chances are, if you DO have a rootkit, you will not have any luck scanning it. A rootkit takes control of the kernel, and hides itself behind windows. So any scan you do will not find the rootkit files themselves. You need to do what some of the users stated in the first pages of this post, grab a bootable CD with ClamAV on it, or some form of linux virus scanning software, make sure you have NTFS support (by using a flavor of linux such as Ubuntu or SuSE, and perform a full system scan on your machine.

 

Also - IF you are experiencing strange behavior, you probably do have a virus or rootkit on your system. Besides keeping your computer up to date (Windows Update, and the like), there are a few tricks you can use to keep your computer safe from viruses.

Keep your virus scanner up to date, as well as making sure you have an adequate firewall (windows firewall does the trick for some people, others will need something more advanced, such as Norton Internet Security 2009), and always watch what you download! Not all safe websites have safe links!. If you don't recognize the file you're downloading, give it a quick scan! There's nothing to be lost except a few precious minutes of your time, much better than losing data. Remember, never run an EXE file if you don't know where it's from, or what it is. And for you gamers out there, who are using Keygens and No-CD Cracks, these are the BIGGEST containers for strange malware. PLEASE if you need to use keygens or no-CD keys, play smart, scan the file first, and NEVER pirate software you can easily pay for.

 

Browse Safe;

Sean "Hellfyre" V.
A+ Certified IT Professional

Hi, I just did a scan now with Norton, and found the same thing, the Fauxvirus and carney ride, then it said it found a tracking cookie when it finished scanning this file, what is a tracking cookie? Are they safe? Thankyou!

If you got a message saying it detected Carny_Ride.exe, that's when you have something to worry about. Carny_Ride.exe is not a tracking cookie, it's a severe virus that can steal bank account information, and it's well known. You'd have recieved a large alert had you really been infected. If you have been infected by Carny_Ride.exe, please, take appropriate procedures to clean yourself of that infection by finding rootkit removal software. If norton just "passed over the file" you're fine. Also tracking cookies are safe. They're not pleasant, but they're safe. When a website is visited, it drops what's called a "cookie" on your computer. The following explains cookies, and is taken from Wikipedia:

 

"HTTP cookies, or more commonly referred to as Web cookies, tracking cookies or just cookies, are parcels of text sent by a server to a Web client (usually a browser) and then sent back unchanged by the client each time it accesses that server. HTTP cookies are used for authenticating, session tracking (state maintenance), and maintaining specific information about users, such as site preferences or the contents of their electronic shopping carts. The term "cookie" is derived from "magic cookie," a well-known concept in UNIX computing which inspired both the idea and the name of HTTP cookies.

Because they can be used for tracking browsing behavior, cookies have been of concern for Internet privacy. As a result, they have been subject to legislation in various countries such as the United States, as well as the European Union. Cookies have also been criticized because the identification of users they provide is not always accurate and because they could potentially be a target of network attackers. Some alternatives to cookies exist, but each has its own uses, advantages, and drawbacks.

Cookies are also subject to a number of misconceptions, mostly based on the erroneous notion that they are computer programs. In fact, cookies are simple pieces of data unable to perform any operation by themselves. In particular, they are neither spyware nor viruses, although cookies from certain sites are described as spyware by many anti-spyware products because they allow users to be tracked when they visit various sites.

Most modern browsers allow users to decide whether to accept cookies, but rejection makes some websites unusable. For example, shopping carts implemented using cookies do not work if cookies are rejected."

 

Sean "Hellfyre" Verezhensky

A+ Certified IT Professional

3 Likes

My Norton full system scan stalls out on “C:\fauxvirus\carny_ride.exe”.  It runs for several minutes and then I get a message reading something like “Norton Internal Program Error, 3038,105”.  It has a Norton link to a possible solution and I follow all the steps, but to no avail.  I have not been able to contact anyone at Norton about the solution and I am becoming very frustrated.  I don’t understand why this is not being investigated by Norton and a fix for it being distributed to their subscribers.  Anyone at Norton / Symantec listening?

Message Edited by Arkie on 10-31-2008 12:27 PM

5 Likes

This sort of sounds OK, but why out of 300 trillion potential threats out there does Norton quickscan spend 2/3 minutes looking for only this thing? I did a WIN XP search of c:\ and got the response "c:\Fauxvirus is unavailable". Not sure if this means its hiding or its not there at all. If this thing is quietly collecting your Bank login and P/W details its going to let your system behave normally while it does it.You will find out when the Bank starts sending back your chqs or the cash machine swallows your card.

Probably being a bit paranoid like everyone else.

1 Like

I'm having the same problems which I believe started when I opened a message  from my niece on Bebo, instead of the message I was taken straight to her Bebo page and my problems began.

When using Word, it constantly flashes, hangs and then shuts down.  Virus scans stop after C:\FAUXVIRUS\carny ride.exe after scanning only 9071 files, normal scans are over 500,000.  Printing documents slowed right down and computer generally slowed up.

I am in the middle of another scan and it seems to be working ok.  I managed to removed some adware.

I was speaking to other relatives who had opened this message from our niece and they have had much worse problems than me.

I can access Norton two ways, direct through Norton Protection Centre and also through BT Yahoo Online Protection, the first one hangs the second one is working ok.  I do not have two virus checking systems, both were installed at the same time from the same source.  Scan using the BT YAHOOO shortcut has now fully completed with nothing showing up, it is certainly a weird situation.

Tried another scan using the Norton Online Protection shortcut, this has failed once again at under 10,000 files and during the fauxvius section. and with tracking cookies showing (only 8 ).

Could it be a problem with Norton?

 

The other day I ran into this problem and the scan halted.

 

Today the scan completed succesfully - I did notice it scaned for C:\FAUXVIRUS carney ride.exe.

Hi Everyone ,hopefully this might be useful.

SUMMARY
I think it might help to summarize the position to date

1)   We have all seen c:\Fauxvirus\carny_ride in our scans.Just

remember there are two scans that Norton does,Quickscan which covers

main risk areas and typically will be under 10,000 items or Fullscan

which will cover perhaps 200,000 or more items.The thing that has drawn

all of our attention is that Norton lingers for about 2/3 minutes over

carny_ride.It does this in both the Quick and Full scan.Just note here

also the item counter moves by 4(In my case from 5077 to 5081) while

lingering on carny_ride.To a non technical person this would suggest

there is something there and Norton has decided it is not a threat.
2)   The technical/Norton position is that carny_ride is just something

that exists and Norton is just making sure you don't have it.The

question then is why check just for carny_ride and why does it take 2/3

minutes to do so and why does the item counter move.
3)   Another forum I read suggested that Fauxvirus\carny_ride is a

deadly and virulent piece of software that can, if executed, load a

Rootkit Trojan called 'Backdoor Agent B'.This can and will record your

bank a\c details and forward to someone in Chechnya or Kyrgystan.Norton

has on its site a fix called FxagentB which is available to download

and run.
http://www.symantec.com/norton/security_response/threatexplorer/azlisti

ng.jsp?azid=B
Norton Safeweb believes it to be a 'Joke Train'
http://safeweb.norton.com/report/show?name=fauxvirus.com
4)  Norton could end this by simply giving a yes/no answer to two

quextions
A) Will the Norton Firewall prevent carny_ride from being downloaded

onto your system?
B) If it beats the Firewall will Norton find and remove with a scan?
I suspect the answers will be a resounding 'Maybe'

5)   The ultimate advice.DO NOT USE INTERNET BANKING UNLESS YOUR BANK

OFFERS A SECOND LEVEL OF SECURITY AFTER YOUR PASSWORD.Typically this

involves the generation of a random group of nmbrs/letrs to enter after

entering your password.
The current and future nature of intrusion attacks are primarily

designed to steal money.They dont care whether you look at BBC,CNN or

FOX, THEY WANT THE MONEY FROM YOUR BANK ACCOUNT.
6)   To see how dangerous and deadly Trojan rootkits are have a look at

the MSsysinternals site written by MS professionals
http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx

To finish on a lighter note one forum suggested that Fauxvirus was a

French response to Freedom Fries.

Elainec, the problem you’re having sounds like a virus infection. i would definately look towards taking your computer in to be repaired or at least looked at. Your other option, if you’re able to, is to back up your data and do the work yourself. This is probably not Carny_Ride, but it definately sounds like a virus.

So in the end, Is this really a virus or is it really a program that stops for a few minutes to check if you have it? Because what Tony said its stop their to check your computer if you have it but you cant search for it because it isnt really in your system because its part of your security. I have never seen this until now when I was doing a full system scan and its up to date. For me, it stops there for a minute or two then just continues until it scaned my whole computer. Once its done, it says I have nothing and that im clean. But what really worries me is this about just saying on that file for a few minutes then continuing without no action whats so ever. So plz, is it a norton program or not?

Ryan, not being part of the norton staff, i can't say one way or another, but i can tell you that from some people's reactions, when it continues scanning (and mine did the same thing, which is how i got to this forum) you probably don't have a virus. When it stops on the file, and then your AV program closes or does something strange, like crashes or claims the scan is done when you know there's many more files to be scanned, chances are you shouldn't just accept it's results and should find a 3rd party software solution to do a scan with, something like Avast, Super Spyblaster, or Ad-Aware, to check and re-check to make sure what you have isn't a malicious program invading your system.

 

Final answer: If you've done a full scan, gotten to your 500,000 file mark, completed with no results, chances are, even if it stopped for a few seconds on a file, you're clean.  If you have it stop, and crash, bigger fish to worry about than that one file.

Unrelated, hopefully Norton/Symantec hear this from an avid gamer, computer builder, IT professional, and programmer. YOUR SCANNING SOFTWARE IS A RESOURCE HOG. Please tone it down to the level of the corporate suite, noone appreciates the fancy graphics and pretty colors. People just want something that works.

 

You have a GREAT piece of software, but your application should not take up HUNDREDS of megs of ram, to load flash-like animations and awesome interfaces. You're providing a virus scanner, not a multimedia movie player or game. Please cut down on the graphics and make it more load-balanced across 64-bit systems!

Well every week I always scan my computer and never gotten a virus because the sites I go to are safe and never ever go to one of those high risk sites even if I download a game from those game host sites(Like ijji or ogplanet). Then today like I said I scaned my computer all up to date until it stopped on this type of file then just continued like normal until all and I mean all of my files were scaned. So hopefully your right and I hope I dont have any kind of virus in my computer. Cause If I would have gotten one, it would have told me and would show up in my history.

Message Edited by Ryan on 11-02-2008 01:08 AM

1 Like

I managed to complete a full system scan using the Norton Online Protection shortcut, it completed and guess what, it found a downloader and has quarantined it.

The only way to deal with virus and spyware is to keep your security systems up-to-date and scan regularly.  Scan incoming and outgoing email, outgoing especially since if you are not sending email and the scanner is showing you are, you have a problem.

Also scan attachments before opening.

1 Like

You guys are doing what helps keep ME and other users safe, thanks :)

Kudos to both!

okay I still couldnt take my mind off of this so I decided to put my windows vista on safe mode and I used norton to scan. Once it hit that file the Faux Virus thing, it stopped only for a mintue then read it as a virus. When I went to go check on what it was, it was manly a security thing to put all the tracking cookies into and this risk is low. So norton deleted and it contiuned to scan the rest of my files. When it was finish scanning my whole computer thank god I didnt get any other types of viruses. So in the end, Faux Virus has no harm to your computer and its not a high risk virus. Then I put my computer back to normal and did a quick scan, So yeah that file does come up at the last of your quickscan because like people are saying and the people who work for norton is just security to check if you have any kind of malware or any other kind of viruses or tracking cookies. In conculation, this is just gets all of the tracking cookies and puts them there, thats why its not found in your computer system because thats part of norton’s protecton. Like I said before, if you would have a virus it would have told you and would appear on your historys. If Faux was really a virus, it would have told us and would quarantine it right? So I hope this information helps you guys.

Message Edited by Ryan on 11-02-2008 12:35 PM

Actually, not true. Fauxvirus is NOT a tracking cookie, nor is it anything like a tracking cookie. there are many strains of the virus “Fauxvirus” and none of them are “low risk” ranging from anomalous user control of your computer (ejecting the CD-Rom Drive or shutting down your system) to more malicious intents, such as scavanging bank logins and passwords, to using your computer to connect to an IRC server where a bot gains control. review your sources.

well thats how it came up when I was scanning while in safe mode. Also Faux is a french word meaning false. So this is just a fake virus.

I'm fluent in french. I know what the word means, and i'm telling you it's not a "fake" virus :)

 

Quoted from known virus archives:

CARNY_RIDE.EXE AUTOMATED MALWARE PROFILE, ANALYSIS, REMOVAL AND SIGNATURE INFORMATION: DEFINITION OF: CARNY_RIDE.EXE
  • Safety Rating: Known Malware, do not run
  • Malware Family: Part of Malware group - Rootkit Haxdoor
  • Malware Form: EXPLOIT

 

These files are activated only on the next system reboot. When the backdoor is active, all its files are hidden. Moreover, the backdoor tries to inject its code into the Windows Explorer process and hides both 'Explorer.exe' and 'Winlogon.exe' processes. However, our F-Secure BlackLight Rootkit Eliminator can successfully find and remove the backdoor.

The "vtd_16.exe" file is a Windows CMD.EXE and it is run by the backdoor as a decoy. The backdoor's name is CMD.EXE, so it runs a command interpreter to hide its other activities.

The "cm.dll" and "draw32.dll" files are identical. They represent the main component of the backdoor. The Winlogon Notification key for the "draw32.dll" file is added to the Registry:

  • [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\draw32]


This allows the backdoor to start when a user logs on. The way of starting these files used by this malware are quite rare.

The backdoor is quite powerful (see below) and it has the password stealing capabilities. The backdoor contains the following strings and it can steal login and password information that the users keys in from different online banks and payment systems:

so what your saying is that we all have that virus on our computers? Cause when it scans it stops there for me for like a minute and two,the number count which tells you how many files it scanned still goes up with no crash whats so ever and continues to scan the rest of my computer until all of my files are scanned. So the question is, does this mean im clean? 

Message Edited by Ryan on 11-02-2008 05:34 PM
Message Edited by Ryan on 11-02-2008 06:20 PM