Author Topic: Win32:parite  (Read 5459 times)

0 Members and 1 Guest are viewing this topic.

surfy

  • Guest
Win32:parite
« on: July 29, 2010, 05:41:35 PM »
Hello,
I am trying to see if I have gotten rid of win32:parite infection.

Kapersky online scanner and avast detected several infected files.

I used doctorweb-cure it but I am not sure how to tell if the computer is clean.

I have attached new OTL and Malwarebytes logs.
and the Kaspersky log prior to using doctorweb.


I noticed that the file C:\WINDOWS\regedit.exe is missing.

The other annoying thing that is occurring is that when I try to open a file I get a "windows installer " opening and I don't know how to get that to stop.

Can anyone offer any advice? Do the logs show any signs of the infection remaining on the system.

Thank you in advance.


Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Win32:parite
« Reply #1 on: July 29, 2010, 05:44:38 PM »
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: Win32:parite
« Reply #2 on: July 29, 2010, 09:24:39 PM »
avast (even v4) is able to fully clean the infection

surfy

  • Guest
Re: Win32:parite
« Reply #3 on: July 29, 2010, 10:19:41 PM »
Thank you for your replies.

When I ran an avast scan it   showed 253 files infected with the threat: win32:parite

I tried to move it to the chest but it said not enough disk space although there was 78 GB of free space.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89228
  • No support PMs thanks
Re: Win32:parite
« Reply #4 on: July 29, 2010, 11:55:05 PM »
Increase the size of the chest and max file size (to cater for large files), avast Settings, Chest, see image.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Jtaylor83

  • Guest
Re: Win32:parite
« Reply #5 on: July 30, 2010, 03:16:56 AM »
The best way to disinfect Parite is to do it in offline mode (at least a boot-time scan). Because Parite is polymorphic, it's best to disinfect your computer with System Restore turned off.
« Last Edit: July 30, 2010, 05:22:55 AM by Jtaylor83 »

surfy

  • Guest
Re: Win32:parite
« Reply #6 on: July 30, 2010, 09:04:15 AM »
Increase the size of the chest and max file size (to cater for large files), avast Settings, Chest, see image.
This is very good to know. I misunderstood what Avast was trying to tell me!

surfy

  • Guest
Re: Win32:parite
« Reply #7 on: July 30, 2010, 09:11:15 AM »
The best way to disinfect Parite is to do it in offline mode (at least a boot-time scan). Because Parite is polymorphic, it's best to disinfect your computer with System Restore turned off.
I did a quick scan with Avast after using doctorweb-cure it and it shows no infected files. Should I do a boot time scan as well?
I have attached an OTL log. I don't know how to interpret this log.
I am trying to do a GMER scan as well but the tool only reaches a certain point and then the computer restarts itself without letting the scan finish therefore no log.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:parite
« Reply #8 on: July 30, 2010, 10:59:45 AM »
There are two elements to remove - however on one of them you have blocked out the file path, you will need to insert that

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

Code: [Select]
:OTL
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\wvcschm.sys -- (pkqltng)
O4 - Startup: C:\Documents and Settings\****\Start Menu\??????µµata\??????s?\LaunchU3.exe.lnk = C:\Documents and Settings\****\Application Data\Microsoft\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe ()

:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: Win32:parite
« Reply #9 on: July 30, 2010, 11:45:59 AM »
don't move the files to chest.. disinfect them with avast ;)

surfy

  • Guest
Re: Win32:parite
« Reply #10 on: July 30, 2010, 11:57:51 AM »
@Maxx_original
Thanks, I didn't know that!

@essexboy

Thank you very much for your reply.
I have attached the OTL logs.

surfy

  • Guest
Re: Win32:parite
« Reply #11 on: August 02, 2010, 10:05:50 AM »
Hello,
I have attached the OTL logs in my previous post.
I also ran a Kaspersky scan and have attached the log.

Is there anything I could do to remove the threats and infected objects?

Thank you in advance.