Author Topic: avast doesnt get rid of Win32 parite's???  (Read 8033 times)

0 Members and 1 Guest are viewing this topic.

Ryan

  • Guest
avast doesnt get rid of Win32 parite's???
« on: June 22, 2003, 06:31:47 AM »
Hey i have a win32 parite and avast wont get rid of it does anyone know how to get tird of them?? or something :-\

Offline raman

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1062
Re:avast doesnt get rid of Win32 parite's???
« Reply #1 on: June 22, 2003, 11:30:07 AM »
What Operating System do you use(Win9x/XP?). Do you FAT(32) or NTFS.
If i remember correctly Pinfi/Parite infects the Explorer.exe. So it is maybe the best to use a Dos-AV for cleaning, but if you use NTFS it is a bit difficult. Maybe your Windows starts a Parite-Dropper on Startup. So tell us, what files get executed on Windowsstart. You can use MSCONFIG.exe or http://www.lurkhere.com/~nicefiles/hijackthis193.zip for that.
MfG Ralf

techie101

  • Guest
Re:avast doesnt get rid of Win32 parite's???
« Reply #2 on: June 22, 2003, 08:30:14 PM »
Ryan,

Try www.symantec.com
You should find a free removal tool for the Win32 Parite.

Good Luck

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re:avast doesnt get rid of Win32 parite's???
« Reply #3 on: June 22, 2003, 08:48:35 PM »
I don't think Symantec has a Parite removal tool. Where did you hear about it, techie101?

However, we do have one :P
Ryan, I'll have it sent to you on Monday (see http://www.avast.com/forum/index.php?board=2;action=display;threadid=411;start=0 )

Vlk
If at first you don't succeed, then skydiving's not for you.

techie101

  • Guest
Re:avast doesnt get rid of Win32 parite's???
« Reply #4 on: June 22, 2003, 09:04:36 PM »
Vlk,

Wasn't exactly sure of which removal tools they had, but I have obtained many that I needed from them.
I should have checked first.
Sorry.

I try.

 ;D

techie101

  • Guest
Re:avast doesnt get rid of Win32 parite's???
« Reply #5 on: June 22, 2003, 09:10:08 PM »
Vlk,

Maybe I can make up for it?
Upon executing a file infected with W32.Pinfi, the virus will perform the following:


1. Adds the registry value:

PINF

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer

2. Appends itself to Explorer.exe to remain memory-resident.

3. Appends itself to all the .EXE and .SCR files that it finds on all the local and mapped drives. The virus contains an algorithm to slow the infection, so the virus will only infect a few files at a time.

4. W32.Pinfi will create a tempfile in the temporary folder. It will get the temporary folder by using a Windows API. The tempfile this virus creates will always have the following name:

[3 random letters][4 random hexadecimal digits].tmp

The file it creates is a UPX packed executable file. The temporary file will be executed by the virus, and it is this file that will attempt to infect files over network shares.


Forgive Oh Great Moderator!!

 ::)


Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re:avast doesnt get rid of Win32 parite's???
« Reply #6 on: June 23, 2003, 10:13:27 AM »
ryan, I've sent the parite removal tool to your e-mail address.

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re:avast doesnt get rid of Win32 parite's???
« Reply #7 on: June 23, 2003, 10:18:18 AM »
Quote
Forgive Oh Great Moderator!!

Apology accepted ;D
If at first you don't succeed, then skydiving's not for you.