Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | February 2009 (4.38) |
| Protection available since | 3 December 2008 20:00:50 (GMT) |
| Last updated | 21 December 2008 05:52:07 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Mario-E copies itself to network shares that are protected by weak passwords.
When first run W32/Mario-E copies itself to <System>\aston.mt and creates the following files:
<System>\dllcache\user32.dll
<System>\nvaux32.dll
The file user32.dll is detected as Troj/User32Hk-A, and the file nvaux32.dll is detected as W32/MarioF-B.
