Go Back   TechArena Community > Technology > Networking & Security
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , ,

Sponsored Links



Removal solution for PWSteal.Marlap.C

Networking & Security


Reply
 
Thread Tools Search this Thread
  #1  
Old 03-03-2010
Member
 
Join Date: Nov 2009
Posts: 580
Removal solution for PWSteal.Marlap.C

Hi friends, I am using samsung laptop which is loaded with Windows Vista operating system. And my anti virus software program are displaying that your system are infected with PWSteal.Marlap.C virus. And I tried to remove this virus from my anti virus program but it is unable to delete this virus. And this virus made my machine tremendously slow. I want some good removal solution for this virus. Can any will tell me that how to remove this virus, please?
Reply With Quote
  #2  
Old 03-03-2010
Steve123's Avatar
Member
 
Join Date: Feb 2008
Posts: 2,619
Re: Removal solution for PWSteal.Marlap.C

PWSteal.Marlap.C generates the given file:

C:\Windows\PictureViewer.exe

And then run EJN[RANDOM NUMBER].tmp.

Now this virus insert the value:

"PictureViewer" = "C:\Windows\PictureViewer.exe"

to the registry subkey:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Reply With Quote
  #3  
Old 03-03-2010
Shen's Avatar
Member
 
Join Date: May 2008
Posts: 2,918
Re: Removal solution for PWSteal.Marlap.C

This virus asks the user to out the given data if an AOL client is installed:
  1. Name
  2. Account Number
  3. Account Type
  4. Address
  5. ZIP
  6. Phone number
  7. PIN number
  8. Birthday
  9. Mother?123,456s Maiden Name
  10. Social Security Number
  11. Credit Card Number and its expiration date
  12. Debit Card Number and its expiration date
Reply With Quote
  #4  
Old 03-03-2010
Big Fish's Avatar
Member
 
Join Date: Jan 2006
Posts: 3,514
Re: Removal solution for PWSteal.Marlap.C

This virus sends the collected information to the gen below Web site:

"http://]imform.coolinc.info/[REMOVED"

This virus also tries to remove %System%\taskmgr.exe.

Note:
%System% is a variable that refers to the System folder. By default this is C:\Windows\System
__________________
Truly, if there is evil in this world, it lies within the heart of mankind. -Edward D. Morrison

Old soldiers never die- they just fade away.
Reply With Quote
  #5  
Old 03-03-2010
Zachary's Avatar
Member
 
Join Date: Jan 2006
Posts: 3,932
Re: Removal solution for PWSteal.Marlap.C

There are some recommendation for PWSteal.Marlap.C:
  • Isolate compromised computers quickly to prevent threats from spreading further. Perform a forensic analysis and restore the computers using trusted media.
  • Ensure that programs and users of the computer use the lowest level of privileges necessary to complete a task. When prompted for a root or UAC password, ensure that the program asking for administration-level access is a legitimate application.
  • Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.
__________________
90% of everything is crap...except for crap, because crap is 100% crap
Reply With Quote
  #6  
Old 03-03-2010
Spyrus's Avatar
Member
 
Join Date: May 2008
Posts: 3,470
Re: Removal solution for PWSteal.Marlap.C

Search and delete to the subkey:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Remove the value in the right panel:

"PictureViewer" = "C:\Windows\PictureViewer.exe"
Reply With Quote
Reply

  TechArena Community > Technology > Networking & Security


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Removal solution for PWSteal.Marlap.C"
Thread Thread Starter Forum Replies Last Post
Need removal solution for TROJ_DROPPER.EAA DeMario Networking & Security 5 10-03-2010 01:31 PM
Removal solution for WORM_SOHANAD.JH Enriquee Networking & Security 4 09-03-2010 12:35 PM
Removal solution for WORM_WALEDAC.NYS Elieis Networking & Security 4 08-03-2010 02:43 PM
Removal solution for TSPY_GIMMIV.A Enriqueta Networking & Security 4 17-02-2010 05:45 AM
Removal solution for TSPY_YALUDLE.M Cruzz Networking & Security 4 12-02-2010 03:48 AM


All times are GMT +5.5. The time now is 06:58 AM.